# Team access

> HTML version: https://zapped.to/api-documentation/teams-member
> Authentication: an API key holding the scope each endpoint lists, sent as `Authorization: Bearer YOUR_API_KEY`. See https://zapped.to/api-documentation/index.md for the base URL, errors and rate limits.

`owner_user_id` identifies the workspace owner. `member_user_id` identifies the accepted member and is null while an invitation is pending. The legacy `user_id` field is deprecated. In collection responses it retains the member ID meaning, while detail and acceptance responses retain the owner ID meaning during the compatibility window.

## api_documentation.read_all

### api_documentation.endpoint

`GET https://zapped.to/api/teams-member/`

### Authentication

An API key with the `teams:read` scope (Read teams and members), sent as `Authorization: Bearer YOUR_API_KEY`.

### api_documentation.example

```bash
curl --request GET \
  --url 'https://zapped.to/api/teams-member/' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

| api_documentation.parameters | Details | Description |
| --- | --- | --- |
| search | api_documentation.optional, api_documentation.string | api_documentation.filters.search |
| search_by | api_documentation.optional, api_documentation.string | api_documentation.filters.search_by |
| datetime_field | api_documentation.optional, api_documentation.string | api_documentation.allowed_values |
| datetime_start | api_documentation.optional, api_documentation.string | api_documentation.filters.datetime_start |
| datetime_end | api_documentation.optional, api_documentation.string | api_documentation.filters.datetime_end |
| order_by | api_documentation.optional, api_documentation.string | api_documentation.filters.order_by |
| order_type | api_documentation.optional, api_documentation.string | api_documentation.filters.order_by_type |
| page | api_documentation.optional, api_documentation.int | api_documentation.filters.page |
| results_per_page | api_documentation.optional, api_documentation.int | api_documentation.filters.results_per_page |

### api_documentation.response

```json
{
    "data": [
        {
            "id": 1,
            "access": {
                "read": true,
                "create": true,
                "update": true,
                "delete": false
            },
            "role": "editor",
            "resource_scope": "all",
            "status": 1,
            "last_datetime": null,
            "datetime": "2026-09-28 08:07:16",
            "team_id": 1,
            "user_id": 42,
            "owner_user_id": 7,
            "member_user_id": 42,
            "name": "Example team"
        },
        {
            "id": 2,
            "access": {
                "read": true,
                "create": false,
                "update": false,
                "delete": false
            },
            "role": "viewer",
            "resource_scope": "all",
            "status": 0,
            "last_datetime": null,
            "datetime": "2026-09-28 08:07:16",
            "team_id": 2,
            "user_id": 0,
            "owner_user_id": 9,
            "member_user_id": null,
            "name": "Pending team"
        }
    ],
    "meta": {
        "page": 1,
        "results_per_page": 25,
        "total": 2,
        "total_pages": 1
    },
    "links": {
        "first": "https://zapped.to/api/teams-member?page=1",
        "last": "https://zapped.to/api/teams-member?page=1",
        "next": null,
        "prev": null,
        "self": "https://zapped.to/api/teams-member?page=1"
    }
}
```

## api_documentation.read

### api_documentation.endpoint

`GET https://zapped.to/api/teams-member/{team_member_id}`

### Authentication

An API key with the `teams:read` scope (Read teams and members), sent as `Authorization: Bearer YOUR_API_KEY`.

### api_documentation.example

```bash
curl --request GET \
  --url 'https://zapped.to/api/teams-member/{team_member_id}' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

### api_documentation.response

```json
{
    "data": {
        "id": 1,
        "access": {
            "read": true,
            "create": true,
            "update": true,
            "delete": false
        },
        "role": "viewer",
        "resource_scope": "projects",
        "status": 1,
        "last_datetime": null,
        "datetime": "2026-09-28 08:07:16",
        "team_id": 1,
        "user_id": 7,
        "owner_user_id": 7,
        "member_user_id": 42,
        "name": "Example team"
    }
}
```

## api_documentation.update

### api_documentation.endpoint

`POST https://zapped.to/api/teams-member/{team_member_id}`

### Authentication

An API key with the `teams:write` scope (Manage teams, invitations and memberships), sent as `Authorization: Bearer YOUR_API_KEY`.

| api_documentation.parameters | Details | Description |
| --- | --- | --- |
| status | api_documentation.required, api_documentation.boolean | - |
| invitation_token | api_documentation.optional, api_documentation.string | Required for an unverified API account while the invitation is pending. A current exact-email verified account may omit it. Use the current opaque token from the invitation email as the compatible fallback. It is never returned by this API. |

### api_documentation.example

```bash
curl --request POST \
  --url 'https://zapped.to/api/teams-member/{team_member_id}' \
  --header 'Authorization: Bearer YOUR_API_KEY' \
  --header 'Content-Type: multipart/form-data' \
  --form 'status=1' \
  --form 'invitation_token={invitation_token}'
```

### api_documentation.response

```json
{
    "data": {
        "id": 1,
        "role": "viewer",
        "resource_scope": "all",
        "status": 1,
        "team_id": 1,
        "user_id": 7,
        "owner_user_id": 7,
        "member_user_id": 42,
        "name": "Example team"
    }
}
```

## api_documentation.delete

### api_documentation.endpoint

`DELETE https://zapped.to/api/teams-member/{team_member_id}`

### Authentication

An API key with the `teams:write` scope (Manage teams, invitations and memberships), sent as `Authorization: Bearer YOUR_API_KEY`.

### api_documentation.example

```bash
curl --request DELETE \
  --url 'https://zapped.to/api/teams-member/{team_member_id}' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

For an authorized pending invitation, DELETE declines it. For an accepted membership, DELETE leaves the team and removes workspace access.

Declining a pending invitation requires either current exact-email verification for the API account or the current `invitation_token` in the DELETE form body.

A successful DELETE returns HTTP 200 with an empty response body.
