---
title: "Search Portal Users"
url: "https://developer.yukisoftware.com/apis/yuki-platform-api-prod-1/versions/9cdc452d-fd77-4e06-8797-f61e76134ec9/operations/searchPortalUsers"
---

> Full API specification: https://developer.yukisoftware.com/apis/yuki-platform-api-prod-1/versions/9cdc452d-fd77-4e06-8797-f61e76134ec9.md

# Search Portal Users

`GET` `/portals/{portal-id}/users/search`

Operation ID: `searchPortalUsers`

This endpoint allows searching for users within a specific portal by email address. Returns the user details if a match is found. Users attempting to perform this operation need to ensure they possess the necessary permissions. You should have the **openid** and **yukiapi:portal:users:read** scopes to access this endpoint. Returns portals:user_not_found (404) if no user in this portal carries that address. <!-- authorization:start --> **Authorization** Called with a **Portal User** token - an employee of an accounting portal. The caller must hold at least one of these roles in the portal: `AccountantManagement`, `Accountant`. <!-- authorization:end -->

## Path parameters

- `portal-id` (string, required) - The portal id

## Query parameters

- `email` (string, email, required) - Email address to search for

## Header parameters

- `Authorization` (string, required) - Bearer token for authentication

## Responses

- `200` - Portal user object
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden
- `404` - Not Found
- `500` - Internal Server Error

## OpenAPI definition

```yaml
openapi: 3.0.0
info:
  title: Yuki Platform API Prod
  version: 1.0.77
servers:
  - url: https://apirest.yukiworks.be/api/v1
paths:
  /portals/{portal-id}/users/search:
    get:
      x-environments:
        - development
        - pilot
        - production
      x-portal-visibility:
        - internal
        - trusted
        - prod
      x-required-roles:
        - any-of:
            - AccountantManagement
            - Accountant
          scope: portal
      summary: Search Portal Users
      description: >-
        This endpoint allows searching for users within a specific portal by
        email address. Returns the user details if a match is found. Users
        attempting to perform this operation need to ensure they possess the
        necessary permissions. You should have the **openid** and
        **yukiapi:portal:users:read** scopes to access this endpoint. Returns
        portals:user_not_found (404) if no user in this portal carries that
        address.


        <!-- authorization:start -->


        **Authorization**


        Called with a **Portal User** token - an employee of an accounting
        portal.


        The caller must hold at least one of these roles in the portal:
        `AccountantManagement`, `Accountant`.


        <!-- authorization:end -->
      operationId: searchPortalUsers
      tags:
        - Portal User
      parameters:
        - $ref: "#/components/parameters/AuthorizationHeader"
        - $ref: "#/components/parameters/PortalIdPath"
        - $ref: "#/components/parameters/EmailQuery"
      security:
        - vismaConnectPortalUser:
            - openid
            - yukiapi:portal:users:read
      responses:
        "200":
          $ref: "#/components/responses/PortalUsersResponse"
        "400":
          $ref: "#/components/responses/BadRequestResponse"
        "401":
          $ref: "#/components/responses/UnauthorizedResponse"
        "403":
          $ref: "#/components/responses/ForbiddenResponse"
        "404":
          $ref: "#/components/responses/NotFoundResponse"
        "500":
          $ref: "#/components/responses/InternalServerErrorResponse"
security:
  - vismaConnectPortalUser:
      - openid
      - yukiapi:portal:users:read
components:
  parameters:
    AuthorizationHeader:
      name: Authorization
      in: header
      required: true
      description: Bearer token for authentication
      schema:
        type: string
    PortalIdPath:
      name: portal-id
      in: path
      required: true
      description: The portal id
      example: 3afb7b54-6144-4561-9a29-1148006f2375
      schema:
        type: string
    EmailQuery:
      name: email
      in: query
      required: true
      description: Email address to search for
      schema:
        type: string
        format: email
  responses:
    PortalUsersResponse:
      description: Portal user object
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/PortalUser"
    BadRequestResponse:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    UnauthorizedResponse:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
    ForbiddenResponse:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
    NotFoundResponse:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/NotFoundError"
    InternalServerErrorResponse:
      description: Internal Server Error
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/InternalServerError"
  schemas:
    PortalUser:
      type: object
      properties:
        id:
          type: string
          description: The user's ID
          example: 3afb7b54-6144-4561-9a29-1148006f2375
        name:
          type: string
          description: Full name of the user
          example: John Doe
        email:
          type: string
          format: email
          description: User email
          example: john.doe@yuki.nl
        language:
          description: >
            The user's locale. Empty string when the stored value has no ISO
            mapping (e.g. the user never chose a language).
          anyOf:
            - $ref: "#/components/schemas/Language"
            - type: string
              enum:
                - ""
        roles:
          $ref: "#/components/schemas/PortalUserRoles"
    BadRequestError:
      description: A 400 comes in two shapes that differ by title. A request that
        fails model binding never reaches the operation and carries the title
        below, with errors keyed by the rejected field. A request the operation
        itself rejects carries the title Validation Error, with errors keyed by
        the rejected field for a field check, or by the errorCode for a business
        rule. Both shapes carry errorCode, traceId and errors.
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/400
        title: One or more validation errors occurred.
        status: 400
        detail: The request contains invalid or malformed fields. See the errors
          property for details.
        instance: /example/bad-request
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: validation:invalid_input
        errors:
          country:
            - The country field is required.
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/401
        title: Unauthorized
        status: 401
        detail: Authentication is required.
        instance: /example/unauthorized
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: authentication:unauthorized
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/403
        title: Forbidden
        status: 403
        detail: You do not have permission to access this resource.
        instance: /example/forbidden
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: authentication:forbidden
        errors:
          authentication:forbidden:
            - You do not have permission to access this resource.
    NotFoundError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/404
        title: Not Found
        status: 404
        detail: The requested resource could not be found.
        instance: /example/not-found
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: companies:not_found
        errors:
          companies:not_found:
            - The requested resource could not be found.
    InternalServerError:
      allOf:
        - $ref: "#/components/schemas/ProblemDetails"
      example:
        type: https://httpstatuses.com/500
        title: Internal Server Error
        status: 500
        detail: An unexpected error occurred.
        instance: /example/internal-server-error
        traceId: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode: server:internal_error
        errors:
          server:internal_error:
            - An unexpected error occurred.
    Language:
      type: string
      enum:
        - nl-BE
        - en-US
        - fr-BE
        - nl-NL
      description: |
        The locale for the domain. \
        BE: nl-BE, en-US, fr-BE. \
        NL: en-US, nl-NL
      example: en-US
    PortalUserRoles:
      type: array
      description: User roles for portal users
      items:
        type: string
        enum:
          - PortalAdministrator
          - PortalBackoffice
          - PortalBackofficeController
          - PortalDataEntry
    ProblemDetails:
      type: object
      description: Error body returned as application/problem+json on every 4xx and
        5xx response. Beyond the standard problem members it carries the
        traceId, errorCode and errors extensions.
      properties:
        type:
          type: string
          description: URI reference identifying the problem type. Always
            https://httpstatuses.com/{status}, so it restates the status and
            carries no Yuki-specific meaning; branch on errorCode instead.
          example: https://httpstatuses.com/400
        title:
          type: string
          description: Short, human-readable summary of the problem type, in English.
          example: Validation Error
        status:
          type: integer
          description: HTTP status code, repeated from the response status line.
          example: 400
        detail:
          type: string
          description: Human-readable explanation of this specific occurrence. Free text
            meant for developers, not a stable contract - do not parse it.
          example: The company id is required.
        instance:
          type: string
          description: Optional. Path of the request as the API received it. The gateway
            fronts the API, so it is not always populated and it may differ from
            the URL the client called.
          example: /api/v1/companies/3afb7b54-6144-4561-9a29-1148006f2375
        traceId:
          type: string
          description: Correlation id for the request - the 32-character hexadecimal W3C
            trace id taken from the incoming traceparent header, or a locally
            generated id when none was propagated. Quote it in support requests.
          example: 4bf92f3577b34da6a3ce929d0e0e4736
        errorCode:
          type: string
          description: Stable machine-readable error identifier in {feature}:{error_type}
            form. This is the member to branch on, together with the status -
            not the feature prefix on its own. A request refused before it
            reaches the operation can answer 403 with validation:invalid_input,
            and an operation that fails on an unexpected internal state can
            answer 500 with that same code.
          example: companies:not_found
        errors:
          type: object
          description: Messages that explain the failure, grouped by key. Present on the
            errors raised while the request is being handled, not only on
            validation failures. It is absent from the errors that stop a
            request before it reaches the operation - the 401 for a missing or
            unaccepted token, the 403 for an absent scope or an unusable tenant
            claim, and the 500 for a session that could not be created - which
            carry only traceId and errorCode. Keys take one of two shapes - the
            name of the rejected field when the request failed model binding or
            field validation, otherwise the errorCode of the failure, repeating
            the errorCode member.
          additionalProperties:
            type: array
            items:
              type: string
          example:
            companies:validation_failed:
              - The company id is required.
  securitySchemes:
    vismaConnectPortalUser:
      type: oauth2
      description: >
        Visma Connect token belonging to a **Portal User** - an employee of an
        accounting portal. The token's tenant must be a portal; the API resolves
        it to the caller's portal. The portal in the route must be that portal
        or one of the caller's master-accountant portals. Unless an endpoint
        says otherwise, the caller's roles are resolved against the portal.
      flows:
        authorizationCode:
          authorizationUrl: https://connect.identity.stagaws.visma.com/connect/authorize
          tokenUrl: https://connect.identity.stagaws.visma.com/connect/token
          scopes:
            openid: Required on every request, together with the endpoint API scope
            yukiapi:domain:companies:read: Allows reading information of a Company
            yukiapi:domain:companies:update: Allows the update of a Company
            yukiapi:portal:portals:read: Allows reading portal information
            yukiapi:domain:domains:read: Allows reading domains information
            yukiapi:domain:domains:write: Allows modifications of domain information, may
              include create/update
            yukiapi:domain:domains:create: Allows the creation of new domains
            yukiapi:domain:domains:update: Allows updating existing domain information
            yukiapi:domain:domains:delete: Allows the deletion of domain data
            yukiapi:domain:users:read: Allows reading of domain user data
            yukiapi:domain:users:write: Allows the creation of Domain Users
            yukiapi:domain:users:delete: Allows the deletion of Domain Users
            yukiapi:portal:portals:write: Allows updating existing portal information
            yukiapi:portal:users:read: Allows reading Portal user data
            yukiapi:portal:users:write: Allows the update of Portal user, may include create/update
            yukiapi:portal:users:update: Allows updating an existing Portal User
            yukiapi:portal:users:delete: Allows the deletion of a Portal User
```
