← Platform API v1.32.0

POST /tenants/{tenantId}/iam/commands

manageIam · General

Requires users.manage in this tenant, checked again inside the write transaction.

Autenticación
SupabaseBearer · http bearer

Ejemplo

Los valores entre <> y {} son marcadores: sustitúyelos por los tuyos antes de ejecutarlo.

curl --request POST \
  --url 'https://api.marky.ec/v1/tenants/{tenantId}/iam/commands' \
  --header 'Authorization: Bearer <SupabaseBearer>' \
  --header 'Content-Type: application/json' \
  --data @body.json

Parámetros

Nombre En Tipo Descripción
tenantIdobligatorio path stringformato uuid Candidate UUIDv7, authorized against live membership
Idempotency-Key header stringformato uuidpatrón ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[47][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}$ UUIDv4/UUIDv7. Scoped by tenant, USER/API_CLIENT and operation. 24h TTL; changed fingerprint gives 409. Expired records are tombstones. Credential issuance cannot replay its secret.

Cuerpo (obligatorio)

application/json
Exactamente una de
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "create_role"
    • codeobligatorio
      stringpatrón ^[A-Za-z][A-Za-z0-9_.-]{0,63}$
    • nameobligatorio
      stringlongitud mín. 1longitud máx. 200
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "set_role_status"
    • roleIdobligatorio
      stringformato uuid
    • statusobligatorio
      uno de "ACTIVE", "DISABLED"
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "replace_role_permissions"
    • roleIdobligatorio
      stringformato uuid
    • permissionsobligatorio
      arrayelementos máx. 21sin repetidos
      Cada elemento
      stringuno de "catalog.read", "catalog.write", "inventory.read", "inventory.adjust", "inventory.transfer", "inventory.serials.read", "pricing.read", "pricing.write", "purchases.read", "purchases.create", "purchases.approve", "sales.read", "sales.create", "sales.cancel", "customers.read", "customers.write", "reports.cost.read", "reports.margin.read", "api.manage", "users.manage", "settings.manage"
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "create_membership"
    • userIdobligatorio
      stringformato uuid
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "set_membership_status"
    • membershipIdobligatorio
      stringformato uuid
    • statusobligatorio
      uno de "ACTIVE", "SUSPENDED"
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "assign_role"
    • membershipIdobligatorio
      stringformato uuid
    • roleIdobligatorio
      stringformato uuid
  • objectsin otras propiedades
    • kindobligatorio
      valor fijo "revoke_role"
    • membershipIdobligatorio
      stringformato uuid
    • roleIdobligatorio
      stringformato uuid

Respuestas

201 Success
  • X-Request-Idstringformato uuid Server-generated UUIDv7
  • X-RateLimit-Limitintegermín. 1 Effective requests per fixed minute window
  • X-RateLimit-Remainingintegermín. 0 Remaining capacity of the most restrictive dimension
  • X-RateLimit-Resetinteger Redis window reset, Unix seconds
  • Idempotency-Replayedvalor fijo "true" Present and true only when replaying a completed non-secret response.
application/json
objectsin otras propiedades
  • idobligatorio
    stringformato uuid
400 Invalid request
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

401 Missing or invalid access token
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

403 Identity, membership or permission denied
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

404 Unknown resource
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

409 Business conflict, fingerprint conflict, expired key or credential response already delivered.
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

413 Payload too large
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

429 Per-minute rate or monthly quota exceeded; authenticated API clients require PUBLIC_API entitlement.
  • Retry-Afterintegermín. 1 Seconds before retrying; quota reset is UTC next month.
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

500 Internal failure
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.

503 Auth/database/governance unavailable; no memory fallback for Redis.
application/problem+json
ProblemDetails
objectsin otras propiedades
  • typeobligatorio
    valor fijo "about:blank"
  • statusobligatorio
    integer
  • codeobligatorio
    string
  • titleobligatorio
    string
  • detailobligatorio
    string
  • requestIdobligatorio
    stringformato uuid
  • errors
    arrayelementos máx. 200

    Where each problem is, for the codes that can say it: a JSON pointer into the request or the record (`/items/0/devices/1/imei1`) and the reason. A line of a serialized article that is short of units also says how many it bills and how many are identified. Never a value typed by the user, and never an identifier of a unit.

    Cada elemento
    objectsin otras propiedades
    • pointerobligatorio
      string
    • codeobligatorio
      string
    • required
      integermín. 0máx. 1000

      For a line short of units (UNITS_DIFFER_FROM_QUANTITY, RECEIPT_REQUIRED, DELIVERY_REQUIRED): how many units the line bills.

    • identified
      integermín. 0máx. 1000

      For the same line: how many units are identified and linked to it. Given to every reader of the document; no IMEI or serial number is.