LaserData Cloud
API Reference

Members & Roles

Read members, manage invitations, and assign roles with scoped permissions

API Variables
ld-api-key
{tenant_id}

Set variables to auto-fill all examples and run requests in-browser.

Members are users who can access a tenant. Roles define their permissions. Send these requests to https://api.laserdata.cloud.

Listing members requires member:read. Invitations and removal require member:manage. Reading roles requires role:read, and creating or deleting them requires role:manage.

Members

List Members

GET
/tenants/{tenant_id}/members

List all members of a tenant with their assigned roles.

bash
curl "https://api.laserdata.cloud/tenants/{tenant_id}/members?page=1&results=10" \
-H "ld-api-key: YOUR_API_KEY"
{
  "items": [
    {
      "id": 1,
      "email": "alice@example.com",
      "name": "Alice",
      "active": true,
      "roles": ["developer"],
      "created_at": "2025-01-15T10:00:00Z"
    }
  ],
  "page": 1,
  "total_results": 1,
  "total_pages": 1
}

Update Member Role

PUT
/tenants/{tenant_id}/members/{member_id}

Change the role assigned to a tenant member.

bash
curl -X PUT https://api.laserdata.cloud/tenants/{tenant_id}/members/{member_id} \
-H "ld-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "active": true,
  "roles": [123, 456]
}'

Remove Member

DELETE
/tenants/{tenant_id}/members/{member_id}

Remove a member from the tenant. Their API keys are not automatically revoked.

bash
curl -X DELETE https://api.laserdata.cloud/tenants/{tenant_id}/members/{member_id} \
-H "ld-api-key: YOUR_API_KEY"

Invitations

Invite a Member

POST
/tenants/{tenant_id}/invitations

Send an invitation email to a new member with a specified role.

bash
curl -X POST https://api.laserdata.cloud/tenants/{tenant_id}/invitations \
-H "ld-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "email": "bob@example.com",
  "roles": [100]
}'

The tenant configuration determines these domain-restriction errors:

Status / CodeCause
400 invitee_domain_lockedThe invitee's email domain belongs to another tenant that has set block_external_invitations: true.
400 invitee_domain_not_allowedThis tenant has enforce_domain_only_invitations: true and the invitee's email domain is outside the tenant's claimed email_domain (and any division subdomains).

List Invitations

GET
/tenants/{tenant_id}/invitations

List all pending invitations.

bash
curl "https://api.laserdata.cloud/tenants/{tenant_id}/invitations?page=1&results=10" \
-H "ld-api-key: YOUR_API_KEY"

Cancel Invitation

DELETE
/tenants/{tenant_id}/invitations/{invitation_id}

Cancel a pending invitation before it is accepted.

bash
curl -X DELETE https://api.laserdata.cloud/tenants/{tenant_id}/invitations/{invitation_id} \
-H "ld-api-key: YOUR_API_KEY"

Roles

List Roles

GET
/tenants/{tenant_id}/roles

List all roles defined in the tenant, including built-in and custom roles.

bash
curl "https://api.laserdata.cloud/tenants/{tenant_id}/roles?page=1&results=10" \
-H "ld-api-key: YOUR_API_KEY"
{
  "items": [
    {
      "id": 1,
      "name": "admin",
      "kind": "system"
    },
    {
      "id": 2,
      "name": "developer",
      "kind": "custom"
    }
  ],
  "page": 1,
  "total_results": 2,
  "total_pages": 1
}

Role kind identifies how the role was created:

  • system identifies admin, developer, viewer, or billing. These four built-in roles cannot be deleted. Tenant ownership is stored separately.
  • custom identifies a role created through the API or Console.
  • api_key identifies a dedicated role created from inline key permissions instead of an existing role_id.

Get Role

GET
/tenants/{tenant_id}/roles/{role_id}

Get a role by ID.

bash
curl https://api.laserdata.cloud/tenants/{tenant_id}/roles/{role_id} \
-H "ld-api-key: YOUR_API_KEY"

List Role Members

GET
/tenants/{tenant_id}/roles/{role_id}/members

List all members assigned to a role.

bash
curl "https://api.laserdata.cloud/tenants/{tenant_id}/roles/{role_id}/members?page=1&results=10" \
-H "ld-api-key: YOUR_API_KEY"

Create Role

POST
/tenants/{tenant_id}/roles

Create a custom role with tenant, division, and environment permission scopes.

bash
curl -X POST https://api.laserdata.cloud/tenants/{tenant_id}/roles \
-H "ld-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "name": "developer",
  "permissions": {
    "tenant": ["info:read", "member:read", "division:read"],
    "division": ["environment:read", "environment:manage"],
    "environment": ["deployment:read"],
    "divisions": {
      "1": {
        "permissions": ["environment:read"],
        "environment": ["deployment:read", "deployment:manage"],
        "environments": {
          "2": ["deployment:read", "deployment:manage", "deployment:telemetry:read"]
        }
      }
    }
  }
}'
FieldRequiredDescription
nameYesUnique role name within the tenant
permissions.tenantNoTenant-level permission strings (e.g. info:read, member:manage)
permissions.divisionNoDefault division permissions applied to all divisions
permissions.environmentNoDefault environment permissions applied to every environment in every division. The blanket "all environments" knob: spares you per-division overrides for read-only or developer-style roles
permissions.divisionsNoPer-division overrides keyed by division ID. Each entry takes its own permissions, environment (default for that division's environments), and environments map (per-environment overrides)

Environment permissions use the most specific grant: the environment override, division environment default, then global permissions.environment. Without a matching grant, access is denied. Division permissions use per-division permissions, then global permissions.division, then none.

Assign Role to Members

PUT
/tenants/{tenant_id}/roles/{role_id}/members/assign

Assign one or more members to a role.

bash
curl -X PUT https://api.laserdata.cloud/tenants/{tenant_id}/roles/{role_id}/members/assign \
-H "ld-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "members": [1, 2, 3]
}'

Revoke Role from Members

PUT
/tenants/{tenant_id}/roles/{role_id}/members/revoke

Remove one or more members from a role.

bash
curl -X PUT https://api.laserdata.cloud/tenants/{tenant_id}/roles/{role_id}/members/revoke \
-H "ld-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "members": [2]
}'

Delete Role

DELETE
/tenants/{tenant_id}/roles/{role_id}

Delete a custom role. Built-in roles cannot be deleted. Members assigned to this role will need a new role assigned.

bash
curl -X DELETE https://api.laserdata.cloud/tenants/{tenant_id}/roles/{role_id} \
-H "ld-api-key: YOUR_API_KEY"

On this page