---
title: "Create a new user"
method: POST
path: "/api/admin/user-admin"
tags: ["Users"]
---

# Create a new user

`POST /api/admin/user-admin`

Creates a new user with the given root role.

## Request body

- CreateUserSchema — The payload must contain at least one of the name and email properties, though which one is up to you. For the user to be able to log in to the system, the user must have an email.
  - `username` string — The user's username. Must be provided if email is not provided.
  - `email` string — The user's email address. Must be provided if username is not provided.
  - `name` string — The user's name (not the user's username).
  - `password` string — Password for the user
  - `rootRole` union, required — The role to assign to the user. Can be either the role's ID or its unique name.
    - integer
    - 'Admin' | 'Editor' | 'Viewer' | 'Owner' | 'Member' | 'Reader'
  - `sendEmail` boolean — Whether to send a welcome email with a login link to the user or not. Defaults to `true`.

## Response `201`

The resource was successfully created.

- CreateUserResponseSchema — An Unleash user after creation
  - `id` integer, required — The user id
  - `name` string, nullable — Name of the user
  - `email` string — Email of the user
  - `username` string, nullable — A unique username for the user
  - `imageUrl` string — URL used for the user profile image
  - `inviteLink` string — If the user is actively inviting other users, this is the link that can be shared with other users
  - `loginAttempts` integer — How many unsuccessful attempts at logging in has the user made
  - `emailSent` boolean — Is the welcome email sent to the user or not
  - `rootRole` union — Which [root role](https://docs.getunleash.io/concepts/rbac#predefined-roles) this user is assigned. Usually a numeric role ID, but can be a string when returning newly created user with an explicit string role.
    - integer
    - 'Admin' | 'Editor' | 'Viewer' | 'Owner' | 'Member' | 'Reader'
  - `seenAt` string, date-time, nullable — The last time this user logged in
  - `createdAt` string, date-time — The user was created at this time
  - `accountType` 'User' | 'Service Account' — A user is either an actual User or a Service Account
  - `permissions` string[] — Deprecated
  - `scimId` string, nullable — The SCIM ID of the user, only present if managed by SCIM
  - `seatType` string, nullable — The seat type of this user
  - `companyRole` string, nullable — The role of the user within the company.
  - `productUpdatesEmailConsent` boolean, nullable — Whether the user has consented to receive product update emails.
  - `activeSessions` integer, nullable — Count of active browser sessions for this user
  - `deletedSessions` number — Experimental. The number of deleted browser sessions after last login

## Other responses

- `400` — The request data does not match what we expect.
- `401` — Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`.
- `403` — The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation

---

[API](https://skmtc.net/unleash/apis/unleash-api-3.md) · [All operations](https://skmtc.net/unleash/apis/unleash-api-3/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/unleash/unleash-api-3/versions/b2c3116e633e/schema)
