Disable user
const url = 'http://localhost:3000/api/v1/users/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/disable';const options = { method: 'POST', headers: {'X-API-Key': '<X-API-Key>', 'Content-Type': 'application/json'}, body: '{"reason":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:3000/api/v1/users/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/disable \ --header 'Content-Type: application/json' \ --header 'X-API-Key: <X-API-Key>' \ --data '{ "reason": "example" }'Disables a user account. Requires Super Admin privileges. Cannot disable yourself or other superusers unless you are a superuser.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”User UUID
Request Bodyrequired
Section titled “Request Bodyrequired”object
Reason for disabling the user
Examplegenerated
{ "reason": "example"}Responses
Section titled “Responses”User disabled successfully
object
Unique user identifier
User email address
User display name
Whether the user account is active
Whether the user email has been verified
Whether the user is a super admin with platform-wide privileges
When the user was created
When the user was last updated
When the user last logged in
FM-1069: the Keycloak identity-provider alias the user last authenticated through (e.g. the Entra broker alias), or null for a local realm login.
FM-1069: whether the user authenticates through an external identity provider (federated). The UI hides the password-reset action when true, since federated users have no local password to reset.
True when this account cannot sign in to its organizations because its e-mail address is unverified AND it is not yet bound to a Keycloak identity. Both conditions matter: an unverified address only blocks the e-mail-keyed binding (FM-837), which is never attempted for an account that is already bound. An already-bound account with an unverified address signs in perfectly well, so flagging it would be a false alarm.
Example
{ "id": "550e8400-e29b-41d4-a716-446655440000", "email": "john.doe@example.com", "name": "John Doe", "active": true, "emailVerified": true, "isSuperAdmin": false, "createdAt": "2024-01-15T10:30:00Z", "updatedAt": "2024-06-20T14:45:00Z", "lastLoginAt": "2024-12-20T09:15:00Z", "identityProvider": "entra", "isFederated": false, "pendingEmailVerification": false}User is already disabled
Unauthorized
Forbidden - Cannot disable yourself or superusers
User not found