> ## Documentation Index
> Fetch the complete documentation index at: https://developers.factify.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List organization members

> Lists members of the caller's current organization.

Authorization: requires `organization#list_members`, which the
SpiceDB schema grants to any organization member (owner, admin,
or regular member).




## OpenAPI

````yaml /openapi.json get /v1/organization/members
openapi: 3.1.0
info:
  title: Factify API
  version: 1.1.1
  description: >-
    Factify API enables organizations to ingest records, manage workflows, and
    extract auditable facts.


    ## Authentication


    Bearer authentication header of the form `Bearer <token>`, where `<token>`
    is your auth token.


    ```

    Authorization: Bearer ffy_prod_<base32_uuid><base62_random>

    ```


    ## Rate Limiting


    Per-API-key rate limits apply. Concrete thresholds are configured per

    deployment and surface via standard `Retry-After` and `RateLimit-*`

    response headers when a request is throttled.


    ## Errors


    Factify uses conventional HTTP status codes and returns structured error
    responses following [RFC 9457](https://www.rfc-editor.org/rfc/rfc9457)
    (Problem Details for HTTP APIs).
  contact:
    name: Factify API Support
    email: api@factify.com
    url: https://factify.com/support
  license:
    name: Proprietary
    url: https://factify.com/terms
servers:
  - url: https://api.factify.com
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Organizations
    description: Organizations and their settings.
  - name: Members
    description: Membership roster and roles within an organization.
  - name: Invitations
    description: Pending invitations to join an organization.
  - name: Users
    description: The authenticated user's profile.
  - name: ApiKeys
    description: API keys used to authenticate SDK and integration callers.
  - name: Usage
    description: |
      Per-organization usage and quota limits. Future operations covering
      API-key-level quotas and usage history land here too.
  - name: Connections
    description: Inbound integration connections that records are ingested from.
  - name: Workflows
    description: Workflow templates that define the rubric set for fact extraction.
  - name: Plans
    description: Workflow instances — bind claims and lock to produce an extraction spec.
  - name: Records
    description: Generic JSON records ingested for claim extraction.
  - name: Audit
    description: Unified audit and provenance events.
  - name: Notifications
    description: In-app notification feed backed by audit events and per-user read state.
  - name: Internal
    description: Internal callbacks not intended for public SDK consumers.
  - name: RubricContentions
    description: >-
      Rubric contention detection and resolution — surface and resolve competing
      claim bindings.
  - name: IdentityProviders
    description: Per-organization SAML identity providers for SSO.
  - name: Analytics
    description: >-
      Org-scoped execution analytics — volume, decision breakdown, and latency
      over plan executions.
  - name: Auth
    description: |
      Browser-facing authentication surface — CSRF, session, OAuth callback,
      OTP, passkey, and refresh-token endpoints. These predate factapi's
      versioned `/v1/*` SDK surface and use the BetterAuth wire format the
      workspace SPA already speaks; SDK generators skip them via
      `x-speakeasy-ignore`.
paths:
  /v1/organization/members:
    get:
      tags:
        - Members
      summary: List organization members
      description: |
        Lists members of the caller's current organization.

        Authorization: requires `organization#list_members`, which the
        SpiceDB schema grants to any organization member (owner, admin,
        or regular member).
      operationId: listMembers
      parameters:
        - $ref: '#/components/parameters/OrgScopeHeader'
      responses:
        '200':
          description: A list of organization members.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MemberListOutputBody'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    OrgScopeHeader:
      name: X-Factify-Organization-Id
      in: header
      required: false
      description: |
        Optional. Factify-staff acting-as override: when set, factapi
        resolves the request against this organization instead of the
        session-bound one. Honored only for callers with `@factify.com`
        emails; non-staff requests carrying this header are rejected
        with 403. The value is a typed org id (e.g.
        `org_01h2xcejqtf2nbrexx3vqjhp41`).
      schema:
        type: string
        pattern: ^org_[0-9a-hjkmnp-tv-z]{26}$
        example: org_01h2xcejqtf2nbrexx3vqjhp41
  schemas:
    MemberListOutputBody:
      additionalProperties: false
      type: object
      description: A list of members in the organization.
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/OrgMember'
      required:
        - items
    OrgMember:
      additionalProperties: false
      type: object
      description: |
        Membership record linking a user to an organization with a role.
        Profile fields (`email`, `display_name`, `given_name`, `family_name`)
        come from the users table JOINed at list time, so consumers don't
        need a second lookup to render the member roster.
      properties:
        org_id:
          type: string
          description: |
            Organization the user is a member of.
            Pattern: `org_[0-9a-hjkmnp-tv-z]{26}`
          example: org_01h2xcejqtf2nbrexx3vqjhp41
        user_id:
          type: string
          description: |
            User account TypedID.
            Pattern: `usr_[0-9a-hjkmnp-tv-z]{26}`
          example: usr_01h2xcejqtf2nbrexx3vqjhp41
        role:
          type: string
          description: The member's role within the organization.
          example: member
        joined_at:
          type: string
          format: date-time
          description: Timestamp when the user joined the organization.
          example: '2025-01-15T10:30:00Z'
        email:
          type: string
          format: email
          description: The member's email address.
          example: alice@factify.com
        display_name:
          type: string
          description: |
            The member's display name. Empty string when the user hasn't
            set one (the column has a `NOT NULL DEFAULT ''` constraint).
          example: Alice Chen
        given_name:
          type: string
          nullable: true
          description: First name. NULL when the user hasn't supplied one.
          example: Alice
        family_name:
          type: string
          nullable: true
          description: Last name. NULL when the user hasn't supplied one.
          example: Chen
      required:
        - org_id
        - user_id
        - role
        - joined_at
        - email
        - display_name
    ErrorModel:
      additionalProperties: false
      type: object
      properties:
        detail:
          type: string
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          example: Property foo is required but is missing.
        errors:
          description: Optional list of individual error details
          type: array
          items:
            $ref: '#/components/schemas/ErrorDetail'
        instance:
          type: string
          format: uri
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          example: https://example.com/error-log/abc123
        status:
          type: integer
          format: int64
          description: HTTP status code
          example: 400
        title:
          type: string
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          example: Bad Request
        type:
          type: string
          format: uri
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          example: https://example.com/errors/example
    ErrorDetail:
      additionalProperties: false
      type: object
      properties:
        location:
          type: string
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
        message:
          type: string
          description: Error message text
        value:
          description: The value at the given location
  responses:
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorModel'
          example:
            type: about:blank
            title: Unauthorized
            status: 401
            detail: Missing or invalid authentication credentials.
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorModel'
          example:
            type: about:blank
            title: Forbidden
            status: 403
            detail: >-
              You do not have permission to perform this action on this
              resource.
    TooManyRequests:
      description: Too Many Requests
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorModel'
          example:
            type: about:blank
            title: Too Many Requests
            status: 429
            detail: >-
              Rate limit exceeded. Retry after the period indicated by the
              Retry-After header.
    InternalServerError:
      description: Internal Server Error
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ErrorModel'
          example:
            type: about:blank
            title: Internal Server Error
            status: 500
            detail: >-
              An unexpected error occurred. Retry, and contact support if the
              issue persists.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: |
        Bearer authentication using a factapi-issued API key
        (`ffy_<env>_<base32_uuid><base62_random>`). Cookie-based
        sessions are accepted automatically by user-facing endpoints
        but are not surfaced as an OpenAPI auth scheme.

````