Groups

Create group

Creates a group in the zone (managed in Keycard). Groups synced from an external directory are created by that directory, not here.

post/zones/{zoneId}/groups

Path parameters

zoneIdstring required

Zone ID

Request body

namestring safe-text required

Human-readable group name

identifierstring safe-text

User-specified identifier, unique within the zone. Derived from the name when omitted (a suffix is appended if it collides).

Response

A zone-scoped group of users, assignable to roles and usable in policies. Roles assigned to a group are inherited by its members. external is false for groups managed in Keycard and true for groups synced from an external directory.

idstring required

Unique identifier of the group

zone_idstring required

Zone this group belongs to

organization_idstring required

Organization this group belongs to

identifierstring required

User-specified identifier, unique within the zone. Automatically assigned for groups from an external directory.

namestring required

Human-readable group name

externalboolean required

Whether the group is synced from an external directory. When true the group is directory-owned and its membership is read-only; when false it is managed in Keycard. Read-only: set by external sync, never by the caller.

member_countinteger

Number of users in the group. Included only when requested via expand[]=member_count (group get or list).

rolesstring[]

Identifiers of the roles assigned to the group; members inherit them. Deduped across scopes. Included only when requested via expand[]=roles (group get or list).

created_atstring date-time required

Entity creation timestamp

updated_atstring date-time required

Entity update timestamp

Changes