Create an Account identity
/portal/v1/accounts/{accountSlug}/identitiesCreates an identity at the Account tier. When environment_id is supplied, a same-transaction EnvironmentMembership is created so the identity can sign into that Environment immediately; when omitted, the identity is created as an orphan in the directory and access is granted later via the membership endpoints. The Environment must belong to this Account (404). Returns 409 on a duplicate email and 400 when the supplied password is found in the breach list.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
identities.manageIdentitiesManage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
Request body
application/json
emailstring Required first_namestring Required last_namestring Required passwordstring Optional Initial password (8-64 chars). NIST SP 800-63B aligned — no composition rules. HaveIBeenPwned breach check runs server-side. Omit to create a passwordless identity (sign-in via SSO/social or forgot-password reset).
external_idstring Optional metadataobject Optional environment_idstring Optional Optional Environment ID. When present, a same-transaction EnvironmentMembership row is created so the identity can sign into the named Environment immediately. Omit to create an orphan identity in the directory — the admin can grant access to one or more Environments later.
Responses
application/json
data *AccountIdentityDetailResponseDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
Returned object
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities" \ -H "Authorization: Bearer $CANOPY_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "email": "string", "first_name": "string", "last_name": "string", "password": "string", "external_id": "string", "metadata": {}, "environment_id": "string" }'
{ "data": { "id": "string", "email": "string", "first_name": "string", "last_name": "string", "avatar_url": "string", "external_id": "string", "metadata": {}, "is_active": false, "erased_at": "2026-04-20T12:00:00.000Z", "email_verified": false, "email_verified_at": "2026-04-20T12:00:00.000Z", "locked_until": "2026-04-20T12:00:00.000Z", "password_changed_at": "2026-04-20T12:00:00.000Z", "environment_membership_count": 0, "total_assignments": 0, "created_at": "2026-04-20T12:00:00.000Z", "environment_memberships": [ { "id": "string", "environment_id": "string", "environment_slug": "string", "environment_name": "string", "application_slug": "string", "application_name": "string", "status": "active", "created_at": "2026-04-20T12:00:00.000Z", "assignment_count": 0 } ] } }
Tell us how we can improve this guide.