A valid request URL is required to generate request examples{
"id": "<string>",
"name": "<string>",
"email": "[email protected]",
"role_id": 123,
"role": {
"id": 123,
"name": "<string>",
"description": "<string>",
"is_system_role": true
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"teams": [
{
"id": "<string>",
"name": "<string>"
}
],
"business_units": [
{
"id": "<string>",
"name": "<string>"
}
],
"access_profiles": [
{
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"access_profile": {
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}Get user (deprecated path)
Returns a single Enterprise user.
A valid request URL is required to generate request examples{
"id": "<string>",
"name": "<string>",
"email": "[email protected]",
"role_id": 123,
"role": {
"id": 123,
"name": "<string>",
"description": "<string>",
"is_system_role": true
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"teams": [
{
"id": "<string>",
"name": "<string>"
}
],
"business_units": [
{
"id": "<string>",
"name": "<string>"
}
],
"access_profiles": [
{
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"access_profile": {
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>",
"error_type": "<string>"
}
}/api/governance/users/{user_id} instead.| Permission | Granted via |
|---|---|
Users:View | RBAC role or API key scope |
Authorizations
Management API authentication for /api/* endpoints. Use the Authorization header
with Bearer <token>, where <token> is one of:
- a Bifrost management API key,
- a dashboard session token issued by
POST /api/session/login, - base64 of
<admin-username>:<admin-password>(legacy equivalent ofBasicAuth).
Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs -
the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.
Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a
Required Permissions table (Resource:Operation, for example Dashboard:View) above
its Authorizations section, and the caller's RBAC role or management API key scopes must
include what it lists, otherwise the request is rejected with 403 Forbidden.
A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.
Path Parameters
User ID
Response
Successful response
Unique user identifier
User's display name
User's email address
ID of the assigned RBAC role
RBAC role details
Show child attributes
Show child attributes
Teams the user belongs to.
Show child attributes
Show child attributes
Business units the user belongs to. Membership is many-to-many and belongs to the user, so this is the authoritative list; manage it under /api/governance/business-units/{business_unit_id}/users.
Show child attributes
Show child attributes
Every access profile the user holds, one per assignment source. All of them are enforced — their budgets, rate limits, and provider access combine.
Active or fallback user access profile, if assigned.
Show child attributes
Show child attributes
Deprecated. A single-value summary of the highest-precedence profile (attribute_mapping > role_default > manual), kept for clients written before a user could hold several. It grants nothing on its own — read access_profiles instead.
Show child attributes
Show child attributes
Was this page helpful?

