Skip to main content

Users endpoint for Azure AD B2C

Use this endpoint to retrieve a user when using the Azure AD B2C platform. The endpoint requires an objectId to be provided, which is equivalent to the Authentication Cloud username.

For Azure AD B2C compatibility, the authenticator data is returned in a single string, instead of an array in the HTTP response.

HTTP request

GET https://{instance}.mauth.nevis.cloud/api/v1/aadb2c/users?objectId={username}
note

This endpoint requires the user to be registered with a username that is in a UUID format. For example: 250558c2-1dfc-4210-84a4-ddd1a37c740a.

Query parameters

ParameterTypeRequired/OptionalDescription
objectIdUUIDrequiredUnique identifier of the user to retrieve. Equivalent to the Authentication Cloud username.

Example HTTP request

Get user by objectId for Azure AD B2C
curl "https://$instance.mauth.nevis.cloud/api/v1/aadb2c/users?objectId=$username" \
-H "Authorization: Bearer $access_key"

HTTP response

The response always returns HTTP 200 - OK, regardless of success or failure. The response only returns the registered FIDO UAF authenticators, such as a mobile app authenticator. Registered FIDO2 authenticators, phone numbers, and recovery codes are not included in the response.

FieldTypeDescription
userIdUUIDUnique identifier of this user.
usernameUUIDThe internal customer ID or unique identifier to link a user to your internal systems. The value can be null.
statusenumThe current status of the user, either new: The user has no confirmed authenticator yet; or active: The user has registered at least one authenticator and is able to log in.
createdAtstringThe date when the user was created.
updatedAtstringThe date when the user was last updated.
lastLoginDateSuccessstringThe date of the last successful login with this user.
lastLoginDateFailurestringThe date of the last failed login with this user.
authenticatorsstringContain data of the already registered FIDO UAF authenticators in a string format.
authenticatorIdUUIDIncluded in authenticators string. The Unique identifier of the authenticator.
namestringIncluded in authenticators string. The name of the authenticator provided by the user.
typeenumIncluded in authenticators string. Defines the mobile platform for mobile app authenticators. The value is ios for iOS, and android for Android.
authenticatorTypeenumIncluded in authenticators string. Determines the type of the authenticator. The value can be appor fido2.
stateenumIncluded in authenticators string. Indicates the state of the authenticator.
enrolledAtstringIncluded in authenticators string. The date when the authenticator was registered.
updatedAtstringIncluded in authenticators string. The date when the authenticator was last updated.
uafDICTIncluded in authenticators string. If present, this field contains data related to the FIDO UAF authenticator. Only applicable if the authenticatorType is app.
uaf.userAgentstringIncluded in authenticators string. Optional user agent. The client application sends the userAgent when a FIDO UAF authenticator is registered or used for authentication.
uaf.deviceRefUUIDIncluded in authenticators string. Unique identifier of the physical device. This value does not change other than in specific scenarios: Can the Device Ref of the authenticator change?
uaf.userDisabledPushNotificationbooleanIncluded in authenticators string. Indicates if a user is disabled (true) or enabled (false) notifications for their application. When disabled, push authentication is not possible.
lastLoginDateSuccessstringIncluded in authenticators string. The date of the last successful login with this authenticator.
lastLoginDateFailurestringIncluded in authenticators string. The date of the last failed login with this authenticator.
phonesarrayContain data of the already registered phone numbers in a string format.
recoveryCodesDICTContains information about the registered recovery codes.
exceededRateLimitsDICTIndicates that the push rate limit is reached for the given user. This means that the user and all of their authenticators are blocked. This field and the objects it contains are only present if push rate limiting is enabled for your instance, and the given user reached the set limit.
exceededRateLimits.pushDICTContains data of the push rate limit.
exceededRateLimits.push.resetInSecondsstringIndicates the remaining amount of time before the rate limit resets and the user gets unblocked. The measurement unit is in UTC epoch seconds.
exceededRateLimits.push.sentstringThe number of push notifications sent in set timeframe.
exceededRateLimits.push.timeframeISO 8601 durationThe time frame in which the number of sent push notification are counted. The time frame is relative to the current time.
note

The lastLoginDateFailure field is only updated when a technical failure occurs during credential validation. If the login flow is interrupted at an earlier stage, or if the request times out, no failed login gets recorded, and thus the field remains unchanged.

Example HTTP response

200 OK: User is found.

JSON code sample of a user with a FIDO UAF authenticator
{
"userId": "b29dcde8-1aef-4fe9-a88e-4bdb7d09469f",
"username": "250558c2-1dfc-4210-84a4-ddd1a37c740a",
"status": "active",
"createdAt": "2023-09-25T17:51:50Z",
"updatedAt": "2023-09-25T17:51:50Z",
"recoveryCodes": null,
"authenticators": "[{\"authenticatorId\":\"88c89879-42cf-4660-a86e-2e8fc626f47d\",\"name\":\"samsung SM-G973F 2023. szept. 25. 19:55:23\",\"type\":\"android\",\"authenticatorType\":\"app\",\"state\":\"active\",\"enrolledAt\":\"2024-01-18T09:46:20Z\",\"updatedAt\":\"2024-01-18T09:46:20Z\",\"lastLoginDateSuccess\":\"2024-04-30T12:33:42Z\",\"lastLoginDateFailure\":\"2024-04-30T12:23:15Z\",\"uaf\":{\"userAgent\":\"NMASDK/3.3.0.1443 (samsung SM-G973F; Android 12) ch.nevis.accessapp.muvonda/2.7.0.1878\",\"deviceRef\":\"22f5ee06-f714-41f1-b819-34eff4688673\",\"userDisabledPushNotification\": false}}]",
"phones": "[]"
}
JSON code sample of a user with a FIDO2 authenticator
{
"userId": "967a8938-73c8-40b0-aed8-413c4198f7ad",
"username": "c242de3f-7788-4eca-93b6-85c93a9cee42",
"status": "active",
"createdAt": "2024-05-24T11:00:30Z",
"updatedAt": "2024-05-24T11:00:56Z",
"lastLoginDateSuccess": "2024-05-24T11:00:56Z",
"lastLoginDateFailure": "2024-04-30T12:23:15Z",
"recoveryCodes": null,
"authenticators": "[{\"authenticatorId\":\"a2dc6dfe-0d21-48a9-be8a-0e24ccc47f81\",\"name\":\"Unnamed FIDO2 authenticator\",\"authenticatorType\":\"fido2\",\"state\":\"active\",\"enrolledAt\":\"2024-05-24T11:00:55Z\",\"updatedAt\":\"2024-05-24T11:01:19Z\",\"fido2\":{\"userAgent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36\",\"rpId\":\"sandbag-dev-7d5f1f.mauth.nevis.cloud\",\"aaguid\":\"53414d53-554e-4700-0000-000000000000\",\"userVerificationRequirement\":\"preferred\",\"attestationConveyancePreference\":\"none\",\"residentKeyRequirement\":\"discouraged\"},\"lastLoginDateSuccess\":\"2024-05-24T11:01:19Z\",\"lastLoginDateFailure\":\"2024-04-30T12:23:15Z\"}]",
"phones": "[]"
}