Skip to content
POST /unified/user-directory/users/assign-role

Query Parameters

Refer Specifying query parameters in Truto APIs

idstring

The unique identifier for a user

1 supported1 required
Elastic Cloud
required
Show Truto-specific parameters
integrated_account_idstring · uuid
required·

The ID of the integrated account to use for the request.

Example: 62f44730-dd91-461e-bd6a-aedd9e0ad79d
truto_response_formatstring

The format of the response.

  • unified returns the response with unified mappings applied.
  • raw returns the unprocessed, raw response from the remote API.
  • normalized applies the unified mappings and returns the data in a normalized format.
  • stream returns the response as a stream, which is ideal for transmitting large datasets, files, or binary data. Using streaming mode helps to efficiently handle large payloads or real-time data flows without requiring the entire data to be buffered in memory.
  • debug returns the final unified result alongside raw remote fetch information. The response is an envelope containing result (identical to unified mode output) and debug (with requestUrl, requestOptions, data, responseHeaders, and for list operations: nextCursor, isLooping, isEmptyResult, resultCount). debug is null for static responses or when truto_skip_api_call=true.

Defaults to unified.

Example: unified
Possible values:
unifiedrawnormalizedstreamdebug
truto_ignore_remote_databoolean

Excludes the remote_data attribute from the response.

truto_enforce_write_schemaboolean

Validates the request body against this method's request_body_schema before the request is sent to the underlying integration. When a field marked required is missing, Truto responds 400 with the missing field names under truto_error_insight.missing_required_body_fields instead of forwarding the call. Only the fields documented in request_body_schema are checked. A body carrying a non-empty remote_data object is forwarded unchecked, because remote_data is merged into the provider request and may already carry the required values. A field the mapping always supplies through its default body is treated as present, and a field that is only conditionally required is reported under truto_error_insight.conditionally_required_body_fields rather than rejected. Some integrations declare fields required on update that the provider only requires on create; check meta/{method} for the resource before enabling this on update calls. If you sent an Idempotency-Key and the request was rejected, use a fresh key when you retry with a corrected body: the idempotency cache is keyed on the integrated account, path and key only — it ignores the query string and the body — so reusing the key replays the rejection. Defaults to false, which forwards the request as-is.

truto_exclude_fieldsstring[]

Array of fields to exclude from the response.

Example: truto_exclude_fields[]=id&truto_exclude_fields[]=name
remote_queryRecord<string, any>

Query parameters to pass to the underlying API without any transformations. Refer this guide to see how to structure the query parameters.

Example: remote_query[foo]=bar

Request Body

Refer Writing data using Unified APIs

idstring
required·

The unique identifier for a user

5 supported3 required
Google Cloud
required
JumpCloud
required
Slack Enterprise
required
Elastic Cloud
supported
Paralus
supported
organizationsobject[]

The organizations of the user

idstring

The unique identifier for an organization

namestring

The name of the organization

remote_dataRecord<string, any>

Any additional data that should be passed as part of the request body. This data is not transformed by Truto and is passed as is to the remote API.

rolesobject[]

The roles of the user

4 supported3 required
Google Cloud
required
JumpCloud
required
Slack Enterprise
required
Paralus
supported
idstring
required·

The unique identifier for a role

groupstring

The role of the user in the group. This is available when the user can have different roles in different groups or teams in an application.

namestring

The name of the role

organizationstring

The role of the user in the organization. This is available when the user can have different roles in different organizations in an application.

workspacestring

The role of the user in the workspace. This is available when the user can have different roles in different workspaces in an application.

user_typestring

The type of user

Possible values:
userservice-account
1 supported1 required
Google Cloud
required
userservice-account
workspace_idstring

The unique identifier for a group.

2 supported2 required
Google Cloud
required
Slack Enterprise
required

Response Body

idstring
required·

The unique identifier for a user

3 supported
Elastic Cloud
supported
JumpCloud
supported
Paralus
supported
activated_atstring · date-time

The date and time the user was activated

avatarstring

The avatar of the user

biostring

The bio of the user. Usually a short description set by the user about them.

created_atstring · date-time

The date and time the user was created

emailsobject[]

The emails of the user

emailstring

The email address

is_primaryboolean

Whether the email address is primary

typestring

The type of email address

external_idstring

The external identifier for a user. This is set when the SCIM API is being used.

first_namestring

The first name of the user

1 supported
Paralus
supported
groupsobject[]

The groups of the user

1 supported
Paralus
supported
idstring

The unique identifier for a group

namestring

The name of the group

organizationstring

The unique identifier of the organization to which the group belongs

identifiersRecord<string, any>

The identifiers of the user.

is_2fa_enabledboolean

Whether the user has 2FA enabled

is_email_verifiedboolean

Whether the user's email has been verified

languagesstring[]

The languages preferred by the user

last_active_atstring · date-time

The date and time the user was last active

last_login_atstring · date-time

The date and time the user was last logged in

1 supported
Paralus
supported
last_namestring

The last name of the user

1 supported
Paralus
supported
licensesobject[]

The licenses of the user or the products the user has access to

idstring

The unique identifier for a license

last_active_atstring · date-time

The date and time the user was last active for the license

namestring

The name of the license

organizationstring

The unique identifier of the organization to which the license belongs

managerobject

The user's manager

References: Users → id
idstring

The unique identifier for a user

namestring

The name of the user

1 supported
Paralus
supported
organizationsobject[]

The organizations of the user

idstring

The unique identifier for an organization

namestring

The name of the organization

phonesobject[]

The phones of the user

extensionstring

The extension of the phone number

numberstring

The phone number

typestring

The type of phone number

remote_dataRecord<string, any>

Raw data returned from the remote API call.

rolesobject[]

The roles of the user

1 supported
Paralus
supported
groupstring

The role of the user in the group. This is available when the user can have different roles in different groups or teams in an application.

idstring

The unique identifier for a role

namestring

The name of the role

organizationstring

The role of the user in the organization. This is available when the user can have different roles in different organizations in an application.

workspacestring

The role of the user in the workspace. This is available when the user can have different roles in different workspaces in an application.

statusstring

The status of the user. If no clear mapping is available, then the raw value is returned.

Possible values:
activeinactivedeletedinvited
1 supported
Paralus
supported
status_changed_atstring · date-time

The date and time the user's status was last changed

timezonestring

The timezone of the user

titlestring

The title of the user

updated_atstring · date-time

The date and time the user was last updated

urlsobject[]

The URLs of the user

typestring

The type of URL

urlstring

The URL

user_typestring

The type of user

usernamestring

The username of the user

1 supported
Paralus
supported
workspacesobject[]

The workspaces of the user

idstring

The unique identifier for a workspace

namestring

The name of the workspaces

truto unified user-directory users \
  -m assign-role \
  -a '<integrated_account_id>' \
  -o json
import Truto from '@truto/truto-ts-sdk';

const truto = new Truto({
  token: '<your_api_token>',
});

// Custom method: assign-role
const result = await truto.unifiedApi.assign-role(
  'user-directory',
  'users',
  { integrated_account_id: '<integrated_account_id>' }
);

console.log(result);
import asyncio
from truto_python_sdk import TrutoApi

truto_api = TrutoApi(token="<your_api_token>")

async def main():
    # Custom method: assign-role
    result = await truto_api.unified_api.assign-role(
        "user-directory",
        "users",
        {"integrated_account_id": "<integrated_account_id>"}
    )
    print(result)

asyncio.run(main())
curl -X POST 'https://api.truto.one/unified/user-directory/users/assign-role?integrated_account_id=<integrated_account_id>' \
  -H 'Authorization: Bearer <your_api_token>' \
  -H 'Content-Type: application/json' \
  -d '{
  "roles": [],
  "organizations": [],
  "workspace_id": "your_workspace_id",
  "id": "your_id",
  "user_type": "user",
  "remote_data": {}
}'
const integratedAccountId = '<integrated_account_id>';

const body = {
  "roles": [],
  "organizations": [],
  "workspace_id": "your_workspace_id",
  "id": "your_id",
  "user_type": "user",
  "remote_data": {}
};

const response = await fetch(`https://api.truto.one/unified/user-directory/users/assign-role?integrated_account_id=${integratedAccountId}`, {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer <your_api_token>',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify(body),
});

const data = await response.json();
console.log(data);
import requests

url = "https://api.truto.one/unified/user-directory/users/assign-role"
headers = {
    "Authorization": "Bearer <your_api_token>",
    "Content-Type": "application/json",
}
params = {
    "integrated_account_id": "<integrated_account_id>"
}
payload = {
    "roles": [],
    "organizations": [],
    "workspace_id": "your_workspace_id",
    "id": "your_id",
    "user_type": "user",
    "remote_data": {}
}

response = requests.post(url, headers=headers, params=params, json=payload)
print(response.json())