Action domain
user
Every action this domain exposes through gitlab_execute_action, from the gitlab://tools manifest. Each entry folds out to its full upstream description and required parameters.
76 · actions14 · destructive37 · read-only
Counted with a Free-tier GitLab token. The catalog is scoped to the token that asks, so the count moves with both its tier and its permissions: higher tiers expose more actions, and administration domains only appear to tokens allowed to use them.
user.activateActivate UserActivate a deactivated user. Returns: confirmation with the user ID and action. See also: user.deactivate, user.unblock, user.get.
Required parameters:
user_id (integer)user.activitiesGet User Activitiesread-onlyList user activities (admin). Returns: username and last-activity date per user. See also: user.list, user.contribution_events, user.memberships.
Required parameters: No required parameters
user.add_emailAdd EmailAdd an email address to the authenticated user's account. Returns: the created email's ID, address, and confirmation timestamp. See also: user.get_email, user.delete_email, user.add_email_for_user.
Required parameters:
email (string)user.add_email_for_userAdd Email For UserAdd an email address to a specific user's account (admin only). Returns: the created email's ID, address, and confirmation timestamp. See also: user.emails_for_user, user.delete_email_for_user, user.add_email.
Required parameters:
email (string),user_id (integer)user.add_gpg_keyAdd GPG KeyAdd a GPG key to the authenticated user's account. Returns: the created key's ID, armored public key, and creation timestamp. See also: user.gpg_keys, user.get_gpg_key, user.delete_gpg_key, user.add_gpg_key_for_user.
Required parameters:
key (string)user.add_gpg_key_for_userAdd GPG Key For UserAdd a GPG key to a specific user's account (admin only). Returns: the created key's ID, armored public key, and creation timestamp. See also: user.gpg_keys_for_user, user.get_gpg_key_for_user, user.delete_gpg_key_for_user, user.add_gpg_key.
Required parameters:
key (string),user_id (integer)user.add_ssh_keyAdd SSH KeyAdd an SSH key to the current user. Returns: created key ID, title, usage type, and expiry. See also: user.ssh_keys, user.get_ssh_key, user.delete_ssh_key.
Required parameters:
key (string),title (string)user.add_ssh_key_for_userAdd SSH Key For UserAdd an SSH key to a specific user. Returns: created key ID, title, usage type, and expiry. Requires admin token. See also: user.ssh_keys_for_user, user.get_ssh_key_for_user, user.delete_ssh_key_for_user.
Required parameters:
key (string),title (string),user_id (integer)user.approveApprove UserApprove a pending user sign-up. Returns: confirmation with the user ID and action. See also: user.reject, user.get, user.list.
Required parameters:
user_id (integer)user.associations_countGet User Associations Countread-onlyGet a user's association counts. Returns: groups, projects, issues, and merge-requests counts. See also: user.get, user.memberships, user.delete.
Required parameters:
user_id (integer)user.avatar_getGet Avatarread-onlyGet the avatar URL for an email address. Returns: the resolved avatar URL for that email address. See also: user.me, user.get_status.
Required parameters:
email (string)user.banBan UserdestructiveBan a user. Returns: confirmation with the user ID and action. Reversible via gitlab_unban_user. See also: user.unban, user.block, user.get.
Required parameters:
user_id (integer)user.blockBlock UserdestructiveBlock a user from signing in. Returns: confirmation with the user ID and action. Reversible via gitlab_unblock_user. See also: user.unblock, user.ban, user.get.
Required parameters:
user_id (integer)user.contribution_eventsList User Contribution Eventsread-onlyList a user's contribution events. Returns: event entries with action, target type/title, project, and timestamp. See also: user.get, user.activities, user.associations_count.
Required parameters:
user_id (integer)user.createCreate UserCreate a user account. Returns: created user identity and profile summary fields. See also: user.get, user.modify, user.block.
Required parameters:
email (string),name (string),username (string)user.create_current_user_patCreate Current User PatCreate a personal access token for the current user. Returns: token ID, the secret token, scopes, and expiry. See also: user.me, user.create_runner.
Required parameters:
name (string),scopes (array)user.create_impersonation_tokenCreate Impersonation TokenCreate an impersonation token for a user with the given scopes and optional expiry. Returns: the new token's id, name, active flag, scopes, revoked flag, created_at, expires_at, and the secret token value (shown once). See also: user.list_impersonation_tokens, user.revoke_impersonation_token, user.create_personal_access_token.
Required parameters:
name (string),scopes (array),user_id (integer)user.create_personal_access_tokenCreate Personal Access TokenCreate a personal access token for a user with the given scopes, optional description, and optional expiry. Returns: the new token's id, name, active flag, scopes, revoked flag, description, user_id, created_at, expires_at, and the secret token value (shown once). See also: user.create_impersonation_token, user.list_impersonation_tokens.
Required parameters:
name (string),scopes (array),user_id (integer)user.create_runnerCreate User RunnerCreate a runner linked to the current user. Returns: runner ID, authentication token, and token expiry. See also: user.me, user.create_current_user_pat.
Required parameters:
runner_type (string)user.create_service_accountCreate Service AccountCreate an instance-level service account. Returns: the created service account with ID, username, name, and email. Requires admin token. See also: user.list_service_accounts, user.update_service_account.
Required parameters: No required parameters
user.currentUser Currentread-onlyGet the current authenticated user. Returns: account ID, username, name, state, avatar URL, and profile metadata. See also: user.list, user.current_user_status, user.emails.
Required parameters: No required parameters
user.current_user_statusCurrent User Statusread-onlyGet the current user's status. Returns: emoji, message, availability, and clear-status time. See also: user.set_status, user.get_status, user.me.
Required parameters: No required parameters
user.deactivateDeactivate UserdestructiveDeactivate an active user. Returns: confirmation with the user ID and action. Reversible via gitlab_activate_user. See also: user.activate, user.block, user.get.
Required parameters:
user_id (integer)user.deleteDelete UserdestructiveDelete a user account. Returns: confirmation with the deleted user ID. Requires admin token. See also: user.get, user.block, user.associations_count.
Required parameters:
user_id (integer)user.delete_emailDelete EmaildestructiveDelete an email address from the authenticated user's account. Returns: a confirmation naming the deleted email ID. See also: user.get_email, user.add_email, user.delete_email_for_user.
Required parameters:
email_id (integer)user.delete_email_for_userDelete Email For UserdestructiveDelete an email address from a specific user's account (admin only). Returns: a confirmation naming the deleted email ID. See also: user.emails_for_user, user.add_email_for_user, user.delete_email.
Required parameters:
email_id (integer),user_id (integer)user.delete_gpg_keyDelete GPG KeydestructiveDelete a GPG key from the authenticated user's account. Returns: a confirmation naming the deleted key ID. See also: user.gpg_keys, user.get_gpg_key, user.add_gpg_key, user.delete_gpg_key_for_user.
Required parameters:
key_id (integer)user.delete_gpg_key_for_userDelete GPG Key For UserdestructiveDelete a GPG key from a specific user's account (admin only). Returns: a confirmation naming the deleted key ID. See also: user.gpg_keys_for_user, user.get_gpg_key_for_user, user.add_gpg_key_for_user, user.delete_gpg_key.
Required parameters:
key_id (integer),user_id (integer)user.delete_identityDelete User IdentitydestructiveDelete a user's external identity. Returns: confirmation with user ID and provider. Requires admin token. See also: user.get, user.modify.
Required parameters:
provider (string),user_id (integer)user.delete_ssh_keyDelete SSH KeydestructiveDelete one of the current user's SSH keys. Returns: confirmation with the deleted key ID. See also: user.ssh_keys, user.get_ssh_key, user.add_ssh_key.
Required parameters:
key_id (integer)user.delete_ssh_key_for_userDelete SSH Key For UserdestructiveDelete a specific user's SSH key. Returns: confirmation with the deleted key ID. Requires admin token. See also: user.ssh_keys_for_user, user.get_ssh_key_for_user, user.add_ssh_key_for_user.
Required parameters:
key_id (integer),user_id (integer)user.disable_two_factorDisable Two FactordestructiveDisable 2FA for a user. Returns: confirmation with the user ID and action. See also: user.get, user.modify.
Required parameters:
user_id (integer)user.emailsList Emailsread-onlyList the current user's email addresses. Returns: email entries with ID, address, and confirmation time. See also: user.me, user.modify.
Required parameters: No required parameters
user.emails_for_userList Emails For Userread-onlyList all email addresses registered to a specific user account. Returns: each email's ID, address, and confirmation timestamp, with offset/keyset pagination support. See also: user.get_email, user.add_email_for_user, user.delete_email_for_user, user.get.
Required parameters: No required parameters
user.event_list_contributionsUser Contribution Event Listread-onlyList the current user's contribution events. Returns: each event with action_name, target type and IID, push_data, embedded note, author object, created timestamp, and pagination metadata. See also: user.event_list_project, user.get.
Required parameters: No required parameters
user.event_list_projectProject Event Listread-onlyList a project's visible activity events. Returns: each event with action_name, target type and IID, push_data, embedded note with author, data (ref, commits, repository), author object, created timestamp, and pagination metadata. See also: user.event_list_contributions, project.get.
Required parameters:
project_id (string)user.getGet Userread-onlyGet one user by ID. Returns: detailed account profile metadata and status fields. See also: user.list, user.modify, user.delete.
Required parameters:
user_id (integer)user.get_emailGet Emailread-onlyGet one email address from the authenticated user's account by ID. Returns: the email's ID, address, and confirmation timestamp. See also: user.add_email, user.delete_email, user.emails_for_user.
Required parameters: No required parameters
user.get_gpg_keyGet GPG Keyread-onlyGet one GPG key from the authenticated user's account by ID. Returns: the key's ID, armored public key, and creation timestamp. See also: user.gpg_keys, user.add_gpg_key, user.delete_gpg_key.
Required parameters:
key_id (integer)user.get_gpg_key_for_userGet GPG Key For Userread-onlyGet one GPG key from a specific user's account by ID. Returns: the key's ID, armored public key, and creation timestamp. See also: user.gpg_keys_for_user, user.add_gpg_key_for_user, user.delete_gpg_key_for_user, user.get.
Required parameters:
key_id (integer),user_id (integer)user.get_impersonation_tokenGet Impersonation Tokenread-onlyGet a single impersonation token for a user by token id. Returns: the token's id, name, active flag, scopes, revoked flag, created_at, expires_at, and last_used_at. See also: user.list_impersonation_tokens, user.revoke_impersonation_token.
Required parameters:
token_id (integer),user_id (integer)user.get_ssh_keyGet SSH Keyread-onlyGet one of the current user's SSH keys by ID. Returns: key ID, title, public key, usage type, and expiry. See also: user.ssh_keys, user.add_ssh_key, user.delete_ssh_key.
Required parameters:
key_id (integer)user.get_ssh_key_for_userGet SSH Key For Userread-onlyGet a specific user's SSH key by ID. Returns: key ID, title, public key, usage type, and expiry. See also: user.ssh_keys_for_user, user.add_ssh_key_for_user, user.delete_ssh_key_for_user.
Required parameters:
key_id (integer),user_id (integer)user.get_statusGet User Statusread-onlyGet a user's status by ID. Returns: emoji, message, availability, and clear-status time. See also: user.current_user_status, user.set_status, user.get.
Required parameters:
user_id (integer)user.gpg_keysList GPG Keysread-onlyList the authenticated user's GPG keys. Returns: each key's ID, armored public key, and creation timestamp. See also: user.get_gpg_key, user.add_gpg_key, user.delete_gpg_key, user.gpg_keys_for_user.
Required parameters: No required parameters
user.gpg_keys_for_userList GPG Keys For Userread-onlyList a specific user's GPG keys. Returns: each key's ID, armored public key, and creation timestamp. See also: user.get_gpg_key_for_user, user.add_gpg_key_for_user, user.delete_gpg_key_for_user, user.get.
Required parameters:
user_id (integer)user.key_get_by_fingerprintGet Key By Fingerprintread-onlyLook up an SSH key or deploy key by fingerprint and return the owning user. Returns: the key ID, title, public key, creation time, and the owning user (ID, username, name). See also: user.get_ssh_key, user.ssh_keys, user.ssh_keys_for_user.
Required parameters:
fingerprint (string)user.key_get_with_userGet Key With Userread-onlyLook up an SSH key by its global ID and return the owning user. Returns: the key ID, title, public key, creation time, and the owning user (ID, username, name). See also: user.get_ssh_key, user.ssh_keys, user.ssh_keys_for_user.
Required parameters:
key_id (integer)user.listList Usersread-onlyList users with filtering and pagination support. Returns: user summaries including ID, username, name, state, and profile URLs. See also: user.get, user.me, user.create.
Required parameters: No required parameters
user.list_impersonation_tokensList Impersonation Tokensread-onlyList all impersonation tokens for a user. Returns: each token's id, name, active flag, scopes, revoked flag, created_at, expires_at, and last_used_at. See also: user.get_impersonation_token, user.create_impersonation_token, user.revoke_impersonation_token.
Required parameters:
user_id (integer)user.list_service_accountsList Service Accountsread-onlyList instance-level service accounts. Returns: service account summaries with ID, username, name, and email. Requires admin token. See also: user.create_service_account, user.update_service_account.
Required parameters: No required parameters
user.meUser Currentalias ofuser.currentread-onlyGet the current authenticated user. Returns: account ID, username, name, state, avatar URL, and profile metadata. See also: user.list, user.current_user_status, user.emails.
Required parameters: No required parameters
user.membershipsGet User Membershipsread-onlyList a user's memberships. Returns: source ID, name, type, and access level per membership. See also: user.get, user.associations_count, user.activities.
Required parameters:
user_id (integer)user.modifyModify UserModify an existing user. Returns: the updated user profile metadata. See also: user.get, user.create, user.delete.
Required parameters:
user_id (integer)user.namespace_existsNamespace Existsread-onlyCheck whether a namespace path is taken. Returns: an exists flag and suggested alternative paths when the path is unavailable. See also: user.namespace_get, user.namespace_search.
Required parameters:
id (string)user.namespace_getNamespace Getread-onlyGet a single namespace by ID or path. Returns: the namespace with id, name, path, kind, full path, parent id, plan, trial state, and seat usage. See also: user.namespace_list, user.namespace_search.
Required parameters:
id (string)user.namespace_listNamespace Listread-onlyList namespaces visible to the authenticated user. Returns: matching namespaces with id, name, path, kind, plan, seat usage, and pagination metadata. See also: user.namespace_get, user.namespace_search, group.list.
Required parameters: No required parameters
user.namespace_searchNamespace Searchread-onlySearch namespaces by name or path. Returns: matching namespaces with id, name, path, kind, and pagination metadata. See also: user.namespace_list, user.namespace_get.
Required parameters:
query (string)user.notification_global_getNotification Global Getread-onlyGet the authenticated user's global notification settings. Returns: the global notification level, notification email, and the per-event flags (issue, merge request, pipeline, note, and epic events) when the level is custom. See also: user.notification_global_update, user.notification_project_get, user.notification_group_get.
Required parameters: No required parameters
user.notification_global_updateNotification Global UpdateUpdate the authenticated user's global notification settings. Returns: the updated global notification level, notification email, and per-event flags. See also: user.notification_global_get, user.notification_project_update, user.notification_group_update.
Required parameters: No required parameters
user.notification_group_getNotification Group Getread-onlyGet the authenticated user's notification settings for a group. Returns: the group notification level, notification email, and per-event flags when the level is custom. See also: user.notification_group_update, user.notification_global_get, user.notification_project_get.
Required parameters:
group_id (string)user.notification_group_updateNotification Group UpdateUpdate the authenticated user's notification settings for a group. Returns: the updated group notification level, notification email, and per-event flags. See also: user.notification_group_get, user.notification_global_update, user.notification_project_update.
Required parameters:
group_id (string)user.notification_project_getNotification Project Getread-onlyGet the authenticated user's notification settings for a project. Returns: the project notification level, notification email, and per-event flags when the level is custom. See also: user.notification_project_update, user.notification_global_get, user.notification_group_get.
Required parameters:
project_id (string)user.notification_project_updateNotification Project UpdateUpdate the authenticated user's notification settings for a project. Returns: the updated project notification level, notification email, and per-event flags. See also: user.notification_project_get, user.notification_global_update, user.notification_group_update.
Required parameters:
project_id (string)user.rejectReject UserdestructiveReject a pending user sign-up. Returns: confirmation with the user ID and action. Permanently deletes the pending user. See also: user.approve, user.get, user.list.
Required parameters:
user_id (integer)user.revoke_impersonation_tokenRevoke Impersonation TokendestructiveRevoke an impersonation token for a user by token id. Returns: a confirmation naming the user_id and token_id with the revoked flag set. See also: user.list_impersonation_tokens, user.get_impersonation_token.
Required parameters:
token_id (integer),user_id (integer)user.set_statusSet User StatusSet the current user's status. Returns: the updated emoji, message, availability, and clear-status time. See also: user.current_user_status, user.get_status.
Required parameters: No required parameters
user.ssh_keysList SSH Keysread-onlyList the current user's SSH keys. Returns: key summaries with ID, title, fingerprint, usage type, and expiry. See also: user.get_ssh_key, user.add_ssh_key, user.delete_ssh_key.
Required parameters: No required parameters
user.ssh_keys_for_userList SSH Keys For Userread-onlyList a specific user's SSH keys. Returns: key summaries with ID, title, fingerprint, usage type, and expiry. See also: user.get_ssh_key_for_user, user.add_ssh_key_for_user, user.delete_ssh_key_for_user.
Required parameters:
user_id (integer)user.todo_listTodo Listread-onlyList the authenticated user's to-do items with optional filtering and pagination. Returns: to-do items with action, target object, project, author, state, and pagination metadata. See also: user.todo_mark_done, user.todo_mark_all_done.
Required parameters: No required parameters
user.todo_mark_all_doneTodo Mark All DoneMark all pending to-do items as done. Returns: a confirmation that all items were cleared. See also: user.todo_list, user.todo_mark_done.
Required parameters: No required parameters
user.todo_mark_doneTodo Mark DoneMark a single to-do item as done. Returns: a confirmation naming the to-do item ID. See also: user.todo_list, user.todo_mark_all_done.
Required parameters:
id (integer)user.unbanUnban UserUnban a previously banned user. Returns: confirmation with the user ID and action. See also: user.ban, user.unblock, user.get.
Required parameters:
user_id (integer)user.unblockUnblock UserUnblock a previously blocked user. Returns: confirmation with the user ID and action. See also: user.block, user.activate, user.get.
Required parameters:
user_id (integer)user.update_service_accountUpdate Instance Service AccountUpdate an instance-level service account. Returns: updated service account object including email and unconfirmed_email. Requires admin token. See also: user.create_service_account, user.list_service_accounts.
Required parameters:
service_account_id (integer)user.upload_avatarUpload User AvatarUpload the current user's avatar. Returns: the updated user profile including the new avatar URL. GitLab 19 responds with only avatar_url, so other profile fields (including id) may be empty. Use gitlab_user_current for the full profile. Provide filename and exactly one of file_path or content_base64. See also: user.me, user.modify.
Required parameters:
filename (string)