organization-members

Deactivate an organization member

Changed on

Deactivate a member (set is_active=False).

Guards:

  • Cannot deactivate own membership (self-lockout prevention).
  • Cannot deactivate the last active admin (org lockout prevention).

Idempotency: deactivating an already-inactive member is a no-op success.

post/organization-members/{user_id}/deactivate/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

user_idstring required

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Request body

user_idinteger required
organization_idinteger required
permissionsstring[] required

Capabilities this membership confers in this organization, as app_label.codename strings (for example organizations.manage_members). Resolved from the membership's groups and direct grants -- the same source every server-side authorization check reads -- so a client can gate UI on the exact string the API will enforce. Only organization-scoped capabilities appear: a global Django permission or superuser status grants nothing here, because it grants nothing in this organization either. An inactive membership resolves an empty list. The set of possible values grows over time; treat an unrecognised entry as an unknown capability rather than an error.

is_activeboolean required

Whether this membership is active. Inactive memberships are treated as gated: the user still has a row but loses all tenant-scoped access until reactivated. Use this to disable a user without deleting their membership record (which would lose their groups and history). Default True keeps every existing read unchanged.

user_emailstring email required
user_first_namestring required
user_last_namestring required

Response

user_idinteger required
organization_idinteger required
permissionsstring[] required

Capabilities this membership confers in this organization, as app_label.codename strings (for example organizations.manage_members). Resolved from the membership's groups and direct grants -- the same source every server-side authorization check reads -- so a client can gate UI on the exact string the API will enforce. Only organization-scoped capabilities appear: a global Django permission or superuser status grants nothing here, because it grants nothing in this organization either. An inactive membership resolves an empty list. The set of possible values grows over time; treat an unrecognised entry as an unknown capability rather than an error.

is_activeboolean required

Whether this membership is active. Inactive memberships are treated as gated: the user still has a row but loses all tenant-scoped access until reactivated. Use this to disable a user without deleting their membership record (which would lose their groups and history). Default True keeps every existing read unchanged.

user_emailstring email required
user_first_namestring required
user_last_namestring required

Changes

    • ▲

      removed the required property from the response with the status

    • ○

      added the required property to the response with the status