# Team API


The team API lets you manage users, departments, locations, and cards.


Version: 1.0

## Servers

Production
```
https://api.brex.com
```

Staging (Note: This is not a sandbox. It will not work with customer tokens.)
```
https://api-staging.brex.com
```

## Security

### OAuth2

OAuth2 security scheme

Type: oauth2

## Download OpenAPI description

[Team API](https://developer.brex.com/_bundle/openapi/team_api.yaml)

## Users

Endpoints for user management.

### List users

 - [GET /v2/users](https://developer.brex.com/openapi/team_api/users/listusers.md): This endpoint lists all users.

Results can be narrowed with the filter query parameters below. Values within a single
filter are OR-ed, and separate filters are AND-ed together.

Filters that accept multiple values take them either as a comma-separated list or as a repeated
parameter: ?status[]=ACTIVE,INVITED and ?status[]=ACTIVE&status[]=INVITED are equivalent.

The legacy singular email and remote_display_id parameters perform an exact lookup that returns
at most one user, and cannot be combined with the filters above.

### Invite user

 - [POST /v2/users](https://developer.brex.com/openapi/team_api/users/createuser.md): This endpoint invites a new user as an employee.
To update user's role, check out this article.

### Create user

 - [POST /v2/users/create](https://developer.brex.com/openapi/team_api/users/adduser.md): This endpoint creates a new user as an employee without inviting them, leaving the user INACTIVE.
Use it to load your team into Brex ahead of time; invite them later with
Invite user, on the Dashboard, or by using auto-invite rules.

The user is assigned to legal_entity_id when provided, and to your account's default legal entity otherwise.

### Get current user

 - [GET /v2/users/me](https://developer.brex.com/openapi/team_api/users/getme.md): This endpoint returns the user associated with the OAuth2 access token.

### Get user

 - [GET /v2/users/{id}](https://developer.brex.com/openapi/team_api/users/getuserbyid.md): This endpoint gets a user by ID.

### Update user

 - [PUT /v2/users/{id}](https://developer.brex.com/openapi/team_api/users/updateuser.md): This endpoint updates a user. Any parameters not provided will be left unchanged.

## Locations

Endpoints for location management.

### List locations

 - [GET /v2/locations](https://developer.brex.com/openapi/team_api/locations/listlocations.md): This endpoint lists all locations.

### Create location

 - [POST /v2/locations](https://developer.brex.com/openapi/team_api/locations/createlocation.md): This endpoint creates a new location.

### Get location

 - [GET /v2/locations/{id}](https://developer.brex.com/openapi/team_api/locations/getlocationbyid.md): This endpoint gets a location by ID.

### Update location

 - [PUT /v2/locations/{id}](https://developer.brex.com/openapi/team_api/locations/updatelocation.md): This endpoint updates a location by ID. Only the fields present in the request body are changed.

### Delete location

 - [DELETE /v2/locations/{id}](https://developer.brex.com/openapi/team_api/locations/deletelocation.md): This endpoint deletes a location by ID. A location cannot be deleted while users are still assigned to it or while it is used as a filter on an active group.

## Departments

Endpoints for department management.

### List departments

 - [GET /v2/departments](https://developer.brex.com/openapi/team_api/departments/listdepartments.md): This endpoint lists all departments.

### Create department

 - [POST /v2/departments](https://developer.brex.com/openapi/team_api/departments/createdepartment.md): This endpoint creates a new department

### Get department

 - [GET /v2/departments/{id}](https://developer.brex.com/openapi/team_api/departments/getdepartmentbyid.md): This endpoint gets a department by ID.

### Update department

 - [PUT /v2/departments/{id}](https://developer.brex.com/openapi/team_api/departments/updatedepartment.md): This endpoint updates a department by ID. Only the fields present in the request body are changed.

### Delete department

 - [DELETE /v2/departments/{id}](https://developer.brex.com/openapi/team_api/departments/deletedepartment.md): This endpoint deletes a department by ID. A department cannot be deleted while users are still assigned to it or while it is used as a filter on an active group.

## Titles

Endpoints for title management.

### List titles

 - [GET /v2/titles](https://developer.brex.com/openapi/team_api/titles/listtitles.md): This endpoint lists all titles.

### Create title

 - [POST /v2/titles](https://developer.brex.com/openapi/team_api/titles/createtitle.md): This endpoint creates a new title

### Get title

 - [GET /v2/titles/{id}](https://developer.brex.com/openapi/team_api/titles/gettitlebyid.md): This endpoint gets a title by ID.

### Update title

 - [PUT /v2/titles/{id}](https://developer.brex.com/openapi/team_api/titles/updatetitle.md): This endpoint updates a title by ID. Only the fields present in the request body are changed. The request must contain at least one field to update.

### Delete title

 - [DELETE /v2/titles/{id}](https://developer.brex.com/openapi/team_api/titles/deletetitle.md): This endpoint deletes a title by ID. A title cannot be deleted while users are still assigned to it or while it is used as a filter on an active group.

## Cost Centers

Endpoints for cost center management.

### List cost centers

 - [GET /v2/cost_centers](https://developer.brex.com/openapi/team_api/cost-centers/listcostcenters.md): This endpoint lists all cost centers.

### Get cost center

 - [GET /v2/cost_centers/{id}](https://developer.brex.com/openapi/team_api/cost-centers/getcostcenterbyid.md): This endpoint gets a cost center by ID.

## Cards

Endpoints for card management.

### List cards

 - [GET /v2/cards](https://developer.brex.com/openapi/team_api/cards/listcardsbyuserid.md): Lists all cards by a user_id.
Only cards with limit_type = CARD have spend_controls

### Create card

 - [POST /v2/cards](https://developer.brex.com/openapi/team_api/cards/createcard.md): Creates a new card.
The spend_controls field is required when limit_type = CARD.
The mailing_address field is required for physical cards and is the shipping address used to send the card; it is not the same as the billing and mailing address used for online purchases.
The first 2 lines of this address must be under 60 characters long. Each user can only have up to 10 active physical cards.
For Empower accounts, this endpoint requires budget management. If your account does not have access to budget management features, a 403 response status will be returned. 
If this is the case and you want to gain access to this endpoint, please contact Brex support.

### Get card

 - [GET /v2/cards/{id}](https://developer.brex.com/openapi/team_api/cards/getcardbyid.md): Retrieves a card by ID. Only cards with limit_type = CARD have spend_controls

### Update card

 - [PUT /v2/cards/{id}](https://developer.brex.com/openapi/team_api/cards/updatecard.md): Update an existing vendor card

### Lock card

 - [POST /v2/cards/{id}/lock](https://developer.brex.com/openapi/team_api/cards/lockcard.md): Locks an existing, unlocked card. And the card owner will receive a notification about it.

### Get card number

 - [GET /v2/cards/{id}/pan](https://developer.brex.com/openapi/team_api/cards/getcardnumber.md): Retrieves card number, CVV, and expiration date of a card by ID.

### Create secure email to send card number

 - [POST /v2/cards/{id}/secure_email](https://developer.brex.com/openapi/team_api/cards/emailcardnumber.md): Creates a secure email to send card number, CVV, and expiration date of a card by ID to the specified email.

This endpoint is currently gated. If you would like to request access, please reach out to
developer-support@brex.com

### Terminate card

 - [POST /v2/cards/{id}/terminate](https://developer.brex.com/openapi/team_api/cards/terminatecard.md): Terminates an existing card. The card owner will receive a notification about it.

### Unlock card

 - [POST /v2/cards/{id}/unlock](https://developer.brex.com/openapi/team_api/cards/unlockcard.md): Unlocks an existing card.

## Legal Entities

Endpoints for legal entities.

### List legal entities

 - [GET /v2/legal_entities](https://developer.brex.com/openapi/team_api/legal-entities/listlegalentities.md): List legal entities for the account.

### Get legal entity

 - [GET /v2/legal_entities/{id}](https://developer.brex.com/openapi/team_api/legal-entities/getlegalentity.md): Get a legal entity by its ID.

## Companies

### Get company

 - [GET /v2/company](https://developer.brex.com/openapi/team_api/companies/getcompany.md): This endpoint returns the company associated with the OAuth2 access token.

