Platform
Users and identities
The users API, linked identities, MFA administration and SCIM provisioning.
Users API#
Call these from your server with your API key (Authorization: Bearer <API key>). They act on the key's environment only.
| Method | Path | Does |
|---|---|---|
| GET | /app/users | List users |
| POST | /app/users | Create a user (the password policy applies) |
| GET | /app/users/:id | Get one user |
| PUT | /app/users/:id | Update a user |
| DELETE | /app/users/:id | Delete a user |
| DELETE | /app/users/:id/sessions/:sessionId | End one session |
Linked identities#
GET /users/:id/identities lists the social-provider identities linked to a user, and DELETE /users/:id/identities/:identityId unlinks one.
MFA administration#
Under /app/users/:userId/mfa/: status, enroll, verify, disable and reset. Reset is the recovery path for a user who lost their authenticator.
SCIM provisioning#
Organizations can connect a directory (Okta, Microsoft Entra ID and others) over SCIM 2.0 at /scim/v2/:orgId. Users and groups can be listed, filtered, created, replaced, patched and deleted. Each directory has its own bearer token, stored hashed. Deprovisioning a user blocks sign-in and ends all their sessions.