Organizations
List my organisations
GET /a/v1/organizations/me
Every organisation the signed-in user is a member of, with their role and membership status. current marks the organisation of this session.
Who can call it: Signed-in user only: do this in the Yona app.
Example request
Responses
Update the current organisation
PATCH /a/v1/organizations/me
Changes the name, contact email, website or address. Changing contactEmail or address also needs the organization.update_contact capability. The response carries the organisation summary plus each contact field that was changed.
Who can call it: Signed-in user only: do this in the Yona app.
Request body
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | 1 to 255 characters. |
contactEmail | string (email) | No | At most 254 characters. |
website | string (uri) | No | At most 255 characters. |
address | object (Address) | No |
address
| Field | Type | Required | Description |
|---|---|---|---|
line1 | string | Yes | 1 to 200 characters. |
line2 | string | No | 1 to 200 characters. |
city | string | Yes | 1 to 100 characters. |
state | string | Yes | 1 to 100 characters. |
postalCode | string | No | 1 to 20 characters. |
country | string | Yes | 2 to 2 characters. |
Example request
Responses
Get the organisation profile
GET /a/v1/organizations/{orgId}
The profile of the organisation the token belongs to. orgId must be that organisation (404 otherwise). Available to users and API keys.
Who can call it: API key or signed-in user.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Example request
Responses
Update an organisation by id
PATCH /a/v1/organizations/{orgId}
The same update as PATCH /a/v1/organizations/me; orgId must be the organisation of the session (404 otherwise). Changes the name, contact email, website or address. Changing contactEmail or address also needs the organization.update_contact capability. The response carries the organisation summary plus each contact field that was changed.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | 1 to 255 characters. |
contactEmail | string (email) | No | At most 254 characters. |
website | string (uri) | No | At most 255 characters. |
address | object (Address) | No |
address
| Field | Type | Required | Description |
|---|---|---|---|
line1 | string | Yes | 1 to 200 characters. |
line2 | string | No | 1 to 200 characters. |
city | string | Yes | 1 to 100 characters. |
state | string | Yes | 1 to 100 characters. |
postalCode | string | No | 1 to 20 characters. |
country | string | Yes | 2 to 2 characters. |
Example request
Responses
List members
GET /a/v1/organizations/{orgId}/users
A page of the organisation’s members, filtered by the query.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
page | query | number | No | Default: 1. At least 1. |
limit | query | number | No | Default: 20. Between 1 and 100. |
status | query | string | No | One of active | suspended. |
role | query | string | No | One of OWNER | ADMIN | ACCOUNTANT | MEMBER | DEVELOPER | VIEWER. |
search | query | string | No | Name or email prefix. 1 to 100 characters. |
Example request
Responses
Get a member
GET /a/v1/organizations/{orgId}/users/{userId}
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
userId | path | string (uuid) | Yes |
Example request
Responses
Remove a member
DELETE /a/v1/organizations/{orgId}/users/{userId}
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
userId | path | string (uuid) | Yes |
Example request
Responses
Leave the organisation
POST /a/v1/organizations/{orgId}/leave
Ends the caller’s own membership in the organisation.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Example request
Responses
Transfer ownership
POST /a/v1/organizations/{orgId}/ownership-transfer
Makes another active member the owner. The caller confirms with their password (and a second-factor code when two-factor is on) and becomes an admin unless they choose to stay an owner.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
toUserId | string (uuid) | Yes | An active member with a verified email, not the caller. |
password | string (password) | Yes | 1 to 128 characters. |
code | string | No | Required when the caller has TOTP: a TOTP or recovery code. |
retainOwnership | boolean | No | Keep OWNER as well (default false: the caller becomes ADMIN). |
Example request
Responses
Change a member’s role
PATCH /a/v1/organizations/{orgId}/users/{userId}/role
Assigns another system role to the member. Access tokens the member already holds are refused until they refresh, so the new role applies at once.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
userId | path | string (uuid) | Yes |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
roleId | string (uuid) | Yes | A system role id (fixed per role key); OWNER is refused by the service. |
Example request
Responses
Suspend or restore a member
PATCH /a/v1/organizations/{orgId}/users/{userId}/status
Sets the membership status in this organisation: suspended needs member.suspend, active needs member.restore.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
userId | path | string (uuid) | Yes |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
status | string | Yes | One of active | suspended. |
reason | string | No | 1 to 500 characters. |
Example request
Responses
List roles
GET /a/v1/organizations/{orgId}/roles
The system roles a member can hold, each with its capabilities.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Example request
Responses
Get a role
GET /a/v1/organizations/{orgId}/roles/{roleId}
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
roleId | path | string (uuid) | Yes |
Example request
Responses
List available capabilities
GET /a/v1/organizations/{orgId}/roles/permissions/available
Every capability a member can hold, with its label and properties, and the subset an API key may hold.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Example request
Responses
List invitations
GET /a/v1/organizations/{orgId}/invitations
A page of the organisation’s invitations (pending by default). No invitation codes are returned.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
status | query | string | No | One of pending | accepted | withdrawn | expired. |
page | query | number | No | Default: 1. At least 1. |
limit | query | number | No | Default: 20. Between 1 and 100. |
Example request
Responses
Invite someone to the organisation
POST /a/v1/organizations/{orgId}/invitations
Emails an invitation code to the invitee. The code is never returned by the API; it exists only in the email.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
email | string (email) | Yes | At most 254 characters. |
fullName | string | Yes | 2 to 255 characters. |
roleId | string (uuid) | No | A system role other than OWNER, ranked ≤ the inviter; default MEMBER. |
message | string | No | Included in the invitation email. 1 to 500 characters. |
Example request
Responses
Get an invitation
GET /a/v1/organizations/{orgId}/invitations/{id}
One invitation of the organisation, without its code.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
id | path | string (uuid) | Yes |
Example request
Responses
Withdraw a pending invitation
DELETE /a/v1/organizations/{orgId}/invitations/{id}
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
id | path | string (uuid) | Yes |
Example request
Responses
Resend an invitation
POST /a/v1/organizations/{orgId}/invitations/{id}/resend
Emails the invitee a new code; the previous code stops working.
Who can call it: Signed-in user only: do this in the Yona app.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
orgId | path | string | Yes | Organisation id — must equal the token’s organisation — or me. |
id | path | string (uuid) | Yes |
Example request
Responses
Accept an invitation
POST /a/v1/accept-invitation
The signed-in user, whose verified email is the invitee’s, joins the organisation. No tokens are returned: to work in the new organisation, switch to it with POST /a/v1/organizations/switch.
Who can call it: Signed-in user only: do this in the Yona app.
Request body
| Field | Type | Required | Description |
|---|---|---|---|
invitationCode | string | Yes | 8 Crockford base32 characters; case, spaces and hyphens are ignored. 8 to 8 characters. |
Example request
Responses
Preview an invitation
POST /a/v1/verify-invitation
Public. Given the invitation code and the invitee’s email, returns what the invitee may see before accepting. Any mismatch answers the same 404.
Who can call it: Signed-in user only: do this in the Yona app.
Request body
| Field | Type | Required | Description |
|---|---|---|---|
invitationCode | string | Yes | 8 Crockford base32 characters; case, spaces and hyphens are ignored. 8 to 8 characters. |
email | string (email) | Yes | At most 254 characters. |
Example request
Responses