Table of contents
Access Control
Download API definition:
POST https://api.bentley.com/accesscontrol/itwins/{id}/members/users

Add or Invite new iTwin user members. Users which are external (i.e. not in the same organization as the iTwin) are not automatically added to the iTwin. Instead, they're invited. Users which are not external, are immediately added as members on the iTwin.

Invited individuals will recieve an invitation via Email, where they'll be prompted to accept the invitation. Upon accepting, they'll then become a member of the iTwin.

The total number of roles assigned in this request must not exceed 50. This can be achieved with many different configurations. For example, 1 role can be assigned to 50 users, or 5 roles can be assigned to 10 users, both resulting in 50 role assignments.

Authentication

Requires Authorization header with valid Bearer token for scope itwin-platform.

For more documentation on authorization and how to get access token visit OAUTH2 Authorization page.

Authorization

User must have the administration_invite_member permission assigned at the iTwin level or be an Organization Administrator for the Organization that owns a given iTwin.

An Organization Administrator must have at least one of the following roles assigned in User Management: Account Administrator, Co-Administrator, or CONNECT Services Administrator. For more information about User Management please visit our Bentley Communities Licensing, Cloud, and Web Services wiki page.

Request parameters

Name
Required?
Description
id
Yes

Request headers

Name
Required?
Description
Authorization
Yes

OAuth access token with itwin-platform scope

Accept
No

Setting to application/vnd.bentley.itwin-platform.v2+json is recommended.

Request body

User Members (add)

Name
Type
Required?
Description
members
No

List of members.

Example

json
{
    "members": [{
            "email": "John.Johnson@example.com",
            "roleIds": ["5abbfcef-0eab-472a-b5f5-5c5a43df34b1", "83ee0d80-dea3-495a-b6c0-7bb102ebbcc3"]
        },
        {
            "email": "Maria.Miller@example.com",
            "roleIds": ["5abbfcef-0eab-472a-b5f5-5c5a43df34b1", "83ee0d80-dea3-495a-b6c0-7bb102ebbcc3"]
        }
    ]
}

Response 201 Created

iTwin user member was successfully added.

json
{
    "members": [{
            "id": "99cf5e21-735c-4598-99eb-fe3940f96353",
            "email": "John.Johnson@example.com",
            "givenName": "John",
            "surname": "Johnson",
            "organization": "Organization Corp.",
            "roles": [{
                "id": "5abbfcef-0eab-472a-b5f5-5c5a43df34b1",
                "displayName": "Read Access",
                "description": "Read Access"
            }]
        },
        {
            "id": "25407933-cad2-41a2-acf4-5a074c83046b",
            "email": "Maria.Miller@example.com",
            "givenName": "Maria",
            "surname": "Miller",
            "organization": "Organization Corp.",
            "roles": [{
                "id": "5abbfcef-0eab-472a-b5f5-5c5a43df34b1",
                "displayName": "Read Access",
                "description": "Read Access"
            }]
        }
    ],
    "invitations": [{
        "id": "25407933-cad2-41a2-acf4-5a074c83046b",
        "email": "invitee.user@anotherOrg.com",
        "invitedByEmail": "inviter.user@org.com",
        "status": "Pending",
        "createdDate": "2023-11-10T14:22:42.231788Z",
        "expirationDate": "2023-11-17T14:22:42.231788Z",
        "roles": [{
            "id": "5abbfcef-0eab-472a-b5f5-5c5a43df34b1",
            "displayName": "Read Access"
        }]
    }]
}

Response 401 Unauthorized

This response indicates that request lacks valid authentication credentials. Access token might not been provided, issued by the wrong issuer, does not have required scopes or request headers were malformed.

json
{
    "error": {
        "code": "HeaderNotFound",
        "message": "Header Authorization was not found in the request. Access denied."
    }
}

Response 403 Forbidden

The user has insufficient permissions for the requested operation.

json
{
    "error": {
        "code": "InsufficientPermissions",
        "message": "The user has insufficient permissions for the requested operation."
    }
}

Response 404 Not Found

This response indicates that iTwin, user member, or roles with specified ID were not found.

json
{
    "error": {
        "code": "ItwinNotFound",
        "message": "Requested iTwin is not available."
    }
}

Response 409 Conflict

Invalid request to add new iTwin user member. User Member already exists in iTwin.

json
{
    "error": {
        "code": "TeamMemberExists",
        "message": "Requested team member already exists in iTwin.",
        "target": "members[0].email"
    }
}

Response 422 Unprocessable Entity

Invalid request to add new iTwin user member. Request payload might be missing some of the required properties.

json
{
    "error": {
        "code": "InvalidiTwinsMemberRequest",
        "message": "Request body or query is invalid.",
        "details": [{
                "code": "MissingRequiredProperty",
                "message": "Required property is missing.",
                "target": "members[0].email"
            },
            {
                "code": "MissingRequiredProperty",
                "message": "Required property is missing.",
                "target": "members[0].roleIds"
            },
            {
                "code": "InvalidProperty",
                "message": "Collection size exceeds maximum size.",
                "target": "members"
            },
            {
                "code": "InvalidRequestBody",
                "message": "Failed to parse request body or collection is empty."
            }
        ]
    }
}

Response 429 Too many requests

This response indicates that the user has sent too many requests in a given amount of time.

json
{
    "error": {
        "code": "TooManyRequests",
        "message": "More requests were received than the subscription rate-limit allows."
    }
}

Response headers

Name
Description
retry-after

The number of requests exceeds the rate-limit for the client subscription.

iTwin User Member

Name
Type
Description
id
String

The user Id in Identity Management System.

email
String

User email.

givenName
String

User given name.

surname
String

User surname.

organization
String

Organization user is member of in Identity Management System.

roles

List of roles.

iTwin User Invitation status

The status of the invitation.

Name
Type
Description
Pending
String
Accepted
String

iTwin User Invitation

Name
Type
Description
id
String

The user Id in Identity Management System.

email
String

User that was invited.

invitedByEmail
String

User that sent the invitation.

iTwin User Invitation status

The status of the invitation.

createdDate
Date-time

Datetime when the invitation was created.

expirationDate
Date-time

DateTime when the invitation will expire.

roles

List of roles.

Adding iTwin User Members (response)

Name
Type
Description
members

List of user members.

invitations

List of user invitations.

Role

Name
Type
Description
id
String

The role id.

displayName
String

The display name of your Role.

description
String

A description of your Role.

permissions
String[]

List of permissions assigned to the role.

User Member (add)

Name
Type
Description
email
String

User email.

roleIds
String[]

List of role ids.

User Members (add)

Name
Type
Description
members

List of members.

Error

Contains error information.

Name
Type
Description
code
String

One of a server-defined set of error codes.

message
String

A human-readable representation of the error.

target
String, null

The target of the error.

Error Response

Gives details for an error that occurred while handling the request. Note that clients MUST NOT assume that every failed request will produce an object of this schema, or that all of the properties in the response will be non-null, as the error may have prevented this response from being constructed.

Name
Type
Description
error

Error information.