Changelog
2026-08-07
Documentation audit — organization, workspace, and a new teams page
Reconciled Organizations and Workspaces against the current code and added a new Teams page, all with updated OpenAPI specs. A lot landed since the last pass:
Org creation & hosting
- Org creation now takes hosting_type (cloud/on_prem) and a required company_code; on_prem orgs skip app-access and admin-user creation entirely and get a license key back instead. company_code/hosting_type/license keys are owned by AuthAPI, not stored locally — CoreAPI just proxies them through.
- Added a platform-admin org list endpoint and an org status (approve/disable) endpoint.
Self-signup
- New public self-signup flow: an applicant verifies their email (6-digit code), then applies — no Zitadel org or local admin user is created until a platform admin approves. Approval generates a temporary password, creates the admin, creates the org's Default workspace, and emails the admin their login details.
Roles & permissions
- PATCH .../users/:userId/role now accepts custom org-scoped roles, not just the five system roles.
- Custom roles can now be updated and deleted (previously create/list only), and a role's current members can be listed.
- Platform-scope roles are no longer returned by the org-scoped role endpoints.
- Added a live permissions-catalog endpoint listing every permission string by scope, so client code doesn't need to hand-maintain its own copy.
- Permission names are now consistently namespaced (e.g. org:users:manage, platform:org:create) — several endpoints' required permission changed name (not behavior) as part of this.
Default workspace
- Every org now gets a Default workspace auto-created — right after admin-user creation for direct org creation, or on approval for a self-signup org. Not skippable; documented in Workspaces.
Teams (new) - Org-scoped teams that can be granted a role on a workspace as a unit, instead of adding every member individually. Full CRUD for teams, team membership, and team-to-workspace role grants, with write-time checks preventing a user from having both direct and team-based access to the same workspace. See the new Teams page.
Corrections
- The JWT role claim documentation was stale — AuthAPI moved from an orgs[] array to a single org: {org_id, org_slug, role} object a while ago; the internal role-lookup endpoint doc now reflects that (and notes it only supports one org per user, LIMIT 1, no org_id filter).
2026-07-22
Added Organizations and Workspaces pages — tenant creation, membership, roles, app access, spaces/channels — with their own OpenAPI specs; updated the domain overview to distinguish the legacy ticketing general settings from the platform org/workspace hierarchy
2026-06-23
Initial tenancy domain documentation