User App Setup API
User App Setup API
Manage User App Setup profiles used by applications at registration and login. Applications link a profile via user_setup_id on the App Configuration API.
Requires cidaas 4.x / Trustdesk.
Relationship to Field Setup
User App Setup does not define field schemas. It references field keys that must exist in Field Setup. Those keys are validated on create and update.
Authentication
Access is granted when the access token matches a required OAuth2 scope or an allowed group/role (interceptor uses OR matching, not AND).
| Operation | Scope | Allowed roles |
|---|---|---|
| Read / graph search | cidaas:usersetup_read | CIDAAS_ADMINS: ADMIN, SECONDARY_ADMIN, SUPER_ADMIN, USERSETUP_MANAGER, USERSETUP_VIEWER; DeveloperGT: APP_MANAGER |
| Create / update | cidaas:usersetup_write | CIDAAS_ADMINS: ADMIN, SECONDARY_ADMIN, SUPER_ADMIN, USERSETUP_MANAGER; DeveloperGT: APP_MANAGER |
| Delete | cidaas:usersetup_delete | CIDAAS_ADMINS: ADMIN, SECONDARY_ADMIN, SUPER_ADMIN, USERSETUP_MANAGER; DeveloperGT: APP_MANAGER |
Missing or invalid token, or no matching scope/role, returns 401 Unauthorized on all endpoints.
Action required for M2M / API integrators: include the matching dedicated cidaas:usersetup_* scope on the application. Tokens that previously relied only on broad unrelated scopes need a scope review.
Ownership
Each profile has a read-only owner value set by the server: client, admin, system, or core.
- Public create always stores
owner: client(clients cannot choose another owner). - PATCH rejects updates when
ownerissystemorcore(403 Forbidden). Profiles withowner: admincan be patched. - DELETE rejects deletion when
ownerisadmin,system, orcore(403 Forbidden). Onlyclient-owned profiles can be deleted. - Graph search results exclude profiles with
ownersystemorcore(admin-owned profiles remain visible).
Related documentation
- App management
- Field settings
- Scope management
- User Search (graph filter operators)
Authentication
- OAuth 2.0: oauth2.0
Security Scheme Type: | oauth2 |
|---|---|
OAuth Flow (authorizationCode): | Token URL: https://domain/token-srv/token Authorization URL: https://domain/authz-srv/authz Scopes:
|
OAuth Flow (clientCredentials): | Token URL: https://domain/token-srv/token Scopes:
|
Contact cidaas support: [email protected]
Terms of Servicehttps://www.cidaas.com/terms-of-use/