List users
List the people with an actual membership in a company, with their role and when they were last seen. `id` and `userId` both carry the SaaSFlow user id, which is what the role and remove endpoints expect. A null `lastSeenTime` means they have never opened the app. Pending invitations are not memberships and do not appear here, so someone who was invited but never accepted is missing from this list rather than showing up inactive.
Authentication
sf_… API key in the bearerAuth field below.A SaaSFlow API key (format sf_…) or an OAuth bearer token. Paste only the key — the proxy adds the Bearer prefix. Create an API key in Settings → Company settings → API keys — see API keys.
In: header
Path Parameters
1 <= lengthResponse Body
application/json
curl -X GET "https://example.com/companies/string/users"[ { "id": "string", "userId": "string", "firebaseUserId": "string", "email": "string", "name": "string", "photoURL": "string", "role": "owner", "lastSeenTime": "2019-08-24T14:15:22Z" }]Update company
Update company settings. Only the fields you send change. Changing `baseCurrency` restates every converted figure in the app, including historical ones, so it is not a cosmetic setting. `plShowPlanningPercentageForPastMonths` and `plShowAllCategories` control how the P&L is rendered, and the valuation fields drive the valuation estimate.
Role
Change a member's role, and optionally their explicit permissions. Leave `permissions` out to keep whatever they have, send an array to pin an exact allowlist, or send null to drop back to the role's preset. Nobody can edit their own membership through this endpoint (403), which is what stops an owner locking themselves out.