Platform

Users and identities

The users API, linked identities, MFA administration and SCIM provisioning.

Users API#

Call these from your server with your API key (Authorization: Bearer <API key>). They act on the key's environment only.

MethodPathDoes
GET/app/usersList users
POST/app/usersCreate a user (the password policy applies)
GET/app/users/:idGet one user
PUT/app/users/:idUpdate a user
DELETE/app/users/:idDelete a user
DELETE/app/users/:id/sessions/:sessionIdEnd one session

Linked identities#

GET /users/:id/identities lists the social-provider identities linked to a user, and DELETE /users/:id/identities/:identityId unlinks one.

MFA administration#

Under /app/users/:userId/mfa/: status, enroll, verify, disable and reset. Reset is the recovery path for a user who lost their authenticator.

SCIM provisioning#

Organizations can connect a directory (Okta, Microsoft Entra ID and others) over SCIM 2.0 at /scim/v2/:orgId. Users and groups can be listed, filtered, created, replaced, patched and deleted. Each directory has its own bearer token, stored hashed. Deprovisioning a user blocks sign-in and ends all their sessions.