---
title: "Get a user by id"
method: GET
path: "/auth/users/{userId}"
tags: ["auth"]
---

# Get a user by id

`GET /auth/users/{userId}`

## Path parameters

- `userId` string, required

## Response `200`

OK

- object
  - `success` true, required
  - `msg` string, required
  - `data` User, required
    - `_id` string, required
    - `firstName` string, required
    - `lastName` string, required
    - `email` string, required
    - `role` string[], required
    - `teamId` string
    - `profileImage` string, nullable
    - `createdAt` string, required
    - `updatedAt` string, required

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `404` — User not found
- `500` — Internal server error

## Changes

- **2026-05-01** `39082d385dda` — 2 breaking, 6 warning, 7 info
  - for the `path` request parameter `userId`, the minLength was increased from `0` to `1`
  - the response's body type/format changed from ``/`` to `object`/`` for status `200`
  - removed the optional property `details` from the response with the `403` status
  - removed the optional property `details` from the response with the `404` status
  - …11 more
- **2025-08-11** `db719f9e3d34` — 1 info
  - endpoint added
- **2025-04-20** `b97ec6888b3c` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/bluewave-labs/apis/checkmate-api/changes/auth/users/:userId/get.md)

---

[API](https://skmtc.dev/bluewave-labs/apis/checkmate-api.md) · [All operations](https://skmtc.dev/bluewave-labs/apis/checkmate-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/bluewave-labs/checkmate-api/revisions/a9ac59e12c59/schema)
