> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List identities

> Retrieves a paginated list of identities in your workspace. Use pagination parameters to navigate through large identity lists efficiently.

<Note>
  **Related guide**: Identities guide. See the [Identities guide](/ai-studio/observability/identities) for a walkthrough with examples.
</Note>


## OpenAPI

````yaml get /v2/identities
openapi: 3.1.0
info:
  title: orq.ai API
  version: '2.0'
  description: orq.ai API documentation
servers:
  - url: https://my.orq.ai
security:
  - ApiKey: []
tags:
  - name: Chunking
    description: Split text into smaller chunks for retrieval and generation workflows.
  - name: File Systems
    description: >-
      Create and manage persistent file systems that agents and MCP clients read
      from and write to.
  - name: Knowledge Bases
    description: Create and manage knowledge bases used by agents and retrieval workflows.
  - name: Memory Stores
    description: Create and manage memory stores, memories, and memory documents.
  - name: Evals
    description: Run an evaluator against a conversation and its result
  - name: Logs
    description: >-
      OpenTelemetry log query API. Search, filter, aggregate, and facet log
      records ingested via OTLP.
  - name: Reporting
    description: >-
      GenAI reporting API over canonical analytics rollups. Accepts a metric
      name, time range, grain, group-by, and filters; returns a typed time
      series and optional totals.
  - name: Traces
    description: >-
      Query and inspect ingested trace data: search trace summaries, aggregate
      metrics, and read individual traces and their spans.
  - description: List models available through the AI Router.
    name: Models
  - name: Policies
  - name: Alerts
    description: >-
      Alerts evaluate a Reporting API metric on a fixed interval and fire
      notifications through notifiers when the value breaches a threshold. Each
      breach opens a trigger that tracks the incident until the value recovers.
  - name: Annotation Queues
    description: Annotation queues collect spans for human review.
  - name: API keys
    description: >-
      API keys authenticate programmatic access to the workspace. They expose
      opaque tokens, per-domain access grants, and budget and rate-limit
      constraints.
  - name: Audit Logs
    description: Audit logs record workspace entity changes and access-relevant events.
  - name: Budgets
    description: >-
      Budgets govern spend, token usage, and request rate across six scopes:
      workspace, project, identity, API key, provider, and model. Every
      applicable budget is enforced, and the most restrictive limit applies per
      dimension.
  - name: Files
    description: File upload and retrieval operations.
  - name: Guardrail Rules
    description: >-
      Guardrail Rules conditionally enforce evaluators and plugins for AI
      Gateway traffic. Rules may be scoped to a project or the whole workspace.
  - name: Hub
    description: Hub items are reusable templates available to a workspace.
  - name: Identities
    description: >-
      Identities represent end users from your system for usage and engagement
      tracking.
  - name: Management keys
    description: >-
      Management keys are workspace-scoped credentials that authenticate
      programmatic access to workspace administration surfaces (API keys,
      budgets). Unlike project-scoped API keys, a management key always operates
      at the workspace level.
  - name: MCP Gateway
    description: >-
      Register upstream MCP servers, discover and sync their tools, and assemble
      gateways that expose a curated tool surface to MCP clients.
  - name: Model Catalog
    description: >-
      Browse the orq.ai model catalog: every model orq offers, across every
      provider, with pricing, capabilities and benchmark data. List endpoints
      only return models that are not deprecated. This API is public, requires
      no authentication, and is rate limited to 120 requests per minute per IP.
      Responses carry a 5-minute cache-control max-age.
  - name: Notifiers
    description: Notifier destinations used to send delivery and workflow notifications.
  - name: Projects
    description: Projects organize resources within a workspace
  - name: Routing Rules
    description: >-
      Routing Rules conditionally select models and enforce request plugins for
      AI Gateway traffic. Rules are evaluated by ascending priority and may be
      scoped to a project or the whole workspace.
  - name: Threads
    description: Threads group related trace invocations and their aggregate usage
  - name: Skills
    description: >-
      Skills are modular instructions you can use to codify processes and
      conventions
  - name: Smart Routers
    description: >-
      Create and manage workspace Smart Routers. A Smart Router selects a model
      from an eligible pool for each request according to a quality, balanced,
      or cost profile.
  - name: Webhooks
    description: >-
      Create and manage webhooks that deliver workspace events to external HTTPS
      endpoints.
  - name: Workspaces
    description: >-
      A workspace is the tenant. Create is called from a user session during
      onboarding; Get, List, and Update are the public management surface.
  - name: Workspace Security
    description: >-
      Workspace-level domain verification and IP allowlist controls. These
      operations are restricted to workspace administrators.
  - name: Workspace Settings
    description: >-
      Workspace-level settings managed with a workspace credential. A workspace
      is the tenant, so these settings are a singleton — there is nothing to
      create or delete, only read and update.
  - name: Responses
  - description: Run agents on a cron cadence. Minimum firing interval is 1 hour.
    name: Agent Schedules
  - name: Embeddings
  - name: Telemetry
    description: >-
      Unified query envelope for traces, metrics, and logs. One request shape,
      one filter dialect, and one response shape per source, validated by a
      per-source registry.
  - description: Beta. Run typed classification questions against a classify model.
    name: Classify
  - description: Search Gateway with managed credits or BYOK.
    name: Web Search
externalDocs:
  url: https://docs.orq.ai
  description: orq.ai Documentation
paths:
  /v2/identities:
    get:
      tags:
        - Identities
      summary: List identities
      description: >-
        Retrieves a paginated list of identities in your workspace. Use
        pagination parameters to navigate through large identity lists
        efficiently.
      operationId: ListIdentities
      parameters:
        - name: limit
          in: query
          schema:
            type: integer
            format: int32
        - name: starting_after
          in: query
          description: >-
            Cursor for forward pagination. Set to the `_id` of the last item
            from
             the previous page.
          schema:
            type: string
        - name: ending_before
          in: query
          description: >-
            Cursor for backward pagination. Set to the `_id` of the first item
            from
             the previous page.
          schema:
            type: string
        - name: search
          in: query
          description: >-
            Case-insensitive search text matched against identity profile
            fields.
          schema:
            type: string
        - name: filter_by.tags
          in: query
          description: Return only identities that have at least one of these tags.
          schema:
            type: array
            items:
              type: string
        - name: include_metrics
          in: query
          description: Include aggregate usage metrics on each returned identity.
          schema:
            type: boolean
        - name: sort_by
          in: query
          description: Field used to order the list.
          schema:
            $ref: '#/components/schemas/IdentitySortField'
        - name: include_budget
          in: query
          description: |-
            When true, embed each identity's identity-scoped budget (config and
             limits only, no live usage) on the returned records. Adds one budget
             lookup for the page; omit to skip it.
          schema:
            type: boolean
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListIdentitiesResponse'
      x-code-samples:
        - lang: curl
          label: Core - List identities by tag
          source: |
            curl --get 'https://my.orq.ai/v2/identities' \
              --header "Authorization: Bearer $ORQ_API_KEY" \
              --data-urlencode 'limit=25' \
              --data-urlencode 'search=acme' \
              --data-urlencode 'filter_by.tags=enterprise' \
              --data-urlencode 'include_metrics=true'
        - lang: python
          label: Python - List identities by tag
          source: |
            import os
            from orq_ai_sdk import Orq

            client = Orq(api_key=os.environ["ORQ_API_KEY"])

            page = client.identities.list(
                limit=25,
                search="acme",
                filter_by={"tags": ["enterprise"]},
                include_metrics=True,
            )

            for identity in page.data:
                print(identity.external_id, identity.display_name)
        - lang: typescript
          label: Node.js - List identities by tag
          source: |
            import { Orq } from '@orq-ai/node';

            const client = new Orq({
              apiKey: process.env.ORQ_API_KEY,
            });

            const page = await client.identities.list({
              limit: 25,
              search: 'acme',
              filterBy: {
                tags: ['enterprise'],
              },
              includeMetrics: true,
            });

            for (const identity of page.data) {
              console.log(identity.externalId, identity.displayName);
            }
components:
  schemas:
    IdentitySortField:
      type: string
      enum:
        - IDENTITY_SORT_FIELD_UNSPECIFIED
        - IDENTITY_SORT_FIELD_DISPLAY_NAME
        - IDENTITY_SORT_FIELD_UPDATED
    ListIdentitiesResponse:
      required:
        - object
        - data
        - has_more
      type: object
      properties:
        object:
          type: string
          description: Object discriminator for list responses; always `list`.
        data:
          type: array
          items:
            $ref: '#/components/schemas/Identity'
          description: Page of identities.
        has_more:
          type: boolean
          description: |-
            Whether more identities are available in the selected pagination
             direction.
    Identity:
      required:
        - _id
        - external_id
        - workspace_id
        - created
        - updated
      type: object
      properties:
        _id:
          type: string
          description: |-
            Unique identity identifier assigned by ORQ. Returned as `_id` for
             compatibility with the v1 identity API.
        external_id:
          type: string
          description: |-
            Customer-provided stable identifier for this identity. This value is
             required on create and is unique within the workspace.
        workspace_id:
          type: string
          description: Workspace that owns the identity.
        display_name:
          type: string
          description: Human-readable display name for the identity.
        email:
          type: string
          description: Email address associated with the identity.
        avatar_url:
          type: string
          description: URL of the identity avatar image.
        tags:
          type: array
          items:
            type: string
          description: Free-form labels used to organize and filter identities.
        metadata:
          type: object
          additionalProperties: true
          description: Custom JSON metadata stored with the identity.
        created:
          type: string
          description: ISO timestamp for when the identity was created.
        updated:
          type: string
          description: ISO timestamp for when the identity was last updated.
        metrics:
          allOf:
            - $ref: '#/components/schemas/IdentityMetrics'
          description: |-
            Optional usage and cost metrics. Present only when requested with
             `include_metrics`.
        budget:
          readOnly: true
          allOf:
            - $ref: '#/components/schemas/Budget'
          description: |-
            The budget scoped to this identity, if one exists. Read-only here:
             budgets are created and managed through the Budgets API
             (scope.identity). Present only when requested with `include_budget`.
             Live consumption (`usage`) is not attached on this path — call the
             Budgets API for current spend.
    IdentityMetrics:
      required:
        - total_tokens
        - total_cost
        - total_requests
        - error_rate
      type: object
      properties:
        total_tokens:
          type: number
          description: Total token count attributed to the identity.
          format: double
        total_cost:
          type: number
          description: Total cost attributed to the identity.
          format: double
        total_requests:
          type: number
          description: Total request count attributed to the identity.
          format: double
        error_rate:
          type: number
          description: Fraction of attributed requests that failed.
          format: double
    Budget:
      required:
        - budget_id
        - limits
        - created_at
        - updated_at
      type: object
      properties:
        budget_id:
          type: string
        scope:
          allOf:
            - $ref: '#/components/schemas/BudgetScope'
          description: >-
            Scope the budget was created for, used to group and filter budgets
            in
             the console. Not used for matching: the `match` expression decides
             which requests a budget applies to. Unset for budgets created from a
             raw CEL expression ("custom").
        match:
          allOf:
            - $ref: '#/components/schemas/BudgetMatch'
          description: |-
            The matching semantics of the budget. A budget applies to a request
             when `match.cel` evaluates to true against the request context.
             Creating a budget for a scope derives the expression for that scope
             (e.g. `provider == "openai"`); an empty expression matches every
             request in the workspace.
        limits:
          $ref: '#/components/schemas/BudgetLimits'
        rate_limit:
          $ref: '#/components/schemas/RateLimit'
        is_active:
          type: boolean
        expires_at:
          type: string
          format: date-time
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
        usage:
          allOf:
            - $ref: '#/components/schemas/BudgetUsage'
          description: |-
            Latest available consumption used for enforcement in the current
             period. This is not an exact billing ledger. Populated by read paths
             (Get / List); omitted on write responses (Create / Update / Reset)
             where it carries no signal. Absent or all-zero for a budget that
             has not been spent against in the current period.
        alerts:
          type: array
          items:
            $ref: '#/components/schemas/BudgetAlert'
          description: Threshold notifications. Absent when the budget has none.
      description: Budget defines limits and matching rules used to govern consumption.
    BudgetScope:
      type: object
      properties:
        workspace:
          $ref: '#/components/schemas/WorkspaceBudgetScope'
        project:
          $ref: '#/components/schemas/ProjectBudgetScope'
        identity:
          $ref: '#/components/schemas/IdentityBudgetScope'
        api_key:
          $ref: '#/components/schemas/ApiKeyBudgetScope'
        provider:
          $ref: '#/components/schemas/ProviderBudgetScope'
        model:
          $ref: '#/components/schemas/ModelBudgetScope'
      description: >-
        Closed oneof of workspace, project, identity, api_key, provider, or
        model. Exactly one variant must be set. Variants are ordered by
        enforcement precedence (most specific to most general).
    BudgetMatch:
      type: object
      properties:
        cel:
          type: string
      description: >-
        CEL expression that decides whether a budget applies to a request.
        Available variables: `model`, `provider`, `model_id`, `api_key`,
        `api_key_labels` (map), `identity`, `project`, `metadata` (map),
        `headers` (map, lowercase keys). An empty expression always matches.
        Expressions are syntax-validated at write time.
    BudgetLimits:
      type: object
      properties:
        period:
          $ref: '#/components/schemas/BudgetPeriod'
        amount:
          type: number
          format: double
        token_limit:
          type: number
          description: |-
            Token ceiling for the budget period. Token counts are whole numbers
             and stored as integers.
          format: double
      description: |-
        BudgetLimits is the per-period spend and token ceiling. At least one
         of `amount`, `token_limit`, or RateLimit.requests_per_minute MUST be
         set on a Budget; that invariant is enforced by the handler.
    RateLimit:
      type: object
      properties:
        requests_per_minute:
          type: integer
          format: int32
      description: |-
        Per-minute request ceiling applied to the requests this budget
         matches.
    BudgetUsage:
      type: object
      properties:
        amount:
          type: number
          format: double
        tokens:
          type: number
          description: |-
            Carried as a double (not int64) so it serializes as a JSON number
             rather than a quoted string, matching limits.token_limit.
          format: double
        requests:
          type: integer
          format: int32
      description: |-
        BudgetUsage is the latest available current-period consumption used
         for budget enforcement, not an exact billing ledger. Each dimension is
         the consumed side of the matching limit dimension: `amount` is the
         accumulated cost in USD (vs limits.amount), `tokens` is the accumulated
         token count (vs limits.token_limit), and `requests` is the count in the
         rolling 60-second window (vs rate_limit.requests_per_minute). All three
         are explicit-presence so the triple is always emitted in full, zeros
         included — a never-spent budget serializes {amount:0, tokens:0,
         requests:0} rather than dropping its zero dimensions.
    BudgetAlert:
      required:
        - threshold_percent
        - notifier_ids
      type: object
      properties:
        id:
          type: string
          description: Assigned by ORQ. Supply an existing id to edit that alert in place.
        threshold_percent:
          type: integer
          description: Percentage of the dimension's limit at which the alert fires, 1–100.
          format: uint32
        notifier_ids:
          type: array
          items:
            type: string
          description: Must be workspace-scoped; project-scoped notifiers are rejected.
        dimension:
          $ref: '#/components/schemas/BudgetAlertDimension'
          description: Defaults to COST when unset.
      description: |-
        Notifies every listed notifier once current-period consumption on
         `dimension` reaches `threshold_percent` of the matching limit. Each alert
         fires at most once per period, re-arming on rollover or a limit change.
         The dimension must have a limit set, or the write is rejected.
    WorkspaceBudgetScope:
      type: object
      properties: {}
      description: Workspace-wide ceiling. The implicit target is the caller's workspace.
    ProjectBudgetScope:
      type: object
      properties:
        project_id:
          type: string
      description: Per-project cap.
    IdentityBudgetScope:
      type: object
      properties:
        identity_external_id:
          type: string
      description: |-
        Per-identity cap. Keyed by the contact's external identifier so the
         scope is stable across imports.
    ApiKeyBudgetScope:
      type: object
      properties:
        api_key_id:
          type: string
      description: |-
        Per-api-key cap. Replaces the legacy embedded `constraints.budget`
         associated with an API key.
    ProviderBudgetScope:
      type: object
      properties:
        provider:
          type: string
      description: |-
        Per-provider cap. The value is the provider enum string (e.g.
         "openai", "anthropic") drawn from ModelIntegrationIdentifier.
    ModelBudgetScope:
      required:
        - model_id
      type: object
      properties:
        model_id:
          type: string
      description: |-
        Per-model cap. The value is the FULL model reference as callers send
         it ("openai/gpt-4o", or "workspaceKey@openai/gpt-4o" for private
         models).
    BudgetPeriod:
      type: string
      enum:
        - BUDGET_PERIOD_UNSPECIFIED
        - BUDGET_PERIOD_DAILY
        - BUDGET_PERIOD_WEEKLY
        - BUDGET_PERIOD_MONTHLY
        - BUDGET_PERIOD_YEARLY
        - BUDGET_PERIOD_ONE_TIME
    BudgetAlertDimension:
      type: string
      enum:
        - BUDGET_ALERT_DIMENSION_UNSPECIFIED
        - BUDGET_ALERT_DIMENSION_COST
        - BUDGET_ALERT_DIMENSION_TOKENS
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: JWT

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.