Skip to main content
Version: Next

lhc users

Manage Lakehousecat users. Requires admin role.

Commands​

users list​

lhc users list [--skip N] [--limit N]
FlagDefaultDescription
--skip0Number of users to skip
--limit50Maximum number of users to return

users get <id>​

lhc users get <user-id>

users create​

Invites a new user by email. Lakehousecat sends a registration email to the address.

lhc users create --email <email> [--role user|builder|admin]
FlagRequiredDefaultDescription
--emailyes—Email address of the new user
--rolenouserInitial role: user, builder, or admin

users update <id>​

Update a user's display name, role, or metadata.

lhc users update <user-id> [--name <name>] [--role <role>] [--meta '<json>']
FlagDescription
--nameNew display name
--roleNew role: user, builder, or admin
--metaJSON object merged into the user's metadata (e.g. {"superset_username":"admin@acme.com"})

At least one of --name, --role, or --meta is required.

Example — set a Superset username:

lhc users update 3e7c3d4f-16ff-4914-8250-bbe693ab7224 \
--meta '{"superset_username":"jane@acme.com"}'

users delete <id>​

lhc users delete <user-id>

users search [query]​

Search matches a substring of the user's name or email.

lhc users search "jane"
lhc users search --tag RED # every red user, across all pages

--tag restricts results to users tagged with that color (repeatable, OR-combined; valid colors: RED, YELLOW, GREEN, BLUE, PURPLE). Tags are per user and assigned in the UI — the CLI only filters by them. The query is optional when --tag is given, but at least one of the two is required.


users count​

lhc users count

users disable <id>​

Blocks login for the user without deleting the account or freeing its seat:

lhc users disable 3e7c3d4f-16ff-4914-8250-bbe693ab7224

users enable <id>​

Re-enables a previously disabled user:

lhc users enable 3e7c3d4f-16ff-4914-8250-bbe693ab7224

users mfa-reset <id>​

Resets (disables) MFA for a user who lost their device or backup codes, so they can sign in again and re-enroll:

lhc users mfa-reset 3e7c3d4f-16ff-4914-8250-bbe693ab7224

Locked out yourself, as the initial Administrator? This same command also works against your own account — but only when it's run with the instance's API key ($LHC_API_KEY, the credential from the Kubernetes secret the Operator sets, e.g. via lhc configure), not while signed in through a browser session. This is the intended recovery path for the one case with no other way back: the initial admin, alone, having lost their device and backup codes. It does not extend to any other admin resetting their own MFA with a personal API key — see Locked out of MFA? for the full picture.