roles
Version 0.1.08 operations
Predefined and custom roles with their permissions
GET/organisations/{id}/rolesDashboard session
Parameters
idstringpathrequired
Responses
200
idstring (uuid)requiredkeystring | nullrequiredPredefined role key, null for custom
namestringrequireddescriptionstring | nullrequiredpredefinedbooleanrequiredpermissionsstring[]requiredmemberCountnumberrequiredMembers of this organisation holding the role
Code samples
curl -X GET "$KONNECT_API_URL/organisations/id/roles" \
-H "Cookie: konnect_session=$KONNECT_SESSION"Example: 200
[
{
"id": "id",
"key": "key",
"name": "name",
"description": "description",
"predefined": true,
"permissions": [
"payments.view"
],
"memberCount": 1
}
]Create a custom role, or duplicate one with basedOnRoleId
POST/organisations/{id}/rolesDashboard session
Parameters
idstringpathrequired
Request body application/json
namestringrequireddescriptionstringpermissionsstring[]Required unless basedOnRoleId is given
basedOnRoleIdstring (uuid)Duplicate the permissions of this role
Responses
201
idstring (uuid)requiredkeystring | nullrequiredPredefined role key, null for custom
namestringrequireddescriptionstring | nullrequiredpredefinedbooleanrequiredpermissionsstring[]requiredmemberCountnumberrequiredMembers of this organisation holding the role
Code samples
curl -X POST "$KONNECT_API_URL/organisations/id/roles" \
-H "Cookie: konnect_session=$KONNECT_SESSION" \
-H "Content-Type: application/json" \
-d '{
"name": "Statistics only",
"description": "description",
"permissions": [
"payments.view"
],
"basedOnRoleId": "basedOnRoleId"
}'Example: request body
{
"name": "Statistics only",
"description": "description",
"permissions": [
"payments.view"
],
"basedOnRoleId": "basedOnRoleId"
}Example: 201
{
"id": "id",
"key": "key",
"name": "name",
"description": "description",
"predefined": true,
"permissions": [
"payments.view"
],
"memberCount": 1
}Edit a custom role (predefined roles are fixed)
PATCH/organisations/{id}/roles/{roleId}Dashboard session
Parameters
idstringpathrequiredroleIdstringpathrequired
Request body application/json
namestringdescriptionstringpermissionsstring[]
Responses
200
idstring (uuid)requiredkeystring | nullrequiredPredefined role key, null for custom
namestringrequireddescriptionstring | nullrequiredpredefinedbooleanrequiredpermissionsstring[]requiredmemberCountnumberrequiredMembers of this organisation holding the role
Code samples
curl -X PATCH "$KONNECT_API_URL/organisations/id/roles/roleId" \
-H "Cookie: konnect_session=$KONNECT_SESSION" \
-H "Content-Type: application/json" \
-d '{
"name": "name",
"description": "description",
"permissions": [
"payments.view"
]
}'Example: request body
{
"name": "name",
"description": "description",
"permissions": [
"payments.view"
]
}Example: 200
{
"id": "id",
"key": "key",
"name": "name",
"description": "description",
"predefined": true,
"permissions": [
"payments.view"
],
"memberCount": 1
}Delete a custom role that no member or pending invitation uses
DELETE/organisations/{id}/roles/{roleId}Dashboard session
Parameters
idstringpathrequiredroleIdstringpathrequired
Responses
204
Code samples
curl -X DELETE "$KONNECT_API_URL/organisations/id/roles/roleId" \
-H "Cookie: konnect_session=$KONNECT_SESSION"The pending ownership transfer, if any
GET/organisations/{id}/ownership-transferDashboard session
Parameters
idstringpathrequired
Responses
200
idstring (uuid)requiredorganisationIdstring (uuid)requiredfromUserIdstring (uuid)requiredtoUserIdstring (uuid)requiredstatusstringrequired- enum: "pending", "accepted", "cancelled"
expiresAtstring (date-time)requireddecidedAtstring (date-time) | nullrequiredcreatedAtstring (date-time)required
Code samples
curl -X GET "$KONNECT_API_URL/organisations/id/ownership-transfer" \
-H "Cookie: konnect_session=$KONNECT_SESSION"Example: 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"fromUserId": "fromUserId",
"toUserId": "toUserId",
"status": "pending",
"expiresAt": "2026-10-01T09:30:00.000Z",
"decidedAt": "2026-10-01T09:30:00.000Z",
"createdAt": "2026-10-01T09:30:00.000Z"
}Owner only: offer ownership to a member (requires re-authentication)
POST/organisations/{id}/ownership-transferDashboard session
Parameters
idstringpathrequired
Request body application/json
toUserIdstring (uuid)requiredA current member of the organisation
Responses
201
idstring (uuid)requiredorganisationIdstring (uuid)requiredfromUserIdstring (uuid)requiredtoUserIdstring (uuid)requiredstatusstringrequired- enum: "pending", "accepted", "cancelled"
expiresAtstring (date-time)requireddecidedAtstring (date-time) | nullrequiredcreatedAtstring (date-time)required
Code samples
curl -X POST "$KONNECT_API_URL/organisations/id/ownership-transfer" \
-H "Cookie: konnect_session=$KONNECT_SESSION" \
-H "Content-Type: application/json" \
-d '{
"toUserId": "toUserId"
}'Example: request body
{
"toUserId": "toUserId"
}Example: 201
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"fromUserId": "fromUserId",
"toUserId": "toUserId",
"status": "pending",
"expiresAt": "2026-10-01T09:30:00.000Z",
"decidedAt": "2026-10-01T09:30:00.000Z",
"createdAt": "2026-10-01T09:30:00.000Z"
}The new owner accepts; the former owner becomes Administrator
POST/organisations/{id}/ownership-transfer/{transferId}/acceptDashboard session
Parameters
idstringpathrequiredtransferIdstringpathrequired
Responses
200
idstring (uuid)requiredorganisationIdstring (uuid)requiredfromUserIdstring (uuid)requiredtoUserIdstring (uuid)requiredstatusstringrequired- enum: "pending", "accepted", "cancelled"
expiresAtstring (date-time)requireddecidedAtstring (date-time) | nullrequiredcreatedAtstring (date-time)required
Code samples
curl -X POST "$KONNECT_API_URL/organisations/id/ownership-transfer/transferId/accept" \
-H "Cookie: konnect_session=$KONNECT_SESSION"Example: 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"fromUserId": "fromUserId",
"toUserId": "toUserId",
"status": "pending",
"expiresAt": "2026-10-01T09:30:00.000Z",
"decidedAt": "2026-10-01T09:30:00.000Z",
"createdAt": "2026-10-01T09:30:00.000Z"
}The owner withdraws, or the recipient declines, a pending transfer
DELETE/organisations/{id}/ownership-transfer/{transferId}Dashboard session
Parameters
idstringpathrequiredtransferIdstringpathrequired
Responses
200
idstring (uuid)requiredorganisationIdstring (uuid)requiredfromUserIdstring (uuid)requiredtoUserIdstring (uuid)requiredstatusstringrequired- enum: "pending", "accepted", "cancelled"
expiresAtstring (date-time)requireddecidedAtstring (date-time) | nullrequiredcreatedAtstring (date-time)required
Code samples
curl -X DELETE "$KONNECT_API_URL/organisations/id/ownership-transfer/transferId" \
-H "Cookie: konnect_session=$KONNECT_SESSION"Example: 200
{
"id": "id",
"organisationId": "org_01J9Z3K4EXAMPLE0000000000",
"fromUserId": "fromUserId",
"toUserId": "toUserId",
"status": "pending",
"expiresAt": "2026-10-01T09:30:00.000Z",
"decidedAt": "2026-10-01T09:30:00.000Z",
"createdAt": "2026-10-01T09:30:00.000Z"
}