Organization ID
Origins to add
Add a sign-in alias to an identity user. The alias is live at once: the caller attests that the person owns the address.
Fails with status 409 when the address is the account's own email, already one of its aliases, or in use by another account in the organization.
Identity user ID
The address to add
Organization ID
The updated identity user
Add a role to a user profile. Idempotent — if the role is already present, the profile is returned unchanged without an update call. Preserves all other roles.
Profile ID
Role string to add (e.g. 'public-files')
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
The updated profile (or the original, unchanged, if the role was already present).
Deactivate (soft-delete) a user profile.
Profile ID
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
Find the identity user that signs in with an address — the canonical
email or one of its aliases. Exact, case-insensitive, one request
(not a page of listIdentityUsers, whose search cannot see aliases).
Returns null when no account in the organization uses the address.
Any address the account signs in with
Organization ID
Get one identity user.
Identity user ID (not the profile ID)
Organization ID
Get a single user profile by ID.
Profile ID
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
List allowed origins for an organization.
Organization ID
List identity users in an organization.
Organization ID (required — identity users are always org-scoped)
List user profiles for an organization.
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
Permanently purge a user profile (GDPR hard delete).
Unlike deactivateProfile, this REMOVES the profile, its identity user, sessions, trusted devices, and access tokens outright — it cannot be undone. The server refuses org/tenant owners, and the endpoint is disabled server-side unless the identity service has purging enabled (a disabled server responds 404).
Profile ID
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
Per-store deletion counts
Remove origin(s) from the allowed list for an organization.
Organization ID
Origins to remove
Remove a sign-in alias. If it was the contact address, mail returns to the account's email. The account's email itself cannot be removed (status 409); an address that is not one of the account's aliases is status 404 — the same status as an unknown user, so check the account exists first if you need to tell the two apart.
Identity user ID
The alias to remove
Organization ID
The updated identity user
Remove a role from a user profile. Idempotent — if the role is not present, the profile is returned unchanged without an update call. Preserves all other roles.
Profile ID
Role string to remove
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
The updated profile (or the original, unchanged, if the role was absent).
Replace all allowed origins for an organization.
Organization ID
Complete list of allowed origins (replaces existing)
Choose where an identity user's mail goes: the account's email or one of its verified aliases (status 400 otherwise).
Identity user ID
The contact address
Organization ID
The updated identity user
Update a user profile's core fields.
Roles are stripped defensively — they cannot be set via this method. Use addRole / removeRole for role changes.
Profile ID
Fields to update
OptionalbrandOrgId: stringOrganization ID. If omitted, defaults to the org associated with the API key.
Add origin(s) to the allowed list for an organization.