Breaking Change Announcement: Users API Response Restricted for Client Portal Users

Breaking Change Announcement: Users API Response Restricted for Client Portal Users

Hi all,
We are introducing a breaking change to the Users API when it is accessed by Client Portal users.

Alert
Status: Live
This change is now live in production. Please review your integrations and make the necessary updates.
Affected endpoints:
  1. GET /users
  2. GET /users/{user_ID}
When these endpoints are accessed by a Client Portal user, the response will be restricted to the following fields for each user:
  1. full_name
  2. last_name
  3. id
  4. first_name
  5. type__s
All other user details will no longer be returned.

Why this change?

Currently, when a Client Portal user accesses the Users API, the response includes CRM user details such as email address, role, profile, ZUID, and other personal or internal information.
This exposes user information to Client Portal users beyond what is required for the intended use case.

To improve data privacy and limit unnecessary exposure of CRM user information, we are restricting the response for Client Portal users to only the minimum details required to identify a user.

What is changing?

Current response
When accessed by a Client Portal user, the response currently includes multiple CRM user details:

{
    "users": [
        {
            "decimal_separator": "Period",
            "role": {
                "name": "CEO",
                "id": "2276164000000015966"
            },
            "$next_shift": null,
            "profile": {
                "name": "Administrator",
                "id": "2276164000000015972"
            },
            "last_name": "Boyle",
            "zuid": "75702610",
            "full_name": "Patricia Boyle",
            "$shift_effective_from": null,
            "$current_shift": null,
            "date_format": "MMM d, yyyy",
            "id": "5276164000000471001",
            "first_name": "Patricia",
            "email": "example@domain.com",
            "type__s": "Regular User",
            "status": "active"
        },
        ...
    ],
    "info": {
        "per_page": 200,
        "count": 3,
        "page": 1,
        "more_records": false
    }
}


New response
After this change, Client Portal users will receive only the following fields:

{
    "users": [
        {
            "full_name": "Patricia Boyle",
            "last_name": "Boyle",
            "id": "5276164000000471001",
            "first_name": "Patricia",
            "type__s": "Regular User"
        },
        {
            "full_name": "Sarah Johnson",
            "last_name": "Johnson",
            "id": "5276164000000799020",
            "first_name": "Sarah",
            "type__s": "Regular User"
        },
        {
            "full_name": "John Smith",
            "last_name": "Smith",
            "id": "5276164000000799326",
            "first_name": "John",
            "type__s": "Regular User"
        }, 
        ...
    ],
    "info": {
        "per_page": 200,
        "count": 3,
        "page": 1,
        "more_records": false
    }
}

The info object and its pagination-related fields remain unchanged.

This restriction applies only when the APIs are accessed by a Client Portal user. Regular CRM users will continue to receive the existing response without any changes.

Note: This change applies to responses returned for all supported values of the type parameter, except when retrieving a Client Portal user using type__s=Client Portal User or the currently logged-in user using type=CurrentUser.

Impact

Any Client Portal integration that relies on additional CRM user fields from the following endpoints will be impacted:
  1. GET /users
  2. GET /users/{user_ID}
The following fields will no longer be available to Client Portal users:
  1. email
  2. role
  3. profile
  4. zuid
  5. status
  6. date_format
  7. decimal_separator
  8. $current_shift
  9. $next_shift
  10. $shift_effective_from
The following fields will remain available:
  1. full_name
  2. last_name
  3. id
  4. first_name
  5. type__s

What you need to do

If your module or integration consumes these APIs in a Client Portal context:
  1. Review your implementation for dependencies on the fields being removed.
  2. Update any logic that relies on the removed fields.
Reach out to us through support@zohocrm.com if you have a valid use case that requires access to any of the removed fields for Client Portal users. Please review your integrations and make the necessary updates.

Release status

This change is now live in production. Please update your integrations accordingly.

Thank you!