---
title: "Get a list of users"
method: GET
path: "/users"
tags: ["Users"]
---

# Get a list of users

`GET /users`

Get a list of the users in your account. There are three main types of searches you can do with this method:

1. Search for a user by username. If you provide the `username` parameter in your call, then only the user who exactly matches that username will be in the list of matches. Any other parameters are ignored.
1. Search for a user by individual filter fields (`nickname`,`email`,`role`,`status`,`homeDir`). Users in the list will be ones who match all of the filters you choose to search by. For example, you could look for users with the "admin" `role` AND `email` addresses ending in "*@acme.com". 
1. Search for a user by search string. If you provide the `search` parameter, users whose nickname OR email OR role OR homeDir match value your provide.

**Notes:**

- You must be an [admin-level user](/docs/account/04-users/00-introduction#managing-user-roles-and-permissions) to use this.
- The homeDir is the full path to the user's home directory, not a resource ID or hash.

## Query parameters

- `username` string
- `homeResource` string
- `nickname` string
- `email` string
- `role` string
- `status` integer
- `search` string
- `offset` integer
- `sort` string
- `limit` integer
- `include` string

## Headers

- `ev-api-key` string, required
- `ev-access-token` string, required

## Response `200`

Successful Operation

- UserCollectionResponse
  - `responseStatus` integer — Http status code of the response.
  - `totalResults` integer — Total results found.
  - `returnedResults` integer — Number of results returned.
  - `data` User[]
    - `id` integer — ID of the user.
    - `type` string — Type of object being returned. Always "user"
    - `attributes` UserAttributes — Attributes of the user including expiration, home directory, and permissions.
      - `status` 0 | 1, required — Indicates user activity status. `0` means the user is locked and cannot log in. `1` means the user is active and can log in.
      - `locked` boolean — `true` if the user is locked and cannot log in.
      - `expiration` string — Timestamp of user expiration.
      - `created` string, date-time, required — Timestamp of user creation.
      - `modified` string, date-time, required — Timestamp of user modification.
      - `accessTimestamp` string — Timestamp of most recent successful user login.
      - `accountName` string, required — Name of the account this user belongs to.
      - `username` string, required — Username of the user.
      - `nickname` string, required — Nickname of the user.
      - `email` string — Email address of the user.
      - `homePath` string — Path to the user's home folder.
      - `permissions` UserPermissions, required
        - `download` boolean, required — Download permission flag
        - `upload` boolean, required — Upload permission flag
        - `modify` boolean, required — Modify permission flag
        - `delete` boolean, required — Delete permission flag
        - `list` boolean, required — View folder contents permission flag
        - `changePassword` boolean, required — Change (own) password permission flag
        - `share` boolean, required — Sharing permission flag
        - `notification` boolean, required — Notifications permission flag
        - `viewFormData` boolean, required — Access Form Data permission flag. If true, user can view submissions that have been stored for a receive folder. This includes any data submitted in the receive folder form.
        - `deleteFormData` boolean, required — Delete form data permission flag. If true, user can remove data that was submitted for a receive folder. This applies only to data submitted in the receive folder form, not the actual files uploaded.
      - `role` 'user' | 'admin' | 'master', required — User's access level
      - `timeZone` string, required — User's timezone. See <a href='https://php.net/manual/en/timezones.php' target='blank'>this page</a> for allowed values.
      - `onboarding` boolean, required — Whether the onboarding help system is enabled for this user. `true` means that additional help popups are displayed in the web application for this user.
      - `firstLogin` boolean — `true` if the user has logged into the system.
    - `relationships` object — Home resource and owner account relationship data for the user.
      - `homeResource` object
        - `data` object
          - `type` 'resource' — Type is resource.
          - `id` integer — ID of home directory resource.
      - `ownerAccount` object, required
        - `data` object
          - `type` 'account' — Type is account.
          - `id` integer — ID of the account.
  - `included` union[]
    - union
      - Account — Object contains all account properties.
        - `id` integer — Account ID
        - `type` 'account' — Type of item. "account"
        - `attributes` AccountAttributes — unresolved $ref
        - `relationships` object
          - `masterUser` object
            - `data` object
              - …
      - Resource — All properties of the resource.
        - `id` integer
        - `type` 'resource' — Type of item. "resource"
        - `attributes` ResourceAttributes — Attributes of resource
          - `hash` string — Unique hash of the resource.
          - `name` string — Resource name, e.g. the name of the file or folder.
          - `extension` string — Resource extension. Property exists only if resource `type` is file.
          - `type` 'file' | 'dir' — Type of the resource.
          - `createdBy` string — Username of the creator.
          - `uploadDate` string, date-time — Timestamp of resource upload.
          - `createdAt` string, date-time — Date-time of resource creation.
          - `updatedAt` string, date-time — Date-time of resource modification.
          - `accessedAt` string, date-time — Date-time of the time when resource was accessed.
          - `createdTime` integer — UNIX timestamp of resource creation
          - `updatedTime` integer — UNIX timestamp of resource modification
          - `accessedTime` integer — UNIX timestamp of last access
          - `path` string — Full path to the resource.
          - `size` integer — Resource size in bytes
          - `fileCount` integer — Number of files within folder. null if resource type is a file.
          - `previewable` true | false — Can resource be previewed. Property equals `null` if resource `type` is dir.
        - `relationships` object
          - `share` object
            - `data` object
              - …
          - `notifications` object[]
            - `data` object
              - …
          - `directFile` object
            - `data` object
              - …
          - `parentResource` object
            - `data` object
              - …

---

[API](https://skmtc.net/prismic/apis/exavault-api.md) · [All operations](https://skmtc.net/prismic/apis/exavault-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/prismic/exavault-api/revisions/a1bd874b5960/schema)
