> ## Documentation Index
> Fetch the complete documentation index at: https://docs.brand-wallet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# The User Object

> The shape of a BrandWallet user record as returned by the user endpoints.

**A user is a member of the merchant organization's team — an account owner, brand manager, branch manager, or cashier — or an API account acting on the organization's behalf. Users operate the business; they are not the shoppers. The end consumer who collects loyalty rewards is a [Customer](/api/customer-object). All user endpoints return this same record.**

Object schema:

```json theme={null}
{
  "id": "fa000708-10f6-47ea-a35d-d3e1acbd4be5",
  "fullname": "Jane Cashier",
  "email": "jane@example.com",
  "phone": "+905321112233",                                   // optional
  "status": 1,
  "organization": "ca5495d7-36ee-4f6d-8149-0dd082f7c745",
  "branch": "377ec3ad-28c8-4008-b3df-005a434dcf8b",           // optional
  "authBranches": ["377ec3ad-28c8-4008-b3df-005a434dcf8b"],   // optional
  "roles": [
    { "id": "e5e94c4a-7ab7-4568-bf5d-4ea61c2300af", "code": "branch_user", "name": "Branch User" }
  ],
  "opaqueId": "pos-user-7",                                   // optional — your own user id
  "createdAt": "2026-10-06T12:31:34.711Z",
  "updatedAt": "2026-10-06T12:32:10.618Z"
}
```

### Fields

| Field | Type | Description |
| - | - | - |
| `id` | string | Unique user id (UUID). Used on all user endpoints. |
| `fullname` | string | The user's display name. |
| `email` | string | Sign-in identifier; globally unique across BrandWallet. |
| `phone` | string | E.164 phone number. |
| `status` | number | Record status code (`1` = active, `-99` = deleted — see [delete](/api/delete-user)). |
| `organization` | string | Id of the organization the user belongs to — always your access token's organization. |
| `branch` | string | Id of the branch the user is assigned to. |
| `authBranches` | string\[] | Ids of the branches the user is authorized to operate in. |
| `roles` | array | The user's public-facing roles as `{id, code, name}`. Integrations can assign only the branch-level codes `branch_user` and `branch_manager` — see [create](/api/create-user). Not included in the [delete](/api/delete-user) response. |
| `opaqueId` | string | Your own system's user id. |
| `createdAt` / `updatedAt` | string | ISO 8601 timestamps. |

Notes:

* Optional fields that have no value (`phone`, `branch`, `authBranches`, `opaqueId`) are omitted from responses — you will not receive `null`.
* `organization`, `branch` and `authBranches` are plain id strings.
* `roles` contains only public-facing roles; internal system roles are not listed, so an empty `roles` array does not mean the user has no role.
* Credentials (`password`) and internal account settings are never returned by any endpoint.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.