Skip to content
PacSpace
Talk to us

Team

Invite people to the workspace, set their roles, and remove them, from the dashboard routes.

Use these routes to manage who can sign in to your workspace. A workspace has up to 4 members, pending invitations included.

The roles, as the Dashboard API routes check them:

RoleWhat it can do
adminEverything a manager can, and manage the team and delete the account.
managerMake and change API keys and webhook endpoints, set the retention window and embed origins, activate an environment, and change the workspace kind before the first entry commits.
analystRead, and manage their own sign-in.

Base URL: https://app.pacspace.io

Protected routes need a dashboard session cookie (-b pacspace-dashboard-cookies.txt). A POST, PATCH, or DELETE made with the cookie also sends X-Pacspace-CSRF: 1 and Origin: https://app.pacspace.io; without them the answer is 403. Some refusals on these routes, such as a full team, come back with a 2xx status, success: false, and the reason in error, so read success as well as the status.

http
GET https://app.pacspace.io/dashboard/team/members

List members

bash
curl https://app.pacspace.io/dashboard/team/members \
  -b pacspace-dashboard-cookies.txt

Answers each active member's id, name, email, role, isVerified, and createdAt, oldest first.

List pending invitations (admin)

bash
curl https://app.pacspace.io/dashboard/team/invitations \
  -b pacspace-dashboard-cookies.txt

Answers each pending invitation's id, email, role, status, expiresAt, createdAt, and the inviter's name. An invitation lasts 48 hours.

Invite a member (admin)

A lab's evaluation lead invites someone from the safety team to read the evaluation records:

bash
curl -X POST https://app.pacspace.io/dashboard/team/invite \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "safety-reviewer@lab.example",
    "role": "analyst"
  }'

role is admin, manager, or analyst. The answer carries the invitation's id, email, role, and expiresAt, with "Invitation sent successfully", and the invitation goes out by email. An invitation is refused when the team is full, when the person is already a member, or when an invitation to that email is still pending.

Check an invitation (public)

The invitation email links to a dashboard page that carries the token. The page sends it here before it shows the form.

bash
curl -X POST https://app.pacspace.io/dashboard/team/validate-invite \
  -H "Content-Type: application/json" \
  -d '{ "token": "INVITE_TOKEN" }'

Answers the invitation's email, role, and organizationName, or success: false with why the invitation no longer works.

Accept an invitation (public)

Creates the account, joins the workspace, and signs the new member in.

bash
curl -X POST https://app.pacspace.io/dashboard/team/accept-invite \
  -c pacspace-dashboard-cookies.txt \
  -H "Content-Type: application/json" \
  -d '{
    "token": "INVITE_TOKEN",
    "name": "Sam Rivera",
    "password": "Battery-Staple-17"
  }'

name is up to 100 characters. The password is 8 to 32 characters with at least one uppercase letter, one lowercase letter, one number, and one special character, and no spaces. The email is the one the invitation was sent to, and it counts as verified.

Change a member's role (admin)

bash
curl -X PATCH https://app.pacspace.io/dashboard/team/members/cmw3h8d2q0002s601k8r1t5vj/role \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io" \
  -H "Content-Type: application/json" \
  -d '{ "role": "manager" }'

role is admin, manager, or analyst. The answer carries id and role, with "Role updated successfully". You cannot change your own role.

Remove a member (admin)

bash
curl -X DELETE https://app.pacspace.io/dashboard/team/members/cmw3h8d2q0002s601k8r1t5vj \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io"

Answers "Team member removed". You cannot remove yourself.

Revoke an invitation (admin)

bash
curl -X DELETE https://app.pacspace.io/dashboard/team/invitations/cmw4p3r8b0004s601q6w2y9hn \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io"

Answers "Invitation revoked". Only a pending invitation can be revoked.

Routes

EndpointMethodAuthRole
/dashboard/team/membersGETSession cookieAny member
/dashboard/team/invitationsGETSession cookieAdmin
/dashboard/team/invitePOSTSession cookieAdmin
/dashboard/team/validate-invitePOSTPublic, with a token
/dashboard/team/accept-invitePOSTPublic, with a token
/dashboard/team/members/:id/rolePATCHSession cookieAdmin
/dashboard/team/members/:idDELETESession cookieAdmin
/dashboard/team/invitations/:idDELETESession cookieAdmin