For the complete documentation index, see llms.txt. This page is also available as Markdown.

Authorize server

Authorize Server User

get

Authorize a Cloud user to access a workspace service.

ZenML and Kitaru services call this endpoint to validate the caller's workspace membership. This is also the endpoint called in the second phase of the workspace authorization flow for web clients.

Args: request: The HTTP request server_id: Workspace ID auth_context: Authentication context workspace_manager: Workspace manager

Returns: The currently authenticated user.

Raises: IllegalOperationError: If a workspace-scoped token is used that was not issued for the given workspace.

Authorizations
OAuth2clientCredentialsRequired
Token URL:

OAuth2authorizationCodeRequired
Authorization URL: Token URL: Refresh URL:
Query parameters
server_idstring · uuidRequired
Responses
200

Successful Response

application/json

User model for displaying user account and service account information.

This model is currently used for both user accounts and service accounts to ensure backward compatibility.

passwordstring · nullableOptional
password_expiredboolean · nullableOptional
namestring · min: 1 · max: 50 · nullableOptional

The name of the user.

avatar_urlstring · nullableOptional

The avatar URL of the user.

companystring · min: 1 · max: 50 · nullableOptional

The company of the user.

job_titlestring · min: 1 · max: 50 · nullableOptional

The job title of the user.

idstring · uuidRequired
usernameany ofRequired

The unique username for the account. For OAuth2 user accounts, this is the same as the email address.

string · min: 1 · max: 50OptionalPattern: ^[a-zA-Z0-9_\-@.]+$
or
string · emailOptional
emailstring · nullableOptional

The email address associated with the account. For OAuth2 user accounts, this is the unique identifier for the user and is also used as the username.

oauth_providerstring · nullableOptional

The external OAuth2 provider that the user is associated with.

oauth_idstring · nullableOptional

The external OAuth2 ID of the user.

is_activebooleanOptional

Whether the account is active.

Default: true
is_superuserbooleanOptional

Whether the account is a superuser.

Default: false
is_service_accountbooleanOptional

Whether the account is a service account.

Default: false
organization_idstring · uuid · nullableOptional

The ID of the organization that the service account belongs to. Only set for service accounts.

password_changed_atstring · date-time · nullableOptional

The time when the user's password was last changed.

is_onboardedbooleanOptional

Whether the user has completed onboarding.

Default: false
get/users/authorize_server
GET /users/authorize_server?server_id=123e4567-e89b-12d3-a456-426614174000 HTTP/1.1
Authorization: Bearer YOUR_OAUTH2_TOKEN
Accept: */*
{
  "password": "text",
  "password_expired": true,
  "name": "text",
  "avatar_url": "text",
  "company": "text",
  "job_title": "text",
  "metadata": {
    "ANY_ADDITIONAL_PROPERTY": "anything"
  },
  "id": "123e4567-e89b-12d3-a456-426614174000",
  "username": "text",
  "email": "text",
  "oauth_provider": "text",
  "oauth_id": "text",
  "is_active": true,
  "is_superuser": false,
  "is_service_account": false,
  "organization_id": "123e4567-e89b-12d3-a456-426614174000",
  "password_changed_at": "2026-01-01T00:00:00.000Z",
  "is_onboarded": false
}
ZenML Scarf

Last updated

Was this helpful?