/api/v1/users
auth: jwt (administrator | manage_users)List all users belonging to the authenticated caller's business (businessId taken from the JWT, not the URL).
handlers: UsersController.list
No parameters.
APIResponseDataList<UserAdminDTO>/api/v1/users
auth: jwt (administrator | manage_users)Create a new user inside the caller's business. Argon2-hashes the password, derives username from the email local part, inserts into Users + UserRoles, and fires USER_CREATED + welcome email (fire-and-forget).
handlers: UsersController.create
| name | required | default | description |
|---|---|---|---|
firstName bodystring | yes | — | Given name (min 1 char). |
lastName bodystring | yes | — | Family name (min 1 char). |
email bodystring (email) | yes | — | Email address — must be globally unique. |
roles bodyUserRole[] | yes | — | At least one role from the UserRole enum. |
password bodystring | yes | — | Plaintext password (min 8 chars). |
APIResponseDataObject<UserAdminDTO>APIErrorAPIError/api/v1/users/:userId
auth: jwt (administrator | manage_users)Partial update of a user inside the caller's business. Patch may include roles, isActive, firstName, lastName, email, and/or password. Admin-removal safeguards prevent removing your own Administrator role or removing the last administrator. Fires USER_DEACTIVATED on isActive=false, USER_UPDATED otherwise.
handlers: UsersController.update
| name | required | default | description |
|---|---|---|---|
userId pathuuid | yes | — | Target user UUID — must belong to the caller's business. |
roles bodyUserRole[] | no | — | Replacement role set (min 1). |
isActive bodyboolean | no | — | Activate/deactivate the user. |
firstName bodystring | no | — | Given name (min 1 char). |
lastName bodystring | no | — | Family name (min 1 char). |
email bodystring (email) | no | — | Replacement email address. |
password bodystring | no | — | Replacement password (min 8 chars, argon2-hashed server-side). |
APIResponseDataObject<UserAdminDTO>APIErrorAPIError