> ## Documentation Index
> Fetch the complete documentation index at: https://inkbox.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Users and capabilities

> Read visible Slack users and inspect granted permissions before choosing an operation

All paths on this page are relative to `https://inkbox.ai/api/v1/slack`.

## Inspect capabilities

```text theme={null}
GET /connections/{connection_id}/capabilities
```

Returns `200` with:

| Field | Meaning |
| :- | :- |
| `connection_id` | Selected workspace connection UUID |
| `scopes` | Permissions granted to this connection |
| `missing_scopes` | Currently requested permissions that this installation has not granted |
| `capabilities` | Capability names mapped to `required_scopes`, `missing_scopes`, and `scopes_satisfied` |
| `native_processing_status` | `missing_scope` or `unknown`; never a guarantee that native session status is available |
| `max_upload_bytes` | `10485760` (10 MiB) |

Capability names include `users`, `user_email`, `reactions_read`, `reactions_write`, `pins_read`, `pins_write`, `files_read`, `files_upload`, `messages_write`, `processing_status`, `conversations_join`, `public_channels_leave`, `private_channels_leave`, `group_direct_messages_leave`, and `direct_messages_open`.

`user_email` requires both `users:read` and `users:read.email`. It indicates permission to request an email, not a guarantee that every profile exposes one.

`scopes_satisfied: true` only means the listed scopes were granted. It does not prove current conversation access, workspace approval, message authorship, or app eligibility. Capabilities can be inspected after disconnect, but retained scope information does not make that connection usable.

Existing connected workspaces may need to [complete authorization again](/docs/api/slack/connections#start-browser-installation) to grant newly requested profile permissions. Missing optional permissions do not mean every unrelated operation is unavailable. Check the individual capability and the actual request result.

## List users

```text theme={null}
GET /connections/{connection_id}/users
```

Requires an active identity and connected workspace. `limit` defaults to `100` and accepts `1`–`200`. `cursor` is optional and accepts up to 2048 characters.

Returns `200` with `users` and `next_cursor`. User objects can include `id`, `name`, `real_name`, `is_bot`, `deleted`, `is_app_user`, `team_id`, `tz`, `tz_label`, and `tz_offset`. The optional `profile` can include `display_name`, `real_name`, `first_name`, `last_name`, `email`, `phone`, `title`, `status_text`, `status_emoji`, `image_48`, `image_72`, and `image_192`.

Fields may be absent or null. Email requires the optional `users:read.email` permission and an email address visible to the connection. Missing email permission does not disable unrelated messaging operations. These native Slack profiles use the connection's Slack permissions, independently of Inkbox contact visibility. A matching email does not grant access to an Inkbox contact.

## Get user

```text theme={null}
GET /connections/{connection_id}/users/{user_id}
```

`user_id` starts with `U` or `W`, followed by uppercase letters or digits, up to 64 characters total. Returns `200` with one user object, without a wrapper.

When this Slack account is already linked to a contact visible to the identity, the response also includes `contact_id`. Use it with the contacts API rather than repeating an email search. A profile lookup does not create, merge, or relink contacts.

In Slack Connect, an external participant may not appear in the ordinary workspace user list. Look up the user ID from the event or conversation when you need available profile details. External visibility and field availability remain subject to the selected connection's permissions.

## List conversation members

```text theme={null}
GET /connections/{connection_id}/conversations/{conversation_id}/members
```

The bot must have access to the conversation. `limit` defaults to `100` and accepts `1`–`200`. `cursor` is optional, up to 2048 characters.

Returns `200` with `members`, an array of user IDs, and `next_cursor`. Fetch user profiles separately as needed. Continue pagination explicitly; one page is not the entire membership list.
