---
title: "Get all users"
method: GET
path: "/users"
tags: ["Users"]
---

# Get all users

`GET /users`

Use this endpoint to retrieve all users

## Query parameters

- `page` integer
- `per_page` integer
- `site_id` string
- `organisation_id` string, uuid
- `sort` string
- `query` string
- `twofa_enabled` boolean
- `twofa_disabled` boolean
- `managed_by_sso` boolean
- `not_managed_by_sso` boolean
- `include_inactive` boolean

## Response `200`

A list of users

- object — Paginated envelope mixin. `allOf` this into any list response that wraps its `data` array with `meta` + `links`; the concrete schema keeps its own title so the SDK surface is unchanged, while the `meta` / `links` shape is sourced from a single definition.
  - `links` PaginationLinks, required — Hypermedia navigation links for paging through a list response. Each property is a fully-qualified URL that preserves the original query string (filters, sort, page size) and only swaps the `page` parameter. `next` and `prev` are `null` at the ends of the result set; `first` and `last` are always present.
    - `first` string, required — The url of the first page for the paginated results set
    - `next` string, nullable, required — The url of the next page for the paginated results set
    - `prev` string, nullable, required — The url of the previous page for the paginated results set
    - `last` string, required — The url of the last page for the paginated results set
  - `meta` PaginationMeta, required — Counts and positional information for the current page of a list response. Use `current_page` and `last_page` to drive pagination UI, `total` for result counts, and `per_page` to confirm the page size the server actually applied (which may differ from the requested value when capped).
    - `from` integer, required — The item number from which this results set starts from
    - `to` integer, required — The item number from which this results set ends at
    - `total` integer, required — The total number of results
    - `current_page` integer, required — The current page number
    - `last_page` integer, required — The page number of the last result set
    - `per_page` integer, required — The number of results per page
    - `path` string, required — The path of this api request
  - `data` User[], required
    - `id` string, uuid, required — Stable unique identifier for the user. Treat as opaque even though the underlying format is a UUID — never parse or construct it client-side.
    - `name` string, required — The user's display name, typically `given_name family_name` but may diverge for users who supplied an alternative.
    - `given_name` string, required — The user's first / given name, as supplied at registration or sync from the identity provider.
    - `family_name` string, required — The user's surname / family name, as supplied at registration or sync from the identity provider.
    - `email` string, email, required — The user's primary email address. Used for sign-in, notification delivery, and forms-of-identity verification.
    - `email_verified` boolean, required — Whether the user has verified their email address
    - `organisation_id` string, uuid, required — ID of the organisation this user is scoped to. Every user belongs to exactly one organisation; cross-org access is modelled via separate user accounts.
    - `organisation_name` string, nullable, required — Human-readable name of the user's organisation, denormalised onto the User payload so callers don't need to make a second fetch. `null` when the organisation has been archived.
    - `site_ids` string[], required — The IDs of the sites that this user belongs to
    - `avatar_id` string, uuid, nullable, required — ID of the `Media` record holding the user's avatar image. Use `avatar.urls` on this same payload to render directly without a separate Media fetch. `null` when the user hasn't uploaded one.
    - `avatar` Media
      - `id` string, uuid, required — Unique identifier of the uploaded media item, returned from `createMedia`. Pass this ID into any field that accepts a media reference (logos, hero images, product images, etc.).
      - `file_name` string, required — Original filename of the uploaded asset, preserved as provided at upload time. Used for display in the media library and as a hint when serving downloads.
      - `mime_type` string, required — The mime type of the media item.
      - `original_url` string, required — The url of the media resource.
      - `size` integer, required — The size of the media item in bytes.
      - `url` string, required — The url of the converted media resource.
    - `cashier_id` string, nullable — Optional cashier identifier linking this user to a Point of Sale cashier profile. `null` when the user isn't a POS operator.
    - `status` string, required — Lifecycle status of the user account. `active` for normal sign-in, `disabled` for accounts locked by an admin.
    - `2fa_enabled` boolean — Whether 2FA is enabled for the user
    - `twofa_enabled` boolean, required — Whether 2FA is enabled for the user
    - `created_at` string, date-time, required — The date and time the user was created
    - `updated_at` string, date-time, required — The date and time the user was last updated
    - `managed_by_sso` boolean, required — Whether the user is managed by SSO
    - `whitelisted_internal_user` boolean — Whether the user is a whitelisted internal user

## Other responses

- `401` — The user is unauthenticated

---

[API](https://skmtc.dev/try/apis/trybe-api.md) · [All operations](https://skmtc.dev/try/apis/trybe-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/try/trybe-api/revisions/f37f92702da5/schema)
