Dynatrace User management API
Manage users in an account and their group memberships.
Manage users in an account and their group memberships.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/dynatrace-user-management-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Dynatrace Account Management User Management API
description: The enterprise management API for Dynatrace SaaS enables automation of operational tasks related to user access and environment lifecycle management.
version: '1.0'
contact: {}
servers: []
tags:
- name: User Management
description: Manage users in an account and their group memberships.
paths:
/iam/v1/accounts/{account-uuid}/users:
get:
operationId: UsersController_getUsers
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
- name: service-users
required: false
in: query
description: Specifies whether service users are included in results.
schema:
type: boolean
responses:
'200':
description: Success. The response contains the list of users.
content:
application/json:
schema:
$ref: '#/components/schemas/UserListDto'
security:
- bearer: []
summary: Lists all users of an account
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-read
post:
operationId: UsersController_createUserForAccount
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
requestBody:
required: true
description: The JSON body of the request. Contains the email address of the new user.
content:
application/json:
schema:
$ref: '#/components/schemas/UserEmailDto'
responses:
'201':
description: Success. The new user has been created. Response contains userUuid.
security:
- bearer: []
summary: Creates a new user in an account
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-write
/iam/v1/accounts/{account-uuid}/users/{email}:
get:
operationId: UsersController_getUserGroups
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
- name: email
required: true
in: path
description: The email address of the required user.
schema:
type: string
responses:
'200':
description: Success. The response contains the groups of the user.
content:
application/json:
schema:
$ref: '#/components/schemas/GroupUserDto'
security:
- bearer: []
summary: Lists all groups of a user
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-read
post:
operationId: UsersController_addUserToGroups
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
- name: email
required: true
in: path
description: The email address of the required user.
schema:
type: string
requestBody:
required: true
description: "The body of the request. Contains a list of groups (specified by UUIDs) to which the user is to be added. The limit is 200 groups. \n\n Any existing group membership remains unaffected."
content:
application/json:
schema:
type: array
items:
type: string
responses:
'201':
description: Success. The user has been added to the groups. Response doesn't have a body.
security:
- bearer: []
summary: Adds a user to groups. Any existing group membership remains unaffected
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-write
delete:
operationId: UsersController_removeUserFromAccount
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
- name: email
required: true
in: path
description: The email address of the required user.
schema:
type: string
responses:
'200':
description: Success. The user has been deleted. Response doesn't have a body.
security:
- bearer: []
summary: Removes a user from an account
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-write
/iam/v1/accounts/{account-uuid}/users/{email}/groups:
put:
operationId: UsersController_replaceUserGroups
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
- name: email
required: true
in: path
description: The email address of the required user.
schema:
type: string
requestBody:
required: true
description: "The body of the request. Contains a list of groups (specified by UUIDs) where the user is to be a member. The limit is 200 groups. \n\n The user will be removed from any group that is not specified here."
content:
application/json:
schema:
type: array
items:
type: string
responses:
'200':
description: Success. The group membership has been set. Response doesn't have a body.
security:
- bearer: []
summary: Sets group membership of a user. Any existing membership is overwritten
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-write
delete:
operationId: UsersController_removeUserFromGroups
parameters:
- name: account-uuid
required: true
in: path
description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client."
schema:
type: string
- name: email
required: true
in: path
description: The email address of the required user.
schema:
type: string
- name: group-uuid
required: true
in: query
description: "A list of groups the user is no longer a member of. \n\n To specify several groups, use the following format: `group-uuid=aaaaaa&group-uuid=bbbb`. \n\n The limit is 200 groups."
schema:
type: array
items:
type: string
responses:
'200':
description: Success. The user has been removed from groups. Response doesn't have a body.
security:
- bearer: []
summary: Removes a user from groups
tags:
- User Management
x-required-permissions:
- account-user-management
x-token-scopes:
- account-idm-write
components:
schemas:
AccountGroupDto:
type: object
properties:
groupName:
type: string
description: The name of the user group.
uuid:
type: string
description: The UUID of the user group.
owner:
type: string
enum:
- LOCAL
- SCIM
- SAML
- DCS
- ALL_USERS
description: The type of the group. `LOCAL`, `SCIM`, `SAML` and `DCS` corresponds to the identity provider from which the group originates. `ALL_USERS` is a special case of `LOCAL` group. It means that group is always assigned to all users in the account.
accountUUID:
type: string
description: The UUID of the Dynatrace account.
accountName:
type: string
description: The name of the Dynatrace account.
description:
type: string
description: A short description of the group.
createdAt:
type: string
description: The date and time of the group creation in `2021-05-01T15:11:00Z` format.
updatedAt:
type: string
description: The date and time of the most recent modification to the group in `2021-05-01T15:11:00Z` format.
required:
- groupName
- uuid
- owner
- accountUUID
- accountName
- description
- createdAt
- updatedAt
UserListDto:
type: object
properties:
count:
type: number
description: The number of entries in the list.
items:
description: A list of the account's users.
type: array
items:
$ref: '#/components/schemas/UsersDto'
required:
- count
- items
GroupUserDto:
type: object
properties:
uid:
type: string
description: The UUID of the user.
email:
type: string
description: The email address of the user.
name:
type: string
description: The first name of the user.
surname:
type: string
description: The last name of the user.
userStatus:
type: string
enum:
- ACTIVE
- INACTIVE
- PENDING
- DELETED
- ECUSTOMS_MANUALLY_BLOCKED
description: "The status of this user in Dynatrace: \n\n* `ACTIVE`: The user is active.\n* `INACTIVE`: The user is deactivated and cannot sign in to Dynatrace. \n* `PENDING`: The user received an invitation, but hasn't completed sign-up yet. \n* `DELETED`: The user was deleted and cannot sign in to Dynatrace anymore. \n* `ECUSTOMS_MANUALLY_BLOCKED`: The user is blocked due to to a trade and export compliance violation. \n"
emergencyContact:
type: boolean
description: The user is (`true`) or is not (`false`) an emergency contact for the account.
groups:
description: A list of groups of which the user is a member.
type: array
items:
$ref: '#/components/schemas/AccountGroupDto'
required:
- uid
- email
- groups
UsersDto:
type: object
properties:
uid:
type: string
description: The UUID of the user.
email:
type: string
description: The email address of the user.
name:
type: string
description: The first name of the user.
surname:
type: string
description: The last name of the user.
userStatus:
type: string
enum:
- ACTIVE
- INACTIVE
- PENDING
- DELETED
- ECUSTOMS_MANUALLY_BLOCKED
description: "The status of this user in Dynatrace: \n\n* `ACTIVE`: The user is active.\n* `INACTIVE`: The user is deactivated and cannot sign in to Dynatrace. \n* `PENDING`: The user received an invitation, but hasn't completed sign-up yet. \n* `DELETED`: The user was deleted and cannot sign in to Dynatrace anymore. \n* `ECUSTOMS_MANUALLY_BLOCKED`: The user is blocked due to to a trade and export compliance violation. \n"
emergencyContact:
type: boolean
description: The user is (`true`) or is not (`false`) an emergency contact for the account.
userLoginMetadata:
description: Available if user has logged into Dynatrace at least once
allOf:
- $ref: '#/components/schemas/UserLoginMetaDataDto'
required:
- uid
- email
UserLoginMetaDataDto:
type: object
properties:
successfulLoginCounter:
type: number
description: The number of successful sign-ins.
failedLoginCounter:
type: number
description: The number of failed sign-ins.
lastSuccessfulLogin:
type: string
description: The date and time of the most recent successful sign-in in `2021-05-01T15:11:00Z` format.
lastFailedLogin:
type: string
description: The date and time of the most recent failed sign-in in `2021-05-01T15:11:00Z` format.
createdAt:
type: string
description: The date and time of user creation in `2021-05-01T15:11:00Z` format.
updatedAt:
type: string
description: The date and time of the most recent modification to the user in `2021-05-01T15:11:00Z` format.
required:
- successfulLoginCounter
- failedLoginCounter
- lastSuccessfulLogin
- lastFailedLogin
- createdAt
- updatedAt
UserEmailDto:
type: object
properties:
email:
type: string
description: The email address of the user.
required:
- email
securitySchemes:
bearer:
scheme: bearer
bearerFormat: JWT
type: http
externalDocs:
description: OpenAPI specification
url: /openapi.json