RAID API
  1. Profile
  • DiveRAID frontend public API
    • Search divers
      POST
    • Search instructors
      POST
    • Search dive centers
      POST
    • Search dive centers by country
      GET
  • DiveRAID rest API V1
    • Auth
      • Register a new user
      • Login and get a Sanctum token
      • Send password reset email
      • Reset password using token
      • Logout and revoke the current token
      • Resend email verification
      • Complete a two-factor login and get a Sanctum token
    • Profile
      • The user resource
      • Get authenticated user profile
        GET
      • Update profile
        PATCH
      • Delete account
        DELETE
      • Update password
        PATCH
      • Update dive center association
        PATCH
    • Diver
      • Shared diver resources
      • Courses
        • List active courses
        • List expired courses
        • Get course detail
        • Submit module quiz
        • Get quiz result
        • Submit course exam
        • Get exam result
        • Get skills progress
        • Sign skills (diver)
      • Free Learnings
        • List enrolled free learnings
        • List available free learning courses
        • Enroll in a free learning course
        • Get free learning detail
        • Submit free learning module quiz
        • Get free learning quiz result
      • Certifications
        • Get certification history
        • Get certification quiz result
        • Get certification exam result
        • Get certification skills
        • List diver certifications
      • Dive Logs
        • Delete dive log
        • Create dive log
        • Update dive log
        • List loggable courses
        • List dive logs (paginated)
        • Get dive log
      • Awards
        • List award cards
      • Documents
        • Upload own medical certificate or insurance
        • List diver documents
      • Forms
        • List diver forms
      • Medical
        • Get medical questionnaire structure
        • Submit medical questionnaire
      • Store
        • List courses available for purchase
        • Get order status
    • Professional
      • Students
        • List students
        • Get student progress
        • Get student quiz result
        • Get student exam result
        • Get student skills progress
        • Sign student skills
      • Certifications
        • Get certification history
        • Get certification quiz result
        • Get certification exam result
        • Get certification skills
        • List all professional certifications
        • List diver-level certifications
        • List specialty certifications
        • List professional certifications
        • List trainer certifications
        • List examiner certifications
      • Classroom
        • List classrooms
        • Get classroom progress (all students)
        • Get classroom student progress
        • Get classroom student quiz result
        • Get classroom student exam result
        • Get classroom student skills
        • Sign classroom student skills
      • Renewals
        • List renewal courses
        • Get renewal progress
        • Renewal status
        • Submit renewal module quiz
        • Get renewal quiz result
        • Submit renewal exam
        • Get renewal exam result
        • Get renewal skills progress
        • Sign renewal skills
      • Recognitions
        • List recognition courses
      • Dive Logs
        • Get student dive log
        • Sign student dive log
        • List student dive logs for a course
      • Store
    • Sync
      • Upload offline operations
      • Download full course data for offline use
      • Get sync status
    • Dive Center
    • Public
      • List all countries
      • Dive-log enum values with labels in the response language
      • Get country data
      • Get country divisions (states/provinces)
      • List time zone identifiers, optionally narrowed to one country
      • List, search, and radius-search publicly visible dive centres
      • Every publicly visible, geolocated dive centre as a map marker
      • Countries with at least one publicly visible dive centre
      • Full detail of one publicly visible dive centre
  • Schemas
    • Frontend API Schema
      • DiverSearch
    • SuccessResponse
    • DiverCertification
    • ValidationErrorResponse
    • TwoFactorChallengeResponse
    • TokenResponse
    • ErrorResponse
    • DiveLog
    • UserProfile
    • CourseLog
    • CourseLogDetail
    • QuizResult
    • ExamResult
    • SkillProgress
    • Certification
    • PaginatedDiveLogs
    • StoreItem
    • PaymentIntentResponse
    • OrderConfirmResponse
    • OrderStatusResponse
    • InstructorSearch
    • DiveCenterSearch
  1. Profile

The user resource

Shared payload returned by GET /api/v1/profile, PATCH /api/v1/profile, PATCH /api/v1/profile/dive-center and POST /api/v1/auth/register. Documented once here; the endpoint files link to it rather than repeating it.
Produced by App\Http\Resources\Backend\UserResource.
This resource is shared with the backend. It is not an API-specific resource, so a change made for an administrative screen changes this payload too. A dedicated Api\V1\UserResource is planned; until it exists, treat the field list as liable to move.

Shape#

data holds the user fields directly. There is no nested data and no second status inside it.
{
  "success": true,
  "status": "success",
  "message": "OK",
  "data": {
    "id": 164553,
    "raid_id": "CA26-801-007",
    "email": "diver@example.com",
    "...": "..."
  }
}

Always present#

FieldTypeNullableNotes
idintegerNoPrimary key
raid_idstringYesRAID member id, e.g. CA26-801-007
emailstringNoAlso the username
qrcodestringNoA complete inline SVG document, roughly 9 kB. See the size warning below
qualificationstringYesHighest qualification, plain text
qualification_caststringYesEnum label, e.g. Recreational
categorystringYesEnum label, null when no category is set
first_namestringYes
last_namestringYes
full_namestringYesDerived server-side, not directly writable
nationalitystringYesISO 3166-1 alpha-2
countrystringYesISO 3166-1 alpha-2
statestringYesSubdivision name
state_codestringYesSubdivision code
citystringYes
addressstringYes
timezonestringYesPHP timezone identifier
postal_codestringYes
phonestringYes
mobilestringYes
genderstringYesEnum label
dobstringYesY-m-d
nok_first_namestringYesNext of kin
nok_last_namestringYesNext of kin
nok_phonestringYesNext of kin
nok_emailstringYesNext of kin
nok_countrystringYesNext of kin
avatarstringNoAbsolute URL. Falls back to a placeholder image
e_cardstringNoAbsolute URL of the certification card image
guardian_first_namestringYesMinors only
guardian_last_namestringYesMinors only
guardian_emailstringYesMinors only
guardian_acceptedbooleanNo
default_languagestringYesTwo-letter language code. May hold legacy codes (cn, kr, us); the API normalizes them when choosing the response language (README §10)
currencystringYesDerived from the country. Not the store currency — the store prices in USD only
preferred_systemstringNoEnum label, Metric or Imperial
vat_ratenumberYesVAT percentage applied to that user's purchases
gdprstringYesY-m-d
termsstringYesY-m-d
policy_accepted_atstringYesY-m-d
email_verified_atstringYesY-m-d. null means the address is not verified
created_atstringNoISO-8601 with microseconds and a UTC offset, e.g. 2026-09-10T09:21:23.000000Z
updated_atstringNoSame format as created_at
dive_centerstringNoCentre name, or the literal string Not assigned
distributorstringNoDistributor name, or the literal string Not assigned
statusstringNoEnum label, e.g. Account Active

Conditional#

These keys appear and disappear depending on the account. A client must check for their presence rather than assume them.
FieldPresent whenTypeNotes
dive_center_ida dive centre is assignedinteger
dive_center_datea dive centre is assignedstringY-m-d, nullable
distributor_ida distributor is assignedinteger
distributor_datea distributor is assignedstringY-m-d, nullable
suspension_daysstatus is not activeinteger
restore_datestatus is not activestringY-m-d, nullable
restore_statusstatus is not activestringEnum label, nullable
status_reasonstatus is not activestringFree text written by administrators
job_countrythe account is a professionalstring
professional_statusthe account is a professionalstringEnum label, nullable
professional_suspension_daysthe account is a professionalinteger
professional_restore_datethe account is a professionalstringY-m-d, nullable
professional_status_reasonthe account is a professionalstringFree text written by administrators
renewal_datethe account is a professionalstringY-m-d, nullable
expire_datethe account is a professionalstringY-m-d, nullable
A recreational diver with an assigned centre and distributor and an active account receives 50 keys. A suspended professional receives up to 15 more.

Things a client integrator should know#

The response is dominated by the QR code. Measured against a live instance: 10 664 bytes total, of which qrcode is 9 292 — 87 %. The field is a complete <svg> document, not a URL and not base64. On a mobile connection this makes the profile call an order of magnitude heavier than the data it carries. If the client does not render the member QR code, it still pays for it on every call.
Two date formats coexist. Domain dates are Y-m-d strings. created_at and updated_at are full ISO-8601 with microseconds. Parse them differently.
Enum fields return the display label, not the machine value. qualification_cast, category, gender, preferred_system, status, restore_status, professional_status all return a display string such as Recreational or Account Active. There is no stable code alongside it, and the label is in the response language (README §10). Do not branch on these strings: they are display text and can change. Returning both a value and a label is a decided change, not yet implemented.
Not assigned is a sentinel, not a name. When no dive centre or distributor is set, dive_center and distributor contain that literal English string rather than null. A client checking for absence must compare against it.
Administrative fields are exposed. vat_rate, status_reason and professional_status_reason are visible to the account holder. The last two are free text written by administrators about the account. Reviewed and deliberately left visible for now, on the basis that the only consumer is the RAID mobile client. It should be revisited before the API is opened to third parties.

Source: docs/api/profile/_user-resource.md
Modified at 2026-10-08 12:41:30
Previous
Complete a two-factor login and get a Sanctum token
Next
Get authenticated user profile
Built with