---
title: "Create User"
method: POST
path: "/api/users"
tags: ["Users"]
---

# Create User

`POST /api/users`

## Request body

- UserPassword
  - `username` string, required — Username of the user.
  - `scope` 'admin' | 'install' | 'update' | 'read'
  - `totp_enabled` boolean — Whether two-factor authentication is enabled/required using TOTP. Not available if Passkey is used.
  - `passkey` boolean — Whether this user authenticates using a Passkey.
  - `limited` boolean — In case the user was authenticated with a passwordless link, the scope of the API token used for generating that link is inherited to the user session. This flag is `true` if the user would have more permissions than currently given by the passwordless link.
  - `password` string, password, required — Password of the user.

## Response `200`

Data of the newly created user.

- User
  - `username` string — Username of the user.
  - `scope` 'admin' | 'install' | 'update' | 'read'
  - `totp_enabled` boolean — Whether two-factor authentication is enabled/required using TOTP. Not available if Passkey is used.
  - `passkey` boolean — Whether this user authenticates using a Passkey.
  - `limited` boolean — In case the user was authenticated with a passwordless link, the scope of the API token used for generating that link is inherited to the user session. This flag is `true` if the user would have more permissions than currently given by the passwordless link.

## Changes

> 45 revisions in range; 5 could not be searched.

- **2025-03-06** `4dc3bf84edf7` — 4 info
  - the endpoint scheme security `CookieAuthentication` was added to the API
  - the endpoint scheme security `TokenAuthentication` was added to the API
  - added the new optional request property `allOf[#/components/schemas/User]/limited`
  - added the optional property `limited` to the response with the `200` status
- **2025-01-29** `b0fe14acdeaf` — 2 info
  - added the new optional request property `allOf[#/components/schemas/User]/passkey`
  - added the optional property `passkey` to the response with the `200` status
- **2024-11-07** `0caa21a70faf` — 2 info
  - added the new optional request property `allOf[#/components/schemas/User]/totp_enabled`
  - added the optional property `totp_enabled` to the response with the `200` status
- **2024-11-06** `e06d9f9dee25` — 2 warning, 2 info
  - removed the request property `allOf[#/components/schemas/User]/roles`
  - removed the optional property `roles` from the response with the `200` status
  - added the new optional request property `allOf[#/components/schemas/User]/scope`
  - added the optional property `scope` to the response with the `200` status
- **2024-11-02** `f68de1bd16a3` — 2 info
  - added the new optional request property `allOf[#/components/schemas/User]/roles`
  - added the optional property `roles` to the response with the `200` status

[Full history](https://skmtc.dev/contao/apis/contao-manager-api/changes/api/users/post.md)

---

[API](https://skmtc.dev/contao/apis/contao-manager-api.md) · [All operations](https://skmtc.dev/contao/apis/contao-manager-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/contao/contao-manager-api/revisions/074d8046de13/schema)
