list_end_users

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/list_end_users, with a bearer credential and the action's payload as the JSON body. It also accepts GET.

Contract description

List an application's end users, a page at a time: each user's opaque id, when it was created, its standing, its sign-in methods, and its provider-verified or tenant-asserted email address. A work-account-only user's address is the one its tenant asserts, marked so. The answer's `next_cursor` fetches the next page. An optional `environment` (`development` or `production`; absent, `production`) names the realm the call addresses, development's standing only once `create_environment` has turned development on.

Access and action metadata

{
  "name": "list_end_users",
  "resource": "realm",
  "tier": "observe",
  "summary": "Each end user's opaque identifier, creation stamp, standing, routes, and provider-verified or tenant-asserted address, paged.",
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "openWorldHint": false,
    "idempotentHint": true
  }
}

MCP catalog entry

{
  "name": "list_end_users",
  "tier": "observe",
  "summary": "List an application's end users, a page at a time: each user's opaque id, when it was created, its standing, its sign-in methods, and its provider-verified or tenant-asserted email address. A work-account-only user's address is the one its tenant asserts, marked so. The answer's `next_cursor` fetches the next page. An optional `environment` (`development` or `production`; absent, `production`) names the realm the call addresses, development's standing only once `create_environment` has turned development on.",
  "owners": [
    "ACS-L0-01",
    "PLD-L0-40"
  ],
  "scenario": "ACS-L0-08"
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["application"]
Additional properties: false
/properties/application The application id, from `list_applications`.

Type: string
/properties/cursor The `next_cursor` a previous page answered; omitted, the first page.

Type: string
/properties/limit Users per page, 1 to 200; 50 where none is given.

Type: integer
Minimum: 1
Maximum: 200
/properties/environment Optional. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement); absent, `production`.

Type: string
Pattern: ^(development|production)$

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","end_users","next_cursor"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/end_users Type: array
/properties/end_users/items Type: object
Required fields: ["id","created_at","standing","routes","email","email_verified"]
Additional properties: false
/properties/end_users/items/properties/id Type: string
/properties/end_users/items/properties/created_at Type: string
/properties/end_users/items/properties/standing Allowed values: ["active","suspended"]
/properties/end_users/items/properties/routes Type: array
/properties/end_users/items/properties/routes/items Type: string
/properties/end_users/items/properties/email The user's address: a verified one, or, for a user who signed in by work account alone, the address the work-account tenant asserts, marked by `email_source`. Null where the user holds none.

Type: ["string","null"]
/properties/end_users/items/properties/email_verified Whether the address is verified. A tenant-asserted address is verified only where the tenant's token stated the domain owner verified it; false otherwise.

Type: boolean
/properties/end_users/items/properties/email_source Present, `tenant`, where the address comes from the work-account tenant; `email_verified` is then true only where the tenant's token stated the domain owner verified it.

Allowed values: ["tenant"]
/properties/next_cursor Type: ["string","null"]
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "application"
    ],
    "properties": {
      "application": {
        "type": "string",
        "description": "The application id, from `list_applications`."
      },
      "cursor": {
        "type": "string",
        "description": "The `next_cursor` a previous page answered; omitted, the first page."
      },
      "limit": {
        "type": "integer",
        "minimum": 1,
        "maximum": 200,
        "description": "Users per page, 1 to 200; 50 where none is given."
      },
      "environment": {
        "type": "string",
        "pattern": "^(development|production)$",
        "description": "Optional. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement); absent, `production`."
      }
    },
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "end_users",
      "next_cursor"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "end_users": {
        "type": "array",
        "items": {
          "type": "object",
          "required": [
            "id",
            "created_at",
            "standing",
            "routes",
            "email",
            "email_verified"
          ],
          "properties": {
            "id": {
              "type": "string"
            },
            "created_at": {
              "type": "string"
            },
            "standing": {
              "enum": [
                "active",
                "suspended"
              ]
            },
            "routes": {
              "type": "array",
              "items": {
                "type": "string"
              }
            },
            "email": {
              "type": [
                "string",
                "null"
              ],
              "description": "The user's address: a verified one, or, for a user who signed in by work account alone, the address the work-account tenant asserts, marked by `email_source`. Null where the user holds none."
            },
            "email_verified": {
              "type": "boolean",
              "description": "Whether the address is verified. A tenant-asserted address is verified only where the tenant's token stated the domain owner verified it; false otherwise."
            },
            "email_source": {
              "enum": [
                "tenant"
              ],
              "description": "Present, `tenant`, where the address comes from the work-account tenant; `email_verified` is then true only where the tenant's token stated the domain owner verified it."
            }
          },
          "additionalProperties": false
        }
      },
      "next_cursor": {
        "type": [
          "string",
          "null"
        ]
      },
      "detail": {
        "type": "string"
      }
    },
    "additionalProperties": false
  }
}

Shared contracts