API

Accounts.

A key can read a little about its own account. Creating users and groups, and changing them, needs an administrator key.

See the API reference for the key and for errors. Changing a password or an authenticator app is not in this list.

The signed-in account

GET /api/v1/auth/me

Who the caller is.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
display_namestringrequired
is_adminbooleanrequired
csrf_tokenstringrequiredSent so the portal can put it on every request that changes something. It is derived from the session, so it is not a second thing to store or expire.
totp_enrolledbooleanrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "email": "[email protected]",
  "display_name": "example",
  "is_admin": true,
  "csrf_token": "example",
  "totp_enrolled": true
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}
csrf_token is an empty string for an API key. A key does not send x-farwing-csrf.

POST /api/v1/auth/sign-out-everywhere

End every session this account has.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Request body. None.

Success. 200.

JSON object.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}
This ends browser sessions for the account. It does not revoke the API key.

GET /api/v1/profile/recovery-codes

How many recovery codes are left.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Success. 200.

FieldTypeMeaning
totalintegerrequiredHow many matched, including ones not on this page.
unusedintegerrequired
{
  "total": 1,
  "unused": 1
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}
The reply is only how many codes exist and how many are unused. It never returns a code. Replacing the codes is refused to an API key.

GET /api/v1/profile/sessions

Where this account is signed in.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Success. 200.

The body is an array.

FieldTypeMeaning
idstringrequiredThe id.
createdAtstringrequiredA time, as RFC 3339.
lastUsedAtstringrequiredA time, as RFC 3339.
expiresAtstringrequiredA time, as RFC 3339.
userAgentstringoptional, left out when empty
ipstringoptional, left out when empty
currentbooleanrequiredWhich row is the browser asking. Without it, "sign this one out" is a guess.
[
  {
    "id": "k7Qm2sLp9vX4aB1c",
    "createdAt": "2026-10-05T18:00:00Z",
    "lastUsedAt": "2026-10-05T18:00:00Z",
    "expiresAt": "2026-10-05T18:00:00Z",
    "userAgent": "example",
    "ip": "example",
    "current": true
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

DELETE /api/v1/profile/sessions/{id}

End one of them.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
okbooleanrequired
{
  "ok": true
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundnot there, or not visible to this caller
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}

Users

GET /api/v1/users

Every account.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Each account has clients: the last version of the farwing command line and of Farwing Desktop it was used from, newest first. Empty for an account only used in a browser.

Success. 200.

The body is an array.

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
isAdminbooleanrequired
disabledbooleanrequired
totpEnrolledbooleanrequiredWhether a second factor is set up. The secret itself never leaves the server after enrollment.
totpRequiredbooleanrequired
hasPasswordbooleanrequiredFalse for an account that signs in through single sign-on only, so the screen can say why there is no password to reset.
createdAtstringrequiredA time, as RFC 3339.
lastLoginAtstringoptional, left out when emptyA time, as RFC 3339.
clientsarray of ClientSeenoptional, left out when emptyThe Farwing clients the account was last used from. In the list of accounts only.

Each item is an object:

FieldTypeMeaning
clientstringrequiredcli or desktop.
versionstringrequiredThe version the client gave, such as 0.5.0.
seenAtstringrequiredWhen it was last seen, RFC 3339.
[
  {
    "id": "k7Qm2sLp9vX4aB1c",
    "email": "[email protected]",
    "displayName": "example",
    "isAdmin": true,
    "disabled": true,
    "totpEnrolled": true,
    "totpRequired": true,
    "hasPassword": true,
    "createdAt": "2026-10-05T18:00:00Z"
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

POST /api/v1/users

Make an account.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
emailstringrequiredAn email address.
displayNamestringrequired
passwordstringoptionalOptional. Leaving it out makes an account that can only sign in through single sign-on, which is the right shape for an organization that has it configured.
isAdminbooleanoptional
totpRequiredbooleanoptional
{
  "email": "[email protected]",
  "displayName": "example",
  "password": "a-secret-shown-once",
  "isAdmin": true,
  "totpRequired": true
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
isAdminbooleanrequired
disabledbooleanrequired
totpEnrolledbooleanrequiredWhether a second factor is set up. The secret itself never leaves the server after enrollment.
totpRequiredbooleanrequired
hasPasswordbooleanrequiredFalse for an account that signs in through single sign-on only, so the screen can say why there is no password to reset.
createdAtstringrequiredA time, as RFC 3339.
lastLoginAtstringoptional, left out when emptyA time, as RFC 3339.
clientsarray of ClientSeenoptional, left out when emptyThe Farwing clients the account was last used from. In the list of accounts only.

Each item is an object:

FieldTypeMeaning
clientstringrequiredcli or desktop.
versionstringrequiredThe version the client gave, such as 0.5.0.
seenAtstringrequiredWhen it was last seen, RFC 3339.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "email": "[email protected]",
  "displayName": "example",
  "isAdmin": true,
  "disabled": true,
  "totpEnrolled": true,
  "totpRequired": true,
  "hasPassword": true,
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe address is taken, or the password was refused
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the address is taken, or the password was refused"
  }
}

PATCH /api/v1/users/{id}

Change an account. The last administrator cannot be demoted or disabled.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
displayNamestringoptional
isAdminbooleanoptional
disabledbooleanoptional
totpRequiredbooleanoptional
{
  "displayName": "example",
  "isAdmin": true,
  "disabled": true,
  "totpRequired": true
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
isAdminbooleanrequired
disabledbooleanrequired
totpEnrolledbooleanrequiredWhether a second factor is set up. The secret itself never leaves the server after enrollment.
totpRequiredbooleanrequired
hasPasswordbooleanrequiredFalse for an account that signs in through single sign-on only, so the screen can say why there is no password to reset.
createdAtstringrequiredA time, as RFC 3339.
lastLoginAtstringoptional, left out when emptyA time, as RFC 3339.
clientsarray of ClientSeenoptional, left out when emptyThe Farwing clients the account was last used from. In the list of accounts only.

Each item is an object:

FieldTypeMeaning
clientstringrequiredcli or desktop.
versionstringrequiredThe version the client gave, such as 0.5.0.
seenAtstringrequiredWhen it was last seen, RFC 3339.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "email": "[email protected]",
  "displayName": "example",
  "isAdmin": true,
  "disabled": true,
  "totpEnrolled": true,
  "totpRequired": true,
  "hasPassword": true,
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe change would leave the server with no administrator
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the change would leave the server with no administrator"
  }
}

DELETE /api/v1/users/{id}

Delete an account.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
deletedbooleanrequired
{
  "deleted": true
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestyou cannot delete your own account
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "you cannot delete your own account"
  }
}

POST /api/v1/users/{id}/password

Set someone's password. Signs them out everywhere.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
passwordstringrequired
{
  "password": "a-secret-shown-once"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
isAdminbooleanrequired
disabledbooleanrequired
totpEnrolledbooleanrequiredWhether a second factor is set up. The secret itself never leaves the server after enrollment.
totpRequiredbooleanrequired
hasPasswordbooleanrequiredFalse for an account that signs in through single sign-on only, so the screen can say why there is no password to reset.
createdAtstringrequiredA time, as RFC 3339.
lastLoginAtstringoptional, left out when emptyA time, as RFC 3339.
clientsarray of ClientSeenoptional, left out when emptyThe Farwing clients the account was last used from. In the list of accounts only.

Each item is an object:

FieldTypeMeaning
clientstringrequiredcli or desktop.
versionstringrequiredThe version the client gave, such as 0.5.0.
seenAtstringrequiredWhen it was last seen, RFC 3339.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "email": "[email protected]",
  "displayName": "example",
  "isAdmin": true,
  "disabled": true,
  "totpEnrolled": true,
  "totpRequired": true,
  "hasPassword": true,
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe request is not valid
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the request is not valid"
  }
}

POST /api/v1/users/{id}/clear-second-factor

Clear a lost authenticator, and its recovery codes.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. None.

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
isAdminbooleanrequired
disabledbooleanrequired
totpEnrolledbooleanrequiredWhether a second factor is set up. The secret itself never leaves the server after enrollment.
totpRequiredbooleanrequired
hasPasswordbooleanrequiredFalse for an account that signs in through single sign-on only, so the screen can say why there is no password to reset.
createdAtstringrequiredA time, as RFC 3339.
lastLoginAtstringoptional, left out when emptyA time, as RFC 3339.
clientsarray of ClientSeenoptional, left out when emptyThe Farwing clients the account was last used from. In the list of accounts only.

Each item is an object:

FieldTypeMeaning
clientstringrequiredcli or desktop.
versionstringrequiredThe version the client gave, such as 0.5.0.
seenAtstringrequiredWhen it was last seen, RFC 3339.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "email": "[email protected]",
  "displayName": "example",
  "isAdmin": true,
  "disabled": true,
  "totpEnrolled": true,
  "totpRequired": true,
  "hasPassword": true,
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

Groups

GET /api/v1/admin/groups

Every group, with how many people are in it and how many folders it reaches.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Success. 200.

The body is an array.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
createdAtstringrequiredA time, as RFC 3339.
membersintegerrequiredHow many people are in it.
sharesintegerrequiredHow many folders it has been shared, so the list says what a group reaches without the administrator having to open each one.
[
  {
    "id": "k7Qm2sLp9vX4aB1c",
    "name": "Rush delivery",
    "createdAt": "2026-10-05T18:00:00Z",
    "members": 1,
    "shares": 1
  }
]

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

POST /api/v1/admin/groups

Make a group.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringrequiredThe name.
{
  "name": "Rush delivery"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
createdAtstringrequiredA time, as RFC 3339.
membersintegerrequiredHow many people are in it.
sharesintegerrequiredHow many folders it has been shared, so the list says what a group reaches without the administrator having to open each one.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "createdAt": "2026-10-05T18:00:00Z",
  "members": 1,
  "shares": 1
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
409conflictthe name is taken
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "conflict",
    "message": "the name is taken"
  }
}

GET /api/v1/admin/groups/{id}

One group, its members and its shared folders.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
createdAtstringrequiredA time, as RFC 3339.
membersarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
sharesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredRelative to the storage location. Empty is the whole location.
canReadbooleanrequired
canWritebooleanrequired
canDeletebooleanrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "createdAt": "2026-10-05T18:00:00Z",
  "members": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "email": "[email protected]",
      "displayName": "example"
    }
  ],
  "shares": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "rootId": "k7Qm2sLp9vX4aB1c",
      "rootName": "example",
      "path": "projects/rush",
      "canRead": true,
      "canWrite": true,
      "canDelete": true
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

PATCH /api/v1/admin/groups/{id}

Rename it.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringrequiredThe name.
{
  "name": "Rush delivery"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
createdAtstringrequiredA time, as RFC 3339.
membersintegerrequiredHow many people are in it.
sharesintegerrequiredHow many folders it has been shared, so the list says what a group reaches without the administrator having to open each one.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "createdAt": "2026-10-05T18:00:00Z",
  "members": 1,
  "shares": 1
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
409conflictthe name is taken
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "conflict",
    "message": "the name is taken"
  }
}

DELETE /api/v1/admin/groups/{id}

Remove it. Memberships and grants go; no file is touched.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

JSON object.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

POST /api/v1/admin/groups/{id}/members

Put somebody in the group. Doing it twice is not an error.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
userIdstringrequiredThe id.
{
  "userId": "k7Qm2sLp9vX4aB1c"
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
createdAtstringrequiredA time, as RFC 3339.
membersarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
displayNamestringrequired
sharesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredRelative to the storage location. Empty is the whole location.
canReadbooleanrequired
canWritebooleanrequired
canDeletebooleanrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "createdAt": "2026-10-05T18:00:00Z",
  "members": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "email": "[email protected]",
      "displayName": "example"
    }
  ],
  "shares": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "rootId": "k7Qm2sLp9vX4aB1c",
      "rootName": "example",
      "path": "projects/rush",
      "canRead": true,
      "canWrite": true,
      "canDelete": true
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestno such account
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "no such account"
  }
}

DELETE /api/v1/admin/groups/{id}/members/{user_id}

Take them out again.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe group.
user_idpathstringrequiredThe account.

Success. 200.

JSON object.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

POST /api/v1/admin/groups/{id}/shares

Give the group a folder, or change the rights it has on one. Prefer a space grant.

Still served, so an older script keeps working. New scripts should use spaces.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
rootIdstringrequiredThe id.
pathstringoptionalLeft out means the whole root, which is the widest share there is and therefore has to be typed deliberately rather than arrived at.
canReadbooleanoptional
canWritebooleanoptional
canDeletebooleanoptional
{
  "rootId": "k7Qm2sLp9vX4aB1c",
  "path": "projects/rush",
  "canRead": true,
  "canWrite": true,
  "canDelete": true
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredRelative to the storage location. Empty is the whole location.
canReadbooleanrequired
canWritebooleanrequired
canDeletebooleanrequired
{
  "id": "k7Qm2sLp9vX4aB1c",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "rootName": "example",
  "path": "projects/rush",
  "canRead": true,
  "canWrite": true,
  "canDelete": true
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requesta share with none of read, write or delete
404not_foundno such group or storage location
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "a share with none of read, write or delete"
  }
}

DELETE /api/v1/admin/groups/{id}/shares/{grant_id}

Take the folder away. Nothing is deleted.

Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe group.
grant_idpathstringrequiredThe share.

Success. 200.

JSON object.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundnot there, or not visible to this caller
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}

The signed-in account

GET /api/v1/profile/traffic

The caller's own effective speed limits.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Success. 200.

FieldTypeMeaning
perTransferBpsintegeroptional
poolBpsintegeroptional
concurrencyintegeroptional
limitedBystringrequired
sentencestringrequired
layersarray of objectsrequiredEvery rule that took part, license first, the person's own last.

Each item is an object:

FieldTypeMeaning
kindstringrequiredlicense, server, group or user.
idstringrequiredThe group or user id. Empty for the license and the server.
groupKindstringoptionalshared or member for a group rule.
totalBpsintegeroptional
perTransferBpsintegeroptional
concurrencyintegeroptional
overriddenarray of stringrequiredFields this layer sets that the person's own rule replaces: total, perTransfer, concurrency.
winnersobjectrequiredThe layer that set each number.

It is an object:

FieldTypeMeaning
totalstringoptionalHow many matched, including ones not on this page.
perTransferstringoptional
concurrencystringoptional
{
  "perTransferBps": 1,
  "poolBps": 1,
  "concurrency": 1,
  "limitedBy": "example",
  "sentence": "example",
  "layers": [
    {
      "kind": "file",
      "id": "k7Qm2sLp9vX4aB1c",
      "groupKind": "example",
      "totalBps": 1,
      "perTransferBps": 1,
      "concurrency": 1,
      "overridden": [
        "example"
      ]
    }
  ],
  "winners": {
    "total": "example",
    "perTransfer": "example",
    "concurrency": "example"
  }
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}