Skip to main content
GET
Shared users are the teammates you invite into your Scanova account — the same list shown on the dashboard’s Users table. This endpoint lets you list, invite, update, or remove them programmatically.
This endpoint was not previously documented. It requires an API key with MANAGEMENT_API (or MANAGEMENT_API_SANDBOX) quota, sent as the raw Authorization header value — see the API overview — plus the account’s own Team quota for shared users. For what each role actually grants, see Roles & permissions; for the wire format of roles themselves, see Roles (access levels).
An account with no invited teammates returns an empty results array, as above. The shape below is what each entry looks like once teammates exist.
string
Exact-match filter on the shared user’s email address.
string
Case-insensitive substring match against the shared user’s first name.
string
Comma-separated role names to filter by, e.g. Admin,Manager.
string
One of invitation_sent, active, inactive.
string
One of enabled, disabled, pending.
string
shared_user__email, shared_user__first_name, or either prefixed with - for descending.

Response fields (per entry)

integer
Shared-user record ID — use this as {pk} for the retrieve/update/delete endpoints below.
object
The invited user’s account.
object
The assigned role, in the same shape returned by GET /multi-users/access-levels/.
string
Computed status: Invitation Sent, Active, Inactive (no login in 60+ days), or Locked.
boolean
Whether the shared user’s account is active (distinct from status — a deactivated user always shows is_active: false regardless of invitation state).
string | null
ISO 8601 timestamp of the (most recent) invitation email.
string | null
ISO 8601 timestamp of when the invite was accepted, or null if still pending.
boolean
If true, this user’s QR Code visibility is restricted to the tags in tags below.
boolean
When tag-based permission is enabled, whether the user can also see untagged QR Codes.
array
Tags this user is scoped to (only meaningful when enable_tag_permission is true), in {id, name} form.
string
string

Authorizations

Authorization
string
header
required

Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: YOUR_API_KEY. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.

Response

200 - application/json

Paginated list of shared users invited to this account.