Skip to main content
Version: 4.0.4
Version: 1.0.0

User App Setup API

User App Setup API​

Manage User App Setup profiles used by applications at registration and login. Applications link a profile via user_setup_id on the App Configuration API.

Requires cidaas 4.x / Trustdesk.

Relationship to Field Setup​

User App Setup does not define field schemas. It references field keys that must exist in Field Setup. Those keys are validated on create and update.

Authentication​

Access is granted when the access token matches a required OAuth2 scope or an allowed group/role (interceptor uses OR matching, not AND).

OperationScopeAllowed roles
Read / graph searchcidaas:usersetup_readCIDAAS_ADMINS: ADMIN, SECONDARY_ADMIN, SUPER_ADMIN, USERSETUP_MANAGER, USERSETUP_VIEWER; DeveloperGT: APP_MANAGER
Create / updatecidaas:usersetup_writeCIDAAS_ADMINS: ADMIN, SECONDARY_ADMIN, SUPER_ADMIN, USERSETUP_MANAGER; DeveloperGT: APP_MANAGER
Deletecidaas:usersetup_deleteCIDAAS_ADMINS: ADMIN, SECONDARY_ADMIN, SUPER_ADMIN, USERSETUP_MANAGER; DeveloperGT: APP_MANAGER

Missing or invalid token, or no matching scope/role, returns 401 Unauthorized on all endpoints.

Action required for M2M / API integrators: include the matching dedicated cidaas:usersetup_* scope on the application. Tokens that previously relied only on broad unrelated scopes need a scope review.

Ownership​

Each profile has a read-only owner value set by the server: client, admin, system, or core.

  • Public create always stores owner: client (clients cannot choose another owner).
  • PATCH rejects updates when owner is system or core (403 Forbidden). Profiles with owner: admin can be patched.
  • DELETE rejects deletion when owner is admin, system, or core (403 Forbidden). Only client-owned profiles can be deleted.
  • Graph search results exclude profiles with owner system or core (admin-owned profiles remain visible).

Related documentation

Authentication​

Security Scheme Type:

oauth2

OAuth Flow (authorizationCode):

Scopes:

  • cidaas:usersetup_read: read User App Setup profiles

  • cidaas:usersetup_write: create and update User App Setup profiles

  • cidaas:usersetup_delete: delete User App Setup profiles

OAuth Flow (clientCredentials):

Scopes:

  • cidaas:usersetup_read: read User App Setup profiles

  • cidaas:usersetup_write: create and update User App Setup profiles

  • cidaas:usersetup_delete: delete User App Setup profiles