filescom-users

SkillFiles & storage

A User represents a human or system/service user with the ability to connect to Files.com via any of the available connectivity methods (unless restricted to specific protocols). Pick `--authentication-method` carefully at creation. Each method behaves differently: `email_signup` mails a "set your password" link; `password` requires the admin to set one upfront; `sso` defers authentication to a configured SSO strategy; `none` allows only API key or SSH key login.

Use filescom-users in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add filescom-users and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the filescom-users skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

filescom-usersStart free

What this skill tells your AI

The instructions your AI receives, as published by files-com/files-cli in skills/filescom-users/SKILL.md and read by Ahel’s review.

A User represents a human or system/service user with the ability to connect to Files.com via any of the available connectivity methods (unless restricted to specific protocols).

Users are associated with API Keys, SSH (SFTP) Keys, Notifications, Permissions, and Group memberships.

Authentication

The authentication_method property on a User determines exactly how that user can login and authenticate to their Files.com account. Files.com offers a variety of authentication methods to ensure flexibility, security, migration, and compliance.

These authentication methods can be configured during user creation and can be modified at any time by site administrators. The meanings of the available values are as follows:

  • password - Allows authentication via a password. If API Keys or SSH (SFTP) Keys are also configured, those can be used instead of the password. If Two Factor Authentication (2FA) methods are also configured, a valid 2nd factor is required in addition to the password.
  • email_signup - When set upon user creation, an email will be sent to the new user with a link for them to create their password. Once the user has created their password, their authentication type will change to password.
  • sso - Allows authentication via a linked Single Sign On provider. If API Keys or SSH (SFTP) Keys are also configured, those can be used instead of Single Sign On. If Two Factor Authentication (2FA) methods are also configured, a valid 2nd factor is required in addition to Single Sign On. When using this method, you must also provide a valid sso_strategy_id to associate the User to the appropriate SSO provider.
  • password_with_imported_hash - Works like the password method but allows importing a hashed password in MD5, SHA-1, or SHA-256 format. Provide the imported hash in the field imported_password_hash. Upon first use, the password will be converted to Files.com's internal storage format and the authentication type will change to password. Typically only used when migrating to Files.com from another MFT solution.
  • none - Does not allow authentication via username and password, but does allow authentication via API Key or SSH (SFTP) Key. Typically only used for service users.
  • password_and_ssh_key - Allows authentication only by providing a password and also a valid SSH (SFTP) Key in a single attempt. If API Keys are also configured, those can be used instead of the password and key combination. This method only works with (typically enterprise) SSH/SFTP clients capable of sending both authentication methods at once. Typically only used for service users.

All subcommands also accept the flags documented in CONTEXT.md (--api-key, --format, --workspace-id, --debug, and the pagination flags --cursor / --per-page / --max-pages on list). Those are not repeated below.

Commands

files-cli users list

List Users.

FlagTypeDescription
--sort-byobjectIf set, sort records by the specified field in either asc or desc direction. Valid fields are site_id, workspace_id, company, name, disabled, authenticate_until, username, email, site_admin, last_desktop_login_at, last_login_at, password_validity_days or ssl_required.
--filterobjectIf set, return records where the specified field is equal to the supplied value. Valid fields are username, name, email, company, site_admin, password_validity_days, ssl_required, last_login_at, authenticate_until, not_site_admin, disabled, partner_id, primary_group_id or workspace_id. Valid field combinations are [ site_admin, username ], [ not_site_admin, username ], [ workspace_id, username ], [ company, name ], [ workspace_id, name ], [ workspace_id, email ], [ workspace_id, company ], [ workspace_id, site_admin ], [ workspace_id, not_site_admin ], [ workspace_id, disabled ], [ workspace_id, partner_id ], [ workspace_id, site_admin, username ], [ workspace_id, not_site_admin, username ], [ workspace_id, disabled, username ], [ workspace_id, partner_id, username ] or [ workspace_id, company, name ].
--filter-gtobjectIf set, return records where the specified field is greater than the supplied value. Valid fields are password_validity_days, last_login_at or authenticate_until.
--filter-gteqobjectIf set, return records where the specified field is greater than or equal the supplied value. Valid fields are password_validity_days, last_login_at or authenticate_until.
--filter-prefixobjectIf set, return records where the specified field is prefixed by the supplied value. Valid fields are username, name, email or company. Valid field combinations are [ company, name ].
--filter-ltobjectIf set, return records where the specified field is less than the supplied value. Valid fields are password_validity_days, last_login_at or authenticate_until.
--filter-lteqobjectIf set, return records where the specified field is less than or equal the supplied value. Valid fields are password_validity_days, last_login_at or authenticate_until.
--idsstringcomma-separated list of User IDs
--include-parent-site-usersboolInclude users from the parent site.
--searchstringSearches for partial matches of name, username, or email.

files-cli users find

Show User.

FlagTypeDescription
--idint64User ID. Required.

files-cli users create

Create User.

FlagTypeDescription
--avatar-filefileAn image file for your user avatar.
--avatar-deleteboolIf true, the avatar will be deleted.
--change-passwordstringUsed for changing a password on an existing user.
--change-password-confirmationstringOptional, but if provided, we will ensure that it matches the value sent in change_password.
--emailstringUser's email.
--grant-permissionstringPermission to grant on the User Root upon user creation. Can be blank or full, read, write, list, read+write, or list+write
--group-idint64Group ID to associate this user with.
--group-idsstringA list of group ids to associate this user with. Comma delimited.
--imported-password-hashstringPre-calculated hash of the user's password. If supplied, this will be used to authenticate the user on first login. Supported hash methods are MD5, SHA1, and SHA256.
--passwordstringUser password.
--password-confirmationstringOptional, but if provided, we will ensure that it matches the value sent in password.
--announcements-readboolSignifies that the user has read all the announcements in the UI.
--ai-assistant-personality-idint64AI Assistant Personality ID assigned directly to this user, if any.
--allowed-ipsstringA list of allowed IPs if applicable. Newline delimited
--attachments-permissionboolDEPRECATED: If true, the user can user create Bundles (aka Share Links). Use the bundle permission instead.
--authenticate-untildatetimeScheduled Date/Time at which user will be deactivated
--authentication-methodenumHow is this user authenticated?. One of: password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key.
--billing-permissionboolAllow this user to perform operations on the account, payments, and invoices?
--bypass-user-lifecycle-rulesboolExempt this user from user lifecycle rules?
--bypass-site-allowed-ipsboolAllow this user to skip site-wide IP blacklists?
--dav-permissionboolCan the user connect with WebDAV?
--desktop-configuration-profile-idint64Desktop Configuration Profile ID assigned directly to this user, if any.
--default-workspace-idint64Workspace ID the user should land in by default when more than one Workspace is available.
--disabledboolIs user disabled? Disabled users cannot log in, and do not count for billing purposes. Users can be automatically disabled after an inactivity period via a Site setting or schedule to be deactivated after specific date.
--filesystem-layoutenumFile system layout. One of: site_root, user_root, partner_root, integration_centric, workspace_root.
--ftp-permissionboolCan the user access with FTP/FTPS?
--header-textstringText to display to the user in the header of the UI
--integration-centric-profile-idint64Integration Centric Profile ID assigned directly to this user, if any.
--languagestringPreferred language
--notification-daily-send-timeint64Hour of the day at which daily notifications should be sent. Can be in range 0 to 23
--namestringUser's full name
--companystringUser's company
--notesstringAny internal notes on the user
--office-integration-enabledboolEnable integration with Office for the web?
--partner-adminboolIs this user a Partner administrator?
--partner-idint64Partner ID if this user belongs to a Partner
--password-validity-daysint64Number of days to allow user to use the same password
--primary-group-idint64Primary group ID for Group Admin scoping
--readonly-site-adminboolIs the user an allowed to view all (non-billing) site configuration for this site?
--receive-admin-alertsboolDeprecated. Use notify_on_all_site_warnings and granular failure notification preferences instead.
--notify-on-all-site-warningsboolShould the user receive site warnings via email?
--notify-on-all-sso-failuresboolShould the user receive sso/scim/ldap configuration/sync failures via email?
--notify-on-all-user-security-eventsboolShould the user receive user security events via email?
--notify-on-all-pending-work-failuresboolShould the user receive pending work failures via email?
--notify-on-all-siem-http-destination-failuresboolShould the user receive siem failures via email?
--notify-on-all-sync-failuresboolShould the user receive sync failures via email?
--notify-on-all-automation-failuresboolShould the user receive automation failures via email?
--notify-on-all-expectation-failuresboolShould the user receive expectation failures and misses via email?
--require-login-bydatetimeRequire user to login by specified date otherwise it will be disabled.
--require-password-changeboolIs a password change required upon next user login?
--responsible-group-idint64ID of the internal Group responsible for this Partner User, overriding the Partner default.
--responsible-user-idint64ID of the internal User responsible for this Partner User, overriding the Partner default.
--restapi-permissionboolCan this user access the Web app, Desktop app, SDKs, or REST API? (All of these tools use the API internally, so this is one unified permission set.)
--s3-compatible-endpoint-permissionboolCan the user access the S3-compatible endpoint? Defaults to true.
--self-managedboolDoes this user manage it's own credentials or is it a shared/bot user?
--sftp-permissionboolCan the user access with SFTP?
--site-adminboolIs the user an administrator for this site?
--skip-welcome-screenboolSkip Welcome page in the UI?
--ssl-requiredenumSSL required setting. One of: use_system_setting, always_require, never_require.
--sso-strategy-idint64SSO (Single Sign On) strategy ID for the user, if applicable.
--subscribe-to-newsletterboolIs the user subscribed to the newsletter?
--require-2faenum2FA required setting. use_system_setting uses the site-wide setting, including SSO exemptions. always_require and never_require override the site-wide setting when user-level overrides are allowed. One of: use_system_setting, always_require, never_require.
--tagsstringComma-separated list of Tags for this user. Tags are used for other features, such as UserLifecycleRules, which can target specific tags. Tags must only contain lowercase letters, numbers, and hyphens.
--time-zonestringUser time zone
--user-rootstringIf filesystem layout is user_root, this path is the root path the user is fixed to for all interfaces. If the filesystem layout is site_root or partner_root, this acts as a root folder only for FTP and SFTP (SFTP applicability also requires a site-wide setting to be set). For partner_root layout, this path is relative to the Partner root folder for all callers and blank opts out of an additional protocol root. In this situation, this path is not applied to the API, Desktop, or Web interface.
--user-homestringHome folder for FTP/SFTP. For users with the partner_root filesystem layout, this path is relative to the Partner root folder. In all other cases, it is an absolute path. Only applies to FTP and SFTP, and not any other interface.
--workspace-adminboolWhether the user is an administrator of their own Custom Workspace. Does not reflect administration granted through Permissions.
--usernamestringUser's username Required.
--workspace-idint64ID of the Workspace the user belongs to. 0 is the Default Workspace.

files-cli users unlock

Unlock user who has been locked out due to failed logins.

FlagTypeDescription
--idint64User ID. Required.

files-cli users resend-welcome-email

Resend user welcome email.

FlagTypeDescription
--idint64User ID. Required.

files-cli users user-2fa-reset

Trigger 2FA Reset process for user who has lost access to their existing 2FA methods.

FlagTypeDescription
--idint64User ID. Required.

files-cli users update

Update User.

FlagTypeDescription
--idint64User ID. Required.
--avatar-filefileAn image file for your user avatar.
--avatar-deleteboolIf true, the avatar will be deleted.
--change-passwordstringUsed for changing a password on an existing user.
--change-password-confirmationstringOptional, but if provided, we will ensure that it matches the value sent in change_password.
--emailstringUser's email.
--grant-permissionstringPermission to grant on the User Root upon user creation. Can be blank or full, read, write, list, read+write, or list+write
--group-idint64Group ID to associate this user with.
--group-idsstringA list of group ids to associate this user with. Comma delimited.
--imported-password-hashstringPre-calculated hash of the user's password. If supplied, this will be used to authenticate the user on first login. Supported hash methods are MD5, SHA1, and SHA256.
--passwordstringUser password.
--password-confirmationstringOptional, but if provided, we will ensure that it matches the value sent in password.
--announcements-readboolSignifies that the user has read all the announcements in the UI.
--ai-assistant-personality-idint64AI Assistant Personality ID assigned directly to this user, if any.
--allowed-ipsstringA list of allowed IPs if applicable. Newline delimited
--attachments-permissionboolDEPRECATED: If true, the user can user create Bundles (aka Share Links). Use the bundle permission instead.
--authenticate-untildatetimeScheduled Date/Time at which user will be deactivated
--authentication-methodenumHow is this user authenticated?. One of: password, sso, none, email_signup, password_with_imported_hash, password_and_ssh_key.
--billing-permissionboolAllow this user to perform operations on the account, payments, and invoices?
--bypass-user-lifecycle-rulesboolExempt this user from user lifecycle rules?
--bypass-site-allowed-ipsboolAllow this user to skip site-wide IP blacklists?
--dav-permissionboolCan the user connect with WebDAV?
--desktop-configuration-profile-idint64Desktop Configuration Profile ID assigned directly to this user, if any.
--default-workspace-idint64Workspace ID the user should land in by default when more than one Workspace is available.
--disabledboolIs user disabled? Disabled users cannot log in, and do not count for billing purposes. Users can be automatically disabled after an inactivity period via a Site setting or schedule to be deactivated after specific date.
--filesystem-layoutenumFile system layout. One of: site_root, user_root, partner_root, integration_centric, workspace_root.
--ftp-permissionboolCan the user access with FTP/FTPS?
--header-textstringText to display to the user in the header of the UI
--integration-centric-profile-idint64Integration Centric Profile ID assigned directly to this user, if any.
--languagestringPreferred language
--notification-daily-send-timeint64Hour of the day at which daily notifications should be sent. Can be in range 0 to 23
--namestringUser's full name
--companystringUser's company
--notesstringAny internal notes on the user
--office-integration-enabledboolEnable integration with Office for the web?
--partner-adminboolIs this user a Partner administrator?
--partner-idint64Partner ID if this user belongs to a Partner
--password-validity-daysint64Number of days to allow user to use the same password
--primary-group-idint64Primary group ID for Group Admin scoping
--readonly-site-adminboolIs the user an allowed to view all (non-billing) site configuration for this site?
--receive-admin-alertsboolDeprecated. Use notify_on_all_site_warnings and granular failure notification preferences instead.
--notify-on-all-site-warningsboolShould the user receive site warnings via email?
--notify-on-all-sso-failuresboolShould the user receive sso/scim/ldap configuration/sync failures via email?
--notify-on-all-user-security-eventsboolShould the user receive user security events via email?
--notify-on-all-pending-work-failuresboolShould the user receive pending work failures via email?
--notify-on-all-siem-http-destination-failuresboolShould the user receive siem failures via email?
--notify-on-all-sync-failuresboolShould the user receive sync failures via email?
--notify-on-all-automation-failuresboolShould the user receive automation failures via email?
--notify-on-all-expectation-failuresboolShould the user receive expectation failures and misses via email?
--require-login-bydatetimeRequire user to login by specified date otherwise it will be disabled.
--require-password-changeboolIs a password change required upon next user login?
--responsible-group-idint64ID of the internal Group responsible for this Partner User, overriding the Partner default.
--responsible-user-idint64ID of the internal User responsible for this Partner User, overriding the Partner default.
--restapi-permissionboolCan this user access the Web app, Desktop app, SDKs, or REST API? (All of these tools use the API internally, so this is one unified permission set.)
--s3-compatible-endpoint-permissionboolCan the user access the S3-compatible endpoint? Defaults to true.
--self-managedboolDoes this user manage it's own credentials or is it a shared/bot user?
--sftp-permissionboolCan the user access with SFTP?
--site-adminboolIs the user an administrator for this site?
--skip-welcome-screenboolSkip Welcome page in the UI?
--ssl-requiredenumSSL required setting. One of: use_system_setting, always_require, never_require.
--sso-strategy-idint64SSO (Single Sign On) strategy ID for the user, if applicable.
--subscribe-to-newsletterboolIs the user subscribed to the newsletter?
--require-2faenum2FA required setting. use_system_setting uses the site-wide setting, including SSO exemptions. always_require and never_require override the site-wide setting when user-level overrides are allowed. One of: use_system_setting, always_require, never_require.
--tagsstringComma-separated list of Tags for this user. Tags are used for other features, such as UserLifecycleRules, which can target specific tags. Tags must only contain lowercase letters, numbers, and hyphens.
--time-zonestringUser time zone
--user-rootstringIf filesystem layout is user_root, this path is the root path the user is fixed to for all interfaces. If the filesystem layout is site_root or partner_root, this acts as a root folder only for FTP and SFTP (SFTP applicability also requires a site-wide setting to be set). For partner_root layout, this path is relative to the Partner root folder for all callers and blank opts out of an additional protocol root. In this situation, this path is not applied to the API, Desktop, or Web interface.
--user-homestringHome folder for FTP/SFTP. For users with the partner_root filesystem layout, this path is relative to the Partner root folder. In all other cases, it is an absolute path. Only applies to FTP and SFTP, and not any other interface.
--workspace-adminboolWhether the user is an administrator of their own Custom Workspace. Does not reflect administration granted through Permissions.
--usernamestringUser's username
--workspace-idint64Workspace ID. Only Site Administrators can change this field. Values supplied by Workspace Administrators, Group Administrators, or other non-Site Administrators using /user are ignored.
--clear-2faboolIf true when changing authentication_method from password to sso, remove all two-factor methods. Ignored in all other cases.
--convert-to-partner-userboolRequired when assigning a Partner to an existing non-Partner user. If true, convert the user by assigning the partner_id provided.

files-cli users delete

Delete User.

FlagTypeDescription
--idint64User ID. Required.
--new-owner-idint64Provide a User ID here to transfer ownership of certain resources such as Automations and Share Links (Bundles) to that new user.

Limitations and considerations

Authentication method determines how the user signs in. The --authentication-method flag accepts these values:

Shortened here. Read the whole file on GitHub.

Signals

GitHub stars
46
Forks
4
Last commit
Oct 2026
Advanced
Item type
skill
Key
filescom-users
Source
github.com/files-com/files-cli