List Users
GET/api/v2/users
Returns a paginated list of users for the current tenant, with Spatie QueryBuilder filtering and sorting. Includes soft-deleted users.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Tenant scoping: Results are restricted to users who are members of the current tenant. The users table lives on the central connection and is shared across all tenants, so without scoping every tenant's settings UI would see every user in the entire installation.
Authentication: Requires Bearer token.
Response notes: Each user includes roles (the user's assigned roles with id, name, description, guard_name) and permissions (a flattened, de-duplicated list of permission names across all assigned roles) — both are always present since the endpoint eager-loads roles with their permissions. features.granular_permissions reflects the per-tenant feature flag; frontends treat anything other than true as OFF.
Request
Responses
- 200
- 401
- 403
- 429
OK
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.