Overview
Users act as the calling entity to the API. Users own tokens, which are used in requests to the API to assume the user’s role. Users are associated to Projects, meaning they have access to the resources in the Project.Managing Users
OnDeck distinguishes between two kinds of user:- Human users are provisioned through the dashboard. They can sign in to the UI and access personal API token management.
- Service accounts are created via
POST /usersfor automation — CI jobs, integrations, worker services.
User Roles
Your first onboarded user will have the roleorg_admin.
You can treat this as your root account to create other Users, API Tokens, and Projects.
Or, directly use it for simple use cases that don’t need access control.
org_admin
• Full access to all resources
• Create and manage users and projects
• Access all projects regardless of explicit assignment
• Manage API tokens for any user
• Create and manage users and projects
• Access all projects regardless of explicit assignment
• Manage API tokens for any user
client
• Limited access to assigned projects only
• Cannot create users or projects
• Manage API tokens only for themselves
• Standard usage of inference capabilities
• Cannot create users or projects
• Manage API tokens only for themselves
• Standard usage of inference capabilities
Assigning Roles and Projects
When creating a service account, you specify its role and list of accessible projects. Human users receive their role at invite time in the admin portal.- Only users with
org_adminrole can create service accounts withorg_adminorclientrole. - Users can create API Tokens for themselves, or have a User with
org_adminrole create one for them. - All users have access to the default Project.
Creating API Tokens
Tokens are created withPOST /users/tokens. A token authenticates as its owning user and inherits that user’s accessible projects at request time — adding or removing a project on the user takes effect on every token they own, immediately. There is no way to scope a token to a subset of the user’s projects.
Pagination and Filtering
When listing Users, the API returns paginated results with support for filtering and sorting.Deletion
Users in an Organization can only be deleted by Users with the role org_admin. A User can only be deleted if they have no API Tokens. This means to delete a User, you must first delete all of their API Tokens first.Related Endpoints
List Users
View users in your organization
Create Service Account
Create a new service account for automation
Get User Details
Retrieve specific user information
Create API Token
Generate tokens for API access
Delete User
Delete a User
Delete API Token
Delete a Token