REST API Reference v2.1 -- Users and Teams
POST /users/provision
Provisions a new user account via SCIM 2.0-compatible endpoint. Requires users:admin scope. Request body follows SCIM schema: {"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"], "userName": "jdoe@example.com", "name": {"givenName": "Jane", "familyName": "Doe"}, "emails": [{"value": "jdoe@example.com", "primary": true}], "roles": [{"value": "member"}], "active": true}. The user receives an activation email with a link to set their password (unless SSO is configured).
Response includes the provisioned user with a platform-generated user ID: {"id": "user_abc123", "userName": "jdoe@example.com", "active": true, "roles": [{"value": "member"}], "meta": {"created": "2025-07-20T10:00:00Z", "resourceType": "User"}}. SCIM provisioning integrates with identity providers like Okta, Azure AD, and OneLogin for automated user lifecycle management.
GET /teams and POST /teams
Teams group users for access control and alert routing. GET /teams returns all teams with their members and assigned projects. POST /teams creates a new team: {"name": "Platform Security", "description": "Responsible for infrastructure and platform security", "members": [{"user_id": "user_abc123", "role": "lead"}, {"user_id": "user_def456", "role": "member"}], "projects": ["proj_xyz"]}. Team roles are lead (can manage team membership) and member (inherits team permissions).
Assign projects to teams via PUT /teams/:id/projects with {"project_ids": ["proj_xyz", "proj_qrs"]}. Team members inherit the team's role-based permissions on assigned projects. A user can belong to multiple teams, and their effective permissions are the union of all team permissions plus any individually assigned permissions.
PUT /users/:id/roles
Updates a user's role assignments at the organization or project level. Requires users:admin scope. Request body: {"org_role": "member", "project_roles": [{"project_id": "proj_xyz", "role": "admin"}, {"project_id": "proj_abc", "role": "viewer"}]}. Project-level roles override the organization-level role for that specific project.
Role changes take effect immediately and are logged in the audit trail. If the user is currently authenticated, their permissions update on the next API request without requiring re-authentication. To enforce immediate session invalidation, call POST /users/:id/sessions/revoke after updating roles.
Peer-reviewed and accepted for publication. Supplementary data available via linked endpoints.