> ## Documentation Index
> Fetch the complete documentation index at: https://api-docs.useopenwrench.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Provision a buyer user

> Creates a buyer contact (and optionally a login) and sends an invite email. Roles are required and may not include admin or super-admin roles (403). The target facility defaults to the API key's facility; a supplied facilityId must belong to the same buyer company (403 otherwise). 400 with conflictException when an account or contact already exists for the email. If password is supplied a login is created immediately (invite email says "invited you to OpenWrench"); otherwise the invite asks the user to sign up. Admin roles force hasAccessToAllLocations=true and clear locationIds/brandIds.



## OpenAPI

````yaml /openapi/buyer.json post /v1/buyer/user/provision
openapi: 3.1.0
info:
  title: OpenWrench Buyer API
  version: 1.0.0
  description: >-
    External REST API for OpenWrench buyers (facilities-management side).
    Generated from the application source (Play routes, controllers and models).


    ## Authentication

    Every request must carry a buyer API key in the `X-API-KEY` header. The key
    resolves to a buyer contact, and all reads/writes are tenant-scoped to that
    contact's buyer company (plus, on several endpoints, role-based
    location/brand restrictions). Endpoints under `/v1/buyer/super_admin/...`
    (and a few others noted per-operation) additionally require the key's
    contact to be a buyer super admin.


    ## Rate limiting

    10 requests per 20-second window per API key; requests beyond that receive
    **429**. A handful of operations noted per-operation bypass the rate
    limiter.


    ## Response envelope

    Single-entity responses: `{ "type": "<EntityName>", "data": { ... },
    "status": "ok" }`.

    List responses: `{ "type": "<EntityName>", "data": [ ... ], "count":
    <total>, "status": "ok" }`.

    count_by responses: `{ "type": "CountBy", "data": <integer>, "status": "ok"
    }`.

    Errors: `{ "message": "...", "type": "<ExceptionType>", "status": "error",
    "traceId": "..." }` — 401 missing/invalid key, 400 bad input, 404 not found,
    429 rate limit.


    ## Pagination & filtering

    List endpoints accept `offset`, `limit` (default 10, max 25 — the locations
    list clamps to 10), `sort_by` and `order` (asc|desc). Every other query
    parameter is treated as a filter and matched against the entity's indexed
    columns (multi-value filters are comma-separated strings); these are
    combined with the tenant-security filters derived from the API key.


    Timestamps are ISO 8601 strings unless noted otherwise.


    ## Date formats

    Date-time fields serialize as strings in one of two shapes depending on the
    underlying type: ISO 8601 with offset (e.g. `2026-08-14T13:05:22.000-07:00`)
    for most timestamps, or `yyyy-MM-dd HH:mm:ss.S` (space-separated, no offset)
    for database timestamp fields. Plain dates are `yyyy-MM-dd`. When sending
    date-times, ISO 8601 is accepted.


    ## Required headers

    Every request must carry BOTH `X-API-KEY` (your API key) and `OW-KEY` (the
    OpenWrench shared secret issued with it). Requests missing either return
    401.
servers:
  - url: https://api.useopenwrench.com/api/external
security:
  - ApiKeyAuth: []
    OwKeyAuth: []
tags:
  - name: Ping
  - name: Me
  - name: Locations
  - name: Regions
  - name: Asset Types
  - name: Asset Meters
  - name: Assets
  - name: Asset Labels
    description: Read the asset label catalog and replace the labels applied to an asset.
  - name: Asset Models
  - name: Work Orders
  - name: Work Order Notes
  - name: Work Order Labels
    description: >-
      Read your work order label catalog and replace the labels applied to a
      work order.
  - name: Service Calls
  - name: Site Survey Walkthroughs
  - name: Invoices
  - name: Proposals
  - name: Files
  - name: Planned Maintenance
  - name: Currency Exchange
  - name: Supplier Network
  - name: User Provisioning
paths:
  /v1/buyer/user/provision:
    post:
      tags:
        - User Provisioning
      summary: Provision a buyer user
      description: >-
        Creates a buyer contact (and optionally a login) and sends an invite
        email. Roles are required and may not include admin or super-admin roles
        (403). The target facility defaults to the API key's facility; a
        supplied facilityId must belong to the same buyer company (403
        otherwise). 400 with conflictException when an account or contact
        already exists for the email. If password is supplied a login is created
        immediately (invite email says "invited you to OpenWrench"); otherwise
        the invite asks the user to sign up. Admin roles force
        hasAccessToAllLocations=true and clear locationIds/brandIds.
      operationId: provisionUser
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                email:
                  type: string
                nameGiven:
                  type: string
                nameFamily:
                  type: string
                roles:
                  type: array
                  items:
                    type: string
                    description: >-
                      Role names (case-insensitive); admin/super-admin roles are
                      rejected.
                facilityId:
                  type:
                    - integer
                    - 'null'
                  description: >-
                    Target buyer facility; defaults to the API key's facility.
                    Must be in the same buyer company.
                title:
                  type:
                    - string
                    - 'null'
                department:
                  type:
                    - string
                    - 'null'
                isSharedContact:
                  type:
                    - boolean
                    - 'null'
                readOnlyAccess:
                  type:
                    - boolean
                    - 'null'
                hasAccessToAllLocations:
                  type:
                    - boolean
                    - 'null'
                locationIds:
                  type:
                    - array
                    - 'null'
                  items:
                    type: integer
                brandIds:
                  type:
                    - array
                    - 'null'
                  items:
                    type: integer
                password:
                  type:
                    - string
                    - 'null'
                  description: >-
                    If supplied, a login is created immediately with this
                    password.
                passwordResetRequired:
                  type:
                    - boolean
                    - 'null'
                epaCertificationType:
                  type:
                    - string
                    - 'null'
                  description: >-
                    EPA 608 certification class; validated against the
                    recognised classes — an unrecognised value is rejected with
                    400.
                epaCertificationNumber:
                  type:
                    - string
                    - 'null'
                  maxLength: 64
                  description: EPA 608 certificate number (free-form, max 64 characters).
              required:
                - email
                - nameGiven
                - nameFamily
                - roles
              additionalProperties: true
      responses:
        '200':
          description: The created contact (type marker "BuyerContact").
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContactResponse'
        '400':
          description: >-
            Bad input, parse failure, or the API key's contact could not be
            resolved.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid X-API-KEY.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            Admin/super-admin role requested, or facility outside the API key's
            buyer company.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded (10 requests per 20-second window per key).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ContactResponse:
      type: object
      properties:
        type:
          type: string
          description: Entity type marker, e.g. "BuyerContact".
        data:
          $ref: '#/components/schemas/Contact'
        status:
          type: string
          enum:
            - ok
      required:
        - type
        - data
        - status
    Error:
      type: object
      properties:
        message:
          type: string
        type:
          type: string
          description: >-
            Exception type, e.g. unauthorizedException, NotFoundException,
            BadRequestException, ParseException, InvalidInputDataException,
            ConflictException, UnexpectedException.
        status:
          type: string
          enum:
            - error
        traceId:
          type: string
          description: >-
            Trace id (a random 11-char alphanumeric string when no explicit
            trace applies).
      required:
        - message
        - type
        - status
        - traceId
      description: >-
        Standard error envelope. 401 = missing/invalid API key, 400 = bad input,
        404 = not found, 429 = rate limit exceeded.
    Contact:
      type: object
      properties:
        email:
          type: string
        nameGiven:
          type: string
        nameFamily:
          type: string
        title:
          type:
            - string
            - 'null'
        department:
          type:
            - string
            - 'null'
        facilityId:
          type:
            - integer
            - 'null'
        contactType:
          type: string
          description: '"buyer" or "supplier".'
        isSharedContact:
          type: boolean
        readOnlyAccess:
          type:
            - boolean
            - 'null'
        invitedByEmail:
          type:
            - string
            - 'null'
        invitedAt:
          type:
            - string
            - 'null'
          format: date-time
        invitedByName:
          type:
            - string
            - 'null'
        epaCertificationType:
          type:
            - string
            - 'null'
        epaCertificationNumber:
          type:
            - string
            - 'null'
        createdAt:
          type:
            - string
            - 'null'
          format: date-time
        updatedAt:
          type:
            - string
            - 'null'
          format: date-time
      required:
        - email
        - nameGiven
        - nameFamily
        - contactType
      additionalProperties: true
      description: >-
        Contact record. Abridged: only fields observed in the provided sources
        are listed.
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-KEY
    OwKeyAuth:
      type: apiKey
      in: header
      name: OW-KEY
      description: >-
        OpenWrench shared secret. Required on every request alongside X-API-KEY;
        issued together with your API key.

````