Staff and permissions
See API introduction for authentication, request conventions, pagination, rate limits, and errors.
Users in Activity Messenger are administrators and staff who have access to the back-office of your organization. Activity Messenger users are uniquely identified by an email address. A user can manage/access multiple organizations. You can invite users, modify their permissions and revoke their access. Read the help page User management and permissionsto find out more.
A user object contains these attributes. The confirmed attribute will be true if the user has confirmed their email and completed their Activity Messenger user account setup.
{
"id": 1234,
"first_name": "Harry",
"last_name": "Potter",
"email": "harry@hogwartsrec.com",
"mobile": "555-123-1234",
"permission": "staff",
"confirmed": true
}
GET /api/v1/organization/{organization}/users
Retrieve all users who have access to or manage the organization.
GET /api/v1/organization/{organization}/users/{user}
Retrieve a user by ID.
POST /api/v1/organization/{organization}/users
Invite a user to manage/access the organization. The email address is the key and required. Attributes first_name and last_name are also required. Attribute mobile is optional. If provided must be formatted as 555-123-1234. Attribute permission determines their access level. Can be one of: staff, staff_no_messaging or guest. Refer to the help page User management and permissions for details.
If a user does not already exist with an account in Activity Messenger they will be created. They will receive an email to set up their account and gain access to your organization. The endpoint will return a 201 status code.
If the user already exists, they will be granted access to the your organization with the provided permission. If they already had access to your organization, their permission will be updated. The user attributes will not be modified. Inviting users with the owner or admin permission levels is not supported by the API. It is also not possible to change the permission level of owner or admin users. Contact us if you require any of those abilities.
PUT /api/v1/organization/{organization}/users/{user}
Update the permission of a staff within the organization. Only the permission attribute should be passed and can be modified. Same constraints as the POST endpoint.
DELETE /api/v1/organization/{organization}/users/{user}
Revoke the user access to the organization.