Org nodes API

Org nodes endpoints in the Brix REST API: 9 operations (GET, POST, PATCH, DELETE), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/org-nodes

Bearer token org-unit.view

Returns the workspace's location tree, for example districts, regions, sites, and departments, with each location's path and member count. Every location in the workspace tree the caller may see (not paginated). Build the tree from parentId.

curl "https://api.brixsignage.com/v1/org-nodes" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of Location
data[].idstringLocation (org node) id.
data[].namestring
data[].parentIdstring | nullParent location; null for the workspace root.
data[].externalIdstring | nullYour own location code (store number, region code). Unique in the workspace.
data[].timezonestring | nullIANA zone screens here inherit, e.g. `America/Chicago`.
data[].tierintegerDepth: 1 = the workspace root.
data[].isSpacebooleanTrue for a workspace (Space) boundary: the root, or a franchise child workspace.
data[].screenCountintegerScreens placed directly at this location (not its children).
data[].membersarray of objectPeople granted a role at this location.
data[].members[].userIdstring
data[].members[].userNamestring
data[].members[].roleIdstring
data[].members[].roleNamestring
data[].members[].roleColorstring | null
data[].members[].sourcestring | null`sso:<connectionId>` when an identity provider granted this; null when granted in Brix.
data[].featureOverridesanyOwner-set feature overrides, as stored (normally an array).
data[].approvalApprovalPolicyThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
data[].approval.requiredboolean
data[].approval.inheritFromParentboolean
data[].approval.escalateUpTiersboolean
data[].approval.allowSharedExemptionsboolean
data[].approval.approversarray of stringUser ids named as approvers.
data[].billinganyOwner-set billing metadata as stored, or null.
data[].prefsLocationPrefsInheritable per-location settings (nearest ancestor wins).
data[].prefs.locationobject | nullPhysical place screens here inherit (drives weather and other location-aware apps).
data[].prefs.languagestring | nullBCP 47 tag screens here inherit, e.g. `de-DE`.
data[].prefs.defaultContentobject | nullWhat screens here play when they have no content of their own.
{
  "data": [
    {
      "id": "on_4d5e6f7a8b9c0d1e",
      "name": "Chicago Loop",
      "parentId": "space_1a2b3c4d5e6f7a8b",
      "externalId": "STORE-0142",
      "timezone": "America/Chicago",
      "tier": 2,
      "isSpace": false,
      "screenCount": 6,
      "members": [
        {
          "userId": "usr_5e6f7a8b9c0d1e2f",
          "userName": "Sam Rivera",
          "roleId": "role_0a1b2c3d4e5f6a7b",
          "roleName": "Store manager",
          "roleColor": null,
          "source": null
        }
      ],
      "featureOverrides": [],
      "approval": {
        "required": false,
        "inheritFromParent": true,
        "escalateUpTiers": false,
        "allowSharedExemptions": false,
        "approvers": []
      },
      "billing": null,
      "prefs": {
        "location": {
          "label": "Chicago Loop",
          "lat": 41.8837,
          "lng": -87.6289
        },
        "language": null,
        "defaultContent": null
      }
    }
  ]
}

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/org-nodes

Bearer token org-unit.create

Creates a new location under a parent location. Provide name, parentId, and an optional kind. To create many locations at once, use the bulk-create operation instead.

Request body application/json

FieldTypeRequiredDescription
namestringyesLocation name.
parentIdstringnoParent location; omit to place it directly under the workspace root.
externalIdstringnoYour own location code; must be unique in the workspace.
timezonestringnoIANA zone, e.g. `Europe/London`.
approvalApprovalPolicynoThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
approval.requiredbooleanno
approval.inheritFromParentbooleanno
approval.escalateUpTiersbooleanno
approval.allowSharedExemptionsbooleanno
approval.approversarray of stringnoUser ids named as approvers.
isSpacebooleannoOwner-only: create a child workspace (franchise).
billingOwnerNodeIdstringnoWith `isSpace`: the ancestor workspace that pays.
screenLimitintegernoOwner-only, advisory.
tierintegernoOwner-only. Defaults to 2.
billinganynoOwner-only.
featureOverridesanynoOwner-only.
curl -X POST "https://api.brixsignage.com/v1/org-nodes" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"Chicago Loop","parentId":"on_0a1b2c3d4e5f6a7b","externalId":"STORE-0142","timezone":"America/Chicago"}'

Response 201 Success.

FieldTypeDescription
dataLocationA location in the workspace tree (an org node).
data.idstringLocation (org node) id.
data.namestring
data.parentIdstring | nullParent location; null for the workspace root.
data.externalIdstring | nullYour own location code (store number, region code). Unique in the workspace.
data.timezonestring | nullIANA zone screens here inherit, e.g. `America/Chicago`.
data.tierintegerDepth: 1 = the workspace root.
data.isSpacebooleanTrue for a workspace (Space) boundary: the root, or a franchise child workspace.
data.screenCountintegerScreens placed directly at this location (not its children).
data.membersarray of objectPeople granted a role at this location.
data.members[].userIdstring
data.members[].userNamestring
data.members[].roleIdstring
data.members[].roleNamestring
data.members[].roleColorstring | null
data.members[].sourcestring | null`sso:<connectionId>` when an identity provider granted this; null when granted in Brix.
data.featureOverridesanyOwner-set feature overrides, as stored (normally an array).
data.approvalApprovalPolicyThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
data.approval.requiredboolean
data.approval.inheritFromParentboolean
data.approval.escalateUpTiersboolean
data.approval.allowSharedExemptionsboolean
data.approval.approversarray of stringUser ids named as approvers.
data.billinganyOwner-set billing metadata as stored, or null.
data.prefsLocationPrefsInheritable per-location settings (nearest ancestor wins).
data.prefs.locationobject | nullPhysical place screens here inherit (drives weather and other location-aware apps).
data.prefs.languagestring | nullBCP 47 tag screens here inherit, e.g. `de-DE`.
data.prefs.defaultContentobject | nullWhat screens here play when they have no content of their own.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 An owner-only field was set (`isSpace`, `billing`, `featureOverrides`, `tier`, `screenLimit`, or a non-inheriting approval policy).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `location_id_taken`: another location already uses this `externalId`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 `name` missing, invalid `externalId`, or `parentId` not found.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/org-nodes/{id}

Bearer token org-unit.view

Returns one location, including its path, parent, and settings.

ParameterInTypeRequiredDescription
idpathstringyesLocation (org node) id.
curl "https://api.brixsignage.com/v1/org-nodes/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataLocationA location in the workspace tree (an org node).
data.idstringLocation (org node) id.
data.namestring
data.parentIdstring | nullParent location; null for the workspace root.
data.externalIdstring | nullYour own location code (store number, region code). Unique in the workspace.
data.timezonestring | nullIANA zone screens here inherit, e.g. `America/Chicago`.
data.tierintegerDepth: 1 = the workspace root.
data.isSpacebooleanTrue for a workspace (Space) boundary: the root, or a franchise child workspace.
data.screenCountintegerScreens placed directly at this location (not its children).
data.membersarray of objectPeople granted a role at this location.
data.members[].userIdstring
data.members[].userNamestring
data.members[].roleIdstring
data.members[].roleNamestring
data.members[].roleColorstring | null
data.members[].sourcestring | null`sso:<connectionId>` when an identity provider granted this; null when granted in Brix.
data.featureOverridesanyOwner-set feature overrides, as stored (normally an array).
data.approvalApprovalPolicyThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
data.approval.requiredboolean
data.approval.inheritFromParentboolean
data.approval.escalateUpTiersboolean
data.approval.allowSharedExemptionsboolean
data.approval.approversarray of stringUser ids named as approvers.
data.billinganyOwner-set billing metadata as stored, or null.
data.prefsLocationPrefsInheritable per-location settings (nearest ancestor wins).
data.prefs.locationobject | nullPhysical place screens here inherit (drives weather and other location-aware apps).
data.prefs.languagestring | nullBCP 47 tag screens here inherit, e.g. `de-DE`.
data.prefs.defaultContentobject | nullWhat screens here play when they have no content of their own.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such location in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

PATCH/v1/org-nodes/{id}

Bearer token org-unit.edit

Updates a location's name, parent location, approval configuration, or preferences. Moving a location to a new parent updates the path of every location beneath it. Rename, re-code, move, or change inheritable settings. Only the fields sent change.

ParameterInTypeRequiredDescription
idpathstringyesLocation (org node) id.

Request body application/json

FieldTypeRequiredDescription
namestringno
parentIdstring | nullnoMove under another location (null = the workspace root).
externalIdstring | nullno
timezonestring | nullnoIANA zone, or null/empty to inherit.
tierintegerno
prefsobjectnoPer-key: a value sets it, null clears it back to inherit, absent keeps it.
prefs.locationobject | nullno
prefs.languagestring | nullnoBCP 47 tag, or null to inherit.
prefs.defaultContentobject | nullno
approvalApprovalPolicynoThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
approval.requiredbooleanno
approval.inheritFromParentbooleanno
approval.escalateUpTiersbooleanno
approval.allowSharedExemptionsbooleanno
approval.approversarray of stringnoUser ids named as approvers.
approvalBaseApprovalPolicynoThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
approvalBase.requiredbooleanno
approvalBase.inheritFromParentbooleanno
approvalBase.escalateUpTiersbooleanno
approvalBase.allowSharedExemptionsbooleanno
approvalBase.approversarray of stringnoUser ids named as approvers.
billinganynoOwner-only.
featureOverridesanynoOwner-only.
curl -X PATCH "https://api.brixsignage.com/v1/org-nodes/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataLocationA location in the workspace tree (an org node).
data.idstringLocation (org node) id.
data.namestring
data.parentIdstring | nullParent location; null for the workspace root.
data.externalIdstring | nullYour own location code (store number, region code). Unique in the workspace.
data.timezonestring | nullIANA zone screens here inherit, e.g. `America/Chicago`.
data.tierintegerDepth: 1 = the workspace root.
data.isSpacebooleanTrue for a workspace (Space) boundary: the root, or a franchise child workspace.
data.screenCountintegerScreens placed directly at this location (not its children).
data.membersarray of objectPeople granted a role at this location.
data.members[].userIdstring
data.members[].userNamestring
data.members[].roleIdstring
data.members[].roleNamestring
data.members[].roleColorstring | null
data.members[].sourcestring | null`sso:<connectionId>` when an identity provider granted this; null when granted in Brix.
data.featureOverridesanyOwner-set feature overrides, as stored (normally an array).
data.approvalApprovalPolicyThe location's content-approval policy, as stored. New locations inherit `{required:false, inheritFromParent:true, …}`.
data.approval.requiredboolean
data.approval.inheritFromParentboolean
data.approval.escalateUpTiersboolean
data.approval.allowSharedExemptionsboolean
data.approval.approversarray of stringUser ids named as approvers.
data.billinganyOwner-set billing metadata as stored, or null.
data.prefsLocationPrefsInheritable per-location settings (nearest ancestor wins).
data.prefs.locationobject | nullPhysical place screens here inherit (drives weather and other location-aware apps).
data.prefs.languagestring | nullBCP 47 tag screens here inherit, e.g. `de-DE`.
data.prefs.defaultContentobject | nullWhat screens here play when they have no content of their own.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 Owner-only field, or a move you lack permission for at the destination.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such location in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `externalId` already used, or `approvalBase` no longer matches.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 Invalid field (a malformed `prefs`, moving a location under itself, unplayable default content).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/org-nodes/{id}

Bearer token org-unit.delete

Soft-deletes a location. Everything at that location, including screens, content and folders, is transferred to its parent location first, so nothing is left orphaned. Role assignments at the location are removed, so the same rule as removing a role assignment applies: only an account owner can remove an owner's assignment. The root location and any location with active child locations cannot be deleted.

ParameterInTypeRequiredDescription
idpathstringyesIdentifier for id.
curl -X DELETE "https://api.brixsignage.com/v1/org-nodes/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/org-nodes/{id}/members

Bearer token user.view

Returns the people directly assigned a role at this specific location, including the id of each role assignment. This id is needed to remove a membership, and is not included in the general roster listing.

ParameterInTypeRequiredDescription
idpathstringyesIdentifier for id.
curl "https://api.brixsignage.com/v1/org-nodes/{id}/members" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/org-nodes/{id}/members

Bearer token user.edit

Grants a person a role at this location. Provide userId and roleId. You cannot grant a role carrying permissions you do not hold yourself at that location.

ParameterInTypeRequiredDescription
idpathstringyesIdentifier for id.
curl -X POST "https://api.brixsignage.com/v1/org-nodes/{id}/members" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/org-nodes/{id}/members/{memberId}

Bearer token user.edit

Removes one person's role assignment at this location. Only an account owner can remove the assignment of a person who is an owner at this location, and you cannot remove an assignment that carries a permission you do not hold here. An API key is never an owner. Refuses the request if it would leave the workspace without any account owner.

ParameterInTypeRequiredDescription
idpathstringyesIdentifier for id.
memberIdpathstringyesIdentifier for memberId.
curl -X DELETE "https://api.brixsignage.com/v1/org-nodes/{id}/members/{memberId}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/org-nodes/bulk

Bearer token

Creates up to 200 sibling locations under one existing parent location in a single call, given parentId and a list of names. This is intended for pasting in a full location list at fleet setup. Empty or duplicate names are skipped, so the same list can safely be submitted again. Requires the create-location permission at the parent location.

curl -X POST "https://api.brixsignage.com/v1/org-nodes/bulk" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.