Users
No OAuth-enabled endpoints in this section. Turn off the OAuth filter in the sidebar to see all of its endpoints.
User Management APIs
Create User
The externalId parameter is meant to be used as an external reference to the system that the user is being created from, it is required if Single Sign-On is enabled where it will be used to match the incoming NameID in SAML (or Subject in OIDC) to the correct User (more on that can be found in Single Sign On section of the documentation).Users need to be associated to Accounts via accountId attribute.
User sessionAPI credentialusers:writeRequest bodyapplication/json
accountRolesobject[]
billingobject
autopaymanualcontactany | object
creditBillingobject
Email address of the user
globalRolesobject[]
providerRolesobject[]
systemRolesobject[]
darklightsystemsystem201User Created application/json
dataUserResource
accountRolesobject[]
addressobject
billingobject
contactobject
creditBillingobject
accountorgglobalRolesobject[]
mfaUserMfaStateDerived MFA enrolment state. Populated on the single-user read only — the list endpoints
deliberately leave it undefined (PI-1116).
Derived MFA enrolment state. Populated on the single-user read only — the list endpoints deliberately leave it undefined (PI-1116).
Multi-factor types the user has enrolled and can be challenged with. Empty means the account is protected by password alone.
Recovery means the user holds for regaining access. Never a second factor — a user with only these is not protected.
providerRolesobject[]
signupobject
systemRolesobject[]
metaobject
400Invalid Request application/json
errorobject
401Unauthorized application/json
errorobject
403Forbidden: missing a required permission, or no access to this resource application/json
errorobject
404Not Found application/json
errorobject
500Internal server error application/json
errorobject
Search Users
The search for users is driven by an index and eventually consistent. That means that an update to users may take a short while before it is reflected in search results.
User sessionAPI credentialusers:readRequest bodyapplication/json
createdAtobject
500sortobjectdefault {"field":"createdAt","order":"desc"}
{"field":"createdAt","order":"desc"}200OK application/json
dataUserResource[]
accountRolesobject[]
addressobject
billingobject
contactobject
creditBillingobject
accountorgglobalRolesobject[]
mfaUserMfaStateDerived MFA enrolment state. Populated on the single-user read only — the list endpoints
deliberately leave it undefined (PI-1116).
Derived MFA enrolment state. Populated on the single-user read only — the list endpoints deliberately leave it undefined (PI-1116).
Multi-factor types the user has enrolled and can be challenged with. Empty means the account is protected by password alone.
Recovery means the user holds for regaining access. Never a second factor — a user with only these is not protected.
providerRolesobject[]
signupobject
systemRolesobject[]
metaobject
400Invalid Request application/json
errorobject
401Unauthorized application/json
errorobject
403Forbidden: missing a required permission, or no access to this resource application/json
errorobject
404Not Found application/json
errorobject
500Internal server error application/json
errorobject
Get User
To access billing information for users (credit billing), the user or credential making the API call must have the users-billing:read permissions.
User sessionAPI credentialusers:readPath parameters1
200User application/json
dataUserResource
accountRolesobject[]
addressobject
billingobject
contactobject
creditBillingobject
accountorgglobalRolesobject[]
mfaUserMfaStateDerived MFA enrolment state. Populated on the single-user read only — the list endpoints
deliberately leave it undefined (PI-1116).
Derived MFA enrolment state. Populated on the single-user read only — the list endpoints deliberately leave it undefined (PI-1116).
Multi-factor types the user has enrolled and can be challenged with. Empty means the account is protected by password alone.
Recovery means the user holds for regaining access. Never a second factor — a user with only these is not protected.
providerRolesobject[]
signupobject
systemRolesobject[]
metaobject
400Invalid Request application/json
errorobject
401Unauthorized application/json
errorobject
403Forbidden: missing a required permission, or no access to this resource application/json
errorobject
404Not Found application/json
errorobject
500Internal server error application/json
errorobject
Update User
Updates User with partial data. When updating or modifying billing data for user objects, the calling user or credential must possess a users-billing:read-write permission. This permission allows the user to make changes to the billing information associated with the specific user entity. Updating a user's email or name does not update nameOnCard on their charge cards; update it separately via PATCH /1/cards/{cardId}.
User sessionAPI credentialusers:writePath parameters1
Request bodyapplication/json
accountRolesobject[]
addressobject
billingobject
autopaymanualcontactany | object
creditBillingobject
globalRolesobject[]
providerRolesobject[]
systemRolesobject[]
darklightsystemsystem200User application/json
dataUserResource
accountRolesobject[]
addressobject
billingobject
contactobject
creditBillingobject
accountorgglobalRolesobject[]
mfaUserMfaStateDerived MFA enrolment state. Populated on the single-user read only — the list endpoints
deliberately leave it undefined (PI-1116).
Derived MFA enrolment state. Populated on the single-user read only — the list endpoints deliberately leave it undefined (PI-1116).
Multi-factor types the user has enrolled and can be challenged with. Empty means the account is protected by password alone.
Recovery means the user holds for regaining access. Never a second factor — a user with only these is not protected.
providerRolesobject[]
signupobject
systemRolesobject[]
metaobject
400Invalid Request application/json
errorobject
401Unauthorized application/json
errorobject
403Forbidden: missing a required permission, or no access to this resource application/json
errorobject
404Not Found application/json
errorobject
500Internal server error application/json
errorobject
Delete User
User sessionAPI credentialusers:writePath parameters1
204User deleted text/plain
400Invalid Request application/json
errorobject
401Unauthorized application/json
errorobject
403Forbidden: missing a required permission, or no access to this resource application/json
errorobject
404Not Found application/json
errorobject
500Internal server error application/json
errorobject
Force Logout User
User sessionAPI credentialusers:writePath parameters1
Request bodyapplication/json
falsefalse