curl --request POST \
--url https://{tenant_id}.hanko.io/admin/users \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"emails": [
{
"address": "<string>",
"is_primary": true,
"is_verified": true
}
],
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"username": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"organizations": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"roles": [
"<string>"
]
}
]
}
'import requests
url = "https://{tenant_id}.hanko.io/admin/users"
payload = {
"emails": [
{
"address": "<string>",
"is_primary": True,
"is_verified": True
}
],
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"username": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"organizations": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"roles": ["<string>"]
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
emails: [{address: '<string>', is_primary: true, is_verified: true}],
id: 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c',
username: '<string>',
created_at: '2023-11-07T05:31:56Z',
organizations: [{id: 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c', roles: ['<string>']}]
})
};
fetch('https://{tenant_id}.hanko.io/admin/users', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenant_id}.hanko.io/admin/users",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'emails' => [
[
'address' => '<string>',
'is_primary' => true,
'is_verified' => true
]
],
'id' => 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c',
'username' => '<string>',
'created_at' => '2023-11-07T05:31:56Z',
'organizations' => [
[
'id' => 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c',
'roles' => [
'<string>'
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenant_id}.hanko.io/admin/users"
payload := strings.NewReader("{\n \"emails\": [\n {\n \"address\": \"<string>\",\n \"is_primary\": true,\n \"is_verified\": true\n }\n ],\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"username\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"organizations\": [\n {\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"roles\": [\n \"<string>\"\n ]\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenant_id}.hanko.io/admin/users")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"emails\": [\n {\n \"address\": \"<string>\",\n \"is_primary\": true,\n \"is_verified\": true\n }\n ],\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"username\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"organizations\": [\n {\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"roles\": [\n \"<string>\"\n ]\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenant_id}.hanko.io/admin/users")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"emails\": [\n {\n \"address\": \"<string>\",\n \"is_primary\": true,\n \"is_verified\": true\n }\n ],\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"username\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"organizations\": [\n {\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"roles\": [\n \"<string>\"\n ]\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"webauthn_credentials": [
{
"id": "f9bebc04-b894-4018-bdb8-8b520a532fef",
"public_key": "<string>",
"attestation_type": "<string>",
"aaguid": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"backup_eligible": true,
"backup_state": true,
"mfa_only": true,
"name": "<string>",
"transports": [
"<string>"
],
"last_used_at": "2023-11-07T05:31:56Z"
}
],
"emails": [
{
"id": "802df042-1ac2-496d-af81-6ace729ed055",
"address": "jsmith@example.com",
"is_verified": true,
"is_primary": true,
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"username": {
"id": "8cbed467-554b-4d17-b23f-bce1b4f1db92",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"username": "john_doe_123"
},
"organizations": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"name": "<string>",
"roles": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"slug": "<string>",
"name": "<string>"
}
]
}
],
"otp": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z"
},
"password": {
"id": "28a7206b-e789-435a-b87c-108e034135c2",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
},
"identities": [
{
"id": "77f8d594-9765-4891-ab2b-f31a797b531d",
"email_id": "d4095586-8318-4a40-a840-b4260496f85a",
"provider_id": "<string>",
"provider_name": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"metadata": {
"public_metadata": {
"role": "admin"
},
"private_metadata": {
"internal_id": "e6c19cfb-09a2-41e5-a908-e33193b7ca0a"
},
"unsafe_metadata": {
"birthday": "2025-05-12"
}
}
}{
"code": 400,
"message": "Bad Request"
}{
"code": 409,
"message": "Conflict"
}{
"code": 500,
"message": "Internal Server Error"
}Create a new user
curl --request POST \
--url https://{tenant_id}.hanko.io/admin/users \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"emails": [
{
"address": "<string>",
"is_primary": true,
"is_verified": true
}
],
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"username": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"organizations": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"roles": [
"<string>"
]
}
]
}
'import requests
url = "https://{tenant_id}.hanko.io/admin/users"
payload = {
"emails": [
{
"address": "<string>",
"is_primary": True,
"is_verified": True
}
],
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"username": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"organizations": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"roles": ["<string>"]
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
emails: [{address: '<string>', is_primary: true, is_verified: true}],
id: 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c',
username: '<string>',
created_at: '2023-11-07T05:31:56Z',
organizations: [{id: 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c', roles: ['<string>']}]
})
};
fetch('https://{tenant_id}.hanko.io/admin/users', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenant_id}.hanko.io/admin/users",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'emails' => [
[
'address' => '<string>',
'is_primary' => true,
'is_verified' => true
]
],
'id' => 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c',
'username' => '<string>',
'created_at' => '2023-11-07T05:31:56Z',
'organizations' => [
[
'id' => 'c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c',
'roles' => [
'<string>'
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenant_id}.hanko.io/admin/users"
payload := strings.NewReader("{\n \"emails\": [\n {\n \"address\": \"<string>\",\n \"is_primary\": true,\n \"is_verified\": true\n }\n ],\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"username\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"organizations\": [\n {\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"roles\": [\n \"<string>\"\n ]\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenant_id}.hanko.io/admin/users")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"emails\": [\n {\n \"address\": \"<string>\",\n \"is_primary\": true,\n \"is_verified\": true\n }\n ],\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"username\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"organizations\": [\n {\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"roles\": [\n \"<string>\"\n ]\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenant_id}.hanko.io/admin/users")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"emails\": [\n {\n \"address\": \"<string>\",\n \"is_primary\": true,\n \"is_verified\": true\n }\n ],\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"username\": \"<string>\",\n \"created_at\": \"2023-11-07T05:31:56Z\",\n \"organizations\": [\n {\n \"id\": \"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c\",\n \"roles\": [\n \"<string>\"\n ]\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"webauthn_credentials": [
{
"id": "f9bebc04-b894-4018-bdb8-8b520a532fef",
"public_key": "<string>",
"attestation_type": "<string>",
"aaguid": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"backup_eligible": true,
"backup_state": true,
"mfa_only": true,
"name": "<string>",
"transports": [
"<string>"
],
"last_used_at": "2023-11-07T05:31:56Z"
}
],
"emails": [
{
"id": "802df042-1ac2-496d-af81-6ace729ed055",
"address": "jsmith@example.com",
"is_verified": true,
"is_primary": true,
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"username": {
"id": "8cbed467-554b-4d17-b23f-bce1b4f1db92",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"username": "john_doe_123"
},
"organizations": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"name": "<string>",
"roles": [
{
"id": "c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c",
"slug": "<string>",
"name": "<string>"
}
]
}
],
"otp": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z"
},
"password": {
"id": "28a7206b-e789-435a-b87c-108e034135c2",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
},
"identities": [
{
"id": "77f8d594-9765-4891-ab2b-f31a797b531d",
"email_id": "d4095586-8318-4a40-a840-b4260496f85a",
"provider_id": "<string>",
"provider_name": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"metadata": {
"public_metadata": {
"role": "admin"
},
"private_metadata": {
"internal_id": "e6c19cfb-09a2-41e5-a908-e33193b7ca0a"
},
"unsafe_metadata": {
"birthday": "2025-05-12"
}
}
}{
"code": 400,
"message": "Bad Request"
}{
"code": 409,
"message": "Conflict"
}{
"code": 500,
"message": "Internal Server Error"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your API key. Must only be used when using Hanko Cloud.
Body
The email addresses of the new user
Show child attributes
Show child attributes
The ID of the new user
"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c"
The username of the new user
Time of creation of the user
Organizations to add the new user to, with optional roles to bind within each. Every organization ID and role ID/slug must already exist within the tenant, or the request fails with 400 and no user is created.
Show child attributes
Show child attributes
Response
Details of the newly created user
The ID of the user
"c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c"
Time of creation of the user
Time of last update of the user
List of registered Webauthn credentials
Show child attributes
Show child attributes
List of emails associated to the user
Show child attributes
Show child attributes
The username of the user
Show child attributes
Show child attributes
Organizations the user belongs to, and the roles held in each. Omitted if the user belongs to no organizations.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
The password credential of a user
Show child attributes
Show child attributes
A list of third party provider identities
Show child attributes
Show child attributes
User metadata
Show child attributes
Show child attributes
Was this page helpful?