Skip to main content

Endpoint

Authentication

This endpoint requires an OAuth access token. Send it as a bearer token:
Required scope: users:read

Query Parameters

Request Example

Response

Success Response

Status Code: 200 OK

Response Fields

User Object

Each object in the users array contains:

Group Reference Object

Each object in a user’s groups array contains:

Error Responses

400 Bad Request

Returned when the access token has no user behind it. client_credentials tokens act as the admin who created the application, so this applies only to tokens issued before application creators were recorded.

401 Unauthorized

Returned when the access token is missing, unknown, revoked, or expired, or when an X-API-Key was sent instead of a bearer token. See OAuth error responses.

403 Forbidden

Returned when the token does not carry the required scope.

404 Not Found

Returned when the organization cannot be found.

422 Unprocessable Entity

Returned when a query parameter fails validation (for example, limit outside the 1250 range or a non-numeric offset).

429 Too Many Requests

Returned when your organization exceeds its per-minute request limit.

500 Internal Server Error

Returned when the users could not be retrieved due to a server error.

Notes

The user directory is organization-wide. Unlike tasks and workflows, results are not narrowed to what the access token’s user can see - users:read grants the whole directory.
Set include_groups=true only when you need group memberships - the groups array is empty otherwise. Use total_count together with limit and offset to page through large result sets.

Use Cases

This endpoint is useful for:
  • User directory sync - Mirror your organization’s users into an external system
  • Role-based reporting - Filter users by role to audit access levels
  • Mention pickers - Resolve user IDs for mention_user_ids when adding comments
  • Group membership lookup - Retrieve which groups each user belongs to