Users
Users are owned by the Organization service and are reached directly under /api/v1, not under a module prefix.
Base path: https://api.rabbitqa.com/api/v1/users
The signed-in user
curl https://api.rabbitqa.com/api/v1/users/me \
-H "Authorization: Bearer $TOKEN"
| Method | Path | Purpose |
|---|---|---|
GET | /users/me | The signed-in account |
GET | /users/me/permissions | Permission keys held by the signed-in user |
GET /api/v1/permissions/me returns the same permission set and is equivalent.
Use it to decide what to show in a client rather than assuming a role implies a capability — permissions are granted per role and can be customized.
Listing and lookup
| Method | Path | Purpose |
|---|---|---|
GET | /users | List users in the company |
GET | /users/filter-options | Values available to filter the list on |
GET | /users/{id} | Retrieve one user |
GET | /users/email | Look up by email address |
POST | /users/{username}/available | Check whether a username is free |
GET | /users/validate | Validate the current session |
Inviting and creating
curl -X POST https://api.rabbitqa.com/api/v1/users/invite \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{ "email": "[email protected]", "roleIds": [4] }'
| Method | Path | Purpose |
|---|---|---|
POST | /users/invite | Invite a user by email |
PUT | /users/activate | Activate an invited account |
POST | /users/activate | Activate an invited account |
An invited user is created in a passive state and becomes active once the invitation is accepted.
Both endpoints accept application/json, and multipart/form-data when a profile image is included.
Updating a user
| Method | Path | Purpose |
|---|---|---|
PUT | /users/{id} | Update a user |
PUT | /users/{id}/profile | Update profile fields |
PUT | /users/{id}/roles | Replace the user's roles |
PUT | /users/{id}/status | Activate or deactivate |
PATCH | /users/{id}/admin | Grant or revoke administrator |
PUT | /users/{id}/companies | Change company membership |
DELETE | /users/{id} | Delete a user |
Passwords
| Method | Path | Purpose |
|---|---|---|
PUT | /users/password | Change your own password |
PUT | /users/{id}/password | Change another user's password |
Password reset for a signed-out user goes through POST /api/v1/auth/forgot-password and POST /api/v1/auth/reset-password. See Authentication.
Profile image
| Method | Path | Purpose |
|---|---|---|
GET | /users/{id}/image | Retrieve the profile image |
DELETE | /users/{id}/image | Remove the profile image |
Sign-in history
| Method | Path | Purpose |
|---|---|---|
GET | /users/user-login-logs/{user-id} | Sign-in log for one user |
Roles and groups
- Roles:
GET|POST /api/v1/roles,GET|PUT|DELETE /api/v1/roles/{id},GET /api/v1/roles/{id}/users - Teams:
GET|POST /api/v1/teams,POST|DELETE /api/v1/teams/{id}/members/{userId} - User groups inside test management:
/tmt/company/api/v1/userGroups
Workspace-level role assignment is done through the workspace endpoints — see Workspaces.