Skip to content

Enterprise users

Enterprise users are the accounts a top-level group owns, typically because their email domain is verified for the group. These actions list and read them, disable a user’s two-factor authentication, and delete one.

  • “List the enterprise users of group acme”
  • “Disable two-factor authentication for enterprise user 42”
  • “Show the enterprise user alice”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as enterprise_user.delete, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_enterprise_user with action set to the action’s name, such as delete, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_delete_enterprise_user, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 4:

  • Free: 0
  • Premium: 4
  • Ultimate: 4

Listed only for a token that carries admin_mode: the server removes the group from every surface for a token whose scopes it knows and that lacks it.

Read-only actions: 2 of 4, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
enterprise_user.deletegitlab_delete_enterprise_user
enterprise_user.disable_2fagitlab_disable_2fa_enterprise_user
enterprise_user.getgitlab_get_enterprise_user
enterprise_user.listgitlab_list_enterprise_users

Delete an enterprise user, optionally with hard_delete. Returns: a success confirmation naming the user and group. See also: enterprise_user.get, enterprise_user.list, enterprise_user.disable_2fa.

  • Meta-tool: gitlab_enterprise_user, action delete
  • Individual tool: gitlab_delete_enterprise_user
  • Tier: Premium
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
user_idintegeryesUser ID
hard_deletebooleannoPermanently delete user instead of soft delete

Disable two-factor authentication for an enterprise user. Returns: a success confirmation naming the user and group. See also: enterprise_user.get, enterprise_user.list, enterprise_user.delete.

  • Meta-tool: gitlab_enterprise_user, action disable_2fa
  • Individual tool: gitlab_disable_2fa_enterprise_user
  • Tier: Premium
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
user_idintegeryesUser ID

Get a single enterprise user by group_id and user_id. Returns: the full user profile (identities, SCIM identities, custom attributes, sign-in metadata, admin/auditor flags, license seat usage, and web URL). See also: enterprise_user.list, enterprise_user.disable_2fa, enterprise_user.delete.

  • Meta-tool: gitlab_enterprise_user, action get
  • Individual tool: gitlab_get_enterprise_user
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
user_idintegeryesUser ID

List enterprise users for a top-level group with filtering and pagination. Returns: enterprise users with full profile fields (identities, SCIM identities, custom attributes, sign-in metadata, license seat usage) and pagination metadata. See also: enterprise_user.get, enterprise_user.disable_2fa, enterprise_user.delete.

  • Meta-tool: gitlab_enterprise_user, action list
  • Individual tool: gitlab_list_enterprise_users
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
activebooleannoFilter for active users only
blockedbooleannoFilter for blocked users only
created_afterstringnoFilter users created after this date (ISO 8601)
created_beforestringnoFilter users created before this date (ISO 8601)
order_bystringnoColumn to order keyset-paginated results by (e.g. id)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
searchstringnoSearch by name or username or email
sortstring (asc, desc)noSort order for keyset pagination: asc or desc
two_factorstring (enabled, disabled)noFilter by 2FA status: enabled or disabled
usernamestringnoFilter by exact username