Xeonr Developer Docs

Describe Team Membership

POST
/xeonr.auth.api.v1.TeamsService/DescribeTeamMembership

Authoritatively answers whether a subject is a member of a team, with their team role and per-application role names for the calling application. This is the product-side authorisation check for destructive or sensitive operations where a cached token claim is not fresh enough.

Required scopes: auth:teams:read

AuthorizationBearer <token>

JWT access token obtained via OAuth2 flow or service account

In: header

Header Parameters

Connect-Protocol-Version*number

Define the version of the Connect protocol

Value in1
Connect-Timeout-Ms?number

Define the timeout, in ms

Request Body

application/json

team?string
Length1 <= length <= 128
subject?string

Subject URN (user or service account). Defaults to the calling subject.

Lengthlength <= 128
[key: string]?never

Response Body

application/json

application/json

curl -X POST "https://auth.xeonr.io/xeonr.auth.api.v1.TeamsService/DescribeTeamMembership" \  -H "Connect-Protocol-Version: 1" \  -H "Content-Type: application/json" \  -d '{}'
{
  "isMember": true,
  "role": "TEAM_ROLE_UNSPECIFIED",
  "applicationRoles": [
    "string"
  ]
}
{
  "code": "not_found",
  "message": "string",
  "details": [
    {
      "type": "string",
      "value": "string",
      "debug": {}
    }
  ]
}