Manage users within an account. Users are individuals who can log in and perform actions. Each account can have multiple users with different roles. Includes user creation with email verification, password management, suspension, and multi-factor authentication (MFA) setup.
Forgot my password
Sends an email containing a reset password token.
query Parameters
account_idlanguageSupported Locales
Forgot my password › Request Body
emailEmail address of the user requesting a password reset
Forgot my password › Responses
Successful Response
emailobjectreset_link_sentReset a user password
Sends an email containing a reset password token.
Required scope(s): users:admin
path Parameters
user_idquery Parameters
account_idReset a user password › Request Body
invalidate_current_passwordIf true, immediately invalidates the current password, forcing the user to reset
Reset a user password › Responses
Successful Response
emailobjectreset_link_sentReset password confirmation
Change a user password if the reset password token is valid for that user.
Reset password confirmation › Request Body
tokenPassword reset token received via email
passwordNew password to set
Reset password confirmation › Responses
Successful Response
objectpassword_resetShow all users in my account
List all users in the authenticated user's account. Results can be filtered by status (active, suspended, or pending) and by email address. Pending users are those who have been invited but have not yet confirmed their account.
Required scope(s): users:read
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
pageper_pagewith_countInclude count in the response
Include count in the response
filterValid Terms:
emailstatus
Valid Operators:
==
Query separator:
;
Valid Terms:
emailstatus
Valid Operators:
==
Query separator:
;
Show all users in my account › Responses
Successful Response
Create a user
Create a new user in the account. By default, the user is created in a pending state and a verification email is sent. The user must confirm their account by following the link in the email and setting a password.
Accounts with the appropriate permissions can skip email verification and create confirmed users directly by providing a password in the request.
Required scope(s): users:write
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
skip_verificationCreate a user › Request Body
first_nameFirst name
last_nameLast name
emailEmail address, used as the login username
titleJob title
office_phoneOffice phone number
mobile_phone[0-9]+Mobile phone number (digits only)
languageSupported Locales
timezoneIANA timezone identifier (e.g. America/Montreal)
passwordPassword (only when creating confirmed users with skip_verification permission)
password_strength_requirementAn enumeration.
Create a user › Responses
Successful Response
idobjectcreatedShow a user details
Retrieve a user's details by ID. Accepts both confirmed user IDs (numeric) and pending user IDs (alphanumeric). Pending users are those who have been invited but have not yet completed email verification.
Required scope(s): users:read
path Parameters
user_id^[a-zA-Z0-9]+$ · requiredquery Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
Show a user details › Responses
Successful Response
Delete a user
Delete a user from the account. Works for both confirmed users (numeric ID) and pending users (alphanumeric ID) who have not yet completed verification.
Required scope(s): users:admin
path Parameters
user_id^[a-zA-Z0-9]+$ · requiredquery Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
Delete a user › Responses
Successful Response
idobjectdeletedUpdate a user
Update a user's profile. All fields are optional — only provided fields are updated. To change a password, the user's current password must be verified unless the caller has admin-level override permissions.
Required scope(s): users:write
path Parameters
user_id^[a-zA-Z0-9]+$ · requiredquery Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
Update a user › Request Body
first_namelast_nametitleJob title
office_phoneOffice phone number
mobile_phone[0-9]+Mobile phone number (digits only)
languageSupported Locales
timezoneIANA timezone identifier (e.g. America/Montreal)
Update a user › Responses
Successful Response
idobjectpatchedSuspend a user
Suspend a user, preventing them from logging in or performing any actions. The user's data is preserved and can be restored by unsuspending.
Required scope(s): users:admin
path Parameters
user_idquery Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
Suspend a user › Responses
Successful Response
idobjectsuspendedUnsuspend a user
Restore a previously suspended user, allowing them to log in and perform actions again.
Required scope(s): users:admin
path Parameters
user_idquery Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
Unsuspend a user › Responses
Successful Response
idobjectsuspendedConfirm a user
Confirm a pending user using the confirmation hash from the verification email. The user must set a password that meets the account's strength requirements. Once confirmed, the user can log in and access the platform.
path Parameters
user_id^[a-zA-Z0-9]+$ · requiredConfirm a user › Request Body
confirmationConfirmation hash from the verification email
passwordPassword to set for the new account
Confirm a user › Responses
Successful Response
idobjectconfirmedResend the user verification email
Resend the verification email to a pending user who has not yet confirmed their account. Rate-limited to prevent abuse.
path Parameters
user_id^[a-zA-Z0-9]+$ · requiredquery Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
Resend the user verification email › Responses
Successful Response
objectconfirmation_resentList active MFA methods
List all multi-factor authentication methods configured for the authenticated user, including their type and activation status.
Required scope(s): account:read
query Parameters
pageper_pagewith_countInclude count in the response
Include count in the response
List active MFA methods › Responses
Successful Response
List of MFA methods
Attach an MFA method
Register a new MFA method for the authenticated user. Currently supports TOTP (time-based one-time password) via authenticator apps. Returns a QR code and secret key for setup. The method must be activated with a valid code before it takes effect.
Required scope(s): account:write
Attach an MFA method › Request Body
typeAn enumeration.
descriptionAttach an MFA method › Responses
Successful Response
idMFA method id
objectObject type
createdWhether the MFA method was created
Activate an MFA method
Activate a previously registered MFA method by verifying a code generated by the authenticator app. Once activated, the user will be required to complete an MFA challenge on every login.
Required scope(s): account:write
path Parameters
mfa_idActivate an MFA method › Request Body
code^[0-9]+$ · required6 digit code from this MFA method
Activate an MFA method › Responses
Successful Response
idMFA method id
objectObject type
activatedWhether the MFA method was activated
Get MFA recovery codes
Retrieve the MFA recovery codes for the authenticated user. Recovery codes are single-use codes that can be used to log in if the user loses access to their authenticator app. Each code is a 12-character hexadecimal string.
Required scope(s): account:read
Get MFA recovery codes › Responses
Successful Response
dataList of recovery codes
Get the MFA portal URL
Get a URL to the MFA management portal where the user can manage their
authentication methods. Optionally provide a return_url to redirect
the user back after they complete their changes.
Required scope(s): account:read
query Parameters
return_urlGet the MFA portal URL › Responses
Successful Response
urlMFA portal URL
Remove an MFA method
Remove an MFA method from the authenticated user's account. If this is the user's only active MFA method, MFA will be disabled for their account.
Required scope(s): account:write
path Parameters
mfa_idRemove an MFA method › Responses
Successful Response
idMFA method id
objectObject type
deletedWhether the MFA method was deleted