Organization
Methods, permissions, request fields and response schemas for organization.
Read and search
Retrieve current records, history and status.
Read organization settings and API identityRead your organization settings and identify the actor behind the API token.GET/auth/organization
/auth/organizationEdit example fields and validate the request against its schema.
What you receive
Current organization business settings and issuing actor identity. Use actor.id when ignoring your bot's own chat-message events.
Request example · cURL
Replace example IDs and values. Supply the token from your secret store. Each intended write uses one stable $ACTION_KEY.
curl -X GET "$BASE/auth/organization" \
-H "Authorization: Bearer $ALLPROFILES_API_TOKEN"Success response schema · HTTP 200
{
"application/json": {
"schema": {
"type": "object",
"properties": {
"id": {
"type": "string",
"format": "uuid"
},
"name": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"logoUrl": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"industry": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"description": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"createdAt": {
"type": "string",
"format": "date-time"
},
"updatedAt": {
"type": "string",
"format": "date-time"
},
"actor": {
"type": "object",
"properties": {
"id": {
"type": "string",
"format": "uuid"
},
"email": {
"type": "string",
"minLength": 0,
"maxLength": 5000
}
},
"required": [
"id",
"email"
],
"additionalProperties": false
}
},
"required": [
"id",
"name",
"actor"
],
"additionalProperties": false
}
}
}Errors and recovery
400- Invalid JSON, request fields, query, path identifier or missing Idempotency-Key.
401- Missing, invalid, revoked or expired organization API token; its issuing actor must still be the current organization owner.
403- Token scope or actor capability denied, disabled/banned account, or action unavailable.
404- Unknown route or resource not accessible in the bound organization. Cross-tenant resources are not enumerated.
409- Conflicting profile/rental state, duplicate resource, idempotency payload mismatch or operation still in progress.
410- event_cursor_expired: the event cursor is behind retained history. Reconcile current resources and start from the supplied recovery cursor.
422- Business validation/moderation rejected the operation. CHAT_MESSAGE_BLOCKED was not delivered.
429- API rate/concurrency limit exceeded; use backoff and Retry-After when present.
500- Internal operation error. Sensitive implementation details are not returned. Investigate using the request ID before repeating a write.
503- Provider or configuration unavailable; uncertain writes must retain the same Idempotency-Key.
These are documented API errors. The local sandbox checks schema fields only and does not test authorization, moderation or provider behavior.
Financial fields named ...Cents or ...InCents use integer cents. Path fields and nested constraints are shown above and in the downloadable OpenAPI contract.
Update and configure
Change existing records, assignments and configuration.
Edit organization detailsEdit business details for the organization bound to the token.PATCH/auth/organization
/auth/organizationSend Idempotency-Key. Retry the same intended action with the same key and exact payload to retrieve its saved result.
Request body
| Field | Type | Description and constraints |
|---|---|---|
nameOptional | string | At least 1 characters · At most 200 characters |
logoUrlOptional | string | null | At least 0 characters · At most 2048 characters |
industryOptional | string | null | At least 0 characters · At most 200 characters |
descriptionOptional | string | null | At least 0 characters · At most 5000 characters |
Edit example fields and validate the request against its schema.
What you receive
Updated authenticated owner/workspace snapshot; empty/null logo, industry and description clear those values.
Request example · cURL
Replace example IDs and values. Supply the token from your secret store. Each intended write uses one stable $ACTION_KEY.
curl -X PATCH "$BASE/auth/organization" \
-H "Authorization: Bearer $ALLPROFILES_API_TOKEN" \
-H "Idempotency-Key: $ACTION_KEY" \
-H "Content-Type: application/json" \
--data '{}'Full JSON request schema
{
"type": "object",
"properties": {
"name": {
"type": "string",
"minLength": 1,
"maxLength": 200
},
"logoUrl": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 2048
},
"industry": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 200
},
"description": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
}
},
"required": [],
"additionalProperties": false
}Success response schema · HTTP 200
{
"application/json": {
"schema": {
"type": "object",
"properties": {
"id": {
"type": "string",
"format": "uuid"
},
"email": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"name": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"avatarUrl": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"onboardingFlags": {
"type": "object",
"additionalProperties": true,
"description": "Platform scrape metadata. Keep credentials out of this field."
},
"notificationPreferences": {
"type": "object",
"additionalProperties": true,
"description": "Platform scrape metadata. Keep credentials out of this field."
},
"role": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"accountType": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"orgRole": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"isEmailVerified": {
"type": "boolean"
},
"registrationStatus": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"createdAt": {
"type": "string",
"format": "date-time"
},
"workspaceId": {
"type": [
"string",
"null"
],
"format": "uuid"
},
"workspaceName": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"workspaceLogoUrl": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"workspaceIndustry": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"workspaceDescription": {
"type": [
"string",
"null"
],
"minLength": 0,
"maxLength": 5000
},
"permissions": {
"type": "object",
"properties": {
"orgRole": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"accountType": {
"type": "string",
"minLength": 0,
"maxLength": 5000
},
"pages": {
"type": "object",
"additionalProperties": {
"type": "boolean"
}
},
"actions": {
"type": "object",
"additionalProperties": {
"type": "boolean"
}
},
"assignedProfileIds": {
"type": [
"array",
"null"
],
"items": {
"type": "string",
"format": "uuid"
}
}
},
"required": [
"orgRole",
"accountType",
"pages",
"actions",
"assignedProfileIds"
],
"additionalProperties": true
}
},
"required": [
"id",
"email",
"name",
"avatarUrl",
"onboardingFlags",
"notificationPreferences",
"role",
"accountType",
"orgRole",
"isEmailVerified",
"registrationStatus",
"createdAt",
"workspaceId",
"workspaceName",
"workspaceLogoUrl",
"workspaceIndustry",
"workspaceDescription",
"permissions"
],
"additionalProperties": true
}
}
}Errors and recovery
400- Invalid JSON, request fields, query, path identifier or missing Idempotency-Key.
401- Missing, invalid, revoked or expired organization API token; its issuing actor must still be the current organization owner.
403- Token scope or actor capability denied, disabled/banned account, or action unavailable.
404- Unknown route or resource not accessible in the bound organization. Cross-tenant resources are not enumerated.
409- Conflicting profile/rental state, duplicate resource, idempotency payload mismatch or operation still in progress.
410- event_cursor_expired: the event cursor is behind retained history. Reconcile current resources and start from the supplied recovery cursor.
422- Business validation/moderation rejected the operation. CHAT_MESSAGE_BLOCKED was not delivered.
429- API rate/concurrency limit exceeded; use backoff and Retry-After when present.
500- Internal operation error. Sensitive implementation details are not returned. Investigate using the request ID before repeating a write.
503- Provider or configuration unavailable; uncertain writes must retain the same Idempotency-Key.
These are documented API errors. The local sandbox checks schema fields only and does not test authorization, moderation or provider behavior.
Financial fields named ...Cents or ...InCents use integer cents. Path fields and nested constraints are shown above and in the downloadable OpenAPI contract.