Skip to main content
POST
Revoke an active company membership

Authorizations

Authorization
string
header
required

Partner API Bearer key: Authorization: Bearer <key>. Keys are created only through authorized portal or staff flows.

Headers

Idempotency-Key
string
required

Required client-supplied key scoped to the Partner owner, method, operation and path. An exact retry replays the original response while it is retained, including after credential rotation or replacement. Current permissions are required.

Path Parameters

company_id
string<uuid>
required

UUID of the managed company in this request.

membership_id
string<uuid>
required

UUID of the company membership in this request.

Body

application/json

Unknown and read-only request fields are rejected with a validation error instead of being silently ignored.

reason
string
required

Reason for revoking the membership.

Required string length: 1 - 500

Response

A user's membership in a managed company.

created_at
string<date-time>
required
read-only

Time at which the membership was created.

email
string<email>
required

Email address submitted with the invitation while it is unaccepted; after acceptance, reflects the user's current profile.

Maximum string length: 128
first_name
string
required

Given name submitted with the invitation while it is unaccepted; after acceptance, reflects the user's current profile.

Maximum string length: 128
id
string<uuid>
required
read-only

Stable identifier of this user's membership in the managed company. Use it as membership_id in the company users endpoints.

invite_expires_at
string<date-time> | null
required
read-only

Expiry time of the setup invitation while the membership is pending_setup; null when no pending setup invitation is attached.

last_name
string
required

Family name submitted with the invitation while it is unaccepted; after acceptance, reflects the user's current profile.

Maximum string length: 128
revocation_reason
string
required
read-only

Reason recorded when the membership was revoked.

revoked_at
string<date-time> | null
required
read-only

Time at which the membership was revoked.

revoked_by_token_id
string<uuid> | null
required
read-only

Partner credential that revoked the membership, when applicable.

role
enum<string>
required

Permissions the user receives within the managed company.

  • admin - admin
  • tax_consultant - tax_consultant
  • member - member
  • readonly - readonly
  • developer - developer
Available options:
admin,
tax_consultant,
member,
readonly,
developer
sandbox_origin
enum<string>
required

Provenance of the user behind this membership — sandbox_native for a subject created inside the sandbox (a test resource), production_mirror for a read-only copy of a production user, unclassified otherwise (always so in production).

  • production_mirror - Production mirror
  • sandbox_native - Sandbox native
  • unclassified - Unclassified
Available options:
production_mirror,
sandbox_native,
unclassified
status
enum<string>
required

Membership lifecycle state: pending_setup awaits invitation acceptance; active grants access; cancelled ends a pending invitation; revoked removes an active membership's access.

Available options:
pending_setup,
active,
cancelled,
revoked
updated_at
string<date-time>
required
read-only

Time at which the membership was last updated.