---
title: "Fetch user account data for a user."
method: GET
path: "/admin/users/{userId}"
tags: ["admin"]
---

# Fetch user account data for a user.

`GET /admin/users/{userId}`

## Response `200`

User's account data.

- UserSchema — Object describing the user related to the issued access and refresh tokens.
  - `id` string, uuid
  - `aud` string
  - `role` string
  - `email` string — User's primary contact email. In most cases you can uniquely identify a user by their email address, but not in all cases.
  - `email_confirmed_at` string, date-time
  - `phone` string, phone — User's primary contact phone number. In most cases you can uniquely identify a user by their phone number, but not in all cases.
  - `phone_confirmed_at` string, date-time
  - `confirmation_sent_at` string, date-time
  - `confirmed_at` string, date-time
  - `recovery_sent_at` string, date-time
  - `new_email` string, email
  - `email_change_sent_at` string, date-time
  - `new_phone` string, phone
  - `phone_change_sent_at` string, date-time
  - `reauthentication_sent_at` string, date-time
  - `last_sign_in_at` string, date-time
  - `app_metadata` object
  - `user_metadata` object
  - `factors` MFAFactorSchema[]
    - `id` string, uuid
    - `status` string — Usually one of: - verified - unverified
    - `friendly_name` string
    - `factor_type` string — Usually one of: - totp - phone - webauthn
    - `webauthn_credential` string
    - `phone` string, phone, nullable
    - `created_at` string, date-time
    - `updated_at` string, date-time
    - `last_challenged_at` string, date-time, nullable
  - `identities` IdentitySchema[]
    - `identity_id` string, uuid
    - `id` string, uuid
    - `user_id` string, uuid
    - `identity_data` object
    - `provider` string
    - `last_sign_in_at` string, date-time
    - `created_at` string, date-time
    - `updated_at` string, date-time
    - `email` string, email
  - `banned_until` string, date-time
  - `created_at` string, date-time
  - `updated_at` string, date-time
  - `deleted_at` string, date-time
  - `is_anonymous` boolean

## Other responses

- `401` — HTTP Unauthorized response.
- `403` — HTTP Forbidden response.
- `404` — There is no such user.

## Changes

- **2025-09-24** `a222d9459767` — 1 warning, 1 info
  - removed the optional property `factors/items/web_authn_credential` from the response with the `200` status
  - added the optional property `factors/items/webauthn_credential` to the response with the `200` status
- **2025-02-07** `4d0f1a6c1ad9` — 1 breaking, 3 info
  - the `factors/items/web_authn_credential` response's property type/format changed from `jsonb`/`` to `string`/`` for status `200`
  - added the optional property `error_code` to the response with the `401` status
  - added the optional property `error_code` to the response with the `403` status
  - added the optional property `error_code` to the response with the `404` status
- **2024-10-11** `f89bf040698f` — 1 breaking, 4 info
  - the response property `factors/items/phone` became nullable for the status `200`
  - added the optional property `factors/items/created_at` to the response with the `200` status
  - added the optional property `factors/items/last_challenged_at` to the response with the `200` status
  - added the optional property `factors/items/updated_at` to the response with the `200` status
  - …1 more
- **2024-08-01** `b33a9ea8493e` — 1 info
  - added the optional property `factors/items/phone` to the response with the `200` status
- …earlier changes not shown

[Full history](https://skmtc.dev/supabase/apis/supabase-auth-rest-api/changes/admin/users/:userId/get.md)

---

[API](https://skmtc.dev/supabase/apis/supabase-auth-rest-api.md) · [All operations](https://skmtc.dev/supabase/apis/supabase-auth-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/supabase/supabase-auth-rest-api/revisions/2e2a74a7459f/schema)
