/v2/mgmt/user/search/testAuthorization
Descope Project ID and Management Key Project ID:Management Key as bearer token.
In: header
Request Body
application/json
Search for specific login ID
If not empty then users must be members of at least one of these tenants
If not empty then users must have one of the specified roles
Default is 100 if not specified
int32Full text search across relevant columns
Page number starting with 0 for the first page
int32Bring only users that have SSO external IDs
falseReturn also users which are test users
Return only test users
falseCustom attributes as key-value pairs. Keys must be strings; values can be strings, numbers, booleans, or arrays.
{
"attribute-key": "attribute-value"
}If not empty then users must be in one of those statuses
Lower bound on user creation time, inclusive. Unix timestamp in milliseconds, sent as a string (e.g. "1743465600000").
Upper bound on user creation time, inclusive. Unix timestamp in milliseconds, sent as a string (e.g. "1746057600000").
Lower bound on user modification time, inclusive. Unix timestamp in milliseconds, sent as a string.
Upper bound on user modification time, inclusive. Unix timestamp in milliseconds, sent as a string.
Bring only users that provisioned or updated by SCIM
If provided, filter users by whether their email is verified
If provided, filter users by whether their phone is verified
Direct row offset for pagination (0-based). When set to a positive value, this takes precedence over the page-based offset (page * limit).
int32If not empty then users must have one of the specified recovery emails (exact match)
If not empty then users must have one of the specified recovery phones (exact match)
If provided, filter users by whether their recovery email is verified
If provided, filter users by whether their recovery phone is verified
Structured field filters (wildcard LIKE, negation, array match). When set, these are ANDed with the scalar filters above. Field names must match the backend's searchable user columns; unknown fields are ignored. Only honored for widget-originated requests (x-descope-widget-id), gated by the MGMT_SEARCH_USERS_SEARCH_FIELDS feature flag (default on).
Lower bound on the user's last authentication time, inclusive. Unix timestamp in milliseconds, sent as a string (e.g. "1743465600000"). Users that never authenticated are excluded.
Upper bound on the user's last authentication time, inclusive. Unix timestamp in milliseconds, sent as a string. Users that never authenticated are excluded.
Search test users, using a valid management key.
curl -X POST "https://api.descope.com/v2/mgmt/user/search/test" \ -H "Content-Type: application/json" \ -d '{}'{ "users": [ { "loginIds": [ "string" ], "userId": "string", "name": "string", "email": "string", "phone": "string", "verifiedEmail": true, "verifiedPhone": true, "roleNames": [ "string" ], "userTenants": [ { "tenantId": "string", "roleNames": [ "string" ], "tenantName": "string", "permissions": [ "string" ], "roleIds": [ "string" ] } ], "status": "string", "externalIds": [ "string" ], "picture": "string", "test": false, "customAttributes": { "attribute-key": "attribute-value" }, "createdTime": 0, "TOTP": false, "SAML": false, "OAuth": { "property1": false, "property2": false }, "webauthn": true, "password": true, "ssoAppIds": [ "string" ], "givenName": "string", "middleName": "string", "familyName": "string", "editable": true, "SCIM": true, "push": true, "permissions": [ "string" ], "OIDC": true, "consentExpiration": 0, "recoveryEmail": "string", "verifiedRecoveryEmail": true, "recoveryPhone": "string", "verifiedRecoveryPhone": true, "modifiedTime": 0, "roleIds": [ "string" ], "recoveryCodes": true } ], "total": 0}export interface Response {users?: {loginIds?: string[]userId?: stringname?: stringemail?: stringphone?: stringverifiedEmail?: booleanverifiedPhone?: booleanroleNames?: string[]userTenants?: UserTenants[]status?: stringexternalIds?: string[]picture?: stringtest?: boolean/** * Custom attributes as key-value pairs. Keys must be strings; values can be strings, numbers, booleans, or arrays. */customAttributes?: {[k: string]: string}createdTime?: numberTOTP?: booleanSAML?: booleanOAuth?: {[k: string]: boolean}webauthn?: booleanpassword?: booleanssoAppIds?: string[]givenName?: stringmiddleName?: stringfamilyName?: stringeditable?: booleanSCIM?: booleanpush?: booleanpermissions?: string[]OIDC?: booleanconsentExpiration?: numberrecoveryEmail?: stringverifiedRecoveryEmail?: booleanrecoveryPhone?: stringverifiedRecoveryPhone?: booleanmodifiedTime?: number/** * roleIds holds the IDs of this entry's roles. Order is NOT guaranteed to match * roleNames — do not pair them by index. Use roleIds or roleNames independently. */roleIds?: string[]/** * whether the user has set up recovery codes */recoveryCodes?: boolean}[]total?: number}export interface UserTenants {tenantId?: stringroleNames?: string[]tenantName?: stringpermissions?: string[]/** * roleIds holds the IDs of this entry's roles. Order is NOT guaranteed to match * roleNames — do not pair them by index. Use roleIds or roleNames independently. */roleIds?: string[]}