> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/get-project-access/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Get users and groups in project GET https://app.unleash-instance.example.com/api/admin/projects/{projectId}/access **Enterprise feature** Get all groups, users and their roles, and available roles for the given project. Reference: https://docs.getunleash.io/api/get-project-access ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Request ### Path parameters - `projectId` (string, required) ## Response ### 200 projectAccessSchema - `groups` (list of groupWithProjectRoleSchema, required) — A list of groups that have access to this project - `users` (list of userWithProjectRoleSchema, required) — A list of users and their roles within this project - `roles` (list of roleSchema, required) — A list of roles that are available within this project. ## Errors ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### groupWithProjectRoleSchema Data about a group including their project role - `id` (integer, required) — The group's ID in the Unleash system - `name` (string, optional) — The name of the group - `addedAt` (string, optional) — When this group was added to the project - `roleId` (integer, optional) — The ID of the role this group has in the given project - `roles` (list of integer, optional) — A list of roles this user has in the given project - `description` (string, optional, nullable) — A custom description of the group - `mappingsSSO` (list of string, optional) — A list of SSO groups that should map to this Unleash group - `rootRole` (double, optional, nullable) — A role id that is used as the root role for all users in this group. This can be either the id of the Viewer, Editor or Admin role. - `createdBy` (string, optional, nullable) — A user who created this group - `createdAt` (string, optional, nullable) — When was this group created - `users` (list of groupUserModelSchema, optional) — A list of users belonging to this group - `scimId` (string, optional, nullable) — The SCIM ID of the group, only present if managed by SCIM ### userWithProjectRoleSchema Data about a user including their project role - `id` (integer, required) — The user's ID in the Unleash system - `name` (string, optional) — The name of the user - `email` (string, optional, nullable) — The user's email address - `imageUrl` (string, optional, nullable) — A URL pointing to the user's image. - `addedAt` (string, optional) — When this user was added to the project - `roleId` (integer, optional) — The ID of the role this user has in the given project - `roles` (list of integer, optional) — A list of roles this user has in the given project - `isAPI` (boolean, optional, deprecated) — Whether this user is authenticated through Unleash tokens or logged in with a session ### roleSchema A role holds permissions to allow Unleash to decide what actions a role holder is allowed to perform - `id` (integer, required) — The role id - `type` (string, required) — A role can either be a global root role (applies to all projects) or a project role - `name` (string, required) — The name of the role - `description` (string, optional) — A more detailed description of the role and what use it's intended for - `project` (string, optional, nullable) — What project the role belongs to ### groupUserModelSchema Details for a single user belonging to a group - `user` (userSchema, required) — An Unleash user - `joinedAt` (string, optional) — The date when the user joined the group - `createdBy` (string, optional, nullable) — The username of the user who added this user to this group ### userSchema An Unleash user - `id` (integer, required) — The user id - `name` (string, optional, nullable) — Name of the user - `email` (string, optional) — Email of the user - `username` (string, optional, nullable) — A unique username for the user - `imageUrl` (string, optional) — URL used for the user profile image - `inviteLink` (string, optional) — If the user is actively inviting other users, this is the link that can be shared with other users - `loginAttempts` (integer, optional) — How many unsuccessful attempts at logging in has the user made - `emailSent` (boolean, optional) — Is the welcome email sent to the user or not - `rootRole` (integer, optional) — Which [root role](https://docs.getunleash.io/concepts/rbac#predefined-roles) this user is assigned - `seenAt` (string, optional, nullable) — The last time this user logged in - `createdAt` (string, optional) — The user was created at this time - `accountType` (enum, optional) — A user is either an actual User or a Service Account - Allowed values: `User`, `Service Account` - `permissions` (list of string, optional) — Deprecated - `scimId` (string, optional, nullable) — The SCIM ID of the user, only present if managed by SCIM - `seatType` (string, optional, nullable) — The seat type of this user - `companyRole` (string, optional, nullable) — The role of the user within the company. - `productUpdatesEmailConsent` (boolean, optional, nullable) — Whether the user has consented to receive product update emails. - `activeSessions` (integer, optional, nullable) — Count of active browser sessions for this user - `deletedSessions` (double, optional) — Experimental. The number of deleted browser sessions after last login ## Examples **Response** ```json { "groups": [ { "id": 1, "name": "DX team", "addedAt": "2023-08-01T14:35:16Z", "roleId": 5, "roles": [ 5 ], "description": "Current members of the DX squad", "mappingsSSO": [ "SSOGroup1", "SSOGroup2" ], "rootRole": 1, "createdBy": "admin", "createdAt": "2023-06-30T11:41:00.123Z", "users": [ { "user": { "id": 123, "name": "User", "email": "user@example.com", "username": "hunter", "imageUrl": "https://example.com/242x200.png", "inviteLink": "http://localhost:4242/invite-link/some-secret", "loginAttempts": 3, "emailSent": false, "rootRole": 1, "seenAt": "2023-06-30T11:42:00.345Z", "createdAt": "2023-06-30T11:41:00.123Z", "accountType": "User", "permissions": [ "string" ], "scimId": "01HTMEXAMPLESCIMID7SWWGHN6", "seatType": "Regular", "companyRole": "Developer", "productUpdatesEmailConsent": false, "activeSessions": 2, "deletedSessions": 1 }, "joinedAt": "2023-06-30T11:41:00.123Z", "createdBy": "admin" } ], "scimId": "01HTMEXAMPLESCIMID7SWWGHN7" } ], "users": [ { "id": 1, "name": "Hunter Burgan", "email": "hunter@hunter.com", "imageUrl": "string", "addedAt": "2023-08-01T14:35:16Z", "roleId": 5, "roles": [ 5 ], "isAPI": false } ], "roles": [ { "id": 9, "type": "root", "name": "Editor", "description": "Users with the editor role have access to most features in Unleash but can not manage users and roles in the global scope. Editors will be added as project owners when creating projects and get superuser rights within the context of these projects. Users with the editor role will also get access to most permissions on the default project by default.", "project": "default" } ] } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/projects/projectId/access" headers = {"Authorization": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/projects/projectId/access'; const options = {method: 'GET', headers: {Authorization: ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/projects/projectId/access" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/projects/projectId/access") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://app.unleash-instance.example.com/api/admin/projects/projectId/access") .header("Authorization", "") .asString(); ``` ```php request('GET', 'https://app.unleash-instance.example.com/api/admin/projects/projectId/access', [ 'headers' => [ 'Authorization' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/projects/projectId/access"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/projects/projectId/access")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```