How to Create a New User in Snipe-IT: Web UI and API Methods

You can create a new user in Snipe-IT either through the web interface by navigating to Users > Add New User or programmatically via the REST API endpoint POST /api/v1/users, both of which utilize the UsersController::store() method and SaveUserRequest validation.

Snipe-IT, an open-source IT asset management system built on Laravel by grokability/snipe-it, provides robust user management capabilities through both graphical and programmatic interfaces. The user creation process is orchestrated through the app/Http/Controllers/Users/UsersController.php file, which handles form rendering, request validation, and persistence logic. Whether you are manually onboarding employees or automating provisioning, understanding the underlying architecture ensures reliable user management.

Prerequisites and Permissions

Before attempting to create a user, ensure you possess the appropriate authorization. Snipe-IT enforces role-based access control through app/Policies/UserPolicy.php, which governs the create ability. The UsersController::store() method explicitly calls authorize('create', User::class) at the beginning of the execution flow, preventing unauthorized access attempts. You must hold an admin role or have explicit user.create permissions assigned to your account.

Creating a User via the Web Interface

The web UI follows a conventional Laravel resource controller pattern, defined in routes/web.php via Route::resource('users', UsersController::class).

Step 1: Access the User Creation Form

Navigate to the Users menu item in the main navigation. Clicking Add New User triggers a GET request to /users/create, handled by UsersController::create() between lines 75-94. This method prepares the view model by loading available groups, permissions, and companies, then renders resources/views/users/edit.blade.php. The form captures essential fields including first name, last name, email, username, password, locale preferences, company assignments, and group memberships.

Step 2: Submit and Validate the Form

Complete the form fields and submit. This posts to /users (the resource store action), where UsersController::store() processes the request. The incoming data first passes through app/Http/Requests/SaveUserRequest.php, which enforces validation rules for required fields, unique email/username constraints, and password policies. Upon validation, the controller populates a new App\Models\User instance, handles optional avatar uploads via ImageUploadRequest, and executes the following critical operations:

  • Persistence: Calls $user->save() to store the record.
  • Company Synchronization: Invokes $user->syncCompaniesWithLogging() to associate the user with specified organizations.
  • Notification Dispatch: If the user is activated and the "send welcome email" option is selected, triggers $user->notify(new WelcomeNotification($user)).
  • Redirect: Uses Helper::getRedirectOption() to determine the post-creation destination (typically returning to the user list or edit form).

Creating a User via the REST API

For automated provisioning, Snipe-IT exposes the POST /api/v1/users endpoint. This requires an API token with admin privileges or user.create permission.

Include the following headers and payload structure:

curl -X POST "https://snipe-it.example.com/api/v1/users" \
     -H "Authorization: Bearer YOUR_API_TOKEN" \
     -H "Content-Type: application/json" \
     -d '{
           "first_name": "Jane",
           "last_name": "Doe",
           "email": "jane.doe@example.com",
           "username": "jdoe",
           "password": "SecretPass123",
           "activated": 1,
           "company_ids": [2],
           "groups": [1, 3],
           "permission": { "admin": true }
         }'

The API controller ultimately delegates to the same UsersController::store() logic used by the web interface, ensuring consistent validation through SaveUserRequest and identical side effects (company syncing, welcome notifications).

Key Laravel Components Behind User Creation

Understanding the architecture helps troubleshoot issues and customize workflows.

UsersController (app/Http/Controllers/Users/UsersController.php)

The controller orchestrates the creation flow. The create() method prepares view data, while store() handles persistence, validation delegation, and post-save operations including welcome notifications.

SaveUserRequest (app/Http/Requests/SaveUserRequest.php)

This FormRequest class centralizes validation rules for both UI and API payloads. It guarantees data integrity by enforcing required fields, password complexity, and uniqueness constraints before the controller ever touches the input.

User Model and Policies (app/Models/User.php and app/Policies/UserPolicy.php)

The User model encapsulates attribute casting and provides helper methods like syncCompaniesWithLogging() for relationship management. The UserPolicy class authorizes actions based on the authenticated user's roles, specifically checking create, update, and delete abilities.

Summary

  • Web Interface: Navigate to Users > Add New User, which triggers UsersController::create(), then submit to UsersController::store() with SaveUserRequest validation.
  • API Method: Send authenticated POST requests to /api/v1/users with JSON payloads; uses identical backend logic as the web interface.
  • Authorization: All creation attempts require create permission verified through UserPolicy.php.
  • Post-Creation: The system automatically syncs company assignments and dispatches WelcomeNotification when activation and email options are enabled.
  • Key Files: UsersController.php, SaveUserRequest.php, User.php, and edit.blade.php comprise the core user creation stack.

Frequently Asked Questions

What permissions do I need to create a user in Snipe-IT?

You must have admin privileges or explicit user.create permissions assigned through the role-based access control system. The UserPolicy::create() method enforces this check before UsersController::store() executes any persistence logic.

Can I create users in bulk using the Snipe-IT API?

While the standard API endpoint POST /api/v1/users handles single user creation, you can script bulk operations by iterating through user datasets and making individual authenticated requests. Each request triggers the same validation and notification workflows as manual creation.

How does Snipe-IT validate new user data?

Validation occurs in app/Http/Requests/SaveUserRequest.php, which checks for required fields (first name, email, username), enforces password policies, and ensures email/username uniqueness across the database. This applies to both web form submissions and API requests.

Why isn't the welcome email being sent to new users?

The WelcomeNotification only dispatches when two conditions are met: the Activated checkbox is selected during creation, and the Send Welcome Email option is enabled. Additionally, verify your Snipe-IT email configuration in the Admin settings to ensure SMTP credentials are properly configured.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →