WorkOS PHP SDK

UserManagement
in package

Table of Contents

Properties

$client  : HttpClient

Methods

__construct()  : mixed
acceptInvitation()  : Invitation
Accept an invitation
authenticateWithCode()  : AuthenticateResponse
authenticateWithDeviceCode()  : AuthenticateResponse
authenticateWithEmailVerification()  : AuthenticateResponse
authenticateWithMagicAuth()  : AuthenticateResponse
authenticateWithOrganizationSelection()  : AuthenticateResponse
authenticateWithPassword()  : AuthenticateResponse
authenticateWithRadarEmailChallenge()  : AuthenticateResponse
authenticateWithRadarSmsChallenge()  : AuthenticateResponse
authenticateWithRefreshToken()  : AuthenticateResponse
authenticateWithTotp()  : AuthenticateResponse
confirmEmailChange()  : EmailChangeConfirmation
Confirm email change
confirmPasswordReset()  : ResetPasswordResponse
Reset the password
createAuthkitOAuthResource()  : AuthkitOAuthResource
Create an MCP resource indicator
createCorsOrigin()  : CORSOriginResponse
Create a CORS origin
createDevice()  : DeviceAuthorizationResponse
Get device authorization URL
createMagicAuth()  : MagicAuthSendMagicAuthCodeAndReturnResponse
Create a Magic Auth code
createRadarChallenge()  : SendRadarSmsChallengeResponse
Send a Radar SMS challenge
createRedirectUri()  : RedirectUri
Create a redirect URI
createUser()  : UserCreateResponse
Create a user
createUserApiKey()  : UserApiKeyWithValue
Create an API key for a user
createWaitlistEntry()  : WaitlistEntry
Create a waitlist entry
createWaitlistEntryApprove()  : WaitlistEntry
Approve a waitlist entry
createWaitlistEntryDeny()  : WaitlistEntry
Deny a waitlist entry
deleteAuthkitOAuthResource()  : void
Delete an MCP resource indicator
deleteRedirectUris()  : void
Delete a redirect URI
deleteUser()  : void
Delete a user
deleteUserAuthorizedApplication()  : void
Delete an authorized application
deleteWaitlistEntry()  : void
Delete a waitlist entry
findInvitationByToken()  : UserInvite
Find an invitation by token
getAuthorizationUrl()  : string
Get an authorization URL
getEmailVerification()  : EmailVerification
Get an email verification code
getInvitation()  : UserInvite
Get an invitation
getJwks()  : JwksResponse
Get JWKS
getLogoutUrl()  : string
Logout
getMagicAuth()  : MagicAuth
Get Magic Auth code details
getPasswordReset()  : PasswordReset
Get a password reset token
getRadarChallenge()  : RadarChallenge
Get Radar Challenge details
getUser()  : User
Get a user
getUserByExternalId()  : User
Get a user by external ID
getUserIdentities()  : array<string|int, mixed>
Get user identities
getWaitlist()  : Waitlist
Get a waitlist
listAuthkitOAuthResources()  : PaginatedResponse<string|int, AuthkitOAuthResource>
List MCP resource indicators
listCorsOrigins()  : PaginatedResponse<string|int, CORSOriginResponse>
List CORS origins
listInvitations()  : PaginatedResponse<string|int, UserInvite>
List invitations
listJWTTemplate()  : JWTTemplateResponse
Get JWT template
listRedirectUris()  : PaginatedResponse<string|int, RedirectUri>
List redirect URIs
listSessions()  : PaginatedResponse<string|int, UserSessionsListItem>
List sessions
listUserApiKeys()  : PaginatedResponse<string|int, UserApiKey>
List API keys for a user
listUserAuthorizedApplications()  : PaginatedResponse<string|int, AuthorizedConnectApplicationListData>
List authorized applications
listUsers()  : PaginatedResponse<string|int, User>
List users
listWaitlistEntries()  : PaginatedResponse<string|int, WaitlistEntry>
List waitlist entries
listWaitlists()  : PaginatedResponse<string|int, Waitlist>
List waitlists
resendInvitation()  : UserInvite
Resend an invitation
resetPassword()  : PasswordReset
Create a password reset token
revokeInvitation()  : Invitation
Revoke an invitation
revokeSession()  : mixed
Revoke Session
sendEmailChange()  : EmailChange
Send email change code
sendInvitation()  : UserInvite
Send an invitation
sendVerificationEmail()  : SendVerificationEmailResponse
Send verification email
updateJWTTemplate()  : JWTTemplateResponse
Update JWT template
updateUser()  : User
Update a user
verifyEmail()  : VerifyEmailResponse
Verify email

Properties

Methods

acceptInvitation()

Accept an invitation

public acceptInvitation(string $id[, RequestOptions|null $options = null ]) : Invitation

Accepts an invitation and, if linked to an organization, activates the user's membership in that organization.

Parameters
$id : string

The unique ID of the invitation.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
Invitation

authenticateWithCode()

public authenticateWithCode(string $code[, string|null $codeVerifier = null ][, string|null $invitationToken = null ][, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, string|null $signalsId = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$code : string
$codeVerifier : string|null = null
$invitationToken : string|null = null
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$signalsId : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithDeviceCode()

public authenticateWithDeviceCode(string $deviceCode[, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$deviceCode : string
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithEmailVerification()

public authenticateWithEmailVerification(string $code, string $pendingAuthenticationToken[, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$code : string
$pendingAuthenticationToken : string
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithMagicAuth()

public authenticateWithMagicAuth(string $code, string $email[, string|null $invitationToken = null ][, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, string|null $radarAuthAttemptId = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$code : string
$email : string
$invitationToken : string|null = null
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$radarAuthAttemptId : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithOrganizationSelection()

public authenticateWithOrganizationSelection(string $pendingAuthenticationToken, string $organizationId[, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$pendingAuthenticationToken : string
$organizationId : string
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithPassword()

public authenticateWithPassword(string $email, string $password[, string|null $invitationToken = null ][, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, string|null $signalsId = null ][, string|null $radarAuthAttemptId = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$email : string
$password : string
$invitationToken : string|null = null
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$signalsId : string|null = null
$radarAuthAttemptId : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithRadarEmailChallenge()

public authenticateWithRadarEmailChallenge(string $code, string $radarChallengeId, string $pendingAuthenticationToken[, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$code : string
$radarChallengeId : string
$pendingAuthenticationToken : string
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithRadarSmsChallenge()

public authenticateWithRadarSmsChallenge(string $code, string $pendingAuthenticationToken[, string|null $verificationId = null ][, string|null $phoneNumber = null ][, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$code : string
$pendingAuthenticationToken : string
$verificationId : string|null = null
$phoneNumber : string|null = null
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithRefreshToken()

public authenticateWithRefreshToken(string $refreshToken[, string|null $organizationId = null ][, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$refreshToken : string
$organizationId : string|null = null
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

authenticateWithTotp()

public authenticateWithTotp(string $code, string $pendingAuthenticationToken, string $authenticationChallengeId[, string|null $ipAddress = null ][, string|null $deviceId = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : AuthenticateResponse
Parameters
$code : string
$pendingAuthenticationToken : string
$authenticationChallengeId : string
$ipAddress : string|null = null
$deviceId : string|null = null
$userAgent : string|null = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthenticateResponse

confirmPasswordReset()

Reset the password

public confirmPasswordReset(string $token, string $newPassword[, RequestOptions|null $options = null ]) : ResetPasswordResponse

Sets a new password using the token query parameter from the link that the user received. Successfully resetting the password will verify a user's email, if it hasn't been verified yet.

Parameters
$token : string

The password reset token.

$newPassword : string

The new password to set for the user.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
ResetPasswordResponse

createAuthkitOAuthResource()

Create an MCP resource indicator

public createAuthkitOAuthResource(string $uri[, bool|null $default = null ][, RequestOptions|null $options = null ]) : AuthkitOAuthResource

Adds an MCP resource indicator (RFC 8707) to an environment, leaving any others in place.

Parameters
$uri : string

The resource URI. May be a wildcard pattern with a single *, either in the leftmost hostname label or as the final path segment, where enabled for the environment.

$default : bool|null = null

Whether the resource being created becomes the environment default, clearing any previous default. Applies at creation only — this API has no update endpoint yet, so changing the default on an existing resource is done from the dashboard. A wildcard pattern cannot be the default.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
AuthkitOAuthResource

createDevice()

Get device authorization URL

public createDevice(string $clientId[, RequestOptions|null $options = null ]) : DeviceAuthorizationResponse

Initiates the CLI Auth flow by requesting a device code and verification URLs. This endpoint implements the OAuth 2.0 Device Authorization Flow (RFC 8628) and is designed for command-line applications or other devices with limited input capabilities.

Parameters
$clientId : string

The WorkOS client ID for your application.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
DeviceAuthorizationResponse

createMagicAuth()

Create a Magic Auth code

public createMagicAuth(string $email[, string|null $invitationToken = null ][, string|null $ipAddress = null ][, string|null $userAgent = null ][, string|null $radarAuthAttemptId = null ][, string|null $signalsId = null ][, RequestOptions|null $options = null ]) : MagicAuthSendMagicAuthCodeAndReturnResponse

Creates a one-time authentication code that can be sent to the user's email address. The code expires in 10 minutes. To verify the code, authenticate the user with Magic Auth.

Parameters
$email : string

The email address to send the magic code to.

$invitationToken : string|null = null

The invitation token to associate with this magic code.

$ipAddress : string|null = null

The IP address of the user's request.

$userAgent : string|null = null

The user agent string from the user's request.

$radarAuthAttemptId : string|null = null

The ID of an existing Radar authentication attempt to associate with this request.

$signalsId : string|null = null

An optional Radar signals ID to correlate client-side signals with this request.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
MagicAuthSendMagicAuthCodeAndReturnResponse

createRadarChallenge()

Send a Radar SMS challenge

public createRadarChallenge(string $userId, string $pendingAuthenticationToken, string $phoneNumber[, string|null $ipAddress = null ][, string|null $userAgent = null ][, RequestOptions|null $options = null ]) : SendRadarSmsChallengeResponse

Sends a one-time verification code over SMS to a user as part of a Radar challenge. Use the returned verification_id to authenticate the user with the urn:workos:oauth:grant-type:radar-sms-challenge:code grant type.

Parameters
$userId : string

The ID of the user to send the SMS challenge to.

$pendingAuthenticationToken : string

The pending authentication token from a previous authentication attempt that triggered the Radar challenge.

$phoneNumber : string

The phone number to send the SMS verification code to.

$ipAddress : string|null = null

The IP address of the user's request.

$userAgent : string|null = null

The user agent string from the user's request.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
SendRadarSmsChallengeResponse

createUser()

Create a user

public createUser(string $email[, string|null $firstName = null ][, string|null $lastName = null ][, string|null $name = null ][, bool|null $emailVerified = null ][, array<string, string>|null $metadata = null ][, string|null $externalId = null ][, string|null $ipAddress = null ][, string|null $userAgent = null ][, string|null $signalsId = null ][, null|PasswordPlaintext|PasswordHashed $password = null ][, RequestOptions|null $options = null ]) : UserCreateResponse

Create a new user in the current environment.

Parameters
$email : string

The email address of the user.

$firstName : string|null = null

The first name of the user.

$lastName : string|null = null

The last name of the user.

$name : string|null = null

The user's full name.

$emailVerified : bool|null = null

Whether the user's email has been verified.

$metadata : array<string, string>|null = null

Object containing metadata key/value pairs associated with the user.

$externalId : string|null = null

The external ID of the user.

$ipAddress : string|null = null

The IP address of the user's request.

$userAgent : string|null = null

The user agent string from the user's request.

$signalsId : string|null = null

An optional Radar signals ID to correlate client-side signals with this request.

$password : null|PasswordPlaintext|PasswordHashed = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
UserCreateResponse

createUserApiKey()

Create an API key for a user

public createUserApiKey(string $userId, string $name, string $organizationId[, array<string|int, string>|null $permissions = null ][, DateTimeImmutable|null $expiresAt = null ][, RequestOptions|null $options = null ]) : UserApiKeyWithValue

Create a new API key owned by a user. The user must have an active membership in the specified organization.

Parameters
$userId : string

Unique identifier of the user.

$name : string

A descriptive name for the API key.

$organizationId : string

The ID of the organization the user API key is associated with. The user must have an active membership in this organization.

$permissions : array<string|int, string>|null = null

The permission slugs to assign to the API key. Each permission must be enabled for user API keys.

$expiresAt : DateTimeImmutable|null = null

The timestamp when the API key should expire. Must be a future timestamp. If omitted, the key does not expire.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
UserApiKeyWithValue

createWaitlistEntry()

Create a waitlist entry

public createWaitlistEntry(string $id, string $email[, array<string, string>|null $additionalFields = null ][, bool|null $sendConfirmationEmail = null ][, RequestOptions|null $options = null ]) : WaitlistEntry

Add an email address to the waitlist. Email addresses are normalized and unique per environment: a request for an email address already on the waitlist returns the existing entry unchanged (still with status 201) and does not send another confirmation email. If a user with the email address already exists in the environment, the request fails with the code user_already_exists.

Parameters
$id : string

The unique ID of the waitlist, or the literal default for the environment's default waitlist. Use default when adding the first entry — the default waitlist is created automatically.

$email : string

The email address of the user joining the waitlist.

$additionalFields : array<string, string>|null = null

Object containing additional key/value pairs collected with the waitlist entry. Supports up to 50 string pairs, with keys up to 40 characters and values up to 600 characters. Values are user-provided — treat them as untrusted input when rendering or exporting.

$sendConfirmationEmail : bool|null = null

Whether to send the waitlist confirmation email to the user. Defaults to false. No email is sent when the waitlist confirmation email is disabled in the environment, even if send_confirmation_email is true.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
WaitlistEntry

createWaitlistEntryApprove()

Approve a waitlist entry

public createWaitlistEntryApprove(string $id[, RequestOptions|null $options = null ]) : WaitlistEntry

Approve a waitlist entry, create an invitation for its email address, and send the invitation email. Approving a denied entry reverses the denial. The approval is saved even when the invitation steps fail, so instead of retrying the approval, recover based on the outcome:

  • 200 — the entry is approved. If invitation creation failed, no invitation exists yet; send one.
  • 422 with code invitation_email_not_sent — the entry is approved and an invitation exists, but its email was not sent; resend it.
  • 422 with code invalid_state — the entry was already approved.
Parameters
$id : string

The unique ID of the waitlist entry.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
WaitlistEntry

createWaitlistEntryDeny()

Deny a waitlist entry

public createWaitlistEntryDeny(string $id[, RequestOptions|null $options = null ]) : WaitlistEntry

Deny a pending waitlist entry. Denying an entry that is not pending fails with the code invalid_state. A denial can be reversed by approving the entry.

Parameters
$id : string

The unique ID of the waitlist entry.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
WaitlistEntry

deleteAuthkitOAuthResource()

Delete an MCP resource indicator

public deleteAuthkitOAuthResource(string $id[, RequestOptions|null $options = null ]) : void

Removes an MCP resource indicator from an environment. Any application consents granted against it are removed too.

Parameters
$id : string

The ID of the MCP resource indicator to delete.

$options : RequestOptions|null = null
Tags
throws
WorkOSException

deleteRedirectUris()

Delete a redirect URI

public deleteRedirectUris(string $id[, RequestOptions|null $options = null ]) : void

Deletes a redirect URI from an application.

Parameters
$id : string

The ID of the redirect URI to delete.

$options : RequestOptions|null = null
Tags
throws
WorkOSException

deleteUser()

Delete a user

public deleteUser(string $id[, RequestOptions|null $options = null ]) : void

Permanently deletes a user in the current environment. It cannot be undone.

Parameters
$id : string

The unique ID of the user.

$options : RequestOptions|null = null
Tags
throws
WorkOSException

deleteUserAuthorizedApplication()

Delete an authorized application

public deleteUserAuthorizedApplication(string $applicationId, string $userId[, RequestOptions|null $options = null ]) : void

Delete an existing Authorized Connect Application.

Parameters
$applicationId : string

The ID or client ID of the application.

$userId : string

The ID of the user.

$options : RequestOptions|null = null
Tags
throws
WorkOSException

deleteWaitlistEntry()

Delete a waitlist entry

public deleteWaitlistEntry(string $id[, RequestOptions|null $options = null ]) : void

Remove the entry from the waitlist. Its email address can join again unless a user with that email now exists in the environment. Deleting the entry does not revoke an invitation created by approving it — revoke that invitation separately to withdraw access.

Parameters
$id : string

The unique ID of the waitlist entry.

$options : RequestOptions|null = null
Tags
throws
WorkOSException

getAuthorizationUrl()

Get an authorization URL

public getAuthorizationUrl(string $redirectUri[, string|null $codeChallengeMethod = null ][, string|null $codeChallenge = null ][, string|null $domainHint = null ][, string|null $connectionId = null ][, array<string, string>|null $providerQueryParams = null ][, array<string|int, string>|null $providerScopes = null ][, string|null $invitationToken = null ][, int|null $maxAge = null ][, RadarStandaloneAssessRequestAction|null $screenHint = null ][, string|null $loginHint = null ][, UserManagementAuthenticationProvider|null $provider = null ][, string|null $prompt = null ][, string|null $state = null ][, string|null $organizationId = null ][, RequestOptions|null $options = null ]) : string

Generates an OAuth 2.0 authorization URL to authenticate a user with AuthKit or SSO.

Parameters
$redirectUri : string

The callback URI where the authorization code will be sent after authentication.

$codeChallengeMethod : string|null = null

The only valid PKCE code challenge method is "S256". Required when specifying a code_challenge.

$codeChallenge : string|null = null

Code challenge derived from the code verifier used for the PKCE flow.

$domainHint : string|null = null

A domain hint for SSO connection lookup.

$connectionId : string|null = null

The ID of an SSO connection to use for authentication.

$providerQueryParams : array<string, string>|null = null

Key/value pairs of query parameters to pass to the OAuth provider.

$providerScopes : array<string|int, string>|null = null

Additional OAuth scopes to request from the identity provider.

$invitationToken : string|null = null

A token representing a user invitation to redeem during authentication.

$maxAge : int|null = null

Maximum allowable elapsed time, in seconds, since the user last actively authenticated. If the last authentication is older than this value, the user is prompted to re-authenticate; a value of 0 forces re-authentication. Only supported when the provider is authkit.

$screenHint : RadarStandaloneAssessRequestAction|null = null

Used to specify which screen to display when the provider is authkit. Defaults to "sign-in".

$loginHint : string|null = null

A hint to the authorization server about the login identifier the user might use.

$provider : UserManagementAuthenticationProvider|null = null

The OAuth provider to authenticate with (e.g., GoogleOAuth, MicrosoftOAuth, GitHubOAuth).

$prompt : string|null = null

Controls the authentication flow behavior for the user.

$state : string|null = null

An opaque value used to maintain state between the request and the callback.

$organizationId : string|null = null

The ID of the organization to authenticate the user against.

$options : RequestOptions|null = null
Tags
throws
ConfigurationException
Return values
string

getJwks()

Get JWKS

public getJwks(string $clientId[, RequestOptions|null $options = null ]) : JwksResponse

Returns the JSON Web Key Set (JWKS) containing the public keys used for verifying access tokens.

Parameters
$clientId : string

Identifies the application making the request to the WorkOS server. You can obtain your client ID from the API Keys page in the dashboard.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
JwksResponse

getLogoutUrl()

Logout

public getLogoutUrl(string $sessionId[, string|null $returnTo = null ][, RequestOptions|null $options = null ]) : string

Logout a user from the current session.

Parameters
$sessionId : string

The ID of the session. This can be extracted from the sid claim of the access token.

$returnTo : string|null = null

The URL to redirect the user to after logout.

$options : RequestOptions|null = null
Return values
string

getUserIdentities()

Get user identities

public getUserIdentities(string $id[, RequestOptions|null $options = null ]) : array<string|int, mixed>

Get a list of identities associated with the user. A user can have multiple associated identities after going through identity linking. Currently only OAuth identities are supported. More provider types may be added in the future.

Parameters
$id : string

The unique ID of the user.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
array<string|int, mixed>

getWaitlist()

Get a waitlist

public getWaitlist(string $id[, RequestOptions|null $options = null ]) : Waitlist

Get the details of an existing waitlist.

Parameters
$id : string

The unique ID of the waitlist, or the literal default for the environment's default waitlist. The default waitlist is created when its first entry is added, so read requests for default return a 404 until then.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
Waitlist

listAuthkitOAuthResources()

List MCP resource indicators

public listAuthkitOAuthResources([string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, AuthkitOAuthResource>

Lists the MCP resource indicators configured for an environment.

Parameters
$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, AuthkitOAuthResource>

listCorsOrigins()

List CORS origins

public listCorsOrigins([string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, CORSOriginResponse>

Lists the CORS origins for the current environment.

Parameters
$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, CORSOriginResponse>

listInvitations()

List invitations

public listInvitations([string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, string|null $organizationId = null ][, string|null $email = null ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, UserInvite>

Get a list of all of invitations matching the criteria specified.

Parameters
$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$organizationId : string|null = null

The ID of the organization that the recipient will join.

$email : string|null = null

The email address of the recipient.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, UserInvite>

listRedirectUris()

List redirect URIs

public listRedirectUris([string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, RedirectUri>

Lists the redirect URIs for an environment.

Parameters
$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, RedirectUri>

listSessions()

List sessions

public listSessions(string $id[, string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, UserSessionsListItem>

Get a list of all active sessions for a specific user.

Parameters
$id : string

The ID of the user.

$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, UserSessionsListItem>

listUserApiKeys()

List API keys for a user

public listUserApiKeys(string $userId[, string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, string|null $organizationId = null ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, UserApiKey>

Get a list of API keys owned by a specific user.

Parameters
$userId : string

Unique identifier of the user.

$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list.

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list.

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Defaults to "desc".

$organizationId : string|null = null

The ID of the organization to filter user API keys by. When provided, only API keys created against that organization membership are returned.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, UserApiKey>

listUserAuthorizedApplications()

List authorized applications

public listUserAuthorizedApplications(string $userId[, string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, AuthorizedConnectApplicationListData>

Get a list of all Connect applications that the user has authorized.

Parameters
$userId : string

The ID of the user.

$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, AuthorizedConnectApplicationListData>

listUsers()

List users

public listUsers([string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, string|null $organization = null ][, string|null $organizationId = null ][, string|null $email = null ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, User>

Get a list of all of your existing users matching the criteria specified.

Parameters
$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$organization : string|null = null

(deprecated) Filter users by the organization they are a member of. Deprecated in favor of organization_id.

$organizationId : string|null = null

Filter users by the organization they are a member of.

$email : string|null = null

Filter users by their email address.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, User>

listWaitlistEntries()

List waitlist entries

public listWaitlistEntries(string $id[, string|null $before = null ][, string|null $after = null ][, int|null $limit = null ][, PaginationOrder $order = PaginationOrder::Desc ][, WaitlistUserState|null $state = null ][, string|null $email = null ][, RequestOptions|null $options = null ]) : PaginatedResponse<string|int, WaitlistEntry>

Get a list of entries on a waitlist matching the criteria specified.

Parameters
$id : string

The unique ID of the waitlist, or the literal default for the environment's default waitlist. The default waitlist is created when its first entry is added, so read requests for default return a 404 until then.

$before : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include before="obj_123" to fetch a new batch of objects before "obj_123".

$after : string|null = null

An object ID that defines your place in the list. When the ID is not present, you are at the end of the list. For example, if you make a list request and receive 100 objects, ending with "obj_123", your subsequent call can include after="obj_123" to fetch a new batch of objects after "obj_123".

$limit : int|null = null

Upper limit on the number of objects to return, between 1 and 100. Defaults to 10.

$order : PaginationOrder = PaginationOrder::Desc

Order the results by the creation time. Supported values are "asc" (ascending), "desc" (descending), and "normal" (descending with reversed cursor semantics where before fetches older records and after fetches newer records). Defaults to "desc".

$state : WaitlistUserState|null = null

Filter waitlist entries by their state.

$email : string|null = null

Filter waitlist entries by their exact email address.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
PaginatedResponse<string|int, WaitlistEntry>

resendInvitation()

Resend an invitation

public resendInvitation(string $id[, CreateUserInviteOptionsLocale|null $locale = null ][, RequestOptions|null $options = null ]) : UserInvite

Resends an invitation email to the recipient. The invitation must be in a pending state.

Parameters
$id : string

The unique ID of the invitation.

$locale : CreateUserInviteOptionsLocale|null = null

The locale to use when rendering the invitation email. See supported locales.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
UserInvite

sendEmailChange()

Send email change code

public sendEmailChange(string $id, string $newEmail[, RequestOptions|null $options = null ]) : EmailChange

Sends an email that contains a one-time code used to change a user's email address.

Parameters
$id : string

The unique ID of the user.

$newEmail : string

The new email address to change to.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
EmailChange

sendInvitation()

Send an invitation

public sendInvitation(string $email[, string|null $organizationId = null ][, string|null $roleSlug = null ][, int|null $expiresInDays = null ][, string|null $inviterUserId = null ][, CreateUserInviteOptionsLocale|null $locale = null ][, RequestOptions|null $options = null ]) : UserInvite

Sends an invitation email to the recipient.

Parameters
$email : string

The email address of the recipient.

$organizationId : string|null = null

The ID of the organization that the recipient will join.

$roleSlug : string|null = null

The role that the recipient will receive when they join the organization in the invitation.

$expiresInDays : int|null = null

How many days the invitations will be valid for. Must be between 1 and 30 days. Defaults to 7 days if not specified.

$inviterUserId : string|null = null

The ID of the user who invites the recipient. The invitation email will mention the name of this user.

$locale : CreateUserInviteOptionsLocale|null = null

The locale to use when rendering the invitation email. See supported locales.

$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
UserInvite

updateUser()

Update a user

public updateUser(string $id[, string|null $email = null ][, string|null $firstName = null ][, string|null $lastName = null ][, string|null $name = null ][, bool|null $emailVerified = null ][, array<string, string>|null $metadata = null ][, string|null $externalId = null ][, string|null $locale = null ][, null|PasswordPlaintext|PasswordHashed $password = null ][, RequestOptions|null $options = null ]) : User

Updates properties of a user. The omitted properties will be left unchanged.

Parameters
$id : string

The unique ID of the user.

$email : string|null = null

The email address of the user.

$firstName : string|null = null

The first name of the user.

$lastName : string|null = null

The last name of the user.

$name : string|null = null

The user's full name.

$emailVerified : bool|null = null

Whether the user's email has been verified.

$metadata : array<string, string>|null = null

Object containing metadata key/value pairs associated with the user.

$externalId : string|null = null

The external ID of the user.

$locale : string|null = null

The user's preferred locale.

$password : null|PasswordPlaintext|PasswordHashed = null
$options : RequestOptions|null = null
Tags
throws
WorkOSException
Return values
User
On this page

Search results