Skip to main content
POST
Error

Autorizaciones

Authorization
string
header
requerido

Bearer authentication. Send Authorization: Bearer .

Cuerpo

application/json

User Input

UserInput payload

email
string
requerido

User's email address.

Ejemplo:

"john@example.com"

firstName
string
requerido

User's first name.

Ejemplo:

"John"

lastName
string
requerido

User's last name.

Ejemplo:

"Doe"

password
string
requerido

User's password for authentication.

Ejemplo:

"password"

username
string
requerido

User's username.

Ejemplo:

"johndoe"

countryCode
string

User's ISO 3166-1 alpha-2 country code. Required whenever a phone is supplied.

len=2,alpha is the closest shape this repo's validator (go-playground v9) can express — it has no iso3166_1_alpha2 rule, and no uppercase rule. The authoritative check is Casdoor's, which rejects a country code that does not resolve against the phone number.

Ejemplo:

"BR"

groups
string[]

Array of user role groups IDs. Role groups IDs can be retrieved through the List Groups endpoint.

Ejemplo:
phone
string

User's phone number in E.164 format (optional). Casdoor validates the number against CountryCode and rejects an unresolvable pair with an opaque upstream error, so the two must travel together — the pairing is enforced by validation.ValidatePhoneCountryPairing in the service, which also covers non-HTTP callers.

Ejemplo:

5511998888777

Respuesta

Created

countryCode
string
Ejemplo:

"BR"

email
string
Ejemplo:

"john@example.com"

firstName
string
Ejemplo:

"John"

groups
string[]
id
string
Ejemplo:

"123e4567-e89b-12d3-a456-426614174000"

lastName
string
Ejemplo:

"Doe"

mfa
object | null

The member's MFA status. NULLABLE, and the null is meaningful — this field is tri-state and a consumer MUST handle all three:

null is NOT "no MFA". It means the authoritative per-member read did not complete — Casdoor was unavailable, the row was skipped, or the listing's enrichment budget expired. Reporting those as enabled=false would tell an administrator that a possibly-protected member is unprotected, so they are reported honestly as unknown instead. Render null as "unknown", never as "off", and never dereference without a null check: user.mfa.enabled throws exactly when Casdoor is degraded, which is the worst moment to throw.

Single-user reads (GET /v1/users/{id}) always populate it — the read that would have failed is the request itself. Only the member LISTING can return null; see enrichUsersWithMFAStatus in internal/services/user_mfa_enrichment.go.

Carries no secrets — only enablement flags, methods and the preferred type.

Ejemplo:
phone
string
Ejemplo:

5511998888777

username
string
Ejemplo:

"johndoe"