Create an User
Create an user access along with its permission group.
Autorizaciones
Bearer authentication. Send Authorization: Bearer .
Cuerpo
User Input
UserInput payload
User's email address.
"john@example.com"
User's first name.
"John"
User's last name.
"Doe"
User's password for authentication.
"password"
User's username.
"johndoe"
User's ISO 3166-1 alpha-2 country code. Required whenever a phone is supplied.
len=2,alpha is the closest shape this repo's validator (go-playground v9) can express — it has no iso3166_1_alpha2 rule, and no uppercase rule. The authoritative check is Casdoor's, which rejects a country code that does not resolve against the phone number.
"BR"
Array of user role groups IDs. Role groups IDs can be retrieved through the List Groups endpoint.
User's phone number in E.164 format (optional). Casdoor validates the number against CountryCode and rejects an unresolvable pair with an opaque upstream error, so the two must travel together — the pairing is enforced by validation.ValidatePhoneCountryPairing in the service, which also covers non-HTTP callers.
5511998888777
Respuesta
Created
"BR"
"john@example.com"
"John"
"123e4567-e89b-12d3-a456-426614174000"
"Doe"
The member's MFA status. NULLABLE, and the null is meaningful — this field is tri-state and a consumer MUST handle all three:
null is NOT "no MFA". It means the authoritative per-member read did not
complete — Casdoor was unavailable, the row was skipped, or the listing's
enrichment budget expired. Reporting those as enabled=false would tell an
administrator that a possibly-protected member is unprotected, so they are
reported honestly as unknown instead. Render null as "unknown", never as
"off", and never dereference without a null check: user.mfa.enabled throws
exactly when Casdoor is degraded, which is the worst moment to throw.
Single-user reads (GET /v1/users/{id}) always populate it — the read that would have failed is the request itself. Only the member LISTING can return null; see enrichUsersWithMFAStatus in internal/services/user_mfa_enrichment.go.
Carries no secrets — only enablement flags, methods and the preferred type.
5511998888777
"johndoe"

