Budibase Users API

Manage Budibase users.

Operations 9

GET /users Search for users #
POST /users Create a user #
GET /users/{id} Retrieve a user #
PUT /users/{id} Update a user #
DELETE /users/{id} Delete a user #
PUT /users/{userId} Update a user #
DELETE /users/{userId} Delete a user #
GET /users/{userId} Retrieve a user #
POST /users/search Search for users #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/budibase-users-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

budibase-users-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Budibase Users API
  version: '1.0'
  description: 'Operations tagged Users across 2 of this provider''s published API definitions: budibase-openapi.yml, budibase-users-api-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://budibase.app/api/public/v1
  description: Budibase Cloud Public API
- url: https://{selfhosted}/api/public/v1
  description: Self-hosted Budibase
  variables:
    selfhosted:
      default: budibase.example.com
      description: Hostname of the self-hosted Budibase instance
tags:
- name: Users
  description: Manage Budibase users.
paths:
  /users:
    get:
      tags:
      - Users
      summary: Search for users
      operationId: searchUsers
      requestBody:
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NameSearch'
      responses:
        '200':
          description: Search results
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/User'
      security:
      - apiKeyAuth: []
    post:
      tags:
      - Users
      summary: Create a user
      operationId: createUser
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserInput'
      responses:
        '200':
          description: Created user
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
      security:
      - apiKeyAuth: []
    servers:
    - url: https://budibase.app/api/public/v1
      description: Budibase Cloud Public API
    - url: https://{selfhosted}/api/public/v1
      description: Self-hosted Budibase
      variables:
        selfhosted:
          default: budibase.example.com
          description: Hostname of the self-hosted Budibase instance
  /users/{id}:
    parameters:
    - $ref: '#/components/parameters/IdPath'
    get:
      tags:
      - Users
      summary: Retrieve a user
      operationId: getUser
      responses:
        '200':
          description: User
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
      security:
      - apiKeyAuth: []
    put:
      tags:
      - Users
      summary: Update a user
      operationId: updateUser
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserInput'
      responses:
        '200':
          description: Updated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
      security:
      - apiKeyAuth: []
    delete:
      tags:
      - Users
      summary: Delete a user
      operationId: deleteUser
      responses:
        '200':
          description: Deleted
      security:
      - apiKeyAuth: []
    servers:
    - url: https://budibase.app/api/public/v1
      description: Budibase Cloud Public API
    - url: https://{selfhosted}/api/public/v1
      description: Self-hosted Budibase
      variables:
        selfhosted:
          default: budibase.example.com
          description: Hostname of the self-hosted Budibase instance
  /users/{userId}:
    servers:
    - url: https://budibase.app/api/public/v1
      description: Budibase Cloud API
      variables:
        apiKey:
          default: <user API key>
          description: The API key of the user to assume for API call.
        appId:
          default: <App ID>
          description: The ID of the app the calls will be executed within the context of, this should start with app_ (production) or app_dev (development).
    put:
      operationId: userUpdate
      summary: Update a user
      tags:
      - Users
      parameters:
      - $ref: '#/components/parameters/userId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/user'
      responses:
        '200':
          description: Returns the updated user.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/userOutput'
              examples:
                user:
                  $ref: '#/components/examples/user'
      security:
      - ApiKeyAuth: []
    delete:
      operationId: userDestroy
      summary: Delete a user
      tags:
      - Users
      parameters:
      - $ref: '#/components/parameters/userId'
      responses:
        '200':
          description: Returns the deleted user.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/userOutput'
              examples:
                user:
                  $ref: '#/components/examples/user'
      security:
      - ApiKeyAuth: []
    get:
      operationId: userGetById
      summary: Retrieve a user
      tags:
      - Users
      parameters:
      - $ref: '#/components/parameters/userId'
      responses:
        '200':
          description: Returns the retrieved user.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/userOutput'
              examples:
                user:
                  $ref: '#/components/examples/user'
      security:
      - ApiKeyAuth: []
  /users/search:
    servers:
    - url: https://budibase.app/api/public/v1
      description: Budibase Cloud API
      variables:
        apiKey:
          default: <user API key>
          description: The API key of the user to assume for API call.
        appId:
          default: <App ID>
          description: The ID of the app the calls will be executed within the context of, this should start with app_ (production) or app_dev (development).
    post:
      operationId: userSearch
      summary: Search for users
      description: Based on user properties (currently only name) search for users.
      tags:
      - Users
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/nameSearch'
      responses:
        '200':
          description: Returns the found users based on search parameters.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/userSearch'
              examples:
                users:
                  $ref: '#/components/examples/users'
      security:
      - ApiKeyAuth: []
components:
  schemas:
    UserInput:
      type: object
      required:
      - email
      properties:
        email:
          type: string
        password:
          type: string
        roles:
          type: object
          additionalProperties:
            type: string
        builder:
          type: object
          properties:
            global:
              type: boolean
        admin:
          type: object
          properties:
            global:
              type: boolean
    User:
      allOf:
      - $ref: '#/components/schemas/UserInput'
      - type: object
        properties:
          _id:
            type: string
          createdAt:
            type: string
            format: date-time
          updatedAt:
            type: string
            format: date-time
    NameSearch:
      type: object
      properties:
        name:
          type: string
        paginate:
          type: boolean
        bookmark:
          type: string
        sort:
          type: object
          properties:
            order:
              type: string
              enum:
              - ascending
              - descending
            type:
              type: string
              enum:
              - string
              - number
    userSearch:
      type: object
      properties:
        data:
          type: array
          items:
            type: object
            properties:
              email:
                description: The email address of the user, this must be unique.
                type: string
              password:
                description: The password of the user if using password based login - this will never be returned. This can be left out of subsequent requests (updates) and will be enriched back into the user structure.
                type: string
              status:
                description: The status of the user, if they are active.
                type: string
                enum:
                - active
              firstName:
                description: The first name of the user
                type: string
              lastName:
                description: The last name of the user
                type: string
              forceResetPassword:
                description: If set to true forces the user to reset their password on first login.
                type: boolean
              builder:
                description: Describes if the user is a builder user or not. This field can only be set on a business or enterprise license.
                type: object
                properties:
                  global:
                    description: If set to true the user will be able to build any app in the system.
                    type: boolean
              admin:
                description: Describes if the user is an admin user or not. This field can only be set on a business or enterprise license.
                type: object
                properties:
                  global:
                    description: If set to true the user will be able to administrate the system.
                    type: boolean
              roles:
                description: Contains the roles of the user per app (assuming they are not a builder user). This field can only be set on a business or enterprise license.
                type: object
                additionalProperties:
                  type: string
                  description: A map of app ID (production app ID, minus the _dev component) to a role ID, e.g. ADMIN.
              _id:
                description: The ID of the user.
                type: string
            required:
            - email
            - _id
      required:
      - data
    user:
      type: object
      properties:
        email:
          description: The email address of the user, this must be unique.
          type: string
        password:
          description: The password of the user if using password based login - this will never be returned. This can be left out of subsequent requests (updates) and will be enriched back into the user structure.
          type: string
        status:
          description: The status of the user, if they are active.
          type: string
          enum:
          - active
        firstName:
          description: The first name of the user
          type: string
        lastName:
          description: The last name of the user
          type: string
        forceResetPassword:
          description: If set to true forces the user to reset their password on first login.
          type: boolean
        builder:
          description: Describes if the user is a builder user or not. This field can only be set on a business or enterprise license.
          type: object
          properties:
            global:
              description: If set to true the user will be able to build any app in the system.
              type: boolean
        admin:
          description: Describes if the user is an admin user or not. This field can only be set on a business or enterprise license.
          type: object
          properties:
            global:
              description: If set to true the user will be able to administrate the system.
              type: boolean
        roles:
          description: Contains the roles of the user per app (assuming they are not a builder user). This field can only be set on a business or enterprise license.
          type: object
          additionalProperties:
            type: string
            description: A map of app ID (production app ID, minus the _dev component) to a role ID, e.g. ADMIN.
      required:
      - email
    nameSearch:
      type: object
      properties:
        name:
          type: string
          description: The name to be used when searching - this will be used in a case insensitive starts with match.
      required:
      - name
    userOutput:
      type: object
      properties:
        data:
          type: object
          properties:
            email:
              description: The email address of the user, this must be unique.
              type: string
            password:
              description: The password of the user if using password based login - this will never be returned. This can be left out of subsequent requests (updates) and will be enriched back into the user structure.
              type: string
            status:
              description: The status of the user, if they are active.
              type: string
              enum:
              - active
            firstName:
              description: The first name of the user
              type: string
            lastName:
              description: The last name of the user
              type: string
            forceResetPassword:
              description: If set to true forces the user to reset their password on first login.
              type: boolean
            builder:
              description: Describes if the user is a builder user or not. This field can only be set on a business or enterprise license.
              type: object
              properties:
                global:
                  description: If set to true the user will be able to build any app in the system.
                  type: boolean
            admin:
              description: Describes if the user is an admin user or not. This field can only be set on a business or enterprise license.
              type: object
              properties:
                global:
                  description: If set to true the user will be able to administrate the system.
                  type: boolean
            roles:
              description: Contains the roles of the user per app (assuming they are not a builder user). This field can only be set on a business or enterprise license.
              type: object
              additionalProperties:
                type: string
                description: A map of app ID (production app ID, minus the _dev component) to a role ID, e.g. ADMIN.
            _id:
              description: The ID of the user.
              type: string
          required:
          - email
          - _id
      required:
      - data
  parameters:
    IdPath:
      name: id
      in: path
      required: true
      schema:
        type: string
    userId:
      in: path
      name: userId
      required: true
      description: The ID of the user which this request is targeting.
      schema:
        type: string
  examples:
    user:
      value:
        data:
          _id: us_693a73206518477283a8d5ae31103252
          email: test@example.com
          roles:
            app_957b12f943d348faa61db7e18e088d0f: BASIC
          builder:
            global: false
          admin:
            global: true
          tenantId: default
          status: active
          budibaseAccess: true
          csrfToken: 9c70291d-7137-48f9-9166-99ab5473a3d4
          userId: us_693a73206518477283a8d5ae31103252
          roleId: ADMIN
          role:
            _id: ADMIN
            name: Admin
            permissionId: admin
            inherits: POWER
    users:
      value:
        data:
        - _id: us_693a73206518477283a8d5ae31103252
          email: test@example.com
          roles:
            app_957b12f943d348faa61db7e18e088d0f: BASIC
          builder:
            global: false
          admin:
            global: true
          tenantId: default
          status: active
          budibaseAccess: true
          csrfToken: 9c70291d-7137-48f9-9166-99ab5473a3d4
          userId: us_693a73206518477283a8d5ae31103252
          roleId: ADMIN
          role:
            _id: ADMIN
            name: Admin
            permissionId: admin
            inherits: POWER
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-budibase-api-key
      description: API key generated from the Budibase portal user dropdown menu.
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-budibase-api-key
      description: Your individual API key, this will provide access based on the configured RBAC settings of your user.
x-refined-from:
- budibase-openapi.yml
- budibase-users-api-openapi.yml