Users

For instructions on how to authenticate to use this endpoint, see API overview.

Endpoints

GET
DELETE
POST
POST
DELETE
GET
POST
GET
DELETE
POST

Retrieve users integrations github install requests

Return the requesting user's GitHub App install-approval requests, newest first.

This is the durable server-side "awaiting org owner approval" state (see posthog.models.user_integration.GitHubInstallRequest), distinct from the in-flight connect spinner, which never touches this table.

Required API key scopes

user:read

Path parameters

  • uuid
    string

Response


Example request

GET /api/users/:uuid/integrations/github/install_requests
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/install_requests/

Example response

Status 200
RESPONSE
{
"results": [
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"github_login": "string",
"status": "pending",
"installation_id": "string",
"account_login": "string",
"account_type": "string",
"requested_at": "2019-08-24T14:15:22Z",
"resolved_at": "2019-08-24T14:15:22Z"
}
],
"install_url": "string"
}

Retrieve users integrations github install requests

Return the requesting user's GitHub App install-approval requests, newest first.

This is the durable server-side "awaiting org owner approval" state (see posthog.models.user_integration.GitHubInstallRequest), distinct from the in-flight connect spinner, which never touches this table.

Required API key scopes

user:read

Path parameters

  • uuid
    string

Response


Example request

GET /api/users/:uuid/integrations/github/install_requests
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/install_requests/

Example response

Status 200
RESPONSE
{
"results": [
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"github_login": "string",
"status": "pending",
"installation_id": "string",
"account_login": "string",
"account_type": "string",
"requested_at": "2019-08-24T14:15:22Z",
"resolved_at": "2019-08-24T14:15:22Z"
}
],
"install_url": "string"
}

Delete users integrations github install requests

Delete one of the requesting user's install-approval requests, whatever its status.

User-facing bookkeeping only: a later connect attempt records a fresh row.

Required API key scopes

user:write

Path parameters

  • request_id
    string
  • uuid
    string

Example request

DELETE /api/users/:uuid/integrations/github/install_requests/:request_id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/install_requests/:request_id/

Example response

Status 204 Request dismissed.

Delete users integrations github install requests

Delete one of the requesting user's install-approval requests, whatever its status.

User-facing bookkeeping only: a later connect attempt records a fresh row.

Required API key scopes

user:write

Path parameters

  • request_id
    string
  • uuid
    string

Example request

DELETE /api/users/:uuid/integrations/github/install_requests/:request_id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/install_requests/:request_id/

Example response

Status 204 Request dismissed.

Create users integrations github prepare callback

Seed personal GitHub manage callback state before opening installation settings on GitHub.

Required API key scopes

user:write

Path parameters

  • uuid
    string

Request parameters

  • installation_id
    string

Example request

POST /api/users/:uuid/integrations/github/prepare_callback
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/prepare_callback/\
-d installation_id="string"

Example response

Status 204 No content

Create users integrations github prepare callback

Seed personal GitHub manage callback state before opening installation settings on GitHub.

Required API key scopes

user:write

Path parameters

  • uuid
    string

Request parameters

  • installation_id
    string

Example request

POST /api/users/:uuid/integrations/github/prepare_callback
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/prepare_callback/\
-d installation_id="string"

Example response

Status 204 No content

Create users integrations github start

Start GitHub linking: either full App install or OAuth-only (user-to-server).

**_kwargs absorbs parent_lookup_uuid from the nested /api/users/{uuid}/integrations/ router (same pattern as local_evaluation under projects).

Usually returns install_url pointing at /installations/new so the user can pick any GitHub org (new or already connected). GitHub's install page handles both cases: orgs where the app is installed show "Configure" (no admin needed), orgs where it isn't show "Install" (needs admin).

OAuth fast path: when the current project already has a team-level GitHub installation, and the user has no UserIntegration for that installation yet, we skip the org picker and redirect straight to /login/oauth/authorize so the user only authorizes themselves. connect_from is preserved for first-party clients so they return to the originating client immediately.

In both cases the response key is install_url for compatibility with callers.

Required API key scopes

user:write

Path parameters

  • uuid
    string

Request parameters

  • team_id
    integer | null
  • connect_from
    string

Response


Example request

POST /api/users/:uuid/integrations/github/start
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/start/\
-d team_id="integer"

Example response

Status 200
RESPONSE
{
"install_url": "string",
"connect_flow": "string"
}

Create users integrations github start

Start GitHub linking: either full App install or OAuth-only (user-to-server).

**_kwargs absorbs parent_lookup_uuid from the nested /api/users/{uuid}/integrations/ router (same pattern as local_evaluation under projects).

Usually returns install_url pointing at /installations/new so the user can pick any GitHub org (new or already connected). GitHub's install page handles both cases: orgs where the app is installed show "Configure" (no admin needed), orgs where it isn't show "Install" (needs admin).

OAuth fast path: when the current project already has a team-level GitHub installation, and the user has no UserIntegration for that installation yet, we skip the org picker and redirect straight to /login/oauth/authorize so the user only authorizes themselves. connect_from is preserved for first-party clients so they return to the originating client immediately.

In both cases the response key is install_url for compatibility with callers.

Required API key scopes

user:write

Path parameters

  • uuid
    string

Request parameters

  • team_id
    integer | null
  • connect_from
    string

Response


Example request

POST /api/users/:uuid/integrations/github/start
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/github/start/\
-d team_id="integer"

Example response

Status 200
RESPONSE
{
"install_url": "string",
"connect_flow": "string"
}

Delete users integrations slack

Remove a Slack identity link by Slack user id. Idempotent and flag-agnostic — users must always be able to unlink even after the feature flag is turned off.

Required API key scopes

user:write

Path parameters

  • slack_user_id
    string
  • uuid
    string

Example request

DELETE /api/users/:uuid/integrations/slack/:slack_user_id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/slack/:slack_user_id/

Example response

Status 204 Slack link removed.

Delete users integrations slack

Remove a Slack identity link by Slack user id. Idempotent and flag-agnostic — users must always be able to unlink even after the feature flag is turned off.

Required API key scopes

user:write

Path parameters

  • slack_user_id
    string
  • uuid
    string

Example request

DELETE /api/users/:uuid/integrations/slack/:slack_user_id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/slack/:slack_user_id/

Example response

Status 204 Slack link removed.

Retrieve users integrations slack linkable workspaces

Return Slack workspaces in the user's organizations that they have not yet linked. The settings UI uses this list to decide whether to show a "Link my Slack account" button (non-empty list) and what to offer in the picker when several are connectable.

Required API key scopes

user:read

Path parameters

  • uuid
    string

Response


Example request

GET /api/users/:uuid/integrations/slack/linkable_workspaces
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/slack/linkable_workspaces/

Example response

Status 200
RESPONSE
{
"results": [
{
"posthog_team_id": 0,
"posthog_team_name": "string",
"posthog_organization_name": "string",
"slack_team_id": "string",
"slack_team_name": "string"
}
]
}

Retrieve users integrations slack linkable workspaces

Return Slack workspaces in the user's organizations that they have not yet linked. The settings UI uses this list to decide whether to show a "Link my Slack account" button (non-empty list) and what to offer in the picker when several are connectable.

Required API key scopes

user:read

Path parameters

  • uuid
    string

Response


Example request

GET /api/users/:uuid/integrations/slack/linkable_workspaces
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/slack/linkable_workspaces/

Example response

Status 200
RESPONSE
{
"results": [
{
"posthog_team_id": 0,
"posthog_team_name": "string",
"posthog_organization_name": "string",
"slack_team_id": "string",
"slack_team_name": "string"
}
]
}

Create users integrations slack start

Mint a Sign-in-with-Slack invite URL initiated from settings, without Slack-DM context. The returned URL takes the user through PostHog login (already satisfied here), then to Slack OAuth, then back to our callback which writes the UserIntegration row.

Without body params, falls back to the user's current_team and that team's first Slack Integration — works when there's exactly one linkable workspace. With team_id + slack_team_id, links against the exact pair (what the frontend uses when a picker is shown).

Refuses if the target team has no matching Slack workspace, if the feature flag is off for the workspace, or if the user is already linked to it.

Required API key scopes

user:write

Path parameters

  • uuid
    string

Request parameters

  • team_id
    integer | null
  • slack_team_id
    string | null

Response


Example request

POST /api/users/:uuid/integrations/slack/start
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/slack/start/\
-d team_id="integer"

Example response

Status 200
RESPONSE
{
"install_url": "string"
}

Create users integrations slack start

Mint a Sign-in-with-Slack invite URL initiated from settings, without Slack-DM context. The returned URL takes the user through PostHog login (already satisfied here), then to Slack OAuth, then back to our callback which writes the UserIntegration row.

Without body params, falls back to the user's current_team and that team's first Slack Integration — works when there's exactly one linkable workspace. With team_id + slack_team_id, links against the exact pair (what the frontend uses when a picker is shown).

Refuses if the target team has no matching Slack workspace, if the feature flag is off for the workspace, or if the user is already linked to it.

Required API key scopes

user:write

Path parameters

  • uuid
    string

Request parameters

  • team_id
    integer | null
  • slack_team_id
    string | null

Response


Example request

POST /api/users/:uuid/integrations/slack/start
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/integrations/slack/start/\
-d team_id="integer"

Example response

Status 200
RESPONSE
{
"install_url": "string"
}

List all users login sessions

List the cookie-auth login sessions for the current user. Self-only — never another user.

Path parameters

  • uuid
    string

Query parameters

  • email
    string
  • is_staff
    boolean

Example request

GET /api/users/:uuid/login_sessions
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/login_sessions/

Example response

Status 200
RESPONSE
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"last_activity": "2019-08-24T14:15:22Z",
"location": "string",
"device": "string",
"login_method": "string",
"is_current": true
}

List all users login sessions

List the cookie-auth login sessions for the current user. Self-only — never another user.

Path parameters

  • uuid
    string

Query parameters

  • email
    string
  • is_staff
    boolean

Example request

GET /api/users/:uuid/login_sessions
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/login_sessions/

Example response

Status 200
RESPONSE
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"last_activity": "2019-08-24T14:15:22Z",
"location": "string",
"device": "string",
"login_method": "string",
"is_current": true
}

Delete users login sessions

Revoke a single login session belonging to the current user. Self-only.

Requires recent auth (TimeSensitiveActionPermission) so a stolen cookie can't weaponize revocation, and is blocked while impersonating via ImpersonationBlockedPathsMiddleware.

Path parameters

  • session_id
    string
  • uuid
    string

Example request

DELETE /api/users/:uuid/login_sessions/:session_id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/login_sessions/:session_id/

Example response

Status 204 Login session revoked.

Delete users login sessions

Revoke a single login session belonging to the current user. Self-only.

Requires recent auth (TimeSensitiveActionPermission) so a stolen cookie can't weaponize revocation, and is blocked while impersonating via ImpersonationBlockedPathsMiddleware.

Path parameters

  • session_id
    string
  • uuid
    string

Example request

DELETE /api/users/:uuid/login_sessions/:session_id
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl -X DELETE \
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/login_sessions/:session_id/

Example response

Status 204 Login session revoked.

Create users login sessions revoke others

Revoke every login session for the current user except the one making this request. Self-only.

Requires recent auth (TimeSensitiveActionPermission) so a stolen cookie can't weaponize the "log out everywhere else" lock-out, and is blocked while impersonating.

Path parameters

  • uuid
    string

Response


Example request

POST /api/users/:uuid/login_sessions/revoke_others
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/login_sessions/revoke_others/

Example response

Status 200
RESPONSE
{
"revoked_count": 0
}

Create users login sessions revoke others

Revoke every login session for the current user except the one making this request. Self-only.

Requires recent auth (TimeSensitiveActionPermission) so a stolen cookie can't weaponize the "log out everywhere else" lock-out, and is blocked while impersonating.

Path parameters

  • uuid
    string

Response


Example request

POST /api/users/:uuid/login_sessions/revoke_others
export POSTHOG_PERSONAL_API_KEY=[your personal api key]
curl
-H 'Content-Type: application/json'\
-H "Authorization: Bearer $POSTHOG_PERSONAL_API_KEY" \
<ph_app_host>/api/users/:uuid/login_sessions/revoke_others/

Example response

Status 200
RESPONSE
{
"revoked_count": 0
}