# USERS Invoke the User API to retrieve User profile information. ## Get Current User Profile - [GET /user](https://api.tenovos.com/openapi/v1.5/users/getcurrentuser.md): Use this endpoint to get the user profile information for the account that you've authenticated against the Tenovos API with. This is useful when needing to check which groups you are in which may restrict the API calls you can make. ## Create User - [POST /user](https://api.tenovos.com/openapi/v1.5/users/createuser.md): Use this endpoint to create a new user account in the system. You must have User Management role privilege and Security Template Management role privilege in order to create a user and assign groups. This endpoint can be used to create local or federated users. Average Response Time: 5140ms ## Get User Profile by ID - [GET /user/{id}](https://api.tenovos.com/openapi/v1.5/users/getuser.md): Current user will get its profile information in response. User will also get ID of a role assigned to them and a list of group IDs they belong to. Average Response Time: 154ms ## Update User Attributes - [PATCH /user/{id}](https://api.tenovos.com/openapi/v1.5/users/updateuser.md): Update User Profile attributes such as First Name, Last Name, Friendly Name, Email, Company, Country, Contact, Phone, and User Role. The user role can be updated by sending either role id or role name. Average Response Time: 1587ms ## Add User to Group - [PATCH /user/{id}/add-to-group](https://api.tenovos.com/openapi/v1.5/users/addusertogroup.md): Assign a Security Group to a User Profile. ## Remove User from Group - [PATCH /user/{id}/remove-from-group](https://api.tenovos.com/openapi/v1.5/users/deletegroupfromuser.md): Remove an assigned Security Group from a User Profile. ## (NEW!) List Users (Paginated) - [GET /users](https://api.tenovos.com/openapi/v1.5/users/listusers.md): Retrieve an offset-paginated, searchable list of users for the authenticated customer. Supports free-text search, status/role/group filtering, and server-side sorting. This endpoint supersedes GET /user/search/{searchText} — it adds userName to the searchable fields and returns createdEpoch/lastUpdatedEpoch on every result. Defaults: - from defaults to 0. - limit defaults to 100 (values above 100 are capped to 100). - sortField defaults to firstName. - order defaults to desc. Business Rules: - searchTerm is trimmed and, when non-empty, matched as a case-insensitive substring against first name, last name, friendly name, email, status, phone, company, country, contact, userName, role name, and group name. Literal % and _ are treated as text, not SQL wildcards. Omitted returns all users — no * sentinel required. - role and group are comma-separated lists of role/group names (not ids); multiple values use OR logic. - status accepts enabled, disabled, pendingApproval. allDisabled is not a supported value and is rejected with 400. Omitted returns users of any status. - groupCount (as a sortField value) sorts by the number of group ids in the user's groups array; a user with no groups sorts as 0, never null. It does not add a groupCount field to the response. - roleName (as a sortField value) sorts using the user's associated role name. - status (as a sortField value) sorts alphabetically by the stored status value. - Each result includes both the id and display name for its role (roleId/roleName) and for each group (groupId/groupName) — the front end does not need to resolve ids to names itself. - connectUser indicates whether the user can access Tenovos Connect. connectRole holds that user's Tenovos Connect role and is null when connectUser is false. The connectUser query parameter filters on this same field: true returns only Tenovos Connect users, false returns only users who are not, and omitting it applies no filter at all rather than defaulting to either. The user submitting the request must have the User Management privilege. ## (NEW!) Get User Status Counts - [GET /users/status-counts](https://api.tenovos.com/openapi/v1.5/users/getuserstatuscounts.md): Retrieve user totals by status for the authenticated customer, calculated in a single grouped query. Backs the User Management screen's status tabs without running a separate paginated GET /users query per status. Business Rules: - This endpoint does not currently accept any query parameters — the counts always represent the complete user population for the authenticated customer and are unaffected by the search/filter state of GET /users. Filtering may be added later as an additive change. - All four properties are always returned, including 0 for a status with no matching users. - Pending-approval identification preserves the existing User Management status/update-attribution rules. The user submitting the request must have the User Management privilege. ## Search User Profiles (deprecated) - [GET /user/search/{searchText}](https://api.tenovos.com/openapi/v1.5/users/getuserbytext.md): Use this endpoint to retrieve a list of User Profiles matching the search keyword provided in the request parameter. Do not enter your search term wrapped in quotation marks. Provided keyword will be matched against the user attributes case insensitively - First Name, Last Name, Friendly Name, Username, Email, Phone, Company, Contact, Country, Status, Group Names, and Role Name. Entering "*" as your search term will return all users. The response is formatted as an area of objects, with each user account being returned as an object, as well as a key called 'count', which indicates how many accounts met the search critera. A maximum limit of 100 accounts will be returned in the response. In the case that more than 100 accounts meet the search criteria, pagination using the optional 'from' and 'limit' query parameters will be required to retrieve all accounts. The user performing this action must have the 'User Management' role privilege. How to use pagination: Pagination should be used when the amount of user accounts that match the entered search term exceeds the amount of users (100) returned in a single response. Paginating through the results will require making more than one call to this endpoint. To retrieve the first 100 users, in your query parameters, set your 'from' value to 0, and your 'limit' value to 100. To return the next set of 100 users, leave your 'limit' value as 100, but set your 'from' value to 100. Continue to repeat this process of adding 100 to your 'from' value until all user account results are captured.