Role
Change a member's role, and optionally their explicit permissions. Leave `permissions` out to keep whatever they have, send an array to pin an exact allowlist, or send null to drop back to the role's preset. Nobody can edit their own membership through this endpoint (403), which is what stops an owner locking themselves out.
Authentication
sf_… API key in the bearerAuth field below.A SaaSFlow API key (format sf_…) or an OAuth bearer token. Paste only the key — the proxy adds the Bearer prefix. Create an API key in Settings → Company settings → API keys — see API keys.
In: header
Path Parameters
1 <= length1 <= lengthRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
curl -X PUT "https://example.com/companies/string/users/string/role" \ -H "Content-Type: application/json" \ -d '{ "role": "owner" }'{ "success": true}List users
List the people with an actual membership in a company, with their role and when they were last seen. `id` and `userId` both carry the SaaSFlow user id, which is what the role and remove endpoints expect. A null `lastSeenTime` means they have never opened the app. Pending invitations are not memberships and do not appear here, so someone who was invited but never accepted is missing from this list rather than showing up inactive.
Delete user
Remove someone from a company. Their user account survives, they just lose access to this company, and the data they created stays. Removing yourself is refused with 403.