Team access & resource scopes
Two surfaces — pick the one matching the token you have:
- Partner API (pk_) — new since 2026-05-28. Manage your own team (you are the channel owner). Members + tasks. See Partner API endpoints below.
- Session-auth — dashboard / OAuth user token. Full surface (invitations with email tokens, chat, delegated workspaces, granular scope rules). See /api/teams below.
Partner API (pk_-authenticated, your own team)
Owner-scoped to the API key holder — channel id is implicit (= the key owner). On first read the team row is auto-created.
# Read your team
curl -s -H "Authorization: Bearer pk_YOUR_KEY_HERE" https://api.dcast.pro/api/v1/team
# → 200 { data: { id, channelId, name, memberCount, ... } }
# Rename
curl -s -X PATCH -H "Authorization: Bearer pk_YOUR_KEY_HERE" \
-H "Content-Type: application/json" \
-d '{"name":"My Production Crew"}' https://api.dcast.pro/api/v1/team
# Invite an existing DCAST user by email — invitee MUST exist on the platform
# (Partner API blocks cold-email invites; use session-auth /api/teams/:id/invite
# for token-based invites to non-users).
curl -s -X POST -H "Authorization: Bearer pk_YOUR_KEY_HERE" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"email":"[email protected]",
"role":"CONTENT_MANAGER",
"permissions":{
"canManageContent":true,
"canViewAnalytics":true
}
}' https://api.dcast.pro/api/v1/team/members
# → 201 | 404 INVITEE_NOT_FOUND | 409 ALREADY_MEMBER | 409 CANNOT_INVITE_SELFAdding, changing and removing members needs an owner-class credential: a key with finance:write (a FULL_ACCESS key without a narrowing permission list has it) or the account owner's X-User-Token; otherwise 403 TEAM_OWNER_REQUIRED.
Allowed roles via Partner API: CONTENT_MANAGER, STREAM_TECHNICIAN, MODERATOR, VIEWER. OWNER is singleton (you) and ADMIN is intentionally not assignable via Partner API per our no-admin canon — use session-auth + the staff tool for those.
| Method | Partner API path | Notes |
|---|---|---|
| GET | https://api.dcast.pro/api/v1/team | auto-creates on first read |
| PATCH | https://api.dcast.pro/api/v1/team | rename |
| GET | https://api.dcast.pro/api/v1/team/members | list with user{} include |
| POST | https://api.dcast.pro/api/v1/team/members | invite existing user; body { email, role, permissions{} } |
| PATCH | https://api.dcast.pro/api/v1/team/members/{memberId} | change role / permissions |
| DELETE | https://api.dcast.pro/api/v1/team/members/{memberId} | remove |
| GET | https://api.dcast.pro/api/v1/team/tasks | ?status filter |
| POST | https://api.dcast.pro/api/v1/team/tasks | required: title; optional priority, assignedTo, tags, dueDate |
| PATCH | https://api.dcast.pro/api/v1/team/tasks/{taskId} | status transitions TODO/IN_PROGRESS/COMPLETED/CANCELLED; completedAt auto-set on COMPLETED |
| DELETE | https://api.dcast.pro/api/v1/team/tasks/{taskId} | remove |
| Team chat (channel-scoped) | ||
| GET | https://api.dcast.pro/api/v1/team/chat | list (?limit, ?before=<ISO> cursor) |
| POST | https://api.dcast.pro/api/v1/team/chat | send. Body: { message, attachments? }. Mirrored to Socket.IO room team:chat:{channelId} so cabinet sees it real-time. |
| PATCH | https://api.dcast.pro/api/v1/team/chat/{messageId} | edit own (403 NOT_AUTHOR if not yours; 409 MESSAGE_DELETED on tombstone) |
| DELETE | https://api.dcast.pro/api/v1/team/chat/{messageId} | soft-delete own (message becomes [deleted]; row retained) |
Session-auth (/api/teams — dashboard token)
The full surface below is exposed under /api/teams on the same API host as the Partner surface. Authentication is different from Partner API v1: use a user session access token (OAuth / dashboard sign-in), not the Partner API key used for https://api.dcast.pro/api/v1.
Base path
https://api.dcast.pro/api/teams/:channelId/...channelId is the channel owner identifier (the same id used in dashboard URLs).
Auth headers
Authorization: Bearer {user_access_token}For browser and server calls that act on behalf of another channel (delegated workspace — team member managing an owner's channel), send the owner's channel id:
X-Effective-Channel-Id: {channel_owner_id}Same header is used across dashboard session APIs (streams, videos, creator stats where allowed, etc.). CORS on the API allows this header. When you call /api/teams/:channelId/..., the channelId in the path must match the channel you are accessing (usually the owner's id). The JWT is always the signed-in user; the header selects which channel context applies when the user is a team member.
Delegated workspace (memberships)
List channels where the current user is an ACTIVE team member (for workspace switcher and automation):
GET https://api.dcast.pro/api/teams/memberships/mine
Authorization: Bearer {user_access_token}Pending invitations: GET /api/teams/invitations/mine, accept/decline via POST /api/teams/invitations/mine/:memberId/accept and .../decline.
Team chat (channel-scoped)
One message thread per channel team. Only ACTIVE team members (or the channel owner) can read and post. Messages are stored server-side; real-time updates are delivered to the dashboard via WebSocket on the channel-scoped room team:chat:{channelId}.
| Method | Path | Notes |
|---|---|---|
| GET | https://api.dcast.pro/api/teams/:channelId/chat | List messages (limit, offset, before) |
| POST | https://api.dcast.pro/api/teams/:channelId/chat | Body: { "message": "..." }, optional attachments |
| PUT | https://api.dcast.pro/api/teams/:channelId/chat/:messageId | Edit own message |
| DELETE | https://api.dcast.pro/api/teams/:channelId/chat/:messageId | Soft-delete own message |
| GET | https://api.dcast.pro/api/teams/:channelId/chat/search | Query q (required) |
Dashboard UI: opening Team Chat as a delegated user uses the same channelId as the owner. Deep link /dashboard/team/chat?channel={ownerId} selects the workspace when the user has a membership for that channel. Acceptance notifications for invites point to this chat URL.
Team tasks
Kanban-style tasks for the channel team: GET/POST https://api.dcast.pro/api/teams/:channelId/tasks, PUT/DELETE .../tasks/:taskId, assign and status transitions under .../assign and .../status. Same auth and channelId rules as chat.
Resource scope model
Each member can have per-domain mode and optional allowlists. When mode is UNRESTRICTED, role permissions apply to all content of that type on the channel. When mode is ALLOWLIST, access is limited to listed resources.
| Field | Type | Meaning |
|---|---|---|
videoScopeMode | UNRESTRICTED | ALLOWLIST | VOD / library videos |
streamScopeMode | UNRESTRICTED | ALLOWLIST | Live streams |
restreamScopeMode | UNRESTRICTED | ALLOWLIST | Restream pipelines |
roomScopeMode | UNRESTRICTED | ALLOWLIST | Real-time video rooms (moderation) |
resourceGrants | array | Entries { "domain": "VIDEO"|"STREAM"|"ROOM"|"RESTREAM", "resourceId": "<id>" }. Required for each domain set to ALLOWLIST (at least one id per restricted domain). |
Member object (response)
Members returned by the API include the fields above plus role, status, permission flags, and nested user.
Endpoints
| Method | Path | Notes |
|---|---|---|
| GET | https://api.dcast.pro/api/teams/:channelId/members | List members (team member) |
| POST | https://api.dcast.pro/api/teams/:channelId/invite | Body: email, role, optional customMessage, optional scope fields (same as PUT member). |
| PUT | https://api.dcast.pro/api/teams/:channelId/members/:memberId | Update role, permissions, and/or scope fields. |
| GET | https://api.dcast.pro/api/teams/:channelId/selectable-resources | Catalog for UI / automation: videos, streams, restreams, rooms available for allowlists. Requires canManageTeam. |
| GET | https://api.dcast.pro/api/teams/:channelId/accessible-resources | Resources the current member can access under scope rules (team member). |
| GET | https://api.dcast.pro/api/teams/:channelId/permissions | Current member's permission flags for the channel. |
| GET | https://api.dcast.pro/api/teams/:channelId | Team metadata (owner, members). |
| DELETE | https://api.dcast.pro/api/teams/:channelId/members/:memberId | Remove member (requires canManageTeam). |
Invite with scopes (example)
POST https://api.dcast.pro/api/teams/{channelId}/invite
Authorization: Bearer {user_access_token}
Content-Type: application/json
{
"email": "[email protected]",
"role": "STREAM_TECHNICIAN",
"customMessage": "Optional",
"videoScopeMode": "UNRESTRICTED",
"streamScopeMode": "ALLOWLIST",
"roomScopeMode": "UNRESTRICTED",
"restreamScopeMode": "ALLOWLIST",
"resourceGrants": [
{ "domain": "STREAM", "resourceId": "stream_cuid_1" },
{ "domain": "RESTREAM", "resourceId": "restream_cuid_2" }
]
}Update member scopes (example)
PUT https://api.dcast.pro/api/teams/{channelId}/members/{memberId}
Authorization: Bearer {user_access_token}
Content-Type: application/json
{
"streamScopeMode": "ALLOWLIST",
"resourceGrants": [
{ "domain": "STREAM", "resourceId": "stream_cuid_1" }
]
}Related
- Partner API v1 (API key): Quickstart, Streams, Restreams, Rooms.
- Authentication — obtain user tokens for dashboard-integrated tools.
