Get User
Returns the details of a single user the caller is allowed to see.
GET /api/users/:id
Who may read which user
Two conditions apply, and both have to hold.
First, the caller needs an administrative role: an organization admin, a global admin, or a
token that acts with admin privileges. Any other session is refused with 403.
Second, the answer is narrowed by the caller's customer scope, the same scope that governs
List Users, /api/customers and the monitor endpoints. A user is
never "owned" by a customer, the link is the customer access assignment, so visibility is
derived from it:
| Caller | Users readable |
|---|---|
| Organization admin, global admin, organization-wide API token | Every user of the organization (a global admin also beyond it) |
| Customer-scoped API token, or a session restricted to specific customers | Only users assigned to at least one of the caller's customers, plus the caller |
A user outside that scope answers 404 userNotFound, the same status as a user that does not
exist: an invisible user and a nonexistent one are deliberately not distinguishable.
The customerAccess array is reduced to the customers the caller is scoped to. A colleague
who also works for other customers does not disclose them here.
Cross-organization access is impossible except for a global admin, the organization boundary is applied before the customer scope.
Response
{
"id": "A7QJr8SOjsnTst1n9YQSYxim1GeEPht7",
"email": "max@deinkunde.com",
"name": "Max Mustermann",
"firstName": "Max",
"lastName": "Mustermann",
"image": null,
"role": "admin",
"isActive": true,
"createdAt": "2026-01-01T00:00:00.000Z",
"customerAccess": [
{ "customerId": 42, "customerName": "Beispiel GmbH" }
]
}Common errors
| Status | data.code | Meaning |
|---|---|---|
| 401 | unauthorized | No valid session or token. |
| 403 | forbidden | The caller is not an admin. |
| 400 | userIdRequired | No user id in the path. |
| 400 | organizationIdRequired | The session carries no organization. |
| 404 | userNotFound | No such user, or the user is outside the caller's organization or customer scope. |