organization-members

A viewset for listing, retrieving, and managing organization members.

Admin-only endpoint — lists both active and inactive members of the caller's organization, suitable for a datatable view. Non-admin members get 403.

Actions:

  • deactivate: POST to disable a member (prevent self-deactivation and protect the last active admin).
  • reactivate: POST to re-enable a member.
  • groups: POST to set a member's groups, and with them their capabilities (protects the last member who can manage members).
get/organization-members/{user_id}{format}

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

format'.json' required
user_idstring required

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Response

user_idinteger required
organization_idinteger required
permissionsstring[] required

Capabilities this membership confers in this organization, as app_label.codename strings (for example organizations.manage_members). Resolved from the membership's groups and direct grants -- the same source every server-side authorization check reads -- so a client can gate UI on the exact string the API will enforce. Only organization-scoped capabilities appear: a global Django permission or superuser status grants nothing here, because it grants nothing in this organization either. An inactive membership resolves an empty list. The set of possible values grows over time; treat an unrecognised entry as an unknown capability rather than an error.

is_activeboolean required

Whether this membership is active. Inactive memberships are treated as gated: the user still has a row but loses all tenant-scoped access until reactivated. Use this to disable a user without deleting their membership record (which would lose their groups and history). Default True keeps every existing read unchanged.

user_emailstring email required
user_first_namestring required
user_last_namestring required

Changes

    • ▲

      removed the required property from the response with the status

    • ○

      added the required property to the response with the status