Skip to content
POST
/v1/organizations/{organizationId}/first-member

Provision an Organization's first management-plane human

Create the first Organization Member, WorkOS User binding, and Owner Grant after Cantora has bound the Organization to WorkOS. This operation is for Cantora operators.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$

Request body

Required.

application/json
object
  • unknown properties allowed false
workosUserIdrequired
stringThe provider-stable WorkOS User identifier to bind.
  • maximum length 512
  • minimum length 1
  • pattern ^[!-~]+$
emailAddressrequired
stringThe Organization Member's WorkOS email address.
  • maximum length 320
  • minimum length 3
  • pattern ^[^@\s]+@[^@\s]+$
displayNamerequired
stringThe Organization Member's human-readable name.
  • maximum length 200
  • minimum length 1

Responses

201OrganizationMemberProvisioned
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json
409Conflict
application/json

Reusable schemas

OrganizationMemberProvisionedEncoded

object
  • unknown properties allowed false
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
grantIdrequired
stringThe Grant identifier.
  • maximum length 64
  • pattern ^grant_[\s\S]+$
rolerequired
stringThe Organization role granted to the provisioned identity.
  • allowed values "owner"
workosUserIdrequired
stringThe provider-stable WorkOS User identifier.
emailAddressrequired
stringThe Organization Member's email address.
displayNamerequired
stringThe human-readable resource name.

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

ConflictEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Conflict"
resourcerequired
stringThe resource type relevant to the error.
reasonrequired
stringA safe explanation of the state conflict.