Cintoo Members API
The Members API from Cintoo — 4 operation(s) for members.
The Members API from Cintoo — 4 operation(s) for members.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/cintoo-members-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 2.0.0
title: Cintoo Open Members API
description: 'Cintoo Open API 1.x documentation: https://aec.cintoo.com/api
BETA: API v2 endpoints tagged "BETA" are available in beta-version, meaning that changes may be done later on.'
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
contact:
name: API Support
email: support@cintoo.com
x-logo:
url: ./assets/logo_api.svg
altText: Cintoo API
servers:
- url: https://aec.cintoo.com
security:
- oauth2: []
tags:
- name: Members
paths:
/api/2/accounts/{accountRef}/projects/{projectRef}/members:
get:
summary: Get Users member of a project
operationId: getProjectMembers
description: 'BETAGetUsers member of a project.
Requires the permission `project:members:list`.'
tags:
- Members
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/projectRef'
responses:
'200':
description: List Users part of the Project
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/User'
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport PROJECTUUID=...\n\ncurl --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/projects/$PROJECTUUID/members\" \\\n --header \"Authorization: Bearer $TOKEN\"\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nprojectUUID = \"...\"\ntoken = \"...\"\n\nresponse = requests.get(\n \"https://%s/api/2/accounts/%s/projects/%s/members\"\n % (host, accountUUID, projectUUID),\n headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst projectUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/projects/${projectUUID}/members`;\nconst res = await fetch(url, {\n headers: {\n \"Authorization\": `Bearer ${token}`,\n },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
post:
summary: Add members to project
operationId: addProjectMembers
description: 'BETAAdd members to a project.
#### Role assignment
* Each member is assigned to a role.
* Each user or group item accepts an optional `expirationDate` (ISO-8601 UTC timestamp). When set, the member access expires automatically around that time (actual removal may be delayed by up to a few hours). When absent or null, the member has no expiration.
* A member must not be already assigned to a different role on any work zone of the project.
* If a member already has the same role, the role is extended to the provided work zones and the expiration date is overridden project-wide on all workzones the member has access (including clearing it with null).
* Supports users and groups under the `members` object.
* Each member must be unique in the request.
* If a user does not exist yet, it will be automatically invited on the account
(equivalent to the Invite users end-point without account role).
* If any `expirationDate` is in the past, the entire request is rejected with HTTP 400 and `errorCode = "expiration-date-in-past"`.
#### Work zones
* Specific work zones can be provided to assign the roles only to those work zones **and their sub-workzones**.
* If the field `workzones` is not provided or null, it is equivalent to provide the topmost work zone of the project,
in other words the roles are assigned to all work zones of the project.
#### Permissions
* Requires a role with "Manage User" permission on the topmost work zone of the project.
* Requires to have at least all permissions of the provided roles, on the provided work zones.'
tags:
- Members
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/projectRef'
requestBody:
content:
application/json:
schema:
type: object
additionalProperties: false
required:
- members
properties:
workzones:
type:
- array
- 'null'
items:
$ref: '#/components/schemas/WorkzoneRef'
members:
type: object
additionalProperties: false
properties:
users:
type: array
items:
type: object
required:
- user
- role
properties:
user:
type: string
description: User's Email
role:
$ref: '#/components/schemas/RoleRef'
expirationDate:
type:
- string
- 'null'
allOf:
- $ref: '#/components/schemas/DateTime'
groups:
type: array
items:
type: object
required:
- group
- role
properties:
group:
$ref: '#/components/schemas/GroupRef'
role:
$ref: '#/components/schemas/RoleRef'
expirationDate:
type:
- string
- 'null'
allOf:
- $ref: '#/components/schemas/DateTime'
responses:
'204':
description: The members were successfully added to the project
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport PROJECTUUID=...\n\ncurl --request POST --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/projects/$PROJECTUUID/members\" \\\n --header \"Authorization: Bearer $TOKEN\" \\\n --header \"Content-Type: application/json\" \\\n --data '{\n \"workzones\": [ \"urn:cintoo:workzone:...\", \"urn:cintoo:workzone:...\" ],\n \"members\": {\n \"users\": [\n { \"user\": \"newuser@mycompany.com\", \"role\": \"urn:cintoo:role:...\", \"expirationDate\": \"2035-12-31T23:59:59Z\" }\n ],\n \"groups\": [\n { \"group\": \"urn:cintoo:group:...\", \"role\": \"urn:cintoo:role:...\", \"expirationDate\": null }\n ]\n }\n }'\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nprojectUUID = \"...\"\nworkzonesIds = [ \"...\", \"...\" ]\ntoken = \"...\"\n\nresponse = requests.post(\n \"https://%s/api/2/accounts/%s/projects/%s/members\"\n % (host, accountUUID, projectUUID),\n headers = { \"Authorization\": \"Bearer %s\" % token},\n json = {\n \"workzones\": workzonesIds,\n \"members\": {\n \"users\": [ { \"user\": \"newuser@mycompany.com\", \"role\": \"...\", \"expirationDate\": \"2035-12-31T23:59:59Z\" } ],\n \"groups\": [ { \"group\": \"urn:cintoo:group:...\", \"role\": \"...\", \"expirationDate\": None } ]\n }\n }\n)\nprint(response.status_code)\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst projectUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/projects/${projectUUID}/members`;\nconst res = await fetch(url, {\n method: \"POST\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n \"Content-Type\": \"application/json\",\n },\n body: JSON.stringify(\n {\n \"workzones\": [ \"urn:cintoo:workzone:...\", \"urn:cintoo:workzone:...\" ],\n \"members\": {\n \"users\": [\n { \"user\": \"newuser@mycompany.com\", \"role\": \"urn:cintoo:role:...\", \"expirationDate\": \"2035-12-31T23:59:59Z\" }\n ],\n \"groups\": [\n { \"group\": \"urn:cintoo:group:...\", \"role\": \"urn:cintoo:role:...\", \"expirationDate\": null }\n ]\n }\n }\n ),\n});\n\nconsole.log(res.status);\nif (res.status !== 204) {\n const data = await res.json();\n console.log(data);\n}\n"
/api/2/accounts/{accountRef}/projects/{projectRef}/members/bulk-remove:
post:
summary: Bulk remove users and groups from project
operationId: removeMembersFromProject
description: 'BETARemove users and groups from the project.
This endpoint will ignore users or groups that are not really contributors of the project.
Permissions:
Requires a role with "Manage User" permission on the top most work zone of the project.'
tags:
- Members
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/projectRef'
requestBody:
content:
application/json:
schema:
type: object
additionalProperties: false
properties:
users:
type: array
items:
$ref: '#/components/schemas/UserRef'
groups:
type: array
items:
$ref: '#/components/schemas/GroupRef'
responses:
'204':
description: The users and groups were successfully removed from the project
'403':
description: Forbidden
content:
application/json:
schema:
type: object
properties:
status:
type: integer
enum:
- 403
type:
type: string
enum:
- Cannot remove users or groups. Need to have "manage_user" permission on the project
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport PROJECTUUID=...\n\ncurl --request POST --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/projects/$PROJECTUUID/members/bulk-remove\" \\\n --header \"Authorization: Bearer $TOKEN\" \\\n --header \"Content-Type: application/json\" \\\n --data '{\n \"users\": [ \"urn:cintoo:user:...\", \"urn:cintoo:user:...\" ],\n \"groups\": [ \"urn:cintoo:group:...\", \"urn:cintoo:group:...\" ]\n }'\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nprojectUUID = \"...\"\nuserIds = [ \"...\", \"...\" ]\ngroupUUIDs = [ \"...\", \"...\" ]\ntoken = \"...\"\n\nresponse = requests.post(\n \"https://%s/api/2/accounts/%s/projects/%s/members/bulk-remove\"\n % (host, accountUUID, projectUUID),\n headers = { \"Authorization\": \"Bearer %s\" % token},\n json = {\n \"users\": userIds,\n \"groups\": groupUUIDs\n }\n)\nprint(response.status_code)\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst projectUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/projects/${projectUUID}/members/bulk-remove`;\nconst res = await fetch(url, {\n method: \"POST\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n \"Content-Type\": \"application/json\",\n },\n body: JSON.stringify(\n {\n \"users\": [ \"urn:cintoo:user:...\", \"urn:cintoo:user:...\" ],\n \"groups\": [ \"urn:cintoo:group:...\", \"urn:cintoo:group:...\" ]\n }\n ),\n});\n\nconsole.log(res.status);\nif (res.status !== 204) {\n const data = await res.json();\n console.log(data);\n}\n"
/api/2/accounts/{accountRef}/projects/{projectRef}/members/users/{userRef}:
delete:
summary: Remove user from project
operationId: removeUserFromProject
description: 'BETARemove a user from the project.
Requires the permission `workzone:members:write` on the top most work zone of the project.
**Note** can be invoked on self. Any user can remove himself from a project.'
tags:
- Members
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/projectRef'
- $ref: '#/components/parameters/userRef'
responses:
'204':
description: The user was successfully removed from the project
'403':
description: Forbidden
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/ErrorForbidden'
- type: object
properties:
errorCode:
type: string
description: '* `remove-contributor-forbidden`
'
examples:
remove-contributor-forbidden:
value:
status: 403
title: Forbidden
detail: You do not have the permission to remove contributor. It requires to be targeting self, or to have permission "manage_users"
errorCode: remove-contributor-forbidden
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport PROJECTUUID=...\nexport USERID=...\n\ncurl --request DELETE --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/projects/$PROJECTUUID/members/users/$USERID\" \\\n --header \"Authorization: Bearer $TOKEN\"\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nprojectUUID = \"...\"\nuserId = \"...\"\ntoken = \"...\"\n\nresponse = requests.delete(\n \"https://%s/api/2/accounts/%s/projects/%s/members/users/%s\"\n % (host, accountUUID, projectUUID, userId),\n headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst projectUUID = \"...\";\nconst userId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/projects/${projectUUID}/members/users/${userId}`;\nconst res = await fetch(url, {\n method: \"DELETE\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n },\n});\n\nconsole.log(res.status);\nif (res.status !== 204) {\n const data = await res.json();\n console.log(data);\n}\n"
/api/2/accounts/{accountRef}/projects/{projectRef}/members/groups/{groupRef}:
delete:
summary: Remove group from project
operationId: removeGroupFromProject
description: 'BETARemove a group from the project.
Permissions:
Requires the permission `workzone:members:write` on the top most work zone of the project.'
tags:
- Members
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/projectRef'
- $ref: '#/components/parameters/groupRef'
responses:
'204':
description: The group was successfully removed from the project
'403':
description: Forbidden
content:
application/json:
schema:
type: object
properties:
status:
type: integer
enum:
- 403
type:
type: string
enum:
- Cannot remove group(s). Need to have "manage_user" permission on the project
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport PROJECTUUID=...\nexport GROUPUUID=...\n\ncurl --request DELETE --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/projects/$PROJECTUUID/members/groups/$GROUPUUID\" \\\n --header \"Authorization: Bearer $TOKEN\"\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nprojectUUID = \"...\"\ngroupUUID = \"...\"\ntoken = \"...\"\n\nresponse = requests.delete(\n \"https://%s/api/2/accounts/%s/projects/%s/members/groups/%s\"\n % (host, accountUUID, projectUUID, groupUUID),\n headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst projectUUID = \"...\";\nconst groupUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/projects/${projectUUID}/members/groups/${groupUUID}`;\nconst res = await fetch(url, {\n method: \"DELETE\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n },\n});\n\nconsole.log(res.status);\nif (res.status !== 204) {\n const data = await res.json();\n console.log(data);\n}\n"
components:
schemas:
WorkzoneUrn:
type: string
pattern: ^urn:cintoo:workzone:[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
description: '"urn:cintoo:workzone:" followed by an UUIDv4
'
AccountRoles:
type: string
enum:
- administrator
- projectLister
- projectManager
AccountUrn:
type: string
description: '"urn:cintoo:account:" followed by an UUIDv4
'
DateTime:
type: string
format: date-time
description: 'The date-time notation as defined by RFC 3339, section 5.6 (ex: 2017-08-18T12:41:31Z)'
example: '2017-08-18T12:41:31Z'
GroupId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
RoleId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
UserOldId:
type: string
pattern: ^[-_0-9a-zA-Z]+$
description: Base64url encoding of "user-{id}"
RoleRef:
oneOf:
- $ref: '#/components/schemas/RoleUrn'
- $ref: '#/components/schemas/RoleId'
UserId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
ProjectUrn:
type: string
description: '"urn:cintoo:project:" followed by an UUIDv4
'
UserUrn:
type: string
description: '"urn:cintoo:user:" followed by an UUIDv4
'
AccountId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
RoleUrn:
type: string
description: '"urn:cintoo:role:" followed by an UUIDv4
'
WorkzoneId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
ErrorForbidden:
type: object
required:
- status
- title
properties:
status:
type: integer
format: int32
enum:
- 403
title:
type: string
enum:
- Forbidden
detail:
type: string
description: human readable description of the error in english
UserRef:
oneOf:
- $ref: '#/components/schemas/UserUrn'
- $ref: '#/components/schemas/UserId'
User:
type: object
required:
- id
- type
- api1Id
- firstName
- email
x-tags:
- User
properties:
id:
readOnly: true
$ref: '#/components/schemas/UserUrn'
type:
type: string
enum:
- user
api1Id:
$ref: '#/components/schemas/UserOldId'
firstName:
type: string
example: John
lastName:
type: string
example: Doe
email:
type: string
format: email
company:
type: string
example: Cintoo
title:
type: string
example: Account Manager
avatar:
type: string
format: uri
accountRoles:
type: array
description: "Account-level roles assigned to this user. Visibility depends on caller's permissions:\n\nVisibility rules:\n- Field is omitted if caller has none of the role read permissions\n- Field is included with filtered roles based on caller's permissions:\n - `account:administrators:read`: can see administrator role\n - `account:project-managers:read`: can see projectManager role\n - `account:project-listers:read`: can see projectLister role\n\nExamples:\n- Account Owner/Admin (has all three read permissions): sees all roles (administrator, projectManager, projectLister)\n- Project Manager (has only project-managers:read): sees only projectManager role\n- Normal user (has no read permissions): field is omitted entirely\n\nNote: The accountOwner role is never exposed in this field.\n"
items:
$ref: '#/components/schemas/AccountRoles'
example:
- administrator
- projectManager
WorkzoneRef:
oneOf:
- $ref: '#/components/schemas/WorkzoneUrn'
- $ref: '#/components/schemas/WorkzoneId'
Error:
type: object
required:
- status
- title
properties:
status:
type: integer
format: int32
title:
type: string
detail:
type: string
description: human readable description of the error in english
errorCode:
type: string
description: detailed code describing error, can be used to map to a localized message
errorValues:
type: object
description: values implied in the error, typically an input parameter, can be used to include in a localized message
GroupRef:
oneOf:
- $ref: '#/components/schemas/GroupUrn'
- $ref: '#/components/schemas/GroupId'
Uuid:
type: string
description: UUIDv4
format: uuid
example: 156fff1a-0ef7-4335-891a-627928a19e29
ProjectId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
GroupUrn:
type: string
description: '"urn:cintoo:group:" followed by an UUIDv4
'
parameters:
userRef:
name: userRef
in: path
required: true
description: The Id or Urn of the user
schema:
$ref: '#/components/schemas/UserRef'
accountRef:
name: accountRef
in: path
required: true
description: The Id or Urn of the account
schema:
oneOf:
- $ref: '#/components/schemas/AccountUrn'
- $ref: '#/components/schemas/AccountId'
projectRef:
name: projectRef
in: path
required: true
description: The Id or Urn of the project
schema:
oneOf:
- $ref: '#/components/schemas/ProjectUrn'
- $ref: '#/components/schemas/ProjectId'
groupRef:
name: groupRef
in: path
required: true
description: The Id or Urn of the group
schema:
$ref: '#/components/schemas/GroupRef'
responses:
UnexpectedError:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
examples:
'400':
value:
status: 400
title: Bad Request
'401':
value:
status: 401
title: Unauthorized
'403':
value:
status: 403
title: Forbidden
'404':
value:
status: 404
title: Not Found
'405':
value:
status: 405
title: Method Not Allowed
'406':
value:
status: 406
title: Not Acceptable
securitySchemes:
oauth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://aec.cintoo.com/oauth/authorize
tokenUrl: https://aec.cintoo.com/oauth/token
scopes: {}
refreshUrl: https://aec.cintoo.com/oauth/token
x-tagGroups:
- name: General
tags:
- errors_list
- internal_information
- token_management
- Permissions
- Authentication
- name: Resources
tags:
- Resources
- name: Tenant
tags:
- Tenant
- name: Account
tags:
- Account
- Subscription
- Role
- User
- Group
- Trusted Device
- name: Subscription
tags:
- Usage Report
- name: Project
tags:
- Project
- Members
- Workzone
- name: Project Data
tags:
- File
- Annotation
- Saved View
- Share Link
- Crop
- Measurement
- Tag List
- Tag
- name: Jobs
tags:
- Progress Monitoring
- Import Model
- Export Scene
- Segmentation
- Video360
- Import IDD
- name: Integrations
tags:
- Integrations
- Konekt
- Autodesk
- Procore
- name: Tutorials
tags:
- tuto_upload_file
- understand_tag_data