People and groups
People are the users of your organization, and groups collect them so access can be granted once. Invite, enable, disable and remove users, and manage group membership.
List groups
Lists every group in the organization by name, with its member count, live role binding count and whether it is the built-in Everyone group.
Create group
Creates a group with a name and optional description in the given organization. Requires the Org Owner or Org Admin role. Returns 201 with the group; a name already in use returns 409.
Delete group
Deletes a group together with its memberships and role bindings, revoking the access they gave. Requires the Org Owner or Org Admin role, and an Org Owner when the group holds Org Owner; the Everyone group cannot be deleted (409). Returns 204 with no body.
Get group
Returns one group with its description, its members and who created and last updated it.
Update group
Renames a group or changes its description; omitted fields stay unchanged. Requires the Org Owner or Org Admin role, and an Org Owner when the group holds Org Owner; renaming the Everyone group returns 409. Returns the group with its members.
Remove group member
Removes one user from a group and revokes the access the group gave them. Requires the Org Owner or Org Admin role, and an Org Owner when the group holds Org Owner; the Everyone group returns 409. Returns 404 when the user is not a member, and 204 with no body otherwise.
Add group member
Adds one user of the group's organization to the group; an existing member is left as is. Requires the Org Owner or Org Admin role, and an Org Owner when the group holds Org Owner; the Everyone group returns 409. Returns 201 with the group and its members.
List users
Lists every user in the organization with profile, activation, last-seen and preference fields. Requires permission to view users.
Create user
Creates a user in the given organization, adds them to the Everyone group and, unless `send_invitation` is false, emails an invitation whose outcome the `invitation` field reports without failing the create. Requires the Org Owner or Org Admin role. Returns 201 with the user, or 409 when the email is taken or the organization has reached its user limit.
Delete user
Permanently deletes a user and their group memberships. Requires the Org Owner or Org Admin role, and only an Org Owner may delete an Org Owner (403). Returns 409 for the caller, the organization's last Org Owner, or a user recorded as the author of other records; disable such a user instead.
Get user
Returns one user with their profile plus `effective_permission_keys` and `accessible_project_ids`, the access picture the list omits. Requires permission to view users.
Update user
Updates a user's name, first and last name, email, description, password, preferences or selected git credential; only the fields sent change. Requires the Org Owner or Org Admin role, and only an Org Owner may edit an Org Owner; changing the caller's own email returns 403. A new password ends the user's open sessions; returns the user.
Disable user
Disables a user, idempotently: they can no longer use Jaah and their open sessions end, while their record and history stay. Requires the Org Owner or Org Admin role, and only an Org Owner may disable an Org Owner; the caller and the organization's last Org Owner return 409. Returns the user.
Enable user
Re-enables a disabled user, idempotently, so they can use Jaah again; sessions ended by the disable stay ended. Requires the Org Owner or Org Admin role, and only an Org Owner may enable an Org Owner; a user disabled by Jaah support returns 403. Returns the user.
Resend invitation
Emails the invitation again to a user who has not activated their account yet, and returns the recipient address. Requires the Org Owner or Org Admin role. Returns 409 once the user is active, while disabled or when email sending is not set up, 429 over the invitation rate limit, and 502 when the send fails.
Add membership
Adds a user to the group named by `group`. Requires the Org Owner or Org Admin role, and an Org Owner when the group holds Org Owner. Returns 201 with the membership, or 409 when it already exists or the group is Everyone.
Remove membership
Removes one group membership from a user and revokes the access it gave them. Requires the Org Owner or Org Admin role, and an Org Owner when the group holds Org Owner. The Everyone membership cannot be removed (409); returns 204 with no body.