Skip to content
© 2026 The ThingsBoard Authors
Try for free

ThingsBoard Cloud

Choose your data region

Your data stays in the region you choose, for residency and compliance. No credit card required.

Rather run it yourself? Install on your own servers

Users

In ThingsBoard, a User is a principal entity with credentials to authenticate and access the platform. Users are governed by an access control model that defines what operations they can perform and which platform resources they may access.

Each user belongs to a specific Tenant or Customer and is assigned to one or more user groups that determine their permissions and roles.
Ownership determines the scope of data and resources available to the user.

ThingsBoard uses a Role-Based Access Control (RBAC) model:

  • Permissions specify actions (read, write, manage) that a user can execute on platform resources such as devices, assets, dashboards, etc.
  • Roles are sets of permissions.
  • Roles are assigned to user groups, not directly to individual users.

User groups aggregate users with similar access requirements and simplify bulk permission management. A user can belong to multiple groups simultaneously and inherits permissions from all assigned groups.

ThingsBoard provides built-in user groups and supports creation of custom groups:

  • Tenant-level groups: Tenant Administrators, Tenant Users
  • Customer-level groups: Customer Administrators, Customer Users
  • All group: A default group that all users belong to; it carries no permissions by default.

From the sidebar, navigate to Customers & users ⇾ Users. The All tab lists every user visible to the current user, with columns for created time, first name, last name, email, owning Customer, and group membership; the Groups tab organizes users into entity groups.

Enable Include customer entities to also list users owned by Customers alongside those owned directly by the Tenant; disable it to show only Tenant-level users.

The Add user dialog collects the new User’s information across two steps.

  1. From the sidebar, navigate to Customers & users ⇾ Users.
  2. Click + Add user in the top right corner.
  3. On the User details step, enter an email (used as the login username). Optionally, fill in the first name, last name, phone (in E.164 format, e.g. +12015550123), language, unit system, and a description.
  4. Choose the user activation method:
    • Display activation link (default) — shows the activation link in a dialog right after the user is created, so you can copy and share it manually.
    • Send activation mail — sends the activation link to the specified email address (requires a configured mail server).
  5. Click Next: Owner and groups to open the optional second step. The Owner field defaults to the current user, keeping the new user at Tenant level; replace it with an existing Customer to scope the user to that Customer instead. Optionally, add the user to one or more Groups to grant initial permissions.
  6. Click Add to create the user.

If you chose Display activation link, a dialog shows the link (it expires after the tenant’s User activation link TTL setting) with a Copy activation link button. After creation, the user must activate the account using the provided link and set a password before logging in.

After receiving the activation link, the user sets a password to activate the account.

  1. Open the activation link.
  2. Enter and confirm a password.
  3. Click Create password.

Once the password is created, the user can log in and access resources according to their assigned permissions.

The User details panel displays and lets you edit all user account properties.

  1. Navigate to Customers & users ⇾ Users from the left-hand menu.
  2. Click the user in the list.
Tab name Description
Details Edit the user’s account information, access management shortcuts (activation, login-as, owner and groups, delete), and copy the User ID.
Attributes Manage attributes associated with the user account.
Latest telemetry View and manage the most recent telemetry values associated with the user account.
Alarms View and manage alarms related to the user.
Relations Manage entity relationships between the user and other entities. Allows creating and deleting relations.
Audit logs View a history of actions performed by or on the user account.
API keys Manage API keys issued for the user account.

The Details tab contains the following fields:

  • Email (required): The user’s login credential and unique identifier on the platform.
  • First name: The user’s given name, shown in the UI and notifications.
  • Last name: The user’s family name, shown in the UI and notifications.
  • Phone: Contact number in E.164 format like +12015550123. Use the flag selector to set the country code prefix.
  • Language: The display language for this user’s UI session.
  • Unit system: The measurement unit system used in the UI for this user. Select Auto to inherit the tenant-level setting, Metric for SI units, Imperial for US customary units, or Hybrid to mix metric and imperial.
  • Description: Free-text field for notes about the user.
  • Default dashboard: The dashboard opened automatically after login. Enable Always fullscreen to open the dashboard in fullscreen mode and hide the toolbar.
  • Home dashboard: The dashboard opened when the user clicks Home in the navigation bar. Enable Hide home dashboard toolbar to hide the navigation toolbar when this dashboard is open. See Home Dashboard for the tenant- and customer-wide equivalents.
  • Custom menu: Assigns a custom navigation menu to the user, replacing the default sidebar.

To save changes, click the checkmark icon at the top of the panel.

Administrators can log in as another user to verify access rights and troubleshoot permission issues.

  1. Open the Customers & users ⇾ Users page.
  2. In the users list, click the Login as … icon next to the required user, or open the user and click the Login as … button on the Details tab. The button is labeled Login as Tenant Admin for a user owned by the Tenant, or Login as Customer User for a user owned by a Customer.
  3. The session switches to the selected user’s access scope.

Changing the owner repositions the user in the multi-tenant hierarchy and updates their accessible resources accordingly.

  1. Open the Customers & users ⇾ Users page and select the required user.
  2. In the user details view, click Manage owner and groups.
  3. In the dialog, update the Owner (Tenant or Customer) if necessary.
  4. Add or remove the user from the required Groups.
  5. Click Update to apply the changes.

Disabling a user account temporarily restricts access without deleting it. A disabled user cannot log in or access any tenant resources.

  1. Open the Customers & users ⇾ Users page and select the required user.
  2. In the user details view, click Disable User Account (or Enable User Account if it’s already disabled) to toggle the account status.

Administrators with sufficient permissions can delete user accounts.

  1. Click the Delete (trash bin) icon next to the user in the list, or open the user and click Delete user on the Details tab.
  2. Confirm the deletion.

Assign users only to groups with the minimum required roles.

Use distinct groups for different permission sets (e.g., read-only vs. manage).

Review group membership regularly to minimize unnecessary access.

Configure outgoing mail server settings to support automated activation workflows.