> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Provision an app user

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Gives a person access to this app ahead of their first sign-in, so the app can be embedded signed in as them. Returns `created` for a new email, and `exists` for an email that already has an access request, whatever its state: a request still pending approval stays pending, and an embed sign-in token for it answers `unknown_user`. A workspace API key needs the **Provision app users** permission. Limited to 120 requests a minute per app, shared with deprovisioning. Higher plans get a higher limit.



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/users/provisions
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/users/provisions:
    post:
      summary: Provision an app user
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Gives a person access to this app ahead of their first sign-in, so the
        app can be embedded signed in as them. Returns `created` for a new
        email, and `exists` for an email that already has an access request,
        whatever its state: a request still pending approval stays pending, and
        an embed sign-in token for it answers `unknown_user`. A workspace API
        key needs the **Provision app users** permission. Limited to 120
        requests a minute per app, shared with deprovisioning. Higher plans get
        a higher limit.
      operationId: provision_user_api_apps__app_id__users_provisions_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ProvisionUserPayload'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProvisionUserResponse'
        '400':
          description: '`role` is not one of the app''s roles: error.code invalid_role.'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: The key can't provision users of this app.
        '404':
          description: App not found.
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '429':
          description: >-
            The app went over its per-minute limit for provision and deprovision
            requests combined.
      security:
        - PersonalAccessTokenAuth: []
        - WorkspaceApiKeyAuth: []
components:
  schemas:
    ProvisionUserPayload:
      properties:
        email:
          type: string
          format: email
          title: Email
          description: The app user's email — their identity in this app
        role:
          type: string
          title: Role
          description: Application-level role for in-app permissions
        full_name:
          anyOf:
            - type: string
              maxLength: 256
            - type: 'null'
          title: Full Name
      additionalProperties: false
      type: object
      required:
        - email
        - role
      title: ProvisionUserPayload
      description: Payload for server-to-server app-user provisioning (embedded platforms).
    ProvisionUserResponse:
      properties:
        status:
          type: string
          enum:
            - created
            - exists
          title: Status
          description: >-
            `created` for a new email, `exists` for one that already had an
            access request.
          example: created
        email:
          type: string
          title: Email
          description: The email, lowercased.
          example: dana@example.com
        role:
          type: string
          title: Role
          description: >-
            The role the email holds in the app. For `exists`, the role it
            already had.
          example: user
      type: object
      required:
        - status
        - email
        - role
      title: ProvisionUserResponse
      description: The app user an email was provisioned as.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'
    WorkspaceApiKeyAuth:
      type: apiKey
      in: header
      name: api_key
      description: 'Workspace API key, sent as `api_key: <key>`.'

````