curl --request POST \
--url https://api.cloud.corbado.io/v1/observe/userSearch \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"userIDs": [
"<string>"
],
"userIDPattern": "<string>",
"externalIDs": [
"<string>"
],
"externalIDPattern": "<string>",
"flowIDs": [
"<string>"
],
"serialNumbers": [
"<string>"
],
"page": 1,
"pageSize": 25
}
'import requests
url = "https://api.cloud.corbado.io/v1/observe/userSearch"
payload = {
"userIDs": ["<string>"],
"userIDPattern": "<string>",
"externalIDs": ["<string>"],
"externalIDPattern": "<string>",
"flowIDs": ["<string>"],
"serialNumbers": ["<string>"],
"page": 1,
"pageSize": 25
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
userIDs: ['<string>'],
userIDPattern: '<string>',
externalIDs: ['<string>'],
externalIDPattern: '<string>',
flowIDs: ['<string>'],
serialNumbers: ['<string>'],
page: 1,
pageSize: 25
})
};
fetch('https://api.cloud.corbado.io/v1/observe/userSearch', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cloud.corbado.io/v1/observe/userSearch",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'userIDs' => [
'<string>'
],
'userIDPattern' => '<string>',
'externalIDs' => [
'<string>'
],
'externalIDPattern' => '<string>',
'flowIDs' => [
'<string>'
],
'serialNumbers' => [
'<string>'
],
'page' => 1,
'pageSize' => 25
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.cloud.corbado.io/v1/observe/userSearch"
payload := strings.NewReader("{\n \"userIDs\": [\n \"<string>\"\n ],\n \"userIDPattern\": \"<string>\",\n \"externalIDs\": [\n \"<string>\"\n ],\n \"externalIDPattern\": \"<string>\",\n \"flowIDs\": [\n \"<string>\"\n ],\n \"serialNumbers\": [\n \"<string>\"\n ],\n \"page\": 1,\n \"pageSize\": 25\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.cloud.corbado.io/v1/observe/userSearch")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"userIDs\": [\n \"<string>\"\n ],\n \"userIDPattern\": \"<string>\",\n \"externalIDs\": [\n \"<string>\"\n ],\n \"externalIDPattern\": \"<string>\",\n \"flowIDs\": [\n \"<string>\"\n ],\n \"serialNumbers\": [\n \"<string>\"\n ],\n \"page\": 1,\n \"pageSize\": 25\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cloud.corbado.io/v1/observe/userSearch")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"userIDs\": [\n \"<string>\"\n ],\n \"userIDPattern\": \"<string>\",\n \"externalIDs\": [\n \"<string>\"\n ],\n \"externalIDPattern\": \"<string>\",\n \"flowIDs\": [\n \"<string>\"\n ],\n \"serialNumbers\": [\n \"<string>\"\n ],\n \"page\": 1,\n \"pageSize\": 25\n}"
response = http.request(request)
puts response.read_body[
{
"id": "<string>",
"externalID": "<string>",
"status": "confirmed",
"createdMs": 123
}
]{
"error": {
"message": "Validation failed",
"details": [
{
"field": "projectID",
"message": "required"
}
]
}
}Search users by filter criteria
Finds Observe users by a single search criterion, such as user ID, external ID, a prefix match, or related flow IDs. Use this endpoint to locate users before opening their Observe context or investigating their flows.
Required API key permission: observe:user:read.
curl --request POST \
--url https://api.cloud.corbado.io/v1/observe/userSearch \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"userIDs": [
"<string>"
],
"userIDPattern": "<string>",
"externalIDs": [
"<string>"
],
"externalIDPattern": "<string>",
"flowIDs": [
"<string>"
],
"serialNumbers": [
"<string>"
],
"page": 1,
"pageSize": 25
}
'import requests
url = "https://api.cloud.corbado.io/v1/observe/userSearch"
payload = {
"userIDs": ["<string>"],
"userIDPattern": "<string>",
"externalIDs": ["<string>"],
"externalIDPattern": "<string>",
"flowIDs": ["<string>"],
"serialNumbers": ["<string>"],
"page": 1,
"pageSize": 25
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
userIDs: ['<string>'],
userIDPattern: '<string>',
externalIDs: ['<string>'],
externalIDPattern: '<string>',
flowIDs: ['<string>'],
serialNumbers: ['<string>'],
page: 1,
pageSize: 25
})
};
fetch('https://api.cloud.corbado.io/v1/observe/userSearch', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.cloud.corbado.io/v1/observe/userSearch",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'userIDs' => [
'<string>'
],
'userIDPattern' => '<string>',
'externalIDs' => [
'<string>'
],
'externalIDPattern' => '<string>',
'flowIDs' => [
'<string>'
],
'serialNumbers' => [
'<string>'
],
'page' => 1,
'pageSize' => 25
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.cloud.corbado.io/v1/observe/userSearch"
payload := strings.NewReader("{\n \"userIDs\": [\n \"<string>\"\n ],\n \"userIDPattern\": \"<string>\",\n \"externalIDs\": [\n \"<string>\"\n ],\n \"externalIDPattern\": \"<string>\",\n \"flowIDs\": [\n \"<string>\"\n ],\n \"serialNumbers\": [\n \"<string>\"\n ],\n \"page\": 1,\n \"pageSize\": 25\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.cloud.corbado.io/v1/observe/userSearch")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"userIDs\": [\n \"<string>\"\n ],\n \"userIDPattern\": \"<string>\",\n \"externalIDs\": [\n \"<string>\"\n ],\n \"externalIDPattern\": \"<string>\",\n \"flowIDs\": [\n \"<string>\"\n ],\n \"serialNumbers\": [\n \"<string>\"\n ],\n \"page\": 1,\n \"pageSize\": 25\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.cloud.corbado.io/v1/observe/userSearch")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"userIDs\": [\n \"<string>\"\n ],\n \"userIDPattern\": \"<string>\",\n \"externalIDs\": [\n \"<string>\"\n ],\n \"externalIDPattern\": \"<string>\",\n \"flowIDs\": [\n \"<string>\"\n ],\n \"serialNumbers\": [\n \"<string>\"\n ],\n \"page\": 1,\n \"pageSize\": 25\n}"
response = http.request(request)
puts response.read_body[
{
"id": "<string>",
"externalID": "<string>",
"status": "confirmed",
"createdMs": 123
}
]{
"error": {
"message": "Validation failed",
"details": [
{
"field": "projectID",
"message": "required"
}
]
}
}Authorizations
Use an Observe API key from the management console. The key selects the project and must grant the permission listed on the operation. Keep this key on your server.
Body
List of exact user IDs to search for (format tus-<number>). Mutually exclusive with other search
fields.
User ID pattern for prefix search (format tus-<number>%, e.g., "tus-123%" matches all user IDs
starting with tus-123...). Mutually exclusive with other search fields.
List of exact external IDs to search for. Mutually exclusive with other search fields.
External ID pattern for prefix search, ending with '%' (e.g., "abc%" matches all external IDs starting with abc). Mutually exclusive with other search fields.
List of flow IDs to search for (e.g., "flw-123"). Returns the users owning those flows. Mutually exclusive with other search fields.
List of exact YubiKey serial numbers. Returns the users owning a passkey with a matching serial number (pre-registered keys). Mutually exclusive with other search fields.
Page number for pagination (1-based). Defaults to 1.
x >= 1Number of items per page. Defaults to 25, maximum 1000.
1 <= x <= 1000Response
Users matching the search criterion, ordered by creation time (newest first).
Was this page helpful?