openapi: 3.0.4
info:
title: Bench AccountActivities AccountUsers API
description: "
Versioning
\n\n The API is currently at version 1.0. All API endpoints (other than\n authentication) require you to specify the API version as part of the path.\n
\n\nURL Paths
\n\n Authentication requests should be made to /auth/signin,\n as documented below. All other API requests should be made to\n sub-paths of /rp/api/1.0/....\n
\n\nAuthentication
\n\n API requests are authenticated using an OAuth Bearer token.\n You can get a token by authenticating your user by sending a\n POST request to /auth/signin, with \"username and \"password\"\n parameters form-encoded in the body of the request.\n\n POST /auth/signin HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n username=user@example.com&password=some-secret-password\n
\n\n The response will be a JSON object including both\n \"access_token\" and \"refresh_token\" property.\n All other requests against the Bench API should include an\n authorization header: Authorization: Bearer xxxYYYzzz,\n where xxxYYYzzz is the value of \"access_token\" in the response.\n
\n For example:\n\n $ curl https://bench.gobridgit.com/auth/signin -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=someone@example.com' --data-urlencode 'password=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n\n
\n\n\n The refresh token can be used to generate new session by request with /auth/token endpoint:\n\n POST /auth/token HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n grant_type=refresh_token&refresh_token=tGzv3JOkF0XG5Qx2TlKWIA\n
\n\n Note that once the refresh token is used, the previous access and refresh token is no longer valid.\n
\n For example:\n\n $ curl https://bench.gobridgit.com/auth/token -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'grant_type=refresh_token' --data-urlencode 'refresh_token=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n
\n\nPagination
\n\n Several of the API endpoints are paginated. These are denoted by\n including the offset (zero-based offset) and limit query\n parameters. For example, to request the 10 items,\n set the offset=0 to limit=10.\n
\n NOTE: the result set contains items with index of 0-9\n
\n To request the next 10 items (starting at index 10),\n set the offset=10 to limit=10\n
\n\n Responses to paginated API endpoints return a JSON array of objects.\n If there are results beyond the page you have requested, the server\n will set a query-has-more: true header in the response.\n
\n\nRequest Encoding
\n\n GET and DELETE requests should have parameters encoded as URL query\n parameters. Boolean values should be encoded as true and\n false, not as 1 and 0.\n
\n\nErrors
\n\n Errors are returned for some response codes such as 400 Bad Request in the\n following format:\n\n {\n \"errors\": [\n {\n \"errorType\": \"ValidationError\",\n \"description\": \"The value of Name must be a string with a minimum length of 1 and a maximum length of 8 and not whitespace.\",\n \"field\": \"Name\",\n \"values\": [\n null\n ]\n }\n ],\n \"title\": \"One or more validation errors occurred.\",\n \"status\": 400,\n \"instance\": \"api/v1/accounts/0/persons\",\n \"requestUid\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n
\n"
version: '1.0'
servers:
- url: https://bench.gobridgit.com
description: Bridgit Bench production
security:
- {}
tags:
- name: AccountUsers
paths:
/rp/api/v1/accounts/{accountId}/users:
get:
tags:
- AccountUsers
summary: Gets the users for the given account
description: '
Permissions
Account: Read'
operationId: AccountUsers_Query
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: offset
in: query
description: Offset for pagination
schema:
maximum: 2147483647
minimum: 0
type: integer
format: int32
default: 0
- name: limit
in: query
description: Maximum number of results in this page
schema:
maximum: 2147483647
minimum: 1
type: integer
format: int32
default: 1000
- name: group
in: query
description: Optional parameter to filter results based on user groups
schema:
type: string
- name: ids
in: query
description: (Optional) Filters the result to contain account users that match the ids passed in.
schema:
type: array
items:
type: integer
format: int32
- name: nameSearch
in: query
description: (Optional) Searches for users by partial name match (minimum 3 characters).
schema:
type: string
responses:
'200':
description: 'Success: List of users on the account'
content:
text/plain:
schema:
type: array
items:
$ref: '#/components/schemas/UserResponse'
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/UserResponse'
text/json:
schema:
type: array
items:
$ref: '#/components/schemas/UserResponse'
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
/rp/api/v1/accounts/{accountId}/users/{id}:
get:
tags:
- AccountUsers
summary: Gets the the specified user for the given account by ID
description: '
Permissions
Account: Read'
operationId: AccountUsers_Get
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: The User's ID
required: true
schema:
type: integer
format: int32
responses:
'200':
description: 'Success: List of users on the account'
content:
text/plain:
schema:
$ref: '#/components/schemas/UserResponse'
application/json:
schema:
$ref: '#/components/schemas/UserResponse'
text/json:
schema:
$ref: '#/components/schemas/UserResponse'
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
patch:
tags:
- AccountUsers
summary: Updates a user for the given account
description: 'Name or Title can be null, but they cannot be empty/whitespace. If null the value will not be changed.
Permissions
Account: Write'
operationId: AccountUsers_Patch
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: Id of the user to update
required: true
schema:
type: integer
format: int32
requestBody:
description: Request object in the body with fields to change
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/UserRequest'
application/json:
schema:
$ref: '#/components/schemas/UserRequest'
text/json:
schema:
$ref: '#/components/schemas/UserRequest'
application/*+json:
schema:
$ref: '#/components/schemas/UserRequest'
required: true
responses:
'204':
description: No Content
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
'409':
description: Conflict
delete:
tags:
- AccountUsers
summary: Deactivates a user from the given account
description: 'Adminsitrators can only deactivate other users from the account and not themselves.
Permissions
Account: Write'
operationId: AccountUsers_Delete
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: Id of the user to remove
required: true
schema:
type: integer
format: int32
responses:
'204':
description: No Content
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
/rp/api/v1/accounts/{accountId}/users/{id}/membership:
put:
tags:
- AccountUsers
summary: Modify user's permission group in the account.
description: 'Groups in the account can be fetched from the api/v{version}/accounts/{accountId}/groups endpoint.
Permissions
Account: Write'
operationId: AccountUsers_SetMembership
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: ID of the user to modify
required: true
schema:
type: integer
format: int32
requestBody:
description: Request object for the user
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/AccountMembershipRequest'
application/json:
schema:
$ref: '#/components/schemas/AccountMembershipRequest'
text/json:
schema:
$ref: '#/components/schemas/AccountMembershipRequest'
application/*+json:
schema:
$ref: '#/components/schemas/AccountMembershipRequest'
required: true
responses:
'204':
description: No Content
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
/rp/api/v1/accounts/{accountId}/users/{userId}/reset-auth-method:
post:
tags:
- AccountUsers
summary: 'Resets a user''s authentication method and sends a new invitation email.
This can be used to switch a user from SSO to username/password authentication.
Note: users can be on multiple accounts in an organization. This resets the auth method in all accounts within
the organization.'
description: '
Permissions
Account: Write'
operationId: AccountUsers_ResetAuthMethod
parameters:
- name: accountId
in: path
description: The account that is currently calling this method.
required: true
schema:
type: integer
format: int32
- name: userId
in: path
description: The ID of the account user.
required: true
schema:
type: integer
format: int32
responses:
'202':
description: Accepted
'204':
description: No Content
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
'422':
description: Unprocessable Entity
components:
schemas:
GroupingGroup:
type: object
properties:
id:
type: integer
format: int64
example: 124
groupId:
type: integer
format: int32
example: 323
additionalProperties: false
UserRequest:
type: object
properties:
name:
type: string
nullable: true
example: John Smith
title:
type: string
nullable: true
example: Human Resources Manager
phoneNumber:
type: string
nullable: true
example: '+18005551234'
team:
type: string
nullable: true
example: Management
additionalProperties: false
AccountMembershipRequest:
type: object
properties:
groupingPermissions:
type: array
items:
$ref: '#/components/schemas/GroupingGroup'
nullable: true
group:
type: string
nullable: true
example: Administrator
additionalProperties: false
UserResponse:
type: object
properties:
id:
type: integer
format: int32
example: 2313
name:
type: string
nullable: true
example: John Smith
title:
type: string
nullable: true
example: Human Resources Manager
team:
type: string
nullable: true
example: Management
email:
type: string
nullable: true
example: johnsmith@example.com
state:
enum:
- Inactive
- Enabled
- Disabled
- PendingEmailChange
type: string
example: Active
group:
type: string
nullable: true
example: Administrator
groupingPermissions:
type: array
items:
$ref: '#/components/schemas/GroupingGroup'
nullable: true
phoneNumber:
type: string
nullable: true
example: '+18005551234'
createdOn:
type: string
format: date-time
example: '2020-01-01'
invitationId:
type: integer
format: int64
nullable: true
lastLoginOn:
type: string
format: date-time
nullable: true
example: '2026-01-15T10:30:00Z'
additionalProperties: false
securitySchemes:
Bearer:
type: http
description: Standard Authorization header using the Bearer scheme
scheme: bearer
bearerFormat: JWT