Users

List users

Returns a list of users in the specified zone.

Note: cursor pagination, search, and sort are not yet enabled for all zones. Where they are not enabled, the response returns all users in the zone (capped at 100) in items, with after_cursor and before_cursor set to null and total_count of 0; filter[email] and filter[identifier] are still applied, while the pagination, search, and sort parameters below are accepted but ignored.

Use cursor pagination via after/before. Sort: comma-separated field list; prefix with - for descending. Use expand[]=total_count to include the matching row count, expand[]=session_count to include per-user session counts, expand[]=grant_count to include per-user delegated-grant counts, expand[]=role-assignments to include each user's structured role grants (direct grants only by default, each tagged with source; use role_source=all to also include group-inherited), expand[]=groups to include each user's group memberships, expand[]=credentials to include each user's authentication credentials (each with its provider_id), and expand[]=credentials.provider to additionally inline the full identity provider on each federation credential. Filter by exact email via filter[email] and by exact identifier via filter[identifier]; restrict to members of a group via filter[groups] (repeatable, OR'd across values); search via query[email] / query[subject] / query[] (substring match, OR'd across repeated values). query[] matches against email and federation credential subject. Pass filter[id] (repeatable, max 100) to restrict results to a known set of users — mutually exclusive with after/before (returns 400 if combined). When filter[id] is set, limit is ignored and the response contains every requested user that exists in the zone, in a single page. IDs not in the zone are silently omitted.

get/zones/{zoneId}/users

Path parameters

zoneIdstring required

Zone ID

Query parameters

afterstring

Cursor for forward pagination

beforestring

Cursor for backward pagination

limitinteger

Maximum number of items to return

'total_count' | 'session_count' | 'grant_count' | 'role-assignments' | 'groups' | 'credentials' | 'credentials.provider'
OR
string[]
role_source'user' | 'group' | 'all'

Selects which grants expand[]=role-assignments returns, tagging each with source: user (direct only, the default), group (group-inherited only), or all (both direct and group-inherited). Requires expand[]=role-assignments.

string email

Filter by exact email address

OR
string[]
string

Restrict results to users with this publicId. Repeatable, max 100. Mutually exclusive with after/before.

OR
string[]
string

Filter by exact user identifier

OR
string[]
string

Restrict to members of this group (by group ID). Repeatable; OR'd across values.

OR
string[]
string

Search by email (substring match)

OR
string[]
string

Search by federated credential subject (substring match)

OR
string[]
string

Search across email and credential subject (substring match)

OR
string[]
sortstring

Comma-separated sort fields. Prefix with - for descending. Allowed: created_at, email, authenticated_at

Response

Default Response

Changes