Endpoint
Authentication
This endpoint requires an OAuth access token. Send it as a bearer token:users:read
Query Parameters
Request Example
Response
Success Response
Status Code:200 OK
Response Fields
User Object
Each object in theusers array contains:
Group Reference Object
Each object in a user’sgroups array contains:
Error Responses
400 Bad Request
Returned when the access token has no user behind it.client_credentials tokens act as the admin who created the application, so this applies only to
tokens issued before application creators were recorded.
401 Unauthorized
Returned when the access token is missing, unknown, revoked, or expired, or when anX-API-Key was
sent instead of a bearer token. See OAuth error responses.
403 Forbidden
Returned when the token does not carry the required scope.404 Not Found
Returned when the organization cannot be found.422 Unprocessable Entity
Returned when a query parameter fails validation (for example,limit outside the 1–250 range
or a non-numeric offset).
429 Too Many Requests
Returned when your organization exceeds its per-minute request limit.500 Internal Server Error
Returned when the users could not be retrieved due to a server error.Notes
The user directory is organization-wide. Unlike tasks and workflows, results are not narrowed to what the
access token’s user can see -
users:read grants the whole directory.Set
include_groups=true only when you need group memberships - the groups array is empty otherwise.
Use total_count together with limit and offset to page through large result sets.Use Cases
This endpoint is useful for:- User directory sync - Mirror your organization’s users into an external system
- Role-based reporting - Filter users by role to audit access levels
- Mention pickers - Resolve user IDs for
mention_user_idswhen adding comments - Group membership lookup - Retrieve which groups each user belongs to