openapi: 3.0.3 info: title: GoodLeap Developer Authorization & Elevation Management User Management API version: '2.0' description: 'The GoodLeap Developer API lets approved partners originate and manage sustainable home-improvement loans through their full lifecycle: authentication and elevation, offers and payment calculation, loan submission, status tracking, case/stipulation management, document upload, project and milestone management, change orders, notes, tags, and user management. Derived faithfully from the public GoodLeap Postman collection (paths, methods, parameters, and JWT bearer auth are as published); request/response schemas are intentionally minimal because the source collection does not publish full schemas.' x-derived-from: postman/good-leap-developer-api.postman_collection.json servers: - url: https://api.goodleap.com description: Production - url: https://sandbox01-api.goodleap.com description: Sandbox / test security: - bearerAuth: [] tags: - name: User Management paths: /posfinancing/rest/v2/user/{id}: get: operationId: userById summary: User by Id tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Returns a user by Id parameters: - name: id in: path required: true schema: type: string /posfinancing/rest/v2/users: post: operationId: createUser summary: Create User tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Create a user requestBody: content: application/json: schema: type: object get: operationId: listAnOrganizationsUsers summary: List an Organizations Users tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Returns a collection of users belonging to the requesting organization. parameters: - name: email in: query required: false schema: type: string - name: phoneNumber in: query required: false schema: type: string - name: page in: query required: false schema: type: string - name: pageSize in: query required: false schema: type: string /posfinancing/rest/v2/users/roles-channels: get: operationId: allRolesAndChannels summary: All Roles and Channels tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Retrieve the possible list of roles and channels that are required for user creation. /posfinancing/rest/v2/users/{id}/license: put: operationId: updateUserStateLicense summary: Update User State License tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Update user license by id parameters: - name: id in: path required: true schema: type: string requestBody: content: application/json: schema: type: object /posfinancing/rest/v2/users/{id}/role: put: operationId: updateUserRole summary: Update User Role tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Update a user’s role. parameters: - name: id in: path required: true schema: type: string requestBody: content: application/json: schema: type: object /posfinancing/rest/v2/users/{id}: put: operationId: updateUserInformation summary: Update User Information tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Update user information by id parameters: - name: id in: path required: true schema: type: string requestBody: content: application/json: schema: type: object /posfinancing/rest/v2/users/{id}/channels: put: operationId: updateUserChannels summary: Update User Channels tags: - User Management security: - bearerAuth: [] responses: '200': description: Successful response description: Update a user’s channels. parameters: - name: id in: path required: true schema: type: string requestBody: content: application/json: schema: type: object components: securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: JWT obtained via POST /posfinancing/rest/v2/auth/token (organizationId), refreshed via /auth/token/refresh.