Skip to Content
API ReferenceWorkspaces

Workspaces API

Workspaces are the primary multi-tenant isolation boundary in Zeotap. Each workspace contains its own sources, models, destinations, Reverse ETL pipelines, audiences, syncs, and other resources. New workspaces are created through their parent organization (see Organizations API), and every workspace belongs to one.

A workspace has no membership of its own. People reach it because a group they belong to holds a role on it, so there is no invitation to send, no member role to change and no member to remove here — all three live on the organization. The two reads below are what this surface offers: who reaches the workspace, and which groups grant that.

Endpoints

MethodPathDescription
GET/api/v1/workspacesList workspaces
GET/api/v1/workspaces/{id}Get a workspace
DELETE/api/v1/workspaces/{id}Delete a workspace
GET/api/v1/workspaces/{id}/membersWho reaches this workspace, and the grants that let them
GET/api/v1/workspaces/{id}/groupsWhich of the organization’s groups reach it, and with what role
GET/api/v1/workspaces/{id}/settingsGet workspace settings
PUT/api/v1/workspaces/{id}/settingsUpdate workspace settings

List Workspaces

GET /api/v1/workspaces

Returns all workspaces the authenticated user is a member of. This endpoint does not require the X-Workspace-ID header.

Response

[ { "id": "550e8400-e29b-41d4-a716-446655440000", "name": "Production", "slug": "production", "avatar_url": "", "settings": {}, "organization_id": "660e8400-e29b-41d4-a716-446655440000", "member_count": 12, "created_at": "2024-01-01T00:00:00Z", "updated_at": "2024-01-15T09:30:00Z" }, { "id": "770e8400-e29b-41d4-a716-446655440000", "name": "Staging", "slug": "staging", "avatar_url": "", "settings": {}, "organization_id": "660e8400-e29b-41d4-a716-446655440000", "member_count": 5, "created_at": "2024-01-05T00:00:00Z", "updated_at": "2024-01-10T09:30:00Z" } ]

Example

curl -X GET https://agentic.zeotap.com/api/v1/workspaces \ -H "Authorization: Bearer <token>"

Create Workspace

Workspaces are created under an organization. See POST /api/v1/organizations/{orgId}/workspaces in the Organizations API.


Get Workspace

GET /api/v1/workspaces/{id}

Returns a single workspace by ID. The authenticated user must be a member of the workspace.

Example

curl -X GET https://agentic.zeotap.com/api/v1/workspaces/{id} \ -H "Authorization: Bearer <token>" \ -H "X-Workspace-ID: <workspace-id>"

Update Workspace

Use the Workspace Settings endpoint (PUT /api/v1/workspaces/{id}/settings) to update workspace name, avatar, default role, and other configuration.


Delete Workspace

DELETE /api/v1/workspaces/{id}

Deletes a workspace and all of its resources. Requires owner role. This action is irreversible.

Response

{ "status": "deleted" }

List Members

GET /api/v1/workspaces/{id}/members

Returns everyone who can act in this workspace. The list is derived from the grants that reach them, so each row carries the group and role behind it rather than a role of its own — which is what lets it answer why somebody has access.

Response

[ { "account_id": "660e8400-e29b-41d4-a716-446655440000", "email": "alice@example.com", "name": "Alice Smith", "avatar_url": "https://...", "grants": [ { "group_id": "8b2c5d19-4e60-4a73-b8f2-1c9d0e6a5432", "group_name": "Organization admins", "system_key": "org_admins", "role_id": "00000000-0000-0000-0000-000000000002", "role_name": "admin", "scope": "organization" } ] }, { "account_id": "770e8400-e29b-41d4-a716-446655440000", "email": "bob@example.com", "name": "Bob Jones", "avatar_url": "https://...", "grants": [ { "group_id": "7c1f4e2a-9b3d-4f18-a0c6-2d5e8b1f9034", "group_name": "EMEA Marketing", "system_key": "", "role_id": "00000000-0000-0000-0000-000000000003", "role_name": "member", "scope": "workspace" } ] } ]

scope is "workspace" for a grant naming this workspace and "organization" for a wildcard one, which reaches every workspace in the organization and so cannot be revoked from here. Somebody in two groups that both reach this workspace has two entries, and their permissions are the union.

A role_id of null is a real state: the group is attached to the workspace and grants no permissions, which keeps its access policies here meaningful.

Example

curl -X GET https://agentic.zeotap.com/api/v1/workspaces/{id}/members \ -H "Authorization: Bearer <token>" \ -H "X-Workspace-ID: <workspace-id>"

List the Groups Reaching This Workspace

GET /api/v1/workspaces/{id}/groups

The workspace-side read behind the Settings → Groups tab: which of the organization’s groups hold a role here.

Response

{ "assignments": [ { "id": "1a2b3c4d-5e6f-4071-8293-a4b5c6d7e8f9", "group_id": "7c1f4e2a-9b3d-4f18-a0c6-2d5e8b1f9034", "group_name": "EMEA Marketing", "group_system_key": "", "workspace_id": "550e8400-e29b-41d4-a716-446655440000", "role_id": "00000000-0000-0000-0000-000000000003" }, { "id": "9f8e7d6c-5b4a-4938-2716-0f1e2d3c4b5a", "group_id": "8b2c5d19-4e60-4a73-b8f2-1c9d0e6a5432", "group_name": "Organization admins", "group_system_key": "org_admins", "role_id": "00000000-0000-0000-0000-000000000002" } ] }

An assignment with no workspace_id is a wildcard: it reaches every workspace in the organization, so it appears here without naming this one.

Granting and Revoking

There is no write on this surface. A grant is made and revoked on the organization:

PUT /api/v1/organizations/{orgId}/groups/{groupId}/workspaces/{workspaceId} DELETE /api/v1/organizations/{orgId}/groups/{groupId}/workspaces/{workspaceId}

See the Organizations API for both, and Managing Members for the flow around them.


Workspace Settings

Get Settings

GET /api/v1/workspaces/{id}/settings

Returns workspace-level configuration settings.

Update Settings

PUT /api/v1/workspaces/{id}/settings

Updates workspace settings. Requires owner or admin role.


Workspace Object

FieldTypeDescription
idstring (UUID)Unique identifier
namestringDisplay name
slugstringURL-safe identifier
avatar_urlstringAvatar image URL
settingsobjectWorkspace-level settings
organization_idstring (UUID)Parent organization. Never null — every workspace belongs to one, because a group is the only thing that grants access and a group lives on an organization
member_countintegerNumber of workspace members
created_atstring (ISO 8601)Creation timestamp
updated_atstring (ISO 8601)Last update timestamp

Workspace Member Object

FieldTypeDescription
workspace_idstring (UUID)Workspace ID
account_idstring (UUID)Account ID
rolestringRole name
role_idstring (UUID) or nullCustom role ID
emailstringMember email
namestringMember display name
avatar_urlstringMember avatar URL
created_atstring (ISO 8601)When the member was added
Last updated on