List members
const url = 'https://api.aletheia-ops.com/api/v1/org/members';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.aletheia-ops.com/api/v1/org/members \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK
Paginated members response
object
A row in the members list
object
Public shape of a user account (never includes the password hash)
object
A role reference on a member (no permissions)
object
Examplegenerated
{ "items": [ { "user": { "id": "example", "email": "example", "name": "example", "status": "example", "created_at": "2026-04-15T12:00:00Z" }, "status": "example", "joined_at": "2026-04-15T12:00:00Z", "roles": [ { "id": "example", "key": "example", "name": "example" } ] } ]}No valid credential was presented, or it has expired.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "unauthorized", "message": "authentication required"}{ "code": "invalid_credentials", "message": "invalid email or password"}{ "code": "invalid_token", "message": "invalid or expired token"}{ "code": "token_reuse", "message": "session revoked"}{ "code": "webhook_unauthorized", "message": "webhook verification failed"}Authenticated, but not permitted to perform this action.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "forbidden", "message": "you do not have permission to perform this action"}{ "code": "csrf_failed", "message": "missing or invalid CSRF token"}{ "code": "account_deactivated", "message": "your account is deactivated; contact your administrator"}{ "code": "ai_disabled", "message": "the AI assistant is disabled for this organization"}An unexpected failure. Diagnostic detail is logged server-side and
deliberately not returned. Quote the X-Request-Id response header when
reporting one.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "internal_error", "message": "internal server error"}