On this page

Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.

16 operations.

GET /api/security/roles

Get available roles

Operation ID: getAvailableRoles

Returns the list of available roles defined by the application. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Roles retrievedapplication/json: —
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

GET /api/security/users

List all users

Operation ID: findAllUsers

Retrieves all users. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Users retrievedapplication/json: TzUserListResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

POST /api/security/users

Create user

Operation ID: createUser

Creates a new user. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzUserCreateRequestDto

Responses

StatusDescriptionBody
200User createdapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

GET /api/security/users/id/{id}

Get user by ID

Operation ID: findByUserId

Retrieves a user by identifier. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1

Responses

StatusDescriptionBody
200User foundapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

GET /api/security/users/my

Get my user

Operation ID: findMyUser

Retrieves the authenticated user’s profile. Restricted to authenticated users.

Security: bearerAuth

Responses

StatusDescriptionBody
200User foundapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

PUT /api/security/users/my

Update my profile

Operation ID: updateMyUser

Updates the authenticated user’s profile. Restricted to authenticated users.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzUserUpdateRequestDto

Responses

StatusDescriptionBody
200Profile updatedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

PUT /api/security/users/password/my

Update my password

Operation ID: updateMyPassword

Updates the authenticated user’s password. Restricted to authenticated users.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontruestring

Responses

StatusDescriptionBody
200Password updatedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

PUT /api/security/users/password/{id}

Set user password

Operation ID: setUserPassword

Sets a user’s password directly. Requires ADMIN role. This is the way out on a deployment with no notification provider, where the reset link cannot be delivered.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestring—
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzSetPasswordRequestDto

Responses

StatusDescriptionBody
200Password setapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

DELETE /api/security/users/password/{id}

Reset user password

Operation ID: resetPassword

Resets password for a user. Requires ADMIN role. Answers 502 if the notification provider could not accept the message: the reset link exists only inside that message, so a failed delivery leaves nothing usable behind.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Password reset initiatedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502The notification provider did not accept the messageapplication/json: —

PUT /api/security/users/{id}

Update user

Operation ID: updateUser

Updates an existing user. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzUserUpdateRequestDto

Responses

StatusDescriptionBody
200User updatedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

DELETE /api/security/users/{id}

Delete user

Operation ID: deleteUser

Deletes a user. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200User deletedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

PUT /api/security/users/{id}/disable

Disable user

Operation ID: disableUser

Disables a user without replacing the rest of the aggregate. This is the reversible form of removing an account; DELETE is not reversible. Requires ADMIN.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200User disabledapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

PUT /api/security/users/{id}/enable

Enable user

Operation ID: enableUser

Enables a user without replacing the rest of the aggregate. Requires ADMIN.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200User enabledapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

POST /api/security/users/{id}/roles/{role}

Add role to user

Operation ID: addRole

Adds a role to a user. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
rolepathtruestringRole to add minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Role addedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

DELETE /api/security/users/{id}/roles/{role}

Remove role from user

Operation ID: removeRole

Removes a role from a user. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
rolepathtruestringRole to remove minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Role removedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value

PUT /api/security/users/{id}/unlock

Unlock user

Operation ID: unlockUser

Lifts a lockout and resets the failure counter without touching the password. Requires ADMIN.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringUser identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200User unlockedapplication/json: TzUserResponseDto
409Conflict/: map of any JSON value
502Bad Gateway/: map of any JSON value
Golden 3.0.0 · Published 2026-10-04