A valid request URL is required to generate request examples{
"id": "user-camille",
"name": "Camille Vendeur",
"email": "camille.vendeur@rivoli-retail.fr",
"role": "cashier",
"store": "Boutique Pilote",
"active": true
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123,
"fieldErrors": [
{
"field": "<string>",
"message": "<string>"
}
]
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}Provision a team member
Adds one staff account to the directory. This PROVISIONS a person who can sign in, so only call it on an explicit instruction naming the individual — never to ‘fill in’ a directory. Unlike the customer and product creates, id is REQUIRED and chosen by YOU: nothing is minted server-side. Pick a stable, human-meaningful id (the directory uses user-<firstname>) and check it first with getTeamMember — an id that already exists is a 409 CONFLICT, never an overwrite, so a duplicate is safe but wasted. email must be a valid address (it is the account’s contact), role is a free-text label with no enforced vocabulary (match the labels the directory already uses — a typo silently creates a new role facet), and store is a display label for the store or network the account is scoped to. active defaults to true: the account may sign in the moment this returns. There is NO delete endpoint — the only way back is updateTeamMember with active: false.
A valid request URL is required to generate request examples{
"id": "user-camille",
"name": "Camille Vendeur",
"email": "camille.vendeur@rivoli-retail.fr",
"role": "cashier",
"store": "Boutique Pilote",
"active": true
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123,
"fieldErrors": [
{
"field": "<string>",
"message": "<string>"
}
]
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}{
"error": {
"code": "VALIDATION_FAILED",
"message": "<string>",
"statusCode": 123
}
}Authorizations
Authorization: Bearer <token>. Accepts EITHER a Keycloak access token (scopes-in-token) OR an opaque POS session token; both resolve to the same pos.* scope vocabulary the route guards enforce.
Body
11^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$11Response
The provisioned account, echoed back exactly as stored.
The provisioned account, echoed back exactly as stored.
11^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$11
