Skip to main content
POST
Create a user. No password is taken — a one-time `access_key`/

Body

application/json
email
string
required
username
string
required
display_name
string | null
is_superuser
boolean

Separate from role — role is a user_role enum value (admin/department_manager/team_lead/team_member/member), never "superuser". This is the one flag that actually grants unrestricted access (bypasses org-visibility scoping, gates superuser-only routes like MCP toolkit registration) — see CLAUDE.md's role vs is_superuser note.

role
string | null

Response

User created

One-time credential material — the only time access_secret is ever returned; the server stores only its hash from here on.

access_key
string
required
access_secret
string
required
id
string<uuid>
required
message
string
required
username
string
required