---
title: "List the SSO bypass allowlist"
method: GET
path: "/sso_bypass_allowlist_users"
tags: ["SSO Bypass"]
---

# List the SSO bypass allowlist

`GET /sso_bypass_allowlist_users`

Returns the users who may verify an email code instead of reaching their identity provider when
enterprise SSO is unreachable.

## Query parameters

- `enterprise_connection_id` string

## Response `200`

The instance's SSO bypass allowlist, deduplicated by user

- SSOBypassAllowlistUser[] — The instance's SSO bypass allowlist, deduplicated by user.
  - `object` 'sso_bypass_allowlist_user', required
  - `user_id` string, required — The allowlisted user, and the identifier the delete endpoint takes.
  - `public_user_data` SSOBypassAllowlistPublicUserData, required — The allowlisted user's public data.
    - `first_name` string, nullable, required
    - `last_name` string, nullable, required
    - `image_url` string
    - `has_image` boolean, required
    - `identifier` string, required
    - `username` string, nullable, required
    - `profile_image_url` string, nullable, required — Use `image_url` instead.
  - `created_at` integer, required — Unix timestamp of creation.
  - `updated_at` integer, required — Unix timestamp of last update.

## Other responses

- `403` — Authorization invalid
- `404` — Resource not found

## Changes

- **2026-10-02** `65fe91cf191f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/clerk/apis/clerk-backend-api/changes/sso_bypass_allowlist_users/get.md)

---

[API](https://skmtc.dev/clerk/apis/clerk-backend-api.md) · [All operations](https://skmtc.dev/clerk/apis/clerk-backend-api/llms.txt) · [OpenAPI document](https://skmtc.dev/clerk/apis/clerk-backend-api/revisions/65fe91cf191f?raw)
