Skip to main content
GET
List of Users

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Query Parameters

filter[id]
string

Filter by an exact ID match.

Example:

"drusr_01hq8xyzabc123def456ghi789"

Filter by a partial ID match.

Example:

"d662"

filter[integration_id]
string

Filter by the associated integration ID (polymorphic).

Example:

"wsitg_01hq8xyzabc123def456ghi789"

filter[integration_type]
string

Filter by the associated integration type (polymorphic morph class).

Example:

"App\\Models\\OktaCredential"

filter[parent_id]
string

For secondary users, you can filter by the parent user ID.

Example:

"drusr_01hq8xyzabc123def456ghi789"

filter[manager_id]
string

Filter by users that report to a specific manager user ID.

Example:

"drusr_01hq8xyzabc123def456ghi789"

filter[first_name]
string

Filter by the first (given) name of the user (exact match).

Example:

"Dade"

Filter by the first (given) name of the user (partial match).

Example:

"Dad"

filter[last_name]
string

Filter by the last (family) name of the user (exact match).

Example:

"Murphy"

Filter by the last (family) name of the user (partial match).

Example:

"Mur"

filter[full_name]
string

Filter by the full (first and last) name of the user (exact match).

Example:

"Dade Murphy"

Filter by the full (first and last) name of the user (partial match).

Example:

"Dade"

filter[email]
string

Filter by the email address of the user (exact match).

Filter by the email address of the user (partial match). This is useful for searching by email handle or domain name.

Example:

"dmurphy"

filter[username]
string

Filter by the username of the user (exact match).

Example:

"dade.murphy"

Filter by the username of the user (partial match).

Example:

"z3r0c00l"

filter[badge_id]
string

Filter by the badge ID number of the user (exact match).

Example:

"a1b2c3d4e5"

Filter by the badge ID number of the user (partial match).

Example:

"a1b2c"

filter[employee_id]
string

Filter by the employee ID number of the user (exact match).

Example:

"a1b2c3d4e5"

Filter by the employee ID number of the user (partial match).

Example:

"a1b2c"

filter[employee_alt_id]
string

Filter by the alternate employee ID number of the user (exact match).

Example:

"a1b2c3d4e5"

Filter by the alternate employee ID number of the user (partial match).

Example:

"a1b2c"

Search organization metadata key/value pairs for any partial string. For more granularity and specific keys, use the Policy Users endpoint for a specific Directory Dimension or Attribute.

Example:

"Engineer"

Search custom organization business logic metadata key/value pairs for any partial string.

filter[manager]
boolean

Filter users that are managers (have direct reports) or are not managers (individual contributors).

filter[state]
string

The state of the Directory User. See the Response Body below for more details on each state type.

Example:

"active"

filter[created_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[created_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[updated_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[updated_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[expires_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[expires_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[expired_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[expired_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[deactivated_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[deactivated_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[deleted_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[deleted_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[provisioned_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[provisioned_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[deprovisioned_pending_deactivation]
string<boolean>

Get all active records that have been deprovisioned by the integration vendor

Example:

true

filter[deprovisioned_before]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[deprovisioned_after]
string<date>

Filter results by date. Any parsable date format can be used.

Example:

"2025-01-01 or 2025-01-01 12:30:00 or 2025-01-01T12:30:00Z"

filter[trashed]
string

Can be a value of with (response will contain deleted items as well), only (will contain only deleted items), or any arbitrary value (will contain only not deleted items).

include
enum<string>[]
Available options:
manager-user,
manager-user-count,
manager-user-exists,
workspace-user,
workspace-user-count,
workspace-user-exists,
parent-user,
parent-user-count,
parent-user-exists,
secondary-users,
secondary-users-count,
secondary-users-exists,
direct-report-users,
direct-report-users-count,
direct-report-users-exists,
directory-identities,
directory-identities-count,
directory-identities-exists,
policy-conditions,
policy-conditions-count,
policy-conditions-exists,
policy-users,
policy-users-count,
policy-users-exists,
policy-rules-manifest,
policy-rules-manifest-count,
policy-rules-manifest-exists,
policy-rules-qualified,
policy-rules-qualified-count,
policy-rules-qualified-exists,
policy-rules-staged,
policy-rules-staged-count,
policy-rules-staged-exists,
policy-rulesets,
policy-rulesets-count,
policy-rulesets-exists
filter
string
page
string
sort
string

Response

The collection of DirectoryUserDetailedResponseData

id
string
required
Example:

"drusr_01hq8xyzabc123def456ghi789"

state
enum<string>
required

The state of the directory user

Available options:
staged,
active,
expiring,
expired,
suspended,
deactivated
Example:

"active"

manager_id
string | null
required

The ID of the manager

Example:

"drusr_01kam9z5z71f7r4hhrm2ydxkhn"

is_manager
boolean
required

Whether or not the user is a people manager with direct reports

Example:

true

first_name
string
required

The first (given) name of the user

Example:

"Dade"

last_name
string
required

The last (family) name of the user

Example:

"Murphy"

full_name
string
required

The first and last name of the user

Example:

"Dade Murphy"

email
string
required

The email address of the user

username
string | null
required

The username of the user. Unless overridden, this is usually the email address handle

Example:

"dmurphy"

badge_id
string | null
required

The badge ID number of the user. This value is dynamically obtained from the primary integration based on the badge_id_profile_key

employee_id
string | null
required

The employee ID number of the user. This value is dynamically obtained from the primary integration based on the employee_id_profile_key

employee_alt_id
string | null
required

An alternative/secondary employee ID number of the user. This value is dynamically obtained from the primary integration based on the employee_alt_id_profile_key

timestamp
DirectoryUserTimestampResponseData · object
required

The timestamps for the directory user record

org
object
required

The user's organization metadata based on their dimension attributes

Example:
metadata
object
required

The user's custom key/value metadata added by someone or automation in your organization

Example:
count
DirectoryUserCountResponseData · object
required

Counts of related resources for the directory user

included
DirectoryUserIncludedResponseData · object
required

Related resources for the directory user. Use include parameter with a comma separated list of resources to fetch related data

API hyperlinks related to the directory user record