Cintoo Role API
The Role API from Cintoo — 2 operation(s) for role.
The Role API from Cintoo — 2 operation(s) for role.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/cintoo-role-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 2.0.0
title: Cintoo Open Role API
description: 'Cintoo Open API 1.x documentation: https://aec.cintoo.com/api
BETA: API v2 endpoints tagged "BETA" are available in beta-version, meaning that changes may be done later on.'
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
contact:
name: API Support
email: support@cintoo.com
x-logo:
url: ./assets/logo_api.svg
altText: Cintoo API
servers:
- url: https://aec.cintoo.com
security:
- oauth2: []
tags:
- name: Role
paths:
/api/2/accounts/{accountRef}/roles:
get:
summary: List Roles
operationId: getRoles
description: 'BETAList available roles into this account.
Requires the permission `account:roles:read`.'
tags:
- Role
parameters:
- $ref: '#/components/parameters/accountRef'
responses:
'200':
description: List and content of the Roles
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/Role'
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\n\ncurl --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles\" \\\n --header \"Authorization: Bearer $TOKEN\"\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\ntoken = \"...\"\n\nresponse = requests.get(\n \"https://%s/api/2/accounts/%s/roles\"\n % (host, accountUUID),\n headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\nprint(response.json())\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles`;\nconst res = await fetch(url, {\n headers: {\n \"Authorization\": `Bearer ${token}`,\n },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
post:
summary: Create Role
operationId: createRole
description: 'BETACreate a custom role.
Requires the permission `account:roles:write`.
One of `permissions` or `legacyPermissions` must be present and non-empty.
If both are specified (discouraged) they must be strictly equivalent.
For the field `permissions`, the allowed combinations are documented here.'
tags:
- Role
parameters:
- $ref: '#/components/parameters/accountRef'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/roleCreate'
responses:
'201':
description: The role was successfully created
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\n\ncurl --request POST --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles\" \\\n --header \"Authorization: Bearer $TOKEN\" \\\n --header \"Content-Type: application/json\" \\\n --data '{\n \"name\": \"Viewer\",\n \"description\": \"Read only user\",\n \"color\": \"#123456\",\n \"permissions\": [\"view3d\", \"measure\", \"view_tag\"]\n}'\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\ntoken = \"...\"\n\nresponse = requests.post(\n \"https://%s/api/2/accounts/%s/roles\"\n % (host, accountUUID),\n headers = { \"Authorization\": \"Bearer %s\" % token },\n json = {\n \"name\": \"Viewer\",\n \"description\": \"Read only user\",\n \"color\": \"#12345e\",\n \"permissions\": [\"view3d\", \"measure\", \"view_tag\"]\n }\n)\nprint(response.status_code)\nprint(response.json())\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles`;\nconst res = await fetch(url, {\n method: \"POST\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n \"Content-Type\": \"application/json\",\n },\n body: JSON.stringify(\n {\n \"name\": \"Viewer\",\n \"description\": \"Read only user\",\n \"color\": \"#123456\",\n \"permissions\": [\"view3d\", \"measure\", \"view_tag\"]\n }\n ),\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
/api/2/accounts/{accountRef}/roles/{roleRef}:
get:
summary: Get Role
operationId: getRole
description: 'BETAGet a role details.
Requires the permission `account:roles:read`.'
tags:
- Role
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/roleRef'
responses:
'200':
description: Content of the requested Role
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport ROLEID=...\n\ncurl --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles/$ROLEID\" \\\n --header \"Authorization: Bearer $TOKEN\"\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nroleId = \"...\"\ntoken = \"...\"\n\nresponse = requests.get(\n \"https://%s/api/2/accounts/%s/roles/%s\"\n % (host, accountUUID, roleId),\n headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\nprint(response.json())\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst roleId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles/${roleId}`;\nconst res = await fetch(url, {\n headers: {\n \"Authorization\": `Bearer ${token}`,\n },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
delete:
summary: Delete Role
operationId: deleteRole
description: 'BETADelete a Role.
Requires the permission `account:roles:write`.'
tags:
- Role
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/roleRef'
responses:
'204':
description: The role was successfully deleted
'400':
description: Cannot delete base role, or role is used in projects
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/ErrorBadRequest'
- type: object
properties:
errorCode:
type: string
description: '* `cannot-delete-base-role` if the role is a base role
* `role-used` if the role is used in projects
'
errorValues:
type: object
properties:
roleId:
type: string
description: role id for errorCode `role-used`
projectIds:
type: string
description: comma separated list of projects using the role for errorCode `role-used`
examples:
cannot-delete-base-role:
value:
status: 400
title: Bad Request
detail: Base roles can't be deleted
errorCode: cannot-delete-base-role
role-used:
value:
status: 400
title: Bad Request
detail: Role 1234 is in use in projects projectId1, projectId2, projectId3
errorCode: role-used
errorValues:
roleId: '1234'
projectIds: projectId1, projectId2, projectId3
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport ROLEID=...\n\ncurl --request DELETE --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles/$ROLEID\" \\\n --header \"Authorization: Bearer $TOKEN\"\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nroleId = \"...\"\ntoken = \"...\"\n\nresponse = requests.delete(\n \"https://%s/api/2/accounts/%s/roles/%s\"\n % (host, accountUUID, roleId),\n headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst roleId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles/${roleId}`;\nconst res = await fetch(url, {\n method: \"DELETE\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
put:
summary: Update Role
operationId: updateRole
description: 'BETAUpdate a role.
⚠ Overwrites all fields. Missing fields will be considered as null and current values will be erased
Permissions:
Requires the permission `account:roles:write`.
One of `permissions` or `legacyPermissions` must be present and non-empty.
If both are specified (discouraged) they must be strictly equivalent.
For the field `permissions`, the allowed combinations are documented here.'
tags:
- Role
parameters:
- $ref: '#/components/parameters/accountRef'
- $ref: '#/components/parameters/roleRef'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/roleUpdate'
responses:
'200':
description: New content of the updated Role
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
'400':
description: Cannot update base role
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/ErrorBadRequest'
- type: object
properties:
errorCode:
type: string
description: '`cannot-update-base-role` if the role is a base role'
examples:
cannot-update-base-role:
value:
status: 400
title: Bad Request
detail: Base roles can't be updated
errorCode: cannot-update-base-role
4XX:
$ref: '#/components/responses/UnexpectedError'
x-codeSamples:
- lang: cURL
source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport ROLEID=...\n\ncurl --request PUT --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles/$ROLEID\" \\\n --header \"Authorization: Bearer $TOKEN\" \\\n --header \"Content-Type: application/json\" \\\n --data '{\n \"description\": \"Better description\",\n \"color\": \"#E529B0\"\n }'\n"
- lang: Python
source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nroleId = \"...\"\ntoken = \"...\"\n\nresponse = requests.put(\n \"https://%s/api/2/accounts/%s/roles/%s\"\n % (host, accountUUID, roleId),\n headers = { \"Authorization\": \"Bearer %s\" % token },\n json = {\n \"description\": \"Better description\",\n \"color\": \"#E529B0\"\n }\n)\nprint(response.status_code)\nprint(response.json())\n"
- lang: TypeScript
source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst roleId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles/${roleId}`;\nconst res = await fetch(url, {\n method: \"PUT\",\n headers: {\n \"Authorization\": `Bearer ${token}`,\n \"Content-Type\": \"application/json\",\n },\n body: JSON.stringify(\n {\n \"description\": \"Better description\",\n \"color\": \"#E529B0\"\n }\n ),\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
components:
parameters:
accountRef:
name: accountRef
in: path
required: true
description: The Id or Urn of the account
schema:
oneOf:
- $ref: '#/components/schemas/AccountUrn'
- $ref: '#/components/schemas/AccountId'
roleRef:
name: roleRef
in: path
required: true
description: The Id or Urn of the role
schema:
oneOf:
- $ref: '#/components/schemas/RoleUrn'
- $ref: '#/components/schemas/RoleId'
schemas:
RoleId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
RoleLegacyPermissions:
type: array
description: "Permissions given by the role, in the legacy format, among:\n - `create_project`: Update, delete or restore projects created by a project manager\n - `workzone`: Create, modify & delete Work Zones\n - `view3d`: Overview, 3D view, Scan View\n - `annotate`: Create, edit and delete annotations, assign notes to Team Members\n - `measure`: Add and view 3D measurements\n - `share`: Can share project\n - `upload`: Upload or delete laser scans or 360° images and manage versions\n - `download`: Export in E57 or download Reality Data via Cintoo Connect\n - `upload_doc`: Upload and download documents and 3D models from BIM platforms or from desktop\n - `manage_users`: Add / remove new Team Members and define permissions\n - `create_asset`: Import, create, edit and delete tags\n - `view_asset`: View and export tags\n - `view_annotation`: View annotations\n - `manage_savedview`: Create, edit and delete saved views\n - `view_savedview`: View saved views\n - `manage_cipm`: Manage Progress Monitoring Jobs\n"
minItems: 1
items:
type: string
enum:
- create_project
- workzone
- view3d
- annotate
- measure
- share
- upload
- download
- upload_doc
- manage_users
- create_asset
- view_asset
- view_annotation
- manage_savedview
- view_savedview
- manage_cipm
ErrorBadRequest:
type: object
required:
- status
- title
properties:
status:
type: integer
format: int32
enum:
- 400
title:
type: string
enum:
- Bad Request
detail:
type: string
description: human readable description of the error in english
roleCreate:
type: object
required:
- name
properties:
name:
type: string
example: BIM / VDC Manager
description:
type: string
example: Can do anything except creating projects
color:
$ref: '#/components/schemas/Color'
permissions:
$ref: '#/components/schemas/RolePermissions'
legacyPermissions:
$ref: '#/components/schemas/RoleLegacyPermissions'
Error:
type: object
required:
- status
- title
properties:
status:
type: integer
format: int32
title:
type: string
detail:
type: string
description: human readable description of the error in english
errorCode:
type: string
description: detailed code describing error, can be used to map to a localized message
errorValues:
type: object
description: values implied in the error, typically an input parameter, can be used to include in a localized message
AccountUrn:
type: string
description: '"urn:cintoo:account:" followed by an UUIDv4
'
Role:
type: object
required:
- id
- type
- api1Id
- name
- description
- color
- createdBy
- createdAt
- updatedAt
- permissions
- legacyPermissions
x-tags:
- Role
properties:
id:
readOnly: true
$ref: '#/components/schemas/RoleUrn'
type:
type: string
enum:
- role
name:
type: string
example: BIM / VDC Manager
description:
type: string
example: Can do anything except creating projects
color:
$ref: '#/components/schemas/Color'
createdBy:
type:
- string
- 'null'
allOf:
- $ref: '#/components/schemas/UserUrn'
createdAt:
type:
- string
- 'null'
allOf:
- $ref: '#/components/schemas/DateTime'
updatedAt:
type:
- string
- 'null'
allOf:
- $ref: '#/components/schemas/DateTime'
permissions:
$ref: '#/components/schemas/RolePermissions'
legacyPermissions:
$ref: '#/components/schemas/RoleLegacyPermissions'
UserUrn:
type: string
description: '"urn:cintoo:user:" followed by an UUIDv4
'
roleUpdate:
type: object
properties:
name:
type: string
example: BIM / VDC Manager
description:
type: string
example: Can do anything except creating projects
color:
$ref: '#/components/schemas/Color'
permissions:
type:
- array
- 'null'
allOf:
- $ref: '#/components/schemas/RolePermissions'
legacyPermissions:
type:
- array
- 'null'
allOf:
- $ref: '#/components/schemas/RoleLegacyPermissions'
Uuid:
type: string
description: UUIDv4
format: uuid
example: 156fff1a-0ef7-4335-891a-627928a19e29
Color:
type: string
pattern: ^#[0-9a-f]{6}$
example: '#0698ec'
AccountId:
allOf:
- $ref: '#/components/schemas/Uuid'
example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
RoleUrn:
type: string
description: '"urn:cintoo:role:" followed by an UUIDv4
'
DateTime:
type: string
format: date-time
description: 'The date-time notation as defined by RFC 3339, section 5.6 (ex: 2017-08-18T12:41:31Z)'
example: '2017-08-18T12:41:31Z'
RolePermissions:
type: array
description: permissions given by the role. Please check the [permissions](#section/API-Specification/Permissions) section for the list of allowed combinations
minItems: 1
items:
type: string
enum:
- project:project:delete
- project:project:update-details
- workzone:workzones:write
- workzone:workzones:read
- workzone:annotations:write
- workzone:annotations:read
- workzone:measurements:write
- workzone:measurements:read
- workzone:share-links:write
- workzone:share-links:read
- workzone:own-share-links:write
- workzone:own-share-links:read
- workzone:reality-data:read
- workzone:reality-data:write
- workzone:reality-data:transform
- workzone:cad-model:transform
- workzone:cad-model:read
- workzone:import-jobs-reality-data:write
- workzone:export-jobs-reality-data:read
- workzone:export-jobs-reality-data:write
- workzone:documents:write
- workzone:documents:read
- workzone:members:write
- workzone:tags:write
- workzone:tags:read
- workzone:savedviews:write
- workzone:savedviews:read
- workzone:model-reports:read
- workzone:model-reports:write
- workzone:progress-monitoring-jobs:read
- workzone:progress-monitoring-jobs:write
- workzone:own-progress-monitoring-jobs:read
- workzone:own-progress-monitoring-jobs:write
responses:
UnexpectedError:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
examples:
'400':
value:
status: 400
title: Bad Request
'401':
value:
status: 401
title: Unauthorized
'403':
value:
status: 403
title: Forbidden
'404':
value:
status: 404
title: Not Found
'405':
value:
status: 405
title: Method Not Allowed
'406':
value:
status: 406
title: Not Acceptable
securitySchemes:
oauth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://aec.cintoo.com/oauth/authorize
tokenUrl: https://aec.cintoo.com/oauth/token
scopes: {}
refreshUrl: https://aec.cintoo.com/oauth/token
x-tagGroups:
- name: General
tags:
- errors_list
- internal_information
- token_management
- Permissions
- Authentication
- name: Resources
tags:
- Resources
- name: Tenant
tags:
- Tenant
- name: Account
tags:
- Account
- Subscription
- Role
- User
- Group
- Trusted Device
- name: Subscription
tags:
- Usage Report
- name: Project
tags:
- Project
- Members
- Workzone
- name: Project Data
tags:
- File
- Annotation
- Saved View
- Share Link
- Crop
- Measurement
- Tag List
- Tag
- name: Jobs
tags:
- Progress Monitoring
- Import Model
- Export Scene
- Segmentation
- Video360
- Import IDD
- name: Integrations
tags:
- Integrations
- Konekt
- Autodesk
- Procore
- name: Tutorials
tags:
- tuto_upload_file
- understand_tag_data