List users
Returns a list of users in the specified zone.
Note: cursor pagination, search, and sort are not yet enabled for all zones. Where they are not enabled, the response returns all users in the zone (capped at 100) in items, with after_cursor and before_cursor set to null and total_count of 0; filter[email] and filter[identifier] are still applied, while the pagination, search, and sort parameters below are accepted but ignored.
Use cursor pagination via after/before. Sort: comma-separated field list; prefix with - for descending. Use expand[]=total_count to include the matching row count, expand[]=session_count to include per-user session counts, expand[]=grant_count to include per-user delegated-grant counts, expand[]=role-assignments to include each user's structured role grants (direct grants only by default, each tagged with source; use role_source=all to also include group-inherited), expand[]=groups to include each user's group memberships, expand[]=credentials to include each user's authentication credentials (each with its provider_id), and expand[]=credentials.provider to additionally inline the full identity provider on each federation credential. Filter by exact email via filter[email] and by exact identifier via filter[identifier]; restrict to members of a group via filter[groups] (repeatable, OR'd across values); search via query[email] / query[subject] / query[] (substring match, OR'd across repeated values). query[] matches against email and federation credential subject. Pass filter[id] (repeatable, max 100) to restrict results to a known set of users — mutually exclusive with after/before (returns 400 if combined). When filter[id] is set, limit is ignored and the response contains every requested user that exists in the zone, in a single page. IDs not in the zone are silently omitted.
Path parameters
Zone ID
Query parameters
Cursor for forward pagination
Cursor for backward pagination
Maximum number of items to return
Selects which grants expand[]=role-assignments returns, tagging each with source: user (direct only, the default), group (group-inherited only), or all (both direct and group-inherited). Requires expand[]=role-assignments.
Comma-separated sort fields. Prefix with - for descending. Allowed: created_at, email, authenticated_at
Response
Default Response