---
title: "Get users and groups in project"
method: GET
path: "/api/admin/projects/{projectId}/access"
tags: ["Projects"]
---

# Get users and groups in project

`GET /api/admin/projects/{projectId}/access`

**Enterprise feature**

Get all groups, users and their roles, and available roles for the given project.

## Path parameters

- `projectId` string, required

## Response `200`

projectAccessSchema

- ProjectAccessSchema — An object describing access permissions for a given project.
  - `groups` GroupWithProjectRoleSchema[], required — A list of groups that have access to this project
    - `name` string — The name of the group
    - `id` integer, required — The group's ID in the Unleash system
    - `addedAt` string, date-time — When this group was added to the project
    - `roleId` integer — The ID of the role this group has in the given project
    - `roles` integer[] — A list of roles this user has in the given project
    - `description` string, nullable — A custom description of the group
    - `mappingsSSO` string[] — A list of SSO groups that should map to this Unleash group
    - `rootRole` number, nullable — A role id that is used as the root role for all users in this group. This can be either the id of the Viewer, Editor or Admin role.
    - `createdBy` string, nullable — A user who created this group
    - `createdAt` string, date-time, nullable — When was this group created
    - `users` GroupUserModelSchema[] — A list of users belonging to this group
      - `joinedAt` string, date-time — The date when the user joined the group
      - `createdBy` string, nullable — The username of the user who added this user to this group
      - `user` UserSchema, required — An Unleash user
        - `id` integer, required — The user id
        - `name` string, nullable — Name of the user
        - `email` string — Email of the user
        - `username` string, nullable — A unique username for the user
        - `imageUrl` string — URL used for the user profile image
        - `inviteLink` string — If the user is actively inviting other users, this is the link that can be shared with other users
        - `loginAttempts` integer — How many unsuccessful attempts at logging in has the user made
        - `emailSent` boolean — Is the welcome email sent to the user or not
        - `rootRole` integer — Which [root role](https://docs.getunleash.io/concepts/rbac#predefined-roles) this user is assigned
        - `seenAt` string, date-time, nullable — The last time this user logged in
        - `createdAt` string, date-time — The user was created at this time
        - `accountType` 'User' | 'Service Account' — A user is either an actual User or a Service Account
        - `permissions` string[] — Deprecated
        - `scimId` string, nullable — The SCIM ID of the user, only present if managed by SCIM
        - `seatType` string, nullable — The seat type of this user
        - `companyRole` string, nullable — The role of the user within the company.
        - `productUpdatesEmailConsent` boolean, nullable — Whether the user has consented to receive product update emails.
        - `activeSessions` integer, nullable — Count of active browser sessions for this user
        - `deletedSessions` number — Experimental. The number of deleted browser sessions after last login
    - `scimId` string, nullable — The SCIM ID of the group, only present if managed by SCIM
  - `users` UserWithProjectRoleSchema[], required — A list of users and their roles within this project
    - `isAPI` boolean — Whether this user is authenticated through Unleash tokens or logged in with a session
    - `name` string — The name of the user
    - `email` string, nullable — The user's email address
    - `id` integer, required — The user's ID in the Unleash system
    - `imageUrl` string, uri, nullable — A URL pointing to the user's image.
    - `addedAt` string, date-time — When this user was added to the project
    - `roleId` integer — The ID of the role this user has in the given project
    - `roles` integer[] — A list of roles this user has in the given project
  - `roles` RoleSchema[], required — A list of roles that are available within this project.
    - `id` integer, required — The role id
    - `type` string, required — A role can either be a global root role (applies to all projects) or a project role
    - `name` string, required — The name of the role
    - `description` string — A more detailed description of the role and what use it's intended for
    - `project` string, nullable — What project the role belongs to

## Other responses

- `401` — Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`.
- `403` — The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation

---

[API](https://skmtc.net/unleash/apis/unleash-api-3.md) · [All operations](https://skmtc.net/unleash/apis/unleash-api-3/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/unleash/unleash-api-3/versions/b2c3116e633e/schema)
