# List all users

```
GET 
https://api.freemius.com/v1/products/{product_id}/users.json
```

#### Auth:Bearer TokenSCOPE: <!-- -->PRODUCT

Product-scoped API tokens allow you to operate on the product itself. This token usually allows read-only access to the product configuration and write access to several operations on subscriptions, customers, payments, and more. For most SaaS or app integrations, this is the token you will need.

1. Go to the [Freemius Developer Dashboard](https://dashboard.freemius.com/).
2. Open the Settings page of the relevant product.
3. Click the API & Keys tab.
4. Copy the API Bearer Authorization Token from the UI.

***

Gets the user collection associated with a product.

## Filtering[​](#filtering "Direct link to Filtering")

There are a few filters that can be applied to the request.

### Search by email[​](#search-by-email "Direct link to Search by email")

You can specify the parameter `email` to filter the users by email. Optionally you can also put a valid email in the `search` parameter.

### Other filtering options[​](#other-filtering-options "Direct link to Other filtering options")

The `search` parameter also accepts the following values:

1. User ID (number).
2. Full or partial name (string).
3. Full or partial email (string).

## Pagination[​](#pagination "Direct link to Pagination")

You can use the combination of `count` and `offset` parameters to paginate the results.

## Request[​](#request "Direct link to request")

### Path Parameters

* **product\_id**
  <!-- -->
  integer\<int64>[](#param-property-users-list-param-path-product-id "Direct link to product_id")required

  The ID of the product.

  **Possible values:** `>= 1`

  **Example:<!-- -->&#x20;**`1234`

### Query Parameters

* **fields**
  <!-- -->
  string[](#param-property-users-list-param-query-fields "Direct link to fields")

  Comma separated list of fields to return in the response. If not specified, all fields are returned.

  **Example:<!-- -->&#x20;**`id,name,slug`

  **count**
  <!-- -->
  integer[](#param-property-users-list-param-query-count "Direct link to count")

  **Default value:<!-- -->&#x20;**`25`

  The number of records to return.

  **Possible values:** `>= 1` and `<= 50`

  **Example:<!-- -->&#x20;**`10`

  **offset**
  <!-- -->
  integer[](#param-property-users-list-param-query-offset "Direct link to offset")

  **Default value:<!-- -->&#x20;**`0`

  The number of records to skip before starting to return records. Default is 0.

  **Possible values:** `>= 0`

  **Example:<!-- -->&#x20;**`10`

  **email**
  <!-- -->
  string[](#param-property-users-list-param-query-email "Direct link to email")

  Search user by email address.

  **filter**
  <!-- -->
  string[](#param-property-users-list-param-query-filter "Direct link to filter")

  Filter user by their financial status

  **Possible values:** \[`all`, `never_paid`, `paid`, `paying`, `beta`]

  **search**
  <!-- -->
  string[](#param-property-users-list-param-query-search "Direct link to search")

  Search by user ID, email or name

<!-- -->

## Responses[​](#responses "Direct link to Responses")

* 200
* 400
* 401
* 402
* 404

OK

application/json

**Schema**

**users** <!-- -->object\[]

* Array \[

**note**string[](#schema-property-users-list-response-schema-note-string "Direct link to note")

A note about the user. Only visible to the developer.

**is\_marketing\_allowed**boolean[](#schema-property-users-list-response-schema-is-marketing-allowed-boolean "Direct link to is_marketing_allowed")nullable

Whether or not the user has given their consent for marketing materials. A `null` value indicates that the user has not made a decision yet.

**is\_beta**boolean[](#schema-property-users-list-response-schema-is-beta-boolean "Direct link to is_beta")

Whether or not the user has opted-in to beta versions. We do not recommend using this option anymore since it will opt-in the user to all sites/activations. Currently, sites or activations can be managed individually.

**email**string[](#schema-property-users-list-response-schema-email-string "Direct link to email")

Email address of the person.

**Example:<!-- -->&#x20;**`jane@example.com`

**first**string[](#schema-property-users-list-response-schema-first-string "Direct link to first")

First name of the person.

**Example:<!-- -->&#x20;**`Jane`

**last**string[](#schema-property-users-list-response-schema-last-string "Direct link to last")

Last name of the person.

**Example:<!-- -->&#x20;**`Doe`

**picture**string[](#schema-property-users-list-response-schema-picture-string "Direct link to picture")

Profile picture URL.

**Example:<!-- -->&#x20;**`https://example.com/profile-pic.jpg`

**ip**string\<ipv4|ipv6>[](#schema-property-users-list-response-schema-ip-string-ipv4-ipv6 "Direct link to ip")nullable

The IP address (v4 or v6).

**Example:<!-- -->&#x20;**`127.0.0.1`

**is\_verified**boolean[](#schema-property-users-list-response-schema-is-verified-boolean "Direct link to is_verified")

Whether the person is trusted or not.

**Example:<!-- -->&#x20;**`true`

**auth**string[](#schema-property-users-list-response-schema-auth-string "Direct link to auth")

The type of authentication. If `app2fa` is set, the person has signed for 2FA authentication.

**Possible values:** \[`app2fa`, `password`]

**secret\_key**string[](#schema-property-users-list-response-schema-secret-key-string "Direct link to secret_key")

The secret key associated with the entity for authorization.

**Example:<!-- -->&#x20;**`sk_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6`

**public\_key**string[](#schema-property-users-list-response-schema-public-key-string "Direct link to public_key")

The public key associated with the entity for authorization.

**Example:<!-- -->&#x20;**`pk_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6`

**id**string\<int64>[](#schema-property-users-list-response-schema-id-string-int64 "Direct link to id")

The unique identifier of the entity.

**Possible values:** `>= 1`

**Example:<!-- -->&#x20;**`123456`

**created**string\<date-time>[](#schema-property-users-list-response-schema-created-string-date-time "Direct link to created")

The date and time the entity was created, under UTC timezone.

**Example:<!-- -->&#x20;**`2025-01-01 00:00:00`

**updated**string\<date-time>[](#schema-property-users-list-response-schema-updated-string-date-time "Direct link to updated")nullable

The date and time the entity was updated, under UTC timezone. If `null` then the entity was never updated since its creation.

**Example:<!-- -->&#x20;**`2025-01-01 00:00:00`

**gross**number\<float>[](#schema-property-users-list-response-schema-gross-number-float "Direct link to gross")

The total amount of money the user has spent on the platform.

**last\_login\_at**string\<date-time>[](#schema-property-users-list-response-schema-last-login-at-string-date-time "Direct link to last_login_at")nullable

Date and time of the last login.

**Example:<!-- -->&#x20;**`2025-07-30 05:56:29`

**email\_status**string[](#schema-property-users-list-response-schema-email-status-string "Direct link to email_status")

The status of the last email sent to the user.

**Possible values:** \[`delivered`, `bounce`, `dropped`]

* ]

Bad request. The request could not be understood by the server due to malformed syntax or arguments.

application/json

**Schema**

**path**string[](#schema-property-users-list-response-schema-path-string "Direct link to path")

The API request path.

**Example:<!-- -->&#x20;**`:/products/product_id/users.json`

**error** <!-- -->object

This object contains the error details.

**type**string[](#schema-property-users-list-response-schema-type-string "Direct link to type")

The type of the error encountered by the server.

**Example:<!-- -->&#x20;**`UnauthorizedAccess`

**message**string[](#schema-property-users-list-response-schema-message-string "Direct link to message")

The descriptive error message.

**Example:<!-- -->&#x20;**`Some error has occured.`

**code**string[](#schema-property-users-list-response-schema-code-string "Direct link to code")

The error code.

**Example:<!-- -->&#x20;**`unauthorized_access`

**http**integer[](#schema-property-users-list-response-schema-http-integer "Direct link to http")

The HTTP status code returned by the server.

**Example:<!-- -->&#x20;**`401`

**timestamp**string[](#schema-property-users-list-response-schema-timestamp-string "Direct link to timestamp")

Current timestamp.

**Example:<!-- -->&#x20;**`Thu, 11 May 2023 11:45:30 +0000`

**request** <!-- -->object

This object sends back the request payload as received by the server (both from path and from body or query).

**property name\***&#x61;ny[](#schema-property-users-list-response-schema-property-name-any "Direct link to property name*")

This object sends back the request payload as received by the server (both from path and from body or query).

**Example:<!-- -->&#x20;**`{"beautify":true,"format":"json"}`

Unauthorized access error. The request requires [authentication](https://freemius.com/help/api/#bearer-token-authentication) but was not provided or the provided authentication does not satisfy the required permissions.

application/json

**Schema**

**path**string[](#schema-property-users-list-response-schema-path-string "Direct link to path")

The API request path.

**Example:<!-- -->&#x20;**`:/products/product_id/users.json`

**error** <!-- -->object

This object contains the error details.

**type**string[](#schema-property-users-list-response-schema-type-string "Direct link to type")

The type of the error encountered by the server.

**Example:<!-- -->&#x20;**`UnauthorizedAccess`

**message**string[](#schema-property-users-list-response-schema-message-string "Direct link to message")

The descriptive error message.

**Example:<!-- -->&#x20;**`Some error has occured.`

**code**string[](#schema-property-users-list-response-schema-code-string "Direct link to code")

The error code.

**Example:<!-- -->&#x20;**`unauthorized_access`

**http**integer[](#schema-property-users-list-response-schema-http-integer "Direct link to http")

The HTTP status code returned by the server.

**Example:<!-- -->&#x20;**`401`

**timestamp**string[](#schema-property-users-list-response-schema-timestamp-string "Direct link to timestamp")

Current timestamp.

**Example:<!-- -->&#x20;**`Thu, 11 May 2023 11:45:30 +0000`

**request** <!-- -->object

This object sends back the request payload as received by the server (both from path and from body or query).

**property name\***&#x61;ny[](#schema-property-users-list-response-schema-property-name-any "Direct link to property name*")

This object sends back the request payload as received by the server (both from path and from body or query).

**Example:<!-- -->&#x20;**`{"beautify":true,"format":"json"}`

The request is missing the specified argument.

application/json

**Schema**

**path**string[](#schema-property-users-list-response-schema-path-string "Direct link to path")

The API request path.

**Example:<!-- -->&#x20;**`:/products/product_id/users.json`

**error** <!-- -->object

This object contains the error details.

**type**string[](#schema-property-users-list-response-schema-type-string "Direct link to type")

The type of the error encountered by the server.

**Example:<!-- -->&#x20;**`UnauthorizedAccess`

**message**string[](#schema-property-users-list-response-schema-message-string "Direct link to message")

The descriptive error message.

**Example:<!-- -->&#x20;**`Some error has occured.`

**code**string[](#schema-property-users-list-response-schema-code-string "Direct link to code")

The error code.

**Example:<!-- -->&#x20;**`unauthorized_access`

**http**integer[](#schema-property-users-list-response-schema-http-integer "Direct link to http")

The HTTP status code returned by the server.

**Example:<!-- -->&#x20;**`401`

**timestamp**string[](#schema-property-users-list-response-schema-timestamp-string "Direct link to timestamp")

Current timestamp.

**Example:<!-- -->&#x20;**`Thu, 11 May 2023 11:45:30 +0000`

**request** <!-- -->object

This object sends back the request payload as received by the server (both from path and from body or query).

**property name\***&#x61;ny[](#schema-property-users-list-response-schema-property-name-any "Direct link to property name*")

This object sends back the request payload as received by the server (both from path and from body or query).

**Example:<!-- -->&#x20;**`{"beautify":true,"format":"json"}`

The requested resource was not found.

application/json

**Schema**

**path**string[](#schema-property-users-list-response-schema-path-string "Direct link to path")

The API request path.

**Example:<!-- -->&#x20;**`:/products/product_id/users.json`

**error** <!-- -->object

This object contains the error details.

**type**string[](#schema-property-users-list-response-schema-type-string "Direct link to type")

The type of the error encountered by the server.

**Example:<!-- -->&#x20;**`UnauthorizedAccess`

**message**string[](#schema-property-users-list-response-schema-message-string "Direct link to message")

The descriptive error message.

**Example:<!-- -->&#x20;**`Some error has occured.`

**code**string[](#schema-property-users-list-response-schema-code-string "Direct link to code")

The error code.

**Example:<!-- -->&#x20;**`unauthorized_access`

**http**integer[](#schema-property-users-list-response-schema-http-integer "Direct link to http")

The HTTP status code returned by the server.

**Example:<!-- -->&#x20;**`401`

**timestamp**string[](#schema-property-users-list-response-schema-timestamp-string "Direct link to timestamp")

Current timestamp.

**Example:<!-- -->&#x20;**`Thu, 11 May 2023 11:45:30 +0000`

**request** <!-- -->object

This object sends back the request payload as received by the server (both from path and from body or query).

**property name\***&#x61;ny[](#schema-property-users-list-response-schema-property-name-any "Direct link to property name*")

This object sends back the request payload as received by the server (both from path and from body or query).

**Example:<!-- -->&#x20;**`{"beautify":true,"format":"json"}`
