Skip to main content
Version: 1.28 (Current)

Change User

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, User management

Changes the user that the following actions work with. After it runs, [User:*] tokens return the new user's data, and actions that use "the current user" when no user is given act on the new user. It's available in Listings, API endpoints and InfoBox.

It doesn't log anyone in or out. The person who made the request stays signed in as themselves, and page and module permissions aren't checked again.

Typical Use Cases​

  • Read another user's profile with [User:*] tokens, for example the user whose ID is in the URL
  • Run user actions, such as Update User Profile or Grant User Role, on a user picked from a Listing row or an API request
  • Send an email where [User:*] tokens describe the recipient instead of the person who clicked

Don't use it to​

Action NameDescription
Load UserLoads one or more users, and also makes the last one the current user.
Load Users from SQLLoads a list of users from a SQL query.
Execute ActionsLimits the change to the actions inside it. The original user is restored afterwards.
User LoginSigns a user in.
Update User ProfileUpdates the current user's profile when no user is given.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
User IdentifierThe user's ID, email address or username, for example [QueryString:UserId] or [Email]. See How the user is found.Yesempty stringNo

How the user is found​

The user is looked up in the current portal only:

  1. If the value is a whole number, it's used as the user ID. Nothing else is tried, so a username made only of digits can't be found this way.
  2. Otherwise, it's looked up by email address.
  3. If no user has that email, it's looked up by username.

If no user is found, including when the value is empty, the action doesn't fail. The current user is cleared, and the following actions run as if nobody were signed in. [User:*] tokens return empty values, and actions that need a user may fail.

What changes​

ChangesDoesn't change
[User:*] tokens and role tokensWho is signed in to the site
The user that user actions act on when their user parameter is emptyPage, module and API permissions, which are checked before the actions run
Whether errors show technical details. Administrators and low-code engineers see the real error. Other users see a general message.Token values already set by earlier actions

The change lasts for the rest of the actions in the list. If you put Change User inside Execute Actions, the original user is restored when those actions finish.

Considerations​

  • Security. Anyone who can change the identifier can make the actions run for any user. For example, with [QueryString:UserId], a visitor could edit the URL and read another user's data through [User:*] tokens, or update their profile. Check that the caller may act on that user first, for example with a condition based on their role, or take the identifier from a source they can't edit.
  • It affects error messages. If you change to an administrator, uncaught errors show technical details to the person who made the request.
  • Check that the user exists. Because a missing user doesn't cause an error, add a check after the action, for example [User:UserId] == "", and stop with Throw Exception.
  • Scope it. Wrap Change User and the actions that need it in Execute Actions, so later actions run as the original user again.
  • One user only. The identifier isn't split on commas. Use Load User for several users.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Grant a role to the user from a Listing row​

This changes to the user in the row's UserId column, fails if the user doesn't exist, and then grants a role. Give it a condition, or put it on a button only administrators can see, so other users can't run it. Because it's inside Execute Actions, the actions after it run as the original user again.

{
"Title": "Execute Actions",
"ActionType": "ExecuteActions",
"Description": "Grant the Reviewer role to the selected user",
"Parameters": {
"ActionList": [
{
"Title": "Change User",
"ActionType": "ChangeUser",
"Description": "Work with the selected user",
"Parameters": {
"Id": "[UserId]"
}
},
{
"Title": "Throw Exception",
"ActionType": "ThrowException",
"Description": "Stop if the user wasn't found",
"Condition": "[User:UserId] == \"\"",
"Parameters": {
"AdminMessage": "Change User found no user for identifier [UserId].",
"FriendlyMessage": "The selected user no longer exists."
}
},
{
"Title": "Grant User Role",
"ActionType": "GrantUserRole",
"Description": "Grant the role to the selected user",
"Parameters": {
"RoleNames": "Reviewer"
}
}
]
}
}

Revised 09/26/2026