Lists the users who can be granted portal access for the current merchant.
GET
/api/developer-portal/accounts/assignable-users
deprecated
Requires: DeveloperPortal.Accounts, DeveloperPortal.Accounts.Create, merchant scope.
Narrow the result with `filter`. Every user returned already meets the rules the create call enforces, so a request built from this list is not refused for the account it names. Create still checks those rules, because a caller need not have read this list first. A user who already holds a developer account for the current merchant is not returned, whether that account is active or disabled, because create refuses a second one. The list is empty when every eligible user already has access. A user whose access was removed is returned, and granting them access again restores it. The developer-account permissions gate this route, not the user-directory permissions: granting portal access does not entitle a caller to browse the directory.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
filter
required |
query | string | |
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
X-Acting-Merchant-Id
required |
header | string (uuid) | The merchant to act for. Optional: when absent, the caller's own merchant scope answers. A caller whose identity carries no merchant scope, such as an administrator, must send it. The selection is authorized on every operation; a merchant the caller may not act for is refused. |
Request body
application/json
, required
| Field | Type | Description |
|---|
This request body has no documented fields.
Responses
200 OK
Body: array of DeveloperPortalUserSummaryDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
id
required |
string (uuid) | |
userName
required |
string | The user's sign-in name. nullable |
email
required |
string | The user's email address. nullable |
hasBackOfficeRole
required |
boolean | Whether the user already holds a back-office role, i.e. one carrying a `RoleType` and therefore sitting on the Admin > Reseller > Merchant ladder. The two portal-only roles deliberately carry no `RoleType`, so a developer who has never been given a gateway account reads as `false` here. nullable |
displayName
required |
string | The label to show for this user: the sign-in name where there is one, the email otherwise, and the bare id as a last resort so a row never renders blank. nullableread only |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.