> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# List users

> List all users in the current organization

<Info>
  Requires the IAM action **`workspace:ListUsers`**. See [WORKSPACE permissions](/workspace/permissions) for the full list, what each one covers, and an example policy.
</Info>


## OpenAPI

````yaml /api-reference/specs/workspace.yaml get /v1/users
openapi: 3.0.3
info:
  title: Basaltic Workspace API
  version: 1.0.0
  description: >
    Organization management: organizations, accounts, human users, users-only
    groups, and organization policies. Account IAM identities may receive
    explicitly delegated organization policies through this API. Personal
    authentication remains at the IAM endpoint.


    Organization resources are global and are resolved in the authenticated
    organization. Canonical CRNs are
    crn:workspace:::organization/<organization-uuid>/<type>/<name-or-uuid>.
    Organization policies are separate from account policies; shared system
    policies use crn:workspace:::policy/<name>.
  contact:
    name: Basaltic Support
    email: ping@basaltic.sh
  license:
    name: Proprietary
    url: https://basaltic.sh/terms
servers:
  - url: https://workspace.basaltic.sh
    description: Global API endpoint
security:
  - BearerAuth: []
paths:
  /v1/users:
    get:
      tags:
        - Workspace
      summary: List users
      description: List all users in the current organization
      operationId: listUsers
      parameters:
        - $ref: '#/components/parameters/IAMNameFilter'
        - $ref: '#/components/parameters/IAMCRNFilter'
        - $ref: '#/components/parameters/Limit'
        - $ref: '#/components/parameters/Marker'
      responses:
        '200':
          description: List of users
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - BearerAuth: []
components:
  parameters:
    IAMNameFilter:
      name: name
      in: query
      allowEmptyValue: true
      description: >-
        Exact resource name, combined with crn using AND before pagination.
        Empty values are filters. Resources without a name never match.
      schema:
        type: string
    IAMCRNFilter:
      name: crn
      in: query
      allowEmptyValue: true
      description: >-
        Exact returned CRN, combined with name using AND before pagination.
        Malformed or empty CRNs return 400; valid mismatched or foreign CRNs
        return an empty page. Resources without a CRN never match.
        Organization-scoped CRNs use the authenticated organization.
      schema:
        type: string
    Limit:
      name: limit
      in: query
      description: >-
        Maximum number of items to return. A value above the maximum is clamped
        to it rather than rejected, so a page shorter than the one you asked for
        is normal — page until `meta.has_more` is false, not until a page looks
        short.
      required: false
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 20
      example: 20
    Marker:
      name: marker
      in: query
      description: >-
        Opaque pagination cursor. Echo back the `meta.marker` value from the
        previous page to fetch the next one; do not construct or parse it. The
        token's internal form varies by endpoint (a resource ID, a timestamp, …)
        and is not guaranteed stable across releases.
      required: false
      schema:
        type: string
      example: 550e8400-e29b-41d4-a716-446655440000
  schemas:
    UserListResponse:
      type: object
      properties:
        users:
          type: array
          items:
            $ref: '#/components/schemas/User'
        meta:
          $ref: '#/components/schemas/PaginationMeta'
    User:
      type: object
      description: A platform user linked to the organization.
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
          example: 550e8400-e29b-41d4-a716-446655440000
        crn:
          type: string
          readOnly: true
          description: Cloud Resource Name
          example: >-
            crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/user/550e8400-e29b-41d4-a716-446655440001
        email:
          type: string
          format: email
          readOnly: true
          example: john.doe@acme.com
        name:
          type: string
          readOnly: true
          example: John Doe
        added_at:
          type: string
          format: date-time
          readOnly: true
          example: '2026-01-15T09:30:00Z'
        tags:
          $ref: '#/components/schemas/Tags'
    PaginationMeta:
      type: object
      properties:
        total:
          type: integer
          description: Total number of items
          example: 150
        limit:
          type: integer
          description: Number of items per page
          example: 20
        marker:
          type: string
          description: >-
            Opaque cursor for the next page. Pass it back as the `marker` query
            parameter; treat it as a token, not a value to parse.
          example: 550e8400-e29b-41d4-a716-446655440000
        has_more:
          type: boolean
          description: Whether there are more items
          example: true
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              description: Error code identifying the type of error
              example: INVALID_INPUT
            message:
              type: string
              description: Human-readable error message
              example: Invalid request parameters
            request_id:
              type: string
              format: uuid
              description: Request ID for debugging
              example: 550e8400-e29b-41d4-a716-446655440000
    Tags:
      type: object
      additionalProperties:
        type: string
      example:
        environment: production
        team: backend
  responses:
    Unauthorized:
      description: Authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHORIZED
              message: Authentication required
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Forbidden:
      description: Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: ACCESS_DENIED
              message: You don't have permission to perform this action
              request_id: 550e8400-e29b-41d4-a716-446655440000
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INTERNAL_ERROR
              message: An internal error occurred
              request_id: 550e8400-e29b-41d4-a716-446655440000
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        An OAuth 2.0 bearer token, sent as `Authorization: Bearer <token>`.
        This is the recommended way to authenticate.

        Get one by exchanging a service account's access key pair at
        `POST /v1/oauth/token` with `grant_type=client_credentials`. It is the
        standard client-credentials grant, so any OAuth-aware library will
        obtain and refresh it for you.

        ```
        curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
          https://iam.basaltic.sh/v1/oauth/token
        ```

        Tokens last an hour by default. The same access key pair is separately
        your AWS SigV4 credential for the S3-compatible object endpoint, which
        speaks nothing else.

````