Organizations and users
Providers and clients use https://api.hashiro.ai/api/ with X-HASHIRO-TOKEN. Organization permissions do not grant access to arbitrary organizations.
Routes
| Method | Path | Operation |
|---|---|---|
| GET | /users/me | Read own user |
| PATCH | /users/me | Update own profile |
| PATCH | /users/me/appearance | Update theme and language |
| GET | /organizations/me | Read own organization |
| PATCH | /organizations/me | Update own organization |
| GET | /organizations/customers | List authorized organization relationships |
| GET | /organizations/:organizationId | Read an authorized organization |
| POST | /organizations/clients | Provider: provision a client and initial user |
| DELETE | /organizations/:organizationId | Provider: delete an unclaimed client it provisioned |
| POST | /organizations/me/deletion-request | Request own organization deletion |
| GET | /users/ | List own organization users |
| GET | /users/:organizationId | List permitted related organization users |
| PUT | /users/ | Create an authorized user |
| POST | /users/:organizationId/:userId | Update an authorized user |
| POST | /users/:organizationId/:userId/delete | Remove an authorized user |
| POST | /users/:organizationId/:userId/resend-invite | Resend a provisional client invitation |
| POST | /users/:organizationId/:userId/revoke-invite | Revoke a provisional invitation |
| POST | /users/:organizationId/:userId/reset-password | Reset a permitted provisional password |
| POST | /organizations/me/logo | Upload own logo |
| DELETE | /organizations/me/logo | Remove own logo |
| GET | /organizations/me/integrations/ | List configured integrations |
| POST | /organizations/me/integrations/ | Create an integration |
| GET | /organizations/me/integrations/:integrationId | Read an integration |
| PATCH | /organizations/me/integrations/:integrationId | Update an integration |
| DELETE | /organizations/me/integrations/:integrationId | Remove an integration |
| POST | /organizations/me/integrations/:integrationId/test | Test an integration |
Start with your identity
Read /users/me and /organizations/me to identify your user, organization, and available permissions. A client's management role applies to its own organization. A provider relationship permits only the operations specifically allowed for linked clients.
Provision a client
A provider with organization-create permission can send this body to POST /organizations/clients:
{
"name":"Example Client",
"shortname":"example-client",
"initial_user":{
"email":"[email protected]",
"firstname":"Example",
"lastname":"Manager",
"mode":"invite"
}
}Invite mode emails the initial user a password-setup link. The organization remains provisional until claimed. Providers can manage its invitation and delete it only while the provisional-state rules allow it. After claim, organization deletion uses the client's own deletion request and platform review.
Users
User creation and management require the relevant User permission and tenant access. Provider reset/revoke/resend operations are for eligible provisional client accounts; they do not grant ongoing control over a claimed client's credentials.
The regular organization management role is manager. Global administrator access is reserved for Hashiro platform staff and is not a client or provider role.
Integrations
Integration endpoints are own-organization operations and require the applicable management permissions and license. Credentials are write inputs; do not expect secret values in subsequent responses. Use the Jira guide for mapping and synchronization steps.