API reference
Members and roles
Everyone with access to the company, their roles, and linking logins to people.
4 actions · base URL https://api.bizisy.com/v1 · generated from the same definitions as the API.
List members and roles#
POST/v1/platform/members.listRead
Lists everyone who has, or was given, access to this organization: email, name, roles (owner, admin, hr, viewer, member), status, whether they have signed in yet (has_login) and the linked person_id. Read this before changing roles.
- Who can call it
- Manage key owner admin hr
- MCP tool
platform_members_liston HR Assistant- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
No input: send {}.
Returns
An array of objects with 8 fields
An array of objects:
membership_idstringrequireduser_idstringrequiredemailstringrequirednamestringrequiredrolesstring[]requiredstatus"active" | "disabled"requiredperson_idstring | nullrequiredhas_loginbooleanrequired
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/platform/members.list \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'const res = await fetch('https://api.bizisy.com/v1/platform/members.list', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/members.list",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": [
{
"membership_id": "m1",
"user_id": "usr1",
"email": "ana@acme.test",
"name": "Ana Ferreira",
"roles": [
"hr"
],
"status": "active",
"person_id": "p1",
"has_login": true
}
]
}Change a member's role#
POST/v1/platform/members.set_roleWrite
Sets the single role of a member: owner, admin, hr, viewer or member. Only owners can grant or remove the owner role. The last owner cannot be demoted. Takes effect on their next request.
- Who can call it
- Manage key owner admin
- MCP tool
platform_members_set_roleon HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity
Input
membership_idstringrequiredrole"owner" | "admin" | "hr" | "viewer" | "member"required
Returns
8 fields
membership_idstringrequireduser_idstringrequiredemailstringrequirednamestringrequiredrolesstring[]requiredstatus"active" | "disabled"requiredperson_idstring | nullrequiredhas_loginbooleanrequired
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/platform/members.set_role \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"membership_id":"m1","role":"viewer"}'const res = await fetch('https://api.bizisy.com/v1/platform/members.set_role', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"membership_id": "m1",
"role": "viewer"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/members.set_role",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"membership_id": "m1",
"role": "viewer",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"membership_id": "m1",
"user_id": "usr1",
"email": "ana@acme.test",
"name": "Ana Ferreira",
"roles": [
"viewer"
],
"status": "active",
"person_id": "p1",
"has_login": true
}
}Disable a member's access#
POST/v1/platform/members.disableDestructive
Disables a membership: their sessions and API keys stop working immediately. You cannot disable yourself or the last owner; only owners can disable owners.
- Who can call it
- Manage key owner admin
- MCP tool
platform_members_disableon HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity
Input
membership_idstringrequired
Returns
8 fields
membership_idstringrequireduser_idstringrequiredemailstringrequirednamestringrequiredrolesstring[]requiredstatus"active" | "disabled"requiredperson_idstring | nullrequiredhas_loginbooleanrequired
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/platform/members.disable \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"membership_id":"m1"}'const res = await fetch('https://api.bizisy.com/v1/platform/members.disable', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"membership_id": "m1"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/members.disable",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"membership_id": "m1",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"membership_id": "m1",
"user_id": "usr1",
"email": "ana@acme.test",
"name": "Ana Ferreira",
"roles": [
"hr"
],
"status": "disabled",
"person_id": "p1",
"has_login": true
}
}Link a login to a person#
POST/v1/platform/members.link_personWrite
Sets which person record a member's login belongs to (person_id), or clears it with person_id null. The link decides whose own profile, team and self-service data that login sees. Use it when someone signed in but their login is not linked to their person (for example after org_setup_init warns about it): take membership_id from platform_members_list and person_id from org_people_list. A person is linked to at most one login, so linking moves the person away from any other login. The person must exist and not be erased. Owners and admins only; only owners can relink an owner's login; nobody can move or clear the link of their own login once it is linked.
- Who can call it
- Manage key owner admin
- MCP tool
platform_members_link_personon HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity
Input
membership_idstringrequiredperson_idstring | nullrequired
Returns
8 fields
membership_idstringrequireduser_idstringrequiredemailstringrequirednamestringrequiredrolesstring[]requiredstatus"active" | "disabled"requiredperson_idstring | nullrequiredhas_loginbooleanrequired
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/platform/members.link_person \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"membership_id":"m1","person_id":"p1"}'const res = await fetch('https://api.bizisy.com/v1/platform/members.link_person', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"membership_id": "m1",
"person_id": "p1"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/platform/members.link_person",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"membership_id": "m1",
"person_id": "p1",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"membership_id": "m1",
"user_id": "usr1",
"email": "ana@acme.test",
"name": "Ana Ferreira",
"roles": [
"hr"
],
"status": "active",
"person_id": null,
"has_login": true
}
}Something missing or wrong on this page? Write to hello@bizisy.com.