> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Users

> Manage an app's users, invitations, access requests, and shared groups with the Base44 Apps API

<Note>
  The Apps API is in beta. Its endpoints and responses may change.
</Note>

These endpoints manage who can use an app. List and change its users, invite people, handle requests to join, and control which workspace groups the app is shared with.

## Getting people in

There are three ways to give someone access.

* [Invite app users](/api-reference/invite-app-users) emails each person a link to the app. Set `collaborator_role` to `editor` to let them edit the app in Base44 too.
* [Provision an app user](/api-reference/provision-an-app-user) gives someone access ahead of their first sign-in, so the app can be embedded signed in as them. Pair it with [Create an embed sign-in token](/api-reference/create-an-embed-sign-in-token) to get the embed URL.
* People can ask to join. [List access requests](/api-reference/list-access-requests) shows them, and [Approve or deny access request](/api-reference/approve-or-deny-access-request) answers each one.

[List app users](/api-reference/list-app-users) shows only people who have signed in. Someone you've invited who hasn't signed in yet isn't listed.

## Roles and groups

A person's role in the app is the highest of the role you gave them directly and the roles of every shared group they belong to. Lowering a group's role, or removing a group share, doesn't lower a role someone still holds another way.

## Endpoints

### App users

* [List app users](/api-reference/list-app-users): List the people who signed up to or joined the app.
* [Count app users](/api-reference/count-app-users): Count the app's users.
* [Get app user](/api-reference/get-app-user): Read one user, or your own record with `me`.
* [Update app user](/api-reference/update-app-user): Change a user's role or custom fields.
* [Remove app user](/api-reference/remove-app-user): Remove a user from the app.

### Invitations and access requests

* [Invite app users](/api-reference/invite-app-users): Invite people to the app by email.
* [List access requests](/api-reference/list-access-requests): List people who asked to join and people invited who haven't joined.
* [Approve or deny access request](/api-reference/approve-or-deny-access-request): Answer a request to join.
* [Update pending invitee](/api-reference/update-pending-invitee): Set custom fields on someone who hasn't joined yet.

### Provisioning

* [Provision an app user](/api-reference/provision-an-app-user): Give someone access before their first sign-in.
* [Deprovision an app user](/api-reference/deprovision-an-app-user): Remove someone's access, including their app user if they've signed in.
* [Create an embed sign-in token](/api-reference/create-an-embed-sign-in-token): Create a single-use token that opens the app signed in as a provisioned user.

### Group shares

* [List group shares](/api-reference/list-group-shares): List the workspace groups the app is shared with.
* [Update group share](/api-reference/update-group-share): Change the app role a group's members get.
* [Remove group share](/api-reference/remove-group-share): Stop sharing the app with a group.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.