Skip to content

API reference

Members and roles

Everyone with access to the company, their roles, and linking logins to people.

4 actions · base URL https://api.bizisy.com/v1 · generated from the same definitions as the API.

List members and roles#

POST/v1/platform/members.listRead

Lists everyone who has, or was given, access to this organization: email, name, roles (owner, admin, hr, viewer, member), status, whether they have signed in yet (has_login) and the linked person_id. Read this before changing roles.

Who can call it
Manage key owner admin hr
MCP tool
platform_members_list on HR Assistant
Method
POST with a JSON body, or GET with the input as query parameters

Input

No input: send {}.

Returns

An array of objects with 8 fields

An array of objects:

  • membership_idstringrequired
  • user_idstringrequired
  • emailstringrequired
  • namestringrequired
  • rolesstring[]required
  • status"active" | "disabled"required
  • person_idstring | nullrequired
  • has_loginbooleanrequired

Errors

validation_failed unauthenticated forbidden not_found rate_limited internal

curl
curl https://api.bizisy.com/v1/platform/members.list \
  -H "Authorization: Bearer $BIZISY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
Response
{
  "data": [
    {
      "membership_id": "m1",
      "user_id": "usr1",
      "email": "ana@acme.test",
      "name": "Ana Ferreira",
      "roles": [
        "hr"
      ],
      "status": "active",
      "person_id": "p1",
      "has_login": true
    }
  ]
}

Change a member's role#

POST/v1/platform/members.set_roleWrite

Sets the single role of a member: owner, admin, hr, viewer or member. Only owners can grant or remove the owner role. The last owner cannot be demoted. Takes effect on their next request.

Who can call it
Manage key owner admin
MCP tool
platform_members_set_role on HR Assistant
Preview
?dry_run=true runs every check and saves nothing
Retries
An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity

Input

  • membership_idstringrequired
  • role"owner" | "admin" | "hr" | "viewer" | "member"required

Returns

8 fields
  • membership_idstringrequired
  • user_idstringrequired
  • emailstringrequired
  • namestringrequired
  • rolesstring[]required
  • status"active" | "disabled"required
  • person_idstring | nullrequired
  • has_loginbooleanrequired

Errors

validation_failed unauthenticated forbidden not_found conflict rate_limited internal

curl
curl https://api.bizisy.com/v1/platform/members.set_role \
  -H "Authorization: Bearer $BIZISY_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{"membership_id":"m1","role":"viewer"}'
Response
{
  "data": {
    "membership_id": "m1",
    "user_id": "usr1",
    "email": "ana@acme.test",
    "name": "Ana Ferreira",
    "roles": [
      "viewer"
    ],
    "status": "active",
    "person_id": "p1",
    "has_login": true
  }
}

Disable a member's access#

POST/v1/platform/members.disableDestructive

Disables a membership: their sessions and API keys stop working immediately. You cannot disable yourself or the last owner; only owners can disable owners.

Who can call it
Manage key owner admin
MCP tool
platform_members_disable on HR Assistant
Preview
?dry_run=true runs every check and saves nothing
Retries
An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity

Input

  • membership_idstringrequired

Returns

8 fields
  • membership_idstringrequired
  • user_idstringrequired
  • emailstringrequired
  • namestringrequired
  • rolesstring[]required
  • status"active" | "disabled"required
  • person_idstring | nullrequired
  • has_loginbooleanrequired

Errors

validation_failed unauthenticated forbidden not_found conflict rate_limited internal

curl
curl https://api.bizisy.com/v1/platform/members.disable \
  -H "Authorization: Bearer $BIZISY_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{"membership_id":"m1"}'
Response
{
  "data": {
    "membership_id": "m1",
    "user_id": "usr1",
    "email": "ana@acme.test",
    "name": "Ana Ferreira",
    "roles": [
      "hr"
    ],
    "status": "disabled",
    "person_id": "p1",
    "has_login": true
  }
}

POST/v1/platform/members.link_personWrite

Sets which person record a member's login belongs to (person_id), or clears it with person_id null. The link decides whose own profile, team and self-service data that login sees. Use it when someone signed in but their login is not linked to their person (for example after org_setup_init warns about it): take membership_id from platform_members_list and person_id from org_people_list. A person is linked to at most one login, so linking moves the person away from any other login. The person must exist and not be erased. Owners and admins only; only owners can relink an owner's login; nobody can move or clear the link of their own login once it is linked.

Who can call it
Manage key owner admin
MCP tool
platform_members_link_person on HR Assistant
Preview
?dry_run=true runs every check and saves nothing
Retries
An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity

Input

  • membership_idstringrequired
  • person_idstring | nullrequired

Returns

8 fields
  • membership_idstringrequired
  • user_idstringrequired
  • emailstringrequired
  • namestringrequired
  • rolesstring[]required
  • status"active" | "disabled"required
  • person_idstring | nullrequired
  • has_loginbooleanrequired

Errors

validation_failed unauthenticated forbidden not_found conflict rate_limited internal

Response
{
  "data": {
    "membership_id": "m1",
    "user_id": "usr1",
    "email": "ana@acme.test",
    "name": "Ana Ferreira",
    "roles": [
      "hr"
    ],
    "status": "active",
    "person_id": null,
    "has_login": true
  }
}

Something missing or wrong on this page? Write to hello@bizisy.com.

Developer docs