Administration
Manages users, groups, service tokens, and OIDC clients.
📄️ Reset Resource Metadata
Clear resource synchronization state so the next synchronization pass reprocesses resource metadata.
📄️ Get Name Fences
Name reservations that outlived their owner and cannot self-heal. Null only until the first sweep runs (or while detection is disabled) — a clean sweep still writes the marker, as ``status: ok`` with ``count: 0``. Act on ``reachable_count``; the rest are scoped to collections that no longer exist and cannot collide.
📄️ Release Name Fences
Release fenced name reservations. Admin only; explicit list, no wildcard. Every precondition is re-checked here rather than trusted from the marker — the marker is up to ``NAME_FENCE_DETECT_INTERVAL_SECONDS`` stale, and the same TOCTOU reasoning applies as to the D1b drop guards. A reservation is released only when it still exists, its owner is still unresolvable, and a non-``completed`` checkpoint is still holding it.
📄️ Get Deletion Guards
Delete guards whose holder died and which nothing will ever clear. Null only until the first sweep runs (or while detection is disabled) — a clean sweep still writes the marker, as ``status: ok`` with ``count: 0``. Act on ``blocking_count``: a ``collection`` guard refuses the DELETE of every child in that collection, and any other kind refuses its own while the resource still exists.
📄️ Release Deletion Guards
Clear stuck delete guards. Admin only; explicit list, no wildcard. Preconditions are re-checked here rather than trusted from the marker, the same TOCTOU reasoning as the D1b drop guards. The one fact taken from the marker is ``first_seen``, for guards too old to carry a ``start_time`` — it is the only record of their age, and it can only under-state it, so it never lets a young guard through. This frees the 409 only. The name reservation is deliberately left held, so no same-name resource can be created and then destroyed by a late cleanup — release those separately via ``/admin/name-fences/release`` once the physical objects are confirmed gone.
📄️ Retry Cleanups
The lossless counterpart of ``/name-fences/release``: instead of freeing the name and abandoning the physical residue, this re-runs the cleanup so the reservation is released on the normal all-steps-succeeded path. Targets any non-``completed`` checkpoint — including ``exhausted`` (re-arms the reclaim series at attempt 1) and the pre-reclaim backlog the scheduled pass skips as too old. A ``running`` checkpoint younger than an hour is refused (a live run may hold it); an older one is a dead mid-run worker, and re-dispatching it is safe because every step is an idempotent DROP.
📄️ Recover Ontology Bulk Delete
Re-dispatch a stored bulk-delete run that stopped in a partial or failed state, using the checkpoint saved for that run. Administrator authentication is required. A run that is still pending or running is refused, and repeating the call on an already re-dispatched run makes no further change.
📄️ List Users
List users after administrator authentication. Use `category` to limit results to a category such as `service_account`.
📄️ Create User
Create a new user. Requires admin authentication.
📄️ Get User Versions
Get user versions. Requires admin authentication.
📄️ Get User
Get a specific user. Requires admin authentication.
📄️ Update User
Update a user. Requires admin authentication.
📄️ Delete User
Permanently remove a user account. Administrator authentication is required, and the deleted account can no longer authenticate.
📄️ List User Permissions
List the permission grants a user directly holds. Requires admin. The inverse of ``GET /permissions`` (subjects for a resource): this returns the resources ``user_id`` was granted a role on — used to review a service account's access. Only directly-written grants are returned (model-implied and collection-inherited roles are excluded), so each is revocable.
📄️ Get User Deletion Blockers
Count the resources that deleting this user would leave without an owner. Administrators only.
📄️ Get User Succession
Read-only — the actual transfer is a later step. Requires admin.
📄️ Transfer User Succession
Requires admin. Each item is independent — one item's failure never blocks another (see ``SuccessionTransferResult.status``).
📄️ Reset User Password
Reset a user's password. Requires admin authentication.
📄️ List Groups
List all groups. Requires admin authentication.
📄️ Create Group
Create a new group. Requires admin authentication.
📄️ Get Group Versions
Get group version history. Requires admin authentication.
📄️ Get Group
Get a specific group. Requires admin authentication.
📄️ Update Group
Partially update a group. Requires admin authentication.
📄️ Delete Group
Permanently remove a group. Administrator authentication is required, and memberships granted through the group stop applying.
📄️ List Group Members
List members of a group. Works for both local and OIDC groups.
📄️ Add Group Member
Add a member to a local group. OIDC groups are read-only.
📄️ Remove Group Member
Remove a member from a local group. OIDC groups are read-only.
📄️ List Providers
List identity providers and report each provider's configuration status and support for user and group management.
📄️ List OIDC Users
List IdP users for OIDC registration workflow.
📄️ List OIDC Groups
List IdP groups for OIDC registration workflow.
📄️ Sync User
Sync user data from IdP.
📄️ Sync Group
Sync group data from IdP.
📄️ Get OIDC Client Options
Return registration choices; the router requires admin authentication.
📄️ List OIDC Clients
List all OIDC clients. Requires admin authentication.
📄️ Create OIDC Client
Create an OIDC client. Returns the plaintext client_secret exactly once for confidential clients. If lost, use rotate-secret to generate a new one.
📄️ Get OIDC Client
Get an OIDC client by its public client_id.
📄️ Update OIDC Client
Update an OIDC client. client_id and client_type are immutable.
📄️ Delete OIDC Client
Permanently delete an OIDC client registration so its client credentials can no longer be used. Administrator authentication is required.
📄️ Rotate OIDC Client Secret
Rotate the client_secret for a confidential OIDC client. Returns the new plaintext secret exactly once.
📄️ Create Service Token
Create a service token for a service account.
📄️ List Service Tokens
List service tokens with optional filters.
📄️ Revoke Service Token
Revoke a service token so it can no longer authenticate API requests. Administrator authentication is required.