Grant and revoke a domain
A whole domain at once: every address on it, including ones added later.
Runs any of 2 calls on your workspace.
POST /members/{userId}/domains
A whole domain at once: every address on it, including ones added later.
Grant a domain
Needs members:write. POST /members/{userId}/domains with { domainId, access }; access defaults to member. Returns the whole member as they now stand, with the grant in domains.
curl -X POST "$OE/members/nQ8vBz1aRd4tYwKx7fQ2mN8vBz1aRd4t/domains" -H "$AUTH" \ -H "Content-Type: application/json" \ -d '{ "domainId": "7d2a9c41-5b3e-4f8a-9c06-1e2b3c4d5e6f", "access": "viewer" }'{ "object": "member", "userId": "nQ8vBz1aRd4tYwKx7fQ2mN8vBz1aRd4t", "email": "[email protected]", "role": { "id": "role_2b81de079c1f0a4b7e05d386", "name": "Support", "builtin": null }, "addresses": [], "domains": [ { "domainId": "7d2a9c41-5b3e-4f8a-9c06-1e2b3c4d5e6f", "domain": "acme.com", "access": "viewer" } ] }An upsert, like an address grant: posting again with a different access changes the grant rather than adding a second one.
A domain grant reaches every address on the domain, including addresses added after it, so it is the grant for somebody who looks after a whole domain. Addresses granted one by one stay as they are beside it.
The person has to be in the workspace already, so invite them with POST /members first. The owner is refused with member_is_owner, because they reach every domain, and a workspace whose plan has no team access is refused with 403 plan_required.
A key or an app limited to particular addresses or domains is refused with 422 capability_unsupported, and an app acting for a member can only give a domain that member reaches.
An OAuth access token needs a verification code for this call. Until the app has verified one in the last 60 minutes, the call answers 403 step_up_required and changes nothing. An API key is never asked. The Authentication page shows how to ask for a code and verify it.
Revoke a domain
Needs members:write. DELETE /members/{userId}/domains/{domainId}. Returns the member, minus that domain.
curl -X DELETE \ "$OE/members/nQ8vBz1aRd4tYwKx7fQ2mN8vBz1aRd4t/domains/7d2a9c41-5b3e-4f8a-9c06-1e2b3c4d5e6f" \ -H "$AUTH"{ "object": "member", "userId": "nQ8vBz1aRd4tYwKx7fQ2mN8vBz1aRd4t", "email": "[email protected]", "role": { "id": "role_2b81de079c1f0a4b7e05d386", "name": "Support", "builtin": null }, "addresses": [], "domains": [] }Addresses on the domain that were granted one by one stay granted, and the person keeps their role.
A domain that is not on this workspace is refused with 422 member_not_found rather than quietly ignored.
An OAuth access token needs a verification code for this call. Until the app has verified one in the last 60 minutes, the call answers 403 step_up_required and changes nothing. An API key is never asked. The Authentication page shows how to ask for a code and verify it.