openapi: 3.2.0 info: title: Dynatrace Account Management User Management API description: The enterprise management API for Dynatrace SaaS enables automation of operational tasks related to user access and environment lifecycle management. version: '1.0' contact: {} servers: [] tags: - name: User Management description: Manage users in an account and their group memberships. paths: /iam/v1/accounts/{account-uuid}/users: get: operationId: UsersController_getUsers parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string - name: service-users required: false in: query description: Specifies whether service users are included in results. schema: type: boolean responses: '200': description: Success. The response contains the list of users. content: application/json: schema: $ref: '#/components/schemas/UserListDto' security: - bearer: [] summary: Lists all users of an account tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-read post: operationId: UsersController_createUserForAccount parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string requestBody: required: true description: The JSON body of the request. Contains the email address of the new user. content: application/json: schema: $ref: '#/components/schemas/UserEmailDto' responses: '201': description: Success. The new user has been created. Response contains userUuid. security: - bearer: [] summary: Creates a new user in an account tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-write /iam/v1/accounts/{account-uuid}/users/{email}: get: operationId: UsersController_getUserGroups parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string - name: email required: true in: path description: The email address of the required user. schema: type: string responses: '200': description: Success. The response contains the groups of the user. content: application/json: schema: $ref: '#/components/schemas/GroupUserDto' security: - bearer: [] summary: Lists all groups of a user tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-read post: operationId: UsersController_addUserToGroups parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string - name: email required: true in: path description: The email address of the required user. schema: type: string requestBody: required: true description: "The body of the request. Contains a list of groups (specified by UUIDs) to which the user is to be added. The limit is 200 groups. \n\n Any existing group membership remains unaffected." content: application/json: schema: type: array items: type: string responses: '201': description: Success. The user has been added to the groups. Response doesn't have a body. security: - bearer: [] summary: Adds a user to groups. Any existing group membership remains unaffected tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-write delete: operationId: UsersController_removeUserFromAccount parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string - name: email required: true in: path description: The email address of the required user. schema: type: string responses: '200': description: Success. The user has been deleted. Response doesn't have a body. security: - bearer: [] summary: Removes a user from an account tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-write /iam/v1/accounts/{account-uuid}/users/{email}/groups: put: operationId: UsersController_replaceUserGroups parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string - name: email required: true in: path description: The email address of the required user. schema: type: string requestBody: required: true description: "The body of the request. Contains a list of groups (specified by UUIDs) where the user is to be a member. The limit is 200 groups. \n\n The user will be removed from any group that is not specified here." content: application/json: schema: type: array items: type: string responses: '200': description: Success. The group membership has been set. Response doesn't have a body. security: - bearer: [] summary: Sets group membership of a user. Any existing membership is overwritten tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-write delete: operationId: UsersController_removeUserFromGroups parameters: - name: account-uuid required: true in: path description: "The ID of the required account. \n\n You can find the UUID on the **Account Management** > **Identity & access management** > **OAuth clients** page, during creation of an OAuth client." schema: type: string - name: email required: true in: path description: The email address of the required user. schema: type: string - name: group-uuid required: true in: query description: "A list of groups the user is no longer a member of. \n\n To specify several groups, use the following format: `group-uuid=aaaaaa&group-uuid=bbbb`. \n\n The limit is 200 groups." schema: type: array items: type: string responses: '200': description: Success. The user has been removed from groups. Response doesn't have a body. security: - bearer: [] summary: Removes a user from groups tags: - User Management x-required-permissions: - account-user-management x-token-scopes: - account-idm-write components: schemas: UserEmailDto: type: object properties: email: type: string description: The email address of the user. required: - email UserListDto: type: object properties: count: type: number description: The number of entries in the list. items: description: A list of the account's users. type: array items: $ref: '#/components/schemas/UsersDto' required: - count - items UsersDto: type: object properties: uid: type: string description: The UUID of the user. email: type: string description: The email address of the user. name: type: string description: The first name of the user. surname: type: string description: The last name of the user. userStatus: type: string enum: - ACTIVE - INACTIVE - PENDING - DELETED - ECUSTOMS_MANUALLY_BLOCKED description: "The status of this user in Dynatrace: \n\n* `ACTIVE`: The user is active.\n* `INACTIVE`: The user is deactivated and cannot sign in to Dynatrace. \n* `PENDING`: The user received an invitation, but hasn't completed sign-up yet. \n* `DELETED`: The user was deleted and cannot sign in to Dynatrace anymore. \n* `ECUSTOMS_MANUALLY_BLOCKED`: The user is blocked due to to a trade and export compliance violation. \n" emergencyContact: type: boolean description: The user is (`true`) or is not (`false`) an emergency contact for the account. userLoginMetadata: description: Available if user has logged into Dynatrace at least once allOf: - $ref: '#/components/schemas/UserLoginMetaDataDto' required: - uid - email GroupUserDto: type: object properties: uid: type: string description: The UUID of the user. email: type: string description: The email address of the user. name: type: string description: The first name of the user. surname: type: string description: The last name of the user. userStatus: type: string enum: - ACTIVE - INACTIVE - PENDING - DELETED - ECUSTOMS_MANUALLY_BLOCKED description: "The status of this user in Dynatrace: \n\n* `ACTIVE`: The user is active.\n* `INACTIVE`: The user is deactivated and cannot sign in to Dynatrace. \n* `PENDING`: The user received an invitation, but hasn't completed sign-up yet. \n* `DELETED`: The user was deleted and cannot sign in to Dynatrace anymore. \n* `ECUSTOMS_MANUALLY_BLOCKED`: The user is blocked due to to a trade and export compliance violation. \n" emergencyContact: type: boolean description: The user is (`true`) or is not (`false`) an emergency contact for the account. groups: description: A list of groups of which the user is a member. type: array items: $ref: '#/components/schemas/AccountGroupDto' required: - uid - email - groups UserLoginMetaDataDto: type: object properties: successfulLoginCounter: type: number description: The number of successful sign-ins. failedLoginCounter: type: number description: The number of failed sign-ins. lastSuccessfulLogin: type: string description: The date and time of the most recent successful sign-in in `2021-05-01T15:11:00Z` format. lastFailedLogin: type: string description: The date and time of the most recent failed sign-in in `2021-05-01T15:11:00Z` format. createdAt: type: string description: The date and time of user creation in `2021-05-01T15:11:00Z` format. updatedAt: type: string description: The date and time of the most recent modification to the user in `2021-05-01T15:11:00Z` format. required: - successfulLoginCounter - failedLoginCounter - lastSuccessfulLogin - lastFailedLogin - createdAt - updatedAt AccountGroupDto: type: object properties: groupName: type: string description: The name of the user group. uuid: type: string description: The UUID of the user group. owner: type: string enum: - LOCAL - SCIM - SAML - DCS - ALL_USERS description: The type of the group. `LOCAL`, `SCIM`, `SAML` and `DCS` corresponds to the identity provider from which the group originates. `ALL_USERS` is a special case of `LOCAL` group. It means that group is always assigned to all users in the account. accountUUID: type: string description: The UUID of the Dynatrace account. accountName: type: string description: The name of the Dynatrace account. description: type: string description: A short description of the group. createdAt: type: string description: The date and time of the group creation in `2021-05-01T15:11:00Z` format. updatedAt: type: string description: The date and time of the most recent modification to the group in `2021-05-01T15:11:00Z` format. required: - groupName - uuid - owner - accountUUID - accountName - description - createdAt - updatedAt securitySchemes: bearer: scheme: bearer bearerFormat: JWT type: http externalDocs: description: OpenAPI specification url: /openapi.json