> ## Documentation Index
> Fetch the complete documentation index at: https://docs.twine.se/llms.txt
> Use this file to discover all available pages before exploring further.

# Get organizations

> Get a list of organizations accessible to the authenticated role. Supports cursor-based pagination.




## OpenAPI

````yaml https://api.twine.se/spec/openapi.json get /v1/org
openapi: 3.0.3
info:
  contact:
    email: help@twine.se
    name: Twine Support
  description: >+
    # Introduction

    Welcome to the Twine Public API reference. This API allows you to read data
    from Twine's system, and to write data back for supported domains. See the
    Pushing data section below for what can be written.


    # Versioning

    The API is versioned. The current version is v1.1, served under the `/v1`
    path. As the API is subject to change, new versions may be released. Always
    refer to the latest documentation to ensure you're using the correct
    version.


    ## Dated model attributes

    In v1.1, every entity field is tracked by change date. This allows you to
    fetch data as it existed at a specific point in time, or retrieve all
    changes from a specific point in time up to the present. You can also supply
    a shape to the API to get data in a format that suits your needs.


    ### Dated values


    In the v1.1 model, all fields are represented by an array of values with an
    optional valid_from timestamp. A null value for valid_from indicates that
    the field value is valid from the beginning of time, meaning it has no
    recorded history in the system. When multiple values exist in the array,
    they are sorted in descending order with the most recent value first. The
    last value may or may not have a null timestamp. An array can never contain
    more than one value with a null timestamp.


    # Authentication

    The Twine public API uses Bearer token authentication. The token should be
    sent in the `Authorization` header with the value `Bearer <token>`.


    ## Provisioning a token

    To provision a token, you must first generate a long-lived refresh token
    using Twine backoffice. This token can then be used to generate short-lived
    access tokens. The refresh token should be kept secret and never shared.

    Follow these steps to obtain an access token:


    1. Invoke `/provisioning/refresh-token/begin` using the JTI you received
    when provisioning the refresh token.

    2. The response will contain a `salt` value

    3. Concatenate the salt with the refresh token, separated by a colon (`:`)

    4. Hash the concatenated string using SHA256, e.g. `sha256
    "<salt>:<refresh_token>"`

    5. The hash should be in lower case

    6. Invoke `/provisioning/refresh-token/refresh` with the JTI (as `jti`) and
    the hash (as `signature`) in the body

    7. The response will contain an access token


    ## Legacy tokens

    Legacy tokens are still supported. These tokens are long-lived and can be
    used to authenticate against the API. However, we recommend using the new
    token provisioning system.


    ## Token expiration

    Provisioned tokens are short-lived. Decode them to find the expiry time.
    Legacy tokens have longer expiry times.


    # Filtering

    Some endpoints allow filtering on certain fields. Not all fields are
    filterable, and filter operations may vary between fields. Refer to specific
    endpoints to discover what is possible. All filters follow the same
    structure:


    ```bash

    GET
    /v1/org/employees?filters[updated_at][value]=2022-01-01T00:00:00Z&filters[updated_at][op]=gt

    ```


    # Ordering

    Some endpoints allow ordering on certain fields. Not all fields are
    orderable. Refer to specific endpoints to discover what is possible. All
    ordering follows the same structure:


    ```bash

    GET /v1/org/employees?order[field]=updated_at&order[direction]=desc

    ```


    # Data reliability

    A given piece of data is a snapshot of the latest data fetched from the
    Vendor. In some cases the data returned by Twine will be out of sync with
    the Vendor.

    This is due to the nature of the integration and the data provided by the
    Vendor. Twine will always strive to provide the most accurate data possible.

    Depending on the Customer, the data may be updated in near real-time, or
    with a longer delay.


    # Permissions

    All API requests are subject to a permissions check. Permissions are
    configured by Twine staff or an approved external admin.


    # Rate limiting

    The API is not currently rate limited. However, you should expect this to
    change in the near future. At that time you will start receiving 429 Too
    Many Requests responses. More information will be provided here when rate
    limiting is implemented.


    ## Fetching single resources

    When requesting single resources with inadequate permissions, you will
    receive a 403 Forbidden in response.


    ## Fetching lists of resources

    When requesting a list of resources, the API will filter out resources you
    do not have access to. This means that the

    response may contain fewer resources than requested. The API will always
    return a 200 OK response, even if the list is empty.


    # Pushing data

    NOTE: The API currently only supports the `employee` domain for writing
    data.


    There are multiple considerations to take into account when writing data to
    the API.


    * In order to write data, the role being used must have the `create` and/or
    `update` permissions for the `employee` domain.

    * As per the RESTful API design specs, the `POST` method is used to create
    new resources, while the `PUT` method is used to update existing resources,
    and the `PATCH` method is used to partially update existing resources.

    * Even though `PATCH` will not touch unspecified dated properties, it will
    still replace all entries of targeted dated properties with the new values
    provided in the request body. This means that if you want to keep existing
    historical values for a given dated property, you must include them in the
    request body. This behaviour can be changed in the future given enough
    demand.

    * If there are incoming domain mappings for the `employee` domain, you
    should avoid updating any properties that are mapped in those integrations.
    Otherwise there will be uncertainty about which integration is responsible
    for the data.

    * If there is a configured `twine` integration with outgoing domain mappings
    for the `employee` domain, a replication job will be created to push the
    changes to the configured integration. If you want to avoid this, create a
    condition in the target integration.


    # Nomenclature


    Throughout the API, we use the following terms:


    | Term        | Description |

    |-------------|-------------|

    | Customer    | The entity on whose behalf Twine processes personnel data |

    | Vendor      | Third party supplier of data with which Twine integrates on
    behalf of Customer |


    # FAQ


    ### Do you have a sandbox environment?

    Yes. Please contact Twine support to get access.


    ### Are there webhooks?

    Not yet, but it is on the roadmap.


    ### How can I keep the response body small?

    Use the `select` parameter to only fetch the fields you need. This will
    reduce the response size and speed up the request. Combine this

    with filtering by `updated_at` to only fetch the data that has changed since
    your last request.

  title: |
    Twine Public API
  version: |
    v1.2
  x-logo:
    altText: Twine Logo
    backgroundColor: '#00000000'
    url: >-
      https://images.squarespace-cdn.com/content/v1/63cec8699b6d396be083ed8b/a2746b2d-2582-49f0-93bb-99a8765c5450/LogoTwineHorizontal.png?format=12w
servers:
  - description: Twine Public Production API
    url: https://api.twine.se
    variables: {}
  - description: Twine Public Staging API
    url: https://api-stage.twine.se
    variables: {}
security:
  - BearerAuth: []
tags:
  - description: >+
      # Fetching

      Employees can be retrieved in paginated lists, or one by one. The employee
      object remains the same in both cases.


      # Data consistency

      Twine allows Customers to map their data to their own wishes. In some
      cases, fields might not contain what you expect.

      Fields like `first_name` and `private_id_number` are more or less
      guaranteed to contain what you expect. However, fields like `phone1`,
      `phone2`

      might mean different things depending on the Customer. Some Customers will
      want to store an employee's private phone number in `phone1`,

      while others will store the work phone number instead. Always refer to the
      Customer's data mapping (upcoming API endpoint) to understand what the
      fields contain.

    name: Employees
  - description: >
      # Fetching

      Organizational units can be retrieved in paginated lists, or one by one.
      The organizational unit object remains the same in both cases.


      # Data consistency

      Twine will attempt to normalize the source system's organizational unit
      tier. If successful, the `tier` field will contain the normalized tier and
      be of type [OrganizationalUnitTier](#model/organizationalunittier)
    name: Organizational Units
  - description: >+
      # Fetching

      Time reports can be retrieved in paginated lists.


      # Time types

      Twine allows Customers to map their time types to their own wishes. In
      some cases, time types might not contain what you expect.

    name: Time Reports
paths:
  /v1/org:
    get:
      tags:
        - Organizations
      summary: Get organizations
      description: >
        Get a list of organizations accessible to the authenticated role.
        Supports cursor-based pagination.
      operationId: getOrganizations
      parameters:
        - description: ''
          in: query
          name: pagination
          required: false
          schema:
            description: Cursor pagination
            properties:
              after:
                description: >-
                  Cursor to start after. Is returned in the response. Must be
                  specified together with `first`. Leave undefined to start at
                  the beginning
                nullable: true
                type: string
              before:
                description: >-
                  Cursor to start before. Is returned in the response. Must be
                  specified together with `last`. Leave undefined to start at
                  the end
                nullable: true
                type: string
              first:
                description: >-
                  Number of subsequent items to return. Must be specified
                  together with `after`. Will be capped at 100, unless otherwise
                  specified
                nullable: true
                type: integer
              last:
                description: >-
                  Number of previous items to return. Must be specified together
                  with `before`. Will be capped at 100, unless otherwise
                  specified
                nullable: true
                type: integer
            title: CursorPagination
            type: object
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationListResponse'
          description: Organization list Response
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
          description: Forbidden Response
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalServerError'
          description: Internal Error Response
      callbacks: {}
components:
  schemas:
    OrganizationListResponse:
      description: >-
        A response object with paginated list of organizations, including
        pagination data
      properties:
        data:
          items:
            description: >-
              An object representing an organization in Twine. Please note that
              the primary key for organizations is `org_id`, not `id`.
            properties:
              custom_properties:
                items:
                  $ref: '#/components/schemas/CustomProperty'
                nullable: true
                type: array
              delete_protection:
                description: If true, the organization cannot be deleted
                example: true
                nullable: true
                type: boolean
              delete_protection_disabled_at:
                description: >-
                  The time delete protection was disabled, if it was previously
                  enabled and consequently disabled. Otherwise null.
                example: '2021-06-01T12:00:00Z'
                format: date-time
                nullable: true
                type: string
              name:
                description: The organization's name
                example: AcmeCorp Inc.
                nullable: false
                type: string
              org_id:
                description: The organization's UUID
                example: 018eae56-8f9d-7ca0-bea3-17f3db6cf75b
                format: uuid
                nullable: false
                type: string
              owner_id:
                description: The organization's owner UUID. The owner will be `User` object
                example: 018eae56-8f9d-7ca0-bea3-17f3db6cf75b
                format: uuid
                nullable: true
                type: string
              parent_id:
                description: The organization's parent UUID
                example: 018eae56-8f9d-7ca0-bea3-17f3db6cf75b
                format: uuid
                nullable: true
                type: string
              roles:
                items:
                  $ref: '#/components/schemas/Role'
                nullable: true
                type: array
              vat:
                description: The organization's VAT number
                example: 018eae56-8f9d-7ca0-bea3-17f3db6cf75b
                nullable: true
                type: string
            required:
              - org_id
            title: Organization
            type: object
          type: array
        pagination:
          $ref: '#/components/schemas/CursorPaginationResult'
      required:
        - data
        - pagination
      title: OrganizationListResponse
      type: object
    ForbiddenError:
      description: Forbidden error
      properties:
        code:
          example: 403
          type: integer
        errors:
          default: []
          items:
            description: Singular error
            properties:
              domain:
                type: string
              message:
                type: string
              reason:
                type: string
            required:
              - domain
              - reason
              - message
            title: InnerError
            type: object
          type: array
        message:
          example: Forbidden
          type: string
      required:
        - code
        - message
        - errors
      title: ForbiddenError
      type: object
    InternalServerError:
      description: Internal server error
      properties:
        code:
          example: 500
          type: integer
        errors:
          default: []
          items:
            description: Singular error
            properties:
              domain:
                type: string
              message:
                type: string
              reason:
                type: string
            required:
              - domain
              - reason
              - message
            title: InnerError
            type: object
          type: array
        message:
          example: Internal Server Error
          type: string
      required:
        - code
        - message
        - errors
      title: InternalServerError
      type: object
    CustomProperty:
      description: A custom property associated with an organization
      properties:
        description:
          description: An optional description of the custom property
          example: The size of the employee's shoes
          nullable: true
          type: string
        domain:
          $ref: '#/components/schemas/Domain'
        id:
          description: The organization's UUID
          example: 018eae56-8f9d-7ca0-bea3-17f3db6cf75b
          format: uuid
          nullable: false
          type: string
        list:
          description: Whether the custom property is a list
          example: false
          nullable: true
          type: boolean
        property:
          description: >-
            The name of the custom property. Should be unique within the
            organization and ideally either snake_case or camelCase.
          example: shoe_size
          nullable: false
          type: string
        reference_domain:
          $ref: '#/components/schemas/Domain'
        type:
          $ref: '#/components/schemas/PropertyType'
      required:
        - id
        - domain
        - property
        - type
      title: CustomProperty
      type: object
    Role:
      description: A role schema
      properties:
        id:
          description: Unique identifier for the role
          example: 018eae56-8f9d-7ca0-bea3-17f3db6cf75b
          format: uuid
          type: string
        name:
          description: Name of the role
          example: Admin Role
          type: string
        tokens:
          description: List of role tokens
          items:
            $ref: '#/components/schemas/RoleToken'
          type: array
      required:
        - id
        - name
        - tokens
      title: Role
      type: object
    CursorPaginationResult:
      description: Cursor pagination result
      properties:
        end_cursor:
          description: Cursor to start after to retrieve the next page
          nullable: true
          type: string
        has_next_page:
          description: If true, there are additional items available after the current page
          type: boolean
        has_previous_page:
          description: >-
            If true, there are additional items available before the current
            page
          type: boolean
        start_cursor:
          description: Cursor to start before to retrieve the previous page
          nullable: true
          type: string
      title: CursorPaginationResult
      type: object
    Domain:
      description: The reference domain
      enum:
        - finance
        - employee_competence
        - competence
        - expense_transaction
        - salary_transaction
        - file_transfer
        - project
        - org_unit
        - customer
        - schedule
        - time_report
        - employee
      example: employee
      nullable: true
      title: Domain
      type: string
    PropertyType:
      description: PropertyType
      enum:
        - enum
        - time
        - datetime
        - date
        - boolean
        - float
        - integer
        - number
        - string
      title: PropertyType
      type: string
    RoleToken:
      description: An object representing a role token
      properties:
        exp:
          description: The expiry for the token in Unix seconds
          example: 1672531199
          type: integer
        jti:
          description: The unique identifier for the token
          type: string
        jwt:
          description: The secret token
          example: s3cr3t-t0k3n
          type: string
        typ:
          description: The type of the token
          enum:
            - access
            - refresh
          type: string
      required:
        - jwt
        - typ
        - exp
        - jti
      title: RoleToken
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: Bearer token for authentication
      scheme: bearer
      type: http

````