Account members

Modify account members

PATCH
/api/v2/members

Full use of this API resource is an Enterprise feature

The ability to perform a partial update to multiple members is available to customers on an Enterprise plan. If you are on another plan, you can update members individually. To learn more, read about our pricing. To upgrade your plan, contact Sales.

Perform a partial update to multiple members. Updating members uses the semantic patch format.

To make a semantic patch request, you must append domain-model=launchdarkly.semanticpatch to your Content-Type header. To learn more, read Updates using semantic patch.

Instructions

Semantic patch requests support the following kind instructions for updating members.

replaceMembersRoles

Replaces the roles of the specified members. This also removes all custom roles assigned to the specified members.

Parameters
  • value: The new role. Must be a valid base role. To learn more, read Roles.
  • memberIDs: List of member IDs.

Here's an example:

{  "instructions": [{    "kind": "replaceMembersRoles",    "value": "reader",    "memberIDs": [      "1234a56b7c89d012345e678f",      "507f1f77bcf86cd799439011"    ]  }]}

replaceAllMembersRoles

Replaces the roles of all members. This also removes all custom roles assigned to the specified members.

Members that match any of the filters are excluded from the update.

Parameters
  • value: The new role. Must be a valid base role. To learn more, read Roles.
  • filterLastSeen: (Optional) A JSON object with one of the following formats:
    • {"never": true} - Members that have never been active, such as those who have not accepted their invitation to LaunchDarkly, or have not logged in after being provisioned via SCIM.
    • {"noData": true} - Members that have not been active since LaunchDarkly began recording last seen timestamps.
    • {"before": 1608672063611} - Members that have not been active since the provided value, which should be a timestamp in Unix epoch milliseconds.
  • filterQuery: (Optional) A string that matches against the members' emails and names. It is not case sensitive.
  • filterRoles: (Optional) A | separated list of roles and custom roles. For the purposes of this filtering, Owner counts as Admin.
  • filterTeamKey: (Optional) A string that matches against the key of the team the members belong to. It is not case sensitive.
  • ignoredMemberIDs: (Optional) A list of member IDs.

Here's an example:

{  "instructions": [{    "kind": "replaceAllMembersRoles",    "value": "reader",    "filterLastSeen": { "never": true }  }]}

replaceMembersCustomRoles

Replaces the custom roles of the specified members.

Parameters
  • values: List of new custom roles. Must be a valid custom role key or ID.
  • memberIDs: List of member IDs.

Here's an example:

{  "instructions": [{    "kind": "replaceMembersCustomRoles",    "values": [ "example-custom-role" ],    "memberIDs": [      "1234a56b7c89d012345e678f",      "507f1f77bcf86cd799439011"    ]  }]}

replaceAllMembersCustomRoles

Replaces the custom roles of all members. Members that match any of the filters are excluded from the update.

Parameters
  • values: List of new roles. Must be a valid custom role key or ID.
  • filterLastSeen: (Optional) A JSON object with one of the following formats:
    • {"never": true} - Members that have never been active, such as those who have not accepted their invitation to LaunchDarkly, or have not logged in after being provisioned via SCIM.
    • {"noData": true} - Members that have not been active since LaunchDarkly began recording last seen timestamps.
    • {"before": 1608672063611} - Members that have not been active since the provided value, which should be a timestamp in Unix epoch milliseconds.
  • filterQuery: (Optional) A string that matches against the members' emails and names. It is not case sensitive.
  • filterRoles: (Optional) A | separated list of roles and custom roles. For the purposes of this filtering, Owner counts as Admin.
  • filterTeamKey: (Optional) A string that matches against the key of the team the members belong to. It is not case sensitive.
  • ignoredMemberIDs: (Optional) A list of member IDs.

Here's an example:

{  "instructions": [{    "kind": "replaceAllMembersCustomRoles",    "values": [ "example-custom-role" ],    "filterLastSeen": { "never": true }  }]}

replaceMembersRoleAttributes

Replaces the role attributes of the specified members.

Parameters
  • value: Map of role attribute keys to lists of values.
  • memberIDs: List of member IDs.

Here's an example:

{  "instructions": [{    "kind": "replaceMembersRoleAttributes",    "value": {      "myRoleProjectKey": ["mobile", "web"],      "myRoleEnvironmentKey": ["production"]    },    "memberIDs": [      "1234a56b7c89d012345e678f",      "507f1f77bcf86cd799439011"    ]  }]}

Authorization

ApiKey read, write
Authorization<token>

In: header

Scope: read, write

Request Body

application/json

comment?string

Optional comment describing the update

instructions*array<>

The instructions to perform when updating. This should be an array with objects that look like {"kind": "update_action"}. Some instructions also require additional parameters as part of this object.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PATCH "https://example.com/api/v2/members" \  -H "Content-Type: application/json" \  -d '{    "comment": "Optional comment about the update",    "instructions": [      {        "kind": "replaceMembersRoles",        "memberIDs": [          "1234a56b7c89d012345e678f",          "507f1f77bcf86cd799439011"        ],        "value": "reader"      }    ]  }'
{  "members": [    "1234a56b7c89d012345e678f"  ],  "errors": [    {      "507f1f77bcf86cd799439011": "you cannot modify your own role"    }  ]}

Invite new members POST

Invite one or more new members to join an account. Each member is sent an invitation. Members with Admin or Owner roles may create new members, as well as anyone with a `createMember` permission for "member/\*". If a member cannot be invited, the entire request is rejected and no members are invited from that request. Each member _must_ have an `email` field and either a `role` or a `customRoles` field. If any of the fields are not populated correctly, the request is rejected with the reason specified in the "message" field of the response. Valid base role names that you can provide for the `role` field include `reader`, `writer`, `admin`, `owner/admin`, and `no_access`. To learn more about base roles, read [Organization roles](https://launchdarkly.com/docs/home/account/roles/organization-roles). If you are using the `customRoles` field instead, you can provide the key for any role that you have created, or for any preset [organization role](https://launchdarkly.com/docs/home/account/roles/organization-roles) or [project role](https://launchdarkly.com/docs/home/account/roles/project-roles) provided by LaunchDarkly. Some preset roles additionally require that you specify `roleAttributes`. To learn more, read [Using role scope](https://launchdarkly.com/docs/home/account/roles/role-scope). Requests to create account members will not work if SCIM is enabled for the account. You can assign new members to teams with the `teamKeys` field. Teams are available only on Enterprise plans. If your plan does not include teams, a request that includes a non-empty `teamKeys` field returns an HTTP response code of 403 (Forbidden). Omit `teamKeys` to invite members without assigning them to a team. _No more than 50 members may be created per request._ A request may also fail because of conflicts with existing members. These conflicts are reported using the additional `code` and `invalid_emails` response fields with the following possible values for `code`: - **email_already_exists_in_account**: A member with this email address already exists in this account. - **email_taken_in_different_account**: A member with this email address exists in another account. - **duplicate_email**s: This request contains two or more members with the same email address. A request that fails for one of the above reasons returns an HTTP response code of 400 (Bad Request).

Get account member GET

Get a single account member by member ID. `me` is a reserved value for the `id` parameter that returns the caller's member information. ### Expanding the member response LaunchDarkly supports the following fields for expanding the "Get member" response. By default, these fields are **not** included in the response. To expand the response, append the `expand` query parameter and add a comma-separated list with any of the following fields: * `customRoles` includes details on each custom role assigned to the member, including the role key, name, and ID. * `roleAttributes` includes a list of the role attributes that you have assigned to the member. For example, `expand=customRoles,roleAttributes` includes both the `customRolesInfo` and `roleAttributes` fields in the response.