Skip to content

Organizations and users ​

Providers and clients use https://api.hashiro.ai/api/ with X-HASHIRO-TOKEN. Organization permissions do not grant access to arbitrary organizations.

Routes ​

MethodPathOperation
GET/users/meRead own user
PATCH/users/meUpdate own profile
PATCH/users/me/appearanceUpdate theme and language
GET/organizations/meRead own organization
PATCH/organizations/meUpdate own organization
GET/organizations/customersList authorized organization relationships
GET/organizations/:organizationIdRead an authorized organization
POST/organizations/clientsProvider: provision a client and initial user
DELETE/organizations/:organizationIdProvider: delete an unclaimed client it provisioned
POST/organizations/me/deletion-requestRequest own organization deletion
GET/users/List own organization users
GET/users/:organizationIdList permitted related organization users
PUT/users/Create an authorized user
POST/users/:organizationId/:userIdUpdate an authorized user
POST/users/:organizationId/:userId/deleteRemove an authorized user
POST/users/:organizationId/:userId/resend-inviteResend a provisional client invitation
POST/users/:organizationId/:userId/revoke-inviteRevoke a provisional invitation
POST/users/:organizationId/:userId/reset-passwordReset a permitted provisional password
POST/organizations/me/logoUpload own logo
DELETE/organizations/me/logoRemove own logo
GET/organizations/me/integrations/List configured integrations
POST/organizations/me/integrations/Create an integration
GET/organizations/me/integrations/:integrationIdRead an integration
PATCH/organizations/me/integrations/:integrationIdUpdate an integration
DELETE/organizations/me/integrations/:integrationIdRemove an integration
POST/organizations/me/integrations/:integrationId/testTest an integration

Start with your identity ​

Read /users/me and /organizations/me to identify your user, organization, and available permissions. A client's management role applies to its own organization. A provider relationship permits only the operations specifically allowed for linked clients.

Provision a client ​

A provider with organization-create permission can send this body to POST /organizations/clients:

json
{
  "name":"Example Client",
  "shortname":"example-client",
  "initial_user":{
    "email":"[email protected]",
    "firstname":"Example",
    "lastname":"Manager",
    "mode":"invite"
  }
}

Invite mode emails the initial user a password-setup link. The organization remains provisional until claimed. Providers can manage its invitation and delete it only while the provisional-state rules allow it. After claim, organization deletion uses the client's own deletion request and platform review.

Users ​

User creation and management require the relevant User permission and tenant access. Provider reset/revoke/resend operations are for eligible provisional client accounts; they do not grant ongoing control over a claimed client's credentials.

The regular organization management role is manager. Global administrator access is reserved for Hashiro platform staff and is not a client or provider role.

Integrations ​

Integration endpoints are own-organization operations and require the applicable management permissions and license. Credentials are write inputs; do not expect secret values in subsequent responses. Use the Jira guide for mapping and synchronization steps.

Hashiro. Continuous Threat Exposure Management.