Prewave Users API
🆕 NEW - API to manage users in the public network. Available from February 2026.
🆕 NEW - API to manage users in the public network. Available from February 2026.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/prewave-users-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Public Prewave Users API
description: Documentation of the Public Prewave API.
version: '1.0'
servers:
- url: https://api.prewave.com
description: Production Environment
security:
- Token authentication: []
tags:
- name: Users
description: 🆕 NEW - API to manage users in the public network. Available from February 2026.
paths:
/public/v1/users:
get:
tags:
- Users
summary: Search and list users
description: '### Overview
Retrieve a comprehensive list of all users within your customer''s scope. This endpoint is ideal for auditing, synchronization, or building user-management dashboards.
### Use Cases
- **Auditing**: Regularly export user lists to verify access levels.
- **Synchronization**: Keep an external user directory in sync with Prewave.
- **Management**: Build custom internal dashboards for your organization.
### Filtering
Refine your results using the following optional parameters:
- **Search**: Matches against name or email (fuzzy matching).
- **Active**: Filter by account status (active/deactivated).
- **Confirmed**: Filter by whether the user has verified their account via email.
### Pagination
This endpoint returns a paginated result. You can control the page size and offset using the `page` and `size` parameters.
- **Default Size**: 100
- **Max Size**: 1000
### Related Operations
- **Retrieve Detail**: GET /public/v1/users/{userId}
- **Onboard User**: POST /public/v1/users
- **Manage Roles**: GET /public/v1/users/{userId}/roles
- **Update User**: PATCH /public/v1/users/{userId}
### Required Permission
`access_public_users`'
operationId: get
parameters:
- name: search
in: query
description: Fuzzy search against **first name**, **last name**, or **email**.
required: false
schema:
type: string
example: john
- name: active
in: query
description: Filter by account status. `true` for active users, `false` for deactivated ones.
required: false
schema:
type: boolean
example: true
- name: confirmed
in: query
description: Filter by confirmation status. `true` for users who have verified their email.
required: false
schema:
type: boolean
example: false
- name: page
in: query
description: Zero-based page index (0..N)
required: false
schema:
minimum: 0
type: integer
default: 0
- name: size
in: query
description: The size of the page to be returned
required: false
schema:
minimum: 1
type: integer
default: 100
responses:
'200':
description: Successfully retrieved the paginated list of users.
content:
application/json:
schema:
type: object
properties:
content:
type: array
items:
$ref: '#/components/schemas/PublicUserResponse'
size:
type: integer
format: int32
number:
type: integer
format: int32
totalElements:
type: integer
format: int32
totalPages:
type: integer
format: int32
numberOfElements:
type: integer
format: int32
first:
type: boolean
last:
type: boolean
empty:
type: boolean
examples:
Paginated User List:
summary: Example of a successful paginated response
description: Paginated User List
value: '{"content":[{"id":123,"active":true,"confirmed":true,"firstname":"John","lastname":"Doe","email":"john.doe@company.com","customer":{"id":8797983,"name":"Prewave"},"organization":{"id":64573456,"name":"Prewave"},"plan":{"id":34345453,"name":"Admin","validFrom":1614616305.000000000},"teams":[],"roles":[{"id":1829,"name":"GRANT_USER_MANAGER_ACCESS","description":null}]}],"totalElements":1,"totalPages":1,"size":500,"number":0,"numberOfElements":1,"first":true,"last":true,"empty":false}'
'403':
description: '403 Forbidden - Authentication or authorization failure. This status code is returned when: (1) the request lacks valid authentication credentials (missing or invalid X-Auth-Token header), or (2) the authenticated user does not have the required permission to access this resource.'
content:
application/json:
schema:
$ref: '#/components/schemas/AccessDeniedErrorDTO'
examples:
Access denied example:
summary: User lacks necessary permissions or authentication
value: "{\n \"loggedIn\": true,\n \"code\": \"access_denied\",\n \"message\": \"Access denied: you don't have necessary permissions to access this resource\",\n \"solution\": \"Contact support for appropriate permissions\"\n }"
'500':
description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
examples:
Error - Server Error:
summary: Unexpected server error
value: "{\n \"code\": \"internal_error\",\n \"message\": \"An unexpected error occurred\",\n \"solution\": \"Please try again later or contact support\"\n }"
'429':
description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
content:
application/json:
schema:
$ref: '#/components/schemas/ApiRateLimitResponse'
examples:
Rate limit exceeded example:
summary: API rate limit exceeded
value: "{\n \"error\": \"API rate limit exceeded\",\n \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n \"requestLimit\": 100,\n \"requestCount\": 100,\n \"limits\": [\n {\n \"requestLimit\": 100,\n \"timeInSeconds\": 10\n },\n {\n \"requestLimit\": 500,\n \"timeInSeconds\": 60\n }\n ],\n \"currentTime\": \"2026-01-15T10:30:00\",\n \"nextResetAt\": \"2026-01-15T10:30:10\"\n }"
post:
tags:
- Users
summary: Invite and onboard a new user
description: '### Overview
Onboard a new member to your organization. This action triggers an automated invitation email.
### Use Cases
- **New Employee**: Onboard a new team member with their required access level.
- **External Partner**: Invite a stakeholder to collaborate with specific roles.
- **Automation**: Programmatically create users as part of your internal onboarding flow.
### Invitation Lifecycle
1. **Request**: You provide the user''s email and initial configuration.
2. **Created**: The user account is initialized with `confirmed: false`.
3. **Activation**: The user receives an email to set their password and log in.
4. **Completion**: Once logged in, the user''s status changes to `confirmed: true`.
### Workflow Tip
- Use the `Location` header in the response to immediately access the new user''s resource URI.
- You can pre-assign **teams** and **roles** during the invitation to ensure the user has access from their first login.
### Related Operations
- **List Users**: GET /public/v1/users
- **Discover Roles**: GET /public/v1/users/roles/available
- **Assign Roles**: POST /public/v1/users/{userId}/roles
### Required Permission
`manage_public_users`'
operationId: invite
requestBody:
description: User configuration for invitation.
content:
application/json:
schema:
$ref: '#/components/schemas/PublicCreateUserRequest'
examples:
Basic Invitation:
summary: Minimum required data to invite a user
description: Basic Invitation
value: '{"email":"new.user@company.com","firstname":"New","lastname":"User","teamIds":[1,2],"roleNames":["ROLE_USER_MANAGER"],"planId":5}'
required: true
responses:
'201':
description: Created - Invitation sent successfully. See Location header.
content:
application/json:
schema:
$ref: '#/components/schemas/PublicUserResponse'
examples:
Created User Response:
description: Created User Response
value: '{"id":4523345,"active":true,"confirmed":false,"firstname":"New","lastname":"User","email":"new.user@company.ai","customer":{"id":8797983,"name":"Prewave"},"organization":{"id":64573456,"name":"Prewave"},"plan":{"id":5,"name":"Admin","validFrom":1614616305.000000000},"teams":[],"roles":[{"id":1829,"name":"ROLE_USER_MANAGER","description":null}]}'
'400':
description: Bad Request - Validation error (e.g., invalid email format).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
examples:
Validation Error:
description: Validation Error
value: '{"code":"invalid_request","message":"Email must be a valid email address."}'
'403':
description: '403 Forbidden - Authentication or authorization failure. This status code is returned when: (1) the request lacks valid authentication credentials (missing or invalid X-Auth-Token header), or (2) the authenticated user does not have the required permission to access this resource.'
content:
application/json:
schema:
$ref: '#/components/schemas/AccessDeniedErrorDTO'
examples:
Access denied example:
summary: User lacks necessary permissions or authentication
value: "{\n \"loggedIn\": true,\n \"code\": \"access_denied\",\n \"message\": \"Access denied: you don't have necessary permissions to access this resource\",\n \"solution\": \"Contact support for appropriate permissions\"\n }"
'500':
description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
examples:
Error - Server Error:
summary: Unexpected server error
value: "{\n \"code\": \"internal_error\",\n \"message\": \"An unexpected error occurred\",\n \"solution\": \"Please try again later or contact support\"\n }"
'429':
description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
content:
application/json:
schema:
$ref: '#/components/schemas/ApiRateLimitResponse'
examples:
Rate limit exceeded example:
summary: API rate limit exceeded
value: "{\n \"error\": \"API rate limit exceeded\",\n \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n \"requestLimit\": 20,\n \"requestCount\": 20,\n \"limits\": [\n {\n \"requestLimit\": 20,\n \"timeInSeconds\": 10\n },\n {\n \"requestLimit\": 100,\n \"timeInSeconds\": 60\n }\n ],\n \"currentTime\": \"2026-01-15T10:30:00\",\n \"nextResetAt\": \"2026-01-15T10:30:10\"\n }"
/public/v1/users/{userId}:
get:
tags:
- Users
summary: Retrieve detailed user profile
description: '### Overview
Fetch the complete profile of a specific user. This includes organizational details, active subscriptions (plans), and assigned access controls.
### Use Cases
- **Profile Inspection**: Verify the current configuration of a specific user.
- **Pre-Update Check**: Retrieve the current state before performing a partial update.
- **Identity Verification**: Confirm the email and name associated with a numerical ID.
### Identification
The `{userId}` is a unique numerical identifier.
### Getting User ID
- To find users and their numerical IDs, use the Users Management API:
- `GET /public/v1/users` - Retrieve all users with their `id` field.
- The `id` field in the user response is the `{userId}` used in this endpoint''s path parameter.
### Related Operations
- **Update Profile**: PATCH /public/v1/users/{userId}
- **Manage Roles**: POST /public/v1/users/{userId}/roles
### Required Permission
`access_public_users`'
operationId: getById
parameters:
- name: userId
in: path
description: The unique numerical identifier of the target user. If you do not have this ID, you can find it by searching for the user via `GET /public/v1/users`.
required: true
schema:
type: integer
format: int32
example: 4523345
responses:
'200':
description: User details retrieved successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/PublicUserResponse'
examples:
Full User Profile:
description: Full User Profile
value: '{"id":4523345,"active":true,"confirmed":true,"firstname":"Max","lastname":"Mustermann","email":"max.mustermann@prewave.ai","customer":{"id":8797983,"name":"Prewave"},"organization":{"id":64573456,"name":"Prewave"},"plan":{"id":34345453,"name":"Admin","validFrom":1614616305.000000000},"teams":[],"roles":[{"id":1829,"name":"ROLE_USER_MANAGER","description":null},{"id":98790,"name":"GRANT_TEAM_MANAGER_ACCESS","description":null}]}'
'404':
description: Not Found - User not found or outside organization scope.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
examples:
User Not Found:
description: User Not Found
value: '{"code":"user_not_found","message":"User with ID 4523345 could not be found."}'
'403':
description: '403 Forbidden - Authentication or authorization failure. This status code is returned when: (1) the request lacks valid authentication credentials (missing or invalid X-Auth-Token header), or (2) the authenticated user does not have the required permission to access this resource.'
content:
application/json:
schema:
$ref: '#/components/schemas/AccessDeniedErrorDTO'
examples:
Access denied example:
summary: User lacks necessary permissions or authentication
value: "{\n \"loggedIn\": true,\n \"code\": \"access_denied\",\n \"message\": \"Access denied: you don't have necessary permissions to access this resource\",\n \"solution\": \"Contact support for appropriate permissions\"\n }"
'500':
description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
examples:
Error - Server Error:
summary: Unexpected server error
value: "{\n \"code\": \"internal_error\",\n \"message\": \"An unexpected error occurred\",\n \"solution\": \"Please try again later or contact support\"\n }"
'429':
description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
content:
application/json:
schema:
$ref: '#/components/schemas/ApiRateLimitResponse'
examples:
Rate limit exceeded example:
summary: API rate limit exceeded
value: "{\n \"error\": \"API rate limit exceeded\",\n \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n \"requestLimit\": 100,\n \"requestCount\": 100,\n \"limits\": [\n {\n \"requestLimit\": 100,\n \"timeInSeconds\": 10\n },\n {\n \"requestLimit\": 500,\n \"timeInSeconds\": 60\n }\n ],\n \"currentTime\": \"2026-01-15T10:30:00\",\n \"nextResetAt\": \"2026-01-15T10:30:10\"\n }"
patch:
tags:
- Users
summary: Update user profile and status
description: '### Overview
Modify profile details, subscription levels, or account status for an existing user.
### Use Cases
- **Profile Correction**: Correct a user''s name or contact details.
- **Plan Management**: Upgrade or downgrade a user''s subscription (e.g., Enterprise vs. Basic).
- **Status Management**: Activate or deactivate user access.
- **Access Refinement**: Update team associations.
### Identification
The `{userId}` is a unique numerical identifier.
### Getting User ID
- To find users and their numerical IDs, use the Users Management API:
- `GET /public/v1/users` - Retrieve all users with their `id` field.
- The `id` field in the user response is the `{userId}` used in this endpoint''s path parameter.
### Partial Updates
This endpoint supports **partial updates**. Only the fields provided in the request body will be changed; omitted fields and fields set to null will retain their current values.
### Related Operations
- **Get Detail**: GET /public/v1/users/{userId}
- **Manage Roles**: POST /public/v1/users/{userId}/roles
### Required Permission
`manage_public_users`'
operationId: update
parameters:
- name: userId
in: path
description: The unique numerical identifier of the target user. If you do not have this ID, you can find it by searching for the user via `GET /public/v1/users`.
required: true
schema:
type: integer
format: int32
example: 4523345
requestBody:
description: Fields to update. Omit fields to keep current values.
content:
application/json:
schema:
$ref: '#/components/schemas/PublicUpdateUserRequest'
examples:
Profile, Plan & Status Update:
summary: Update multiple fields including status
description: Profile, Plan & Status Update
value: '{"firstname":"Updated","lastname":"User","planId":1234,"active":true}'
Deactivate User:
summary: Disable user access
description: Deactivate User
value: '{"firstname":null,"lastname":null,"planId":null,"active":false}'
required: true
responses:
'200':
description: User profile and status successfully updated.
content:
application/json:
schema:
$ref: '#/components/schemas/PublicUserResponse'
examples:
Updated User Profile:
description: Updated User Profile
value: '{"id":4523345,"active":true,"confirmed":true,"firstname":"Updated","lastname":"User","email":"user@company.ai","customer":{"id":8797983,"name":"Prewave"},"organization":{"id":64573456,"name":"Prewave"},"plan":{"id":1234,"name":"Enterprise","validFrom":1614616305.000000000},"teams":[],"roles":[]}'
'404':
description: Not Found - The specified user does not exist.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
'403':
description: '403 Forbidden - Authentication or authorization failure. This status code is returned when: (1) the request lacks valid authentication credentials (missing or invalid X-Auth-Token header), or (2) the authenticated user does not have the required permission to access this resource.'
content:
application/json:
schema:
$ref: '#/components/schemas/AccessDeniedErrorDTO'
examples:
Access denied example:
summary: User lacks necessary permissions or authentication
value: "{\n \"loggedIn\": true,\n \"code\": \"access_denied\",\n \"message\": \"Access denied: you don't have necessary permissions to access this resource\",\n \"solution\": \"Contact support for appropriate permissions\"\n }"
'500':
description: 500 Internal Server Error - An unexpected error occurred on the server. The request may or may not have been processed.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorDTO'
examples:
Error - Server Error:
summary: Unexpected server error
value: "{\n \"code\": \"internal_error\",\n \"message\": \"An unexpected error occurred\",\n \"solution\": \"Please try again later or contact support\"\n }"
'429':
description: '429 Too Many Requests - API rate limit exceeded. The request has been rejected because the rate limit for this endpoint has been exceeded. Default rate limits: GET requests - 100 per 10 seconds, 500 per minute; POST/PUT/PATCH/DELETE requests - 20 per 10 seconds, 100 per minute. For increased access, please contact customer success.'
content:
application/json:
schema:
$ref: '#/components/schemas/ApiRateLimitResponse'
examples:
Rate limit exceeded example:
summary: API rate limit exceeded
value: "{\n \"error\": \"API rate limit exceeded\",\n \"message\": \"You have reached the maximum allowed requests. Please try again later or upgrade your plan for increased access\",\n \"requestLimit\": 20,\n \"requestCount\": 20,\n \"limits\": [\n {\n \"requestLimit\": 20,\n \"timeInSeconds\": 10\n },\n {\n \"requestLimit\": 100,\n \"timeInSeconds\": 60\n }\n ],\n \"currentTime\": \"2026-01-15T10:30:00\",\n \"nextResetAt\": \"2026-01-15T10:30:10\"\n }"
components:
schemas:
PublicUserResponse:
required:
- active
- confirmed
- customer
- id
- roles
- teams
type: object
properties:
id:
type: integer
format: int32
example: null
active:
type: boolean
example: null
confirmed:
type: boolean
example: null
firstname:
type:
- string
- 'null'
example: null
lastname:
type:
- string
- 'null'
example: null
email:
type:
- string
- 'null'
example: null
customer:
$ref: '#/components/schemas/PublicUserResponseCustomerDTO'
organization:
allOf:
- $ref: '#/components/schemas/PublicUserResponseOrganizationDTO'
example: null
plan:
allOf:
- $ref: '#/components/schemas/PublicUserResponsePlanDTO'
example: null
teams:
type: array
items:
$ref: '#/components/schemas/PublicUserResponseTeamDTO'
example: null
roles:
type: array
items:
$ref: '#/components/schemas/PublicUserRoleDTO'
example: null
example: null
ApiRateLimitResponse:
type: object
properties:
error:
type: string
description: Error type identifier
example: RateLimitExceeded
message:
type: string
description: Human-readable error message explaining the rate limit violation
example: API rate limit exceeded. Please reduce your request rate.
requestLimit:
type: integer
description: Maximum number of requests allowed in the current time window
format: int32
example: 100
requestCount:
type: integer
description: Number of requests made in the current time window
format: int32
example: 101
limits:
type: array
description: All rate limits that apply to this endpoint, showing different time windows
items:
$ref: '#/components/schemas/ApiRateLimitTimeRequestLimit'
example: null
currentTime:
type: string
description: Current server time in ISO 8601 format
format: date-time
example: '2026-01-19T10:30:00'
nextResetAt:
type: string
description: Time when the rate limit will reset in ISO 8601 format
format: date-time
example: '2026-01-19T10:30:10'
description: Response returned when API rate limit is exceeded (HTTP 429)
example: null
PublicUserRoleDTO:
required:
- id
- name
type: object
properties:
id:
type: integer
format: int32
example: null
name:
type: string
example: null
description:
type:
- string
- 'null'
example: null
example: null
ApiRateLimitTimeRequestLimit:
type: object
properties:
requestLimit:
type: integer
description: Maximum number of requests allowed in this time window
format: int32
example: 100
timeInSeconds:
type: integer
description: Time window duration in seconds
format: int32
example: 10
description: Rate limit configuration for a specific time window
example: null
PublicUpdateUserRequest:
type: object
properties:
firstname:
type:
- string
- 'null'
example: null
lastname:
type:
- string
- 'null'
example: null
planId:
type:
- integer
- 'null'
format: int32
example: null
active:
type:
- boolean
- 'null'
example: null
example: null
PublicUserResponsePlanDTO:
required:
- id
- name
type: object
properties:
id:
type: integer
format: int32
example: null
name:
type: string
example: null
validFrom:
type:
- string
- 'null'
format: date-time
example: null
example: null
PublicUserResponseOrganizationDTO:
required:
- id
- name
type: object
properties:
id:
type: integer
format: int32
example: null
name:
type: string
example: null
example: null
AccessDeniedErrorDTO:
required:
- code
- loggedIn
- message
type: object
properties:
loggedIn:
type: boolean
example: null
permission:
type:
- string
- 'null'
example: null
code:
type: string
description: Error code
example: null
message:
type: string
description: Error message
example: null
solution:
type:
- string
- 'null'
description: Possible solution to the error
example: null
example: null
PublicUserResponseCustomerDTO:
required:
- id
- name
type: object
properties:
id:
type: integer
format: int32
example: null
name:
type: string
example: null
example: null
PublicUserResponseTeamDTO:
required:
- id
- name
type: object
properties:
id:
type: integer
format: int32
example: null
name:
type: string
example: null
example: null
PublicCreateUserRequest:
required:
- email
type: object
properties:
email:
minLength: 1
type: string
format: email
example: null
firstname:
type:
- string
- 'null'
example: null
lastname:
type:
- string
- 'null'
example: null
teamIds:
type:
- array
- 'null'
items:
type: integer
format: int32
example: null
example: null
roleNames:
type:
- array
- 'null'
items:
type: string
example: null
example: null
planId:
type:
- integer
- 'null'
format: int32
example: null
example: null
ErrorDTO:
required:
- code
- message
type: object
properties:
code:
type: string
description: Error code
example: null
message:
type: string
description: Error message
example: null
solution:
type:
- string
- 'null'
description: Possible solution to the error
example: null
description: Error response
example: null
securitySchemes:
Token_authentication:
type: apiKey
description: Generate an API token at https://www.prewave.com/management/api and paste it in here.
name: X-Auth-Token
in: header