Cintoo Role API

The Role API from Cintoo — 2 operation(s) for role.

Business capability
Identity & Access Management BC-620.20

Operations 5

GET /api/2/accounts/{accountRef}/roles List Roles #
POST /api/2/accounts/{accountRef}/roles Create Role #
GET /api/2/accounts/{accountRef}/roles/{roleRef} Get Role #
DELETE /api/2/accounts/{accountRef}/roles/{roleRef} Delete Role #
PUT /api/2/accounts/{accountRef}/roles/{roleRef} Update Role #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cintoo-role-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cintoo-role-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 2.0.0
  title: Cintoo Open Role API
  description: 'Cintoo Open API 1.x documentation: https://aec.cintoo.com/api


    BETA: API v2 endpoints tagged "BETA" are available in beta-version, meaning that changes may be done later on.'
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  contact:
    name: API Support
    email: support@cintoo.com
  x-logo:
    url: ./assets/logo_api.svg
    altText: Cintoo API
servers:
- url: https://aec.cintoo.com
security:
- oauth2: []
tags:
- name: Role
paths:
  /api/2/accounts/{accountRef}/roles:
    get:
      summary: List Roles
      operationId: getRoles
      description: 'BETAList available roles into this account.


        Requires the permission `account:roles:read`.'
      tags:
      - Role
      parameters:
      - $ref: '#/components/parameters/accountRef'
      responses:
        '200':
          description: List and content of the Roles
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Role'
        4XX:
          $ref: '#/components/responses/UnexpectedError'
      x-codeSamples:
      - lang: cURL
        source: "export TOKEN=...\nexport ACCOUNTUUID=...\n\ncurl --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles\" \\\n  --header \"Authorization: Bearer $TOKEN\"\n"
      - lang: Python
        source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\ntoken = \"...\"\n\nresponse = requests.get(\n  \"https://%s/api/2/accounts/%s/roles\"\n    % (host, accountUUID),\n  headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\nprint(response.json())\n"
      - lang: TypeScript
        source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles`;\nconst res = await fetch(url, {\n  headers: {\n    \"Authorization\": `Bearer ${token}`,\n  },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
    post:
      summary: Create Role
      operationId: createRole
      description: 'BETACreate a custom role.


        Requires the permission `account:roles:write`.


        One of `permissions` or `legacyPermissions` must be present and non-empty.

        If both are specified (discouraged) they must be strictly equivalent.


        For the field `permissions`, the allowed combinations are documented here.'
      tags:
      - Role
      parameters:
      - $ref: '#/components/parameters/accountRef'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/roleCreate'
      responses:
        '201':
          description: The role was successfully created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        4XX:
          $ref: '#/components/responses/UnexpectedError'
      x-codeSamples:
      - lang: cURL
        source: "export TOKEN=...\nexport ACCOUNTUUID=...\n\ncurl --request POST --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles\" \\\n  --header \"Authorization: Bearer $TOKEN\" \\\n  --header \"Content-Type: application/json\" \\\n  --data '{\n    \"name\": \"Viewer\",\n    \"description\": \"Read only user\",\n    \"color\": \"#123456\",\n    \"permissions\": [\"view3d\", \"measure\", \"view_tag\"]\n}'\n"
      - lang: Python
        source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\ntoken = \"...\"\n\nresponse = requests.post(\n  \"https://%s/api/2/accounts/%s/roles\"\n    % (host, accountUUID),\n  headers = { \"Authorization\": \"Bearer %s\" % token },\n  json = {\n    \"name\": \"Viewer\",\n    \"description\": \"Read only user\",\n    \"color\": \"#12345e\",\n    \"permissions\": [\"view3d\", \"measure\", \"view_tag\"]\n  }\n)\nprint(response.status_code)\nprint(response.json())\n"
      - lang: TypeScript
        source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles`;\nconst res = await fetch(url, {\n  method: \"POST\",\n  headers: {\n    \"Authorization\": `Bearer ${token}`,\n    \"Content-Type\": \"application/json\",\n  },\n  body: JSON.stringify(\n    {\n        \"name\": \"Viewer\",\n        \"description\": \"Read only user\",\n        \"color\": \"#123456\",\n        \"permissions\": [\"view3d\", \"measure\", \"view_tag\"]\n    }\n  ),\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
  /api/2/accounts/{accountRef}/roles/{roleRef}:
    get:
      summary: Get Role
      operationId: getRole
      description: 'BETAGet a role details.


        Requires the permission `account:roles:read`.'
      tags:
      - Role
      parameters:
      - $ref: '#/components/parameters/accountRef'
      - $ref: '#/components/parameters/roleRef'
      responses:
        '200':
          description: Content of the requested Role
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        4XX:
          $ref: '#/components/responses/UnexpectedError'
      x-codeSamples:
      - lang: cURL
        source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport ROLEID=...\n\ncurl --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles/$ROLEID\" \\\n  --header \"Authorization: Bearer $TOKEN\"\n"
      - lang: Python
        source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nroleId = \"...\"\ntoken = \"...\"\n\nresponse = requests.get(\n  \"https://%s/api/2/accounts/%s/roles/%s\"\n    % (host, accountUUID, roleId),\n  headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\nprint(response.json())\n"
      - lang: TypeScript
        source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst roleId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles/${roleId}`;\nconst res = await fetch(url, {\n  headers: {\n    \"Authorization\": `Bearer ${token}`,\n  },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
    delete:
      summary: Delete Role
      operationId: deleteRole
      description: 'BETADelete a Role.


        Requires the permission `account:roles:write`.'
      tags:
      - Role
      parameters:
      - $ref: '#/components/parameters/accountRef'
      - $ref: '#/components/parameters/roleRef'
      responses:
        '204':
          description: The role was successfully deleted
        '400':
          description: Cannot delete base role, or role is used in projects
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/ErrorBadRequest'
                - type: object
                  properties:
                    errorCode:
                      type: string
                      description: '* `cannot-delete-base-role` if the role is a base role

                        * `role-used` if the role is used in projects

                        '
                    errorValues:
                      type: object
                      properties:
                        roleId:
                          type: string
                          description: role id for errorCode `role-used`
                        projectIds:
                          type: string
                          description: comma separated list of projects using the role for errorCode `role-used`
              examples:
                cannot-delete-base-role:
                  value:
                    status: 400
                    title: Bad Request
                    detail: Base roles can't be deleted
                    errorCode: cannot-delete-base-role
                role-used:
                  value:
                    status: 400
                    title: Bad Request
                    detail: Role 1234 is in use in projects projectId1, projectId2, projectId3
                    errorCode: role-used
                    errorValues:
                      roleId: '1234'
                      projectIds: projectId1, projectId2, projectId3
        4XX:
          $ref: '#/components/responses/UnexpectedError'
      x-codeSamples:
      - lang: cURL
        source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport ROLEID=...\n\ncurl --request DELETE --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles/$ROLEID\" \\\n  --header \"Authorization: Bearer $TOKEN\"\n"
      - lang: Python
        source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nroleId = \"...\"\ntoken = \"...\"\n\nresponse = requests.delete(\n  \"https://%s/api/2/accounts/%s/roles/%s\"\n    % (host, accountUUID, roleId),\n  headers = { \"Authorization\": \"Bearer %s\" % token}\n)\nprint(response.status_code)\n"
      - lang: TypeScript
        source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst roleId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles/${roleId}`;\nconst res = await fetch(url, {\n  method: \"DELETE\",\n  headers: {\n    \"Authorization\": `Bearer ${token}`,\n  },\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
    put:
      summary: Update Role
      operationId: updateRole
      description: 'BETAUpdate a role.


        ⚠ Overwrites all fields. Missing fields will be considered as null and current values will be erased


        Permissions:


        Requires the permission `account:roles:write`.


        One of `permissions` or `legacyPermissions` must be present and non-empty.

        If both are specified (discouraged) they must be strictly equivalent.


        For the field `permissions`, the allowed combinations are documented here.'
      tags:
      - Role
      parameters:
      - $ref: '#/components/parameters/accountRef'
      - $ref: '#/components/parameters/roleRef'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/roleUpdate'
      responses:
        '200':
          description: New content of the updated Role
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        '400':
          description: Cannot update base role
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/ErrorBadRequest'
                - type: object
                  properties:
                    errorCode:
                      type: string
                      description: '`cannot-update-base-role` if the role is a base role'
              examples:
                cannot-update-base-role:
                  value:
                    status: 400
                    title: Bad Request
                    detail: Base roles can't be updated
                    errorCode: cannot-update-base-role
        4XX:
          $ref: '#/components/responses/UnexpectedError'
      x-codeSamples:
      - lang: cURL
        source: "export TOKEN=...\nexport ACCOUNTUUID=...\nexport ROLEID=...\n\ncurl --request PUT --url \"https://aec.cintoo.com/api/2/accounts/$ACCOUNTUUID/roles/$ROLEID\" \\\n  --header \"Authorization: Bearer $TOKEN\" \\\n  --header \"Content-Type: application/json\" \\\n  --data '{\n      \"description\": \"Better description\",\n      \"color\": \"#E529B0\"\n  }'\n"
      - lang: Python
        source: "import requests\n\nhost = \"aec.cintoo.com\"\naccountUUID = \"...\"\nroleId = \"...\"\ntoken = \"...\"\n\nresponse = requests.put(\n  \"https://%s/api/2/accounts/%s/roles/%s\"\n    % (host, accountUUID, roleId),\n  headers = { \"Authorization\": \"Bearer %s\" % token },\n  json = {\n    \"description\": \"Better description\",\n    \"color\": \"#E529B0\"\n  }\n)\nprint(response.status_code)\nprint(response.json())\n"
      - lang: TypeScript
        source: "\nconst host = \"aec.cintoo.com\";\nconst accountUUID = \"...\";\nconst roleId = \"...\";\nconst token = \"...\";\n\nconst url = `https://${host}/api/2/accounts/${accountUUID}/roles/${roleId}`;\nconst res = await fetch(url, {\n  method: \"PUT\",\n  headers: {\n    \"Authorization\": `Bearer ${token}`,\n    \"Content-Type\": \"application/json\",\n  },\n  body: JSON.stringify(\n    {\n          \"description\": \"Better description\",\n          \"color\": \"#E529B0\"\n      }\n  ),\n});\n\nconsole.log(res.status);\nconst data = await res.json();\nconsole.log(data);\n"
components:
  parameters:
    accountRef:
      name: accountRef
      in: path
      required: true
      description: The Id or Urn of the account
      schema:
        oneOf:
        - $ref: '#/components/schemas/AccountUrn'
        - $ref: '#/components/schemas/AccountId'
    roleRef:
      name: roleRef
      in: path
      required: true
      description: The Id or Urn of the role
      schema:
        oneOf:
        - $ref: '#/components/schemas/RoleUrn'
        - $ref: '#/components/schemas/RoleId'
  schemas:
    RoleId:
      allOf:
      - $ref: '#/components/schemas/Uuid'
      example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
    RoleLegacyPermissions:
      type: array
      description: "Permissions given by the role, in the legacy format, among:\n  - `create_project`: Update, delete or restore projects created by a project manager\n  - `workzone`: Create, modify & delete Work Zones\n  - `view3d`: Overview, 3D view, Scan View\n  - `annotate`: Create, edit and delete annotations, assign notes to Team Members\n  - `measure`: Add and view 3D measurements\n  - `share`: Can share project\n  - `upload`: Upload or delete laser scans or 360° images and manage versions\n  - `download`: Export in E57 or download Reality Data via Cintoo Connect\n  - `upload_doc`: Upload and download documents and 3D models from BIM platforms or from desktop\n  - `manage_users`: Add / remove new Team Members and define permissions\n  - `create_asset`: Import, create, edit and delete tags\n  - `view_asset`: View and export tags\n  - `view_annotation`: View annotations\n  - `manage_savedview`: Create, edit and delete saved views\n  - `view_savedview`: View saved views\n  - `manage_cipm`: Manage Progress Monitoring Jobs\n"
      minItems: 1
      items:
        type: string
        enum:
        - create_project
        - workzone
        - view3d
        - annotate
        - measure
        - share
        - upload
        - download
        - upload_doc
        - manage_users
        - create_asset
        - view_asset
        - view_annotation
        - manage_savedview
        - view_savedview
        - manage_cipm
    ErrorBadRequest:
      type: object
      required:
      - status
      - title
      properties:
        status:
          type: integer
          format: int32
          enum:
          - 400
        title:
          type: string
          enum:
          - Bad Request
        detail:
          type: string
          description: human readable description of the error in english
    roleCreate:
      type: object
      required:
      - name
      properties:
        name:
          type: string
          example: BIM / VDC Manager
        description:
          type: string
          example: Can do anything except creating projects
        color:
          $ref: '#/components/schemas/Color'
        permissions:
          $ref: '#/components/schemas/RolePermissions'
        legacyPermissions:
          $ref: '#/components/schemas/RoleLegacyPermissions'
    Error:
      type: object
      required:
      - status
      - title
      properties:
        status:
          type: integer
          format: int32
        title:
          type: string
        detail:
          type: string
          description: human readable description of the error in english
        errorCode:
          type: string
          description: detailed code describing error, can be used to map to a localized message
        errorValues:
          type: object
          description: values implied in the error, typically an input parameter, can be used to include in a localized message
    AccountUrn:
      type: string
      description: '"urn:cintoo:account:" followed by an UUIDv4

        '
    Role:
      type: object
      required:
      - id
      - type
      - api1Id
      - name
      - description
      - color
      - createdBy
      - createdAt
      - updatedAt
      - permissions
      - legacyPermissions
      x-tags:
      - Role
      properties:
        id:
          readOnly: true
          $ref: '#/components/schemas/RoleUrn'
        type:
          type: string
          enum:
          - role
        name:
          type: string
          example: BIM / VDC Manager
        description:
          type: string
          example: Can do anything except creating projects
        color:
          $ref: '#/components/schemas/Color'
        createdBy:
          type:
          - string
          - 'null'
          allOf:
          - $ref: '#/components/schemas/UserUrn'
        createdAt:
          type:
          - string
          - 'null'
          allOf:
          - $ref: '#/components/schemas/DateTime'
        updatedAt:
          type:
          - string
          - 'null'
          allOf:
          - $ref: '#/components/schemas/DateTime'
        permissions:
          $ref: '#/components/schemas/RolePermissions'
        legacyPermissions:
          $ref: '#/components/schemas/RoleLegacyPermissions'
    UserUrn:
      type: string
      description: '"urn:cintoo:user:" followed by an UUIDv4

        '
    roleUpdate:
      type: object
      properties:
        name:
          type: string
          example: BIM / VDC Manager
        description:
          type: string
          example: Can do anything except creating projects
        color:
          $ref: '#/components/schemas/Color'
        permissions:
          type:
          - array
          - 'null'
          allOf:
          - $ref: '#/components/schemas/RolePermissions'
        legacyPermissions:
          type:
          - array
          - 'null'
          allOf:
          - $ref: '#/components/schemas/RoleLegacyPermissions'
    Uuid:
      type: string
      description: UUIDv4
      format: uuid
      example: 156fff1a-0ef7-4335-891a-627928a19e29
    Color:
      type: string
      pattern: ^#[0-9a-f]{6}$
      example: '#0698ec'
    AccountId:
      allOf:
      - $ref: '#/components/schemas/Uuid'
      example: 8196e320-8a4d-4d29-b0a9-077cd7ed3368
    RoleUrn:
      type: string
      description: '"urn:cintoo:role:" followed by an UUIDv4

        '
    DateTime:
      type: string
      format: date-time
      description: 'The date-time notation as defined by RFC 3339, section 5.6 (ex: 2017-08-18T12:41:31Z)'
      example: '2017-08-18T12:41:31Z'
    RolePermissions:
      type: array
      description: permissions given by the role. Please check the [permissions](#section/API-Specification/Permissions) section for the list of allowed combinations
      minItems: 1
      items:
        type: string
        enum:
        - project:project:delete
        - project:project:update-details
        - workzone:workzones:write
        - workzone:workzones:read
        - workzone:annotations:write
        - workzone:annotations:read
        - workzone:measurements:write
        - workzone:measurements:read
        - workzone:share-links:write
        - workzone:share-links:read
        - workzone:own-share-links:write
        - workzone:own-share-links:read
        - workzone:reality-data:read
        - workzone:reality-data:write
        - workzone:reality-data:transform
        - workzone:cad-model:transform
        - workzone:cad-model:read
        - workzone:import-jobs-reality-data:write
        - workzone:export-jobs-reality-data:read
        - workzone:export-jobs-reality-data:write
        - workzone:documents:write
        - workzone:documents:read
        - workzone:members:write
        - workzone:tags:write
        - workzone:tags:read
        - workzone:savedviews:write
        - workzone:savedviews:read
        - workzone:model-reports:read
        - workzone:model-reports:write
        - workzone:progress-monitoring-jobs:read
        - workzone:progress-monitoring-jobs:write
        - workzone:own-progress-monitoring-jobs:read
        - workzone:own-progress-monitoring-jobs:write
  responses:
    UnexpectedError:
      description: unexpected error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            '400':
              value:
                status: 400
                title: Bad Request
            '401':
              value:
                status: 401
                title: Unauthorized
            '403':
              value:
                status: 403
                title: Forbidden
            '404':
              value:
                status: 404
                title: Not Found
            '405':
              value:
                status: 405
                title: Method Not Allowed
            '406':
              value:
                status: 406
                title: Not Acceptable
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://aec.cintoo.com/oauth/authorize
          tokenUrl: https://aec.cintoo.com/oauth/token
          scopes: {}
          refreshUrl: https://aec.cintoo.com/oauth/token
x-tagGroups:
- name: General
  tags:
  - errors_list
  - internal_information
  - token_management
  - Permissions
  - Authentication
- name: Resources
  tags:
  - Resources
- name: Tenant
  tags:
  - Tenant
- name: Account
  tags:
  - Account
  - Subscription
  - Role
  - User
  - Group
  - Trusted Device
- name: Subscription
  tags:
  - Usage Report
- name: Project
  tags:
  - Project
  - Members
  - Workzone
- name: Project Data
  tags:
  - File
  - Annotation
  - Saved View
  - Share Link
  - Crop
  - Measurement
  - Tag List
  - Tag
- name: Jobs
  tags:
  - Progress Monitoring
  - Import Model
  - Export Scene
  - Segmentation
  - Video360
  - Import IDD
- name: Integrations
  tags:
  - Integrations
  - Konekt
  - Autodesk
  - Procore
- name: Tutorials
  tags:
  - tuto_upload_file
  - understand_tag_data