---
title: "Add a user to the SSO bypass allowlist"
method: POST
path: "/sso_bypass_allowlist_users"
tags: ["SSO Bypass"]
---

# Add a user to the SSO bypass allowlist

`POST /sso_bypass_allowlist_users`

Puts a user on the allowlist. The request is rejected unless the user holds a verified email
address on a domain one of the instance's enterprise connections serves.

## Request body

- object
  - `user_id` string, required — The ID of the user to allowlist.

## Response `201`

An SSO bypass allowlist entry

- SSOBypassAllowlistUser — A user who may verify an email code instead of reaching their identity provider when enterprise SSO is unreachable.
  - `object` 'sso_bypass_allowlist_user', required
  - `user_id` string, required — The allowlisted user, and the identifier the delete endpoint takes.
  - `public_user_data` SSOBypassAllowlistPublicUserData, required — The allowlisted user's public data.
    - `first_name` string, nullable, required
    - `last_name` string, nullable, required
    - `image_url` string
    - `has_image` boolean, required
    - `identifier` string, required
    - `username` string, nullable, required
    - `profile_image_url` string, nullable, required — Use `image_url` instead.
  - `created_at` integer, required — Unix timestamp of creation.
  - `updated_at` integer, required — Unix timestamp of last update.

## Other responses

- `402` — Payment required
- `403` — Authorization invalid
- `404` — Resource not found
- `422` — Invalid request parameters

## Changes

- **2026-10-02** `65fe91cf191f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/clerk/apis/clerk-backend-api/changes/sso_bypass_allowlist_users/post.md)

---

[API](https://skmtc.dev/clerk/apis/clerk-backend-api.md) · [All operations](https://skmtc.dev/clerk/apis/clerk-backend-api/llms.txt) · [OpenAPI document](https://skmtc.dev/clerk/apis/clerk-backend-api/revisions/65fe91cf191f?raw)
