List team members
The site's team members and their roles.
https://webbuddy.radioworkflow.com/api/v1/membersmembers:readEveryone with access to the site, oldest membership first — so the founding owner leads the list.
Pending invitations are NOT included: someone who has been invited but has not accepted has no membership yet and does not appear here.
Authentication
| Header | Required | Value |
|---|---|---|
| Authorization | Required | Bearer wb_live_your_key_here The site API key as a bearer token: Bearer wb_live_…. It is the only credential — there are no cookies, no session and no CSRF token in this API. |
The key must also carry the members:readscope. Scopes are ticked when a key is created on the site's API tab and cannot be added afterwards — a key without this one answers insufficient_scope to this endpoint however many times it is retried, so the fix is a new key. What each scope unlocks.
Parameters
This endpoint takes no query parameters and no request body.
Request
curl 'https://webbuddy.radioworkflow.com/api/v1/members' \ -H "Authorization: Bearer wb_live_your_key_here"
Try it
This form calls /api/v1/members from your browser, straight to the API, on this same origin. The key you paste below is put into an Authorization header on that one request — it is not sent to the documentation, not written to storage on this device, and not kept once you close the tab.
It is a real request against a real key: it counts against the same limit as any other call — 120 per minute per key — and it appears in your site's API log like anything else you send.
A live key for the site, carrying the members:read scope.
GET /api/v1/members Authorization: Bearer wb_live_your_key_here
The placeholder above is what the docs print. Your key is never shown back to you here, in the preview or in the response.
Response
application/jsonA JSON array — the fields below describe one element.| Field | Type | Description |
|---|---|---|
| name | string | The member's display name. |
| string | The address they sign in with, and the identifier an invite was sent to. | |
| role | enum | owner can manage billing, domains, keys and the team; editor can edit content and toggle add-ons. A site always has at least one owner.ownereditorValues come from SiteRole in src/lib/sites.ts (server-only — restated here). |
Ordered oldest membership first. Members only — pending invites are not listed.
[
{ "name": "Jordan Rivers", "email": "jordan@example.com", "role": "owner" },
{ "name": "Sam Lee", "email": "sam@example.com", "role": "editor" }
]Every response also carries the headers listed under what every response carries.
Errors
| HTTP | code | Retry? | What to do |
|---|---|---|---|
| 401 | unauthorized | Do not | Check the header is exactly Authorization: Bearer wb_live_…. If it is, the key was probably revoked — mint a new one on the site's API tab. Do not retry: nothing about this request will succeed on a second attempt. |
| 403 | insufficient_scope | Do not | Mint a new key on the site's API tab with the required scope ticked, then revoke the old one. Do not retry: the same key answers 403 forever. The message names the scope that was missing. |
| 429 | rate_limited | Retry | Back off and retry — the window is at most 60 seconds long, so an exponential backoff starting around a second will clear it. If you hit this steadily, cache the responses you poll rather than raising your request rate. If the message mentions failed authentications, fix the key first: retrying the same bad token is what filled that bucket. |
| 500 | internal_error | Retry | Retry once after a short delay. If it persists for a given endpoint, it is a bug on our side rather than something your request can fix; report it with the endpoint and the time. |
What each code means, and the envelope they arrive in, are on the errors page.