# Team members

> HTML version: https://zapped.to/api-documentation/team-members
> Authentication: an API key holding the scope each endpoint lists, sent as `Authorization: Bearer YOUR_API_KEY`. See https://zapped.to/api-documentation/index.md for the base URL, errors and rate limits.

`owner_user_id` identifies the team owner. `member_user_id` identifies an accepted member and is null for pending invitations. The legacy `user_id` field remains the member ID, or zero while pending, during the compatibility window.

## api_documentation.read

### api_documentation.endpoint

`GET https://zapped.to/api/team-members/{team_id}`

### Authentication

An API key with the `teams:read` scope (Read teams and members), sent as `Authorization: Bearer YOUR_API_KEY`.

### api_documentation.example

```bash
curl --request GET \
  --url 'https://zapped.to/api/team-members/{team_id}' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

### api_documentation.response

```json
{
    "data": [
        {
            "id": 1,
            "team_id": 1,
            "user_id": 42,
            "owner_user_id": 7,
            "member_user_id": 42,
            "user_email": "hello@example.com",
            "access": {
                "read.all": true
            },
            "role": "viewer",
            "resource_scope": "all",
            "status": 1,
            "datetime": "2026-09-28 08:10:05",
            "last_datetime": null
        }
    ]
}
```

## api_documentation.create

### api_documentation.endpoint

`POST https://zapped.to/api/team-members`

### Authentication

An API key with the `teams:write` scope (Manage teams, invitations and memberships), sent as `Authorization: Bearer YOUR_API_KEY`.

Team member API writes support roles with All resources access only. Use the web app to assign selected projects or selected cards.

| api_documentation.parameters | Details | Description |
| --- | --- | --- |
| team_id | api_documentation.required, api_documentation.int | - |
| user_email | api_documentation.required, api_documentation.string | - |
| role | api_documentation.optional, api_documentation.string | `viewer`, `editor`, or `admin`. Defaults to `viewer`. |
| access | api_documentation.optional, api_documentation.string, api_documentation.array | Compatibility input only. Supply every permission as an explicit true or false value, or supply the complete enabled-key list for one role. Partial capability lists are rejected. |

### api_documentation.example

```bash
curl --request POST \
  --url 'https://zapped.to/api/team-members' \
  --header 'Authorization: Bearer YOUR_API_KEY' \
  --header 'Content-Type: multipart/form-data' \
  --form 'team_id=1' \
  --form 'user_email=hello@example.com' \
  --form 'role=editor'
```

### api_documentation.response

```json
{
    "data": {
        "id": 1,
        "team_id": 1,
        "user_id": 0,
        "owner_user_id": 7,
        "member_user_id": null,
        "user_email": "hello@example.com",
        "role": "editor",
        "resource_scope": "all",
        "status": 0
    }
}
```

## api_documentation.update

### api_documentation.endpoint

`POST https://zapped.to/api/team-members/{team_member_id}`

### Authentication

An API key with the `teams:write` scope (Manage teams, invitations and memberships), sent as `Authorization: Bearer YOUR_API_KEY`.

Team member API writes support roles with All resources access only. Use the web app to assign selected projects or selected cards.

| api_documentation.parameters | Details | Description |
| --- | --- | --- |
| role | api_documentation.optional, api_documentation.string | `viewer`, `editor`, or `admin`. |
| access | api_documentation.optional, api_documentation.string, api_documentation.array | Compatibility input only. Supply the complete canonical true or false object or the complete enabled-key list for one role. If role is also supplied, both values must describe the same permissions. |

### api_documentation.example

```bash
curl --request POST \
  --url 'https://zapped.to/api/team-members/{team_member_id}' \
  --header 'Authorization: Bearer YOUR_API_KEY' \
  --header 'Content-Type: multipart/form-data' \
  --form 'role=viewer'
```

### api_documentation.response

```json
{
    "data": {
        "id": 1,
        "team_id": 1,
        "user_id": 42,
        "owner_user_id": 7,
        "member_user_id": 42,
        "user_email": "hello@example.com",
        "role": "viewer",
        "resource_scope": "all",
        "status": 1
    }
}
```

## api_documentation.delete

### api_documentation.endpoint

`DELETE https://zapped.to/api/team-members/{team_member_id}`

### Authentication

An API key with the `teams:write` scope (Manage teams, invitations and memberships), sent as `Authorization: Bearer YOUR_API_KEY`.

### api_documentation.example

```bash
curl --request DELETE \
  --url 'https://zapped.to/api/team-members/{team_member_id}' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

A successful DELETE returns HTTP 200 with an empty response body.
