curl --request POST \
--url https://app.orgo.space/api/v1/custom_field_values \
--header 'Api-Token: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"field": "/api/v1/custom_fields/1",
"user": "/api/v1/users/1",
"value": "Vegetarian",
"contact": "/api/v1/contacts/1",
"media": "/api/v1/media/1",
"eventAttend": "/api/v1/event_attends/1"
}
'import requests
url = "https://app.orgo.space/api/v1/custom_field_values"
payload = {
"field": "/api/v1/custom_fields/1",
"user": "/api/v1/users/1",
"value": "Vegetarian",
"contact": "/api/v1/contacts/1",
"media": "/api/v1/media/1",
"eventAttend": "/api/v1/event_attends/1"
}
headers = {
"Api-Token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Api-Token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
field: '/api/v1/custom_fields/1',
user: '/api/v1/users/1',
value: 'Vegetarian',
contact: '/api/v1/contacts/1',
media: '/api/v1/media/1',
eventAttend: '/api/v1/event_attends/1'
})
};
fetch('https://app.orgo.space/api/v1/custom_field_values', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.orgo.space/api/v1/custom_field_values",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'field' => '/api/v1/custom_fields/1',
'user' => '/api/v1/users/1',
'value' => 'Vegetarian',
'contact' => '/api/v1/contacts/1',
'media' => '/api/v1/media/1',
'eventAttend' => '/api/v1/event_attends/1'
]),
CURLOPT_HTTPHEADER => [
"Api-Token: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.orgo.space/api/v1/custom_field_values"
payload := strings.NewReader("{\n \"field\": \"/api/v1/custom_fields/1\",\n \"user\": \"/api/v1/users/1\",\n \"value\": \"Vegetarian\",\n \"contact\": \"/api/v1/contacts/1\",\n \"media\": \"/api/v1/media/1\",\n \"eventAttend\": \"/api/v1/event_attends/1\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Api-Token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.orgo.space/api/v1/custom_field_values")
.header("Api-Token", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"field\": \"/api/v1/custom_fields/1\",\n \"user\": \"/api/v1/users/1\",\n \"value\": \"Vegetarian\",\n \"contact\": \"/api/v1/contacts/1\",\n \"media\": \"/api/v1/media/1\",\n \"eventAttend\": \"/api/v1/event_attends/1\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.orgo.space/api/v1/custom_field_values")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Api-Token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"field\": \"/api/v1/custom_fields/1\",\n \"user\": \"/api/v1/users/1\",\n \"value\": \"Vegetarian\",\n \"contact\": \"/api/v1/contacts/1\",\n \"media\": \"/api/v1/media/1\",\n \"eventAttend\": \"/api/v1/event_attends/1\"\n}"
response = http.request(request)
puts response.read_body{
"id": 42,
"field": "/api/v1/custom_fields/1",
"user": "/api/v1/users/1",
"value": "Vegetarian",
"contact": "/api/v1/contacts/1",
"media": {
"size": 42,
"mimeType": "application/pdf"
},
"eventAttend": "/api/v1/event_attends/1"
}Create a custom field value
Creates a single custom field value attached to one of a user, a contact, or an event attendance (exactly one of user, contact, eventAttend must be set; the others must be omitted or null). The field IRI is required. For file-type custom fields, send a media IRI and the value will be ignored; for other field types, send value as a string (callers should JSON-encode multi-option answers themselves before sending).
All foreign-key fields take an IRI-reference string in the form /api/v1/{resource}/{id} rather than plain numeric ids. Concrete examples are listed in the “Request body” section below.
Permission gates per owner type mirror the existing PATCH endpoints on the owning entities:
user: caller is the user, hasHR_LOCALon the user, or is a parent of the user.contact: caller hasHR_LOCALorFINANCIAL_LOCALon the contact.eventAttend: caller is the attendee, hasEVENT_LOCALon the event’s unit, or hasHR_TENANT.
For contact-attached values the field’s tenant must match the contact’s tenant and the field’s discriminator must be profile; for event-attended values the field’s tenant must match the event’s tenant and the discriminator must be event. The user-attached path inherits the existing nested-write behavior, which does not enforce either of those checks today.
curl --request POST \
--url https://app.orgo.space/api/v1/custom_field_values \
--header 'Api-Token: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"field": "/api/v1/custom_fields/1",
"user": "/api/v1/users/1",
"value": "Vegetarian",
"contact": "/api/v1/contacts/1",
"media": "/api/v1/media/1",
"eventAttend": "/api/v1/event_attends/1"
}
'import requests
url = "https://app.orgo.space/api/v1/custom_field_values"
payload = {
"field": "/api/v1/custom_fields/1",
"user": "/api/v1/users/1",
"value": "Vegetarian",
"contact": "/api/v1/contacts/1",
"media": "/api/v1/media/1",
"eventAttend": "/api/v1/event_attends/1"
}
headers = {
"Api-Token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Api-Token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
field: '/api/v1/custom_fields/1',
user: '/api/v1/users/1',
value: 'Vegetarian',
contact: '/api/v1/contacts/1',
media: '/api/v1/media/1',
eventAttend: '/api/v1/event_attends/1'
})
};
fetch('https://app.orgo.space/api/v1/custom_field_values', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.orgo.space/api/v1/custom_field_values",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'field' => '/api/v1/custom_fields/1',
'user' => '/api/v1/users/1',
'value' => 'Vegetarian',
'contact' => '/api/v1/contacts/1',
'media' => '/api/v1/media/1',
'eventAttend' => '/api/v1/event_attends/1'
]),
CURLOPT_HTTPHEADER => [
"Api-Token: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.orgo.space/api/v1/custom_field_values"
payload := strings.NewReader("{\n \"field\": \"/api/v1/custom_fields/1\",\n \"user\": \"/api/v1/users/1\",\n \"value\": \"Vegetarian\",\n \"contact\": \"/api/v1/contacts/1\",\n \"media\": \"/api/v1/media/1\",\n \"eventAttend\": \"/api/v1/event_attends/1\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Api-Token", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.orgo.space/api/v1/custom_field_values")
.header("Api-Token", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"field\": \"/api/v1/custom_fields/1\",\n \"user\": \"/api/v1/users/1\",\n \"value\": \"Vegetarian\",\n \"contact\": \"/api/v1/contacts/1\",\n \"media\": \"/api/v1/media/1\",\n \"eventAttend\": \"/api/v1/event_attends/1\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.orgo.space/api/v1/custom_field_values")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Api-Token"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"field\": \"/api/v1/custom_fields/1\",\n \"user\": \"/api/v1/users/1\",\n \"value\": \"Vegetarian\",\n \"contact\": \"/api/v1/contacts/1\",\n \"media\": \"/api/v1/media/1\",\n \"eventAttend\": \"/api/v1/event_attends/1\"\n}"
response = http.request(request)
puts response.read_body{
"id": 42,
"field": "/api/v1/custom_fields/1",
"user": "/api/v1/users/1",
"value": "Vegetarian",
"contact": "/api/v1/contacts/1",
"media": {
"size": 42,
"mimeType": "application/pdf"
},
"eventAttend": "/api/v1/event_attends/1"
}Authorizations
Server-to-server authentication. Generate a token in the admin UI at
Settings → Developers → API Access. Send the raw token in the
Api-Token header — there is no Bearer prefix.
Tokens can be marked read-only at creation time, in which case the API
rejects any non-GET request with 403 Forbidden.
Body
The new CustomFieldValue resource
Stored answers for tenant-defined custom fields. Each row links a CustomField definition to one of three possible owners: a user (user), a contact (contact), or an event attendance (eventAttend). Exactly one of these is set per row; the others are null. The value column holds the answer as a string (multi-option fields store a comma-separated list, file/image fields store the answer in media and leave value blank). All queries are tenant-isolated through field.tenant, which is guaranteed non-null. The endpoint exposes only the values whose custom field definition belongs to the current user's tenant. Custom field values attached to event attendances are typically read through /event_attends/{id} rather than this collection. Values can be created directly through POST on this resource (one value per request, with exactly one of user/contact/ eventAttend set), or as nested writes inside the owning entity (e.g. PATCH /users/{id} with a rawUserCustomFieldsValues map, PATCH /contacts/{id} with rawContactCustomFieldsValues). The direct POST route delegates to the same underlying service as the nested-write path, so encryption, file-media handling, and field-visibility checks behave identically.
"/api/v1/custom_fields/1"
"/api/v1/users/1"
"/api/v1/contacts/1"
"/api/v1/media/1"
"/api/v1/event_attends/1"
Response
CustomFieldValue resource created
Stored answers for tenant-defined custom fields. Each row links a CustomField definition to one of three possible owners: a user (user), a contact (contact), or an event attendance (eventAttend). Exactly one of these is set per row; the others are null. The value column holds the answer as a string (multi-option fields store a comma-separated list, file/image fields store the answer in media and leave value blank). All queries are tenant-isolated through field.tenant, which is guaranteed non-null. The endpoint exposes only the values whose custom field definition belongs to the current user's tenant. Custom field values attached to event attendances are typically read through /event_attends/{id} rather than this collection. Values can be created directly through POST on this resource (one value per request, with exactly one of user/contact/ eventAttend set), or as nested writes inside the owning entity (e.g. PATCH /users/{id} with a rawUserCustomFieldsValues map, PATCH /contacts/{id} with rawContactCustomFieldsValues). The direct POST route delegates to the same underlying service as the nested-write path, so encryption, file-media handling, and field-visibility checks behave identically.
"/api/v1/custom_fields/1"
"/api/v1/users/1"
"/api/v1/contacts/1"
Show child attributes
Show child attributes
"/api/v1/event_attends/1"

