---
title: "OneRoster - Get all users"
method: GET
path: "/oneroster/users"
tags: ["Oneroster"]
---

# OneRoster - Get all users

`GET /oneroster/users`

**Requires permission:** *ServiceAccount*

OneRoster v1.1 GetAllUsers. Pupils map to role=student, staff to role=teacher. Supports offset/limit paging and status / dateLastModified filtering.

## Response `200`

Success - users

- UserSetResponse
  - `users` OrUser[]
    - `sourcedId` string, nullable
    - `status` string
    - `dateLastModified` string, date-time, nullable
    - `enabledUser` boolean
    - `username` string, nullable
    - `givenName` string, nullable
    - `familyName` string, nullable
    - `middleName` string, nullable
    - `role` string, nullable
    - `identifier` string, nullable
    - `email` string, nullable
    - `orgs` OrGuidRef[]
      - `href` string, nullable
      - `sourcedId` string, nullable
      - `type` string, nullable
    - `grades` string[]

## Other responses

- `401` — Unauthorized
- `403` — Caller is not an authorised service account

## Changes

- **2026-07-26** `87818d31ea72` — 2 info
  - api operation id `PanopticApiEndpointsExternalOneRosterGetOneRosterUsersEndpoint` removed and replaced with `PanopticApiEndpointsExternalOneRosterGetOneRosterUsersEndpoint1`
  - the security scope `ServiceAccount` was removed from the endpoint's security scheme `JWTBearerAuth`

[Change history](https://skmtc.dev/tonbridge/apis/tonbridge-app-api/changes/oneroster/users/get.md)

---

[API](https://skmtc.dev/tonbridge/apis/tonbridge-app-api.md) · [All operations](https://skmtc.dev/tonbridge/apis/tonbridge-app-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/tonbridge/tonbridge-app-api/revisions/223cb0feedeb/schema)
