Teams, organization & audit log
All requests below use Authorization: Bearer <access_token> — see Authentication. List endpoints accept ?limit= and ?cursor= — see Response format & pagination.
Teams
{
"id": "5b1c...",
"org_id": "7a1c2e3f-...",
"name": "Platform",
"icon_index": 2,
"color": "#22C55E",
"created_at": "2026-01-10T08:00:00.000Z"
}
GET /v1/teams — paginated list.
curl -s https://api.oneguard.one/v1/teams \
-H "Authorization: Bearer $TOKEN"POST /v1/teams — returns 201 with a Location header.
curl -s https://api.oneguard.one/v1/teams \
-X POST \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"name":"Platform"}'GET /v1/teams/{teamId}
curl -s https://api.oneguard.one/v1/teams/{teamId} \
-H "Authorization: Bearer $TOKEN"PATCH /v1/teams/{teamId} — partial, any of name, icon_index, color.
curl -s https://api.oneguard.one/v1/teams/{teamId} \
-X PATCH \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"name":"New name"}'DELETE /v1/teams/{teamId} — 204 No Content.
curl -s https://api.oneguard.one/v1/teams/{teamId} \
-X DELETE \
-H "Authorization: Bearer $TOKEN"Team members
{
"id": "8c2f...",
"team_id": "5b1c...",
"user": { "id": "3f1a...", "name": "Sam", "email": "sam@example.com" },
"created_at": "2026-01-11T09:00:00.000Z"
}
GET /v1/teams/{teamId}/members — paginated list.
curl -s https://api.oneguard.one/v1/teams/{teamId}/members \
-H "Authorization: Bearer $TOKEN"POST /v1/teams/{teamId}/members — there is no role on a team member; membership itself is the only state.
curl -s https://api.oneguard.one/v1/teams/{teamId}/members \
-X POST \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"user_id":"3f1a..."}'DELETE /v1/teams/{teamId}/members/{memberId} — 204 No Content. There is no PATCH: team membership has nothing to update besides removing it.
curl -s https://api.oneguard.one/v1/teams/{teamId}/members/{memberId} \
-X DELETE \
-H "Authorization: Bearer $TOKEN"Organization
GET /v1/org
The calling key's own organization.
curl -s https://api.oneguard.one/v1/org \
-H "Authorization: Bearer $TOKEN"{
"id": "7a1c2e3f-...",
"name": "Acme Inc",
"plan": "pro",
"emoji_icon": "🛡️",
"color": "#4F46E5",
"created_at": "2026-01-01T00:00:00.000Z"
}
Organization members
{
"id": "9e2a...",
"org_id": "7a1c2e3f-...",
"user": { "id": "3f1a...", "name": "Sam", "email": "sam@example.com" },
"email": "sam@example.com",
"role": "member",
"status": "active",
"created_at": "2026-01-05T12:00:00.000Z"
}
GET /v1/org/members — paginated list.
curl -s https://api.oneguard.one/v1/org/members \
-H "Authorization: Bearer $TOKEN"PATCH /v1/org/members/{memberId} — an admin-acting key can never grant a role above its own effective role.
curl -s https://api.oneguard.one/v1/org/members/{memberId} \
-X PATCH \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"role":"admin"}'DELETE /v1/org/members/{memberId} — 204 No Content.
curl -s https://api.oneguard.one/v1/org/members/{memberId} \
-X DELETE \
-H "Authorization: Bearer $TOKEN"Invitations
{
"id": "1a2b...",
"org_id": "7a1c2e3f-...",
"invitee_email": "new.person@example.com",
"role": "member",
"status": "pending",
"expires_at": "2026-09-30T00:00:00.000Z",
"created_at": "2026-09-23T10:00:00.000Z"
}
GET /v1/org/invitations — paginated list.
curl -s https://api.oneguard.one/v1/org/invitations \
-H "Authorization: Bearer $TOKEN"POST /v1/org/invitations — "owner" cannot be granted by invitation; ownership only transfers by changing an existing member's role.
curl -s https://api.oneguard.one/v1/org/invitations \
-X POST \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"email":"new.person@example.com","role":"member"}'Audit log
GET /v1/audit
{
"id": "6f3a...",
"action": "secret.value.read",
"resource": "secret:3cb0cce2-...",
"user_name": "Sam",
"ip_address": "203.0.113.7",
"success": true,
"type": "read",
"time": "2026-09-23T14:58:02.000Z"
}
curl -s https://api.oneguard.one/v1/audit \
-H "Authorization: Bearer $TOKEN"