Enable Team Application
Entitles a team to an application. Only applications with automatic team binding enabled may be self-served; others require an organisation administrator. Requires team owner.
Under auth:teams:manage:app a product may entitle ONLY itself, and only to a team the calling user owns and names explicitly; a team the caller does not own is indistinguishable from one that does not exist. Naming another application under that scope is refused.
Required scopes: auth:teams:manage or auth:teams:manage:app
JWT access token obtained via OAuth2 flow or service account
In: header
Header Parameters
Define the version of the Connect protocol
1Define the timeout, in ms
Request Body
application/json
1 <= length <= 128Application slug to entitle. Defaults to the calling client's application.
Only applications with automatic team binding enabled may be self-served;
others require an organisation administrator. Under
auth:teams:manage:app this must be empty or name the caller's own
application — a product may entitle only itself.
length <= 64Response Body
application/json
application/json
curl -X POST "https://auth.xeonr.io/xeonr.auth.api.v1.TeamsService/EnableTeamApplication" \ -H "Connect-Protocol-Version: 1" \ -H "Content-Type: application/json" \ -d '{}'{}{
"code": "not_found",
"message": "string",
"details": [
{
"type": "string",
"value": "string",
"debug": {}
}
]
}Disable Team Application POST
Removes a team's entitlement to an application, revoking team-derived access for its members. Requires team owner. **Required scopes:** `auth:teams:manage` or `auth:teams:manage:app` (the latter additionally requires the team to be entitled to the calling application)
Get Team POST
Fetches a team by URN or slug, with the calling subject's membership. The team must be entitled to the calling application. **Required scopes:** `auth:teams:read`