curl --request POST \
--url https://workspace.basaltic.sh/v1/users \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"email": "john.doe@acme.com",
"tags": {
"environment": "production",
"team": "backend"
},
"groups": [
"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers"
]
}
'import requests
url = "https://workspace.basaltic.sh/v1/users"
payload = {
"email": "john.doe@acme.com",
"tags": {
"environment": "production",
"team": "backend"
},
"groups": ["crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
email: 'john.doe@acme.com',
tags: {environment: 'production', team: 'backend'},
groups: [
'crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers'
]
})
};
fetch('https://workspace.basaltic.sh/v1/users', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://workspace.basaltic.sh/v1/users",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => 'john.doe@acme.com',
'tags' => [
'environment' => 'production',
'team' => 'backend'
],
'groups' => [
'crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://workspace.basaltic.sh/v1/users"
payload := strings.NewReader("{\n \"email\": \"john.doe@acme.com\",\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n },\n \"groups\": [\n \"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://workspace.basaltic.sh/v1/users")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"email\": \"john.doe@acme.com\",\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n },\n \"groups\": [\n \"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://workspace.basaltic.sh/v1/users")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"email\": \"john.doe@acme.com\",\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n },\n \"groups\": [\n \"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"invitation": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"email": "jane.doe@example.com",
"groups": [
{
"id": "a1b2c3d4-e5f6-7890-1234-567890abcdef",
"name": "developers"
}
],
"invited_by": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"name": "John Doe",
"email": "john.doe@acme.com",
"type": "user",
"crn": "<string>",
"account_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"status": "pending",
"expires_at": "2026-01-22T09:30:00Z",
"created_at": "2026-01-15T09:30:00Z",
"crn": "crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/invitation/550e8400-e29b-41d4-a716-446655440002"
},
"status": "invited"
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "IDEMPOTENCY_KEY_REUSED",
"message": "This Idempotency-Key was already used with a different request payload",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}Add user to organization
Invite a user to the organization by email. An invitation email is always sent and the user joins on accepting it — there is no path that adds someone without their consent, even when they already have a platform account. Inviting an existing member, or someone who already has a pending invitation, is rejected with 409.
Optionally specify groups to add the user to on acceptance.
curl --request POST \
--url https://workspace.basaltic.sh/v1/users \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"email": "john.doe@acme.com",
"tags": {
"environment": "production",
"team": "backend"
},
"groups": [
"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers"
]
}
'import requests
url = "https://workspace.basaltic.sh/v1/users"
payload = {
"email": "john.doe@acme.com",
"tags": {
"environment": "production",
"team": "backend"
},
"groups": ["crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
email: 'john.doe@acme.com',
tags: {environment: 'production', team: 'backend'},
groups: [
'crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers'
]
})
};
fetch('https://workspace.basaltic.sh/v1/users', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://workspace.basaltic.sh/v1/users",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => 'john.doe@acme.com',
'tags' => [
'environment' => 'production',
'team' => 'backend'
],
'groups' => [
'crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://workspace.basaltic.sh/v1/users"
payload := strings.NewReader("{\n \"email\": \"john.doe@acme.com\",\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n },\n \"groups\": [\n \"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://workspace.basaltic.sh/v1/users")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"email\": \"john.doe@acme.com\",\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n },\n \"groups\": [\n \"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://workspace.basaltic.sh/v1/users")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"email\": \"john.doe@acme.com\",\n \"tags\": {\n \"environment\": \"production\",\n \"team\": \"backend\"\n },\n \"groups\": [\n \"crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/group/developers\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"invitation": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"email": "jane.doe@example.com",
"groups": [
{
"id": "a1b2c3d4-e5f6-7890-1234-567890abcdef",
"name": "developers"
}
],
"invited_by": {
"id": "550e8400-e29b-41d4-a716-446655440000",
"name": "John Doe",
"email": "john.doe@acme.com",
"type": "user",
"crn": "<string>",
"account_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
},
"status": "pending",
"expires_at": "2026-01-22T09:30:00Z",
"created_at": "2026-01-15T09:30:00Z",
"crn": "crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/invitation/550e8400-e29b-41d4-a716-446655440002"
},
"status": "invited"
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "IDEMPOTENCY_KEY_REUSED",
"message": "This Idempotency-Key was already used with a different request payload",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}workspace:AddUser. See WORKSPACE permissions for the full list, what each one covers, and an example policy.Authorizations
An OAuth 2.0 bearer token, sent as Authorization: Bearer <token>.
This is the recommended way to authenticate.
Get one by exchanging a service account's access key pair at
POST /v1/oauth/token with grant_type=client_credentials. It is the
standard client-credentials grant, so any OAuth-aware library will
obtain and refresh it for you.
curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
https://iam.basaltic.sh/v1/oauth/token
Tokens last an hour by default. The same access key pair is separately your AWS SigV4 credential for the S3-compatible object endpoint, which speaks nothing else.
Headers
Optional client-generated key that makes a create replay-safe. Retrying a request with the same key returns the original outcome verbatim instead of creating a duplicate resource. Reusing a key with a different request body is rejected (422); a request whose key is still being processed returns 409. Records are honored for 24 hours. Use a UUID or similarly unique token.
255Body
Email of the user to add
"john.doe@acme.com"
Show child attributes
Show child attributes
{
"environment": "production",
"team": "backend"
}
Groups to assign when the invitation is accepted. Each reference is validated in the caller organization before the invitation is created.
Group UUID, immutable name in the authenticated organization, or organization-qualified Workspace CRN. Groups contain users only.