Users
List Users
Lists the users of the organization that the caller is allowed to see.
GET /api/users
Who sees which users
The response is narrowed by the caller's customer scope, the same scope that governs
/api/customers, /api/incidents and the monitor endpoints. A user is never "owned" by a
customer, the link is the customer access assignment, so visibility is derived from it:
| Caller | Users returned |
|---|---|
| Organization admin, global admin, global supporter, organization-wide API or agent token | Every user of the organization (unchanged) |
| Editor without customer assignments | Every user of the organization |
| Readonly user, editor with customer assignments, customer-scoped API token, customer-bound agent token | Only users assigned to at least one of the caller's customers, plus the caller |
Caller restricted to no customer at all (for example the IM-only responder role) | Empty list |
Two further points for a customer-scoped caller:
- The
customerAccessarray of every returned user is reduced to the customers the caller is scoped to. A colleague who also works for other customers does not disclose them here. limitsis still returned. Seat allowances are organization-level plan facts, andcurrentSeatscounts the users actually contained in the response.
Cross-organization access is impossible in every case, the organization boundary is applied before the customer scope.
Response
{
"users": [
{
"id": "A7QJr8SOjsnTst1n9YQSYxim1GeEPht7",
"email": "max@deinkunde.com",
"name": "Max Mustermann",
"firstName": "Max",
"lastName": "Mustermann",
"image": null,
"role": "admin",
"isActive": true,
"createdAt": "2026-01-01T00:00:00.000Z",
"customerAccess": [
{ "customerId": 42, "customerName": "Beispiel GmbH" }
]
}
],
"limits": {
"maxSeats": null,
"currentSeats": 1,
"remainingSeats": null
}
}Common errors
| Status | data.code | Meaning |
|---|---|---|
| 401 | unauthorized | No valid session or token. |
| 400 | organizationIdRequired | The session carries no organization. |