# Manage users Find the people who sign in to your applications, check the state of their account, and act on it: edit a profile, reset a password, sign them out, disable the account, or open a support session. All of it is under **Users** in your tenant's dashboard; the matching management API operations are listed at the end for reference. Viewing users needs the **View users** permission, changing them needs **Manage users**, and impersonating needs **Impersonate users**. ## Find a user **Users** lists 20 people at a time and loads more as you scroll. **Search** matches username, email, display name, and first and last name. The filters are **Status** (**Active**, **Disabled**, **Suspended**), **Email verification**, **Principal** (**People** by default, or include the **Service accounts** behind machine applications), and **Created after** and **Created before**. Choose **Apply**, then select a row to open that person's page. ## Add a user People usually arrive by signing up through your application, under the [sign-up mode](https://www.udibo.com/docs/identity/sign-in-methods#decide-who-can-create-an-account) you chose. To add someone yourself, such as your first user: 1. Open **Users** → **Create user**. 2. Enter a **Username**, **First name** and **Last name**. **Email address**, **Display name** and **Password** are optional. A password must be at least 8 characters; leave it blank for someone who signs in with a social provider or an emailed code. 3. Choose **Create user**. You land on the new user's page. The address starts unverified, and creating the account sends no email. ## Read a user's page The header shows the username, a **Disabled** or **Suspended** badge, and the **Edit** and **More** buttons. The page then shows the account's details and email verification, two-factor enrollment, the reason a disabled account was disabled, its tenant-wide **Roles** (see [Permissions](https://www.udibo.com/docs/identity/permissions)), **Linked identities**, **Active sessions** each with **Revoke**, and the 20 most recent audit events under **Activity**. **Metadata** holds two JSON editors: **Metadata (admin)**, which the person cannot edit, and **User metadata**, which they can. **Save metadata** replaces both; see [Sign-up fields](https://www.udibo.com/docs/identity/signup-fields). **Edit** changes the username, names, display name and email. Moving the email to a different address clears its verified mark. ## Maintain an account The **More** menu holds account maintenance. **Reset password** sets a random password, shows it to you once, and signs them out everywhere; pass it on through a channel you trust. **Email a reset link** sends a reset email. **Mark email verified** and **Send a verification email** appear while the address is unverified. **Clear email suppression** appears when mail to the address was stopped, for example after a bounce, and lets your tenant email it again. ## Sign out, reset MFA, disable or suspend The **Danger zone** at the bottom of the page: - **Revoke all sessions** ends every session on its next request; they can sign in again at once. See [Sessions and sign-out](https://www.udibo.com/docs/identity/sessions). - **Reset multi-factor**, shown while they are enrolled, removes their authenticator and recovery codes and signs them out. See [MFA](https://www.udibo.com/docs/identity/mfa#resetting-a-users-mfa). - **Disable this account** takes a required reason, then **Disable account** signs them out everywhere, invalidates any password reset or verification link already sent, and refuses sign-in. Their username and email stay reserved. **Enable account** undoes it. You cannot disable your own account. - **Suspend user** also refuses sign-in and ends their sessions, and releases the username and email for someone else. The record is kept, and **Unsuspend user** restores it without bringing back any session. ## Open a support session Support impersonation is off by default. Turn it on under **Settings** → **General** → **Allow support impersonation**, then **Save settings**. The owner, admin and support access levels carry **Impersonate users**. 1. Open the person's page, then **More** → **Impersonate**. 2. Read the list of what you cannot do, and enter a **Reason** of up to 500 characters. Reference a ticket where you can. 3. Choose **Start impersonating**. Your browser opens the session on your tenant's own host and lands on your first-party application, or on a status page if you have not registered one. The session lasts at most one hour; end it early with **Stop impersonating**. You cannot impersonate yourself, a disabled or suspended account, a service account, or an administrator whose access level over the tenant is equal to or above yours. Udibo issues no tokens to an impersonated session and refuses every change, so you see your tenant's hosted account pages, read-only. The [audit log](https://www.udibo.com/docs/identity/audit-log) records the start and end with your reason, and the person sees both on their own security page. ## Management API reference These operations are dashboard-only today; see [choose the right API](https://www.udibo.com/docs/identity/apis#the-management-api). Paths are under `https://www.udibo.com/api/identity/{tenantId}`: | Method | Path | Scope | Dashboard equivalent | | -------- | ----------------------------------------- | ------------------------------ | ------------------------------ | | `GET` | `/users` | `identity:users:read` | The list and its filters | | `POST` | `/users` | `identity:users:write` | **Create user** | | `GET` | `/users/{id}` | `identity:users:read` | The user's page | | `PATCH` | `/users/{id}` | `identity:users:write` | **Edit** and **Save metadata** | | `DELETE` | `/users/{id}` | `identity:users:write` | **Suspend user** | | `POST` | `/users/{id}/unsuspend` | `identity:users:write` | **Unsuspend user** | | `POST` | `/users/{id}/disable` | `identity:users:write` | **Disable account** | | `POST` | `/users/{id}/enable` | `identity:users:write` | **Enable account** | | `POST` | `/users/{id}/password` | `identity:users:write` | **Reset password** | | `POST` | `/users/{id}/send-reset` | `identity:users:write` | **Email a reset link** | | `POST` | `/users/{id}/verify-email` | `identity:users:write` | **Mark email verified** | | `POST` | `/users/{id}/send-verification` | `identity:users:write` | **Send a verification email** | | `POST` | `/users/{id}/sessions/revoke` | `identity:users:write` | **Revoke all sessions** | | `POST` | `/users/{id}/sessions/{sessionId}/revoke` | `identity:users:write` | **Revoke** on one session | | `POST` | `/users/{id}/reset-mfa` | `identity:users:write` | **Reset multi-factor** | | `POST` | `/users/{id}/impersonate` | `identity:users:impersonate` | **Impersonate** | | `GET` | `/users/{id}/roles` | `identity:organizations:read` | **Roles** | | `POST` | `/users/{id}/roles` | `identity:organizations:write` | **Assign** | | `DELETE` | `/users/{id}/roles/{roleId}` | `identity:organizations:write` | **Revoke** on a role | The list takes `search`, `status`, `emailVerified`, `type`, `createdAfter` and `createdBefore`, parsed the same way as the dashboard filters; an unknown value is refused with a 400. `disable` and `impersonate` take `{"reason": "..."}`, and `password` takes `{"password": "..."}`, checked against your [password policy](https://www.udibo.com/docs/identity/account-protection#set-the-password-policy). `impersonate` returns a single-use `handoffUrl` to open in the browser. The full reference is in the [API reference](https://www.udibo.com/docs/api). ## Limits today - There is no invitation email for a user you create, no bulk action, and no permanent deletion; **Suspend user** keeps the record. - The dashboard's **Create user** form checks only the 8-character minimum, not your tenant's password policy; the API checks the policy. - **Clear email suppression** has no API equivalent. - Roles assigned on a user's page are tenant-wide. For roles inside an organization, see [organizations](https://www.udibo.com/docs/identity/organizations#roles-inside-an-organization). - No dashboard control lifts a sign-in lockout; see [Protect accounts](https://www.udibo.com/docs/identity/account-protection#help-a-locked-out-person-back-in). Next: [protect accounts](https://www.udibo.com/docs/identity/account-protection), [read the audit log](https://www.udibo.com/docs/identity/audit-log), or [manage sessions](https://www.udibo.com/docs/identity/sessions). _Last verified 2026-09-29._