> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vort-sourcing.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Register a recruiter of the organization

> Upsert on `external_id` within the organization. Safe to retry. The recruiter is registered as an API-only identity of this organization: `email` is stored as the recruiter's contact / display e-mail only. It is not a login, and no Vort account is created or linked under it. Recruiters registered this way cannot sign in to Vort directly; they act in Vort only through your calls.



## OpenAPI

````yaml /api-reference/openapi.yaml post /users
openapi: 3.1.0
info:
  title: Vort Partner API
  version: 1.0.0
  summary: Server-to-server API for ATS vendors embedding Vort candidate matching.
  description: >
    Guides: [Integration flow](/integration-flow). UI rules: [UI
    specification](/ui-specification). Notices: [Notices](/notices).


    - Every call is server-to-server. `vpk_` keys and `vot_` org tokens MUST NOT
    reach a browser.

    - Clients MUST ignore unknown response fields; additive changes within v1
    are non-breaking.

    - Notices with an unknown `code` MUST be rendered generically from `title` +
    `body`,
      styled by `severity`, placed by `slot`.
    - Rate limits are per partner (default 120/minute, 20,000/day); `429`
    carries `Retry-After`.

    - Sandbox ([Sandbox guide](/sandbox)): every sandbox response carries
    `x-vort-environment: sandbox`;
      names are masked, reveals are synthetic and free, `target_count` <= 20, 20 real runs
      per organization per 24 h, `cert-*` jobs run certification fixtures, and the
      sandbox-only headers `x-vort-sandbox-simulate` / `x-vort-sandbox-reveal-price` and
      route `POST /sandbox/webhooks/test` exist. None of these exist in production.
  contact:
    name: Vort partner support (always include the run_id)
  license:
    name: Proprietary
    identifier: LicenseRef-Vort-Proprietary
servers:
  - url: https://vort-partner-api.vercel.app/sandbox/v1
    description: Sandbox
security:
  - partnerKey: []
    orgToken: []
tags:
  - name: Activation
    description: Connect a customer organization by redeeming its one-time activation code.
  - name: Users
    description: Register the recruiters who act on runs (a field, never a credential).
  - name: Jobs
    description: Jobs the runs search for.
  - name: Runs
    description: Start runs and read their progress, notices and candidates.
  - name: Candidates
    description: Reveal candidate contact details (charges credits).
  - name: Decisions
    description: Report recruiter decisions and the notices shown (mandatory).
  - name: Sandbox
    description: >-
      Sandbox-only helpers (see the [Sandbox guide](/sandbox)). Not present in
      production (404).
  - name: Webhooks
    description: >-
      Events Vort posts to your registered HTTPS endpoint, signed with
      `x-vort-signature`.
paths:
  /users:
    post:
      tags:
        - Users
      summary: Register a recruiter of the organization
      description: >-
        Upsert on `external_id` within the organization. Safe to retry. The
        recruiter is registered as an API-only identity of this organization:
        `email` is stored as the recruiter's contact / display e-mail only. It
        is not a login, and no Vort account is created or linked under it.
        Recruiters registered this way cannot sign in to Vort directly; they act
        in Vort only through your calls.
      operationId: upsertUser
      parameters:
        - $ref: '#/components/parameters/Lang'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserRequest'
            example:
              external_id: u-88121
              email: dana@acme-staffing.example
              full_name: Dana Levi
              role: recruiter
      responses:
        '200':
          description: >-
            Registered (`created` is false when the `external_id` was already
            registered).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserResponse'
              example:
                user_id: 5e0a9d63-8b7c-4c36-9e0d-6a2f41b7c3aa
                created: true
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '422':
          description: >-
            `invalid_user` — a required field is missing or `email` is
            malformed. The same code and message for every input problem.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          $ref: '#/components/responses/RateLimited'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  parameters:
    Lang:
      name: x-vort-lang
      in: header
      required: false
      description: Language of notices and messages. Defaults to the partner default.
      schema:
        type: string
        enum:
          - he
          - en
  schemas:
    UserRequest:
      type: object
      required:
        - external_id
        - email
        - full_name
        - role
      properties:
        external_id:
          type: string
          minLength: 1
        email:
          type: string
          format: email
          description: >-
            The recruiter's work e-mail, stored as their contact / display
            e-mail only. Not a login: no Vort account is created or linked under
            this address.
        full_name:
          type: string
          description: Shown as the recruiter's display name in Vort.
        role:
          type: string
          description: >-
            The user's role in your product (e.g. recruiter, admin).
            Informational in v1.
    UserResponse:
      type: object
      required:
        - user_id
        - created
      properties:
        user_id:
          type: string
          format: uuid
        created:
          type: boolean
    Error:
      type: object
      description: >-
        Error envelope. Branch on `error`; unknown codes are handled by HTTP
        status.
      required:
        - error
        - message
      properties:
        error:
          type: string
          examples:
            - invalid_partner_key
            - invalid_org_token
            - partner_disabled
            - organization_disabled
            - rate_limited
            - rate_limit_unavailable
            - code_not_found
            - code_expired
            - external_id_taken
            - invalid_user
            - job_not_found
            - user_not_found
            - run_not_found
            - candidate_not_in_run
            - invalid_decision
        message:
          type: string
      additionalProperties: true
  responses:
    Unauthorized:
      description: '`invalid_partner_key` or `invalid_org_token`'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: invalid_org_token
            message: The organization token is not valid.
    Forbidden:
      description: '`partner_disabled` or `organization_disabled`'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: organization_disabled
            message: This organization's Vort connection is disabled.
    RateLimited:
      description: '`rate_limited`'
      headers:
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: rate_limited
            message: Too many requests.
    ServiceUnavailable:
      description: >-
        `rate_limit_unavailable` — the rate limiter could not be checked, so the
        request was refused rather than let through unmetered. Retry with
        backoff.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: rate_limit_unavailable
            message: Rate limiting is temporarily unavailable. Retry shortly.
  headers:
    RetryAfter:
      description: Seconds to wait before retrying.
      schema:
        type: integer
        minimum: 0
  securitySchemes:
    partnerKey:
      type: apiKey
      in: header
      name: x-partner-key
      description: 'Partner API key: `vpk_live_` + 48 lowercase hex. Server-side only.'
    orgToken:
      type: apiKey
      in: header
      name: x-vort-org
      description: >-
        Customer org token: `vot_` + 48 lowercase hex, from /activations/redeem.
        Server-side only.

````