Business Users#
Users of client businesses: management by KIO admins, and settings of the signed-in business user.Concepts#
Business user: belongs to one business and has one business user role. Business users sign in with email and password or a one-time token (see Auth).
Admin: the first user created in a business becomes its admin.
Deactivation: users are never deleted, only deactivated (active: false). Deactivating a user cancels their upcoming KIO Link events and removes them from releases.
Datacenter access (dc_access): the days, hours and locations the user may visit, always within the business's datacenters.
Two-factor authentication: admins can reset a user's daily code limits or toggle 2FA for a user.
Audit trail: creations and deactivations are recorded.
"My" endpoints (releasesstatus, alertsstatus, delete-account) act on the signed-in business user and require no permission.
Endpoints#
Every business user, grouped by business.GET /v1/businessusers/{businessid}Every user of a business.POST /v1/businessusers/{businessid}Creates or reactivates a user and sends the welcome email.GET /v1/businessusers/{businessid}/user/{id}Returns a user of a business.PATCH /v1/businessusers/{businessid}/user/{id}Updates a user's profile.PATCH /v1/businessusers/{businessid}/user/{id}/avatarDELETE /v1/businessusers/{businessid}/user/{id}/avatarPATCH /v1/businessusers/business/{businessid}/deleteDeactivates several users.GET /v1/businessusers/search/{query}Up to 10 active users by name or email.GET /v1/businessusers/search/{query}/business/{businessid}Users of a business by name or email.GET /v1/businessusers/{businessid}/user/{id}/resetpasswordEmails a user a password reset link.GET /v1/businessusers/{businessid}/user/{id}/reset-token-otsResets a user's daily sign-in code limits.GET /v1/businessusers/user/{id}/toggle-two-factor-authTurns 2FA off or on for a user.GET /v1/business/list/export-usersDownloads every business user as CSV.POST /v1/business/users/importIntended to create users from CSV (currently broken).PATCH /v1/businessusers/releasesstatusOpts the signed-in user in or out of releases.PATCH /v1/businessusers/alertsstatusOpts the signed-in user in or out of alerts.DELETE /v1/businessusers/delete-accountAsks the KIO admins to delete the signed-in user's account.Source#
Router: routes/v1/business.js
Controllers: controllers/business/business-users.js, controllers/business.js
Models: models/business_user.js, models/business_user_access_token.js, models/records.js
Services: services/mailing.js, services/s3.js
Email templates: newUser, resetPassword, delete-account
Modified at 2026-10-05 20:40:40