> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.lakera.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server.

# Management API — Members

Manage the members of a shared folder and their [roles](/docs/red/folder-roles). All
endpoints require a Management API Key and are scoped to its organization — see the
[Overview](/docs/red/management-api-overview) for authentication and error conventions.

Membership is managed only on shared folders you create. The organization folder (whose
membership is maintained automatically) and personal folders reject member operations
with `400`.

A member's role is one of `viewer`, `member`, or `admin`. A folder always keeps at least
one admin: demoting or removing the last admin is rejected with `400`.

## List organization members

`GET /management/members`

Lists the distinct users who belong to at least one folder in the organization, across
all folders, in ascending `userId` order. Use it to discover a user's `userId` before
adding them to a folder. This is organization-scoped, not folder-scoped: a user appears
once regardless of how many folders they belong to, and folder association and role are
reported per folder by [List members](#list-members) below.

| Query parameter | Type   | Notes                                                                                         |
| --------------- | ------ | --------------------------------------------------------------------------------------------- |
| `limit`         | number | Maximum members to return. Default 100, capped at 500.                                        |
| `after`         | string | Return members whose `userId` sorts after this one — the `nextCursor` from the previous page. |

```bash
curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  "https://$LAKERA_RED_HOST/management/members?limit=100"
```

Each member carries its `userId` plus the `email` and `name` resolved from the
organization's identity provider. When a user's profile cannot be resolved, `email` and
`name` are `null` and the member is still listed, so no folder member is ever omitted.

```json
{
  "members": [
    { "userId": "...", "email": "alice@example.com", "name": "Alice Admin" },
    { "userId": "...", "email": null, "name": null }
  ],
  "nextCursor": "..."
}
```

`nextCursor` is the `after` value to pass to fetch the next page, or `null` when the
last page has been reached. Keep requesting with it until it comes back `null`:

```bash
curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  "https://$LAKERA_RED_HOST/management/members?limit=100&after={nextCursor}"
```

## List members

`GET /management/folders/{folderId}/members`

```bash
curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/members
```

```json
{
  "members": [{ "userId": "...", "role": "admin" }]
}
```

## Add a member

`POST /management/folders/{folderId}/members`

| Field    | Type   | Required | Notes                                        |
| -------- | ------ | -------- | -------------------------------------------- |
| `userId` | string | yes      | Must be a user in the folder's organization. |
| `role`   | string | yes      | `viewer`, `member`, or `admin`.              |

```bash
curl -X POST -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"userId": "{userId}", "role": "member"}' \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/members
```

Responds `204`. Adding a user who is not in the organization, or who is already a
member, is rejected with `400`.

## Change a member's role

`PATCH /management/folders/{folderId}/members/{userId}`

```bash
curl -X PATCH -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"role": "admin"}' \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/members/{userId}
```

Responds `204`.

## Remove a member

`DELETE /management/folders/{folderId}/members/{userId}`

```bash
curl -X DELETE -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/members/{userId}
```

Responds `204`.