Bridgit AccountUsers API

The AccountUsers API from Bridgit — 4 operation(s) for accountusers.

OpenAPI Specification

bridgit-accountusers-api-openapi.yml Raw ↑
openapi: 3.0.4
info:
  title: Bench AccountActivities AccountUsers API
  description: "<h2>Versioning</h2>\n<p>\n    The API is currently at version <code>1.0</code>. All API endpoints (other than\n    authentication) require you to specify the API version as part of the path.\n</p>\n\n<h2>URL Paths</h2>\n<p>\n    Authentication requests should be made to <code>/auth/signin</code>,\n    as documented below. All other API requests should be made to\n    sub-paths of <code>/rp/api/1.0/...</code>.\n</p>\n\n<h2>Authentication</h2>\n<p>\n    API requests are authenticated using an OAuth Bearer token.\n    You can get a token by authenticating your user by sending a\n    POST request to <code>/auth/signin</code>, with \"username and \"password\"\n    parameters form-encoded in the body of the request.\n\n    POST /auth/signin HTTP/1.1\n    Content-Type: application/x-www-form-urlencoded\n\n    username=user@example.com&password=some-secret-password\n</p>\n<p>\n    The response will be a JSON object including both\n    <b>\"access_token\"</b> and <b>\"refresh_token\"</b> property.\n    All other requests against the Bench API should include an\n    authorization header: <code>Authorization: Bearer xxxYYYzzz</code>,\n    where <b>xxxYYYzzz</b> is the value of <b>\"access_token\"</b> in the response.\n    <br><br>\n    For example:\n\n    $ curl https://bench.gobridgit.com/auth/signin -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=someone@example.com' --data-urlencode 'password=[...snip...]'\n    {\n        \"access_token\": \"...snip...\",\n        \"token_type\": \"Bearer\",\n        \"refresh_token\": \"...snip...\"\n        \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n    }\n\n</p>\n\n<p>\n    The refresh token can be used to generate new session by request with <code>/auth/token</code> endpoint:\n\n    POST /auth/token HTTP/1.1\n    Content-Type: application/x-www-form-urlencoded\n\n    grant_type=refresh_token&refresh_token=tGzv3JOkF0XG5Qx2TlKWIA\n</p>\n<p>\n    Note that once the refresh token is used, the previous access and refresh token is no longer valid.\n    <br><br>\n    For example:\n\n    $ curl https://bench.gobridgit.com/auth/token -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'grant_type=refresh_token' --data-urlencode 'refresh_token=[...snip...]'\n    {\n        \"access_token\": \"...snip...\",\n        \"token_type\": \"Bearer\",\n        \"refresh_token\": \"...snip...\"\n        \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n    }\n</p>\n\n<h2>Pagination</h2>\n<p>\n    Several of the API endpoints are paginated. These are denoted by\n    including the <code>offset</code> (zero-based offset) and <code>limit</code> query\n    parameters. For example, to request the <code>10</code> items,\n    set the <code>offset=0</code> to <code>limit=10</code>.\n    <br>\n    NOTE: the result set contains items with index of 0-9\n    <br>\n    To request the next 10 items (starting at index 10),\n    set the <code>offset=10</code> to <code>limit=10</code>\n</p>\n<p>\n    Responses to paginated API endpoints return a JSON array of objects.\n    If there are results beyond the page you have requested, the server\n    will set a <code>query-has-more: true</code> header in the response.\n</p>\n\n<h2>Request Encoding</h2>\n<p>\n    <code>GET</code> and <code>DELETE</code> requests should have parameters encoded as URL query\n    parameters. Boolean values should be encoded as <code>true</code> and\n    <code>false</code>, not as <code>1</code> and <code>0</code>.\n</p>\n\n<h2>Errors</h2>\n<p>\n    Errors are returned for some response codes such as <code>400 Bad Request</code> in the\n    following format:\n\n    {\n      \"errors\": [\n        {\n          \"errorType\": \"ValidationError\",\n          \"description\": \"The value of Name must be a string with a minimum length of 1 and a maximum length of 8 and not whitespace.\",\n          \"field\": \"Name\",\n          \"values\": [\n            null\n          ]\n        }\n      ],\n      \"title\": \"One or more validation errors occurred.\",\n      \"status\": 400,\n      \"instance\": \"api/v1/accounts/0/persons\",\n      \"requestUid\": \"123e4567-e89b-12d3-a456-426614174000\"\n    }\n</p>\n"
  version: '1.0'
servers:
- url: https://bench.gobridgit.com
  description: Bridgit Bench production
security:
- {}
tags:
- name: AccountUsers
paths:
  /rp/api/v1/accounts/{accountId}/users:
    get:
      tags:
      - AccountUsers
      summary: Gets the users for the given account
      description: '<br/><strong>Permissions</strong><br/>Account: Read'
      operationId: AccountUsers_Query
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: offset
        in: query
        description: Offset for pagination
        schema:
          maximum: 2147483647
          minimum: 0
          type: integer
          format: int32
          default: 0
      - name: limit
        in: query
        description: Maximum number of results in this page
        schema:
          maximum: 2147483647
          minimum: 1
          type: integer
          format: int32
          default: 1000
      - name: group
        in: query
        description: Optional parameter to filter results based on user groups
        schema:
          type: string
      - name: ids
        in: query
        description: (Optional) Filters the result to contain account users that match the ids passed in.
        schema:
          type: array
          items:
            type: integer
            format: int32
      - name: nameSearch
        in: query
        description: (Optional) Searches for users by partial name match (minimum 3 characters).
        schema:
          type: string
      responses:
        '200':
          description: 'Success: List of users on the account'
          content:
            text/plain:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/UserResponse'
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/UserResponse'
            text/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/UserResponse'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
  /rp/api/v1/accounts/{accountId}/users/{id}:
    get:
      tags:
      - AccountUsers
      summary: Gets the the specified user for the given account by ID
      description: '<br/><strong>Permissions</strong><br/>Account: Read'
      operationId: AccountUsers_Get
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: The User's ID
        required: true
        schema:
          type: integer
          format: int32
      responses:
        '200':
          description: 'Success: List of users on the account'
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/UserResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/UserResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/UserResponse'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
    patch:
      tags:
      - AccountUsers
      summary: Updates a user for the given account
      description: 'Name or Title can be null, but they cannot be empty/whitespace. If null the value will not be changed.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: AccountUsers_Patch
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: Id of the user to update
        required: true
        schema:
          type: integer
          format: int32
      requestBody:
        description: Request object in the body with fields to change
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/UserRequest'
          application/json:
            schema:
              $ref: '#/components/schemas/UserRequest'
          text/json:
            schema:
              $ref: '#/components/schemas/UserRequest'
          application/*+json:
            schema:
              $ref: '#/components/schemas/UserRequest'
        required: true
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '409':
          description: Conflict
    delete:
      tags:
      - AccountUsers
      summary: Deactivates a user from the given account
      description: 'Adminsitrators can only deactivate other users from the account and not themselves.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: AccountUsers_Delete
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: Id of the user to remove
        required: true
        schema:
          type: integer
          format: int32
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
  /rp/api/v1/accounts/{accountId}/users/{id}/membership:
    put:
      tags:
      - AccountUsers
      summary: Modify user's permission group in the account.
      description: 'Groups in the account can be fetched from the api/v{version}/accounts/{accountId}/groups endpoint.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: AccountUsers_SetMembership
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: ID of the user to modify
        required: true
        schema:
          type: integer
          format: int32
      requestBody:
        description: Request object for the user
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/AccountMembershipRequest'
          application/json:
            schema:
              $ref: '#/components/schemas/AccountMembershipRequest'
          text/json:
            schema:
              $ref: '#/components/schemas/AccountMembershipRequest'
          application/*+json:
            schema:
              $ref: '#/components/schemas/AccountMembershipRequest'
        required: true
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
  /rp/api/v1/accounts/{accountId}/users/{userId}/reset-auth-method:
    post:
      tags:
      - AccountUsers
      summary: 'Resets a user''s authentication method and sends a new invitation email.

        This can be used to switch a user from SSO to username/password authentication.

        Note: users can be on multiple accounts in an organization. This resets the auth method in all accounts within

        the organization.'
      description: '<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: AccountUsers_ResetAuthMethod
      parameters:
      - name: accountId
        in: path
        description: The account that is currently calling this method.
        required: true
        schema:
          type: integer
          format: int32
      - name: userId
        in: path
        description: The ID of the account user.
        required: true
        schema:
          type: integer
          format: int32
      responses:
        '202':
          description: Accepted
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '422':
          description: Unprocessable Entity
components:
  schemas:
    GroupingGroup:
      type: object
      properties:
        id:
          type: integer
          format: int64
          example: 124
        groupId:
          type: integer
          format: int32
          example: 323
      additionalProperties: false
    UserRequest:
      type: object
      properties:
        name:
          type: string
          nullable: true
          example: John Smith
        title:
          type: string
          nullable: true
          example: Human Resources Manager
        phoneNumber:
          type: string
          nullable: true
          example: '+18005551234'
        team:
          type: string
          nullable: true
          example: Management
      additionalProperties: false
    AccountMembershipRequest:
      type: object
      properties:
        groupingPermissions:
          type: array
          items:
            $ref: '#/components/schemas/GroupingGroup'
          nullable: true
        group:
          type: string
          nullable: true
          example: Administrator
      additionalProperties: false
    UserResponse:
      type: object
      properties:
        id:
          type: integer
          format: int32
          example: 2313
        name:
          type: string
          nullable: true
          example: John Smith
        title:
          type: string
          nullable: true
          example: Human Resources Manager
        team:
          type: string
          nullable: true
          example: Management
        email:
          type: string
          nullable: true
          example: johnsmith@example.com
        state:
          enum:
          - Inactive
          - Enabled
          - Disabled
          - PendingEmailChange
          type: string
          example: Active
        group:
          type: string
          nullable: true
          example: Administrator
        groupingPermissions:
          type: array
          items:
            $ref: '#/components/schemas/GroupingGroup'
          nullable: true
        phoneNumber:
          type: string
          nullable: true
          example: '+18005551234'
        createdOn:
          type: string
          format: date-time
          example: '2020-01-01'
        invitationId:
          type: integer
          format: int64
          nullable: true
        lastLoginOn:
          type: string
          format: date-time
          nullable: true
          example: '2026-01-15T10:30:00Z'
      additionalProperties: false
  securitySchemes:
    Bearer:
      type: http
      description: Standard Authorization header using the Bearer scheme
      scheme: bearer
      bearerFormat: JWT