---
title: "Create an Identity"
method: POST
path: "/admin/identities"
tags: ["identity"]
---

# Create an Identity

`POST /admin/identities`

Create an [identity](https://www.ory.sh/docs/kratos/concepts/identity-user-model).  This endpoint can also be used to
[import credentials](https://www.ory.sh/docs/kratos/manage-identities/import-user-accounts-identities)
for instance passwords, social sign in configurations or multifactor methods.

## Request body

- CreateIdentityBody — Create Identity Body
  - `credentials` IdentityWithCredentials — Create Identity and Import Credentials
    - `oidc` IdentityWithCredentialsOidc — Create Identity and Import Social Sign In Credentials
      - `config` IdentityWithCredentialsOidcConfig
        - `providers` IdentityWithCredentialsOidcConfigProvider[] — A list of OpenID Connect Providers
          - `organization` string, uuid4, nullable
          - `provider` string, required — The OpenID Connect provider to link the subject to. Usually something like `google` or `github`.
          - `subject` string, required — The subject (`sub`) of the OpenID Connect connection. Usually the `sub` field of the ID Token.
          - `use_auto_link` boolean — If set, this credential allows the user to sign in using the OpenID Connect provider without setting the subject first.
    - `password` IdentityWithCredentialsPassword — Create Identity and Import Password Credentials
      - `config` IdentityWithCredentialsPasswordConfig — Create Identity and Import Password Credentials Configuration
        - `hashed_password` string — The hashed password in [PHC format](https://www.ory.sh/docs/kratos/manage-identities/import-user-accounts-identities#hashed-passwords)
        - `password` string — The password in plain text if no hash is available.
        - `use_password_migration_hook` boolean — If set to true, the password will be migrated using the password migration hook.
    - `saml` IdentityWithCredentialsSaml — Payload to import SAML credentials
      - `config` IdentityWithCredentialsSamlConfig — Payload of SAML providers
        - `providers` IdentityWithCredentialsSamlConfigProvider[] — A list of SAML Providers
          - `organization` string, uuid4, nullable
          - `provider` string, required — The SAML provider to link the subject to.
          - `subject` string, required — The unique subject of the SAML connection. This value must be immutable at the source.
  - `external_id` string — ExternalID is an optional external ID of the identity. This is used to link the identity to an external system. If set, the external ID must be unique across all identities.
  - `metadata_admin` unknown
  - `metadata_public` unknown
  - `organization_id` string, uuid4, nullable
  - `recovery_addresses` RecoveryIdentityAddress[] — RecoveryAddresses contains all the addresses that can be used to recover an identity. Use this structure to import recovery addresses for an identity. Please keep in mind that the address needs to be represented in the Identity Schema or this field will be overwritten on the next identity update.
    - `created_at` string, date-time — CreatedAt is a helper struct field for gobuffalo.pop.
    - `id` string, uuid
    - `updated_at` string, date-time — UpdatedAt is a helper struct field for gobuffalo.pop.
    - `value` string, required
    - `via` string, required
  - `schema_id` string, required — SchemaID is the ID of the JSON Schema to be used for validating the identity's traits.
  - `state` 'active' | 'inactive' — State is the identity's state. active StateActive inactive StateInactive
  - `traits` object, required — Traits represent an identity's traits. The identity is able to create, modify, and delete traits in a self-service manner. The input will always be validated against the JSON Schema defined in `schema_url`.
  - `verifiable_addresses` VerifiableIdentityAddress[] — VerifiableAddresses contains all the addresses that can be verified by the user. Use this structure to import verified addresses for an identity. Please keep in mind that the address needs to be represented in the Identity Schema or this field will be overwritten on the next identity update.
    - `created_at` string, date-time — When this entry was created
    - `id` string, uuid — The ID
    - `status` string, required — VerifiableAddressStatus must not exceed 16 characters as that is the limitation in the SQL Schema
    - `updated_at` string, date-time — When this entry was last updated
    - `value` string, required — The address value example foo@user.com
    - `verified` boolean, required — Indicates if the address has already been verified
    - `verified_at` string, date-time
    - `via` 'email' | 'sms', required — The delivery method

## Response `201`

identity

- Identity — An [identity](https://www.ory.sh/docs/kratos/concepts/identity-user-model) represents a (human) user in Ory.
  - `created_at` string, date-time — CreatedAt is a helper struct field for gobuffalo.pop.
  - `credentials` object — Credentials represents all credentials that can be used for authenticating this identity.
  - `external_id` string — ExternalID is an optional external ID of the identity. This is used to link the identity to an external system. If set, the external ID must be unique across all identities.
  - `id` string, uuid, required — ID is the identity's unique identifier. The Identity ID can not be changed and can not be chosen. This ensures future compatibility and optimization for distributed stores such as CockroachDB.
  - `metadata_admin` unknown
  - `metadata_public` unknown
  - `organization_id` string, uuid4, nullable
  - `recovery_addresses` RecoveryIdentityAddress[] — RecoveryAddresses contains all the addresses that can be used to recover an identity.
    - `created_at` string, date-time — CreatedAt is a helper struct field for gobuffalo.pop.
    - `id` string, uuid
    - `updated_at` string, date-time — UpdatedAt is a helper struct field for gobuffalo.pop.
    - `value` string, required
    - `via` string, required
  - `schema_id` string, required — SchemaID is the ID of the JSON Schema to be used for validating the identity's traits.
  - `schema_url` string, required — SchemaURL is the URL of the endpoint where the identity's traits schema can be fetched from. format: url
  - `state` 'active' | 'inactive' — State is the identity's state. This value has currently no effect. active StateActive inactive StateInactive
  - `state_changed_at` string, date-time
  - `traits` unknown, required
  - `updated_at` string, date-time — UpdatedAt is a helper struct field for gobuffalo.pop.
  - `verifiable_addresses` VerifiableIdentityAddress[] — VerifiableAddresses contains all the addresses that can be verified by the user.
    - `created_at` string, date-time — When this entry was created
    - `id` string, uuid — The ID
    - `status` string, required — VerifiableAddressStatus must not exceed 16 characters as that is the limitation in the SQL Schema
    - `updated_at` string, date-time — When this entry was last updated
    - `value` string, required — The address value example foo@user.com
    - `verified` boolean, required — Indicates if the address has already been verified
    - `verified_at` string, date-time
    - `via` 'email' | 'sms', required — The delivery method

## Other responses

- `400` — errorGeneric
- `409` — errorGeneric
- `default` — errorGeneric

---

[API](https://skmtc.net/ory/apis/ory-identities-api.md) · [All operations](https://skmtc.net/ory/apis/ory-identities-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/ory/ory-identities-api/versions/7a0df90e2f13/schema)
