client.identity.users
client.identity.users — the identity.users operations.
On AsyncKindgi every method is the same, awaited.
client.identity.users.list()
Section titled “client.identity.users.list()”list( *, limit: int | None = None, cursor: str | None = None, query: str | None = None, timeout: float | None = None,) -> UserCollectionPageList users in the tenant. GET /v1/identity/users
Cursor-paginated list of tenant users (sort order is binding-defined). Optional ?query= is a prefix match on displayName — the natural filter shape for a "search users" surface. primaryEmail may be redacted per tenant policy.
client.identity.users.get()
Section titled “client.identity.users.get()”get(*, timeout: float | None = None) -> UserRecordGet a user by id. GET /v1/identity/users/{userId}
client.identity.users.list_sessions()
Section titled “client.identity.users.list_sessions()”list_sessions(*, timeout: float | None = None) -> IdentitySessionCollectionPageList active sessions for a user. GET /v1/identity/users/{userId}/sessions
Returns the wire-safe IdentitySessionSummary shape — provider access-token + refresh-token never cross the wire, even to admins. Unknown user id returns an empty list (call GET /v1/identity/users/:userId first to distinguish "no sessions" from "no user").
client.identity.users.revoke_sessions()
Section titled “client.identity.users.revoke_sessions()”revoke_sessions( *, idempotency_key: str | None = None, timeout: float | None = None,) -> RevokeSessionsResultRevoke every active session for a user. POST /v1/identity/users/{userId}/revoke-sessions
Admin op — idempotent. Under the hood, deployments typically delegate to SessionStoreBinding.revokeAllForUser. Returns { revokedCount: 0 } when the user was already fully signed out.