> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nasiko.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a user. No password is taken — a one-time `access_key`/

> Create a user. No password is taken — a one-time `access_key`/
`access_secret` pair is minted and returned once; the secret doubles as
the user's login password (see `nasiko-user-creation-contract`).



## OpenAPI

````yaml /api-reference/openapi.json post /api/users
openapi: 3.1.0
info:
  title: Nasiko API
  description: >-
    HTTP API for the Nasiko OpenRuntime: agents, coding harnesses, TokenOps,
    routing, MCP, and secrets. Spec is generated from annotated routes; some
    surfaces are documented on the hand-written pages alongside this file.
  license:
    name: ''
  version: 0.1.0
servers: []
security: []
tags:
  - name: secrets
    description: Encrypted per-user agent secrets
  - name: catalog
    description: >-
      Agent catalog: registration, discovery, versions, per-agent secrets, and
      source import
  - name: agents
    description: >-
      Agent lifecycle: deployments, LLM routing config, update/rollback,
      upload-and-deploy
  - name: orchestrator
    description: >-
      A2A dispatch: routing-engine/ReAct orchestrator and direct agent chat,
      plus routing stats
  - name: users
    description: >-
      User management: CRUD, roles, credentials, accessible agents
      (superuser-only)
  - name: usage
    description: Per-user token usage and cost reporting
  - name: observability
    description: Sessions, traces, spans, agent logs, and FinOps reporting
  - name: llm-router
    description: LLM routing presets, provider/model catalog, and tier→model registry
  - name: mcp
    description: >-
      MCP gateway: agent-facing JSON-RPC tool calls, connector
      registration/upload/sharing, credentials & OAuth, and per-agent tool
      permissions
paths:
  /api/users:
    post:
      tags:
        - users
      summary: Create a user. No password is taken — a one-time `access_key`/
      description: |-
        Create a user. No password is taken — a one-time `access_key`/
        `access_secret` pair is minted and returned once; the secret doubles as
        the user's login password (see `nasiko-user-creation-contract`).
      operationId: create_user
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateUser'
        required: true
      responses:
        '201':
          description: User created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateUserResponse'
        '409':
          description: Username or email already exists
components:
  schemas:
    CreateUser:
      type: object
      required:
        - username
        - email
      properties:
        display_name:
          type:
            - string
            - 'null'
        email:
          type: string
        is_superuser:
          type: boolean
          description: |-
            Separate from `role` — `role` is a `user_role` enum value
            (admin/department_manager/team_lead/team_member/member), never
            "superuser". This is the one flag that actually grants unrestricted
            access (bypasses org-visibility scoping, gates superuser-only routes
            like MCP toolkit registration) — see CLAUDE.md's `role` vs
            `is_superuser` note.
        role:
          type:
            - string
            - 'null'
        username:
          type: string
    CreateUserResponse:
      type: object
      description: |-
        One-time credential material — the only time `access_secret` is ever
        returned; the server stores only its hash from here on.
      required:
        - id
        - username
        - access_key
        - access_secret
        - message
      properties:
        access_key:
          type: string
        access_secret:
          type: string
        id:
          type: string
          format: uuid
        message:
          type: string
        username:
          type: string

````