Seems I was confused by the term external_id since it was included in the data sent by discourse during SSO. Apparently it’s supposed to be external to me, not to discourse (which makes sense now).
Calling GET /admin/users/:user-id (where user-id is the external-id given by discourse earlier) works well.
On a side note, is there a way of doing this without having to supply the API key? That would make integration with my client easier.