Enterprise users
Enterprise users are the accounts a top-level group owns, typically because their email domain is verified for the group. These actions list and read them, disable a user’s two-factor authentication, and delete one.
Sample questions
Section titled “Sample questions”- “List the enterprise users of group acme”
- “Disable two-factor authentication for enterprise user 42”
- “Show the enterprise user alice”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such asenterprise_user.delete, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_enterprise_userwithactionset to the action’s name, such asdelete, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_delete_enterprise_user, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 4:
- Free: 0
- Premium: 4
- Ultimate: 4
Listed only for a token that carries admin_mode: the server removes the group from every surface for a token whose scopes it knows and that lacks it.
Read-only actions: 2 of 4, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).
| Action | Individual |
|---|---|
enterprise_user.delete | gitlab_delete_enterprise_user |
enterprise_user.disable_2fa | gitlab_disable_2fa_enterprise_user |
enterprise_user.get | gitlab_get_enterprise_user |
enterprise_user.list | gitlab_list_enterprise_users |
enterprise_user.delete
Section titled “enterprise_user.delete”Delete an enterprise user, optionally with hard_delete. Returns: a success confirmation naming the user and group. See also:
enterprise_user.get,enterprise_user.list,enterprise_user.disable_2fa.
- Meta-tool:
gitlab_enterprise_user, actiondelete - Individual tool:
gitlab_delete_enterprise_user - Tier: Premium
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
user_id | integer | yes | User ID |
hard_delete | boolean | no | Permanently delete user instead of soft delete |
enterprise_user.disable_2fa
Section titled “enterprise_user.disable_2fa”Disable two-factor authentication for an enterprise user. Returns: a success confirmation naming the user and group. See also:
enterprise_user.get,enterprise_user.list,enterprise_user.delete.
- Meta-tool:
gitlab_enterprise_user, actiondisable_2fa - Individual tool:
gitlab_disable_2fa_enterprise_user - Tier: Premium
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
user_id | integer | yes | User ID |
enterprise_user.get
Section titled “enterprise_user.get”Get a single enterprise user by group_id and user_id. Returns: the full user profile (identities, SCIM identities, custom attributes, sign-in metadata, admin/auditor flags, license seat usage, and web URL). See also:
enterprise_user.list,enterprise_user.disable_2fa,enterprise_user.delete.
- Meta-tool:
gitlab_enterprise_user, actionget - Individual tool:
gitlab_get_enterprise_user - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
user_id | integer | yes | User ID |
enterprise_user.list
Section titled “enterprise_user.list”List enterprise users for a top-level group with filtering and pagination. Returns: enterprise users with full profile fields (identities, SCIM identities, custom attributes, sign-in metadata, license seat usage) and pagination metadata. See also:
enterprise_user.get,enterprise_user.disable_2fa,enterprise_user.delete.
- Meta-tool:
gitlab_enterprise_user, actionlist - Individual tool:
gitlab_list_enterprise_users - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
active | boolean | no | Filter for active users only |
blocked | boolean | no | Filter for blocked users only |
created_after | string | no | Filter users created after this date (ISO 8601) |
created_before | string | no | Filter users created before this date (ISO 8601) |
order_by | string | no | Column to order keyset-paginated results by (e.g. id) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
search | string | no | Search by name or username or email |
sort | string (asc, desc) | no | Sort order for keyset pagination: asc or desc |
two_factor | string (enabled, disabled) | no | Filter by 2FA status: enabled or disabled |
username | string | no | Filter by exact username |