Describe Team Membership
Authoritatively answers whether a subject is a member of a team, with their team role and per-application role names for the calling application. This is the product-side authorisation check for destructive or sensitive operations where a cached token claim is not fresh enough.
Required scopes: auth:teams:read
JWT access token obtained via OAuth2 flow or service account
In: header
Header Parameters
Define the version of the Connect protocol
1Define the timeout, in ms
Request Body
application/json
1 <= length <= 128Subject URN (user or service account). Defaults to the calling subject.
length <= 128Response Body
application/json
application/json
curl -X POST "https://auth.xeonr.io/xeonr.auth.api.v1.TeamsService/DescribeTeamMembership" \ -H "Connect-Protocol-Version: 1" \ -H "Content-Type: application/json" \ -d '{}'{
"isMember": true,
"role": "TEAM_ROLE_UNSPECIFIED",
"applicationRoles": [
"string"
]
}{
"code": "not_found",
"message": "string",
"details": [
{
"type": "string",
"value": "string",
"debug": {}
}
]
}Describe Team Entitlement POST
Returns whether a team is entitled to the calling application, with the entitlement's per-product configuration. **Required scopes:** `auth:teams:read`
Disable Team Application POST
Removes a team's entitlement to an application, revoking team-derived access for its members. Requires team owner. **Required scopes:** `auth:teams:manage` or `auth:teams:manage:app` (the latter additionally requires the team to be entitled to the calling application)