curl --request POST \
--url https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user \
--header 'Content-Type: application/json' \
--header 'x-access-token: <api-key>' \
--data '{}'import requests
url = "https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user"
payload = {}
headers = {
"x-access-token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-access-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-access-token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user")
.header("x-access-token", "<api-key>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-access-token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"success": true,
"suspendedMemberships": 123,
"userDeactivated": true,
"tokensRevoked": true
}Suspend the user flagged by a Praxis Shield incident
Remediation action. The scope body field selects the axis (defaults to institution; if omitted, super defaults to global). global is super-only — it deactivates the account (user.status=‘inactive’), sets all memberships inactive, and revokes the user’s keys/sessions. institution sets ONLY the userInstitution memberships tying the user to the incident institutions the caller administers inactive; the account stays active elsewhere and no tokens are revoked. Mounted under the admin gate (isAdmin) and scoped per-institution via the institutions.edit entitlement (super bypasses). Cannot suspend a super-admin or yourself.
curl --request POST \
--url https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user \
--header 'Content-Type: application/json' \
--header 'x-access-token: <api-key>' \
--data '{}'import requests
url = "https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user"
payload = {}
headers = {
"x-access-token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-access-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-access-token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user")
.header("x-access-token", "<api-key>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://pria.praxislxp.com/api/admin/security/threats/{incidentId}/suspend-user")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-access-token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"success": true,
"suspendedMemberships": 123,
"userDeactivated": true,
"tokensRevoked": true
}Authorizations
JWT token passed in x-access-token header
Path Parameters
Incident id (drives the target user and the institution scope)
Body
Suspend axis. institution (default) inactivates only the memberships for the incident institutions the caller manages. global (super-only) deactivates the account + revokes keys/sessions.
institution, global Was this page helpful?