Endpoints for querying organization members, updating their roles, and managing member statistics and quotas.
Query parameters:
Response example:
Request example:
Response example:
Create a new user and add the user to the organization. This endpoint creates new accounts only. If the email is already registered, the existing account is not reused and its password is not changed.
Request body:
Request example:
Response example:
The endpoint may return
Request example:
Response example:
Request example:
Returns HTTP 204 No Content on success.
Request example:
Response example:
Request body:
Response example:
Request body:
Response example:
Request body:
Each request accepts 1–100 non-empty member IDs and applies the same cap to every member.
Response example:
Use the target organization’s API key:
Returns the updated member details directly, using the same fields as the get member details endpoint.
Other IAM business errors use the standard OpenAPI error response with
List members
| Parameter | Type | Description |
|---|---|---|
userId | string | Exact user UUID lookup; cannot be combined with email |
email | string | Exact match on email address |
includeDeleted | boolean | Include deleted members; defaults to false |
maxResults | integer | Items per page; default 20, max 100 |
nextToken | string | Pagination cursor |
userId must be a non-empty standard UUID. Exact lookup by userId or email returns at most one member and does not return a new nextToken. If no member matches, the API returns 200 OK with an empty members array.
Request example:
Member status values
| Status | Description |
|---|---|
ENABLED | Active |
DISABLED | Disabled |
UNACTIVATED | Not yet activated |
APPROVE_PENDING | Pending approval |
APPROVE_DECLINED | Approval declined |
DELETED | Deleted |
Get member details
Create a member
| Field | Type | Required | Description |
|---|---|---|---|
email | string | Yes | New user email. Its domain must be verified and enabled for the organization |
name | string | Yes | User and member display name |
password | string | Yes | Initial password. It must meet the password-strength requirements and is never returned |
role | string | No | org_member or org_admin; defaults to org_member |
InvalidParameter, InvalidPassword, InvalidRole, EmailDomainRequired, EmailDomainNotSupported, or InsufficientSeats (HTTP 400), or EmailAlreadyExists (HTTP 409).
Member statistics
| Field | Description |
|---|---|
totalMembers | Total number of members |
billableMembers | Number of billable members |
adminMembers | Number of administrators |
purchasedSeats | Total purchased seats |
remainingSeats | Available seats |
Delete a member
Get member quota
| Field | Description |
|---|---|
planQuota | Quota from the subscription plan |
resourcePackageQuota | Quota from resource packages |
totalQuota | Total available quota |
sharedQuota | Shared pool quota |
Batch get member quotas
memberIds: Array of member IDs (1–100 items).
Update member Add-On Cap
addOnCap accepts a non-negative integer, null, or omission. null or omission means unlimited; 0 disables the quota.
Request example:
Batch update Add-On Cap
addOnCap accepts a non-negative integer, null, or omission; null or omission means unlimited.
Request example:
previousAddOnCap is omitted when the member was previously unlimited. Request validation may return InvalidBatchAddOnCapRequest, EmptyMemberIDs, TooManyMemberIDs, EmptyMemberIDAtIndex, or InvalidAddOnCapFormat.
Update member role
PUT /v1/organizations/{organization_id}/members/{member_id}/role
Set an organization member’s role to Organization Admin, Organization Member, Config Admin, or Directory. Available for CN / Global and Teams / Enterprise, using the same IAM role-change capability as the dashboard.
Authentication and permissions
Use the target organization’s API key: Authorization: Bearer <api_key>. The key must belong to the organization in the path. Service account credentials cannot call this endpoint. The member_id must belong to that organization.
Path parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
organization_id | string | Yes | Organization ID |
member_id | string | Yes | Member ID returned by a member query endpoint; this is not the user ID |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
role | string | Yes | org_admin: Organization Admin; org_member: Organization Member; org_config_admin: Config Admin; org_directory: Directory |
role cannot be omitted, null, or an empty string. The deprecated org_free_member and other roles are not supported. Setting a non-billable role again still triggers IAM entitlement reclamation and can retry an incomplete reclamation.
Success response (200 OK)
Returns the updated member details directly, using the same fields as the get member details endpoint.
Business restrictions
- At least one administrator (Organization Admin or Config Admin) must remain. Role transitions use the same IAM validation as the dashboard.
- Removed members cannot change roles; IAM rejects other unavailable member states.
- Role changes are prohibited while a Teams-to-Enterprise upgrade is pending activation.
- New assignments of Config Admin or Directory require the DirectoryRole rollout to be enabled for the organization; otherwise, the endpoint returns 403. Both are non-billable roles. Switching to them uses the IAM flow to release seats, remove billing entitlements, and revoke sessions. Switching back to a billable role requires an available seat; failures use the IAM compensation flow. Special-account restrictions match the dashboard.
Error responses
| Error code | HTTP status | Description |
|---|---|---|
BadRequest | 400 | Malformed request body, invalid member ID, or member state does not allow changes |
InvalidRole | 400 | Role is missing or unsupported |
OrgMemberAdminCountLacked | 400 | Cannot remove the last administrator role |
OrganizationPendingUpgrade | 400 | Organization is awaiting activation of a Teams-to-Enterprise upgrade |
Unauthorized | 401 | Missing or invalid credentials |
Forbidden | 403 | Credentials lack permission, or the new role is not enabled for the organization |
UserNotTeamMember | 404 | Member does not exist, was removed, or belongs to a different organization |
InternalError | 500 | Internal service error |
requestId, code, and message.

