openapi: 3.1.0 info: title: Class Developer Classes Users API version: v1 x-apievangelist-provenance: generated: '2026-07-18' method: generated source: https://developer.class.com/ note: Faithful OpenAPI reconstruction of the operations, paths, HTTP methods, authentication scheme, permission scopes, pagination model and documented request fields published on developer.class.com. Request/response object schemas capture only fields named in the public documentation; no fields were invented. This is an API Evangelist generated spec, not a Class-published artifact. description: REST API for Class (fka ClassEDU), the virtual classroom platform built for Zoom and Microsoft Teams. The API lets administrators and integrators provision classes, manage enrollments, generate learner launch links, schedule class dates, manage reusable class templates, manage non-learner users, and pull attendance and engagement reporting. Authentication uses a per-organization API key presented as a Bearer token, gated by permission scopes. contact: name: Class Developer Platform url: https://developer.class.com/ termsOfService: https://www.class.com/terms-of-service/ servers: - url: https://{organization}.class.com description: Base URL is unique to each organization and is retrieved from the API Keys page in the Class Admin UI after an API key is created. variables: organization: default: your-organization description: Your organization's Class subdomain. security: - bearerAuth: [] tags: - name: Users description: Manage non-learner users (instructors, admins). paths: /api/v1/users: put: operationId: upsertUser summary: Create or Update a User tags: - Users security: - bearerAuth: - user:write requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UserUpsert' responses: '200': $ref: '#/components/responses/UserResponse' '201': $ref: '#/components/responses/UserResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' get: operationId: getUsers summary: Get users description: Get all users, or a single user by id or ext_user_id. tags: - Users security: - bearerAuth: - user:read parameters: - $ref: '#/components/parameters/UserId' - $ref: '#/components/parameters/ExtUserId' - $ref: '#/components/parameters/Page' - $ref: '#/components/parameters/Limit' responses: '200': $ref: '#/components/responses/UserListResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' delete: operationId: deleteUser summary: Remove a User tags: - Users security: - bearerAuth: - user:write parameters: - $ref: '#/components/parameters/UserId' - $ref: '#/components/parameters/ExtUserId' responses: '200': $ref: '#/components/responses/Deleted' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' components: schemas: Error: type: object properties: message: type: string description: Human-readable explanation of the failure. UserUpsert: type: object properties: identified_by: type: string description: Which identifier the request keys on (id or ext_user_id). id: type: string ext_user_id: type: string email: type: string format: email user_name: type: string roles: type: array items: type: string User: type: object properties: id: type: string ext_user_id: type: string email: type: string format: email user_name: type: string roles: type: array items: type: string Pagination: type: object properties: total_records: type: integer current_page: type: integer total_pages: type: integer next_page: type: - integer - 'null' prev_page: type: - integer - 'null' parameters: UserId: name: id in: query description: User identifier assigned by Class. required: false schema: type: string Limit: name: limit in: query description: Records per page (1-1000). required: false schema: type: integer minimum: 1 maximum: 1000 default: 100 ExtUserId: name: ext_user_id in: query description: External user identifier supplied by the integrator. required: false schema: type: string Page: name: page in: query description: Page number to retrieve (positive integer). required: false schema: type: integer minimum: 1 default: 1 responses: Unauthorized: description: Unauthorized - missing or invalid API key. content: application/json: schema: $ref: '#/components/schemas/Error' UserResponse: description: A user. content: application/json: schema: $ref: '#/components/schemas/User' NotFound: description: Not Found. content: application/json: schema: $ref: '#/components/schemas/Error' Forbidden: description: Forbidden - the API key lacks the required scope. content: application/json: schema: $ref: '#/components/schemas/Error' Deleted: description: The resource was removed. BadRequest: description: Bad Request - validation failed. content: application/json: schema: $ref: '#/components/schemas/Error' UserListResponse: description: A page of users. content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/User' pagination: $ref: '#/components/schemas/Pagination' securitySchemes: bearerAuth: type: http scheme: bearer description: 'Per-organization API key presented as a Bearer token in the Authorization header (Authorization: Bearer ). The key secret is shown only once, at key creation, in the Admin UI. Each key is granted a set of permission scopes; selecting a write scope automatically grants the matching read scope. Documented scopes: class:read, class:write, enrollment:read, enrollment:write, attendance:read, metrics:read, schedule:read, schedule:write, template:read, template:write, user:read, user:write.'