# Organization API: Org Staff Push

> Every Organization API operation tagged Org Staff Push.

Source: https://www.coritan.com/docs/api/reference/organizations/org-staff-push/

Base URL: `https://api.coritan.com/api/v1`. Paths below are complete.

To try these requests in the browser, open the [interactive Organization API reference](https://api.coritan.com/docs/org).

## Operations

| Method | Path | Summary |
| --- | --- | --- |
| GET | [`/api/v1/orgs/{org_slug}/staff/push/config`](#op-get-api-v1-orgs-org-slug-staff-push-config) | Staff push config |
| GET | [`/api/v1/orgs/{org_slug}/staff/push/preferences`](#op-get-api-v1-orgs-org-slug-staff-push-preferences) | Staff push preferences |
| PUT | [`/api/v1/orgs/{org_slug}/staff/push/preferences`](#op-put-api-v1-orgs-org-slug-staff-push-preferences) | Staff push set preferences |
| GET | [`/api/v1/orgs/{org_slug}/staff/push/subscriptions`](#op-get-api-v1-orgs-org-slug-staff-push-subscriptions) | Staff push devices |
| POST | [`/api/v1/orgs/{org_slug}/staff/push/subscriptions`](#op-post-api-v1-orgs-org-slug-staff-push-subscriptions) | Save the calling member's browser for notifications |
| DELETE | [`/api/v1/orgs/{org_slug}/staff/push/subscriptions/{subscription_id}`](#op-delete-api-v1-orgs-org-slug-staff-push-subscriptions-subscription-id) | Stop sending notifications to one of the calling member's devices |
| POST | [`/api/v1/orgs/{org_slug}/staff/push/test`](#op-post-api-v1-orgs-org-slug-staff-push-test) | Send "Test notification" to every device of the calling member, whatever their kinds say |

### Staff push config {#op-get-api-v1-orgs-org-slug-staff-push-config}

`GET /api/v1/orgs/{org_slug}/staff/push/config`

What a browser needs to ask for notifications: whether this brand can
send them, and the public key the browser subscribes with. `supported` is
false when the brand's console has no notification service worker, and then
`public_key` is null.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Staff push preferences {#op-get-api-v1-orgs-org-slug-staff-push-preferences}

`GET /api/v1/orgs/{org_slug}/staff/push/preferences`

Which kinds of event the calling member is told of: `kind`, `label`,
`enabled`, `allowed` and `reason`. A kind the member's role cannot read has
`allowed` false, `enabled` false and, in `reason`, the role it needs, such
as "Needs Tier 3 support or higher". A kind the member never chose is on or
off as its default says.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Staff push set preferences {#op-put-api-v1-orgs-org-slug-staff-push-preferences}

`PUT /api/v1/orgs/{org_slug}/staff/push/preferences`

Turn kinds of event on or off for the calling member, and answer with
the same list as the read. An unknown kind answers 422 naming the kinds
there are. Turning on a kind the member's role cannot read answers 403 with
the role it needs; turning one off is always allowed.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Request body

`application/json` (required)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `kinds` | Kinds | yes | Kind to on (true) or off (false). A kind left out keeps its setting. |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Staff push devices {#op-get-api-v1-orgs-org-slug-staff-push-subscriptions}

`GET /api/v1/orgs/{org_slug}/staff/push/subscriptions`

The calling member's own devices, oldest first: `id`, `label` (such as
"Safari on iPhone"), `created_at` and `last_sent_at`.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Save the calling member's browser for notifications {#op-post-api-v1-orgs-org-slug-staff-push-subscriptions}

`POST /api/v1/orgs/{org_slug}/staff/push/subscriptions`

Save the calling member's browser for notifications. The address must be
a browser's own push service over https; anything else answers 422. Sending
the same browser again updates its keys and answers 200 with the same
device, and a member keeps at most 10 devices, the oldest dropping first.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Request body

`application/json` (required)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `endpoint` | string | yes | The push service address the browser gave the subscription |
| `p256dh` | string | yes | The browser's public key for this subscription, base64url |
| `auth` | string | yes | The browser's 16-byte secret for this subscription, base64url |
| `user_agent` | string or null | no | The browser's user agent; read from the request when left out |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Stop sending notifications to one of the calling member's devices {#op-delete-api-v1-orgs-org-slug-staff-push-subscriptions-subscription-id}

`DELETE /api/v1/orgs/{org_slug}/staff/push/subscriptions/{subscription_id}`

Stop sending notifications to one of the calling member's devices.
Another member's device answers 404.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `subscription_id` | path | integer | yes |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Send "Test notification" to every device of the calling member, whatever their kinds say {#op-post-api-v1-orgs-org-slug-staff-push-test}

`POST /api/v1/orgs/{org_slug}/staff/push/test`

Send "Test notification" to every device of the calling member, whatever
their kinds say. Answers `devices` (how many the member has) and `sent` (how
many a push service accepted). Answers 409 when the member has no device, and
429 after 10 tests in an hour.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |
