organizations

List the authenticated user's active organization memberships

Changed on

Return all active memberships for the authenticated caller.

Designed for the frontend org switcher: the client calls this endpoint before it knows which X-Organization-Id to send, so no header is required. The response is always HTTP 200; gated users receive an empty list ([]).

get/organizations/mine/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Response

permissionsstring[] required

Capabilities this membership confers in this organization, as app_label.codename strings (for example organizations.manage_members). Resolved from the membership's groups and direct grants -- the same source every server-side authorization check reads -- so a client can gate UI on the exact string the API will enforce. Only organization-scoped capabilities appear: a global Django permission or superuser status grants nothing here, because it grants nothing in this organization either. An inactive membership resolves an empty list. The set of possible values grows over time; treat an unrecognised entry as an unknown capability rather than an error.

can_manage_brandingboolean required

Whether this membership can manage branding: its organizations.manage_branding capability plus the parentless, entitled organization gate -- see CurrentMembershipSerializer.get_can_manage_branding for the full rationale. Computed per membership, so a permitted member and an unpermitted member in the same eligible organization receive different values.

Reads from the batch _MyMembershipListSerializer precomputes on the shared context when serializing a list (the many=True path this serializer is actually used on). Falls back to the single-organization is_branding_eligible_organization call when there is no such batch in context (e.g. this serializer instantiated directly against one membership), which is exactly what the batch entry would have computed for that one organization anyway.

Changes

    • ▲

      removed the required property / from the response with the status

    • ○

      the ////// response's property pattern ^[-a-zA-Z0-9_]+$ was removed for the status

    • ○

      added the required property / to the response with the status

    • ○

      added the required property / to the response with the status

    • ○

      added the required property ////// to the response with the status