Group
A Group of Users, a subject in an entity's Permissions. Groups and their membership are managed in the identity provider, and like Users are not scoped to an Organization; a Group is provisioned when a User in it logs in. Bot Users are the exception: they are added to a Group through the API.
Operations
| Method | Endpoint | Description |
|---|---|---|
GET |
/group |
List Groups |
GET |
/group/{group_id} |
Get Group |
POST |
/group/{group_id}/user/{user_id} |
Add a bot User to a Group |
DELETE |
/group/{group_id}/user/{user_id} |
Remove a bot User from a Group |
List Groups
GET /group
List Groups
Operation ID: ListGroups
Parameters
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
where |
string | The specified string is an expression for the purpose of filtering the list of Groups returned. The expression syntax was inspired by SQL. It supports conjunctions using AND of relational expressions of the form attribute operator attribute_or_literal. The attribute names are case-sensitive and PascalCase, as in the JSON encoding. Strings support the following operators: <, >, <=, >=, =, !=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*, IN, NOT IN. String pattern operators: LIKE and ~~ for pattern matching with % and _ wildcards, ILIKE for case-insensitive pattern matching, NOT LIKE and !~~ for negated pattern matching. String regex operators: ~ for regex matching, ~* for case-insensitive regex, !~ and !~* for regex not matching (case-sensitive and insensitive). Integers support the following operators: <, >, <=, >=, =, !=, IN, NOT IN. UUIDs and boolean attributes support equality and inequality only. UUID and time literals must be quoted as string literals. String literals are quoted with single quotes, such as 'string'. Time literals use the same form as when serialized as JSON, such as: CreatedAt > '2025-02-18T23:16:34'. Integer and boolean literals are also supported for attributes of those types. Arrays support the ? operator to to match any element of the array, as in FromLinkID ? '7c61626f-ddbe-41af-93f6-b69f4ab6d308'. Arrays can perform LEN() to check for length, as in LEN(FromLinkID) > 0. An attribute naming a list of other entities can be filtered on their attributes with a * segment, as in FromLink.*.Slug = 'upgrade-app', which holds when any element satisfies it. Without the * such a reference is an error, since it names no single value to compare. Map support the dot notation to specify a particular map key, as in Labels.tier = 'Backend'. Maps support IS NULL and IS NOT NULL with dot notation to check for key absence or presence, as in Labels.tier IS NULL (key doesn't exist) or Labels.tier IS NOT NULL (key exists). Comparison results can be tested with IS TRUE, IS FALSE, IS NOT TRUE, and IS NOT FALSE. These are useful for nullable columns: MergeSourceID = '<uuid>' IS NOT FALSE matches rows where MergeSourceID equals the value OR is NULL. The IN and NOT IN operators accept a comma-separated list of values in parentheses, such as Slug IN ('slugone', 'slugtwo') or Labels.environment IN ('prod', 'staging'). Conjunctions are supported using the AND operator. An example conjunction is: CreatedAt >= '2025-01-07' AND Slug = 'test' AND Labels.mykey = 'myvalue'. Supported attributes for filtering on Group: CreatedAt, DisplayName, ExternalID, GroupID, Slug, UpdatedAt. The whole string must be query-encoded. |
|
filter |
string | UUID of a Filter entity to apply to the Group list. The Filter must be in the same Organization as the user credentials. The Filter's From field must match the entity type being filtered (Group). For Space-resident entities, if the Filter has a FromSpaceID, it must match the operation's SpaceID. The Filter's Where clause will be combined with any explicit 'where' parameter using AND logic. If both 'filter' and 'where' parameters are specified, they are combined with AND logic. | |
contains |
string | Free text search that approximately matches the specified string against string fields and map keys/values. The search is case-insensitive and uses pattern matching to find entities containing the text. Searchable string fields include attributes like Slug, DisplayName, and string-typed custom fields. For map fields (like Labels and Annotations), the search matches both map keys and values. The search uses OR logic across all searchable fields, so matching any field will return the entity. If both 'where' and 'contains' parameters are specified, they are combined with AND logic. Searchable fields for Group include string and map-type attributes from the queryable attributes list. The whole string must be query-encoded. | |
select |
string | Select clause for specifying which fields to include in the response for Group. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, GroupID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded. | |
include_hidden |
string | Hidden Group entities, those with a HiddenReason, are left out of the results, or of what a bulk operation acts on, unless this names their HiddenReason. It is a comma-separated list of HiddenReasons, or * for all of them. A where clause naming the entities, by their Slug or ID with = or IN, or naming HiddenReason at all, also returns hidden entities it selects. ConfigHub/YAML Units, which hold the configuration of entities, are hidden with the HiddenReason BackingUnit. |
|
limit |
integer | Maximum number of Group entities to return. If not specified, all matching entities are returned. Values greater than 1000 are rejected with 400. When there may be more entities, the response has a ConfigHub-Continue header to pass as the continue parameter of the next request. | |
order_by |
string | Comma-separated list of fields to sort Group results by, each in the form 'ASC|DESC:FieldName' or just 'FieldName'. Field names are case-sensitive and PascalCase, as in the JSON encoding. Sort direction defaults to ASC when the 'DIRECTION:' prefix is omitted. Supported attributes for ordering Group: CreatedAt, DisplayName, ExternalID, GroupID, Slug, UpdatedAt. Example: 'DESC:CreatedAt' or 'DisplayName,DESC:CreatedAt'. Results are ordered by the Group's ID after the fields named, and by the ID alone if none are. The whole string must be query-encoded. | |
continue |
string | The token from the ConfigHub-Continue header of the previous page, to return the Group entities after it. The request's other parameters, except limit, must be the same as those of the request that returned the token. Keep reading until a response has no such header: a page can hold fewer entities than the limit, or none, and still be followed by more. |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | OK | application/json |
Array of ExtendedGroup |
| 400 | Group request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | Group not found. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing Group. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Get Group
GET /group/{group_id}
Get Group
Operation ID: GetGroup
Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
group_id |
string | ✓ | Unique identifier for a group_id |
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
select |
string | Select clause for specifying which fields to include in the response for Group. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, GroupID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded. |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | Group with additional related entities expanded based on the request's include parameter. | application/json |
ExtendedGroup |
| 400 | Group request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | Group not found. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing Group. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Add a bot User to a Group
POST /group/{group_id}/user/{user_id}
Add the bot User of a BridgeWorker in the caller's Organization to the Group. Other Users' Group memberships are managed in the identity provider. An organization admin or manager may. So may a member of the Group who has Manage permission on the bot User's BridgeWorker. Adding a bot that is already a member does nothing. Returns the bot User with its GroupIDs.
Operation ID: AddGroupBotUser
Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
group_id |
string | ✓ | Unique identifier for a group_id |
user_id |
string | ✓ | Unique identifier for a user_id |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | a User in Confighub. | application/json |
User |
| 400 | Group request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | Group not found. | application/json |
StandardErrorResponse |
| 409 | Group data conflict. Data has changed since last read. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing Group. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Remove a bot User from a Group
DELETE /group/{group_id}/user/{user_id}
Remove the bot User of a BridgeWorker in the caller's Organization from the Group. An organization admin or manager may. So may a member of the Group who has Manage permission on the bot User's BridgeWorker. Removing a bot that is not a member does nothing. Returns the bot User with its GroupIDs.
Operation ID: RemoveGroupBotUser
Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
group_id |
string | ✓ | Unique identifier for a group_id |
user_id |
string | ✓ | Unique identifier for a user_id |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | a User in Confighub. | application/json |
User |
| 400 | Group request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | Group not found. | application/json |
StandardErrorResponse |
| 409 | Group is still in use: it has DeleteGates, or other entities still reference it. Or data has changed since last read. | application/json |
StandardErrorResponse |
| 422 | Group could not be deleted. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing Group. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Schemas
ExtendedGroup
Group with additional related entities expanded based on the request's include parameter.
Properties
| Property | Type | Required | Description |
|---|---|---|---|
Error |
ResponseError |
||
Group |
Group |
StandardErrorResponse
Error response details.
Properties
| Property | Type | Required | Description |
|---|---|---|---|
Code |
string | HTTP status code of the response. | |
Message |
string | Message returned with the response. |
User
a User in Confighub.
Properties
| Property | Type | Required | Description |
|---|---|---|---|
CreatedAt |
string (date-time) | The timestamp when the entity was created in "2023-01-01T12:00:00Z" format. | |
DisplayName |
string | Friendly name for the entity. | |
EntityType |
string | The type of entity. | |
ExternalID |
string | Unique identifier for the External Identity Provider record matching this User. | |
GroupIDs |
Array of UUID |
The Groups the User belongs to, from the identity provider's claims at their last login. A bot User's Groups are the ones it was added to through the Group API instead. (readonly) | |
HiddenReason |
string | The reason the entity is hidden, if it is. A hidden entity is left out of List and Search results, and of what bulk operations act on, unless the include_hidden parameter names its reason or is *, or the where parameter names the entity by Slug or ID. ConfigHub/YAML Units are created hidden with the reason BackingUnit unless given another. | |
ProfilePictureURL |
string | The URL to get the profile avatar picture of the User. | |
Slug |
string | ✓ | Unique URL-safe identifier for the entity. |
UpdatedAt |
string (date-time) | The timestamp when the entity was last updated in "2023-01-01T12:00:00Z" format. | |
UserID |
string (uuid) | Unique identifier for a User. | |
Username |
string | Unique username for a User. Must be unique for all of Confighub. | |
Version |
integer (int64) | An entity-specific sequence number used for optimistic concurrency control. The value read must be sent in calls to Update. |