> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ユーザーの作成

> Create a human user directly, outside of the SCIM provisioning flow. Use this for non-SCIM-managed users (for example, contractors, break-glass accounts, or organizations without SCIM configured). Users created via this endpoint carry `scim_managed: false` in the response. For SCIM-provisioned users, configure SCIM sync with your IdP. This endpoint is idempotent by `external_id`: a second POST with the same `external_id` returns the existing user instead of creating a duplicate.




## OpenAPI

````yaml ja/API/Management-API.yaml POST /users
openapi: 3.1.0
info:
  title: CData Connect AI Management API
  version: v1
  description: >
    The Connect AI Management API provides programmatic control over enterprise
    platform administration. Base path: /api/v1/admin. Use it to manage users,
    service accounts, roles, and resource permissions without manual UI
    operations. The API follows OAS 3.0 standards with OAuth 2.0 scoped
    authentication.

    On versioning: the version prefix is incremented when breaking changes
    require it. A new /api/v2/admin path will be introduced with a 6-month
    deprecation notice before any v1 endpoint is retired.

    On human users vs. service accounts: human users are provisioned and
    lifecycle-managed by SCIM; the Management API handles direct overrides and
    atomic deprovisioning. Service accounts (CI/CD pipelines, IaC tooling,
    Terraform) are fully managed via the Management API and are not SCIM-owned.
servers:
  - url: https://cloud.cdata.com/api/v1/admin
    description: Production base URL
security:
  - oauth2: []
tags:
  - name: Users
    description: >
      Lifecycle management for human users: create, update, deprovision, and
      manage direct role assignments, workspace-scoped roles, and direct
      resource permissions. SCIM handles group-based provisioning and user
      creation at scale; this API handles direct overrides and atomic
      deprovisioning.
  - name: Service Accounts
    description: >
      Full lifecycle management for machine identities (CI/CD pipelines, IaC
      tooling, Terraform automation). Service accounts are not SCIM-owned and
      authenticate via OAuth 2.0 client credentials using the `client_id`
      returned on creation.
paths:
  /users:
    post:
      tags:
        - Users
      summary: Create User
      description: >
        Create a human user directly, outside of the SCIM provisioning flow. Use
        this for non-SCIM-managed users (for example, contractors, break-glass
        accounts, or organizations without SCIM configured). Users created via
        this endpoint carry `scim_managed: false` in the response. For
        SCIM-provisioned users, configure SCIM sync with your IdP. This endpoint
        is idempotent by `external_id`: a second POST with the same
        `external_id` returns the existing user instead of creating a duplicate.
      operationId: createUser
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateUserRequest'
            example:
              email: jane.doe@example.com
              first_name: Jane
              last_name: Doe
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
              example:
                id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
                email: jane.doe@example.com
                first_name: Jane
                last_name: Doe
                status: invited
                scim_managed: false
                external_id: null
                created_at: '2026-01-15T10:00:00Z'
                created_by: 00000000-0000-0000-0000-000000000001
        '400':
          $ref: '#/components/responses/ValidationError'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                user_already_exists:
                  summary: Email already exists
                  value:
                    error:
                      code: USER_ALREADY_EXISTS
                      message: A user with this email already exists.
      security:
        - oauth2:
            - management:users:write
components:
  schemas:
    CreateUserRequest:
      type: object
      required:
        - email
        - first_name
      properties:
        email:
          type: string
          format: email
          description: Must be globally unique across all Connect AI orgs.
        first_name:
          type: string
          description: The user's first name.
        last_name:
          type: string
          nullable: true
          description: The user's last name. Omit for users with a single name.
        external_id:
          type: string
          description: >
            Idempotency key supplied by the calling system (for example, an HR
            system employee ID or Terraform resource ID). A second POST with the
            same key returns the existing user instead of creating a duplicate.
            Connect AI does not generate this value; the caller provides it.
    User:
      type: object
      properties:
        id:
          type: string
          format: uuid
          description: User identifier.
        email:
          type: string
          format: email
          description: The email address of the user.
        first_name:
          type: string
          description: The user's first name.
        last_name:
          type: string
          nullable: true
          description: The user's last name.
        status:
          type: string
          enum:
            - active
            - invited
            - deactivated
          description: Current lifecycle state of the user.
        scim_managed:
          type: boolean
          description: '`false` for API-created users. `true` for SCIM-provisioned users.'
        external_id:
          type: string
          nullable: true
          description: Idempotency key supplied by the calling system.
        created_at:
          type: string
          format: date-time
          description: ISO 8601 UTC.
        created_by:
          type: string
          format: uuid
          nullable: true
          description: User ID of the creator. null for SCIM-provisioned users.
    ErrorResponse:
      type: object
      properties:
        error:
          type: object
          description: Error details.
          properties:
            code:
              type: string
              description: SCREAMING_SNAKE_CASE error code.
            message:
              type: string
              description: Human-readable error description.
  responses:
    ValidationError:
      description: Bad Request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            error:
              code: VALIDATION_ERROR
              message: Missing required field or invalid value.
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://cloud-login.cdata.com/oauth/token
          scopes:
            management:users:read: Read access to user resources.
            management:users:write: Write access to user resources.
            management:service-accounts:read: Read access to service account resources.
            management:service-accounts:write: Write access to service account resources.

````