Documentation / Members & roles

Members & roles

Project members, invitations and roles — the Member and Role objects, the permission bitmask, and the endpoints for inviting, re-assigning and removing members and managing roles.

Every project member has exactly one role. A role is a named set of permissions, stored as an integer bitmask. The project owner is a member too but bypasses all permission checks, whatever their role.

New members join by invitation: inviting an existing Configo user by email sends them a notification. They become a member only when they accept it. Until then, the invitation is listed among the members with is_pending: true.

Field types follow the field notation.

Access

Every endpoint on this page requires both the projects and members OAuth scopes. The user must be a member of the project, and the owner's subscription must be active. Otherwise the endpoint returns 404 RES_NOT_FOUND.

Managing members and roles requires both can_edit_project and can_edit_members. Reading roles requires the same two permissions, because a role is the project's access map. Any member can list members.

Member Object

Member Structure

Field Type Description
uuid uuid The user's ID. Use it as {member.uuid} in the endpoints below
email string The user's email
user_name string The user's full name
role_uuid ?uuid The member's role; null if the role was deleted
role_name ?string Name of that role
permissions? integer The role's permission bitmask. Present only if the caller has can_edit_members, and never for invitations
is_pending boolean true for an invitation that has not been accepted yet. Only in List Members
created_at ISO8601 datetime When the user joined, or when the invitation was sent
updated_at ISO8601 datetime When the membership last changed

Example Member

{
  "uuid": "0198f0b2-3c4d-7e5f-8a6b-7c8d9e0f1a2b",
  "email": "[email protected]",
  "user_name": "Ivan Sidorov",
  "role_uuid": "0198e7a0-0000-7000-8000-0000000000a2",
  "role_name": "Manager",
  "permissions": 14293971053567,
  "is_pending": false,
  "created_at": "2026-07-02T08:00:00.000Z",
  "updated_at": "2026-07-02T08:00:00.000Z"
}

List Members

GET /api/v1/projects/{project.uuid}/members

Returns all members, oldest first, followed by pending invitations. Any member can call it.

Errors

Status Code When
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
404 RES_NOT_FOUND The project does not exist or is not accessible

Get Member

GET /api/v1/projects/{project.uuid}/members/{member.uuid}

Returns a single member, without is_pending. Pending invitations are not returned here. Any member can call it.

Errors

Status Code When
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
404 RES_NOT_FOUND The project does not exist, or the user is not a member

Invite Member

POST /api/v1/projects/{project.uuid}/members

Invites a registered Configo user. The user gets a notification and joins with the given role once they accept it. The owner's plan member limit is checked when the invitation is sent. Pending invitations do not count towards it.

Requires can_edit_project and can_edit_members.

JSON Params

Field Type Description
email string Email of an existing Configo user, up to 255 characters
role_uuid uuid Role to give; must belong to this project

Example Request

{
  "email": "[email protected]",
  "role_uuid": "0198e7a0-0000-7000-8000-0000000000a2"
}

Response

201 Created

{
  "user_uuid": "0198f0b2-3c4d-7e5f-8a6b-7c8d9e0f1a2b",
  "invited": true
}

Errors

Status Code When
400 REQ_VALIDATION_FAILED The body does not match the schema, or role_uuid is not a role of this project
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_PROJECT_ACCESS The user's role lacks can_edit_project or can_edit_members
403 BILL_SUBSCRIPTION_EXPIRED The project owner has no active subscription
403 LIMIT_MEMBER_COUNT_REACHED The project has as many members as the owner's plan allows
404 RES_NOT_FOUND The project does not exist, or no Configo user has this email
409 RES_ALREADY_EXISTS The user is already a member, or already has a pending invitation

Modify Member

PATCH /api/v1/projects/{project.uuid}/members/{member.uuid}

Changes the member's role. PUT on the same path behaves identically. You cannot change your own role.

Requires can_edit_project and can_edit_members.

JSON Params

Field Type Description
role_uuid uuid New role; must belong to this project

Response

204 No Content

Errors

Status Code When
400 REQ_VALIDATION_FAILED role_uuid is malformed or not a role of this project
400 REQ_NO_DATA_PROVIDED role_uuid is missing
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_PROJECT_ACCESS The user's role lacks can_edit_project or can_edit_members
403 MEMBER_SELF_EDIT_FORBIDDEN {member.uuid} is the authenticated user
404 RES_NOT_FOUND The project does not exist, or the user is not a member

Remove Member

DELETE /api/v1/projects/{project.uuid}/members/{member.uuid}

Removes a member, or revokes a pending invitation for that user. Their orders, contacts and tasks stay in the project and keep them as the responsible member.

Leaving a project. A member can pass their own uuid to leave. This needs no permissions and works even when the owner's subscription has lapsed. The owner cannot leave or be removed.

Requires can_edit_project and can_edit_members, except when leaving.

Response

204 No Content

Errors

Status Code When
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_PROJECT_ACCESS The user's role lacks can_edit_project or can_edit_members
403 PROJECT_OWNER_REQUIRED Trying to remove the owner, or the owner trying to leave
404 RES_NOT_FOUND The project does not exist, or the user is neither a member nor invited

Role Object

Role Structure

Field Type Description
uuid uuid Role ID
project_uuid uuid Project ID. Only in Get Role
name string Name, 1–255 characters
permissions integer Permission bitmask
order integer Sort position
created_at ISO8601 datetime When the role was created

Example Role

{
  "uuid": "0198e7a0-0000-7000-8000-0000000000a2",
  "name": "Manager",
  "permissions": 14293971053567,
  "order": 2,
  "created_at": "2026-06-26T10:00:00.000Z"
}

Permission bits

permissions is the sum (bitwise OR) of these values. The largest value fits in a JavaScript number without loss. Bits not listed are reserved, and a mask containing them is rejected with REQ_VALIDATION_FAILED.

For orders, contacts and tasks, the three view permissions are alternatives: a role normally has one of own/role/all. The widest one present applies.

Permission Value Grants
can_view_own_orders 1 See orders where the user is responsible
can_view_role_orders 2 See orders of members with the same role
can_view_all_orders 4 See all orders
can_edit_orders 8 Create, edit, delete orders
can_view_own_contacts 16 See contacts assigned to the user
can_view_role_contacts 32 See contacts of members with the same role
can_view_all_contacts 64 See all contacts
can_edit_contacts 128 Create, edit, delete, merge, export contacts; manage tags
can_view_own_tasks 256 See tasks assigned to the user
can_view_role_tasks 512 See tasks of members with the same role
can_view_all_tasks 1024 See all tasks
can_edit_tasks 2048 Create, edit, delete tasks
can_view_purchase_price 4096 See purchase (cost) prices
can_view_sale_price 8192 See sale prices
can_view_dealer_price 16384 See dealer prices
can_edit_order_products_price 32768 Change prices of products in an order
can_view_materials 65536 See materials
can_edit_materials 131072 Edit materials
can_view_configurators 1048576 See configurators
can_edit_configurators 2097152 Edit configurators
can_view_products 16777216 See products
can_edit_products 33554432 Edit products
can_view_documents 268435456 See document templates
can_edit_documents 536870912 Edit document templates
can_view_email_templates 1073741824 See email templates
can_edit_email_templates 2147483648 Edit email templates
can_view_reports 4294967296 See reports
can_view_warehouses 68719476736 See warehouses and stock
can_edit_warehouses 137438953472 Edit warehouses and stock
can_view_wiki 1099511627776 Read the wiki
can_edit_wiki 2199023255552 Edit the wiki
can_view_wiki_comment 4398046511104 Read wiki comments
can_edit_wiki_comment 8796093022208 Write wiki comments
can_view_automations 17592186044416 Reserved for automations; automations are currently governed by can_edit_project
can_edit_automations 35184372088832 Reserved, as above
can_edit_project 281474976710656 Edit project settings
can_edit_members 562949953421312 Manage members and roles (together with can_edit_project)
can_edit_statuses 1125899906842624 Manage funnels, statuses, transitions and loss reasons
can_export_data 2251799813685248 Reserved for data export

A new project's Owner role has every bit above: 4291608416878591. Its Manager role has 14293971053567.

List Roles

GET /api/v1/projects/{project.uuid}/roles

Returns the project's roles, sorted by order.

Requires can_edit_project and can_edit_members.

Errors

Status Code When
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_ACCESS The user's role lacks can_edit_project or can_edit_members
404 RES_NOT_FOUND The project does not exist or is not accessible

Get Role

GET /api/v1/projects/{project.uuid}/roles/{role.uuid}

Returns a single role.

Requires can_edit_project and can_edit_members.

Errors

Same as List Roles, plus 404 RES_NOT_FOUND if the role does not exist.

Create Role

POST /api/v1/projects/{project.uuid}/roles

Creates a role at the end of the list.

Requires can_edit_project and can_edit_members.

JSON Params

Field Type Description
name string 1–255 characters
permissions integer Permission bitmask, ≥ 0

Example Request

{
  "name": "Production",
  "permissions": 206158430208
}

That is can_view_warehouses + can_edit_warehouses.

Response

201 Created

{
  "uuid": "0199a8d3-0a1b-7c2d-8e3f-405162738495"
}

Errors

Status Code When
400 REQ_VALIDATION_FAILED The body does not match the schema, or permissions has unknown bits
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_PROJECT_ACCESS The user's role lacks can_edit_project or can_edit_members
404 RES_NOT_FOUND The project does not exist or is not accessible

Modify Role

PATCH /api/v1/projects/{project.uuid}/roles/{role.uuid}

Updates any of name, permissions, order (integer ≥ 0). At least one must be present. A change of permissions applies to every member with this role immediately.

Requires can_edit_project and can_edit_members.

Response

204 No Content

Errors

Status Code When
400 REQ_VALIDATION_FAILED The body does not match the schema, or permissions has unknown bits
400 REQ_NO_DATA_PROVIDED The body has no fields
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_PROJECT_ACCESS The user's role lacks can_edit_project or can_edit_members
404 RES_NOT_FOUND The project or role does not exist

Replace Role

PUT /api/v1/projects/{project.uuid}/roles/{role.uuid}

Same as Modify Role, but name, permissions and order are all required.

Delete Role

DELETE /api/v1/projects/{project.uuid}/roles/{role.uuid}

Deletes the role. Members who had it are left without a role and lose access to the project until they are given another one through Modify Member. Move them to another role first.

Requires can_edit_project and can_edit_members.

Response

204 No Content

Errors

Status Code When
403 AUTH_INSUFFICIENT_SCOPE The token lacks projects or members
403 AUTH_NO_PROJECT_ACCESS The user's role lacks can_edit_project or can_edit_members
404 RES_NOT_FOUND The project or role does not exist