# HumanIdentities Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/humanidentities/

Schema for the `HumanIdentities` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, verbatim -- a full ARN, resource id, or self-link. Never truncated or normalised. Use it to find the object in the provider's console.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider gives none, the collector's queried region is used instead and flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified -- for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them -- no case folding, key/value normalisation, or merging across providers. An empty object means no tags; unreadable tags appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider-supplied timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Additional detail on the reason, when there is any.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`identity_id`** _(string)_
  The provider's own identifier for the identity.
- **`identity_store`** _(string)_
  Which identity store this row came from. On AWS, IAM users and Identity Center users share no identifiers and populate different subsets of fields.
- **`display_name`** _(string)_
  The person's display name. Null for AWS IAM users (they have no display name, only a user name and path), flagged not_supported_by_provider.
- **`email_or_upn`** _(string)_
  Email address or user principal name. AWS IAM users have no email attribute in the API, so this is null there unless the customer set it as a tag.
- **`enabled`** _(boolean)_
  Whether the identity can currently sign in. Read directly for Identity Center users; for AWS IAM users it is derived from having no login profile and no active access keys, and flagged as derived.
- **`identity_type`** _(string)_
  Whether this is a person, a service account, or an external guest.
  Allowed: `human`, `service`, `guest`, `external`, `unknown`
- **`mfa_registered`** _(boolean)_
  Whether this specific user has MFA registered (per user, not per account). Null with not_supported_by_provider for AWS Identity Center, which exposes no such field.
- **`mfa_methods`** _(array<string>)_
  The registered MFA method types. On AWS these are inferred from the device serial number shape (not returned by the API) and marked derived; FIDO and TOTP cannot always be distinguished.
- **`mfa_device_count`** _(integer)_
  Number of MFA devices registered to this identity.
- **`is_admin`** _(boolean)_
  Whether this identity holds administrative privilege. Derived from attached permissions, since no provider exposes an admin flag directly.
- **`admin_roles`** _(array<string>)_
  The administrative roles or policies behind is_admin, as provider references.
- **`last_sign_in_at`** _(string)_
  Last interactive console sign-in. On AWS, console-only, at five-minute granularity, with no tracking before 2014-10-20 and a gap in 2018; not available for Identity Center. Null forever for programmatic-only users -- do not read as 'never signed in'.
- **`created_at`** _(string)_
  When the identity was created.
- **`group_memberships`** _(array<string>)_
  Group references for this identity.
- **`has_console_access`** _(boolean)_
  Whether the identity has interactive sign-in, distinct from programmatic-only access. On AWS derived from a 404 on GetLoginProfile; null on the Identity Center path (IAM-only concept).
- **`has_static_credentials`** _(boolean)_
  Whether the identity holds long-lived credentials. An IAM-only concept on AWS; null on the Identity Center path.

## Methods

- [GET /unified/cloud-infrastructure/human_identities](/docs/api-reference/unified-cloud-infrastructure-api/humanidentities/list) — List Human identities
