---
title: "List app users"
method: GET
path: "/api/apps/{app_id}/entities/User"
---

# List app users

`GET /api/apps/{app_id}/entities/User`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the app's users: the people who signed up to it, or who accepted an invitation and signed in. Someone you've invited who hasn't signed in yet isn't listed.

It leaves out accounts Base44 added to the app on its own, such as workspace admins and support staff granted access, and the short-lived accounts a test run creates. Unless your own account has a Base44 or Wix email address, [Count app users](/api-reference/count-app-users) also leaves out accounts with one. This list includes them, so the two can differ. Row-level security on the `User` entity applies, so rules that narrow reads narrow this list too.

Filter with `q`, or by passing a field name directly as a query parameter for an exact match, as in `?role=admin`. Users come back in the order they joined unless you set `sort`.

<Warning>Each user includes fields beyond the ones documented here. Don't rely on undocumented response fields, as they can change at any time.</Warning>

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app, including a read-only key. Workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app whose users you want to list.

## Query parameters

- `q` string
- `limit` integer
- `skip` integer
- `sort` string
- `fields` string

## Response `200`

The app's users.

- object[]
  - `id` string, nullable — ID of the user.
  - `email` string, nullable — Email the user signs in with.
  - `full_name` string, nullable — The user's name, or `null` if they haven't given one.
  - `role` string, nullable — The user's role in the app. `user` and `admin` are built in, and an app can define its own.
  - `collaborator_role` 'editor', nullable — `editor` when the user can also edit the app in Base44, otherwise `null`.
  - `created_date` string, nullable — When the user joined the app, as a UTC timestamp in ISO 8601 format.
  - `updated_date` string, nullable — When the user's record last changed, as a UTC timestamp in ISO 8601 format.

## Other responses

- `400` — `q` isn't a JSON object, `limit` or `skip` is out of range or not a whole number, or `sort` names more than one field.
- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app.
- `404` — App not found.
- `422` — A filter you passed as its own query parameter doesn't match the type the `User` schema declares for that field.
- `429` — Rate limit exceeded. The base limit is 100 requests per minute, and this endpoint shares it with [Count app users](/api-reference/count-app-users). See [Rate limits](/developers/references/apps-api/get-started/rate-limits) for the multiplier your plan gets.

## Changes

> 18 revisions in range; 1 not diffed.

- **2026-09-28** `28fc82924122` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/entities/User/get.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/28fc82924122?raw)
