The organization, user, role, permission and API-credential control plane behind SIMBA Build. Creates and manages organisations, domains, invites, org-scoped and custom system roles, bulk user imports, device apps and registrations, notification templates, passkeys and TOTP two-factor enrolment, and the client_id / client_secret pairs the SIMBA SDKs authenticate with. OpenAPI 3.1.0, 106 operations across 74 paths, served publicly (unauthenticated spec, OAuth2-protected operations) from SIMBA's own hosted Blocks instance.
SIMBA Blocks Member Service API is one of 4 APIs that SIMBA Chain publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Identity, Organization, User, Roles, and Permissions. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.
This API exposes
106 operations
across 74 paths,
organized into 16 resource areas,
and defines 95 schemas.
It is described by OpenAPI 3.1.0, at version 2.10.1.
Requests are made against the base URL https://blocks.simbachain.com/api/member-service.
106 operations74 paths95 schemas11 DELETE46 GET1 PATCH27 POST21 PUT
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.1.0
API Version
2.10.1
Base URL
https://blocks.simbachain.com/api/member-service
Authentication
OAuth 2.0
Resource Areas
16
Authentication & Security 1
SIMBA Blocks Member Service API declares
1 security scheme
for authenticating requests.
It supports OAuth 2.0 (OAuth2AuthorizationCodeBearer) using the authorizationCode flow.
Paths & Operations 106
Across 74 paths, the API surfaces 106 operations — 11 DELETE, 46 GET, 1 PATCH, 27 POST, 21 PUT. They span 16 resource areas, including ClientCredentials, Organisations, Domains, Events, Permissions, Roles, Templates, Users, and 8 more. Each is listed below with its method, path, parameters, and response codes.
The contract defines 95 schemas that model the data the API accepts and returns. The most detailed are DeviceAppRegistration (22 properties), UserAccount (15 properties), Role (13 properties), ClientCredential (13 properties). Each schema is shown below with its type and property counts.
Only time the plain secret is provided, at it's creation
4 properties3 required
GenericConfigurationRequest
object
4 properties1 required
HTTPValidationError
object
1 property
IdentityPermissionItem
object
7 properties7 required
Invite
object
11 properties7 required
InviteInfo
object
3 properties3 required
InviteStatus
string
Inviter
object
4 properties4 required
OrgScopedUserAccount
object
A model representing a organisation user account. The field email is unique.
9 properties2 required
Organisation
object
A model representing an organisation. The field name is unique.
7 properties3 required
OrganisationMinimal
object
2 properties2 required
OrganisationName
object
1 property1 required
OrganisationWithDefaultRoles
object
8 properties3 required
OrganisationWithRoles
object
8 properties4 required
Page_BulkUsersImportRequest_
object
5 properties5 required
Page_ClientCredential_
object
5 properties5 required
Page_DeviceAppRegistration_
object
5 properties5 required
Page_DeviceApp_
object
5 properties5 required
Page_Domain_
object
5 properties5 required
Page_Invite_
object
5 properties5 required
Page_OrgScopedUserAccount_
object
5 properties5 required
Page_Organisation_
object
5 properties5 required
Page_Permission_
object
5 properties5 required
Page_RoleWithFlags_
object
5 properties5 required
Page_RoleWithoutPermissions_
object
5 properties5 required
Page_Template_
object
5 properties5 required
Page_UserAccountSummary_
object
5 properties5 required
PasskeyRegisterVerifyRequest
object
POST /register/verify body — the attestation JSON from @simplewebauthn/browser startRegistration plus the user-chosen nickname.
2 properties2 required
PasskeyRenameRequest
object
1 property1 required
PasskeyResponse
object
SPA listing / registration-result shape. Metadata only — the credential public key + raw credential id bytes never cross the HTTP boundary (audit events follow…
7 properties4 required
Permission
object
A model representing a permission.
12 properties8 required
PingResponse
object
3 properties2 required
PingResponses
object
2 properties2 required
RedactedGenericConfiguration
object
3 properties
RemoveDomainOrganisationInput
object
1 property1 required
RepublishEventChoices
string
RepublishEventsInput
object
1 property1 required
Role
object
A model representing a role.
13 properties6 required
RoleMinimal
object
4 properties1 required
RoleNamesInput
object
1 property
RoleWithFlags
object
11 properties5 required
RoleWithoutPermissions
object
7 properties1 required
ServiceConfigurations
object
7 properties
SubInvite
object
7 properties6 required
SystemTypes
string
Template
object
A model representing a template. The field name is unique.
6 properties2 required
TotpCodeRequest
object
Body shape for every code-gated endpoint.
1 property1 required
TotpRecoveryCodesResponse
object
Body for endpoints that return plaintext recovery codes (one-shot generation + re-display).
1 property1 required
TotpSetupResponse
object
GET /account/security/2fa/setup payload.
3 properties3 required
TotpStatusResponse
object
GET /account/security/2fa payload. enabled is true when totpenabledat IS NOT NULL. haspendingenrolment lets the SPA show "you have an in-flight enrolment" with…
3 properties3 required
UpdateClientCredentialInput
object
1 property1 required
UpdateCustomRoleInput
object
4 properties
UpdateDeviceAppRegistrationInput
object
1 property
UpdateDomainInput
object
3 properties
UpdateIdentityRolesInput
object
2 properties
UpdateOrganisationInput
object
3 properties
UpdateTemplateInput
object
3 properties2 required
UpdateUserAccountInput
object
2 properties
UpdateUserProfileInput
object
2 properties2 required
UserAccount
object
15 properties2 required
UserAccountSummary
object
A model representing a organisation user account. The field email is unique.
7 properties1 required
UserInputBase
object
3 properties3 required
UserMoniker
object
4 properties1 required
UserProfile
object
A model representing a user profile.
6 properties3 required
ValidationError
object
5 properties3 required
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of SIMBA Blocks Member Service API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.