Aiven Application_Users API

The Application_Users API from Aiven — 4 operation(s) for application_users.

Operations 8

POST /organization/{organization_id}/application-users/{user_id}/access-tokens Create an application token #
GET /organization/{organization_id}/application-users/{user_id}/access-tokens List application tokens #
DELETE /organization/{organization_id}/application-users/{user_id}/access-tokens/{token_prefix} Delete an application token #
POST /organization/{organization_id}/application-users Create an application user #
GET /organization/{organization_id}/application-users List application users #
DELETE /organization/{organization_id}/application-users/{user_id} Delete an application user #
GET /organization/{organization_id}/application-users/{user_id} Get an application user #
PATCH /organization/{organization_id}/application-users/{user_id} Update details on an application user of the organization #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/aiven-application-users-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

aiven-application-users-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: support@aiven.io
    name: Aiven support team
    url: https://aiven.io/support-services
  title: Aiven API Documentation Application Users API
  version: v1
  x-logo:
    altText: Aiven logo
    backgroundColor: '#fafafa'
    href: https://api.aiven.io/doc
    url: https://aiven.io/assets/img/aiven-logo.png
  description: '# Introduction


    Direct link to openapi.json for use with external tools


    Aiven is a modern fully-managed open source data platform for streaming, storing, and analyzing data on any public cloud.'
servers:
- url: https://api.aiven.io/v1
tags:
- name: Application Users
  x-displayName: Application Users
paths:
  /organization/{organization_id}/application-users/{user_id}/access-tokens:
    post:
      summary: Create an application token
      tags:
      - Application Users
      operationId: ApplicationUserAccessTokenCreate
      description: Creates a token for an application user.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      - $ref: '#/components/parameters/user_id'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationUserAccessTokenCreateRequestBody'
            example:
              description: Integration client Alpha
              extend_when_used: false
              ip_allowlist:
              - 192.168.0.0/24
              - 2001:db8::/32
              max_age_seconds: 86400
              scopes:
              - user:read
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationUserAccessTokenCreateResponse'
      security:
      - tokenAuth: []
        oauth2:
        - accounts:write
        - authentication:write
    get:
      summary: List application tokens
      tags:
      - Application Users
      operationId: ApplicationUserAccessTokensList
      description: Returns a list of tokens for an application user.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      - $ref: '#/components/parameters/user_id'
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationUserAccessTokensListResponse'
      security:
      - tokenAuth: []
        oauth2:
        - accounts:read
        - authentication:read
  /organization/{organization_id}/application-users/{user_id}/access-tokens/{token_prefix}:
    delete:
      summary: Delete an application token
      tags:
      - Application Users
      operationId: ApplicationUserAccessTokenDelete
      description: Deletes an application user's token.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      - $ref: '#/components/parameters/user_id'
      - $ref: '#/components/parameters/token_prefix'
      responses:
        '204':
          description: Delete an application token
          content: {}
      security:
      - tokenAuth: []
        oauth2:
        - accounts:write
        - authentication:write
  /organization/{organization_id}/application-users:
    post:
      summary: Create an application user
      tags:
      - Application Users
      operationId: ApplicationUserCreate
      description: Creates an application user in an organization.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationUserCreateRequestBody'
            example:
              is_super_admin: true
              name: devops app user
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationUserCreateResponse'
      security:
      - tokenAuth: []
        oauth2:
        - accounts:write
        - authentication:write
    get:
      summary: List application users
      tags:
      - Application Users
      operationId: ApplicationUsersList
      description: Returns a list of application users for an organization.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationUsersListResponse'
      security:
      - tokenAuth: []
        oauth2:
        - accounts:read
        - authentication:read
  /organization/{organization_id}/application-users/{user_id}:
    delete:
      summary: Delete an application user
      tags:
      - Application Users
      operationId: ApplicationUserDelete
      description: Deletes an application user.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      - $ref: '#/components/parameters/user_id'
      responses:
        '204':
          description: Delete an application user
          content: {}
      security:
      - tokenAuth: []
        oauth2:
        - accounts:write
        - authentication:write
    get:
      summary: Get an application user
      tags:
      - Application Users
      operationId: ApplicationUserGet
      description: Gets profile information for an application user.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      - $ref: '#/components/parameters/user_id'
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationUserGetResponse'
        '404':
          description: Resource not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    title: Human readable error message
                  errors:
                    type: array
                    title: List of error details. Typically there is only one element
                    items:
                      type: object
                      properties:
                        message:
                          type: string
                          title: Human readable error message
                        error_code:
                          type: string
                          enum:
                          - organization_not_found
                          - organization_user_not_found
                          title: Machine processable error code. Clients must be prepared to handle new codes.
                          description: 'organization_not_found: Organization not found.. organization_user_not_found: User not in organization'
        '403':
          description: Operation not allowed
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    title: Human readable error message
                  errors:
                    type: array
                    title: List of error details. Typically there is only one element
                    items:
                      type: object
                      properties:
                        message:
                          type: string
                          title: Human readable error message
                        error_code:
                          type: string
                          enum:
                          - user_is_internal_user
                          title: Machine processable error code. Clients must be prepared to handle new codes.
                          description: 'user_is_internal_user: User is internal'
        '400':
          description: Invalid request parameters
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    title: Human readable error message
                  errors:
                    type: array
                    title: List of error details. Typically there is only one element
                    items:
                      type: object
                      properties:
                        message:
                          type: string
                          title: Human readable error message
                        error_code:
                          type: string
                          enum:
                          - user_not_application_user
                          title: Machine processable error code. Clients must be prepared to handle new codes.
                          description: 'user_not_application_user: User is not an application user'
      security:
      - tokenAuth: []
        oauth2:
        - accounts:read
        - authentication:read
    patch:
      summary: Update details on an application user of the organization
      tags:
      - Application Users
      operationId: ApplicationUserUpdate
      description: Update details on an application user of the organization.
      parameters:
      - $ref: '#/components/parameters/organization_id'
      - $ref: '#/components/parameters/user_id'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationUserUpdateRequestBody'
            example:
              is_super_admin: true
              name: devops app user
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationUserUpdateResponse'
        '404':
          description: Resource not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    title: Human readable error message
                  errors:
                    type: array
                    title: List of error details. Typically there is only one element
                    items:
                      type: object
                      properties:
                        message:
                          type: string
                          title: Human readable error message
                        error_code:
                          type: string
                          enum:
                          - organization_not_found
                          - organization_user_not_found
                          title: Machine processable error code. Clients must be prepared to handle new codes.
                          description: 'organization_not_found: Organization not found.. organization_user_not_found: User not in organization'
        '403':
          description: Operation not allowed
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    title: Human readable error message
                  errors:
                    type: array
                    title: List of error details. Typically there is only one element
                    items:
                      type: object
                      properties:
                        message:
                          type: string
                          title: Human readable error message
                        error_code:
                          type: string
                          enum:
                          - user_is_internal_user
                          title: Machine processable error code. Clients must be prepared to handle new codes.
                          description: 'user_is_internal_user: User is internal'
        '400':
          description: Invalid request parameters
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    title: Human readable error message
                  errors:
                    type: array
                    title: List of error details. Typically there is only one element
                    items:
                      type: object
                      properties:
                        message:
                          type: string
                          title: Human readable error message
                        error_code:
                          type: string
                          enum:
                          - user_not_application_user
                          title: Machine processable error code. Clients must be prepared to handle new codes.
                          description: 'user_not_application_user: User is not an application user'
      security:
      - tokenAuth: []
        oauth2:
        - accounts:write
components:
  schemas:
    ApplicationUserGetResponse:
      type: object
      description: ApplicationUserGetResponse
      properties:
        create_time:
          type: string
          maxLength: 36
          description: Time this application user was created
        is_super_admin:
          type: boolean
          description: Super admin state of the organization application user
        name:
          type: string
          description: Name
        user_email:
          type: string
          maxLength: 254
          description: User Email
        user_id:
          type: string
          description: User ID
      required:
      - create_time
      - is_super_admin
      - name
      - user_email
      - user_id
    ApplicationUsersListResponse:
      type: object
      description: ApplicationUsersListResponse
      properties:
        application_users:
          type: array
          description: Application Users
          items:
            type: object
            properties:
              create_time:
                type: string
                maxLength: 36
                description: Time this application user was created
              is_super_admin:
                type: boolean
                description: Super admin state of the organization application user
              name:
                type: string
                description: Name
              user_email:
                type: string
                maxLength: 254
                description: User Email
              user_id:
                type: string
                description: User ID
            required:
            - create_time
            - is_super_admin
            - name
            - user_email
            - user_id
      required:
      - application_users
    ApplicationUserCreateRequestBody:
      type: object
      description: ApplicationUserCreateRequestBody
      properties:
        is_super_admin:
          type: boolean
          description: Alters super admin state of the organization application user
        name:
          type: string
          description: Name
      required:
      - name
    ApplicationUserCreateResponse:
      type: object
      description: ApplicationUserCreateResponse
      properties:
        create_time:
          type: string
          maxLength: 36
          description: Time this application user was created
        is_super_admin:
          type: boolean
          description: Super admin state of the organization application user
        name:
          type: string
          description: Name
        user_email:
          type: string
          maxLength: 254
          description: User Email
        user_id:
          type: string
          description: User ID
      required:
      - create_time
      - is_super_admin
      - name
      - user_email
      - user_id
    ApplicationUserAccessTokensListResponse:
      type: object
      description: ApplicationUserAccessTokensListResponse
      properties:
        tokens:
          type: array
          description: Tokens
          items:
            type: object
            properties:
              create_time:
                type: string
                maxLength: 36
                description: Create Time
              created_manually:
                type: boolean
                description: True for tokens explicitly created via the access_tokens API, false for tokens created via login.
              currently_active:
                type: boolean
                description: true if API request was made with this access token
              description:
                type: string
                maxLength: 1000
                description: Description
              expiry_time:
                type: string
                maxLength: 36
                description: Timestamp when the access token will expire unless extended, if ever
              extend_when_used:
                type: boolean
                description: Extend token expiration time when token is used. Only applicable if max_age_seconds is specified.
                default: false
              ip_allowlist:
                type: array
                maxItems: 100
                description: List of allowed IP ranges
                items:
                  type: string
              last_ip:
                type: string
                description: IP address the access token was last used from in case it has ever been used
              last_used_time:
                type: string
                maxLength: 36
                description: Timestamp when the access token was last used, if ever
              last_user_agent:
                type: string
                description: User agent string of the client that last used the token in case it has ever been used
              last_user_agent_human_readable:
                type: string
                description: Human readable user agent string of the client that last used the token in case user agent is known
              max_age_seconds:
                type: integer
                minimum: 600
                maximum: 315360000
                description: Time the token remains valid since creation (or since last use if extend_when_used is true)
              scopes:
                type: array
                maxItems: 100
                description: Scopes this token is restricted to if specified
                items:
                  type: string
              token_prefix:
                type: string
                description: First characters of the actual token value. Full value is only exposed after creation. This value is used when updating or revoking tokens. Note that the value may contain /, + and = characters and must be URL encoded when used (/ => %2F, + => %2B, = => %3D).
            required:
            - create_time
            - created_manually
            - currently_active
            - token_prefix
      required:
      - tokens
    ApplicationUserAccessTokenCreateRequestBody:
      type: object
      description: ApplicationUserAccessTokenCreateRequestBody
      properties:
        description:
          type: string
          maxLength: 1000
          description: Description
        extend_when_used:
          type: boolean
          description: Extend token expiration time when token is used. Only applicable if max_age_seconds is specified.
          default: false
        ip_allowlist:
          type: array
          maxItems: 100
          description: List of allowed IP ranges
          items:
            type: string
        max_age_seconds:
          type: integer
          minimum: 600
          maximum: 315360000
          description: Time the token remains valid since creation (or since last use if extend_when_used is true)
        scopes:
          type: array
          maxItems: 100
          description: Scopes this token is restricted to if specified
          items:
            type: string
      required:
      - description
    ApplicationUserUpdateRequestBody:
      type: object
      description: ApplicationUserUpdateRequestBody
      properties:
        is_super_admin:
          type: boolean
          description: Alters super admin state of the organization application user
        name:
          type: string
          description: Name
      required:
      - name
    ApplicationUserUpdateResponse:
      type: object
      description: ApplicationUserUpdateResponse
      properties:
        create_time:
          type: string
          maxLength: 36
          description: Time this application user was created
        is_super_admin:
          type: boolean
          description: Super admin state of the organization application user
        name:
          type: string
          description: Name
        user_email:
          type: string
          maxLength: 254
          description: User Email
        user_id:
          type: string
          description: User ID
      required:
      - create_time
      - is_super_admin
      - name
      - user_email
      - user_id
    ApplicationUserAccessTokenCreateResponse:
      type: object
      description: ApplicationUserAccessTokenCreateResponse
      properties:
        full_token:
          type: string
          description: Full Token
        token_prefix:
          type: string
          description: Token Prefix
      required:
      - full_token
      - token_prefix
  parameters:
    token_prefix:
      in: path
      name: token_prefix
      description: Access token prefix
      schema:
        type: string
      required: true
    user_id:
      in: path
      name: user_id
      description: User ID
      schema:
        type: string
      required: true
    organization_id:
      in: path
      name: organization_id
      description: ID of an organization
      schema:
        type: string
      required: true
  securitySchemes:
    tokenAuth:
      description: 'Header should be of the format `authorization: aivenv1 <TOKEN>`. Tokens can be obtained from [your Aiven profile page](https://console.aiven.io/profile/auth)'
      scheme: bearer
      type: http
    oauth2:
      type: oauth2
      description: OAuth2 security scheme
      flows:
        authorizationCode:
          authorizationUrl: https://console.aiven.io/oauth/authorize
          tokenUrl: https://api.aiven.io/v1/oauth2/token
          scopes:
            all: Provide full access to the API
            accounts: Allow enumerating and reading accounts configuration
            accounts:read: Allow modifying account configuration
            accounts:write: Provides full access to authentication related API
            authentication: Provides full access to authentication related API
            authentication:read: Allow reading authentication related configuration on resources (user profile, accounts)
            authentication:write: Allow modifying authentication related configurations on resources (user profile, accounts)
            billing: Provide full access to billing APIs
            billing:read: Allow reading billing information and configuration
            billing:write: Allow writing billing configuration
            payments: Provide full access to payment method APIs
            payments:read: Allow reading the payment method configurations
            payments:write: Allows writing payment method configuration
            privatelink: Provide full access to private link APIs
            privatelink:read: Allow enumerating and reading private link items and configurations
            privatelink:write: Allow writing (creating, modifying, deleting) private link items
            projects: Provide full access to projects APIs
            projects:read: Allow enumerating projects and reading their configuration
            projects:write: Allow writing (creating, modifying, deleting) projects
            scim: Provide full access to SCIM operations
            scim:read: Allow reading SCIM endpoints
            scim:write: Allow writing (modifying) SCIM endpoints
            services: Provide full access to services APIs
            services:read: Allow enumerating services and reading their configuration
            services:write: Allow writing (creating, modifying, deleting) services
            static_ips: Provide full access to static IPs APIs
            static_ips:read: Allow enumerating and reading static IP items and configurations
            static_ips:write: Allow writing (creating, modifying, deleting) static IP items
            tickets: Provide full access to support ticket APIs
            tickets:read: Allow enumerating and reading support tickets
            tickets:write: Allow writing (creating, modifying) support tickets
            user: Provide full access to user profile APIs
            user:read: Allow reading user profile and configuration
            user:write: Allow writing (modifying) user profile and configuration
externalDocs:
  description: Aiven CLI client
  url: https://github.com/aiven/aiven-client