0.x — pre-release, no compatibility promise yet.What this means
Access review: every member, their MFA, last sign-in, projects and tokens (owner / admin; JSON or CSV)
Who can reach this organization, and with which tokens. Owner / admin. Accept: text/csv for a spreadsheet.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”Header Parameters
Section titled “Header Parameters”An ETag you hold; unchanged → 304 with no body.
Responses
Section titled “ Responses ”Successful Response
Returned by organizations.access_review.
object
The org’s two-step sign-in policy: off, admins or all
Part of AccessReview.
object
user or service_account
Tokens that authenticate right now
Part of ReviewMember.
object
enrolled, not_enrolled, unknown (the auth service could not say) or n/a (a service account)
The organization’s two-step sign-in policy covers this member’s role
Active tokens whose principal is no longer an active member
Part of AccessReview.
object
Part of AccessReview.
object
Active members, people and service accounts
People the policy requires MFA of who have not set it up (or are unknown)
Data rows of the CSV form (one per member and token)
Part of AccessReview.
object
People the auth service could not be asked about; their mfa is unknown
Example
{ "org_id": "string", "generated_at": "string", "mfa_policy": "off", "members": [ { "user_id": "string", "username": "string", "email": "string", "kind": "string", "role": "string", "designation": "string", "last_active_at": "string", "tokens": [ { "token_id": "string", "name": "string", "token_prefix": "string", "kind": "string", "grant_type": "string", "scopes": [ "string" ], "project_ids": [ "string" ], "expires_at": "string", "last_used_at": "string" } ], "mfa": "unknown", "mfa_required": false, "last_sign_in_at": "string", "projects": [ { "project_id": "string", "name": "string", "role": "string" } ] } ], "unattached_tokens": [ { "token_id": "string", "name": "string", "token_prefix": "string", "kind": "string", "grant_type": "string", "scopes": [ "string" ], "project_ids": [ "string" ], "expires_at": "string", "last_used_at": "string", "principal_user_id": "string" } ], "summary": { "members": 0, "people": 0, "service_accounts": 0, "owners_admins": 0, "guests": 0, "active_tokens": 0, "unattached_tokens": 0, "mfa_enrolled": 0, "mfa_not_enrolled": 0, "mfa_unknown": 0, "mfa_required_missing": 0, "csv_rows": 0 }, "meta": { "auth_error": 0 }}Example
user_id,username,email,kind,role,designation,last_active_at,token_id,token_name,token_prefix,token_kind,grant_type,scopes,project_ids,expires_at,last_used_at,mfa,mfa_required,last_sign_in_at,projectsNot Modified - If-None-Match matched the current ETag (no body)
Bad request - a query parameter outside what the operation accepts (invalid-parameter)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Bad request", "status": 400, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Missing or invalid bearer token
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Missing or invalid bearer token", "status": 401, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Authenticated, but not allowed
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Authenticated, but not allowed", "status": 403, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Not found
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Not found", "status": 404, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Conflict (a duplicate, or an Idempotency-Key still in flight)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Conflict (a duplicate, or an `Idempotency-Key` still in flight)", "status": 409, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}If-Match does not match the current ETag
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "`If-Match` does not match the current `ETag`", "status": 412, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}The body or query did not validate (validation), or an Idempotency-Key was reused
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "The body or query did not validate (`validation`), or an `Idempotency-Key` was reused", "status": 422, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}An access token, or a signed-in user, or an address over its limit (rate-limit; see Retry-After)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "An access token, or a signed-in user, or an address over its limit (`rate-limit`; see `Retry-After`)", "status": 429, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}Unexpected server error - quote request_id
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Unexpected server error", "status": 500, "detail": "…", "instance": "/v1/…", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"}