---
title: "List all system administrators"
method: GET
path: "/system/admin/list"
tags: ["System Admin"]
---

# List all system administrators

`GET /system/admin/list`

Retrieve a paginated list of users with system administrator
privileges (SystemAdmin only). Supports `offset` (default 0)
and `limit` (default 50, max 200) query parameters. Walks the
partial-friendly idx_users_is_system_admin index.

## Query parameters

- `offset` integer
- `limit` integer

## Response `200`

System admins retrieved successfully

- InternalHandlerListSystemAdminsResponse
  - `admins` GithubComTencentWeKnoraInternalTypesUserInfo[]
    - `avatar` string
    - `can_access_all_tenants` boolean
    - `created_at` string
    - `email` string
    - `id` string
    - `is_active` boolean
    - `is_system_admin` boolean
    - `preferences` GithubComTencentWeKnoraInternalTypesUserPreferences
      - `last_active_tenant_id` integer — LastActiveTenantID remembers the last workspace the user actively switched into, so a fresh login (new device, cleared browser, new refresh token) lands them back in that workspace instead of always bouncing to their home workspace. Login / RefreshToken validate that the workspace still exists and the user still has an active membership (or CanAccessAllTenants) before honouring this preference; an invalid pointer is best-effort cleared and the user falls back to home. nil = no preference (use user.TenantID, i.e. home) *0 = "clear preference" sentinel for the partial-update endpoint (UpdateUserPreferences turns this into nil). Otherwise treat a stored *0 the same as nil. *N = preferred workspace id.
      - `oidc_only_login` boolean — OidcOnlyLogin is set server-side when an account is auto-provisioned via OIDC with a random password the user never received. The profile UI hides self-service password rotation until the user sets a known password via ChangePassword (which clears this flag).
    - `tenant_id` integer
    - `updated_at` string
    - `username` string
  - `total` integer

## Other responses

- `403` — Forbidden: not a system admin

---

[API](https://skmtc.net/tencentblueking/apis/weknora-api.md) · [All operations](https://skmtc.net/tencentblueking/apis/weknora-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/tencentblueking/weknora-api/revisions/abce9036def5/schema)
