Users API

Users endpoints in the Brix REST API: 9 operations (GET, PATCH, POST, DELETE), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/users

Bearer token user.view

Returns the workspace roster: each person's role, which locations they can access, their sign-in method, two-factor authentication status, and last login. **Notes.** - Not paginated. Deleted (erased) people are not listed. A caller whose access is limited to some locations sees only the people with access there, and only those locations in access.

curl "https://api.brixsignage.com/v1/users" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of User
data[].idstring
data[].namestring
data[].emailstring
data[].status"active" | "invited" | "deactivated"`invited` until the person sets a password or signs in.
data[].roleIdstring | nullThe role of the first entry in `access`; null when the person has no access.
data[].scopestringThe location name of the first entry in `access`; `—` when none.
data[].loginMethod"sso" | "passkey" | "password"How the person signs in.
data[].totpEnabledbooleanTwo-factor authentication with an authenticator app is on.
data[].passkeyCountinteger
data[].lastLoginAtstring | null
data[].accessarray of objectEach location the person can access and the role they hold there. Only locations the caller can see are listed.
data[].access[].nodeIdstringLocation id.
data[].access[].nodeNamestringLocation name; `—` when the location no longer exists.
data[].access[].roleIdstring
data[].access[].roleNamestringRole name; `—` when the role no longer exists.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

PATCH/v1/users/{id}

Bearer token user.edit

Updates a person's profile. Supported fields are name and trainingStep (which resets a feature walkthrough for that person). Email address and account status cannot be changed through this operation. Requires access to every location the target person belongs to.

ParameterInTypeRequiredDescription
idpathstringyesUser id.

Request body application/json

FieldTypeRequiredDescription
namestringnoTrimmed; must not be empty.
trainingStepstring | nullnoWalkthrough position (`s1`…`s5`, `l1`…`l6`, `done`); null resets it.
curl -X PATCH "https://api.brixsignage.com/v1/users/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.emailstring
data.namestring
data.status"active" | "invited" | "deactivated"
data.trainingStepstring | nullWalkthrough position; null when not started or reset.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 Nothing to update, an empty or over-long `name`, or an unknown `trainingStep`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/users/{id}/deactivate

Bearer token user.edit

Deactivates a person's account. This revokes all of their active sessions, signing them out everywhere immediately and blocking further sign-in including through SSO, and removes them from every location's approver list. This action is reversible. You cannot deactivate your own account or the last remaining account owner. Only an account owner can do this to an owner, and you cannot do it to a person who holds a permission you do not hold. An API key is never an owner. **Notes.** - Only an owner can deactivate an owner, and nobody can deactivate a person who holds a permission they do not hold. An API key is never an owner, whatever its permissions.

ParameterInTypeRequiredDescription
idpathstringyesUser id.
curl -X POST "https://api.brixsignage.com/v1/users/{id}/deactivate" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.status"deactivated"
data.deactivatedAtstringISO-8601 timestamp (UTC).

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`; `owner_required`: the person is an owner and you are not an owner there (an API key is never an owner); or `outranked`: the person holds a permission you do not hold where they hold it.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `cant_deactivate_self`, `already_deactivated`, or `last_owner` (the last owner of the workspace or of a location).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/users/{id}/erase

Bearer token user.edit

Permanently erases a deactivated person's personal data to satisfy a right-to-be-forgotten request: it anonymizes their profile and hard-deletes their passkeys, linked identities, sessions, and location role assignments. The account must already be deactivated. You cannot erase your own account or the last remaining account owner. Only an account owner can do this to an owner, and you cannot do it to a person who holds a permission you do not hold. An API key is never an owner. **Notes.** - Irreversible. The same rule as deactivation applies: only an owner can erase an owner, and the caller must hold every permission the person holds.

ParameterInTypeRequiredDescription
idpathstringyesUser id.
curl -X POST "https://api.brixsignage.com/v1/users/{id}/erase" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.erasedtrue

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`; `owner_required`: the person is an owner and you are not an owner there (an API key is never an owner); or `outranked`: the person holds a permission you do not hold where they hold it.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person in this workspace (an erased person is not found again).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `cant_erase_self`, `last_owner`, or `must_deactivate_first`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/users/{id}/reactivate

Bearer token user.edit

Restores a deactivated person's account to active status. Their previous role assignments are restored along with the access they grant. Any approver-list entries removed at deactivation are not automatically restored. Only an account owner can do this to an owner, and you cannot do it to a person who holds a permission you do not hold. An API key is never an owner.

ParameterInTypeRequiredDescription
idpathstringyesUser id.
curl -X POST "https://api.brixsignage.com/v1/users/{id}/reactivate" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.status"active"

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`; `owner_required`: the person is an owner and you are not an owner there (an API key is never an owner); or `outranked`: the person holds a permission you do not hold where they hold it.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `not_deactivated`: the person is not deactivated.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/users/{id}/sessions

Bearer token user.edit

Returns a person's currently active sign-in sessions: id, creation time, last used time, expiry, device or browser, IP address, and which session belongs to the caller. Revoked and expired sessions are not included. **Notes.** - Needs user.edit, not user.view: the rows carry IP addresses. Sorted by last use, newest first.

ParameterInTypeRequiredDescription
idpathstringyesUser id.
curl "https://api.brixsignage.com/v1/users/{id}/sessions" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of UserSession
data[].idstringSession id (not the session token, which is never returned).
data[].createdAtstringISO-8601 timestamp (UTC).
data[].lastUsedAtstring | null
data[].expiresAtstringISO-8601 timestamp (UTC).
data[].userAgentstring | nullThe browser or device that signed in.
data[].ipAddressstring | null
data[].currentbooleanThis is the session making the call (always false for an API key).

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/users/{id}/sessions/{sessionId}

Bearer token user.edit

Signs one of a person's devices out by revoking that session. The session record itself is kept, not deleted. Calling this on an already-revoked session is safe and reports revoked: false.

ParameterInTypeRequiredDescription
idpathstringyesUser id.
sessionIdpathstringyesSession id from the session list.
curl -X DELETE "https://api.brixsignage.com/v1/users/{id}/sessions/{sessionId}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.revokedbooleanFalse when the session was already revoked.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person, or no such session for this person.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/users/{id}/sessions/revoke-all

Bearer token user.edit

Signs a person out of every active session without deactivating their account, so they can still sign back in afterward. Returns the number of sessions that were revoked.

ParameterInTypeRequiredDescription
idpathstringyesUser id.
curl -X POST "https://api.brixsignage.com/v1/users/{id}/sessions/revoke-all" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstringUser id.
data.revokedintegerSessions revoked.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The person belongs to a location where you do not hold `user.edit`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such person in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/users/invite

Bearer token user.edit

Creates a new person in the workspace, or reuses an existing one, and assigns them a role at the chosen locations. A new person gets an email with a link to set their password. When a signed-in user sends the invite, the email goes out only when that user's own email address is verified. An invite made with an API key sends the email in the workspace's name. You cannot grant a role carrying permissions you do not hold yourself. **Notes.** - Answers 200 (not 201) for a new person too; created tells the two apart. - For a signed-in user, the set-password email is sent only when that user's own email address is verified. An invite made with an API key sends the email too, from the workspace (the key's name is not shown). The 30-a-minute limit counts per key for a key.

Request body application/json

FieldTypeRequiredDescription
emailstringyesStored in lower case.
namestringnoUsed only when the person is new.
roleIdstringyes
nodeIdsarray of stringyesLocations to grant the role at. You need `user.edit` and every permission of the role at each one.
curl -X POST "https://api.brixsignage.com/v1/users/invite" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]","name":"Sam Rivera","roleId":"role_5e6f7a8b9c0d1e2f","nodeIds":["on_4d5e6f7a8b9c0d1e"]}'

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.emailstring
data.status"active" | "invited" | "deactivated"
data.createdbooleanTrue when a new person was created; false when an existing person got the extra access.
data.emailSentbooleanA set-password email went out.
data.emailBlockedReason"inviter-unverified" | "provider-refused" | nullWhy no email went out for a new person: the calling user's own email address is not verified (never for an API key), or the mail provider refused it. Null when sent, or when the person already existed.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The role holds permissions you do not hold, or you lack `user.edit` or the role's permissions at one of the locations.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such role or location in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 Invalid `email`, or `roleId` / `nodeIds` missing.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 429 More than 30 invites a minute.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.