lhc users
Manage Lakehousecat users. Requires admin role.
Commands
users list
lhc users list [--skip N] [--limit N]
| Flag | Default | Description |
|---|---|---|
--skip | 0 | Number of users to skip |
--limit | 50 | Maximum number of users to return |
users get <id>
lhc users get <user-id>
users create
Invites a new user by email. Lakehousecat sends a registration email to the address.
lhc users create --email <email> [--role user|builder|admin]
| Flag | Required | Default | Description |
|---|---|---|---|
--email | yes | — | Email address of the new user |
--role | no | user | Initial role: user, builder, or admin |
users update <id>
Update a user's display name, role, or metadata.
lhc users update <user-id> [--name <name>] [--role <role>] [--meta '<json>']
| Flag | Description |
|---|---|
--name | New display name |
--role | New role: user, builder, or admin |
--meta | JSON object merged into the user's metadata (e.g. {"superset_username":"admin@acme.com"}) |
At least one of --name, --role, or --meta is required.
Example — set a Superset username:
lhc users update 3e7c3d4f-16ff-4914-8250-bbe693ab7224 \
--meta '{"superset_username":"jane@acme.com"}'
users delete <id>
lhc users delete <user-id>
users search [query]
Search matches a substring of the user's name or email.
lhc users search "jane"
lhc users search --tag RED # every red user, across all pages
--tag restricts results to users tagged with that color (repeatable, OR-combined; valid
colors: RED, YELLOW, GREEN, BLUE, PURPLE). Tags are per user and assigned in the UI —
the CLI only filters by them. The query is optional when --tag is given, but at least one of
the two is required.
users count
lhc users count
users disable <id>
Blocks login for the user without deleting the account or freeing its seat:
lhc users disable 3e7c3d4f-16ff-4914-8250-bbe693ab7224
users enable <id>
Re-enables a previously disabled user:
lhc users enable 3e7c3d4f-16ff-4914-8250-bbe693ab7224
users mfa-reset <id>
Resets (disables) MFA for a user who lost their device or backup codes, so they can sign in again and re-enroll:
lhc users mfa-reset 3e7c3d4f-16ff-4914-8250-bbe693ab7224
Locked out yourself, as the initial Administrator? This same command also works against your
own account — but only when it's run with the instance's API key ($LHC_API_KEY, the credential
from the Kubernetes secret the Operator sets, e.g. via lhc configure), not while signed in
through a browser session. This is the intended recovery path for the one case with no other way
back: the initial admin, alone, having lost their device and backup codes. It does not extend to
any other admin resetting their own MFA with a personal API key — see
Locked out of MFA? for the full picture.