# How to Create a New User in Snipe-IT: Web UI and API Methods

> Learn to create a new user in Snipe-IT using the web UI or API. Follow simple steps for efficient user management and streamline your asset tracking workflow.

- Repository: [Grokability, Inc./snipe-it](https://github.com/grokability/snipe-it)
- Tags: how-to-guide
- Published: 2026-07-31

---

**You can create a new user in Snipe-IT either through the web interface by navigating to Users > Add New User or programmatically via the REST API endpoint `POST /api/v1/users`, both of which utilize the `UsersController::store()` method and `SaveUserRequest` validation.**

Snipe-IT, an open-source IT asset management system built on Laravel by grokability/snipe-it, provides robust user management capabilities through both graphical and programmatic interfaces. The user creation process is orchestrated through the [`app/Http/Controllers/Users/UsersController.php`](https://github.com/grokability/snipe-it/blob/main/app/Http/Controllers/Users/UsersController.php) file, which handles form rendering, request validation, and persistence logic. Whether you are manually onboarding employees or automating provisioning, understanding the underlying architecture ensures reliable user management.

## Prerequisites and Permissions

Before attempting to create a user, ensure you possess the appropriate authorization. Snipe-IT enforces role-based access control through [`app/Policies/UserPolicy.php`](https://github.com/grokability/snipe-it/blob/main/app/Policies/UserPolicy.php), which governs the `create` ability. The `UsersController::store()` method explicitly calls `authorize('create', User::class)` at the beginning of the execution flow, preventing unauthorized access attempts. You must hold an admin role or have explicit `user.create` permissions assigned to your account.

## Creating a User via the Web Interface

The web UI follows a conventional Laravel resource controller pattern, defined in [`routes/web.php`](https://github.com/grokability/snipe-it/blob/main/routes/web.php) via `Route::resource('users', UsersController::class)`.

### Step 1: Access the User Creation Form

Navigate to the **Users** menu item in the main navigation. Clicking **Add New User** triggers a `GET` request to `/users/create`, handled by `UsersController::create()` between lines 75-94. This method prepares the view model by loading available groups, permissions, and companies, then renders [`resources/views/users/edit.blade.php`](https://github.com/grokability/snipe-it/blob/main/resources/views/users/edit.blade.php). The form captures essential fields including first name, last name, email, username, password, locale preferences, company assignments, and group memberships.

### Step 2: Submit and Validate the Form

Complete the form fields and submit. This posts to `/users` (the resource `store` action), where `UsersController::store()` processes the request. The incoming data first passes through [`app/Http/Requests/SaveUserRequest.php`](https://github.com/grokability/snipe-it/blob/main/app/Http/Requests/SaveUserRequest.php), which enforces validation rules for required fields, unique email/username constraints, and password policies. Upon validation, the controller populates a new `App\Models\User` instance, handles optional avatar uploads via `ImageUploadRequest`, and executes the following critical operations:

- **Persistence**: Calls `$user->save()` to store the record.
- **Company Synchronization**: Invokes `$user->syncCompaniesWithLogging()` to associate the user with specified organizations.
- **Notification Dispatch**: If the user is activated and the "send welcome email" option is selected, triggers `$user->notify(new WelcomeNotification($user))`.
- **Redirect**: Uses `Helper::getRedirectOption()` to determine the post-creation destination (typically returning to the user list or edit form).

## Creating a User via the REST API

For automated provisioning, Snipe-IT exposes the `POST /api/v1/users` endpoint. This requires an API token with admin privileges or `user.create` permission.

Include the following headers and payload structure:

```bash
curl -X POST "https://snipe-it.example.com/api/v1/users" \
     -H "Authorization: Bearer YOUR_API_TOKEN" \
     -H "Content-Type: application/json" \
     -d '{
           "first_name": "Jane",
           "last_name": "Doe",
           "email": "jane.doe@example.com",
           "username": "jdoe",
           "password": "SecretPass123",
           "activated": 1,
           "company_ids": [2],
           "groups": [1, 3],
           "permission": { "admin": true }
         }'

```

The API controller ultimately delegates to the same `UsersController::store()` logic used by the web interface, ensuring consistent validation through `SaveUserRequest` and identical side effects (company syncing, welcome notifications).

## Key Laravel Components Behind User Creation

Understanding the architecture helps troubleshoot issues and customize workflows.

**UsersController** ([`app/Http/Controllers/Users/UsersController.php`](https://github.com/grokability/snipe-it/blob/main/app/Http/Controllers/Users/UsersController.php))

The controller orchestrates the creation flow. The `create()` method prepares view data, while `store()` handles persistence, validation delegation, and post-save operations including welcome notifications.

**SaveUserRequest** ([`app/Http/Requests/SaveUserRequest.php`](https://github.com/grokability/snipe-it/blob/main/app/Http/Requests/SaveUserRequest.php))

This FormRequest class centralizes validation rules for both UI and API payloads. It guarantees data integrity by enforcing required fields, password complexity, and uniqueness constraints before the controller ever touches the input.

**User Model and Policies** ([`app/Models/User.php`](https://github.com/grokability/snipe-it/blob/main/app/Models/User.php) and [`app/Policies/UserPolicy.php`](https://github.com/grokability/snipe-it/blob/main/app/Policies/UserPolicy.php))

The `User` model encapsulates attribute casting and provides helper methods like `syncCompaniesWithLogging()` for relationship management. The `UserPolicy` class authorizes actions based on the authenticated user's roles, specifically checking `create`, `update`, and `delete` abilities.

## Summary

- **Web Interface**: Navigate to Users > Add New User, which triggers `UsersController::create()`, then submit to `UsersController::store()` with `SaveUserRequest` validation.
- **API Method**: Send authenticated `POST` requests to `/api/v1/users` with JSON payloads; uses identical backend logic as the web interface.
- **Authorization**: All creation attempts require `create` permission verified through [`UserPolicy.php`](https://github.com/grokability/snipe-it/blob/main/UserPolicy.php).
- **Post-Creation**: The system automatically syncs company assignments and dispatches `WelcomeNotification` when activation and email options are enabled.
- **Key Files**: [`UsersController.php`](https://github.com/grokability/snipe-it/blob/main/UsersController.php), [`SaveUserRequest.php`](https://github.com/grokability/snipe-it/blob/main/SaveUserRequest.php), [`User.php`](https://github.com/grokability/snipe-it/blob/main/User.php), and [`edit.blade.php`](https://github.com/grokability/snipe-it/blob/main/edit.blade.php) comprise the core user creation stack.

## Frequently Asked Questions

### What permissions do I need to create a user in Snipe-IT?

You must have admin privileges or explicit `user.create` permissions assigned through the role-based access control system. The `UserPolicy::create()` method enforces this check before `UsersController::store()` executes any persistence logic.

### Can I create users in bulk using the Snipe-IT API?

While the standard API endpoint `POST /api/v1/users` handles single user creation, you can script bulk operations by iterating through user datasets and making individual authenticated requests. Each request triggers the same validation and notification workflows as manual creation.

### How does Snipe-IT validate new user data?

Validation occurs in [`app/Http/Requests/SaveUserRequest.php`](https://github.com/grokability/snipe-it/blob/main/app/Http/Requests/SaveUserRequest.php), which checks for required fields (first name, email, username), enforces password policies, and ensures email/username uniqueness across the database. This applies to both web form submissions and API requests.

### Why isn't the welcome email being sent to new users?

The `WelcomeNotification` only dispatches when two conditions are met: the **Activated** checkbox is selected during creation, and the **Send Welcome Email** option is enabled. Additionally, verify your Snipe-IT email configuration in the Admin settings to ensure SMTP credentials are properly configured.