Avalara Users API

The Users API from Avalara — 5 operation(s) for users.

Business capability
Identity & Access Management BC-620.20

Operations 8

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

PUT /api/v2/passwords Change my own password · Avalara ChangePassword #
Ask an LLM
“How do I change my password through the API?”
“Can I change my password if my account uses SAML sign-in?”
Tell an agent
Change my password.
Update the password for the user I'm signed in as.
POST /api/v2/accounts/{accountId}/users Invite new users to an account · Avalara CreateUsers #
Ask an LLM
“How do I add a team member to my account?”
“Can I create several users at once?”
Tell an agent
Create users on account {accountId}.
Invite a new team member to account {accountId}.
GET /api/v2/accounts/{accountId}/users List users on an account · Avalara ListUsersByAccount #
Ask an LLM
“Who has access to a given account?”
“Can I see every user attached to one account?”
Tell an agent
List users for account {accountId}.
Show everyone with access to account {accountId}.
DELETE /api/v2/accounts/{accountId}/users/{id} Delete a user · Avalara DeleteUser #
Ask an LLM
“How do I remove someone's access to my account?”
“Which administrators are allowed to delete users?”
Tell an agent destructive · confirm first
Delete user {id} from account {accountId}.
Revoke access for user {id} on account {accountId}.
GET /api/v2/accounts/{accountId}/users/{id} Get one user · Avalara GetUser #
Ask an LLM
“Can I look up a single user's details?”
“What role and settings does a specific user have?”
Tell an agent
Get user {id} on account {accountId}.
Show the profile of user {id} in account {accountId}.
PUT /api/v2/accounts/{accountId}/users/{id} Update a user · Avalara UpdateUser #
Ask an LLM
“How do I change a user's role or contact details?”
“Does updating a user replace every field on the record?”
Tell an agent
Update user {id} on account {accountId}.
Replace the details of user {id} in account {accountId}.
GET /api/v2/accounts/{accountId}/users/{id}/entitlements Get a user's entitlements · Avalara GetUserEntitlements #
Ask an LLM
“Which API calls and companies is a user allowed to use?”
“What access level does a particular user have?”
Tell an agent
Get entitlements for user {id} on account {accountId}.
Show which companies and calls user {id} in account {accountId} can access.
GET /api/v2/users Query users across all accounts · Avalara QueryUsers #
Ask an LLM
“Can I search users across every account I can see?”
“Which accounts does a particular person have a login on?”
Tell an agent
Query users across all accounts.
Search every account's users with a filter.

Documentation

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/avalara-users-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

avalara-users-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Avalara AvaTax Users API
  description: Welcome to the AvaTax API Postman Collection!
  version: 1.0.0
servers:
- url: http://{{baseurl}}
security:
- basicAuth: []
tags:
- name: Users
paths:
  /api/v2/passwords:
    put:
      tags:
      - Users
      summary: Avalara ChangePassword
      description: 'Allows a user to change their password via an API call.


        This API allows an authenticated user to change their password via an API call. This feature is only available

        for accounts that do not use SAML integrated password validation.


        This API only allows the currently authenticated user to change their password; it cannot be used to apply to a

        different user than the one authenticating the current API call.


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPTester, FirmAdmin, FirmUser, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              example:
                oldPassword: MyOldPassword123!
                newPassword: ANewPassword567:)
      parameters:
      - name: Content-Type
        in: header
        schema:
          type: string
        example: application/json
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: putApiV2Passwords
      x-operation-id-source: derived
  /api/v2/accounts/{accountId}/users:
    post:
      tags:
      - Users
      summary: Avalara CreateUsers
      description: 'Create one or more new user objects attached to this account.


        A user represents one person with access privileges to make API calls and work with a specific account.


        Users who are account administrators or company users are permitted to create user records to invite

        additional team members to work with AvaTax.


        A newly created user will receive an email inviting them to create their password. This means that you

        must provide a valid email address for all user accounts created.


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPTester, FirmAdmin, FirmUser, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              example:
                id: 12345
                accountId: 123456789
                companyId: 123456
                userName: bobExample
                firstName: Bob
                lastName: Example
                email: bob@example.org
                postalCode: '98110'
                securityRoleId: AccountUser
                passwordStatus: UserCanChange
                isActive: true
                suppressNewUserEmail: false
      parameters:
      - name: Content-Type
        in: header
        schema:
          type: string
        example: application/json
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      - name: accountId
        in: path
        schema:
          type: string
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: postApiV2AccountsByAccountIdUsers
      x-operation-id-source: derived
    get:
      tags:
      - Users
      summary: Avalara ListUsersByAccount
      description: 'List all user objects attached to this account.

        A user represents one person with access privileges to make API calls and work with a specific account.


        When an API is called using a legacy AvaTax License Key, the API log entry is recorded as being performed by a special user attached to that license key.

        By default, this API will not return a listing of license key users. Users with registrar-level security may call this API to list license key users.


        Search for specific objects using the criteria in the `$filter` parameter; full documentation is available on Filtering in REST .

        Paginate your results using the `$top`, `$skip`, and `$orderby` parameters.


        You may specify one or more of the following values in the `$include` parameter to fetch additional nested data, using commas to separate multiple values:


        * FetchDeleted


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      parameters:
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      - name: accountId
        in: path
        schema:
          type: string
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: getApiV2AccountsByAccountIdUsers
      x-operation-id-source: derived
  /api/v2/accounts/{accountId}/users/{id}:
    delete:
      tags:
      - Users
      summary: Avalara DeleteUser
      description: 'Mark the user object identified by this URL as deleted.


        This API is available for use by account and company administrators only.


        Account and company administrators may only delete users within the appropriate organizations

        they control.


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, BatchServiceAdmin, CompanyAdmin, Compliance Root User, CSPTester, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TreasuryAdmin.'
      parameters:
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      - name: accountId
        in: path
        schema:
          type: string
        required: true
      - name: id
        in: path
        schema:
          type: string
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: deleteApiV2AccountsByAccountIdUsersById
      x-operation-id-source: derived
    get:
      tags:
      - Users
      summary: Avalara GetUser
      description: 'Get the user object identified by this URL.

        A user represents one person with access privileges to make API calls and work with a specific account.


        You may specify one or more of the following values in the `$include` parameter to fetch additional nested data, using commas to separate multiple values:


        * FetchDeleted


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      parameters:
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      - name: accountId
        in: path
        schema:
          type: string
        required: true
      - name: id
        in: path
        schema:
          type: string
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: getApiV2AccountsByAccountIdUsersById
      x-operation-id-source: derived
    put:
      tags:
      - Users
      summary: Avalara UpdateUser
      description: 'Replace the existing user object at this URL with an updated object.

        A user represents one person with access privileges to make API calls and work with a specific account.

        All data from the existing object will be replaced with data in the object you PUT.

        To set a field''s value to null, you may either set its value to null or omit that field from the object you post.


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPTester, FirmAdmin, FirmUser, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              example:
                id: 12345
                accountId: 123456789
                companyId: 123456
                userName: bobExample
                firstName: Bob
                lastName: Example
                email: bob@example.org
                postalCode: '98110'
                securityRoleId: AccountUser
                passwordStatus: UserCanChange
                isActive: true
                suppressNewUserEmail: false
      parameters:
      - name: Content-Type
        in: header
        schema:
          type: string
        example: application/json
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      - name: accountId
        in: path
        schema:
          type: string
        required: true
      - name: id
        in: path
        schema:
          type: string
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: putApiV2AccountsByAccountIdUsersById
      x-operation-id-source: derived
  /api/v2/accounts/{accountId}/users/{id}/entitlements:
    get:
      tags:
      - Users
      summary: Avalara GetUserEntitlements
      description: 'Return a list of all entitlements to which this user has rights to access.

        Entitlements are a list of specified API calls the user is permitted to make, a list of identifier numbers for companies the user is

        allowed to use, and an access level identifier that indicates what types of access roles the user is allowed to use.

        This API call is intended to provide a validation endpoint to determine, before making an API call, whether this call is likely to succeed.

        For example, if user 567 within account 999 is attempting to create a new child company underneath company 12345, you could preview the user''s

        entitlements and predict whether this call would succeed:


        * Retrieve entitlements by calling ''/api/v2/accounts/999/users/567/entitlements'' . If the call fails, you do not have accurate

        credentials for this user.

        * If the ''accessLevel'' field within entitlements is ''None'', the call will fail.

        * If the ''accessLevel'' field within entitlements is ''SingleCompany'' or ''SingleAccount'', the call will fail if the companies

        table does not contain the ID number 12345.

        * If the ''permissions'' array within entitlements does not contain ''AccountSvc.CompanySave'', the call will fail.


        For a full list of defined permissions, please use ''/api/v2/definitions/permissions'' .


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      parameters:
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      - name: accountId
        in: path
        schema:
          type: string
        required: true
      - name: id
        in: path
        schema:
          type: string
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: getApiV2AccountsByAccountIdUsersByIdEntitlements
      x-operation-id-source: derived
  /api/v2/users:
    get:
      tags:
      - Users
      summary: Avalara QueryUsers
      description: 'Get multiple user objects across all accounts.


        A user represents one person or set of credentials with access privileges to make API calls and work with a specific account. A user can be authenticated

        via either username / password authentication, an OpenID / OAuth Bearer Token, or a legacy AvaTax License Key.


        When an API is called using a legacy AvaTax License Key, the API log entry is recorded as being performed by a special user attached to that license key.

        By default, this API will not return a listing of license key users. Users with registrar-level security may call this API to list license key users.


        Search for specific objects using the criteria in the `$filter` parameter; full documentation is available on Filtering in REST .

        Paginate your results using the `$top`, `$skip`, and `$orderby` parameters.


        You may specify one or more of the following values in the `$include` parameter to fetch additional nested data, using commas to separate multiple values:


        * FetchDeleted


        ### Security Policies


        * This API requires one of the following user roles: AccountAdmin, AccountOperator, AccountUser, BatchServiceAdmin, CompanyAdmin, CompanyUser, Compliance Root User, ComplianceAdmin, ComplianceUser, CSPAdmin, CSPTester, ECMAccountUser, ECMCompanyUser, FirmAdmin, FirmUser, ProStoresOperator, Registrar, SiteAdmin, SSTAdmin, SystemAdmin, SystemOperator, TechnicalSupportAdmin, TechnicalSupportUser, TreasuryAdmin, TreasuryUser.'
      parameters:
      - name: X-Avalara-Client
        in: header
        schema:
          type: string
        description: Identifies the software you are using to call this API. For more information on the client header, see [Client Headers](https://developer.avalara.com/avatax/client-headers/).
        example: AvaTax Postman Collection
      responses:
        '200':
          description: Successful response
          content:
            application/json: {}
      operationId: getApiV2Users
      x-operation-id-source: derived
components:
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic