sondahub

sondahub / Identity API / Users

Fake identity users API

300 users from the Identity API, a fake user directory API. People. user_name is unique and is the login everywhere (SAML, OIDC password grant: password "probe"); email is [email protected].

Reads with filters, sorting, search and relations; writes that answer like a real server and stay in your session token. Same ids on every build. Free, no key, CORS open.

Connect

List
https://api.sondahub.com/v1/identity/users
One record
https://api.sondahub.com/v1/identity/users/{id}
OpenAPI 3
https://api.sondahub.com/v1/identity/openapi.json
GraphQL
https://api.sondahub.com/v1/identity/graphql
JSON file
https://api.sondahub.com/data/identity/users.json
MCP
https://api.sondahub.com/mcp · list_records
The first three users
curl "https://api.sondahub.com/v1/identity/users?limit=3"

Sample records

Records 1 to 3 of 300, exactly as GET /v1/identity/users/{id} answers them. The data file holds all of them.

[
  {
    "id": 1,
    "created_at": "2023-05-26T12:00:00Z",
    "updated_at": "2023-09-26T12:00:00Z",
    "user_name": "clara.brown",
    "given_name": "Clara",
    "family_name": "Brown",
    "display_name": "Clara Brown",
    "email": "[email protected]",
    "title": "Chief Executive Officer",
    "department": "Executive",
    "employee_number": "E1001",
    "manager_id": null,
    "phone": "+1-715-381-2882",
    "locale": "en-US",
    "timezone": "America/New_York",
    "office": "New York",
    "active": true,
    "external_id": "hr-21b07abaa4",
    "last_login_at": "2026-09-01T02:54:00Z"
  },
  {
    "id": 2,
    "created_at": "2023-07-03T12:00:00Z",
    "updated_at": "2024-04-05T12:00:00Z",
    "user_name": "giulia.thomas",
    "given_name": "Giulia",
    "family_name": "Thomas",
    "display_name": "Giulia Thomas",
    "email": "[email protected]",
    "title": "VP of Engineering",
    "department": "Engineering",
    "employee_number": "E1002",
    "manager_id": 1,
    "phone": "+1-707-878-9686",
    "locale": "en-US",
    "timezone": "America/Chicago",
    "office": "Remote",
    "active": true,
    "external_id": "hr-3d023e9c18",
    "last_login_at": "2026-08-29T20:53:00Z"
  },
  {
    "id": 3,
    "created_at": "2023-06-14T12:00:00Z",
    "updated_at": "2023-12-18T12:00:00Z",
    "user_name": "max.park",
    "given_name": "Max",
    "family_name": "Park",
    "display_name": "Max Park",
    "email": "[email protected]",
    "title": "VP of Product",
    "department": "Product",
    "employee_number": "E1003",
    "manager_id": 1,
    "phone": "+1-876-614-6679",
    "locale": "en-GB",
    "timezone": "Europe/London",
    "office": "London",
    "active": true,
    "external_id": "hr-35330577ea",
    "last_login_at": "2026-08-22T18:07:00Z"
  }
]

Fields

FieldTypeNotes
idread-onlyintAssigned by the server. Seed records keep their ids across restarts; records you create continue after the seed.
created_atread-onlydatetimeWhen the record was created (ISO 8601, UTC).
updated_atread-onlydatetimeWhen the record last changed.
user_namerequiredstringUnique login.
given_namerequiredstring
family_namerequiredstring
display_namestringDefaults to given and family name.
emailrequiredstring
titlestring
departmentstring
employee_numberstring
manager_idint → usersWho this person reports to; null for the CEO.
phonestring
localestring
timezonestring
officestring
activeboolfalse: deprovisioned — cannot sign in.
external_idstringThe id an upstream system (an HR tool, an IdP) knows this person by.
last_login_atdatetime

Relations: manager → one user through manager_id; reports → the users whose manager_id is this user; memberships → the memberships whose user_id is this user. Use ?expand=manager,reports,memberships to embed them, or the nested routes.

Endpoints

POST and PATCH keep user_name and email unique (409 already_exists, naming the user who has it); display_name defaults to the two names and active to true. The same people sign in through SAML and OIDC and are provisioned over SCIM.
GET/v1/identity/usersA page, with every filter, sort, search, field and expand option.
POST/v1/identity/usersCreate one: 201 with the record, its id, a Location header and the session token that keeps it; 422 names each field that is wrong.
GET/v1/identity/users/{id}One record, with an ETag; If-None-Match earns a 304.
PATCH/v1/identity/users/{id}Change the fields you send.
PUT/v1/identity/users/{id}Replace the record; required fields must all be there.
DELETE/v1/identity/users/{id}Answers 200 with what was removed (a real server’s 204 lives at /v1/utils/status/204); gone for the session.
GET/v1/identity/users/{id}/managerThe user this record points at.
GET/v1/identity/users/{id}/reportsIts users, as a page with all the list options.
GET/v1/identity/users/{id}/membershipsIts memberships, as a page with all the list options.

Try it

List with a filter
curl "https://api.sondahub.com/v1/identity/users?expand=manager&limit=3"
One record
curl https://api.sondahub.com/v1/identity/users/1?expand=manager
Its reports
curl "https://api.sondahub.com/v1/identity/users/1/reports?limit=5"
Create
curl -i -X POST https://api.sondahub.com/v1/identity/users \
  -H "Content-Type: application/json" \
  -d '{"user_name":"ada.lovelace","given_name":"Ada","family_name":"Lovelace","email":"[email protected]","title":"Staff Engineer","department":"Engineering","employee_number":"E1042","locale":"en-US","timezone":"America/New_York","office":"New York"}'
Read it back: newest first (send the session token)
curl "https://api.sondahub.com/v1/identity/users?sort=-id&limit=3" \
  -H "X-Sondahub-Session: THE_TOKEN_FROM_THE_CREATE"
Change one field
curl -X PATCH https://api.sondahub.com/v1/identity/users/1 \
  -H "Content-Type: application/json" \
  -d '{"user_name":"Changed user name"}'
Delete the one you created
curl -X DELETE https://api.sondahub.com/v1/identity/users/301 \
  -H "X-Sondahub-Session: THE_TOKEN_FROM_THE_CREATE"

Query recipes

Every list option works on users; these are ready to paste. All the options.

WhatRequest
Page 2, 50 at a time (of 300)/v1/identity/users?page=2&limit=50
Newest first by created at/v1/identity/users?sort=-created_at&limit=5
User name contains “clara”/v1/identity/users?user_name_like=clara
Full-text search/v1/identity/users?q=clara
Only some fields/v1/identity/users?fields=id,user_name&limit=5
Embed the manager/v1/identity/users/1?expand=manager
Its reports (nested route)/v1/identity/users/1/reports?limit=5
Just the count/v1/identity/users?limit=1&fields=id

GraphQL

The same users as the users query on https://api.sondahub.com/v1/identity/graphql, and one user as user(id: 1). Introspection is on. More on the GraphQL API.

{
  users(limit: 3, sort: "-id") {
    total
    data {
      id user_name given_name family_name
      manager { user_name }
      reports(limit: 2) { id }
    }
  }
}
Run it
curl https://api.sondahub.com/v1/identity/graphql -H "Content-Type: application/json" -d '{"query": "{ users(limit: 3, sort: \"-id\") { total data { id user_name given_name family_name manager { user_name } reports(limit: 2) { id } } } }"}'

From an AI agent (MCP)

The MCP server reaches the same rows with list_records, get_record, create_record, update_record and delete_record, and as the resource sondahub://identity/users.

tools/call
curl https://api.sondahub.com/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_records","arguments":{"api":"identity","collection":"users","limit":3}}}'

More in the Identity API

groups (40) · memberships (1,457)

The live streams, and the whole API on one page: Identity API. Other worlds: fake e-commerce API, fake IoT API, fake banking API, fake social media API, fake helpdesk API, fake flight booking API.