$client->members
Каждый метод этого пространства имён: его сигнатура, параметры, что он возвращает, и пример.
Методы
People who share the workspace, their role and the addresses they may use, and the invitations still waiting.
members->listmembers->listAllmembers->iteratemembers->getmembers->addmembers->updatemembers->removemembers->grantAddressmembers->revokeAddressmembers->grantDomainmembers->revokeDomainmembers->listInvitationsmembers->listAllInvitationsmembers->iterateInvitationsmembers->revokeInvitationmembers->resendInvitation
members->list
List everybody with access to the workspace
list(?int $limit = null, ?string $cursor = null, ?string $apiKey = null): PageReturns one page of the workspace's members, the owner first and the rest by email. members->listAll collects every page and members->iterate walks them lazily. Each row carries two axes that a client must not merge: role and permissions say what the person may do, and addresses and domains say what they may do it to, each with its own access. A whole domain reaches every address on it, including ones made later. A send needs both axes, so emails:send with nothing granted sends from nothing.
The one exception is addresses:all. When permissions holds it, the person reaches every address on every domain of the workspace, including ones added later, and sends as any of them when permissions also holds emails:send. addresses and domains still list only the grants made to them directly, which they may have kept from before or been given since, or none at all. Read reach from permissions first, and from those two lists only when it lacks addresses:all.
The list is a union of people with a membership row and people who only hold address or domain grants and no membership row. The second group comes back with implied true, $member['role']['id'] null and createdAt null, and their role is inferred from their grants: Member if any grant has access set to member, Viewer otherwise. Until someone calls members->update for them, widening their addresses silently widens what they may do.
The workspace owner is the FIRST row, marked with isOwner true, so an unshared workspace returns one member rather than an empty page. They hold every permission by definition, and members->add, members->update and members->remove refuse them with member_is_owner. Exclude isOwner when counting seats.
Параметры
limitintPage size, from 1 to 100. The server defaults to 25.
cursorstringThe
nextCursorof the previous page. Leave it out for the first page.apiKeystringOverrides the client's API key for this call only.
Возвращает
A Page of member arrays, with items, hasMore and nextCursor. Each item has userId, email, name, image, isOwner, role, implied, permissions, addresses, domains and createdAt.
Пример
$page = $client->members->list(); foreach ($page as $member) { $reach = in_array('addresses:all', $member['permissions'], true) ? 'every address' : implode(', ', array_column($member['addresses'], 'address')); echo $member['email'], ' (', $member['role']['name'], $member['isOwner'] ? ', owner' : '', '): ', $reach, PHP_EOL;}Примечания
Every other method here takes
userId, the account id, not the email address.accessset tovieweron an address blocks sending from it even when the role holdsemails:send, unless the role also holdsaddresses:all. Otherwise the two axes are ANDed, never added.The cursor is opaque and holds where the last row sat in this order, so a row deleted or edited between pages never breaks the walk: the next page starts at the first row that sorts after it. A cursor this list did not hand out is a 400
invalid_cursor.
Также доступно в
- API
GET /members- TypeScript
members.list()- Python
members.list()- Ruby
members.list- CLI
openemail members list
members->listAll
Collect every member into one array
listAll(?int $limit = null, ?string $cursor = null, ?string $apiKey = null): arrayWalks every page of members->list and returns all members in one array, the owner first and the rest by email. One request per page.
Параметры
limitintPage size for each request, from 1 to 100. The server defaults to 25.
cursorstringStarts the walk after this cursor instead of the first page.
apiKeystringOverrides the client's API key for every page of this walk.
Возвращает
A list of member arrays holding every member.
Пример
$members = $client->members->listAll(limit: 100); $seats = array_filter($members, static fn(array $member): bool => !$member['isOwner']);$implied = array_filter($members, static fn(array $member): bool => $member['implied']); echo count($seats), ' seats, ', count($implied), ' with a role nobody chose', PHP_EOL;Примечания
If any page fails, the exception is thrown and the members already fetched are discarded.
Также доступно в
- API
GET /members- TypeScript
members.listAll()- Python
members.list_all()- Ruby
members.list_all
members->iterate
Stream the members one at a time
iterate(?int $limit = null, ?string $cursor = null, ?string $apiKey = null): GeneratorReturns a Generator that yields members one at a time, the owner first and the rest by email, and requests the next page only once the current one is used up. Nothing is fetched until the loop starts, and breaking out of the foreach stops the requests.
Параметры
limitintPage size for each request, from 1 to 100. The server defaults to 25.
cursorstringStarts the walk after this cursor instead of the first page.
apiKeystringOverrides the client's API key for every page of this walk.
Возвращает
A Generator that yields one member array per step.
Пример
foreach ($client->members->iterate() as $member) { if ($member['implied']) { echo $member['email'], ' has grants but no role yet', PHP_EOL; }}Примечания
The generator is lazy, so an abandoned loop costs only the pages you consumed.
Также доступно в
- API
GET /members- TypeScript
members.iterate()- Python
members.iterate()- Ruby
members.iterate
members->get
Read one member by account id
get(string $userId, ?string $apiKey = null): arrayReturns a single member with their role, resolved permissions and address grants. The lookup runs over the same union as members->list, so a legacy grant holder with no membership row is found here too, with implied true.
The path takes the account id from members->list, not an email. An email can change on the account, and a stale one would point at the wrong person. The owner's account id returns the owner's row, with isOwner true, and an id that is not on the workspace answers 404.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array with userId, email, name, image, role (an array of id, name and builtin), isOwner, implied, the resolved permissions, addresses (each holding addressId, address and access), domains (each holding domainId, domain and access) and createdAt.
Пример
$member = $client->members->get('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E'); echo $member['email'], ' is ', $member['role']['name'], $member['implied'] ? ', inferred from grants' : '', PHP_EOL; foreach ($member['addresses'] as $grant) { echo ' ', $grant['address'], ' as ', $grant['access'], PHP_EOL;}Примечания
A missing member is 404
resource_not_found.For an implied member,
permissionsare the Member or Viewer template permissions, not a stored role thatroles->getcould read.
Также доступно в
- API
GET /members/{userId}- TypeScript
members.get()- Python
members.get()- Ruby
members.get- CLI
openemail members get
members->add
Invite somebody to the workspace with a role
add(array $body, ?string $apiKey = null): arraySends an invitation to join the workspace. Whether or not the address already has an OpenEmail account, the answer is an invitation rather than a member: nobody is put into a workspace without accepting, and this method is held to the same rule as the app.
The invitation carries the role, the addresses and the whole domains you name, and grants exactly those the moment it is accepted. Nothing is granted before that. Calling it again for the same address within ten minutes is refused with 409 invitation_too_soon. After that it refreshes the one outstanding invitation rather than sending a second.
Somebody already in the workspace is refused with 422 member_is_owner. Change what an existing member may do with members->update, members->grantAddress and members->revokeAddress, which only work on people already in.
Role and grants are separate axes. access applies to every id in addressIds and domainIds, and it never widens the role: 'access' => 'member' under a role without emails:send still cannot send. A role holding addresses:all reaches every address without any ids, and no key or access token can invite with one, because none of them holds that console-only permission.
Параметры
emailstringОбязательноWho to invite. Trimmed and lowercased. It does not need to have an account yet.
roleIdstringОбязательноRole id from
roles->list. The owner role is refused with 409role_immutable, and a role holding more than the key itself holds is refused with 403insufficient_authority. That covers every role with a console-only permission in it, such asaddresses:all.addressIdsstring[]Up to 64 address ids on this workspace the invitation carries, all at
access.domainIdsstring[]Up to 64 domain ids on this workspace the invitation carries, all at
access. A whole domain covers every address on it, including ones made later.accessstringmemberreads and sends as the granted addresses,vieweronly reads them. Defaults tomember.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the invitation, answered with a 202: the invitation id, what it carries, when it expires, and delivered, which is false when the email did not leave the mail server.
Пример
$invitation = $client->members->add([ 'email' => '[email protected]', 'roleId' => 'role_8b1f4c2e9a7d3b60e5f1a2c4', 'domainIds' => ['93542ff8-2baa-4f2f-841d-5ceaa074ab0d'], 'access' => 'member',]); echo 'Invitation ', $invitation['id'], ' expires ', $invitation['expiresAt'], PHP_EOL; if ($invitation['delivered'] === false) { echo 'The email did not go out: ', $invitation['deliveryError'], PHP_EOL;}Примечания
An unknown
roleIdis 404role_not_foundwithparamset toroleId. An address or domain id that is not on this workspace is 422member_not_foundwithparamset toaddressIdordomainId.The workspace owner, and anybody already in the workspace, is refused with 422
member_is_owner.deliveredfalse means the invitation exists but the email did not go out. It can be sent again from the app once the ten minute cooldown has passed.Not retried automatically. Re-posting the same body inside ten minutes is 409 rather than a duplicate.
Также доступно в
- API
POST /members- TypeScript
members.add()- Python
members.add()- Ruby
members.add- CLI
openemail members add
members->update
Change the role a member holds
update(string $userId, array $patch, ?string $apiKey = null): arrayMoves a member to a different role and changes nothing else, for somebody ALREADY in the workspace. Their address and domain grants are untouched, and grants cannot be patched here at all: members->grantAddress and members->revokeAddress change one grant at a time.
This is also how a legacy grant holder stops being implied. They have address or domain grants and no membership row, this writes one, and from then on implied is false and their permissions come from a role someone chose rather than from what their access implied.
Nobody joins through members->update. An account that is not in the workspace is 422 member_not_found: invite them with members->add and they are in once they accept. The owner role cannot be handed out, which is 409 role_immutable, and the workspace owner cannot be given a role, which is 422 member_is_owner.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.roleIdstringОбязательноId of the role to move them to.
apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the member with the new role and permissions, and implied set to false.
Пример
$member = $client->members->update('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E', ['roleId' => 'role_2c7e9a1f4b8d3e60c5a7f1b9']); echo $member['email'], ' is now ', $member['role']['name'], ' with ', count($member['permissions']), ' permissions', PHP_EOL;Примечания
The account has to be in the workspace already, by membership row or by a grant. Anybody else is 422
member_not_found. Usemembers->addto invite them.An unknown
roleIdis 404role_not_found, and a user id with no OpenEmail account behind it is 404user_not_found.A role holding more than the key itself holds is 403
insufficient_authority. No key or access token holds a console-only permission, so a role withaddresses:all, billing orworkspace:managein it is handed out only in the app. That includes the seeded Admin, which holds billing.Retried automatically on network failure, since it names the role it wants and a replay lands on the same row.
Также доступно в
- API
PATCH /members/{userId}- TypeScript
members.update()- Python
members.update()- Ruby
members.update- CLI
openemail members update
members->remove
Remove a member and every address and domain grant they hold
remove(string $userId, ?string $apiKey = null): arrayTakes somebody out of the workspace entirely: the membership row and every address and domain grant they hold on it. Removing only the row would drop them from the list while they kept reading the mail, so both go together.
It does not 404 for somebody who is not a member. The people this most needs to reach are legacy grant holders with no membership row, so there is no existence check, and addressesRevoked reports what actually happened: the address and domain grants it revoked, counted together. Zero is the honest answer for a no-op.
Their account, their sent mail and anything they wrote are untouched. Only their access to this workspace ends.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array with object set to member, the userId, deleted set to true and addressesRevoked.
Пример
$removed = $client->members->remove('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E'); echo 'Removed, ', $removed['addressesRevoked'], ' grants revoked', PHP_EOL;Примечания
Idempotent on the server, but the SDK does not retry it automatically, so repeat it yourself after a network failure.
The workspace owner is refused with 422
member_is_owner, because their access never came from a membership.
Также доступно в
- API
DELETE /members/{userId}- TypeScript
members.remove()- Python
members.remove()- Ruby
members.remove- CLI
openemail members remove
members->grantAddress
Grant a member one address or change their access to it
grantAddress(string $userId, array $body, ?string $apiKey = null): arrayGives one person one address on this workspace, or changes the access they already have to it. It is an upsert: there is one grant per person and address, so posting again with a different access turns a viewer into a member rather than adding a second grant.
This is the address axis and it cannot widen the role. 'access' => 'member' lets somebody send as the address only if their role also holds emails:send, and otherwise it lets them read.
Granting an address to an account with no membership row makes them appear in members->list as an implied member whose role is inferred from their grants, so call members->update as well if the role should be a decision. The whole member comes back, which lets a client redraw the row without another read.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.addressIdstringОбязательноId of an address on this workspace.
accessstringmemberreads and sends as the address,vieweronly reads it. Defaults tomember.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the member with the grant applied, including the full addresses list.
Пример
$member = $client->members->grantAddress('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E', [ 'addressId' => '4f0c1b6e-2d7a-4a9e-8c35-91b2e7d4f6a0', 'access' => 'viewer',]); foreach ($member['addresses'] as $grant) { echo $grant['address'], ' as ', $grant['access'], PHP_EOL;}Примечания
An address id that is not on this workspace is 422 with code
member_not_foundandparamset toaddressId.The workspace owner is refused with 422
member_is_owner, since they already reach every address. A user id with no OpenEmail account behind it is 404user_not_found.Gated on
members:writerather than on owning the address, so an admin who owns nothing can still manage grants.Retried automatically on network failure, since replaying the same grant lands on the same row.
Также доступно в
members->revokeAddress
Take one address back from a member
revokeAddress(string $userId, string $addressId, ?string $apiKey = null): arrayRemoves one address grant and leaves the person in the workspace with their role and their other addresses. This is the narrow revocation to use when somebody changes team.
An address id that is not on this workspace is refused with 422 member_not_found rather than ignored, so a typo cannot report a revocation that never happened. An address that is on the workspace but was never granted to this person is a silent no-op, and the member comes back unchanged.
The member is returned rather than a tombstone, because the useful answer is what they can still reach.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.addressIdstringОбязательноId of an address on this workspace.
apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the member with the remaining addresses.
Пример
$member = $client->members->revokeAddress('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E', '4f0c1b6e-2d7a-4a9e-8c35-91b2e7d4f6a0'); echo $member['email'], ' still reaches: ', implode(', ', array_column($member['addresses'], 'address')), PHP_EOL;Примечания
Revoking the last grant of an implied member removes them from the workspace entirely. The call still succeeds and returns the member as they stood, without that address.
Somebody who is not a member of this workspace is a 404.
Not retried automatically by the SDK.
Также доступно в
members->grantDomain
Grant a member a whole domain or change their access to it
grantDomain(string $userId, array $body, ?string $apiKey = null): arrayGives one person every address on one domain of this workspace, including addresses added after the grant, or changes the access they already have to it. It is an upsert: there is one grant per person and domain, so calling it again with a different access turns a viewer into a member rather than adding a second grant.
This is the address axis and it cannot widen the role. 'access' => 'member' lets somebody send from the domain only if their role also holds emails:send, and otherwise it lets them read.
The person has to be in the workspace already, so invite them with members->add first. The whole member comes back, with the grant in domains.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.domainIdstringОбязательноId of a domain on this workspace, as
domains->listreturns it.accessstringmemberreads and sends from the domain,vieweronly reads it. Defaults tomember.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the member with the grant applied, including the full domains list.
Пример
$member = $client->members->grantDomain('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E', [ 'domainId' => '7d2a9c41-5b3e-4f8a-9c06-1e2b3c4d5e6f', 'access' => 'member',]); foreach ($member['domains'] as $grant) { echo 'Every address on ', $grant['domain'], ' as ', $grant['access'], PHP_EOL;}Примечания
A domain id that is not on this workspace is 422 with code
member_not_foundandparamset todomainId. Somebody who is not in the workspace yet is refused the same way withparamset touserId.The workspace owner is refused with 422
member_is_owner, since they already reach every domain. A user id with no OpenEmail account behind it is 404user_not_found.A workspace whose plan has no team access is refused with 403
plan_required. A key or an access token limited to particular addresses or domains is refused with 422capability_unsupported, and an access token acting for a member can only give a domain that member reaches, or it is refused with 403insufficient_authority.An OAuth access token needs a verification code for this call, and is refused with 403
step_up_requireduntil the app has verified one in the last 60 minutes.isStepUpRequired()on the error says so. An API key is never asked for a code.Retried automatically on network failure, since replaying the same grant lands on the same row.
Также доступно в
members->revokeDomain
Take a whole domain back from a member
revokeDomain(string $userId, string $domainId, ?string $apiKey = null): arrayRemoves one domain grant and leaves the person in the workspace with their role and their other grants. Addresses on that domain that were granted to them one by one stay granted.
A domain id that is not on this workspace is refused with 422 member_not_found rather than ignored, so a typo cannot report a revocation that never happened. A domain that is on the workspace but was never granted to this person is a silent no-op, and the member comes back unchanged.
The member is returned rather than a tombstone, because the useful answer is what they can still reach.
Параметры
userIdstringОбязательноThe account id from
members->list, not the email address.domainIdstringОбязательноId of a domain on this workspace.
apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the member with the remaining domains.
Пример
use OpenEmail\Exception\ApiException; try { $member = $client->members->revokeDomain('q7Vd3kX9mT2pLw8RzN4bYc6HfJ1sGa5E', '7d2a9c41-5b3e-4f8a-9c06-1e2b3c4d5e6f'); echo $member['email'], ' keeps ', count($member['domains']), ' domains and ', count($member['addresses']), ' addresses', PHP_EOL;} catch (ApiException $error) { if (!$error->isStepUpRequired()) { throw $error; } echo 'Ask the person for a verification code first', PHP_EOL;}Примечания
Somebody who is not a member of this workspace is a 404.
A key or an access token limited to particular addresses or domains is refused with 422
capability_unsupported.An OAuth access token needs a verification code for this call, and is refused with 403
step_up_requireduntil the app has verified one in the last 60 minutes.isStepUpRequired()on the error says so. An API key is never asked for a code.Not retried automatically by the SDK.
Также доступно в
members->listInvitations
List the invitations nobody has accepted yet
listInvitations(?int $limit = null, ?string $cursor = null, ?string $apiKey = null): PageReturns one page of the invitations to this workspace that are still waiting, by email: the role and the addresses and whole domains each one grants once accepted, when it expires, and whether the last email reached them. members->listAllInvitations collects every page and members->iterateInvitations walks them lazily.
A waiting invitation grants nothing. It becomes access only at the moment somebody accepts it, which is why it is listed apart from members->list. An expired one stays on the list with expired true until it is sent again or withdrawn.
Параметры
limitintPage size, from 1 to 100. The server defaults to 25.
cursorstringThe
nextCursorof the previous page. Leave it out for the first page.apiKeystringOverrides the client's API key for this call only.
Возвращает
A Page of invitation arrays, with items, hasMore and nextCursor. Each item has id, email, role, addresses, domains, expiresAt, expired, lastSentAt, delivered, deliveryError and createdAt.
Пример
$page = $client->members->listInvitations(); foreach ($page as $invitation) { $state = $invitation['expired'] ? 'expired' : 'expires ' . $invitation['expiresAt']; echo $invitation['email'], ' as ', $invitation['role']['name'], ', ', $state, PHP_EOL;}Примечания
deliveredis null when no send outcome was recorded, false when the email did not leave the mail server, with the reason indeliveryError.A key limited to particular addresses or domains lists only the invitations that grant nothing outside them.
Также доступно в
members->listAllInvitations
Collect every waiting invitation into one array
listAllInvitations(?int $limit = null, ?string $cursor = null, ?string $apiKey = null): arrayWalks every page of members->listInvitations and returns every waiting invitation in one array, by email. One request per page, with the same filters on each.
Параметры
limitintPage size for each request, from 1 to 100. The server defaults to 25.
cursorstringStarts the walk after this cursor instead of the first page.
apiKeystringOverrides the client's API key for every page of this walk.
Возвращает
A list of invitation arrays holding every waiting invitation.
Пример
$invitations = $client->members->listAllInvitations(); $undelivered = array_filter($invitations, static fn(array $invitation): bool => $invitation['delivered'] === false); echo count($invitations), ' waiting, ', count($undelivered), ' never reached their inbox', PHP_EOL;Примечания
If any page fails, the exception is thrown and the rows already fetched are discarded.
Также доступно в
members->iterateInvitations
Stream the waiting invitations one at a time
iterateInvitations(?int $limit = null, ?string $cursor = null, ?string $apiKey = null): GeneratorReturns a Generator that yields one invitation at a time, by email, and requests the next page only once the current one is used up. Nothing is fetched until the loop starts, and breaking out of the foreach stops the requests.
Параметры
limitintPage size for each request, from 1 to 100. The server defaults to 25.
cursorstringStarts the walk after this cursor instead of the first page.
apiKeystringOverrides the client's API key for every page of this walk.
Возвращает
A Generator that yields one invitation array per step.
Пример
foreach ($client->members->iterateInvitations() as $invitation) { if ($invitation['expired']) { echo $invitation['email'], ' let the invitation run out', PHP_EOL; }}Примечания
The generator is lazy, so an abandoned loop costs only the pages you consumed.
Также доступно в
members->revokeInvitation
Withdraw an invitation
revokeInvitation(string $invitationId, ?string $apiKey = null): arrayWithdraws an invitation nobody has accepted. Its link stops working at once and nothing it would have granted is granted. It is Withdraw on the members screen. Inviting the same address later with members->add sends a new one.
Параметры
invitationIdstringОбязательноThe invitation id from
members->listInvitations.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array with object set to invitation, id, email and revoked set to true.
Пример
use OpenEmail\Exception\ConflictException; try { $revoked = $client->members->revokeInvitation('winv_6bb640f5b99e47deb758f1f5'); echo 'Withdrew the invitation to ', $revoked['email'], PHP_EOL;} catch (ConflictException) { echo 'Already accepted, so remove the member instead', PHP_EOL;}Примечания
An invitation that was accepted first answers 409
invitation_accepted: remove the member instead. One that is unknown or already withdrawn answers 404.A key limited to particular addresses or domains can withdraw only an invitation that grants nothing outside them.
Также доступно в
members->resendInvitation
Send an invitation again
resendInvitation(string $invitationId, ?string $apiKey = null): arraySends a waiting invitation again: a new link, fourteen more days, and the old link retired, so only the newest email works. It is Send again on the members screen, and it renews an expired invitation too.
Параметры
invitationIdstringОбязательноThe invitation id from
members->listInvitations.apiKeystringOverrides the client's API key for this call only.
Возвращает
An array for the invitation with the new expiresAt and lastSentAt, and delivered for this send.
Пример
foreach ($client->members->listAllInvitations() as $invitation) { if ($invitation['expired'] || $invitation['delivered'] === false) { $sent = $client->members->resendInvitation($invitation['id']); echo 'Sent again to ', $sent['email'], ', valid until ', $sent['expiresAt'], PHP_EOL; }}Примечания
The same address cannot be sent to twice within ten minutes: that is 409
invitation_too_soon. The daily limit on invitations is 409invitation_limit_reached.The invitation's role cannot hold more than the key does, the rule
members->addapplies too: a role with a permission the key or access token lacks, any console-only one such asaddresses:allincluded, is 403insufficient_authority. An access token acting for a member is also refused with it when the invitation carries addresses or domains that member does not reach.The SDK does not retry it, because each call sends an email.