Gravitee user API

The user API from Gravitee — 38 operation(s) for user.

Operations 45

GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users List users for a security domain #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users Create a user on the specified security domain #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/bulk Create/update/delete multiple users on the specified security domain #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user} Get a user #
PUT /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user} Update a user #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user} Delete a user #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/audits Get a user audit logs #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/audits/{audit} Get a user audit log #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/cert-credentials Get user certificate credentials #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/cert-credentials Enroll a certificate credential for a user #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/cert-credentials/{credential} Get a user certificate credential #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/cert-credentials/{credential} Revoke a user certificate credential #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/consents Get a user consents #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/consents Revoke user consents #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/consents/{consent} Get a user consent #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/consents/{consent} Revoke a user consent #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/credentials Get a user credentials #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/credentials/{credential} Get a user credential #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/credentials/{credential} Revoke a user credential #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/factors Get a user enrolled factors #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/factors/{factor} Revoke user factor #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/identities Get a user linked identities #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/identities/{identity} Unlink user identity #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/lock Lock a user #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/resetPassword Reset password #
GET /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/roles Get a user roles #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/roles Assign roles to a user #
DELETE /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/roles/{role} Revoke role to a user #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/sendRegistrationConfirmation Send registration confirmation email #
PUT /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/status Update a user status #
POST /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/unlock Unlock a user #
PATCH /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/username Update a user username #
GET /organizations/{organizationId}/users List users of the organization #
POST /organizations/{organizationId}/users Create a platform user or Service Account #
POST /organizations/{organizationId}/users/bulk Create/update/delete platform users or Service Accounts #
GET /organizations/{organizationId}/users/{user} Get a user #
PUT /organizations/{organizationId}/users/{user} Update a user #
DELETE /organizations/{organizationId}/users/{user} Delete a user #
POST /organizations/{organizationId}/users/{user}/resetPassword Reset password #
PUT /organizations/{organizationId}/users/{user}/status Update a user status #
GET /organizations/{organizationId}/users/{user}/tokens Get tokens of a user #
POST /organizations/{organizationId}/users/{user}/tokens Generate an account access token for a user #
DELETE /organizations/{organizationId}/users/{user}/tokens/{tokenId} Revoke an account access token #
PATCH /organizations/{organizationId}/users/{user}/username Update a user username #
GET /user Get the current user #

Documentation

Specifications

SDKs

Schemas & Data

Other Resources

🔗
ChangeLog
https://documentation.gravitee.io/apim/release-information/changelog
🔗
License
https://github.com/gravitee-io/gravitee-api-management/blob/master/LICENSE.txt
🔗
SDKs
https://github.com/gravitee-io/gravitee-clients-sdk
🔗
SDKs
https://github.com/gravitee-io/terraform-provider-apim
🔗
CLI
https://github.com/gravitee-io/graviteeio-cli
🔗
KubernetesOperator
https://github.com/gravitee-io/gravitee-kubernetes-operator
🔗
HelmChart
https://github.com/gravitee-io/helm-charts
🔗
DockerImage
https://hub.docker.com/r/graviteeio/apim-gateway
🔗
JSONLDContext
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/json-ld/gravitee-context.jsonld
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_apidefinitions.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_apiv4definitions.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_apiresources.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_applications.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_subscriptions.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_managementcontexts.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_sharedpolicygroups.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_groups.yaml
🔗
KubernetesCRD
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/crd/gravitee.io_notifications.yaml
🔗
Plans
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/plans/gravitee-plans-pricing.yml
🔗
FinOps
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/finops/gravitee-finops.yml
🔗
GraphQL
https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/graphql/gravitee-graphql.md
🔗
Reference
https://documentation.gravitee.io/am/reference/am-api-reference
🔗
ChangeLog
https://documentation.gravitee.io/am/releases-and-changelog/release-notes
🔗
License
https://github.com/gravitee-io/gravitee-access-management/blob/master/LICENSE
🔗
SDKs
https://github.com/gravitee-io/gravitee-access-management/tree/master/gravitee-am-management-api-sdk-java
🔗
HelmChart
https://github.com/gravitee-io/helm-charts/tree/master/helm/gravitee-am
🔗
DockerImage
https://hub.docker.com/r/graviteeio/am-gateway

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/gravitee-user-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

gravitee-user-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Gravitee.io - Access Management User API
  version: 4.12.0-alpha.3
servers:
- url: /management
security:
- gravitee-auth: []
tags:
- name: user
paths:
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users:
    get:
      tags:
      - user
      summary: List users for a security domain
      description: User must have the DOMAIN_USER[LIST] permission on the specified domain or DOMAIN_USER[LIST] permission on the specified environment or DOMAIN_USER[LIST] permission on the specified organization. Each returned user is filtered and contains only basic information such as id and username and displayname. Last login and identity provider name will be also returned if current user has DOMAIN_USER[READ] permission on the domain, environment or organization.
      operationId: listUsers
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: q
        in: query
        schema:
          type: string
      - name: filter
        in: query
        schema:
          type: string
      - name: page
        in: query
        schema:
          type: integer
          format: int32
          default: 0
      - name: size
        in: query
        schema:
          maximum: 1000
          minimum: 1
          type: integer
          format: int32
          default: 30
      responses:
        '200':
          description: List users for a security domain
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserPage'
        '500':
          description: Internal server error
    post:
      tags:
      - user
      summary: Create a user on the specified security domain
      description: User must have the DOMAIN_USER[CREATE] permission on the specified domain or DOMAIN_USER[CREATE] permission on the specified environment or DOMAIN_USER[CREATE] permission on the specified organization
      operationId: createUser
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NewUser'
        required: true
      responses:
        '201':
          description: User successfully created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/bulk:
    post:
      tags:
      - user
      summary: Create/update/delete multiple users on the specified security domain
      description: User must have the DOMAIN_USER[CREATE/UPDATE/DELETE] permission on the specified domain, the environment, or the organization
      operationId: bulkUserOperation
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DomainUserBulkRequest'
        required: true
      responses:
        '200':
          description: Some users got created, inspect each result for details
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BulkResponse'
        '201':
          description: All users successfully created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BulkResponse'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}:
    get:
      tags:
      - user
      summary: Get a user
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: findUser
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User successfully fetched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserEntity'
        '500':
          description: Internal server error
    put:
      tags:
      - user
      summary: Update a user
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: updateUser
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateUser'
        required: true
      responses:
        '201':
          description: User successfully updated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '500':
          description: Internal server error
    delete:
      tags:
      - user
      summary: Delete a user
      description: User must have the DOMAIN_USER[DELETE] permission on the specified domain or DOMAIN_USER[DELETE] permission on the specified environment or DOMAIN_USER[DELETE] permission on the specified organization
      operationId: deleteUser
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User successfully deleted
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/audits:
    get:
      tags:
      - user
      summary: Get a user audit logs
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserAuditLogs
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: type
        in: query
        schema:
          type: string
      - name: status
        in: query
        schema:
          type: string
      - name: from
        in: query
        schema:
          type: integer
          format: int64
      - name: to
        in: query
        schema:
          type: integer
          format: int64
      - name: size
        in: query
        schema:
          type: integer
          format: int32
          default: 10
      - name: page
        in: query
        schema:
          type: integer
          format: int32
          default: 0
      responses:
        '200':
          description: User audit logs successfully fetched
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Audit'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/audits/{audit}:
    get:
      tags:
      - user
      summary: Get a user audit log
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: getUserAuditLog
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: audit
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User audit log successfully fetched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Audit'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/cert-credentials:
    get:
      tags:
      - user
      summary: Get user certificate credentials
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserCertificateCredentials
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User certificate credentials successfully fetched
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/CertificateCredential'
        '404':
          description: Domain not found
        '500':
          description: Internal server error
    post:
      tags:
      - user
      summary: Enroll a certificate credential for a user
      description: User must have the DOMAIN_USER[CREATE] permission on the specified domain or DOMAIN_USER[CREATE] permission on the specified environment or DOMAIN_USER[CREATE] permission on the specified organization
      operationId: enrollUserCertificateCredential
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NewCertificateCredential'
        required: true
      responses:
        '201':
          description: Certificate credential successfully enrolled
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CertificateCredential'
        '400':
          description: Invalid certificate or limit exceeded
        '404':
          description: Domain not found
        '409':
          description: Duplicate certificate
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/cert-credentials/{credential}:
    get:
      tags:
      - user
      summary: Get a user certificate credential
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: getUserCertificateCredential
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: credential
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User certificate credential successfully fetched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CertificateCredential'
        '404':
          description: Domain or certificate credential not found
        '500':
          description: Internal server error
    delete:
      tags:
      - user
      summary: Revoke a user certificate credential
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: revokeUserCertificateCredential
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: credential
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: Certificate credential successfully revoked
        '404':
          description: Domain or certificate credential not found
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/consents:
    get:
      tags:
      - user
      summary: Get a user consents
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserConsents
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: clientId
        in: query
        schema:
          type: string
      responses:
        '200':
          description: User consents successfully fetched
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ScopeApprovalEntity'
        '500':
          description: Internal server error
    delete:
      tags:
      - user
      summary: Revoke user consents
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: revokeUserConsents
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: clientId
        in: query
        schema:
          type: string
      responses:
        '204':
          description: User consents successfully revoked
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/consents/{consent}:
    get:
      tags:
      - user
      summary: Get a user consent
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: getUserConsent
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: consent
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User consent successfully fetched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ScopeApprovalEntity'
        '500':
          description: Internal server error
    delete:
      tags:
      - user
      summary: Revoke a user consent
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: revokeUserConsent
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: consent
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User consent successfully revoked
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/credentials:
    get:
      tags:
      - user
      summary: Get a user credentials
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserCredentials
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User credentials successfully fetched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Credential'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/credentials/{credential}:
    get:
      tags:
      - user
      summary: Get a user credential
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: getUserCredential
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: credential
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User credential successfully fetched
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Credential'
        '500':
          description: Internal server error
    delete:
      tags:
      - user
      summary: Revoke a user credential
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: revokeUserCredential
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: credential
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User credential successfully revoked
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/factors:
    get:
      tags:
      - user
      summary: Get a user enrolled factors
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserEnrolledFactors
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User enrolled factors successfully fetched
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/EnrolledFactorEntity'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/factors/{factor}:
    delete:
      tags:
      - user
      summary: Revoke user factor
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: deleteUserFactor
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: factor
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User factor successfully revoked
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/identities:
    get:
      tags:
      - user
      summary: Get a user linked identities
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserIdentities
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          description: User linked identities successfully fetched
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/UserIdentityEntity'
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/identities/{identity}:
    delete:
      tags:
      - user
      summary: Unlink user identity
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: unlinkUserIdentity
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: identity
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User identity successfully unlinked
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/lock:
    post:
      tags:
      - user
      summary: Lock a user
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: lockUser
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      responses:
        '204':
          description: User locked
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/resetPassword:
    post:
      tags:
      - user
      summary: Reset password
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: resetPassword
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          '*/*':
            schema:
              $ref: '#/components/schemas/PasswordValue'
        required: true
      responses:
        '200':
          description: Password reset
        '500':
          description: Internal server error
  /organizations/{organizationId}/environments/{environmentId}/domains/{domain}/users/{user}/roles:
    get:
      tags:
      - user
      summary: Get a user roles
      description: User must have the DOMAIN_USER[READ] permission on the specified domain or DOMAIN_USER[READ] permission on the specified environment or DOMAIN_USER[READ] permission on the specified organization
      operationId: listUserRoles
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      - name: dynamic
        in: query
        schema:
          type: boolean
          default: false
      responses:
        '200':
          description: User roles successfully fetched
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Role'
        '500':
          description: Internal server error
    post:
      tags:
      - user
      summary: Assign roles to a user
      description: User must have the DOMAIN_USER[UPDATE] permission on the specified domain or DOMAIN_USER[UPDATE] permission on the specified environment or DOMAIN_USER[UPDATE] permission on the specified organization
      operationId: assignRolesToUser
      parameters:
      - name: organizationId
        in: path
        required: true
        schema:
          type: string
      - name: environmentId
        in: path
        required: true
        schema:
          type: string
      - name: domain
        in: path
        required: true
        schema:
          type: string
      - name: user
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
        requ

# --- truncated at 32 KB (79 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/gravitee/refs/heads/main/openapi/gravitee-user-api-openapi.yml