DocuSign技术咨询:单个账户是否对应多个Base URI?
Let’s break down your questions one by one, based on common enterprise REST API design patterns:
1. Is the stated method of fetching Base URI/URL correct?
Yes, this is a common and valid pattern for REST APIs that map users to accounts and enterprises. Here’s why:
- When not using OAuth, the
/login_informationendpoint typically returns context about the authenticated user (including their linked account’s Base URI) after a standard login flow—this makes sense because post-login, the system needs to direct the user to their account-specific resources. - For OAuth, the
/oauth/userinfoendpoint is designed to return claims about the authenticated user, which often includes metadata like their associated account’s Base URL. This aligns with OAuth’s core purpose of providing user context after successful authentication.
Of course, this depends on your specific API’s implementation, but this approach is widely adopted in enterprise-grade systems.
2. Does a single Base URI correspond to one account, and are all users under that account assigned the same Base URI?
In most cases, yes. Here’s the reasoning:
- Since an account belongs to a single enterprise, the Base URI is almost always tied to the account (or enterprise) rather than individual users. It acts as the root endpoint for all resources belonging to that account (like invoices, team data, etc.).
- Users associated with the same account will access the same set of account-specific resources, so their Base URI should be identical.
The only exception might be if your API supports users linked to multiple accounts—in that case, a user might have different Base URIs depending on which account context they’re operating in. But for the standard one-user-to-multiple-accounts model you described, the same Base URI applies to all users of a single account.
3. Is there a dedicated interface to fetch Base URI for an account (not tied to a user)?
Many mature enterprise APIs do provide such endpoints, though this varies by implementation. Examples of common patterns include:
- Admin-only endpoints like
GET /admin/accounts/{accountId}/base-uri(requires admin-level authentication to access account metadata without user context) - Account metadata endpoints like
GET /accounts/{accountId}/detailsthat include the Base URI alongside other account attributes (like enterprise name, creation date)
These endpoints are useful for scenarios where you need to retrieve account context without relying on a user’s authentication—for example, backend services syncing account data, or admin dashboards managing multiple accounts. If your current API doesn’t offer this, it’s a reasonable feature request for the API maintainers.
内容的提问来源于stack exchange,提问作者NicoFC34

