> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zivio.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List Supplier Users

> Retrieve a paginated list of supplier_users. Use filters to narrow results.

## Filtering

Use the `filter[<attribute>]` parameter to filter results. Multiple filters are combined with AND logic.

### Basic Examples
```
# Equality (implicit)
GET /api/v4/supplier_users?filter[vetting_status]=NOT REGISTERED

# Multiple values (implicit IN)
GET /api/v4/supplier_users?filter[vetting_status]=NOT REGISTERED,FAILED

# With explicit operator
GET /api/v4/supplier_users?filter[created_at][gte]=2024-01-01

# Range query
GET /api/v4/supplier_users?filter[org_id][between]=10,100

# Multiple filters (AND)
GET /api/v4/supplier_users?filter[vetting_status]=NOT REGISTERED&filter[org_id][gte]=10
```

### Available Attributes

| Attribute | Type | Operators | Permitted Values |
|-----------|------|-----------|------------------|
| base_currency | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| created_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| email | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| first_name | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| has_oversight | boolean | `eq`, `not_eq` | - |
| id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| last_name | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| linkedin_url | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| org_id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| sso_only | boolean | `eq`, `not_eq` | - |
| supplier_id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| time_zone | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| uid | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | - |
| updated_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`, `between` | - |
| vetting_status | string | `eq`, `not_eq`, `in`, `not_in` | `NOT REGISTERED`, `PASSED`, `FAILED`, `PENDING` |

### Custom Fields

This resource supports custom field filtering using `cf[key]` syntax:
```
# Equality
GET /api/v4/supplier_users?cf[priority]=high

# With operator
GET /api/v4/supplier_users?cf[department][in]=engineering,design

# Check existence
GET /api/v4/supplier_users?cf[priority][exists]=

# Negation
GET /api/v4/supplier_users?cf[priority][not_eq]=low
```

### OR Conditions

Use `or[group]` to combine filter groups with OR logic. Filters within a group are ANDed:
```
# Simple OR
GET /api/v4/supplier_users?or[1][vetting_status]=PASSED&or[2][vetting_status]=NOT REGISTERED

# Complex OR (vetting_status=PASSED AND org_id>=10) OR (vetting_status=NOT REGISTERED)
GET /api/v4/supplier_users?or[1][vetting_status]=PASSED&or[1][org_id][gte]=10&or[2][vetting_status]=NOT REGISTERED
```

## Sorting

Use `sort[<attribute>]` to order results. Default direction is ascending.
```
# Ascending (implicit)
GET /api/v4/supplier_users?sort[created_at]=

# Descending
GET /api/v4/supplier_users?sort[created_at]=desc

# Combined with filters
GET /api/v4/supplier_users?filter[vetting_status]=NOT REGISTERED&sort[created_at]=desc
```



## OpenAPI

````yaml /api-reference/v4/openapi.json get /supplier_users
openapi: 3.1.0
info:
  title: API V4
  version: '4'
  description: >-
    OAuth 2.0 secured API. Obtain an access token using client credentials to
    access protected endpoints. The regional endpoints listed below serve every
    Zivio organisation, so each request — including the token request — must
    carry a `zivio-tenant-id` header identifying yours. Requests without it are
    rejected with a 404 before any token is checked.
  contact:
    name: API Support
    email: support@zivio.com
servers:
  - url: https://api.zivio.net/api/v4
    description: Global API Router
  - url: https://api.eu.zivio.net/api/v4
    description: EU Data Region
  - url: https://api.uk.zivio.net/api/v4
    description: UK Data Region
  - url: https://api.us.zivio.net/api/v4
    description: US Data Region
security:
  - oauth2: []
    tenantId: []
paths:
  /supplier_users:
    get:
      tags:
        - Supplier Users
      summary: List Supplier Users
      description: >-
        Retrieve a paginated list of supplier_users. Use filters to narrow
        results.


        ## Filtering


        Use the `filter[<attribute>]` parameter to filter results. Multiple
        filters are combined with AND logic.


        ### Basic Examples

        ```

        # Equality (implicit)

        GET /api/v4/supplier_users?filter[vetting_status]=NOT REGISTERED


        # Multiple values (implicit IN)

        GET /api/v4/supplier_users?filter[vetting_status]=NOT REGISTERED,FAILED


        # With explicit operator

        GET /api/v4/supplier_users?filter[created_at][gte]=2024-01-01


        # Range query

        GET /api/v4/supplier_users?filter[org_id][between]=10,100


        # Multiple filters (AND)

        GET /api/v4/supplier_users?filter[vetting_status]=NOT
        REGISTERED&filter[org_id][gte]=10

        ```


        ### Available Attributes


        | Attribute | Type | Operators | Permitted Values |

        |-----------|------|-----------|------------------|

        | base_currency | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | created_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`,
        `between` | - |

        | email | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` |
        - |

        | first_name | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | has_oversight | boolean | `eq`, `not_eq` | - |

        | id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`,
        `lte`, `between` | - |

        | last_name | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | linkedin_url | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | org_id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`, `lt`,
        `lte`, `between` | - |

        | sso_only | boolean | `eq`, `not_eq` | - |

        | supplier_id | integer | `eq`, `not_eq`, `in`, `not_in`, `gt`, `gte`,
        `lt`, `lte`, `between` | - |

        | time_zone | string | `eq`, `not_eq`, `in`, `not_in`, `like`,
        `not_like` | - |

        | uid | string | `eq`, `not_eq`, `in`, `not_in`, `like`, `not_like` | -
        |

        | updated_at | datetime | `eq`, `not_eq`, `gt`, `gte`, `lt`, `lte`,
        `between` | - |

        | vetting_status | string | `eq`, `not_eq`, `in`, `not_in` | `NOT
        REGISTERED`, `PASSED`, `FAILED`, `PENDING` |


        ### Custom Fields


        This resource supports custom field filtering using `cf[key]` syntax:

        ```

        # Equality

        GET /api/v4/supplier_users?cf[priority]=high


        # With operator

        GET /api/v4/supplier_users?cf[department][in]=engineering,design


        # Check existence

        GET /api/v4/supplier_users?cf[priority][exists]=


        # Negation

        GET /api/v4/supplier_users?cf[priority][not_eq]=low

        ```


        ### OR Conditions


        Use `or[group]` to combine filter groups with OR logic. Filters within a
        group are ANDed:

        ```

        # Simple OR

        GET
        /api/v4/supplier_users?or[1][vetting_status]=PASSED&or[2][vetting_status]=NOT
        REGISTERED


        # Complex OR (vetting_status=PASSED AND org_id>=10) OR
        (vetting_status=NOT REGISTERED)

        GET
        /api/v4/supplier_users?or[1][vetting_status]=PASSED&or[1][org_id][gte]=10&or[2][vetting_status]=NOT
        REGISTERED

        ```


        ## Sorting


        Use `sort[<attribute>]` to order results. Default direction is
        ascending.

        ```

        # Ascending (implicit)

        GET /api/v4/supplier_users?sort[created_at]=


        # Descending

        GET /api/v4/supplier_users?sort[created_at]=desc


        # Combined with filters

        GET /api/v4/supplier_users?filter[vetting_status]=NOT
        REGISTERED&sort[created_at]=desc

        ```
      operationId: getSupplierUsers
      parameters:
        - name: page
          in: query
          schema:
            type: integer
            default: 1
          description: Page number for pagination
        - name: limit
          in: query
          schema:
            type: integer
            default: 20
            maximum: 100
          description: Number of results per page (max 100)
        - name: filter[<attribute>]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            Filterable attributes:


            **integer** (operators: eq, not_eq, in, not_in, gt, gte, lt, lte,
            between): id, org_id, supplier_id

            **datetime** (operators: eq, not_eq, gt, gte, lt, lte, between):
            created_at, updated_at

            **string** (operators: eq, not_eq, in, not_in, like, not_like):
            base_currency, email, first_name, last_name, linkedin_url,
            time_zone, uid, vetting_status (one of: NOT REGISTERED, PASSED,
            FAILED, PENDING)

            **boolean** (operators: eq, not_eq): has_oversight, sso_only


            Note: `like` is a case-insensitive substring match — pass the bare
            term (filter[title][like]=redesign). Do not add % wildcards; they
            are not needed.
          examples:
            equality:
              summary: Simple equality
              value:
                vetting_status: NOT REGISTERED
            multiple_values:
              summary: Multiple values (implicit IN)
              value:
                vetting_status: NOT REGISTERED,FAILED
            with_operator:
              summary: With explicit operator
              value:
                created_at:
                  gte: '2024-01-01'
            range:
              summary: Range query
              value:
                org_id:
                  between: 10,100
        - name: or[group]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            OR condition groups. Filters within a group are ANDed; groups are
            ORed.


            **Syntax**: `or[group_key][<attribute>]=value` or
            `or[group_key][<attribute>][operator]=value`


            **Examples**:

            - Simple OR: `or[1][state]=draft&or[2][state]=pending`

            - Complex:
            `or[1][state]=draft&or[1][budget][gte]=50000&or[2][state]=closed`

            - With custom fields:
            `or[1][cf][priority]=high&or[2][state]=pending`


            Group keys can be any string (1, 2, a, b, etc.) - they just need to
            be unique.
          examples:
            simple_or:
              summary: Simple OR
              value:
                '1':
                  vetting_status: PASSED
                '2':
                  vetting_status: NOT REGISTERED
            complex_or:
              summary: Complex OR with AND within groups
              value:
                '1':
                  vetting_status: PASSED
                  org_id:
                    gte: '10'
                '2':
                  vetting_status: NOT REGISTERED
        - name: cf[key]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            Custom field filters using concise syntax.


            **Syntax**:

            - Equality: `cf[key]=value`

            - With operator: `cf[key][operator]=value`


            **Operators**: eq (default), not_eq, in, not_in, contains,
            not_contains, exists, not_exists


            **Examples**:

            - `cf[priority]=high` - exact match

            - `cf[department][in]=eng,design` - matches any

            - `cf[priority][not_eq]=low` - not equal

            - `cf[notes][contains]=urgent` - contains text

            - `cf[legacy_field][exists]=` - field exists (value ignored)

            - `cf[deprecated][not_exists]=` - field does not exist
          examples:
            equality:
              summary: Simple equality
              value:
                priority: high
            with_operator:
              summary: With IN operator
              value:
                department:
                  in: eng,design
            exists:
              summary: Check existence
              value:
                priority:
                  exists: ''
        - name: or[group][cf][key]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            Custom field filters within OR condition groups.


            **Syntax**: `or[group][cf][key]=value` or
            `or[group][cf][key][operator]=value`


            **Example**: `or[1][cf][priority]=high&or[2][state]=pending`
        - name: sort[<attribute>]
          in: query
          style: deepObject
          explode: true
          schema:
            type: object
          description: >-
            Sort results by attribute. Direction defaults to ascending.


            **Syntax**: `sort[<attribute>]=` (ascending) or
            `sort[<attribute>]=desc` (descending)


            **Sortable attributes**: base_currency, created_at, email,
            first_name, has_oversight, id, last_name, linkedin_url, org_id,
            sso_only, supplier_id, time_zone, uid, updated_at, vetting_status


            **Examples**:

            - Ascending: `sort[created_at]=` or `sort[created_at]=asc`

            - Descending: `sort[created_at]=desc`
          examples:
            ascending:
              summary: Ascending (implicit)
              value:
                created_at: ''
            descending:
              summary: Descending
              value:
                created_at: desc
      responses:
        '200':
          description: List of supplier_users
          content:
            application/json:
              schema:
                type: object
                properties:
                  supplier_users:
                    type: array
                    items:
                      $ref: '#/components/schemas/User'
              examples:
                success:
                  summary: Successful response with supplier_users
                  value:
                    supplier_users:
                      - id: 101
                        first_name: Demo
                        last_name: User
                        email: user1@example.com
                        org_name: Acme Corporation
                        org_id: 501
                        business_unit: null
                        division: null
                        department: null
                        has_oversight: true
                        vetting_status: PASSED
                        custom_fields:
                          department: Engineering
                          priority: high
                          cost_code: CC-001
                        created_at: '2024-01-16T10:30:00+00:00'
                        updated_at: '2024-01-16T10:30:00+00:00'
                      - id: 102
                        first_name: Jane
                        last_name: Smith
                        email: user2@example.com
                        org_name: Global Services Ltd
                        org_id: 502
                        business_unit: null
                        division: null
                        department: null
                        has_oversight: true
                        vetting_status: FAILED
                        custom_fields:
                          department: Engineering
                          priority: high
                          cost_code: CC-001
                        created_at: '2024-01-17T10:30:00+00:00'
                        updated_at: '2024-01-17T10:30:00+00:00'
                empty:
                  summary: Empty result set
                  value:
                    supplier_users: []
                filtered:
                  summary: Filtered results
                  description: Results after applying filters
                  value:
                    supplier_users:
                      - id: 101
                        first_name: Demo
                        last_name: User
                        email: user1@example.com
                        org_name: Acme Corporation
                        org_id: 501
                        business_unit: null
                        division: null
                        department: null
                        has_oversight: true
                        vetting_status: PASSED
                        custom_fields:
                          department: Engineering
                          priority: high
                          cost_code: CC-001
                        created_at: '2024-01-16T10:30:00+00:00'
                        updated_at: '2024-01-16T10:30:00+00:00'
        '401':
          description: >-
            Unauthorized - the access token is missing, expired, revoked or
            malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: invalid_token
                error_description: >-
                  The access token provided is expired, revoked, malformed, or
                  invalid for other reasons
        '403':
          description: Forbidden - insufficient scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error: insufficient_scope
                error_description: >-
                  The request requires higher privileges than provided by the
                  access token
                required_scope: supplier_users:read
                provided_scopes:
                  - welcome:read
        '422':
          description: Invalid filter or sort parameters
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                invalid_attribute:
                  summary: Unknown filter attribute
                  value:
                    error: 'Invalid filter attribute: unknown_field'
                invalid_operator:
                  summary: Invalid operator for type
                  value:
                    error: Operator 'like' is not valid for integer type
                invalid_value:
                  summary: Invalid value format
                  value:
                    error: 'Invalid date format for created_at: not-a-date'
                invalid_sort_attribute:
                  summary: Unknown sort attribute
                  value:
                    error: 'Invalid sort attribute: unknown_field'
                invalid_sort_direction:
                  summary: Invalid sort direction
                  value:
                    error: Invalid sort direction 'random'. Must be 'asc' or 'desc'
      security:
        - oauth2:
            - supplier_users:read
          tenantId: []
components:
  schemas:
    User:
      type: object
      properties:
        id:
          type: integer
        first_name:
          type: string
        last_name:
          type: string
        email:
          type: string
        org_name:
          type: string
        org_id:
          type: integer
        business_unit:
          type: string
        division:
          type: string
        department:
          type: string
        has_oversight:
          type: boolean
          example: true
        vetting_status:
          type: string
          enum:
            - NOT REGISTERED
            - PASSED
            - FAILED
            - PENDING
          example: NOT REGISTERED
        custom_fields:
          type: object
          additionalProperties:
            type: string
          description: Key-value pairs of custom field data
        created_at:
          type: string
        updated_at:
          type: string
    Error:
      type: object
      description: Error envelope returned by every non-2xx V4 response
      properties:
        error:
          type: string
          example: insufficient_scope
        error_description:
          type: string
        message:
          type: string
        details:
          type: object
          additionalProperties: true
        required_scope:
          type: string
          example: projects:read
        provided_scopes:
          type: array
          items:
            type: string
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client credentials. The access token from POST /oauth/token is
        sent as a bearer token. Request only the scopes you need.
      flows:
        clientCredentials:
          tokenUrl: https://api.zivio.net/api/v4/oauth/token
          scopes:
            bank_accounts:read: Read bank account details on suppliers and the org.
            catalogs:read: Read catalog items.
            cost_centers:read: Read cost center records.
            eoi_responses:read: Read responses to expressions of interest.
            eois:read: Read expressions of interest.
            offers:read: Read offers for projects.
            org_units:read: Read your organization unit hierarchy.
            org_users:read: Read members of your organization.
            resources:read: Read resource (worker) records.
            sales_invoices:read: Read invoices issued to clients.
            sales_milestones:read: Read milestones on sales engagements.
            skill_categories:read: Read the skill category taxonomy.
            skill_taxonomies:read: Read skill taxonomy structure.
            skills:read: Read individual skills.
            supplier_documents:read: Read documents uploaded by suppliers.
            supplier_lists:read: Read curated lists of suppliers.
            supplier_users:read: Read users belonging to supplier organizations.
            tax_types:read: Read configured tax types.
            users:read: Read user profiles.
            variation_orders:read: Read variation orders on projects.
            welcome:read: 'Required: confirms your identity to the application.'
            bid_evaluations:read: >-
              Read evaluation scorecards for bids, including criterion scores
              and quality, cost and total scores.
            bid_evaluations:write: >-
              Score bids against a project's quality criteria and override
              calculated cost scores.
            bids:read: Read bids submitted on projects.
            bids:write: >-
              Shortlist, select, eliminate and reinstate bids submitted on
              projects.
            invoices:read: Read invoices on projects.
            invoices:write: Create and update invoices.
            notes:read: Read notes on projects and EOIs.
            notes:write: Create and update notes on projects and EOIs.
            project_approvals:read: Read project approval workflows.
            project_approvals:write: Create and update project approval workflows.
            project_conversations:read: Read messages exchanged with suppliers on a project.
            project_conversations:write: Send messages to suppliers on a project.
            project_invitations:read: Read supplier invitations on projects.
            project_invitations:write: Invite suppliers to bid on projects.
            project_questions:read: Read supplier clarification questions on projects.
            project_questions:write: Answer and approve supplier clarification questions.
            projects:read: Read projects.
            projects:write: Create and update projects.
            milestones:read: Read milestones on projects.
            milestones:write: Create and update milestones.
            orgs:read: Read organization records.
            orgs:write: Create and update organization records.
            purchase_orders:read: Read purchase orders.
            purchase_orders:write: Create and update purchase orders.
            reviews:read: Read reviews left on suppliers.
            reviews:write: Create and update reviews.
            suppliers:read: Read supplier profiles.
            suppliers:write: Create and update supplier profiles.
            raw_scorecard_entries:write: Create and update raw scorecard entries.
            raw_scorecard_entries:read: Read raw scorecard entries.
            tasks:read: >-
              Read the acting user's task queue, including outstanding approvals
              and items to review.
            tasks:write: Complete and dismiss tasks in the acting user's task queue.
            act_as_user: >-
              Make requests as another user within the token holder's delegation
              boundary.
    tenantId:
      type: apiKey
      name: zivio-tenant-id
      in: header
      description: >-
        Your Zivio organisation identifier. The regional API endpoints serve
        every Zivio organisation, so each request must identify yours.

````