Onecli Team API

Provision team members programmatically. Requires admin role. Cloud only.

Operations 1

POST /team/provisions Provision a team member #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onecli-team-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onecli-team-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: OneCLI Agent Setup Team API
  version: '1.0'
  description: 'The OneCLI API lets you manage agents, secrets, policy rules, app connections, and user settings programmatically.


    **Base URL:** `https://api.onecli.sh/v1` (Cloud) or `http://localhost:10254/v1` (self-hosted)


    ## Authentication


    All endpoints require authentication via one of:


    - **API Key** — `Authorization: Bearer <key>` header. Generate keys in the dashboard or via `GET /v1/user/api-key`.

    - **Session** — Cookie-based session from the web dashboard.


    For organization-scoped API keys, include the `X-Project-Id` header to specify which project to operate on.

    '
servers:
- url: https://api.onecli.sh/v1
  description: OneCLI Cloud
- url: http://localhost:10254/v1
  description: Self-hosted (Docker)
security:
- bearerAuth: []
tags:
- name: Team
  description: Provision team members programmatically. Requires admin role. Cloud only.
paths:
  /team/provisions:
    post:
      operationId: provisionUser
      summary: Provision a team member
      description: 'Pre-creates a user account with its own project, a usable API key, a default

        agent, and a claim link. The API key works immediately, so agents can make

        requests before the user signs up. The user later opens the claim link to bind

        the account to their identity. Unclaimed provisions expire after 7 days and are

        cleaned up automatically.


        Requires an admin or owner role. Cloud only.

        '
      tags:
      - Team
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                role:
                  type: string
                  enum:
                  - admin
                  - member
                  default: member
                  description: Role the provisioned user will have in the organization.
                skipOnboarding:
                  type: boolean
                  default: true
                  description: Whether the user skips the onboarding wizard after claiming.
      responses:
        '201':
          description: User provisioned
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProvisionResult'
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Insufficient permissions (requires admin or owner)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ErrorEnvelope:
      type: object
      description: Envelope error shape used for authentication failures and service errors.
      properties:
        error:
          type: object
          properties:
            message:
              type: string
            type:
              type: string
              description: Error category (e.g. `authentication_error`).
    Error:
      description: 'Error responses take one of two shapes depending on the failing layer:

        route-level validation returns the flat shape (`{ "error": "..." }`),

        while authentication failures (401/403) and service errors (not-found,

        conflict, and service-level validation) return the envelope

        (`{ "error": { "message": "...", "type": "..." } }`).

        '
      oneOf:
      - $ref: '#/components/schemas/ErrorFlat'
      - $ref: '#/components/schemas/ErrorEnvelope'
    ProvisionResult:
      type: object
      description: Returned once when a user is provisioned. The API key is shown only here.
      properties:
        id:
          type: string
          description: Provision record ID.
        userId:
          type: string
          description: Placeholder user ID (becomes the real user after the claim).
        projectId:
          type: string
          description: Pre-created project ID.
        apiKey:
          type: string
          description: Project-scoped API key (`oc_…`), usable immediately.
        claimUrl:
          type: string
          description: Link the user opens to claim the account.
        expiresAt:
          type: string
          format: date-time
          description: When the unclaimed provision expires (7 days from creation).
    ErrorFlat:
      type: object
      description: Flat error shape used by route-level validation.
      properties:
        error:
          type: string
      required:
      - error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key obtained from the dashboard or `GET /user/api-key`