Team & Org Admin
Skip this page if you're not building org-admin tooling. Most license-management integrations don't need any of these endpoints.
These are the dashboard endpoints behind the "Team", "Settings", and "Analytics" pages of the GeckoGuard UI. They live under /v1/dashboard/* and require a JWT access token (Bearer). API keys are not accepted. Role required is shown per endpoint.
Members
| Method | Endpoint | Min role | Description |
|---|---|---|---|
GET | /v1/dashboard/orgs/:orgId/members | VIEWER | List org members (id, email, name, role) and the latest role-change timestamp |
PATCH | /v1/dashboard/orgs/:orgId/members/:memberId | ADMIN (or OWNER to assign OWNER) | Update a member's role |
DELETE | /v1/dashboard/orgs/:orgId/members/:memberId | ADMIN (or OWNER to remove an OWNER) | Remove a member from the org |
Roles, in increasing privilege: VIEWER < DEV < ADMIN < OWNER. The last OWNER cannot be demoted or removed (409 CONFLICT).
Invites
| Method | Endpoint | Min role | Description |
|---|---|---|---|
POST | /v1/dashboard/orgs/:orgId/invites | ADMIN (or OWNER to invite OWNER) | Create an invite (email + role). Sends an email. |
GET | /v1/dashboard/orgs/:orgId/invites | VIEWER | List pending invites |
POST | /v1/dashboard/orgs/:orgId/invites/:inviteId/revoke | ADMIN | Revoke a pending invite |
POST | /v1/dashboard/orgs/:orgId/invites/:inviteId/resend | ADMIN | Resend the invite email |
The invitee accepts via the dashboard — there's a separate public endpoint for invite preview (/v1/dashboard/invites/preview) that doesn't require auth.
Plan usage counts unique email identities across organization members, product-specific collaborators, and active pending invites. Granting another product permission to someone already on the team does not consume another seat. Expired or revoked invites do not consume seats.
Ownership
| Method | Endpoint | Min role | Description |
|---|---|---|---|
POST | /v1/dashboard/orgs/:orgId/transfer-ownership | OWNER | Transfer the OWNER role to another member. The current owner is demoted to ADMIN. |
Body: { newOwnerId: <userId> }. The target must already be a member of the org.
Analytics
| Method | Endpoint | Min role | Description |
|---|---|---|---|
GET | /v1/dashboard/orgs/:orgId/analytics | VIEWER | Time-series + totals for license activity, authorizations, denials, and API call volume |
GET | /v1/dashboard/orgs/:orgId/licenses/analytics | VIEWER | License counts grouped by status (PENDING / ACTIVE / EXPIRED / REVOKED / SUSPENDED) and product |
Sample response from licenses/analytics:
{
"ok": true,
"data": {
"total": 1500,
"byStatus": { "PENDING": 50, "ACTIVE": 1170, "EXPIRED": 250, "REVOKED": 20, "SUSPENDED": 10 },
"byProduct": [
{ "productId": "abc", "productName": "My App", "count": 800 },
{ "productId": "def", "productName": "My Tool", "count": 700 }
]
}
}
Audit log
Every state-changing call on this page (and on license management) writes an audit row. Read it with:
GET /v1/dashboard/audit?orgId=:orgId&limit=50
The activity list and event details include the recorded actor ID, target ID,
product, request context, and event metadata such as the file name or denial
reason. Customer authorization and verification events distinguish allowed and
denied checks. Organization owners and admins can also see resolved customer
usernames and email addresses; other roles retain the recorded IDs. Names are
resolved from current records, so deleted customers and products fall back to
their recorded identifiers. License credentials are not fetched for display.
The customer category includes both USER.* and ENDUSER.* events.
Use the returned nextCursor as cursor to fetch the next page. Filter by productId, an exact or prefix action (for example LICENSE.), actorType, q, or range=24h|7d|30d.
Add format=csv to download up to 10,000 matching rows. The export applies the same organization/product authorization and actor-email redaction as the JSON view.