Changelog2025
Restricting Access to Email Addresses in the `/v1/meta/users/` Endpoint to Admin Users Only
Previously, any user who could create an API key could retrieve the email addresses of all users in their organization, including inactive users, regardless of their assigned permissions. We introduced a resource permission check to ensure that only admin users can access email addresses via the API.
Impact:
- Non-admin users are no longer able to retrieve email addresses from the
/v1/meta/users/endpoint. - Admin users continue to have access to this data.
We recommend reviewing your API usage to ensure that any integrations relying on email addresses from this endpoint are being accessed by an admin user.