API ReferenceManagement

User Management API Overview

Overview

The User Management APIs let you programmatically create, update, search, and delete users using a management key.

Management keys are generated from Company > Management Keys. Include the key in the Authorization header as a bearer token in the format <Project ID>:<Management Key>.

Endpoints

These are the available User Management API endpoints:

  1. Load User
  2. Load Users
  3. Get User Provider Token
  4. Search Users
  5. Get User's Login History
  6. Create User
  7. Batch Create Users
  8. Update User
  9. Update User Status
  10. Update User Email
  11. Update User Login ID
  12. Update User Phone
  13. Update User Display Name
  14. Update User Picture
  15. Update User Custom Attributes
  16. Update JWT
  17. Expire User Password
  18. Set Active Password for User
  19. Set Temporary Password for User
  20. Update User Add Tenant
  21. Update User Remove Tenant
  22. Update User Add Role
  23. Set User's Roles
  24. Update User Remove Role
  25. Add Application to User
  26. Set Applications for User
  27. Remove Application from User
  28. Log User Out of All Sessions
  29. Delete User's Passkeys
  30. Delete User
  31. Batch Delete Users
  32. Delete User's Recovery Codes

Examples

Loading a user

Use the Load User API endpoint to retrieve user information.

Important

Do not call Load User in a frequently invoked function such as authentication middleware. Instead, use custom claims to include the data you need directly in the session token.

Creating a user

  1. Call the Create User API endpoint with the desired user configuration.
  2. The user can then log in using any supported sign-in method, which changes their status from invited to active.

Updating a user

Important

Update User performs a full overwrite — any field not included in the request body will be removed from the user. For example, if a user has both an email and a phone number but the update only includes email, the phone number will be cleared. To modify individual fields without affecting other settings, use one of the specific update endpoints listed above (Update User Email, Update User Phone, etc.).

When a user's details change (for example, a role is added), their JWT is automatically refreshed within their current session.

Was this helpful?

On this page