Users

A user is a person with an account. One account can belong to several workspaces, and it can create API keys.

Create an account

  • Sign up with an email address and a password, or sign in with a connected provider (Google, Microsoft, LinkedIn, Apple or Facebook, where enabled).
  • You receive an email to activate the account. Follow the link in it.
  • Sign-up is rate limited per address and per network address, and may ask you to solve a captcha.

API: POST /v1/user/signup, POST /v1/user/register, GET /v1/user/activate.

Sign in

  • Email or username plus password, or a connected provider.
  • If two-step verification (MFA) is on for your account, you are asked for a code after the password.
  • Repeated wrong passwords temporarily lock the account.
  • You can review your active sessions and recent activity on your account page.

Your account page

Open User > Details. The left menu links to:

Link What it does
Change password Set a new password.
Select workspace / Manage workspace Choose the workspace you are working in.
Workspace invitations Accept invitations sent to you.
API Keys Create and delete your own API keys. Only shown on your own account.
Delete account Permanently delete your account.

The page also has sections for overview, security, workspaces, API keys, sessions and activity logs.

Profile

You can change your display name, username and profile picture from the overview section. Some fields, such as the user id, cannot be edited.

API: PUT /v1/user/{id}, POST /v1/user/profile_picture.

Email addresses

An account has one primary email and up to 3 additional addresses. Each new address must be verified before it can be used.

API: GET/POST /v1/user/{id}/email, POST /v1/user/{id}/email/primary, POST /v1/user/{id}/email/resend, DELETE /v1/user/{id}/email, GET /v1/user/email/verify.

Passwords

  • Forgot your password: request a reset link, then choose a new password from the link.
  • Change password: while signed in, from your account page.

API: POST /v1/user/password_forgot, GET /v1/user/password_reset, POST /v1/user/password_set, POST /v1/user/password_update.

Who can see and change a profile

GET /v1/user/{id} and PUT /v1/user/{id} are allowed for the account owner and for administrators. Other users get 403 Forbidden.

Roles

Roles decide what a user may do. The built-in roles are super_admin, admin, workspace_admin, super_user, user and readonly_user. A user's roles are kept per workspace, except the platform-wide admin roles.

Export and delete your data

  • Export: GET /v1/user/{id}/export returns the data held about your account.
  • Delete: Delete account on your account page, or DELETE /v1/user/{id}.

Authentication for API calls

Most endpoints accept one of:

  • a signed-in session (the access_token cookie), or a Bearer token
  • HTTP Basic credentials, which can be a user name and password or an API key

Many requests also take an X-TenantId header naming the workspace to act in. You must be a member of that workspace.