Admin accounts
Everyone who signs in to the panel. password in a body is always your own, so those calls need a session, never a key. Only the owner may change the owner.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
GET /api/users
Section titled “GET /api/users”Every admin, the owner first.
- Level: Read only
- Notes: Not over MCP
- Returns:
{items: PanelUser[]}
POST /api/users
Section titled “POST /api/users”Add an admin with a first password they can change themselves.
- Level: Full
- Notes: Not over MCP
- Input:
{username, password} - Returns:
201 PanelUser
GET /api/users/:id
Section titled “GET /api/users/:id”One admin, with their 2FA status and last sign-in.
- Level: Read only
- Notes: Not over MCP
- Returns:
PanelUser
DELETE /api/users/:id
Section titled “DELETE /api/users/:id”Remove an admin and end their sessions; never the owner, never yourself.
- Level: Full
- Notes: Destructive · Not over MCP
PUT /api/users/:id/username
Section titled “PUT /api/users/:id/username”Rename an admin; nobody is signed out.
- Level: Full
- Notes: Not over MCP
- Input:
{password, username}
PUT /api/users/:id/email
Section titled “PUT /api/users/:id/email”Set the recovery email; it takes over once the link sent to it is followed.
- Level: Full
- Notes: Not over MCP
- Input:
{password, email}
DELETE /api/users/:id/email
Section titled “DELETE /api/users/:id/email”Remove the recovery email, and any reset link still out.
- Level: Full
- Notes: Destructive · Not over MCP
- Input:
{password}
PUT /api/users/:id/password
Section titled “PUT /api/users/:id/password”Set a new password; ends their other sessions, or all of them when it is someone else’s.
- Level: Full
- Notes: Not over MCP
- Input:
{password, newPassword}
POST /api/users/:id/totp/setup
Section titled “POST /api/users/:id/totp/setup”Mint a pending 2FA secret and its QR code - your own account only.
- Level: Full
- Notes: Not over MCP
- Input:
{password}
POST /api/users/:id/totp/enable
Section titled “POST /api/users/:id/totp/enable”Arm 2FA with a code; returns ten recovery codes, once.
- Level: Full
- Notes: Not over MCP
- Input:
{code}
POST /api/users/:id/totp/recovery-codes
Section titled “POST /api/users/:id/totp/recovery-codes”Issue a fresh set of recovery codes - your own account only.
- Level: Full
- Notes: Not over MCP
- Input:
{password}
DELETE /api/users/:id/totp
Section titled “DELETE /api/users/:id/totp”Turn 2FA off - yours, or a colleague’s who lost their phone.
- Level: Full
- Notes: Destructive · Not over MCP
- Input:
{password}