On this page
Users API
Generated Golden API operations for Users.
Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.
16 operations.
GET /api/security/roles
Get available roles
Operation ID: getAvailableRoles
Returns the list of available roles defined by the application. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Roles retrieved | application/json: — |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
GET /api/security/users
List all users
Operation ID: findAllUsers
Retrieves all users. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Users retrieved | application/json: TzUserListResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
POST /api/security/users
Create user
Operation ID: createUser
Creates a new user. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzUserCreateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | User created | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
GET /api/security/users/id/{id}
Get user by ID
Operation ID: findByUserId
Retrieves a user by identifier. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Responses
| Status | Description | Body |
|---|---|---|
200 | User found | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
GET /api/security/users/my
Get my user
Operation ID: findMyUser
Retrieves the authenticated user’s profile. Restricted to authenticated users.
Security: bearerAuth
Responses
| Status | Description | Body |
|---|---|---|
200 | User found | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
PUT /api/security/users/my
Update my profile
Operation ID: updateMyUser
Updates the authenticated user’s profile. Restricted to authenticated users.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzUserUpdateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Profile updated | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
PUT /api/security/users/password/my
Update my password
Operation ID: updateMyPassword
Updates the authenticated user’s password. Restricted to authenticated users.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | string |
Responses
| Status | Description | Body |
|---|---|---|
200 | Password updated | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
PUT /api/security/users/password/{id}
Set user password
Operation ID: setUserPassword
Sets a user’s password directly. Requires ADMIN role. This is the way out on a deployment with no notification provider, where the reset link cannot be delivered.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | — |
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzSetPasswordRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Password set | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
DELETE /api/security/users/password/{id}
Reset user password
Operation ID: resetPassword
Resets password for a user. Requires ADMIN role. Answers 502 if the notification provider could not accept the message: the reset link exists only inside that message, so a failed delivery leaves nothing usable behind.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Password reset initiated | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | The notification provider did not accept the message | application/json: — |
PUT /api/security/users/{id}
Update user
Operation ID: updateUser
Updates an existing user. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzUserUpdateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | User updated | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
DELETE /api/security/users/{id}
Delete user
Operation ID: deleteUser
Deletes a user. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | User deleted | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
PUT /api/security/users/{id}/disable
Disable user
Operation ID: disableUser
Disables a user without replacing the rest of the aggregate. This is the reversible form of removing an account; DELETE is not reversible. Requires ADMIN.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | User disabled | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
PUT /api/security/users/{id}/enable
Enable user
Operation ID: enableUser
Enables a user without replacing the rest of the aggregate. Requires ADMIN.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | User enabled | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
POST /api/security/users/{id}/roles/{role}
Add role to user
Operation ID: addRole
Adds a role to a user. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
role | path | true | string | Role to add minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Role added | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
DELETE /api/security/users/{id}/roles/{role}
Remove role from user
Operation ID: removeRole
Removes a role from a user. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
role | path | true | string | Role to remove minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Role removed | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |
PUT /api/security/users/{id}/unlock
Unlock user
Operation ID: unlockUser
Lifts a lockout and resets the failure counter without touching the password. Requires ADMIN.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | User identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | User unlocked | application/json: TzUserResponseDto |
409 | Conflict | /: map of any JSON value |
502 | Bad Gateway | /: map of any JSON value |