Get a user
Serves one user of the organisation; any other id is 404 (a platform administrator also reads a pending organisation’s members).
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
The record's id — a positive 32-bit integer the platform minted.
Query parameters
latest (the default) shows a row's pending proposal where one exists; approved shows what the platform enforces. Resources without proposals serve the same rows for both.
Response
The user's row, rendered as the guide's Reads section describes: the position header and body field, the ETag, money as decimal strings.
The user's capabilities — what they may do; empty on a discovered row. a set (SBE bit-set) served as the array of its scope strings — each choice spelled <route family>:<verb> (the schema's camel-cased choice name de-camelled: accountAddressesApprove is account-addresses:approve) — in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict
What the IdP stated at discovery (the name, else email, else nickname claim); informational, never a key.
The position as a decimal string — the last change this member had applied, orders and balance readings included.
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
Platform name — per-org unique among live users with a non-empty name; empty until admission.
Membership — stamped by the owner from the actor's org, or from the discovery's parent ref.
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
The identity provider's subject, opaque, never parsed: a token's sub resolves to this row inside the token's organisation. Empty = unbound (a locally authenticated user). Unique among all the organisation's users, disabled included — a subject binds for the life of its row, and a second binding is refused IDP_REF_TAKEN.
Never present since 0.3.3: every money value on this API states its own scale on the wire — a policy amount or cap since 0.3.3, an order's and an execution's since 0.3.2, a balance's since 0.3.1 — so a row is never served raw, whether or not this member holds the asset or instrument it references. Kept, deprecated, so a client generated from 0.3.2 still compiles; it goes at the next major.