curl --request POST \
--url https://api.useopenwrench.com/api/external/v1/buyer/user/provision \
--header 'Content-Type: application/json' \
--header 'OW-KEY: <api-key>' \
--header 'X-API-KEY: <api-key>' \
--data '
{
"email": "<string>",
"nameGiven": "<string>",
"nameFamily": "<string>",
"roles": [
"<string>"
],
"facilityId": 123,
"title": "<string>",
"department": "<string>",
"isSharedContact": true,
"readOnlyAccess": true,
"hasAccessToAllLocations": true,
"locationIds": [
123
],
"brandIds": [
123
],
"password": "<string>",
"passwordResetRequired": true,
"epaCertificationType": "<string>",
"epaCertificationNumber": "<string>"
}
'import requests
url = "https://api.useopenwrench.com/api/external/v1/buyer/user/provision"
payload = {
"email": "<string>",
"nameGiven": "<string>",
"nameFamily": "<string>",
"roles": ["<string>"],
"facilityId": 123,
"title": "<string>",
"department": "<string>",
"isSharedContact": True,
"readOnlyAccess": True,
"hasAccessToAllLocations": True,
"locationIds": [123],
"brandIds": [123],
"password": "<string>",
"passwordResetRequired": True,
"epaCertificationType": "<string>",
"epaCertificationNumber": "<string>"
}
headers = {
"X-API-KEY": "<api-key>",
"OW-KEY": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-API-KEY': '<api-key>',
'OW-KEY': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
email: '<string>',
nameGiven: '<string>',
nameFamily: '<string>',
roles: ['<string>'],
facilityId: 123,
title: '<string>',
department: '<string>',
isSharedContact: true,
readOnlyAccess: true,
hasAccessToAllLocations: true,
locationIds: [123],
brandIds: [123],
password: '<string>',
passwordResetRequired: true,
epaCertificationType: '<string>',
epaCertificationNumber: '<string>'
})
};
fetch('https://api.useopenwrench.com/api/external/v1/buyer/user/provision', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.useopenwrench.com/api/external/v1/buyer/user/provision",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => '<string>',
'nameGiven' => '<string>',
'nameFamily' => '<string>',
'roles' => [
'<string>'
],
'facilityId' => 123,
'title' => '<string>',
'department' => '<string>',
'isSharedContact' => true,
'readOnlyAccess' => true,
'hasAccessToAllLocations' => true,
'locationIds' => [
123
],
'brandIds' => [
123
],
'password' => '<string>',
'passwordResetRequired' => true,
'epaCertificationType' => '<string>',
'epaCertificationNumber' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"OW-KEY: <api-key>",
"X-API-KEY: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.useopenwrench.com/api/external/v1/buyer/user/provision"
payload := strings.NewReader("{\n \"email\": \"<string>\",\n \"nameGiven\": \"<string>\",\n \"nameFamily\": \"<string>\",\n \"roles\": [\n \"<string>\"\n ],\n \"facilityId\": 123,\n \"title\": \"<string>\",\n \"department\": \"<string>\",\n \"isSharedContact\": true,\n \"readOnlyAccess\": true,\n \"hasAccessToAllLocations\": true,\n \"locationIds\": [\n 123\n ],\n \"brandIds\": [\n 123\n ],\n \"password\": \"<string>\",\n \"passwordResetRequired\": true,\n \"epaCertificationType\": \"<string>\",\n \"epaCertificationNumber\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("OW-KEY", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.useopenwrench.com/api/external/v1/buyer/user/provision")
.header("X-API-KEY", "<api-key>")
.header("OW-KEY", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"email\": \"<string>\",\n \"nameGiven\": \"<string>\",\n \"nameFamily\": \"<string>\",\n \"roles\": [\n \"<string>\"\n ],\n \"facilityId\": 123,\n \"title\": \"<string>\",\n \"department\": \"<string>\",\n \"isSharedContact\": true,\n \"readOnlyAccess\": true,\n \"hasAccessToAllLocations\": true,\n \"locationIds\": [\n 123\n ],\n \"brandIds\": [\n 123\n ],\n \"password\": \"<string>\",\n \"passwordResetRequired\": true,\n \"epaCertificationType\": \"<string>\",\n \"epaCertificationNumber\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.useopenwrench.com/api/external/v1/buyer/user/provision")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-KEY"] = '<api-key>'
request["OW-KEY"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"email\": \"<string>\",\n \"nameGiven\": \"<string>\",\n \"nameFamily\": \"<string>\",\n \"roles\": [\n \"<string>\"\n ],\n \"facilityId\": 123,\n \"title\": \"<string>\",\n \"department\": \"<string>\",\n \"isSharedContact\": true,\n \"readOnlyAccess\": true,\n \"hasAccessToAllLocations\": true,\n \"locationIds\": [\n 123\n ],\n \"brandIds\": [\n 123\n ],\n \"password\": \"<string>\",\n \"passwordResetRequired\": true,\n \"epaCertificationType\": \"<string>\",\n \"epaCertificationNumber\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"type": "<string>",
"data": {
"email": "<string>",
"nameGiven": "<string>",
"nameFamily": "<string>",
"contactType": "<string>",
"title": "<string>",
"department": "<string>",
"facilityId": 123,
"isSharedContact": true,
"readOnlyAccess": true,
"invitedByEmail": "<string>",
"invitedAt": "2023-11-07T05:31:56Z",
"invitedByName": "<string>",
"epaCertificationType": "<string>",
"epaCertificationNumber": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
},
"status": "ok"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}Provision a buyer user
Creates a buyer contact (and optionally a login) and sends an invite email. Roles are required and may not include admin or super-admin roles (403). The target facility defaults to the API key’s facility; a supplied facilityId must belong to the same buyer company (403 otherwise). 400 with conflictException when an account or contact already exists for the email. If password is supplied a login is created immediately (invite email says “invited you to OpenWrench”); otherwise the invite asks the user to sign up. Admin roles force hasAccessToAllLocations=true and clear locationIds/brandIds.
curl --request POST \
--url https://api.useopenwrench.com/api/external/v1/buyer/user/provision \
--header 'Content-Type: application/json' \
--header 'OW-KEY: <api-key>' \
--header 'X-API-KEY: <api-key>' \
--data '
{
"email": "<string>",
"nameGiven": "<string>",
"nameFamily": "<string>",
"roles": [
"<string>"
],
"facilityId": 123,
"title": "<string>",
"department": "<string>",
"isSharedContact": true,
"readOnlyAccess": true,
"hasAccessToAllLocations": true,
"locationIds": [
123
],
"brandIds": [
123
],
"password": "<string>",
"passwordResetRequired": true,
"epaCertificationType": "<string>",
"epaCertificationNumber": "<string>"
}
'import requests
url = "https://api.useopenwrench.com/api/external/v1/buyer/user/provision"
payload = {
"email": "<string>",
"nameGiven": "<string>",
"nameFamily": "<string>",
"roles": ["<string>"],
"facilityId": 123,
"title": "<string>",
"department": "<string>",
"isSharedContact": True,
"readOnlyAccess": True,
"hasAccessToAllLocations": True,
"locationIds": [123],
"brandIds": [123],
"password": "<string>",
"passwordResetRequired": True,
"epaCertificationType": "<string>",
"epaCertificationNumber": "<string>"
}
headers = {
"X-API-KEY": "<api-key>",
"OW-KEY": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-API-KEY': '<api-key>',
'OW-KEY': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
email: '<string>',
nameGiven: '<string>',
nameFamily: '<string>',
roles: ['<string>'],
facilityId: 123,
title: '<string>',
department: '<string>',
isSharedContact: true,
readOnlyAccess: true,
hasAccessToAllLocations: true,
locationIds: [123],
brandIds: [123],
password: '<string>',
passwordResetRequired: true,
epaCertificationType: '<string>',
epaCertificationNumber: '<string>'
})
};
fetch('https://api.useopenwrench.com/api/external/v1/buyer/user/provision', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.useopenwrench.com/api/external/v1/buyer/user/provision",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'email' => '<string>',
'nameGiven' => '<string>',
'nameFamily' => '<string>',
'roles' => [
'<string>'
],
'facilityId' => 123,
'title' => '<string>',
'department' => '<string>',
'isSharedContact' => true,
'readOnlyAccess' => true,
'hasAccessToAllLocations' => true,
'locationIds' => [
123
],
'brandIds' => [
123
],
'password' => '<string>',
'passwordResetRequired' => true,
'epaCertificationType' => '<string>',
'epaCertificationNumber' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"OW-KEY: <api-key>",
"X-API-KEY: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.useopenwrench.com/api/external/v1/buyer/user/provision"
payload := strings.NewReader("{\n \"email\": \"<string>\",\n \"nameGiven\": \"<string>\",\n \"nameFamily\": \"<string>\",\n \"roles\": [\n \"<string>\"\n ],\n \"facilityId\": 123,\n \"title\": \"<string>\",\n \"department\": \"<string>\",\n \"isSharedContact\": true,\n \"readOnlyAccess\": true,\n \"hasAccessToAllLocations\": true,\n \"locationIds\": [\n 123\n ],\n \"brandIds\": [\n 123\n ],\n \"password\": \"<string>\",\n \"passwordResetRequired\": true,\n \"epaCertificationType\": \"<string>\",\n \"epaCertificationNumber\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-KEY", "<api-key>")
req.Header.Add("OW-KEY", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.useopenwrench.com/api/external/v1/buyer/user/provision")
.header("X-API-KEY", "<api-key>")
.header("OW-KEY", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"email\": \"<string>\",\n \"nameGiven\": \"<string>\",\n \"nameFamily\": \"<string>\",\n \"roles\": [\n \"<string>\"\n ],\n \"facilityId\": 123,\n \"title\": \"<string>\",\n \"department\": \"<string>\",\n \"isSharedContact\": true,\n \"readOnlyAccess\": true,\n \"hasAccessToAllLocations\": true,\n \"locationIds\": [\n 123\n ],\n \"brandIds\": [\n 123\n ],\n \"password\": \"<string>\",\n \"passwordResetRequired\": true,\n \"epaCertificationType\": \"<string>\",\n \"epaCertificationNumber\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.useopenwrench.com/api/external/v1/buyer/user/provision")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-KEY"] = '<api-key>'
request["OW-KEY"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"email\": \"<string>\",\n \"nameGiven\": \"<string>\",\n \"nameFamily\": \"<string>\",\n \"roles\": [\n \"<string>\"\n ],\n \"facilityId\": 123,\n \"title\": \"<string>\",\n \"department\": \"<string>\",\n \"isSharedContact\": true,\n \"readOnlyAccess\": true,\n \"hasAccessToAllLocations\": true,\n \"locationIds\": [\n 123\n ],\n \"brandIds\": [\n 123\n ],\n \"password\": \"<string>\",\n \"passwordResetRequired\": true,\n \"epaCertificationType\": \"<string>\",\n \"epaCertificationNumber\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"type": "<string>",
"data": {
"email": "<string>",
"nameGiven": "<string>",
"nameFamily": "<string>",
"contactType": "<string>",
"title": "<string>",
"department": "<string>",
"facilityId": 123,
"isSharedContact": true,
"readOnlyAccess": true,
"invitedByEmail": "<string>",
"invitedAt": "2023-11-07T05:31:56Z",
"invitedByName": "<string>",
"epaCertificationType": "<string>",
"epaCertificationNumber": "<string>",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z"
},
"status": "ok"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}{
"message": "<string>",
"type": "<string>",
"status": "error",
"traceId": "<string>"
}Authorizations
OpenWrench shared secret. Required on every request alongside X-API-KEY; issued together with your API key.
Body
Role names (case-insensitive); admin/super-admin roles are rejected.
Target buyer facility; defaults to the API key's facility. Must be in the same buyer company.
If supplied, a login is created immediately with this password.
EPA 608 certification class; validated against the recognised classes — an unrecognised value is rejected with 400.
EPA 608 certificate number (free-form, max 64 characters).
64