Disable a user
Disables a user at once (users:manage); the organisation’s last administrator refuses 409 LAST_ADMIN. The user’s pending proposals stay approvable and withdrawable.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
The record's id — a positive 32-bit integer the platform minted.
Headers
Required on every write: a URL-safe string of 1 to 64 characters from [A-Za-z0-9._~-] (a UUID fits), scoped to you. It names one operation on one record, ever: a retry replays the stored outcome (Idempotent-Replay: true) or attaches to the live one, and reuse on another record refuses 409 IDEMPOTENCY_KEY_REUSED. Missing or malformed, 400.
The ETag the read minted, quoted or bare; absent or * is unconditional; a weak validator refuses 400 INVALID_IF_MATCH. A stale value answers 412 VERSION_CONFLICT with currentVersion and a fresh ETag: re-read, reapply, retry. Send it — every write restates the whole record, so an unconditional write overwrites every field from your copy, and an amend against a pending proposal replaces that proposal.
Request
Response
The user as the platform now holds it after the write — the same row the read serves, with the answering change's position, the row's ETag and, on a replayed key, Idempotent-Replay.
The user's capabilities — what they may do; empty on a discovered row. a set (SBE bit-set) served as the array of its scope strings — each choice spelled <route family>:<verb> (the schema's camel-cased choice name de-camelled: accountAddressesApprove is account-addresses:approve) — in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict
What the IdP stated at discovery (the name, else email, else nickname claim); informational, never a key.
The position as a decimal string — the last change this member had applied, orders and balance readings included.
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
Platform name — per-org unique among live users with a non-empty name; empty until admission.
Membership — stamped by the owner from the actor's org, or from the discovery's parent ref.
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
The identity provider's subject, opaque, never parsed: a token's sub resolves to this row inside the token's organisation. Empty = unbound (a locally authenticated user). Unique among all the organisation's users, disabled included — a subject binds for the life of its row, and a second binding is refused IDP_REF_TAKEN.
Never present since 0.3.3: every money value on this API states its own scale on the wire — a policy amount or cap since 0.3.3, an order's and an execution's since 0.3.2, a balance's since 0.3.1 — so a row is never served raw, whether or not this member holds the asset or instrument it references. Kept, deprecated, so a client generated from 0.3.2 still compiles; it goes at the next major.