Accounts.
A key can read a little about its own account. Creating users and groups, and changing them, needs an administrator key.
See the API reference for the key and for errors. Changing a password or an authenticator app is not in this list.
The signed-in account
GET /api/v1/auth/me
Who the caller is.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
id | string | required | The id. |
email | string | required | An email address. |
display_name | string | required | |
is_admin | boolean | required | |
csrf_token | string | required | Sent so the portal can put it on every request that changes something. It is derived from the session, so it is not a second thing to store or expire. |
totp_enrolled | boolean | required |
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"display_name": "example",
"is_admin": true,
"csrf_token": "example",
"totp_enrolled": true
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
csrf_token is an empty string for an API key. A key does not send x-farwing-csrf.POST /api/v1/auth/sign-out-everywhere
End every session this account has.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Request body. None.
Success. 200.
JSON object.
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
GET /api/v1/profile/recovery-codes
How many recovery codes are left.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
total | integer | required | How many matched, including ones not on this page. |
unused | integer | required |
{
"total": 1,
"unused": 1
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
GET /api/v1/profile/sessions
Where this account is signed in.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Success. 200.
The body is an array.
| Field | Type | Meaning | |
|---|---|---|---|
id | string | required | The id. |
createdAt | string | required | A time, as RFC 3339. |
lastUsedAt | string | required | A time, as RFC 3339. |
expiresAt | string | required | A time, as RFC 3339. |
userAgent | string | optional, left out when empty | |
ip | string | optional, left out when empty | |
current | boolean | required | Which row is the browser asking. Without it, "sign this one out" is a guess. |
[
{
"id": "k7Qm2sLp9vX4aB1c",
"createdAt": "2026-10-05T18:00:00Z",
"lastUsedAt": "2026-10-05T18:00:00Z",
"expiresAt": "2026-10-05T18:00:00Z",
"userAgent": "example",
"ip": "example",
"current": true
}
]
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
DELETE /api/v1/profile/sessions/{id}
End one of them.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
ok | boolean | required |
{
"ok": true
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 404 | not_found | not there, or not visible to this caller |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "not_found",
"message": "not found"
}
}
Users
GET /api/v1/users
Every account.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Each account has clients: the last version of the farwing command line and of Farwing Desktop it was used from, newest first. Empty for an account only used in a browser.
Success. 200.
The body is an array.
| Field | Type | Meaning | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||
email | string | required | An email address. | ||||||||||||||||
displayName | string | required | |||||||||||||||||
isAdmin | boolean | required | |||||||||||||||||
disabled | boolean | required | |||||||||||||||||
totpEnrolled | boolean | required | Whether a second factor is set up. The secret itself never leaves the server after enrollment. | ||||||||||||||||
totpRequired | boolean | required | |||||||||||||||||
hasPassword | boolean | required | False for an account that signs in through single sign-on only, so the screen can say why there is no password to reset. | ||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||
lastLoginAt | string | optional, left out when empty | A time, as RFC 3339. | ||||||||||||||||
clients | array of ClientSeen | optional, left out when empty | The Farwing clients the account was last used from. In the list of accounts only. | ||||||||||||||||
Each item is an object:
| |||||||||||||||||||
[
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example",
"isAdmin": true,
"disabled": true,
"totpEnrolled": true,
"totpRequired": true,
"hasPassword": true,
"createdAt": "2026-10-05T18:00:00Z"
}
]
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
POST /api/v1/users
Make an account.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
email | string | required | An email address. |
displayName | string | required | |
password | string | optional | Optional. Leaving it out makes an account that can only sign in through single sign-on, which is the right shape for an organization that has it configured. |
isAdmin | boolean | optional | |
totpRequired | boolean | optional |
{
"email": "[email protected]",
"displayName": "example",
"password": "a-secret-shown-once",
"isAdmin": true,
"totpRequired": true
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||
email | string | required | An email address. | ||||||||||||||||
displayName | string | required | |||||||||||||||||
isAdmin | boolean | required | |||||||||||||||||
disabled | boolean | required | |||||||||||||||||
totpEnrolled | boolean | required | Whether a second factor is set up. The secret itself never leaves the server after enrollment. | ||||||||||||||||
totpRequired | boolean | required | |||||||||||||||||
hasPassword | boolean | required | False for an account that signs in through single sign-on only, so the screen can say why there is no password to reset. | ||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||
lastLoginAt | string | optional, left out when empty | A time, as RFC 3339. | ||||||||||||||||
clients | array of ClientSeen | optional, left out when empty | The Farwing clients the account was last used from. In the list of accounts only. | ||||||||||||||||
Each item is an object:
| |||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example",
"isAdmin": true,
"disabled": true,
"totpEnrolled": true,
"totpRequired": true,
"hasPassword": true,
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | the address is taken, or the password was refused |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "the address is taken, or the password was refused"
}
}
PATCH /api/v1/users/{id}
Change an account. The last administrator cannot be demoted or disabled.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
displayName | string | optional | |
isAdmin | boolean | optional | |
disabled | boolean | optional | |
totpRequired | boolean | optional |
{
"displayName": "example",
"isAdmin": true,
"disabled": true,
"totpRequired": true
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||
email | string | required | An email address. | ||||||||||||||||
displayName | string | required | |||||||||||||||||
isAdmin | boolean | required | |||||||||||||||||
disabled | boolean | required | |||||||||||||||||
totpEnrolled | boolean | required | Whether a second factor is set up. The secret itself never leaves the server after enrollment. | ||||||||||||||||
totpRequired | boolean | required | |||||||||||||||||
hasPassword | boolean | required | False for an account that signs in through single sign-on only, so the screen can say why there is no password to reset. | ||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||
lastLoginAt | string | optional, left out when empty | A time, as RFC 3339. | ||||||||||||||||
clients | array of ClientSeen | optional, left out when empty | The Farwing clients the account was last used from. In the list of accounts only. | ||||||||||||||||
Each item is an object:
| |||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example",
"isAdmin": true,
"disabled": true,
"totpEnrolled": true,
"totpRequired": true,
"hasPassword": true,
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | the change would leave the server with no administrator |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "the change would leave the server with no administrator"
}
}
DELETE /api/v1/users/{id}
Delete an account.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
deleted | boolean | required |
{
"deleted": true
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | you cannot delete your own account |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "you cannot delete your own account"
}
}
POST /api/v1/users/{id}/password
Set someone's password. Signs them out everywhere.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
password | string | required |
{
"password": "a-secret-shown-once"
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||
email | string | required | An email address. | ||||||||||||||||
displayName | string | required | |||||||||||||||||
isAdmin | boolean | required | |||||||||||||||||
disabled | boolean | required | |||||||||||||||||
totpEnrolled | boolean | required | Whether a second factor is set up. The secret itself never leaves the server after enrollment. | ||||||||||||||||
totpRequired | boolean | required | |||||||||||||||||
hasPassword | boolean | required | False for an account that signs in through single sign-on only, so the screen can say why there is no password to reset. | ||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||
lastLoginAt | string | optional, left out when empty | A time, as RFC 3339. | ||||||||||||||||
clients | array of ClientSeen | optional, left out when empty | The Farwing clients the account was last used from. In the list of accounts only. | ||||||||||||||||
Each item is an object:
| |||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example",
"isAdmin": true,
"disabled": true,
"totpEnrolled": true,
"totpRequired": true,
"hasPassword": true,
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | the request is not valid |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "the request is not valid"
}
}
POST /api/v1/users/{id}/clear-second-factor
Clear a lost authenticator, and its recovery codes.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. None.
Success. 200.
| Field | Type | Meaning | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||
email | string | required | An email address. | ||||||||||||||||
displayName | string | required | |||||||||||||||||
isAdmin | boolean | required | |||||||||||||||||
disabled | boolean | required | |||||||||||||||||
totpEnrolled | boolean | required | Whether a second factor is set up. The secret itself never leaves the server after enrollment. | ||||||||||||||||
totpRequired | boolean | required | |||||||||||||||||
hasPassword | boolean | required | False for an account that signs in through single sign-on only, so the screen can say why there is no password to reset. | ||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||
lastLoginAt | string | optional, left out when empty | A time, as RFC 3339. | ||||||||||||||||
clients | array of ClientSeen | optional, left out when empty | The Farwing clients the account was last used from. In the list of accounts only. | ||||||||||||||||
Each item is an object:
| |||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example",
"isAdmin": true,
"disabled": true,
"totpEnrolled": true,
"totpRequired": true,
"hasPassword": true,
"createdAt": "2026-10-05T18:00:00Z"
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
Groups
GET /api/v1/admin/groups
Every group, with how many people are in it and how many folders it reaches.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Success. 200.
The body is an array.
| Field | Type | Meaning | |
|---|---|---|---|
id | string | required | The id. |
name | string | required | The name. |
createdAt | string | required | A time, as RFC 3339. |
members | integer | required | How many people are in it. |
shares | integer | required | How many folders it has been shared, so the list says what a group reaches without the administrator having to open each one. |
[
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"createdAt": "2026-10-05T18:00:00Z",
"members": 1,
"shares": 1
}
]
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
POST /api/v1/admin/groups
Make a group.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
name | string | required | The name. |
{
"name": "Rush delivery"
}
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
id | string | required | The id. |
name | string | required | The name. |
createdAt | string | required | A time, as RFC 3339. |
members | integer | required | How many people are in it. |
shares | integer | required | How many folders it has been shared, so the list says what a group reaches without the administrator having to open each one. |
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"createdAt": "2026-10-05T18:00:00Z",
"members": 1,
"shares": 1
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 409 | conflict | the name is taken |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "conflict",
"message": "the name is taken"
}
}
GET /api/v1/admin/groups/{id}
One group, its members and its shared folders.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||||||||||||||||||
name | string | required | The name. | ||||||||||||||||||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||||||||||||||||||
members | array of objects | required | |||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||
shares | array of objects | required | |||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"createdAt": "2026-10-05T18:00:00Z",
"members": [
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example"
}
],
"shares": [
{
"id": "k7Qm2sLp9vX4aB1c",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"canRead": true,
"canWrite": true,
"canDelete": true
}
]
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
PATCH /api/v1/admin/groups/{id}
Rename it.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
name | string | required | The name. |
{
"name": "Rush delivery"
}
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
id | string | required | The id. |
name | string | required | The name. |
createdAt | string | required | A time, as RFC 3339. |
members | integer | required | How many people are in it. |
shares | integer | required | How many folders it has been shared, so the list says what a group reaches without the administrator having to open each one. |
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"createdAt": "2026-10-05T18:00:00Z",
"members": 1,
"shares": 1
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 409 | conflict | the name is taken |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "conflict",
"message": "the name is taken"
}
}
DELETE /api/v1/admin/groups/{id}
Remove it. Memberships and grants go; no file is touched.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Success. 200.
JSON object.
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
POST /api/v1/admin/groups/{id}/members
Put somebody in the group. Doing it twice is not an error.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
userId | string | required | The id. |
{
"userId": "k7Qm2sLp9vX4aB1c"
}
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
id | string | required | The id. | ||||||||||||||||||||||||||||||||
name | string | required | The name. | ||||||||||||||||||||||||||||||||
createdAt | string | required | A time, as RFC 3339. | ||||||||||||||||||||||||||||||||
members | array of objects | required | |||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||
shares | array of objects | required | |||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||
{
"id": "k7Qm2sLp9vX4aB1c",
"name": "Rush delivery",
"createdAt": "2026-10-05T18:00:00Z",
"members": [
{
"id": "k7Qm2sLp9vX4aB1c",
"email": "[email protected]",
"displayName": "example"
}
],
"shares": [
{
"id": "k7Qm2sLp9vX4aB1c",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"canRead": true,
"canWrite": true,
"canDelete": true
}
]
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | no such account |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "no such account"
}
}
DELETE /api/v1/admin/groups/{id}/members/{user_id}
Take them out again.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The group. |
user_id | path | string | required | The account. |
Success. 200.
JSON object.
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}
POST /api/v1/admin/groups/{id}/shares
Give the group a folder, or change the rights it has on one. Prefer a space grant.
Still served, so an older script keeps working. New scripts should use spaces.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The resource's id. |
Request body. JSON.
A field the server does not know is refused with 400.
| Field | Type | Meaning | |
|---|---|---|---|
rootId | string | required | The id. |
path | string | optional | Left out means the whole root, which is the widest share there is and therefore has to be typed deliberately rather than arrived at. |
canRead | boolean | optional | |
canWrite | boolean | optional | |
canDelete | boolean | optional |
{
"rootId": "k7Qm2sLp9vX4aB1c",
"path": "projects/rush",
"canRead": true,
"canWrite": true,
"canDelete": true
}
Success. 200.
| Field | Type | Meaning | |
|---|---|---|---|
id | string | required | The id. |
rootId | string | required | The id. |
rootName | string | required | The storage location's name. |
path | string | required | Relative to the storage location. Empty is the whole location. |
canRead | boolean | required | |
canWrite | boolean | required | |
canDelete | boolean | required |
{
"id": "k7Qm2sLp9vX4aB1c",
"rootId": "k7Qm2sLp9vX4aB1c",
"rootName": "example",
"path": "projects/rush",
"canRead": true,
"canWrite": true,
"canDelete": true
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 400 | bad_request | a share with none of read, write or delete |
| 404 | not_found | no such group or storage location |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "bad_request",
"message": "a share with none of read, write or delete"
}
}
DELETE /api/v1/admin/groups/{id}/shares/{grant_id}
Take the folder away. Nothing is deleted.
Who. An administrator, with a key that has the admin scope. An administrator's key that does not have that scope is refused. The key needs a license that includes the REST API.
Parameters.
| Name | In | Type | Meaning | |
|---|---|---|---|---|
id | path | string | required | The group. |
grant_id | path | string | required | The share. |
Success. 200.
JSON object.
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 404 | not_found | not there, or not visible to this caller |
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "not_found",
"message": "not found"
}
}
The signed-in account
GET /api/v1/profile/traffic
The caller's own effective speed limits.
Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.
Success. 200.
| Field | Type | Meaning | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
perTransferBps | integer | optional | |||||||||||||||||||||||||||||||||
poolBps | integer | optional | |||||||||||||||||||||||||||||||||
concurrency | integer | optional | |||||||||||||||||||||||||||||||||
limitedBy | string | required | |||||||||||||||||||||||||||||||||
sentence | string | required | |||||||||||||||||||||||||||||||||
layers | array of objects | required | Every rule that took part, license first, the person's own last. | ||||||||||||||||||||||||||||||||
Each item is an object:
| |||||||||||||||||||||||||||||||||||
winners | object | required | The layer that set each number. | ||||||||||||||||||||||||||||||||
It is an object:
| |||||||||||||||||||||||||||||||||||
{
"perTransferBps": 1,
"poolBps": 1,
"concurrency": 1,
"limitedBy": "example",
"sentence": "example",
"layers": [
{
"kind": "file",
"id": "k7Qm2sLp9vX4aB1c",
"groupKind": "example",
"totalBps": 1,
"perTransferBps": 1,
"concurrency": 1,
"overridden": [
"example"
]
}
],
"winners": {
"total": "example",
"perTransfer": "example",
"concurrency": "example"
}
}
Errors. The body always has the shape in Errors. Match on code.
| Status | code | When |
|---|---|---|
| 401 | unauthenticated | no key, or a key that is unknown, expired, revoked, or owned by a disabled account |
| 403 | forbidden | the key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator |
| 402 | licence_required | the license does not include the REST API |
{
"error": {
"code": "unauthenticated",
"message": "sign in to continue"
}
}