---
title: "Create Portal User"
url: "https://developer.yukisoftware.com/apis/yuki-platform-api-prod-1/versions/1237fe18-1f8f-477a-8f52-b3546dd409bf/operations/createUser"
---

> Full API specification: https://developer.yukisoftware.com/apis/yuki-platform-api-prod-1/versions/1237fe18-1f8f-477a-8f52-b3546dd409bf.md

# Create Portal User

`POST` `/portals/{portal-id}/users`

Operation ID: `createUser`

This endpoint allows the creation of a user in the portal. Ensure the user has the necessary permissions before attempting to create a user. You should have yukiapi:portal:users:write scope to access this endpoint. <!-- authorization:start --> **Authorization** Called with a **Portal User** token - an employee of an accounting portal. The caller must hold the `AccountantManagement` role in the portal. <!-- authorization:end -->

## Path parameters

- `portal-id` (string, required) - The portal id

## Header parameters

- `Authorization` (string, required) - Bearer token for authentication
- `Content-Type` (string, required) - Content type of the request body

## Request body (required)

Content types: `application/json`

## Responses

- `201` - Portal user created successfully
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden
- `500` - Internal Server Error

## OpenAPI definition

```yaml
openapi: 3.0.0
info:
  title: Yuki Platform API Prod
  version: 1.0.52
servers:
  - url: https://apirest.yukiworks.com/api/v1
paths:
  /portals/{portal-id}/users:
    post:
      x-environments:
        - development
        - pilot
        - production
      x-portal-visibility:
        - internal
        - trusted
        - prod
      x-required-roles:
        - any-of:
            - AccountantManagement
          scope: portal
      summary: Create Portal User
      description: >-
        This endpoint allows the creation of a user in the portal. Ensure the
        user has the necessary permissions before attempting to create a user.
        You should have yukiapi:portal:users:write scope to access this
        endpoint.


        <!-- authorization:start -->


        **Authorization**


        Called with a **Portal User** token - an employee of an accounting
        portal.


        The caller must hold the `AccountantManagement` role in the portal.


        <!-- authorization:end -->
      operationId: createUser
      tags:
        - Portal User
      parameters:
        - $ref: "#/components/parameters/AuthorizationHeader"
        - $ref: "#/components/parameters/ContentTypeHeader"
        - $ref: "#/components/parameters/PortalIdPath"
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: "#/components/schemas/CreatePortalUser"
      security:
        - vismaConnectPortalUser:
            - yukiapi:portal:users:write
      responses:
        "201":
          $ref: "#/components/responses/PortalUserCreateResponse"
        "400":
          $ref: "#/components/responses/BadRequestResponse"
        "401":
          $ref: "#/components/responses/UnauthorizedResponse"
        "403":
          $ref: "#/components/responses/ForbiddenResponse"
        "500":
          $ref: "#/components/responses/InternalServerErrorResponse"
security:
  - vismaConnectPortalUser:
      - yukiapi:portal:users:write
components:
  parameters:
    AuthorizationHeader:
      name: Authorization
      in: header
      required: true
      description: Bearer token for authentication
      schema:
        type: string
    ContentTypeHeader:
      name: Content-Type
      in: header
      required: true
      description: Content type of the request body
      schema:
        type: string
        default: application/json
    PortalIdPath:
      name: portal-id
      in: path
      required: true
      description: The portal id
      example: 3afb7b54-6144-4561-9a29-1148006f2375
      schema:
        type: string
  schemas:
    CreatePortalUser:
      type: object
      properties:
        firstName:
          type: string
          description: First name of the user
        lastName:
          type: string
          description: Last name of the user
        email:
          type: string
          format: email
          description: User email
          example: john.doe@yuki.nl
        language:
          $ref: "#/components/schemas/Language"
        role:
          type: string
          description: Role of the user
          enum:
            - PortalAdministrator
            - PortalBackoffice
            - PortalDataEntry
        message:
          type: string
          description: User message
      required:
        - firstName
        - lastName
        - email
        - language
        - role
    Language:
      type: string
      enum:
        - nl-BE
        - en-US
        - fr-BE
        - nl-NL
      description: |
        The locale for the domain. \
        BE: nl-BE, en-US, fr-BE. \
        NL: en-US, nl-NL
      example: en-US
    BadRequestError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://example.com/errors/bad-request
        title: Bad Request
        status: 400
        detail: The request is invalid or malformed.
        instance: /example/bad-request
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://example.com/errors/unauthorized
        title: Unauthorized
        status: 401
        detail: Authentication is required.
        instance: /example/unauthorized
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://example.com/errors/forbidden
        title: Forbidden
        status: 403
        detail: You do not have permission to access this resource.
        instance: /example/forbidden
    InternalServerError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://example.com/errors/internal-server-error
        title: Internal Server Error
        status: 500
        detail: An unexpected error occurred.
        instance: /example/internal-server-error
    ProblemDetails:
      type: object
      properties:
        type:
          type: string
          example: https://dev.yuki.nl/errors/problem
        title:
          type: string
          example: Problem
        status:
          type: integer
          example: 500
        detail:
          type: string
          example: An unexpected error occurred.
        instance:
          type: string
          example: /example/endpoint
  responses:
    PortalUserCreateResponse:
      description: Portal user created successfully
      headers:
        Location:
          description: The URL of the newly created user resource
          schema:
            type: string
      content:
        application/json:
          schema:
            type: object
            properties:
              id:
                type: string
                description: The ID of the created user
                example: 3afb7b54-6144-4561-9a29-1148006f2375
    BadRequestResponse:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
    ForbiddenResponse:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/InternalServerError"
  securitySchemes:
    vismaConnectPortalUser:
      type: oauth2
      description: >
        Visma Connect token belonging to a **Portal User** - an employee of an
        accounting portal. The token carries a `portal-id` claim, and the portal
        it identifies must match the portal in the route. Unless an endpoint
        says otherwise, the caller's roles are resolved against the portal.
      flows:
        authorizationCode:
          authorizationUrl: https://connect.identity.stagaws.visma.com/connect/authorize
          tokenUrl: https://connect.identity.stagaws.visma.com/connect/token
          scopes:
            yukiapi:domain:companies:read: Allows reading information of a Company
            yukiapi:domain:companies:update: Allows the update of a Company
            yukiapi:portal:portals:read: Allows reading portal information
            yukiapi:domain:domains:read: Allows reading domains information
            yukiapi:domain:domains:write: Allows modifications of domain information, may
              include create/update
            yukiapi:domain:domains:create: Allows the creation of new domains
            yukiapi:domain:domains:update: Allows updating existing domain information
            yukiapi:domain:domains:delete: Allows the deletion of domain data
            yukiapi:domain:users:read: Allows reading of domain user data
            yukiapi:domain:users:write: Allows the update of domain user data, may include create/update
            yukiapi:domain:users:update: Allows updating a Domain User
            yukiapi:domain:users:delete: Allows the deletion of Domain Users
            yukiapi:portal:portals:write: Allows updating existing portal information
            yukiapi:portal:users:read: Allows reading Portal user data
            yukiapi:portal:users:write: Allows the update of Portal user, may include create/update
            yukiapi:portal:users:update: Allows updating an existing Portal User
            yukiapi:portal:users:delete: Allows the deletion of a Portal User
```
