Haijun Platform Docs
ID

List RBAC Groups

GET /v1/organizations/rbac_groups

List RBAC Groups in the Haijun Enterprise tenant.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Query parameters

  • limit: optional number

Number of items to return per page.

Defaults to 20. Ranges from 1 to 1000.

default: 20, minimum: 1, maximum: 1000

  • page: optional string

Optionally set to the next_page token from the previous response.

Returns

  • data: array of BetaRBACGroup
  • type: "rbac_group"

Object type.

For RBAC Groups, this is always "rbac_group".

default: rbac_group

  • id: string

ID of the RBAC Group.

  • created_at: string

RFC 3339 timestamp of when the RBAC Group was created.

format: date-time

  • name: string

Name of the RBAC Group. Not uniqueness-enforced.

  • role_ids: array of string or null

RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. null means role data was temporarily unavailable — retry to distinguish from an empty list.

  • source_type: "direct" or "scim"

How the RBAC Group was created: "direct" for groups created directly (for example, in the organization's admin settings), "scim" for groups provisioned by the identity provider.

  • "direct"
  • "scim"
  • updated_at: string

RFC 3339 timestamp of when the RBAC Group was last updated.

format: date-time

  • roles: array of string or null

Deprecated: Use role_ids instead; roles always has the same value.

Deprecated: use role_ids instead. IDs of the RBAC Roles attached to this RBAC Group; always the same value as role_ids, null included.

  • has_more: boolean

Indicates if there are more results in the requested page direction.

  • next_page: string or null

Token to provide in as page in the subsequent request to retrieve the next page of data.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "data": [
    {
      "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
      "created_at": "2024-10-30T23:58:27.427722Z",
      "name": "Engineering",
      "role_ids": [
        "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
      ],
      "roles": [
        "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
      ],
      "source_type": "direct",
      "type": "rbac_group",
      "updated_at": "2024-10-30T23:58:27.427722Z"
    }
  ],
  "has_more": false,
  "next_page": "eyJjdXJzb3IiOiAicmJhY19ncm91cF8wMSJ9"
}

Get RBAC Group

GET /v1/organizations/rbac_groups/{rbac_group_id}

Retrieve an RBAC Group by ID.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Path parameters

  • rbac_group_id: string

ID of the RBAC Group.

Returns

  • BetaRBACGroup object
  • type: "rbac_group"

Object type.

For RBAC Groups, this is always "rbac_group".

default: rbac_group

  • id: string

ID of the RBAC Group.

  • created_at: string

RFC 3339 timestamp of when the RBAC Group was created.

format: date-time

  • name: string

Name of the RBAC Group. Not uniqueness-enforced.

  • role_ids: array of string or null

RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. null means role data was temporarily unavailable — retry to distinguish from an empty list.

  • source_type: "direct" or "scim"

How the RBAC Group was created: "direct" for groups created directly (for example, in the organization's admin settings), "scim" for groups provisioned by the identity provider.

  • "direct"
  • "scim"
  • updated_at: string

RFC 3339 timestamp of when the RBAC Group was last updated.

format: date-time

  • roles: array of string or null

Deprecated: Use role_ids instead; roles always has the same value.

Deprecated: use role_ids instead. IDs of the RBAC Roles attached to this RBAC Group; always the same value as role_ids, null included.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups/$RBAC_GROUP_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "name": "Engineering",
  "role_ids": [
    "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
  ],
  "roles": [
    "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
  ],
  "source_type": "direct",
  "type": "rbac_group",
  "updated_at": "2024-10-30T23:58:27.427722Z"
}

Create RBAC Group

POST /v1/organizations/rbac_groups

Create an RBAC Group in the Haijun Enterprise tenant. Groups created via the API have source type "direct".

The RBAC Groups API is available to Haijun Enterprise organizations only.

Body parameters

  • name: string

Name of the RBAC Group. Not uniqueness-enforced.

minLength: 1, maxLength: 255

Returns

  • BetaRBACGroup object
  • type: "rbac_group"

Object type.

For RBAC Groups, this is always "rbac_group".

default: rbac_group

  • id: string

ID of the RBAC Group.

  • created_at: string

RFC 3339 timestamp of when the RBAC Group was created.

format: date-time

  • name: string

Name of the RBAC Group. Not uniqueness-enforced.

  • role_ids: array of string or null

RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. null means role data was temporarily unavailable — retry to distinguish from an empty list.

  • source_type: "direct" or "scim"

How the RBAC Group was created: "direct" for groups created directly (for example, in the organization's admin settings), "scim" for groups provisioned by the identity provider.

  • "direct"
  • "scim"
  • updated_at: string

RFC 3339 timestamp of when the RBAC Group was last updated.

format: date-time

  • roles: array of string or null

Deprecated: Use role_ids instead; roles always has the same value.

Deprecated: use role_ids instead. IDs of the RBAC Roles attached to this RBAC Group; always the same value as role_ids, null included.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "name": "Engineering"
        }'

Response (200)

json
{
  "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "name": "Engineering",
  "role_ids": [
    "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
  ],
  "roles": [
    "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
  ],
  "source_type": "direct",
  "type": "rbac_group",
  "updated_at": "2024-10-30T23:58:27.427722Z"
}

Update RBAC Group

POST /v1/organizations/rbac_groups/{rbac_group_id}

Update an RBAC Group's name. Groups provisioned by an identity provider (source type "scim") cannot be modified via the API while an organization in the tenant uses SCIM provisioning.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Path parameters

  • rbac_group_id: string

ID of the RBAC Group.

Body parameters

  • name: optional string or null

Name of the RBAC Group. Not uniqueness-enforced.

minLength: 1, maxLength: 255

Returns

  • BetaRBACGroup object
  • type: "rbac_group"

Object type.

For RBAC Groups, this is always "rbac_group".

default: rbac_group

  • id: string

ID of the RBAC Group.

  • created_at: string

RFC 3339 timestamp of when the RBAC Group was created.

format: date-time

  • name: string

Name of the RBAC Group. Not uniqueness-enforced.

  • role_ids: array of string or null

RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. null means role data was temporarily unavailable — retry to distinguish from an empty list.

  • source_type: "direct" or "scim"

How the RBAC Group was created: "direct" for groups created directly (for example, in the organization's admin settings), "scim" for groups provisioned by the identity provider.

  • "direct"
  • "scim"
  • updated_at: string

RFC 3339 timestamp of when the RBAC Group was last updated.

format: date-time

  • roles: array of string or null

Deprecated: Use role_ids instead; roles always has the same value.

Deprecated: use role_ids instead. IDs of the RBAC Roles attached to this RBAC Group; always the same value as role_ids, null included.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups/$RBAC_GROUP_ID \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "name": "Engineering"
        }'

Response (200)

json
{
  "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "name": "Engineering",
  "role_ids": [
    "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
  ],
  "roles": [
    "rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
  ],
  "source_type": "direct",
  "type": "rbac_group",
  "updated_at": "2024-10-30T23:58:27.427722Z"
}

Delete RBAC Group

DELETE /v1/organizations/rbac_groups/{rbac_group_id}

Delete an RBAC Group. Groups provisioned by an identity provider (source type "scim") cannot be deleted via the API while an organization in the tenant uses SCIM provisioning.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Path parameters

  • rbac_group_id: string

ID of the RBAC Group.

Returns

  • BetaRBACGroupDeleted object
  • type: "rbac_group_deleted"

Deleted object type.

For RBAC Groups, this is always "rbac_group_deleted".

default: rbac_group_deleted

  • id: string

ID of the RBAC Group.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups/$RBAC_GROUP_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "type": "rbac_group_deleted"
}

Domain types

Beta RBAC Group

  • BetaRBACGroup object
  • type: "rbac_group"

Object type.

For RBAC Groups, this is always "rbac_group".

default: rbac_group

  • id: string

ID of the RBAC Group.

  • created_at: string

RFC 3339 timestamp of when the RBAC Group was created.

format: date-time

  • name: string

Name of the RBAC Group. Not uniqueness-enforced.

  • role_ids: array of string or null

RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. null means role data was temporarily unavailable — retry to distinguish from an empty list.

  • source_type: "direct" or "scim"

How the RBAC Group was created: "direct" for groups created directly (for example, in the organization's admin settings), "scim" for groups provisioned by the identity provider.

  • "direct"
  • "scim"
  • updated_at: string

RFC 3339 timestamp of when the RBAC Group was last updated.

format: date-time

  • roles: array of string or null

Deprecated: Use role_ids instead; roles always has the same value.

Deprecated: use role_ids instead. IDs of the RBAC Roles attached to this RBAC Group; always the same value as role_ids, null included.

Beta RBAC Group Deleted

  • BetaRBACGroupDeleted object
  • type: "rbac_group_deleted"

Deleted object type.

For RBAC Groups, this is always "rbac_group_deleted".

default: rbac_group_deleted

  • id: string

ID of the RBAC Group.

RBAC Groups › Members

List RBAC Group Members

GET /v1/organizations/rbac_groups/{rbac_group_id}/members

List members of an RBAC Group.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Path parameters

  • rbac_group_id: string

ID of the RBAC Group.

Query parameters

  • limit: optional number

Number of items to return per page.

Defaults to 20. Ranges from 1 to 1000.

default: 20, minimum: 1, maximum: 1000

  • page: optional string

Optionally set to the next_page token from the previous response.

Returns

  • data: array of BetaRBACGroupMember
  • type: "rbac_group_member"

Object type.

For RBAC Group Members, this is always "rbac_group_member".

default: rbac_group_member

  • created_at: string

RFC 3339 timestamp of when the User was added to the RBAC Group.

format: date-time

  • email: string

Email of the User.

  • rbac_group_id: string

ID of the RBAC Group.

  • user_id: string

ID of the User.

  • group_id: string

Deprecated: Use rbac_group_id instead; group_id always has the same value.

Deprecated: use rbac_group_id instead. ID of the RBAC Group; always the same value as rbac_group_id.

  • has_more: boolean

Indicates if there are more results in the requested page direction.

  • next_page: string or null

Token to provide in as page in the subsequent request to retrieve the next page of data.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups/$RBAC_GROUP_ID/members \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "data": [
    {
      "created_at": "2024-10-30T23:58:27.427722Z",
      "email": "user@emaildomain.com",
      "group_id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
      "rbac_group_id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
      "type": "rbac_group_member",
      "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
    }
  ],
  "has_more": false,
  "next_page": "eyJjdXJzb3IiOiAicmJhY19ncm91cF8wMSJ9"
}

Add RBAC Group Member

POST /v1/organizations/rbac_groups/{rbac_group_id}/members

Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type "scim") cannot be modified via the API while an organization in the tenant uses SCIM provisioning.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Path parameters

  • rbac_group_id: string

ID of the RBAC Group.

Body parameters

  • user_id: string

ID of the User.

Returns

  • BetaRBACGroupMember object
  • type: "rbac_group_member"

Object type.

For RBAC Group Members, this is always "rbac_group_member".

default: rbac_group_member

  • created_at: string

RFC 3339 timestamp of when the User was added to the RBAC Group.

format: date-time

  • email: string

Email of the User.

  • rbac_group_id: string

ID of the RBAC Group.

  • user_id: string

ID of the User.

  • group_id: string

Deprecated: Use rbac_group_id instead; group_id always has the same value.

Deprecated: use rbac_group_id instead. ID of the RBAC Group; always the same value as rbac_group_id.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups/$RBAC_GROUP_ID/members \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
        }'
Response (200)
json
{
  "created_at": "2024-10-30T23:58:27.427722Z",
  "email": "user@emaildomain.com",
  "group_id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "rbac_group_id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "type": "rbac_group_member",
  "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
}

Remove RBAC Group Member

DELETE /v1/organizations/rbac_groups/{rbac_group_id}/members/{user_id}

Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type "scim") cannot be modified via the API while an organization in the tenant uses SCIM provisioning.

The RBAC Groups API is available to Haijun Enterprise organizations only.

Path parameters

  • rbac_group_id: string

ID of the RBAC Group.

  • user_id: string

ID of the User.

Returns

  • BetaRBACGroupMemberDeleted object
  • type: "rbac_group_member_deleted"

Deleted object type. For RBAC Group Members, this is always "rbac_group_member_deleted".

default: rbac_group_member_deleted

  • rbac_group_id: string

ID of the RBAC Group.

  • user_id: string

ID of the User.

  • group_id: string

Deprecated: Use rbac_group_id instead; group_id always has the same value.

Deprecated: use rbac_group_id instead. ID of the RBAC Group; always the same value as rbac_group_id.

Example

bash
curl https://haijun.my.id/v1/organizations/rbac_groups/$RBAC_GROUP_ID/members/$USER_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "group_id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "rbac_group_id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
  "type": "rbac_group_member_deleted",
  "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
}
On this page
List RBAC GroupsQuery parametersReturnsExampleResponse (200)Get RBAC GroupPath parametersReturnsExampleResponse (200)Create RBAC GroupBody parametersReturnsExampleResponse (200)Update RBAC GroupPath parametersBody parametersReturnsExampleResponse (200)Delete RBAC GroupPath parametersReturnsExampleResponse (200)Domain typesBeta RBAC GroupBeta RBAC Group DeletedRBAC Groups › MembersList RBAC Group MembersPath parametersQuery parametersReturnsExampleAdd RBAC Group MemberPath parametersBody parametersReturnsExampleRemove RBAC Group MemberPath parametersReturnsExample