Activate or deactivate a user

posthttps://api.expiryedge.com/v1/user/status
bearer token (Firebase ID token only; session JWTs are rejected); role admin60/min
Request
curl -X POST 'https://api.expiryedge.com/v1/user/status' \
  -H "Authorization: Bearer $EXPIRYEDGE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "userId": "u_4Np8cZe",
  "status": "deactivated"
}'
Response
{
  "message": "User deactivated successfully",
  "userId": "u_4Np8cZe",
  "status": "deactivated"
}

Deactivating disables sign-in and revokes the user's sessions. You cannot change your own status, deactivate the organization owner, or deactivate the last active admin.

Body parameters

application/json
  • userIdstringrequired
  • statusstringrequired
    Allowedactivedeactivated

Returns

200
Status changed.
  • messagestringrequired
  • userIdstringrequired
  • statusstringrequired
    Allowedactivedeactivated

Errors

400
The request is missing required fields or contains invalid values.
401
Missing, expired or invalid bearer token.
403
Authenticated, but your role or organization does not allow this action.
404
The record does not exist or is not in your organization.
405
The endpoint does not accept this HTTP method.
429
Too many requests for this endpoint from your IP. Wait Retry-After seconds.
500
Unexpected server error. Retry later; quote requestId to support.