v4

OpenAPI 3.0.1Apache 2.02026-08-016169702.3 MB
User search

Find users with permissions

Returns a list of users who fulfill these criteria:

  • their user attributes match a search string.
  • they have a set of permissions for a project or issue.

If no search string is provided, a list of all users with the permissions is returned.

This operation takes the users in the range defined by startAt and maxResults, up to the thousandth user, and then returns only the users from that range that match the search string and have permission for the project or issue. This means the operation usually returns fewer users than specified in maxResults. To get all the users who match the search string and have permission for the project or issue, use Get all users and filter the records in your code.

Privacy controls are applied to the response based on the users' preferences. This could mean, for example, that the user's email address is hidden. See the Profile visibility overview for more details.

This operation can be accessed anonymously.

Permissions required:

get/rest/api/3/user/permission/search

Query parameters

querystring
Example:query

A query string that is matched against user attributes, such as displayName and emailAddress, to find relevant users. The string can match the prefix of the attribute's value. For example, query=john matches a user with a displayName of John Smith and a user with an emailAddress of johnson@example.com. Required, unless accountId is specified.

usernamestring

This parameter is no longer available. See the deprecation notice for details.

accountIdstring

A query string that is matched exactly against user accountId. Required, unless query is specified.

permissionsstring required

A comma separated list of permissions. Permissions can be specified as any:

  • permission returned by Get all permissions.

  • custom project permission added by Connect apps.

  • (deprecated) one of the following:

    • ASSIGNABLE_USER
    • ASSIGN_ISSUE
    • ATTACHMENT_DELETE_ALL
    • ATTACHMENT_DELETE_OWN
    • BROWSE
    • CLOSE_ISSUE
    • COMMENT_DELETE_ALL
    • COMMENT_DELETE_OWN
    • COMMENT_EDIT_ALL
    • COMMENT_EDIT_OWN
    • COMMENT_ISSUE
    • CREATE_ATTACHMENT
    • CREATE_ISSUE
    • DELETE_ISSUE
    • EDIT_ISSUE
    • LINK_ISSUE
    • MANAGE_WATCHER_LIST
    • MODIFY_REPORTER
    • MOVE_ISSUE
    • PROJECT_ADMIN
    • RESOLVE_ISSUE
    • SCHEDULE_ISSUE
    • SET_ISSUE_SECURITY
    • TRANSITION_ISSUE
    • VIEW_VERSION_CONTROL
    • VIEW_VOTERS_AND_WATCHERS
    • VIEW_WORKFLOW_READONLY
    • WORKLOG_DELETE_ALL
    • WORKLOG_DELETE_OWN
    • WORKLOG_EDIT_ALL
    • WORKLOG_EDIT_OWN
    • WORK_ISSUE
issueKeystring

The issue key for the issue.

projectKeystring

The project key for the project (case sensitive).

startAtinteger

The index of the first item to return in a page of results (page offset).

maxResultsinteger

The maximum number of items to return per page.

Response

Returned if the request is successful.

accountIdstring

The account ID of the user, which uniquely identifies the user across all Atlassian products. For example, 5b10ac8d82e05b22cc7d4ef5. Required in requests.

accountType'atlassian' | 'app' | 'customer' | 'unknown'

The user account type. Can take the following values:

  • atlassian regular Atlassian user account
  • app system account used for Connect applications and OAuth to represent external systems
  • customer Jira Service Desk account representing an external service desk
activeboolean

Whether the user is active.

appTypestring

The app type of the user account when accountType is 'app'. Can take the following values:

  • service Service Account
  • agent Rovo Agent Account
  • unknown Unknown app type
displayNamestring

The display name of the user. Depending on the user’s privacy setting, this may return an alternative value.

emailAddressstring

The email address of the user. Depending on the user’s privacy setting, this may be returned as null.

expandstring

Expand options that include additional user details in the response.

guestboolean

Whether the user is a guest.

keystring

This property is no longer available and will be removed from the documentation soon. See the deprecation notice for details.

localestring

The locale of the user. Depending on the user’s privacy setting, this may be returned as null.

namestring

This property is no longer available and will be removed from the documentation soon. See the deprecation notice for details.

selfstring uri

The URL of the user.

timeZonestring

The time zone specified in the user's profile. If the user's time zone is not visible to the current user (due to user's profile setting), or if a time zone has not been set, the instance's default time zone will be returned.