Revoke the current user's web browser
Idempotently disables only an owned device and clears its encrypted token. Unknown or foreign ids do not change another user's subscription.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
id*stringuuidOwned browser revoked or already absent
curl -X DELETE 'https://api.monetaryai.uz/api/v1/push/devices/497f6eca-6276-4993-bfeb-53cbbbba6f08'Edit a company user's name, role and status PUT
Replaces company-local display name, optional contact email, one default role and ACTIVE/SUSPENDED status using lockVersion. Login email/password and global profile are never changed. Self edits and owner edits are forbidden. Existing temporary/special grants are revoked; suspension also revokes refresh sessions. Other company memberships are untouched. Company permission: `updateCompanyUser`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
Read a tenant-scoped web push message status GET
Requires live company permission. Per-device ACCEPTED is Firebase acceptance only; UNCERTAIN is not automatically retried. COMPLETE means no pending/claimed work, not proof of browser display. Company permission: `getWebPushMessageStatus`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.