Skip to content

Group

A Group of Users, a subject in an entity's Permissions. Groups and their membership are managed in the identity provider, and like Users are not scoped to an Organization; a Group is provisioned when a User in it logs in. Bot Users are the exception: they are added to a Group through the API.

Operations

Method Endpoint Description
GET /group List Groups
GET /group/{group_id} Get Group
POST /group/{group_id}/user/{user_id} Add a bot User to a Group
DELETE /group/{group_id}/user/{user_id} Remove a bot User from a Group

List Groups

GET /group

List Groups

Operation ID: ListGroups

Parameters

Query Parameters

Parameter Type Required Description
where string The specified string is an expression for the purpose of filtering the list of Groups returned. The expression syntax was inspired by SQL. It supports conjunctions using AND of relational expressions of the form attribute operator attribute_or_literal. The attribute names are case-sensitive and PascalCase, as in the JSON encoding. Strings support the following operators: <, >, <=, >=, =, !=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*, IN, NOT IN. String pattern operators: LIKE and ~~ for pattern matching with % and _ wildcards, ILIKE for case-insensitive pattern matching, NOT LIKE and !~~ for negated pattern matching. String regex operators: ~ for regex matching, ~* for case-insensitive regex, !~ and !~* for regex not matching (case-sensitive and insensitive). Integers support the following operators: <, >, <=, >=, =, !=, IN, NOT IN. UUIDs and boolean attributes support equality and inequality only. UUID and time literals must be quoted as string literals. String literals are quoted with single quotes, such as 'string'. Time literals use the same form as when serialized as JSON, such as: CreatedAt > '2025-02-18T23:16:34'. Integer and boolean literals are also supported for attributes of those types. Arrays support the ? operator to to match any element of the array, as in FromLinkID ? '7c61626f-ddbe-41af-93f6-b69f4ab6d308'. Arrays can perform LEN() to check for length, as in LEN(FromLinkID) > 0. An attribute naming a list of other entities can be filtered on their attributes with a * segment, as in FromLink.*.Slug = 'upgrade-app', which holds when any element satisfies it. Without the * such a reference is an error, since it names no single value to compare. Map support the dot notation to specify a particular map key, as in Labels.tier = 'Backend'. Maps support IS NULL and IS NOT NULL with dot notation to check for key absence or presence, as in Labels.tier IS NULL (key doesn't exist) or Labels.tier IS NOT NULL (key exists). Comparison results can be tested with IS TRUE, IS FALSE, IS NOT TRUE, and IS NOT FALSE. These are useful for nullable columns: MergeSourceID = '<uuid>' IS NOT FALSE matches rows where MergeSourceID equals the value OR is NULL. The IN and NOT IN operators accept a comma-separated list of values in parentheses, such as Slug IN ('slugone', 'slugtwo') or Labels.environment IN ('prod', 'staging'). Conjunctions are supported using the AND operator. An example conjunction is: CreatedAt >= '2025-01-07' AND Slug = 'test' AND Labels.mykey = 'myvalue'. Supported attributes for filtering on Group: CreatedAt, DisplayName, ExternalID, GroupID, Slug, UpdatedAt. The whole string must be query-encoded.
filter string UUID of a Filter entity to apply to the Group list. The Filter must be in the same Organization as the user credentials. The Filter's From field must match the entity type being filtered (Group). For Space-resident entities, if the Filter has a FromSpaceID, it must match the operation's SpaceID. The Filter's Where clause will be combined with any explicit 'where' parameter using AND logic. If both 'filter' and 'where' parameters are specified, they are combined with AND logic.
contains string Free text search that approximately matches the specified string against string fields and map keys/values. The search is case-insensitive and uses pattern matching to find entities containing the text. Searchable string fields include attributes like Slug, DisplayName, and string-typed custom fields. For map fields (like Labels and Annotations), the search matches both map keys and values. The search uses OR logic across all searchable fields, so matching any field will return the entity. If both 'where' and 'contains' parameters are specified, they are combined with AND logic. Searchable fields for Group include string and map-type attributes from the queryable attributes list. The whole string must be query-encoded.
select string Select clause for specifying which fields to include in the response for Group. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, GroupID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded.
include_hidden string Hidden Group entities, those with a HiddenReason, are left out of the results, or of what a bulk operation acts on, unless this names their HiddenReason. It is a comma-separated list of HiddenReasons, or * for all of them. A where clause naming the entities, by their Slug or ID with = or IN, or naming HiddenReason at all, also returns hidden entities it selects. ConfigHub/YAML Units, which hold the configuration of entities, are hidden with the HiddenReason BackingUnit.
limit integer Maximum number of Group entities to return. If not specified, all matching entities are returned. Values greater than 1000 are rejected with 400. When there may be more entities, the response has a ConfigHub-Continue header to pass as the continue parameter of the next request.
order_by string Comma-separated list of fields to sort Group results by, each in the form 'ASC|DESC:FieldName' or just 'FieldName'. Field names are case-sensitive and PascalCase, as in the JSON encoding. Sort direction defaults to ASC when the 'DIRECTION:' prefix is omitted. Supported attributes for ordering Group: CreatedAt, DisplayName, ExternalID, GroupID, Slug, UpdatedAt. Example: 'DESC:CreatedAt' or 'DisplayName,DESC:CreatedAt'. Results are ordered by the Group's ID after the fields named, and by the ID alone if none are. The whole string must be query-encoded.
continue string The token from the ConfigHub-Continue header of the previous page, to return the Group entities after it. The request's other parameters, except limit, must be the same as those of the request that returned the token. Keep reading until a response has no such header: a page can hold fewer entities than the limit, or none, and still be followed by more.

Responses

Status Description Content-Type Schema
200 OK application/json Array of ExtendedGroup
400 Group request is invalid (Bad Request). application/json StandardErrorResponse
401 Unauthorized access. application/json StandardErrorResponse
403 Forbidden access. application/json StandardErrorResponse
404 Group not found. application/json StandardErrorResponse
500 Something went wrong while processing Group. application/json StandardErrorResponse
default Unexpected error. application/json StandardErrorResponse

Get Group

GET /group/{group_id}

Get Group

Operation ID: GetGroup

Parameters

Path Parameters

Parameter Type Required Description
group_id string ✓ Unique identifier for a group_id

Query Parameters

Parameter Type Required Description
select string Select clause for specifying which fields to include in the response for Group. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, GroupID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded.

Responses

Status Description Content-Type Schema
200 Group with additional related entities expanded based on the request's include parameter. application/json ExtendedGroup
400 Group request is invalid (Bad Request). application/json StandardErrorResponse
401 Unauthorized access. application/json StandardErrorResponse
403 Forbidden access. application/json StandardErrorResponse
404 Group not found. application/json StandardErrorResponse
500 Something went wrong while processing Group. application/json StandardErrorResponse
default Unexpected error. application/json StandardErrorResponse

Add a bot User to a Group

POST /group/{group_id}/user/{user_id}

Add the bot User of a BridgeWorker in the caller's Organization to the Group. Other Users' Group memberships are managed in the identity provider. An organization admin or manager may. So may a member of the Group who has Manage permission on the bot User's BridgeWorker. Adding a bot that is already a member does nothing. Returns the bot User with its GroupIDs.

Operation ID: AddGroupBotUser

Parameters

Path Parameters

Parameter Type Required Description
group_id string ✓ Unique identifier for a group_id
user_id string ✓ Unique identifier for a user_id

Responses

Status Description Content-Type Schema
200 a User in Confighub. application/json User
400 Group request is invalid (Bad Request). application/json StandardErrorResponse
401 Unauthorized access. application/json StandardErrorResponse
403 Forbidden access. application/json StandardErrorResponse
404 Group not found. application/json StandardErrorResponse
409 Group data conflict. Data has changed since last read. application/json StandardErrorResponse
500 Something went wrong while processing Group. application/json StandardErrorResponse
default Unexpected error. application/json StandardErrorResponse

Remove a bot User from a Group

DELETE /group/{group_id}/user/{user_id}

Remove the bot User of a BridgeWorker in the caller's Organization from the Group. An organization admin or manager may. So may a member of the Group who has Manage permission on the bot User's BridgeWorker. Removing a bot that is not a member does nothing. Returns the bot User with its GroupIDs.

Operation ID: RemoveGroupBotUser

Parameters

Path Parameters

Parameter Type Required Description
group_id string ✓ Unique identifier for a group_id
user_id string ✓ Unique identifier for a user_id

Responses

Status Description Content-Type Schema
200 a User in Confighub. application/json User
400 Group request is invalid (Bad Request). application/json StandardErrorResponse
401 Unauthorized access. application/json StandardErrorResponse
403 Forbidden access. application/json StandardErrorResponse
404 Group not found. application/json StandardErrorResponse
409 Group is still in use: it has DeleteGates, or other entities still reference it. Or data has changed since last read. application/json StandardErrorResponse
422 Group could not be deleted. application/json StandardErrorResponse
500 Something went wrong while processing Group. application/json StandardErrorResponse
default Unexpected error. application/json StandardErrorResponse

Schemas

ExtendedGroup

Group with additional related entities expanded based on the request's include parameter.

Properties

Property Type Required Description
Error ResponseError
Group Group

StandardErrorResponse

Error response details.

Properties

Property Type Required Description
Code string HTTP status code of the response.
Message string Message returned with the response.

User

a User in Confighub.

Properties

Property Type Required Description
CreatedAt string (date-time) The timestamp when the entity was created in "2023-01-01T12:00:00Z" format.
DisplayName string Friendly name for the entity.
EntityType string The type of entity.
ExternalID string Unique identifier for the External Identity Provider record matching this User.
GroupIDs Array of UUID The Groups the User belongs to, from the identity provider's claims at their last login. A bot User's Groups are the ones it was added to through the Group API instead. (readonly)
HiddenReason string The reason the entity is hidden, if it is. A hidden entity is left out of List and Search results, and of what bulk operations act on, unless the include_hidden parameter names its reason or is *, or the where parameter names the entity by Slug or ID. ConfigHub/YAML Units are created hidden with the reason BackingUnit unless given another.
ProfilePictureURL string The URL to get the profile avatar picture of the User.
Slug string ✓ Unique URL-safe identifier for the entity.
UpdatedAt string (date-time) The timestamp when the entity was last updated in "2023-01-01T12:00:00Z" format.
UserID string (uuid) Unique identifier for a User.
Username string Unique username for a User. Must be unique for all of Confighub.
Version integer (int64) An entity-specific sequence number used for optimistic concurrency control. The value read must be sent in calls to Update.