Manage users
Find the people who sign in to your applications, check the state of their account, and act on it: edit a profile, reset a password, sign them out, disable the account, or open a support session. All of it is under Users in your tenant's dashboard; the matching management API operations are listed at the end for reference. Viewing users needs the View users permission, changing them needs Manage users, and impersonating needs Impersonate users.
Find a user
Users lists 20 people at a time and loads more as you scroll. Search matches username, email, display name, and first and last name. The filters are Status (Active, Disabled, Suspended), Email verification, Principal (People by default, or include the Service accounts behind machine applications), and Created after and Created before. Choose Apply, then select a row to open that person's page.
Add a user
People usually arrive by signing up through your application, under the sign-up mode you chose. To add someone yourself, such as your first user:
Open Users → Create user.
Enter a Username, First name and Last name. Email address, Display name and Password are optional. A password must be at least 8 characters; leave it blank for someone who signs in with a social provider or an emailed code.
Choose Create user. You land on the new user's page.
The address starts unverified, and creating the account sends no email.
Read a user's page
The header shows the username, a Disabled or Suspended badge, and the Edit and More buttons. The page then shows the account's details and email verification, two-factor enrollment, the reason a disabled account was disabled, its tenant-wide Roles (see Permissions), Linked identities, Active sessions each with Revoke, and the 20 most recent audit events under Activity. Metadata holds two JSON editors: Metadata (admin), which the person cannot edit, and User metadata, which they can. Save metadata replaces both; see Sign-up fields.
Edit changes the username, names, display name and email. Moving the email to a different address clears its verified mark.
Maintain an account
The More menu holds account maintenance. Reset password sets a random password, shows it to you once, and signs them out everywhere; pass it on through a channel you trust. Email a reset link sends a reset email. Mark email verified and Send a verification email appear while the address is unverified. Clear email suppression appears when mail to the address was stopped, for example after a bounce, and lets your tenant email it again.
Sign out, reset MFA, disable or suspend
The Danger zone at the bottom of the page:
Revoke all sessions ends every session on its next request; they can sign in again at once. See Sessions and sign-out.
Reset multi-factor, shown while they are enrolled, removes their authenticator and recovery codes and signs them out. See MFA.
Disable this account takes a required reason, then Disable account signs them out everywhere, invalidates any password reset or verification link already sent, and refuses sign-in. Their username and email stay reserved. Enable account undoes it. You cannot disable your own account.
Suspend user also refuses sign-in and ends their sessions, and releases the username and email for someone else. The record is kept, and Unsuspend user restores it without bringing back any session.
Open a support session
Support impersonation is off by default. Turn it on under Settings → General → Allow support impersonation, then Save settings. The owner, admin and support access levels carry Impersonate users.
Open the person's page, then More → Impersonate.
Read the list of what you cannot do, and enter a Reason of up to 500 characters. Reference a ticket where you can.
Choose Start impersonating. Your browser opens the session on your tenant's own host and lands on your first-party application, or on a status page if you have not registered one.
The session lasts at most one hour; end it early with Stop impersonating. You cannot impersonate yourself, a disabled or suspended account, a service account, or an administrator whose access level over the tenant is equal to or above yours. Udibo issues no tokens to an impersonated session and refuses every change, so you see your tenant's hosted account pages, read-only. The audit log records the start and end with your reason, and the person sees both on their own security page.
Management API reference
These operations are dashboard-only today; see
choose the right API.
Paths are under https://www.udibo.com/api/identity/{tenantId}:
| Method | Path | Scope | Dashboard equivalent |
|---|---|---|---|
GET | /users | identity:users:read | The list and its filters |
POST | /users | identity:users:write | Create user |
GET | /users/{id} | identity:users:read | The user's page |
PATCH | /users/{id} | identity:users:write | Edit and Save metadata |
DELETE | /users/{id} | identity:users:write | Suspend user |
POST | /users/{id}/unsuspend | identity:users:write | Unsuspend user |
POST | /users/{id}/disable | identity:users:write | Disable account |
POST | /users/{id}/enable | identity:users:write | Enable account |
POST | /users/{id}/password | identity:users:write | Reset password |
POST | /users/{id}/send-reset | identity:users:write | Email a reset link |
POST | /users/{id}/verify-email | identity:users:write | Mark email verified |
POST | /users/{id}/send-verification | identity:users:write | Send a verification email |
POST | /users/{id}/sessions/revoke | identity:users:write | Revoke all sessions |
POST | /users/{id}/sessions/{sessionId}/revoke | identity:users:write | Revoke on one session |
POST | /users/{id}/reset-mfa | identity:users:write | Reset multi-factor |
POST | /users/{id}/impersonate | identity:users:impersonate | Impersonate |
GET | /users/{id}/roles | identity:organizations:read | Roles |
POST | /users/{id}/roles | identity:organizations:write | Assign |
DELETE | /users/{id}/roles/{roleId} | identity:organizations:write | Revoke on a role |
The list takes search, status, emailVerified, type, createdAfter and
createdBefore, parsed the same way as the dashboard filters; an unknown value
is refused with a 400. disable and impersonate take {"reason": "..."}, and
password takes {"password": "..."}, checked against your
password policy.
impersonate returns a single-use handoffUrl to open in the browser. The full
reference is in the API reference.
Limits today
There is no invitation email for a user you create, no bulk action, and no permanent deletion; Suspend user keeps the record.
The dashboard's Create user form checks only the 8-character minimum, not your tenant's password policy; the API checks the policy.
Clear email suppression has no API equivalent.
Roles assigned on a user's page are tenant-wide. For roles inside an organization, see organizations.
No dashboard control lifts a sign-in lockout; see Protect accounts.
Next: protect accounts, read the audit log, or manage sessions.
Last verified 2026-09-29.

