Revoke a member’s access
const url = 'https://api.sloose.com/orgs/org_9f3c/members/usr_4b19/block';const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/orgs/org_9f3c/members/usr_4b19/block \ --header 'Authorization: Bearer <token>'Blocks the member. Their next request is refused with ACCESS_REVOKED, and signing in again does not restore them — which is the whole point, since anybody in the customer’s Zoho org is otherwise admitted automatically and could simply sign in once more.
The membership row is kept rather than deleted, so the revocation is auditable and reversible.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The org id the session was issued for. A token for one org can never read another.
Example
org_9f3cThe org id the session was issued for. A token for one org can never read another.
The member’s user id, from the member list.
Example
usr_4b19The member’s user id, from the member list.
Responses
Section titled “Responses”Access revoked.
object
object
Where the role came from: the CRM profile at sign-in, or set by hand here. A manual role is not reset by signing in again.
How the org’s CRM knows this member — the Zoho user id. Null for someone who joined another way.
When access was revoked. Null while they can still use the org.
Example
{ "member": { "role": "operator" }}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}You tried to raise your own role (SELF_CHANGE), or to change somebody who outranks you or grant a role above your own (OUTRANKED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}That person is not in this org (MEMBER_NOT_FOUND).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}The org would be left with no owner (LAST_OWNER), or their access is revoked and must be restored first (ACCESS_REVOKED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}