Skip to main content
A Sub) is a subdivision of your PrimeVault organization that groups the users and resources belonging to a customer or business unit. It lets you manage access to each group separately while keeping everything under one parent organizationA SubOrg (sub-org-Org is a subdivision of your PrimeVault organization that groups the users and resources belonging to a customer or business unit. It lets you manage access to each group separately while keeping everything under one parent organizationA Sub-Org is a subdivision of your PrimeVault organization that groups the users and resources belonging to a customer or business unit. It lets you manage access to each group separately while keeping everything under one parent organization. Create and list sub-orgs within the authenticated API user’s organization. The external API currently exposes collection creation and listing only.

Access and permissions

Requests must use an active API user with the ADMIN or OWNER role. The organization and acting user are derived from authentication; caller-supplied organization or user identifiers cannot change the scope.

Create a SubOrg

List SubOrgs

Data models

Both SDKs provide CreateSubOrgRequest, SubOrg, SubOrgListResponse, and SubOrgControlMode.

CreateSubOrgRequest

Contains one required field: name: string. It has no controlMode field.

SubOrg

string (UUID)
SubOrg identifier.
string (UUID)
Owning organization.
string
SubOrg name.
SubOrgControlMode | null
Read-only metadata. New SubOrgs created here return MANAGED.
string (date-time)
Creation timestamp.
string (date-time)
Last update timestamp.
boolean
Deletion flag. Listed rows are not deleted.
The response does not expose type, status, or parentSubOrgId. Python response attributes keep the same camelCase field names as the JSON response.

SubOrgListResponse

SubOrg[]
SubOrgs on the current page.
string | null
Cursor for the next page, or null at the end.
boolean
Whether another page is available.

SubOrgControlMode

The response enum contains MANAGED and INDEPENDENT; existing data can also return null. These are response values, not creation options. This API always creates with MANAGED and rejects caller-supplied control mode.

SDK method reference

Both list methods accept optional name filters in params, a limit that defaults to 20, and a cursor. JavaScript methods return promises. Python methods return dataclass instances; controlMode is parsed as SubOrgControlMode when non-null.

Errors and supported operations

Only GET and POST on /api/external/sub_orgs/ are available. There are no external retrieve-by-ID, update, delete, or embedded-user actions in this section’s API. Create and list sub-orgs within the authenticated API user’s organization. The external API currently exposes collection creation and listing only.

Access and permissions

Requests must use an active API user with the ADMIN or OWNER role. The organization and acting user are derived from authentication; caller-supplied organization or user identifiers cannot change the scope.

Create a SubOrg

List SubOrgs

Data models

Both SDKs provide CreateSubOrgRequest, SubOrg, SubOrgListResponse, and SubOrgControlMode.

CreateSubOrgRequest

Contains one required field: name: string. It has no controlMode field.

SubOrg

string (UUID)
SubOrg identifier.
string (UUID)
Owning organization.
string
SubOrg name.
SubOrgControlMode | null
Read-only metadata. New SubOrgs created here return MANAGED.
string (date-time)
Creation timestamp.
string (date-time)
Last update timestamp.
boolean
Deletion flag. Listed rows are not deleted.
The response does not expose type, status, or parentSubOrgId. Python response attributes keep the same camelCase field names as the JSON response.

SubOrgListResponse

SubOrg[]
SubOrgs on the current page.
string | null
Cursor for the next page, or null at the end.
boolean
Whether another page is available.

SubOrgControlMode

The response enum contains MANAGED and INDEPENDENT; existing data can also return null. These are response values, not creation options. This API always creates with MANAGED and rejects caller-supplied control mode.

SDK method reference

Both list methods accept optional name filters in params, a limit that defaults to 20, and a cursor. JavaScript methods return promises. Python methods return dataclass instances; controlMode is parsed as SubOrgControlMode when non-null.

Errors and supported operations

Only GET and POST on /api/external/sub_orgs/ are available. There are no external retrieve-by-ID, update, delete, or embedded-user actions in this section’s API.