Skip to main content

Overview

Users act as the calling entity to the API. Users own tokens, which are used in requests to the API to assume the user’s role. Users are associated to Projects, meaning they have access to the resources in the Project.
All users regardless of role have access to the default project in the organization.

Managing Users

OnDeck distinguishes between two kinds of user:
  • Human users are provisioned through the dashboard. They can sign in to the UI and access personal API token management.
  • Service accounts are created via POST /users for automation — CI jobs, integrations, worker services.
Both can own API tokens and use any endpoint within their role and project scope.

User Roles

Your first onboarded user will have the role org_admin. You can treat this as your root account to create other Users, API Tokens, and Projects. Or, directly use it for simple use cases that don’t need access control.

org_admin

• Full access to all resources
• Create and manage users and projects
• Access all projects regardless of explicit assignment
• Manage API tokens for any user

client

• Limited access to assigned projects only
• Cannot create users or projects
• Manage API tokens only for themselves
• Standard usage of inference capabilities

Assigning Roles and Projects

When creating a service account, you specify its role and list of accessible projects. Human users receive their role at invite time in the admin portal.
  • Only users with org_admin role can create service accounts with org_admin or client role.
  • Users can create API Tokens for themselves, or have a User with org_admin role create one for them.
  • All users have access to the default Project.

Creating API Tokens

Tokens are created with POST /users/tokens. A token authenticates as its owning user and inherits that user’s accessible projects at request time — adding or removing a project on the user takes effect on every token they own, immediately. There is no way to scope a token to a subset of the user’s projects.

Pagination and Filtering

When listing Users, the API returns paginated results with support for filtering and sorting.

Deletion

Users in an Organization can only be deleted by Users with the role org_admin. A User can only be deleted if they have no API Tokens. This means to delete a User, you must first delete all of their API Tokens first.

List Users

View users in your organization

Create Service Account

Create a new service account for automation

Get User Details

Retrieve specific user information

Create API Token

Generate tokens for API access

Delete User

Delete a User

Delete API Token

Delete a Token