Newstore users API

Users

Operations 5

GET /iam/users listUsers #
POST /iam/users createUser #
DELETE /iam/users/{id} destroyUser #
GET /iam/users/{id} showUser #
PUT /iam/users/{id} replaceUser #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/newstore-users-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

newstore-users-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: '1.0'
  title: NewStore Users API
  description: NewStore public APIs
  contact:
    email: support@newstore.com
    name: NewStore API Support
    url: https://developer.newstore.com
servers:
- url: https://dodici-demo.p.newstore.net/
security: []
tags:
- name: users
  description: Users
paths:
  /iam/users:
    get:
      description: Retrieves all available user accounts for the retailer. Searches if the query parameter is used.
      summary: listUsers
      tags:
      - users
      operationId: listUsers
      deprecated: false
      parameters:
      - name: q
        in: query
        required: false
        description: Query the resulting list by first/last name or email address.
        schema:
          type: string
      - name: associate_id
        in: query
        required: false
        description: Filter to get user with the given associate_id.
        schema:
          type: string
      - name: offset
        in: query
        required: false
        description: The offset to be used for the resulting user account list.
        schema:
          type: integer
          format: int32
          default: 0
          maximum: 1000000.0
          minimum: 0.0
      - name: count
        in: query
        required: false
        description: The number of requested user accounts.
        schema:
          type: integer
          format: int32
          default: 25
          maximum: 50.0
      - name: role
        in: query
        required: false
        description: The role of the users to filter by.
        schema:
          type: string
      responses:
        default:
          description: Default response
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '200':
          description: Returns all users.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/GetUsersResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/GetUsersResponse'
        '400':
          description: Bad Request, invalid query parameters.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '401':
          description: Unauthorized.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '403':
          description: Forbidden.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '429':
          description: Too Many Requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '500':
          description: Internal Server Error.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '502':
          description: Bad Gateway
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '503':
          description: Service Unavailable
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
      security:
      - oauth:
        - iam:users:read
    post:
      description: 'Creates a new user account.


        To assign roles to a new user account, provide the IDs of the relevant roles in the `roles` property.

        To retrieve the role IDs, use the [List roles method](#operation/ListRoles).


        If the `external_directory` property is set to `false`, the user account is created

        in Auth0 as well and an email with password setup instructions is sent. The user can then use these

        credentials to log into NewStore.


        **Note:** If the user has no roles assigned, they will be able to log in to NOM but will not be able to interact

        with NOM until you assign roles to the user to allow them to interact with the various apps. See the

        [Create user role](#operation/CreateRole) method.

        '
      summary: createUser
      tags:
      - users
      operationId: createUser
      deprecated: false
      parameters:
      - name: Content-Type
        in: header
        required: false
        description: ''
        schema:
          type: string
          enum:
          - application/json
      responses:
        default:
          description: Default response
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '201':
          description: The user account is created.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/User'
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '400':
          description: Bad Request, invalid request body.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '401':
          description: Unauthorized.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '403':
          description: Forbidden.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '409':
          description: The provided email address is already in use.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '412':
          description: One or more user roles used were not found.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '429':
          description: Too Many Requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '500':
          description: Internal server error.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '502':
          description: Bad Gateway
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '503':
          description: Service Unavailable
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
      security:
      - oauth:
        - iam:users:write
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PostUsersRequest'
        required: true
  /iam/users/{id}:
    delete:
      description: 'Deletes the user account with the specified ID.


        If the `external_directory` property is set to `false`, the user account will be deleted in Auth0 as well.


        If the `external_directory` property is set to `true`, the user account will not be deleted from the

        respective enterprise directory.

        '
      summary: destroyUser
      tags:
      - users
      operationId: destroyUser
      deprecated: false
      parameters:
      - name: id
        in: path
        required: true
        description: user id
        schema:
          type: string
      responses:
        default:
          description: Default response
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '204':
          description: The deletion request was successful.
          headers: {}
        '401':
          description: Unauthorized.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '403':
          description: Forbidden.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '404':
          description: User account was not found.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '429':
          description: Too Many Requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '500':
          description: Internal server error.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '502':
          description: Bad Gateway
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '503':
          description: Service Unavailable
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
      security:
      - oauth:
        - iam:users:write
    get:
      description: Retrieves the user account with the specified ID.
      summary: showUser
      tags:
      - users
      operationId: showUser
      deprecated: false
      parameters:
      - name: id
        in: path
        required: true
        description: user id
        schema:
          type: string
      responses:
        default:
          description: Default response
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '200':
          description: Returns specific user
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/User'
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '401':
          description: Unauthorized.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '403':
          description: Forbidden.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '404':
          description: User not found.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '429':
          description: Too Many Requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '500':
          description: Internal server error.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '502':
          description: Bad Gateway
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '503':
          description: Service Unavailable
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
      security:
      - oauth:
        - iam:users:read
    put:
      description: 'Updates the user account with the specified ID.


        If the `external_directory` property is changed to `false`, the user account will be created in

        Auth0 as well and an email with password setup instructions will be send. The user can then use

        these credentials to log into NewStore.


        **Note:** If the user has no roles assigned, they will be able to log in to NOM but will not be able to interact

        with NOM until you assign roles to the user to allow them to interact with the various apps. See the

        [Create user role](#operation/CreateRole) method..


        If the `external_directory` property is changed to `true`, the user account will be deleted from Auth0.

        The user then can login with the enterprise directory credentials.

        '
      summary: replaceUser
      tags:
      - users
      operationId: replaceUser
      deprecated: false
      parameters:
      - name: id
        in: path
        required: true
        description: user id
        schema:
          type: string
      - name: Content-Type
        in: header
        required: false
        description: ''
        schema:
          type: string
          enum:
          - application/json
      responses:
        default:
          description: Default response
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '200':
          description: The updated user account.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/User'
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '400':
          description: Bad Request, invalid request body.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '401':
          description: Unauthorized.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '403':
          description: Forbidden.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '404':
          description: User account was not found.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '412':
          description: One or more user roles used were not found.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '429':
          description: Too Many Requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '500':
          description: Internal server error.
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '502':
          description: Bad Gateway
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
        '503':
          description: Service Unavailable
          headers: {}
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
            application/json:
              schema:
                $ref: '#/components/schemas/Problem'
      security:
      - oauth:
        - iam:users:write
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PutUsersByIdRequest'
        required: true
components:
  schemas:
    RoleItem:
      title: RoleItem
      description: Needed for granting permissions per group not individually.
      type: object
      properties:
        id:
          description: Identifier of the role.
          type: string
        is_readonly:
          description: The role is read-only and not editable.
          type: boolean
        name:
          description: Name of the role.
          type: string
        updated_at:
          type: string
          format: date-time
      required:
      - id
      - name
    PaginatedResponse:
      title: PaginatedResponse
      description: Contains default fields for paginatable APIs.
      type: object
      properties:
        count:
          description: Contains the count of returned elements.
          type: integer
          format: int32
        offset:
          description: Contains the current offset.
          type: integer
          format: int32
        total:
          description: Contains the total count of elements.
          type: integer
          format: int32
      required:
      - count
      - offset
      - total
    Problem:
      title: Problem
      type: object
      properties:
        detail:
          description: A human readable explanation specific to this occurrence of the problem that is helpful to locate the problem and give advice on how to proceed. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
          example: some description for the error situation
          type: string
        error_code:
          type: string
        instance:
          description: A URI reference that identifies the specific occurrence of the problem, e.g. by adding a fragment identifier or sub-path to the problem type. May be used to locate the root of this problem in the source code.
          example: /some/uri-reference#specific-occurrence-context
          type: string
        message:
          type: string
        messages:
          type: array
          items:
            type: string
        request_id:
          type: string
        status:
          description: The HTTP status code generated by the origin server for this occurrence of the problem.
          type: integer
          minimum: 100.0
          format: int32
          exclusiveMaximum: 600.0
        title:
          description: A short summary of the problem type. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
          example: some title for the error situation
          type: string
        type:
          description: A URI reference that uniquely identifies the problem type only in the context of the provided API. Opposed to the specification in RFC-7807, it is neither recommended to be dereferenceable and point to a human-readable documentation nor globally unique for the problem type.
          example: /some/uri-reference
          type: string
          default: about:blank
    User:
      title: User
      type: object
      properties:
        associate_id:
          description: External identifier for the NewStore plattform. Formerly known as "newstore_id".
          type: string
        created_at:
          type: string
          format: date-time
        email:
          description: Email address of the user.
          type: string
        external_directory:
          description: User is managed by an external directory.
          type: boolean
        first_name:
          description: First name of the user.
          type: string
        id:
          description: Identifier of the user.
          type: string
        is_active:
          description: Whether the user can login or not.
          type: boolean
        last_login_at:
          description: Shows last login time of the user. If user never logged in the property is not presence.
          type: string
          format: date-time
        last_name:
          description: Last name of the user.
          type: string
        phone:
          description: Telephone number of the user.
          type: string
        roles:
          description: List of roles the user is assigned to.
          type: array
          items:
            $ref: '#/components/schemas/RoleItem'
        updated_at:
          type: string
          format: date-time
    PutUsersByIdRequest:
      title: PutUsersByIdRequest
      type: object
      properties:
        external_directory:
          description: User is managed by an external directory.
          type: boolean
        first_name:
          description: First name of the user.
          type: string
        is_active:
          description: Whether the user can login or not.
          type: boolean
        last_name:
          description: Last name of the user.
          type: string
        phone:
          description: Telephone number of the user.
          type: string
        roles:
          description: List of role names the user is assigned to.
          type: array
          items:
            type: string
      required:
      - external_directory
      - first_name
      - is_active
      - last_name
      - phone
      - roles
    PostUsersRequest:
      title: PostUsersRequest
      type: object
      properties:
        email:
          description: Email address of the user.
          type: string
        external_directory:
          description: User is managed by an external directory.
          type: boolean
        first_name:
          description: First name of the user.
          type: string
        is_active:
          description: Whether the user can login or not.
          type: boolean
        last_name:
          description: Last name of the user.
          type: string
        phone:
          description: Telephone number of the user.
          type: string
        roles:
          description: List of role names the user is assigned to.
          type: array
          items:
            type: string
      required:
      - email
    GetUsersResponse:
      title: GetUsersResponse
      description: Gets all users
      type: object
      properties:
        elements:
          type: array
          items:
            $ref: '#/components/schemas/User'
        pagination_info:
          type: object
          allOf:
          - $ref: '#/components/schemas/PaginatedResponse'
          - description: Contains default fields for paginatable APIs.
  securitySchemes:
    oauth:
      type: oauth2
      flows:
        clientCredentials:
          scopes:
            catalog:import-schemas:read: Grants privileges to read import schema
            catalog:import-schemas:write: Grants privileges to write import schema
            catalog:pricebook-export:read: Grants privileges to export pricebook data
            catalog:product-export:read: Grants privileges to export product data
            checkout:carts:read: Grants privileges to read cart data
            checkout:carts:write: Grants privileges to write cart data
            clienteling:profile:read: Grants privileges to read clienteling profiles
            customer:profile:read: Grants privileges to read API customer data
            customer:profile:write: Grants privileges to modify API customer data
            newstore:configuration:read: Grants privileges to read configuration
            newstore:configuration:write: Grants privileges to write configuration
            fiscalization:orders:read: View orders with fiscal transactions and signatures
            fiscalization:orders:write: Create orders with fiscal transactions and signatures
            shipments:read: Read Shipping Options and Audits
            iam:providers:read: ' Grants read privileges to provider resources'
            iam:providers:write: ' Grants write privileges to provider resources'
            iam:roles:read: ' Grants privileges to read roles data'
            iam:roles:write: ' Grants privileges to write roles data'
            iam:users:read: ' Grants privileges to read user data'
            iam:users:write: ' Grants privileges to write user data'
            inventory:reservations:read: Allows access to retrieve reservations
            inventory:reservations:write: Allows access to create and update reservations
            promotions:config:read: Grants privileges to read configuration
            promotions:config:write: Grants privileges to write into configuration
            promotions:reason-codes:read: Grants privileges to list reason codes
            promotions:reason-codes:write: Grants privileges to create and update reason codes
            audit-events:read: Grants read access to the tenant's audit events.
            taxes:preview-transactions:write: Preview tax transactions
            taxes:transactions:read: Read tax transactions
          tokenUrl: https://id.p.newstore.net/auth/realms/dodici-demo/protocol/openid-connect/token