---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "List end users"
description: "`auth.end_users.list` (GET /v1/{parent}/end_users): Lists end users."
type: reference
product: auth
summary: "Lists end users."
updated: 2026-09-28
nav: false
---

Lists end users.

- **Path** `GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users`
- **Scope** `auth:read`
- **Effect** `read` — nothing is written.
- **Collection** [end_users](/docs/api/end_users)
- **Query** `page_size`, `page_token`, `filter`, `order_by`
- **Pagination** the answer carries `end_users` and, when there is more, `next_page_token`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The parent to list in. Required. |
| `page_size` | `int32` | At most this many; default 50, clamped to 1000. |
| `page_token` | `string` | `next_page_token` of the previous page. |
| `filter` | `string` | AIP-160 filter over labels and filterable fields. |
| `order_by` | `string` | AIP-132 ordering over filterable fields. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `end_users` | `EndUser[]` | The page. |
| `next_page_token` | `string` | The token of the next page; empty on the last page. |

### EndUser

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}`. |
| `uid` | `string` | `usr_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `email` | `string` | The primary email address. |
| `email_verify_time` | `timestamp` | When `email` was verified. Output only. |
| `password` | `string` | An initial password; write-only, checked against breached passwords. Never returned again. |
| `state` | `EndUserState` | The lifecycle state. Output only. One of `active`, `suspended`. |
| `factors` | `AuthMethod[]` | Enrolled factors. Output only. One of `password`, `magic_link`, `email_otp`, `passkey`, `totp`, `oidc`, `saml`. |
| `public_metadata` | `struct` | App data readable by the end user's own tokens. |
| `private_metadata` | `struct` | App data readable only with an Access key. |
| `last_login_time` | `timestamp` | The last successful sign-in. Output only. |
| `unsafe_metadata` | `struct` | App data the end user may write with their own session (preferences a sign-up form collects); never trust it for authorization. |
| `lock_expire_time` | `timestamp` | Until when sign-in is locked after repeated failures; unset when not locked. Unlock clears it; a suspension is `state`, not a lock. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`PAGE_TOKEN_MISMATCH`](/docs/api/errors/PAGE_TOKEN_MISMATCH) — A page token was reused with different parameters.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"
```

**TypeScript**

```ts
const response = await sylphx.auth.endUsers.list({ parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::auth::ListEndUsersRequest::default();
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.auth().end_users().list(req).await?;
```

**CLI**

```bash
sylphx auth end-users list orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "auth.end_users.list", "args": {"parent":"orgs/acme/projects/shop/envs/production"} }
```
