Members & roles
Project members, invitations and roles — the Member and Role objects, the permission bitmask, and the endpoints for inviting, re-assigning and removing members and managing roles.
Every project member has exactly one role. A role is a named set of permissions, stored as an integer bitmask. The project owner is a member too but bypasses all permission checks, whatever their role.
New members join by invitation: inviting an existing Configo user by email sends them a notification. They become a
member only when they accept it. Until then, the invitation is listed among the members with is_pending: true.
Field types follow the field notation.
Access
Every endpoint on this page requires both the projects and members OAuth scopes. The user must be a member of
the project, and the owner's subscription must be active. Otherwise the endpoint returns 404 RES_NOT_FOUND.
Managing members and roles requires both can_edit_project and can_edit_members. Reading roles requires the same
two permissions, because a role is the project's access map. Any member can list members.
Member Object
Member Structure
| Field | Type | Description |
|---|---|---|
| uuid | uuid | The user's ID. Use it as {member.uuid} in the endpoints below |
| string | The user's email | |
| user_name | string | The user's full name |
| role_uuid | ?uuid | The member's role; null if the role was deleted |
| role_name | ?string | Name of that role |
| permissions? | integer | The role's permission bitmask. Present only if the caller has can_edit_members, and never for invitations |
| is_pending | boolean | true for an invitation that has not been accepted yet. Only in List Members |
| created_at | ISO8601 datetime | When the user joined, or when the invitation was sent |
| updated_at | ISO8601 datetime | When the membership last changed |
Example Member
{
"uuid": "0198f0b2-3c4d-7e5f-8a6b-7c8d9e0f1a2b",
"email": "[email protected]",
"user_name": "Ivan Sidorov",
"role_uuid": "0198e7a0-0000-7000-8000-0000000000a2",
"role_name": "Manager",
"permissions": 14293971053567,
"is_pending": false,
"created_at": "2026-07-02T08:00:00.000Z",
"updated_at": "2026-07-02T08:00:00.000Z"
}
List Members
GET /api/v1/projects/{project.uuid}/members
Returns all members, oldest first, followed by pending invitations. Any member can call it.
Errors
| Status | Code | When |
|---|---|---|
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 404 | RES_NOT_FOUND |
The project does not exist or is not accessible |
Get Member
GET /api/v1/projects/{project.uuid}/members/{member.uuid}
Returns a single member, without is_pending. Pending invitations are not returned here. Any member
can call it.
Errors
| Status | Code | When |
|---|---|---|
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 404 | RES_NOT_FOUND |
The project does not exist, or the user is not a member |
Invite Member
POST /api/v1/projects/{project.uuid}/members
Invites a registered Configo user. The user gets a notification and joins with the given role once they accept it. The owner's plan member limit is checked when the invitation is sent. Pending invitations do not count towards it.
Requires can_edit_project and can_edit_members.
JSON Params
| Field | Type | Description |
|---|---|---|
| string | Email of an existing Configo user, up to 255 characters | |
| role_uuid | uuid | Role to give; must belong to this project |
Example Request
{
"email": "[email protected]",
"role_uuid": "0198e7a0-0000-7000-8000-0000000000a2"
}
Response
201 Created
{
"user_uuid": "0198f0b2-3c4d-7e5f-8a6b-7c8d9e0f1a2b",
"invited": true
}
Errors
| Status | Code | When |
|---|---|---|
| 400 | REQ_VALIDATION_FAILED |
The body does not match the schema, or role_uuid is not a role of this project |
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_PROJECT_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 403 | BILL_SUBSCRIPTION_EXPIRED |
The project owner has no active subscription |
| 403 | LIMIT_MEMBER_COUNT_REACHED |
The project has as many members as the owner's plan allows |
| 404 | RES_NOT_FOUND |
The project does not exist, or no Configo user has this email |
| 409 | RES_ALREADY_EXISTS |
The user is already a member, or already has a pending invitation |
Modify Member
PATCH /api/v1/projects/{project.uuid}/members/{member.uuid}
Changes the member's role. PUT on the same path behaves identically. You cannot change your own role.
Requires can_edit_project and can_edit_members.
JSON Params
| Field | Type | Description |
|---|---|---|
| role_uuid | uuid | New role; must belong to this project |
Response
204 No Content
Errors
| Status | Code | When |
|---|---|---|
| 400 | REQ_VALIDATION_FAILED |
role_uuid is malformed or not a role of this project |
| 400 | REQ_NO_DATA_PROVIDED |
role_uuid is missing |
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_PROJECT_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 403 | MEMBER_SELF_EDIT_FORBIDDEN |
{member.uuid} is the authenticated user |
| 404 | RES_NOT_FOUND |
The project does not exist, or the user is not a member |
Remove Member
DELETE /api/v1/projects/{project.uuid}/members/{member.uuid}
Removes a member, or revokes a pending invitation for that user. Their orders, contacts and tasks stay in the project and keep them as the responsible member.
Leaving a project. A member can pass their own uuid to leave. This needs no permissions and works even when the
owner's subscription has lapsed. The owner cannot leave or be removed.
Requires can_edit_project and can_edit_members, except when leaving.
Response
204 No Content
Errors
| Status | Code | When |
|---|---|---|
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_PROJECT_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 403 | PROJECT_OWNER_REQUIRED |
Trying to remove the owner, or the owner trying to leave |
| 404 | RES_NOT_FOUND |
The project does not exist, or the user is neither a member nor invited |
Role Object
Role Structure
| Field | Type | Description |
|---|---|---|
| uuid | uuid | Role ID |
| project_uuid | uuid | Project ID. Only in Get Role |
| name | string | Name, 1–255 characters |
| permissions | integer | Permission bitmask |
| order | integer | Sort position |
| created_at | ISO8601 datetime | When the role was created |
Example Role
{
"uuid": "0198e7a0-0000-7000-8000-0000000000a2",
"name": "Manager",
"permissions": 14293971053567,
"order": 2,
"created_at": "2026-06-26T10:00:00.000Z"
}
Permission bits
permissions is the sum (bitwise OR) of these values. The largest value fits in a JavaScript number without loss.
Bits not listed are reserved, and a mask containing them is rejected with REQ_VALIDATION_FAILED.
For orders, contacts and tasks, the three view permissions are alternatives: a role normally has one of own/role/all. The widest one present applies.
| Permission | Value | Grants |
|---|---|---|
can_view_own_orders |
1 | See orders where the user is responsible |
can_view_role_orders |
2 | See orders of members with the same role |
can_view_all_orders |
4 | See all orders |
can_edit_orders |
8 | Create, edit, delete orders |
can_view_own_contacts |
16 | See contacts assigned to the user |
can_view_role_contacts |
32 | See contacts of members with the same role |
can_view_all_contacts |
64 | See all contacts |
can_edit_contacts |
128 | Create, edit, delete, merge, export contacts; manage tags |
can_view_own_tasks |
256 | See tasks assigned to the user |
can_view_role_tasks |
512 | See tasks of members with the same role |
can_view_all_tasks |
1024 | See all tasks |
can_edit_tasks |
2048 | Create, edit, delete tasks |
can_view_purchase_price |
4096 | See purchase (cost) prices |
can_view_sale_price |
8192 | See sale prices |
can_view_dealer_price |
16384 | See dealer prices |
can_edit_order_products_price |
32768 | Change prices of products in an order |
can_view_materials |
65536 | See materials |
can_edit_materials |
131072 | Edit materials |
can_view_configurators |
1048576 | See configurators |
can_edit_configurators |
2097152 | Edit configurators |
can_view_products |
16777216 | See products |
can_edit_products |
33554432 | Edit products |
can_view_documents |
268435456 | See document templates |
can_edit_documents |
536870912 | Edit document templates |
can_view_email_templates |
1073741824 | See email templates |
can_edit_email_templates |
2147483648 | Edit email templates |
can_view_reports |
4294967296 | See reports |
can_view_warehouses |
68719476736 | See warehouses and stock |
can_edit_warehouses |
137438953472 | Edit warehouses and stock |
can_view_wiki |
1099511627776 | Read the wiki |
can_edit_wiki |
2199023255552 | Edit the wiki |
can_view_wiki_comment |
4398046511104 | Read wiki comments |
can_edit_wiki_comment |
8796093022208 | Write wiki comments |
can_view_automations |
17592186044416 | Reserved for automations; automations are currently governed by can_edit_project |
can_edit_automations |
35184372088832 | Reserved, as above |
can_edit_project |
281474976710656 | Edit project settings |
can_edit_members |
562949953421312 | Manage members and roles (together with can_edit_project) |
can_edit_statuses |
1125899906842624 | Manage funnels, statuses, transitions and loss reasons |
can_export_data |
2251799813685248 | Reserved for data export |
A new project's Owner role has every bit above: 4291608416878591. Its Manager role has 14293971053567.
List Roles
GET /api/v1/projects/{project.uuid}/roles
Returns the project's roles, sorted by order.
Requires can_edit_project and can_edit_members.
Errors
| Status | Code | When |
|---|---|---|
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 404 | RES_NOT_FOUND |
The project does not exist or is not accessible |
Get Role
GET /api/v1/projects/{project.uuid}/roles/{role.uuid}
Returns a single role.
Requires can_edit_project and can_edit_members.
Errors
Same as List Roles, plus 404 RES_NOT_FOUND if the role does not exist.
Create Role
POST /api/v1/projects/{project.uuid}/roles
Creates a role at the end of the list.
Requires can_edit_project and can_edit_members.
JSON Params
| Field | Type | Description |
|---|---|---|
| name | string | 1–255 characters |
| permissions | integer | Permission bitmask, ≥ 0 |
Example Request
{
"name": "Production",
"permissions": 206158430208
}
That is can_view_warehouses + can_edit_warehouses.
Response
201 Created
{
"uuid": "0199a8d3-0a1b-7c2d-8e3f-405162738495"
}
Errors
| Status | Code | When |
|---|---|---|
| 400 | REQ_VALIDATION_FAILED |
The body does not match the schema, or permissions has unknown bits |
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_PROJECT_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 404 | RES_NOT_FOUND |
The project does not exist or is not accessible |
Modify Role
PATCH /api/v1/projects/{project.uuid}/roles/{role.uuid}
Updates any of name, permissions, order (integer ≥ 0). At least one must be present. A change of permissions
applies to every member with this role immediately.
Requires can_edit_project and can_edit_members.
Response
204 No Content
Errors
| Status | Code | When |
|---|---|---|
| 400 | REQ_VALIDATION_FAILED |
The body does not match the schema, or permissions has unknown bits |
| 400 | REQ_NO_DATA_PROVIDED |
The body has no fields |
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_PROJECT_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 404 | RES_NOT_FOUND |
The project or role does not exist |
Replace Role
PUT /api/v1/projects/{project.uuid}/roles/{role.uuid}
Same as Modify Role, but name, permissions and order are all required.
Delete Role
DELETE /api/v1/projects/{project.uuid}/roles/{role.uuid}
Deletes the role. Members who had it are left without a role and lose access to the project until they are given another one through Modify Member. Move them to another role first.
Requires can_edit_project and can_edit_members.
Response
204 No Content
Errors
| Status | Code | When |
|---|---|---|
| 403 | AUTH_INSUFFICIENT_SCOPE |
The token lacks projects or members |
| 403 | AUTH_NO_PROJECT_ACCESS |
The user's role lacks can_edit_project or can_edit_members |
| 404 | RES_NOT_FOUND |
The project or role does not exist |