Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
title: Avalara AvaTax Users API
description: Welcome to the AvaTax API Postman Collection!
version: 1.0.0
servers:
- url: http://{{baseurl}}
security:
- basicAuth: []
tags:
- name: Users
paths:
/api/v2/passwords:
put:
tags:
- Users
summary: Avalara ChangePassword
description: 'Allows a user to change their password via an API call.
This API allows an authenticated user to change their password via an API call. This feature is only available
for accounts that do not use SAML integrated password validation.
This API only allows the currently authenticated user to change their password; it cannot be used to apply to a
different user than the one authenticating the current API call.
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPTester, FirmAdmin, FirmUser, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
requestBody:
content:
application/json:
schema:
type: object
example:
oldPassword: MyOldPassword123!
newPassword: ANewPassword567:)
parameters:
- name: Content-Type
in: header
schema:
type: string
example: application/json
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: putApiV2Passwords
x-operation-id-source: derived
/api/v2/accounts/{accountId}/users:
post:
tags:
- Users
summary: Avalara CreateUsers
description: 'Create one or more new user objects attached to this account.
A user represents one person with access privileges to make API calls and work with a specific account.
Users who are account administrators or company users are permitted to create user records to invite
additional team members to work with AvaTax.
A newly created user will receive an email inviting them to create their password. This means that you
must provide a valid email address for all user accounts created.
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPTester, FirmAdmin, FirmUser, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
requestBody:
content:
application/json:
schema:
type: object
example:
id: 12345
accountId: 123456789
companyId: 123456
userName: bobExample
firstName: Bob
lastName: Example
email: bob@example.org
postalCode: '98110'
securityRoleId: AccountUser
passwordStatus: UserCanChange
isActive: true
suppressNewUserEmail: false
parameters:
- name: Content-Type
in: header
schema:
type: string
example: application/json
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
- name: accountId
in: path
schema:
type: string
required: true
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: postApiV2AccountsByAccountIdUsers
x-operation-id-source: derived
get:
tags:
- Users
summary: Avalara ListUsersByAccount
description: 'List all user objects attached to this account.
A user represents one person with access privileges to make API calls and work with a specific account.
When an API is called using a legacy AvaTax License Key, the API log entry is recorded as being performed by a special user attached to that license key.
By default, this API will not return a listing of license key users. Users with registrar-level security may call this API to list license key users.
Search for specific objects using the criteria in the `$filter` parameter; full documentation is available on Filtering in REST .
Paginate your results using the `$top`, `$skip`, and `$orderby` parameters.
You may specify one or more of the following values in the `$include` parameter to fetch additional nested data, using commas to separate multiple values:
* FetchDeleted
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
parameters:
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
- name: accountId
in: path
schema:
type: string
required: true
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: getApiV2AccountsByAccountIdUsers
x-operation-id-source: derived
/api/v2/accounts/{accountId}/users/{id}:
delete:
tags:
- Users
summary: Avalara DeleteUser
description: 'Mark the user object identified by this URL as deleted.
This API is available for use by account and company administrators only.
Account and company administrators may only delete users within the appropriate organizations
they control.
### Security Policies
* This API requires one of the following user roles: AccountAdmin, BatchServiceAdmin, CompanyAdmin, Compliance Root User, CSPTester, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TreasuryAdmin.'
parameters:
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
- name: accountId
in: path
schema:
type: string
required: true
- name: id
in: path
schema:
type: string
required: true
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: deleteApiV2AccountsByAccountIdUsersById
x-operation-id-source: derived
get:
tags:
- Users
summary: Avalara GetUser
description: 'Get the user object identified by this URL.
A user represents one person with access privileges to make API calls and work with a specific account.
You may specify one or more of the following values in the `$include` parameter to fetch additional nested data, using commas to separate multiple values:
* FetchDeleted
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
parameters:
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
- name: accountId
in: path
schema:
type: string
required: true
- name: id
in: path
schema:
type: string
required: true
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: getApiV2AccountsByAccountIdUsersById
x-operation-id-source: derived
put:
tags:
- Users
summary: Avalara UpdateUser
description: 'Replace the existing user object at this URL with an updated object.
A user represents one person with access privileges to make API calls and work with a specific account.
All data from the existing object will be replaced with data in the object you PUT.
To set a field''s value to null, you may either set its value to null or omit that field from the object you post.
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPTester, FirmAdmin, FirmUser, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
requestBody:
content:
application/json:
schema:
type: object
example:
id: 12345
accountId: 123456789
companyId: 123456
userName: bobExample
firstName: Bob
lastName: Example
email: bob@example.org
postalCode: '98110'
securityRoleId: AccountUser
passwordStatus: UserCanChange
isActive: true
suppressNewUserEmail: false
parameters:
- name: Content-Type
in: header
schema:
type: string
example: application/json
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
- name: accountId
in: path
schema:
type: string
required: true
- name: id
in: path
schema:
type: string
required: true
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: putApiV2AccountsByAccountIdUsersById
x-operation-id-source: derived
/api/v2/accounts/{accountId}/users/{id}/entitlements:
get:
tags:
- Users
summary: Avalara GetUserEntitlements
description: 'Return a list of all entitlements to which this user has rights to access.
Entitlements are a list of specified API calls the user is permitted to make, a list of identifier numbers for companies the user is
allowed to use, and an access level identifier that indicates what types of access roles the user is allowed to use.
This API call is intended to provide a validation endpoint to determine, before making an API call, whether this call is likely to succeed.
For example, if user 567 within account 999 is attempting to create a new child company underneath company 12345, you could preview the user''s
entitlements and predict whether this call would succeed:
* Retrieve entitlements by calling ''/api/v2/accounts/999/users/567/entitlements'' . If the call fails, you do not have accurate
credentials for this user.
* If the ''accessLevel'' field within entitlements is ''None'', the call will fail.
* If the ''accessLevel'' field within entitlements is ''SingleCompany'' or ''SingleAccount'', the call will fail if the companies
table does not contain the ID number 12345.
* If the ''permissions'' array within entitlements does not contain ''AccountSvc.CompanySave'', the call will fail.
For a full list of defined permissions, please use ''/api/v2/definitions/permissions'' .
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
parameters:
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
- name: accountId
in: path
schema:
type: string
required: true
- name: id
in: path
schema:
type: string
required: true
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: getApiV2AccountsByAccountIdUsersByIdEntitlements
x-operation-id-source: derived
/api/v2/users:
get:
tags:
- Users
summary: Avalara QueryUsers
description: 'Get multiple user objects across all accounts.
A user represents one person or set of credentials with access privileges to make API calls and work with a specific account. A user can be authenticated
via either username / password authentication, an OpenID / OAuth Bearer Token, or a legacy AvaTax License Key.
When an API is called using a legacy AvaTax License Key, the API log entry is recorded as being performed by a special user attached to that license key.
By default, this API will not return a listing of license key users. Users with registrar-level security may call this API to list license key users.
Search for specific objects using the criteria in the `$filter` parameter; full documentation is available on Filtering in REST .
Paginate your results using the `$top`, `$skip`, and `$orderby` parameters.
You may specify one or more of the following values in the `$include` parameter to fetch additional nested data, using commas to separate multiple values:
* FetchDeleted
### Security Policies
* This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
parameters:
- name: X-Avalara-Client
in: header
schema:
type: string
description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
example: AvaTax Postman Collection
responses:
'200':
description: Successful response
content:
application/json: {}
operationId: getApiV2Users
x-operation-id-source: derived
components:
securitySchemes:
basicAuth:
type: http
scheme: basic