---
title: endpointUser query | Wartiva GraphQL API
description: Retrieves an EndpointUser by its graph object id: an operating system or domain user account on an endpoint. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/queries/endpoint-user.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL query

# `endpointUser` query

Retrieves an [EndpointUser](https://wartiva.com/api-docs/types/endpoint-user.html) by its graph object id: an operating system or domain user account on an endpoint, identified by its SID on Windows or UID on macOS and Linux, with its account type, home directory, group memberships, and logon sessions. An [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) lists its current users through `users` and their history through `usersSeen`; find them across endpoints with [graphSearch](https://wartiva.com/api-docs/queries/graph-search.html) on the ENDPOINT_USER object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

## Response

Returns an [`EndpointUserPayload!`](https://wartiva.com/api-docs/types/endpoint-user-payload.html)

## Arguments

| Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The EndpointUser identifier. |
| `mockOptions` - [`MockDataInput`](https://wartiva.com/api-docs/types/mock-data-input.html) | Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |

## Example

### Query

```graphql
query endpointUser(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  endpointUser(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      applicationInstallUserSettings {
        ...ApplicationInstallUserSettingsConnectionFragment
      }
      userSystemSettings {
        ...UserSystemSettingsFragment
      }
      username
      userType
      description
      homeDirectory
      shell
      uid
      sid
      gid
      accountSecurity {
        ...AccountSecurityFragment
      }
      homeDirectoryPermissions
      duplicateUidUsernames
      duplicateUidCount
      duplicateUsernameUids
      duplicateUsernameCount
      logonSessions {
        ...LogonSessionConnectionFragment
      }
      groups {
        ...EndpointGroupConnectionFragment
      }
      groupsSeen {
        ...EndpointGroupConnectionFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

```

### Variables

```json
{
  "id": "4",
  "mockOptions": MockDataInput
}

```

### Response

```json
{"data": {"endpointUser": {"node": EndpointUser}}}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
