Skip to content

Manage API

Everything /manage can ask for and everything it can change. /manage/graphql accepts a bearer carrying masks:manage or one of the narrower manage roles, issued for this tenant’s manage resource and no other. A mutation the bearer’s roles do not cover answers with an error naming the scopes it needs.

Generated from ManageSchema by ./dev reference. CI fails when this page and the schema disagree.

Field Type Description
viewer Actor!
manageLevels [String!]! What the viewer’s token may do here: read, support, security, and owner.
tenant Tenant!
actors
search: String
activated: Boolean
holds: String
pendingApproval: Boolean
suspended: Boolean
afterId: ID
limit: Int
[Actor!]!
actorCount
search: String
activated: Boolean
holds: String
pendingApproval: Boolean
suspended: Boolean
Int!
actor
uuid: ID!
Actor
clients
search: String
archived: Boolean
afterId: ID
limit: Int
[Client!]!
clientCount
search: String
archived: Boolean
Int!
client
clientId: ID!
Client
sessions
actor: ID
limit: Int
[Session!]!
devices
actor: ID
blocked: Boolean
unattached: Boolean
agent: String
limit: Int
[Device!]!
device
id: ID!
Device
tokens
actor: ID
client: ID
kind: String
live: Boolean
limit: Int
[Token!]!
connections
actor: ID
provider: ID
revoked: Boolean
limit: Int
[Connection!]!
consents
actor: ID
client: ID
revoked: Boolean
limit: Int
[Consent!]!
namespaces [Namespace!]!
providers
archived: Boolean
[Provider!]!
provider
key: ID!
Provider
providerPresets [ProviderPreset!]!
adapters
kind: String
archived: Boolean
[Adapter!]!
adapterServices [AdapterService!]!
domainClaims [DomainClaim!]!
organizations
archived: Boolean
limit: Int
[Organization!]!
organization
key: ID!
Organization
eventStreams
archived: Boolean
[EventStream!]!
signInPolicies
archived: Boolean
[SignInPolicy!]!
signInPolicy
key: ID!
SignInPolicy
defaultSignInPolicy SignInPolicy!
scopesSupported [String!]!
provisioningTokens [ProvisioningToken!]!
scimBaseUrl String!
samlMetadataUrl String!
minimumPassword Int!
mailPreviews
client: ID
[MailPreview!]!
mailTemplates [MailTemplate!]! One entry for each email the tenant can reword, and the signature.
tally Tally!
activity
days: Int
[ActivityDay!]!
events
actor: ID
client: ID
device: ID
action: String
grave: Boolean
organization: ID
afterId: ID
limit: Int
[Event!]!
eventCount
actor: ID
client: ID
device: ID
action: String
grave: Boolean
organization: ID
Int!
eventActions [EventAction!]!
Field Type Description
createActor
nickname: String
email: String
password: String
scopes: [String!]
CreateActorPayload
resendInvitation
uuid: ID!
ResendInvitationPayload
resetPassword
uuid: ID!
ResetPasswordPayload
verifyEmail
uuid: ID!
VerifyEmailPayload
updateActor
uuid: ID!
nickname: String
email: String
phone: String
name: String
givenName: String
familyName: String
middleName: String
profileUrl: String
pictureUrl: String
websiteUrl: String
gender: String
birthdate: String
zoneinfo: String
locale: String
UpdateActorPayload
approveActor
uuid: ID!
ApproveActorPayload
setActorScopes
uuid: ID!
scopes: [String!]!
SetActorScopesPayload
signOutActor
uuid: ID!
SignOutActorPayload
suspendActor
uuid: ID!
SuspendActorPayload
restoreActor
uuid: ID!
RestoreActorPayload
deleteActor
uuid: ID!
DeleteActorPayload
issueProvisioningToken
label: String!
expiresIn: Int
organization: ID
IssueProvisioningTokenPayload
revokeProvisioningToken
id: ID!
RevokeProvisioningTokenPayload
generateBackupCodes
uuid: ID!
GenerateBackupCodesPayload
disableAuthenticator
uuid: ID!
DisableAuthenticatorPayload
disableCodeFactor
uuid: ID!
factor: String!
DisableCodeFactorPayload
revokePasskey
uuid: ID!
id: ID!
RevokePasskeyPayload
uploadAvatar
uuid: ID!
photo: Upload!
UploadAvatarPayload
removeAvatar
uuid: ID!
RemoveAvatarPayload
createClient
name: String!
grantTypes: [String!]
redirectUris: [String!]
postLogoutRedirectUris: [String!]
resources: [String!]
requiredScopes: [String!]
allowedScopes: [String!]
tokenEndpointAuthMethod: String
dpopBoundAccessTokens: Boolean
jwks: JSON
jwksUri: String
requireSignedRequestObject: Boolean
CreateClientPayload
createSamlApplication
name: String!
entityId: String!
acsUrls: [String!]!
certificate: String
nameIdFormat: String
requestsSigned: Boolean
idpInitiated: Boolean
attributes: JSON
CreateSamlApplicationPayload
readSamlApplicationMetadata
xml: String!
ReadSamlApplicationMetadataPayload
updateClient
clientId: ID!
name: String
grantTypes: [String!]
redirectUris: [String!]
postLogoutRedirectUris: [String!]
resources: [String!]
requiredScopes: [String!]
allowedScopes: [String!]
subjectType: String
dpopBoundAccessTokens: Boolean
sectorIdentifierUri: String
backchannelLogoutUri: String
backchannelLogoutSessionRequired: Boolean
requirePushedAuthorizationRequests: Boolean
jwks: JSON
jwksUri: String
requireSignedRequestObject: Boolean
tokenEndpointAuthMethod: String
samlEntityId: String
samlCertificate: String
samlNameIdFormat: String
samlRequestsSigned: Boolean
samlIdpInitiated: Boolean
samlAttributes: JSON
consentRequired: Boolean
signInPolicy: ID
clientUri: String
logoUri: String
tosUri: String
policyUri: String
consentLifetime: Int
authorizationDetailsTypes: [String!]
authorizationDetailsSchemas: JSON
UpdateClientPayload
rotateClientSecret
clientId: ID!
expiresIn: Int
RotateClientSecretPayload
archiveClient
clientId: ID!
ArchiveClientPayload
restoreClient
clientId: ID!
RestoreClientPayload
releaseNamespace
name: String!
ReleaseNamespacePayload
discoverProvider
issuer: String!
DiscoverProviderPayload
readSamlMetadata
metadataUrl: String
metadataXml: String
ReadSamlMetadataPayload
createProvider
key: ID!
name: String!
preset: ID
presetValues: JSON
protocol: String
authorizationUrl: String
tokenUrl: String
clientId: String
clientSecret: String
userinfoUrl: String
emailsUrl: String
scopes: [String!]
authorizeParams: JSON
claims: JSON
subjectClaim: String
issuer: String
jwksUri: String
tokenAuthMethod: String
responseMode: String
teamId: String
keyId: String
privateKey: String
idpEntityId: String
idpSsoUrl: String
idpCertificates: String
metadataUrl: String
nameIdFormat: String
role: String
trustsEmail: Boolean
receivesSignals: Boolean
emailDomains: [String!]
signupScopes: [String!]
delegates: Boolean
delegatedScopes: [String!]
delegationParams: JSON
resourceUrl: String
CreateProviderPayload
updateProvider
key: ID!
name: String
protocol: String
authorizationUrl: String
tokenUrl: String
clientId: String
clientSecret: String
userinfoUrl: String
emailsUrl: String
claims: JSON
tokenAuthMethod: String
responseMode: String
teamId: String
keyId: String
privateKey: String
idpEntityId: String
idpSsoUrl: String
idpCertificates: String
metadataUrl: String
nameIdFormat: String
scopes: [String!]
authorizeParams: JSON
subjectClaim: String
issuer: String
jwksUri: String
role: String
trustsEmail: Boolean
receivesSignals: Boolean
emailDomains: [String!]
signupScopes: [String!]
delegates: Boolean
delegatedScopes: [String!]
delegationParams: JSON
resourceUrl: String
UpdateProviderPayload
archiveProvider
key: ID!
ArchiveProviderPayload
restoreProvider
key: ID!
RestoreProviderPayload
revokeToken
id: ID!
family: Boolean
RevokeTokenPayload
revokeConnection
id: ID!
RevokeConnectionPayload
revokeConsent
id: ID!
RevokeConsentPayload
revokeDelegation
id: ID!
RevokeDelegationPayload
registerProvider
key: ID!
RegisterProviderPayload
revokeSession
id: ID!
RevokeSessionPayload
blockDevice
id: ID!
BlockDevicePayload
unblockDevice
id: ID!
UnblockDevicePayload
blockDevices
ids: [ID!]
agent: String
refuse: Boolean
BlockDevicesPayload
unblockDevices
ids: [ID!]!
UnblockDevicesPayload
signOutDevice
id: ID!
SignOutDevicePayload
updateTenant
name: String
dynamicClientScopes: [String!]
dynamicRegistration: String
namedBy: String
browsersOnly: Boolean
blockedAgents: String
signInPolicy: ID
suspendAfter: Int
deleteAfter: Int
riskyNetworks: String
eventRetentionDays: Int
UpdateTenantPayload
createSignInPolicy
name: String
signup: Boolean
nickname: String
email: String
emailVerified: Boolean
phone: String
phoneVerified: Boolean
passwordMinimum: Int
refuseCommonPasswords: Boolean
firstFactors: [String!]
secondFactors: [String!]
secondFactorRequired: Boolean
appsRequireSecondFactor: Boolean
refuseBreachedPasswords: Boolean
riskStepUpAt: Int
riskRefuseAt: Int
sessionLifetime: Int
sessionIdleTimeout: Int
emailDomains: [String!]
providers: [String!]
everyProvider: Boolean
confirmation: String
hidden: Boolean
signupScopes: [String!]
key: ID!
CreateSignInPolicyPayload
updateSignInPolicy
name: String
signup: Boolean
nickname: String
email: String
emailVerified: Boolean
phone: String
phoneVerified: Boolean
passwordMinimum: Int
refuseCommonPasswords: Boolean
firstFactors: [String!]
secondFactors: [String!]
secondFactorRequired: Boolean
appsRequireSecondFactor: Boolean
refuseBreachedPasswords: Boolean
riskStepUpAt: Int
riskRefuseAt: Int
sessionLifetime: Int
sessionIdleTimeout: Int
emailDomains: [String!]
providers: [String!]
everyProvider: Boolean
confirmation: String
hidden: Boolean
signupScopes: [String!]
key: ID!
UpdateSignInPolicyPayload
archiveSignInPolicy
key: ID!
ArchiveSignInPolicyPayload
restoreSignInPolicy
key: ID!
RestoreSignInPolicyPayload
createAdapter
key: ID!
service: String!
name: String!
config: JSON
primary: Boolean
CreateAdapterPayload
updateAdapter
key: ID!
name: String
config: JSON
primary: Boolean
UpdateAdapterPayload
archiveAdapter
key: ID!
ArchiveAdapterPayload
restoreAdapter
key: ID!
RestoreAdapterPayload
testAdapter
key: ID!
to: String!
TestAdapterPayload
createEventStream
key: ID!
name: String!
url: String!
actions: [String!]
organization: ID
CreateEventStreamPayload
updateEventStream
key: ID!
name: String
url: String
actions: [String!]
organization: ID
UpdateEventStreamPayload
updateMailTemplate
kind: ID!
subject: String
message: String
UpdateMailTemplatePayload Sets the tenant’s wording for one kind of email. Leaving both the subject and the message blank goes back to the wording masks writes.
archiveEventStream
key: ID!
ArchiveEventStreamPayload
restoreEventStream
key: ID!
RestoreEventStreamPayload
rotateEventStreamSecret
key: ID!
RotateEventStreamSecretPayload
testEventStream
key: ID!
TestEventStreamPayload
createOrganization
key: ID!
name: String!
roles: [String!]
CreateOrganizationPayload Creates an organization, owned by the person who creates it.
updateOrganization
key: ID!
name: String
roles: [String!]
signInPolicy: ID
UpdateOrganizationPayload
archiveOrganization
key: ID!
ArchiveOrganizationPayload
restoreOrganization
key: ID!
RestoreOrganizationPayload
addMember
organization: ID!
role: String!
uuid: ID
email: String
AddMemberPayload Adds a person to an organization. Name an existing account by uuid, or an email address, which invites a new account when none holds it.
setMemberRole
organization: ID!
uuid: ID!
role: String!
SetMemberRolePayload
removeMember
organization: ID!
uuid: ID!
RemoveMemberPayload
resendOrganizationInvitation
organization: ID!
uuid: ID!
ResendOrganizationInvitationPayload Sends an organization invitation again and starts its lifetime over. An invitation is sent again at most once an hour.
setProviderOrganization
key: ID!
organization: ID
roleClaim: String
roleMap: JSON
unmappedRole: String
SetProviderOrganizationPayload Hands a provider to one organization, or back to the whole tenant. People who sign in through it become members, in the role their groups map to.
claimDomain
domain: String!
provider: ID
ClaimDomainPayload Starts claiming a domain. Publish the TXT record it returns, then check it.
checkDomain
domain: String!
CheckDomainPayload Looks up a claim’s TXT record now, instead of waiting for the hourly check.
updateDomainClaim
domain: String!
provider: ID
UpdateDomainClaimPayload
releaseDomain
domain: String!
ReleaseDomainPayload
serveDomain
host: String
ServeDomainPayload Serves sign-in from a host within a proven domain, such as login.example.com, or stops when host is null. The host is a second issuer, so apps that use it must name it.
exportEvents
from: ISO8601DateTime!
to: ISO8601DateTime!
action: String
organization: ID
actor: ID
ExportEventsPayload Prepares a download of every event in a range as newline-delimited JSON, one event per line in the shape event streams send. The link works for ten minutes, in a browser signed in as the manager who asked for it.
stageSigningKey StageSigningKeyPayload
activateSigningKey
kid: ID!
ActivateSigningKeyPayload
discardSigningKey
kid: ID!
DiscardSigningKeyPayload
rotateSigningKey RotateSigningKeyPayload

Autogenerated return type of ActivateSigningKey.

Field Type
signingKey SigningKey!
Field Type
date ISO8601Date!
signIns Int!
Field Type Description
uuid ID!
identifier String!
nickname String
email String
emailVerified Boolean!
phone String
phoneVerified Boolean!
signedUpAt ISO8601DateTime
pendingApproval Boolean!
suspendedAt ISO8601DateTime
externalId String The id a tenant-wide directory knows this actor by. An organization’s directory keeps its own on the membership.
activated Boolean!
invitedAt ISO8601DateTime
scopes [String!]!
otpEnabled Boolean!
emailCodesEnabled Boolean!
textCodesEnabled Boolean!
backupCodesRemaining Int!
passkeys [Passkey!]!
sessions [Session!]!
devices [Device!]!
connections [Connection!]!
consents [Consent!]!
tokens [Token!]!
memberships [Membership!]!
events
limit: Int
[Event!]!
backupCodesGeneratedAt ISO8601DateTime
lastLoginAt ISO8601DateTime
lastActiveAt ISO8601DateTime
idleWarnedAt ISO8601DateTime
createdAt ISO8601DateTime!
updatedAt ISO8601DateTime!
avatars Avatars!
photoUploaded Boolean!
name String
givenName String
familyName String
middleName String
profileUrl String
pictureUrl String
websiteUrl String
gender String
birthdate String
zoneinfo String
locale String
Field Type
key ID!
name String!
kind String!
service String!
label String!
primary Boolean!
settings JSON!
secretsHeld [String!]!
archivedAt ISO8601DateTime
createdAt ISO8601DateTime!
updatedAt ISO8601DateTime!
Field Type
key String!
label String!
type String!
secret Boolean!
required Boolean!
options [String!]
default JSON
hint String
Field Type
service ID!
kind String!
label String!
fields [AdapterField!]!

Autogenerated return type of AddMember.

Field Type
membership Membership!
delivered Boolean!
url String

Autogenerated return type of ApproveActor.

Field Type
actor Actor!

Autogenerated return type of ArchiveAdapter.

Field Type
adapter Adapter!

Autogenerated return type of ArchiveClient.

Field Type
client Client!

Autogenerated return type of ArchiveEventStream.

Field Type
eventStream EventStream!

Autogenerated return type of ArchiveOrganization.

Field Type
organization Organization!

Autogenerated return type of ArchiveProvider.

Field Type
provider Provider!

Autogenerated return type of ArchiveSignInPolicy.

Field Type
signInPolicy SignInPolicy!
Field Type
photo String
identicon String!
initials String!

Autogenerated return type of BlockDevice.

Field Type
device Device!

Autogenerated return type of BlockDevices.

Field Type
count Int!
spared Boolean!

Autogenerated return type of CheckDomain.

Field Type
domainClaim DomainClaim!
found Boolean!

Autogenerated return type of ClaimDomain.

Field Type
domainClaim DomainClaim!
Field Type Description
clientId ID!
name String!
redirectUris [String!]!
postLogoutRedirectUris [String!]!
grantTypes [String!]!
responseTypes [String!]!
resources [String!]!
requiredScopes [String!]!
allowedScopes [String!]!
namespaces [Namespace!]!
tokenEndpointAuthMethod String!
subjectType String!
dpopBoundAccessTokens Boolean!
sectorIdentifierUri String
applicationType String!
clientUri String
logoUri String
tosUri String
policyUri String
logoUrl
size: Int
String
backchannelLogoutUri String
backchannelLogoutSessionRequired Boolean!
requirePushedAuthorizationRequests Boolean!
jwks JSON
jwksUri String
consentLifetime Int Seconds a person’s consent lasts before they are asked again. Null lasts until revoked.
authorizationDetailsTypes [String!]! The types of authorization detail this client may ask for.
authorizationDetailsSchemas JSON! The types of authorization detail this client accepts as a resource, with the label and schema of each.
protocol String!
samlEntityId String
samlCertificate String
samlNameIdFormat String
samlRequestsSigned Boolean!
samlIdpInitiated Boolean!
samlAttributes JSON!
requireSignedRequestObject Boolean!
consentRequired Boolean!
signInPolicy SignInPolicy
dynamic Boolean!
approvedAt ISO8601DateTime
approvedBy Actor
archivedAt ISO8601DateTime
secretExpiresAt ISO8601DateTime
createdAt ISO8601DateTime!
delegations [Delegation!]!
consents
limit: Int
[Consent!]!
tokens
limit: Int
[Token!]!
events
limit: Int
[Event!]!
Field Type
id ID!
provider Provider!
actor Actor!
subject String!
label String
email String
emailVerified Boolean!
connectedAt ISO8601DateTime
signedInAt ISO8601DateTime
revokedAt ISO8601DateTime
revokedReason String
createdAt ISO8601DateTime!
delegable Boolean!
tokensRefreshedAt ISO8601DateTime
delegations [Delegation!]!
Field Type Description
id ID!
actor Actor!
client Client!
scopes [String!]!
audience [String!]!
authorizationDetails JSON! The authorization details the person allowed this client to ask for again without asking them, each with the time it expires.
expiresAt ISO8601DateTime When this consent ends and the person is asked again. Null lasts until revoked.
revokedAt ISO8601DateTime
createdAt ISO8601DateTime!
updatedAt ISO8601DateTime!

Autogenerated return type of CreateActor.

Field Type
actor Actor!
delivered Boolean!
url String

Autogenerated return type of CreateAdapter.

Field Type
adapter Adapter!

Autogenerated return type of CreateClient.

Field Type
client Client!
secret String

Autogenerated return type of CreateEventStream.

Field Type
eventStream EventStream!
secret String!

Autogenerated return type of CreateOrganization.

Field Type
organization Organization!

Autogenerated return type of CreateProvider.

Field Type
provider Provider!

Autogenerated return type of CreateSamlApplication.

Field Type
client Client!

Autogenerated return type of CreateSignInPolicy.

Field Type
signInPolicy SignInPolicy!
Field Type
id ID!
client Client!
actor Actor!
connection Connection!
provider Provider!
scopes [String!]!
consentedAt ISO8601DateTime!
releasedAt ISO8601DateTime
revokedAt ISO8601DateTime
revokedReason String

Autogenerated return type of DeleteActor.

Field Type
uuid ID!
identifier String!
Field Type
id ID!
label String!
name String
category String!
known Boolean!
userAgent String
ipAddress String
lastSeenAt ISO8601DateTime!
blockedAt ISO8601DateTime
createdAt ISO8601DateTime!
actors [Actor!]!
sessions [Session!]!

Autogenerated return type of DisableAuthenticator.

Field Type
actor Actor!

Autogenerated return type of DisableCodeFactor.

Field Type
actor Actor!

Autogenerated return type of DiscardSigningKey.

Field Type
kid ID!

Autogenerated return type of DiscoverProvider.

Field Type
issuer String!
authorizationUrl String!
tokenUrl String!
userinfoUrl String
jwksUri String!
scopesSupported [String!]!
Field Type Description
domain ID!
recordName String! The DNS name to publish a TXT record at.
recordValue String! The TXT record’s value.
verifiedAt ISO8601DateTime
checkedAt ISO8601DateTime
missingSince ISO8601DateTime When a proven record stopped answering. The claim is released a week later.
provider Provider The provider people with an address here are sent to.
Field Type
id ID!
action String!
label String!
createdAt ISO8601DateTime!
ipAddress String
userAgent String
details JSON!
actor Actor
by Actor
client Client
device Device
organization Organization
Field Type
action String!
label String!
Field Type Description
key ID!
name String!
url String!
actions [String!]!
organization Organization When set, only this organization’s events are sent.
lastDeliveredAt ISO8601DateTime
lastFailure String
archivedAt ISO8601DateTime
createdAt ISO8601DateTime!
updatedAt ISO8601DateTime!

Autogenerated return type of ExportEvents.

Field Type
url String!
count Int!
expiresAt ISO8601DateTime!

Autogenerated return type of GenerateBackupCodes.

Field Type
actor Actor!
codes [String!]!

Autogenerated return type of IssueProvisioningToken.

Field Type
provisioningToken ProvisioningToken!
secret String!
Field Type
key ID!
name String!
journey String!
heading String!
subject String!
from String!
to String!
html String
text String

The tenant’s own wording for one kind of email. masks still adds the button or code, how long it lasts, and the lines that keep a person safe.

Field Type Description
kind ID! Which email this changes, or signature for the closing lines every email ends with.
subject String The subject line. Blank keeps the one masks writes.
message String The opening text, in place of the one masks writes. A blank line starts a new paragraph. Blank keeps the one masks writes.
placeholders [String!]! The names this kind fills in when written as {{name}}.
updatedAt ISO8601DateTime
Field Type Description
actor Actor!
organization Organization!
role String!
pending Boolean! True until the person accepts. A pending membership grants nothing.
invitedBy Actor
invitedAs String The address an invitation went to. Only that address can accept it.
provisioned Boolean! True when a directory added this member through SCIM.
externalId String The id the organization’s directory knows this member by.
invitedAt ISO8601DateTime When the invitation was last sent.
expiresAt ISO8601DateTime When a pending invitation stops being accepted. Sending it again starts it over.
expired Boolean! True when the invitation can no longer be accepted.
createdAt ISO8601DateTime!
Field Type
name String!
resource String!
client Client
claimedAt ISO8601DateTime!
releasable Boolean!
scopes [String!]!
Field Type Description
uuid ID!
key ID!
name String!
roles [String!]! Every role a member can hold here, owner and member included.
members [Membership!]!
memberCount Int! Members who have accepted.
ownerCount Int! Members who have accepted and hold owner.
pendingCount Int! Invitations still open, neither accepted nor expired.
liveTokenCount Int! Live tokens issued for this organization. Archiving revokes them.
domains [DomainClaim!]! Domains claimed for this organization’s providers, proven or not.
provisioningTokens [ProvisioningToken!]! Live provisioning tokens that reach only this organization.
signInPolicy SignInPolicy The policy for signing in as a member, ahead of the app’s and the tenant’s.
providers [Provider!]!
events [Event!]! The organization’s most recent events.
archivedAt ISO8601DateTime
createdAt ISO8601DateTime!
Field Type
id ID!
label String!
aaguid String
certification String
compromise String
userVerified Boolean!
lastUsedAt ISO8601DateTime
createdAt ISO8601DateTime!
Field Type Description
key ID!
name String!
protocol String!
preset String
authorizationUrl String
tokenUrl String
userinfoUrl String
clientId String
emailsUrl String
claims JSON!
tokenAuthMethod String!
responseMode String
teamId String
keyId String
privateKeyHeld Boolean!
callbackUrl String!
idpEntityId String
idpSsoUrl String
idpCertificates String
metadataUrl String
metadataFetchedAt ISO8601DateTime
nameIdFormat String
spEntityId String
scopes [String!]!
authorizeParams JSON!
subjectClaim String!
secretHeld Boolean!
connections Int!
signedIn Int!
archivedAt ISO8601DateTime
organization Organization The organization whose people sign in through this provider, or null for the whole tenant.
roleClaim String The claim that lists a person’s groups. groups when null.
roleMap JSON! Groups mapped to organization roles. The first group a person holds wins.
unmappedRole String The role for someone in none of the mapped groups. member when null.
createdAt ISO8601DateTime!
issuer String
jwksUri String
jwksFetchedAt ISO8601DateTime
role String!
trustsEmail Boolean!
receivesSignals Boolean! Whether masks accepts the shared signals this provider sends to /ssf/events.
emailDomains [String!]!
signupScopes [String!]!
delegates Boolean!
delegatedScopes [String!]!
delegationParams JSON!
delegationScope String!
resourceUrl String
registrationUrl String
registeredAt ISO8601DateTime
delegations Int!
Field Type
key ID!
name String!
protocol String!
asks [String!]!
needs [String!]!
defaults JSON!
guide String
trustsEmail Boolean!
custom Boolean!
delegatedScopes [String!]!
delegates Boolean!
Field Type Description
id ID!
label String!
issuedBy Actor
organization Organization The one organization this token provisions into, or null for every account.
usedAt ISO8601DateTime
expiresAt ISO8601DateTime!
createdAt ISO8601DateTime!

Autogenerated return type of ReadSamlApplicationMetadata.

Field Type
entityId String
acsUrls [String!]!
certificate String
nameIdFormat String
requestsSigned Boolean!

Autogenerated return type of ReadSamlMetadata.

Field Type
idpEntityId String!
idpSsoUrl String!
idpCertificates String!

Autogenerated return type of RegisterProvider.

Field Type
provider Provider!

Autogenerated return type of ReleaseDomain.

Field Type
domain String!

Autogenerated return type of ReleaseNamespace.

Field Type
released String!

Autogenerated return type of RemoveAvatar.

Field Type
actor Actor!

Autogenerated return type of RemoveMember.

Field Type
organization Organization!

Autogenerated return type of ResendInvitation.

Field Type
actor Actor!
delivered Boolean!
url String

Autogenerated return type of ResendOrganizationInvitation.

Field Type
membership Membership!
delivered Boolean!
url String

Autogenerated return type of ResetPassword.

Field Type
actor Actor!
delivered Boolean!
url String

Autogenerated return type of RestoreActor.

Field Type
actor Actor!

Autogenerated return type of RestoreAdapter.

Field Type
adapter Adapter!

Autogenerated return type of RestoreClient.

Field Type
client Client!

Autogenerated return type of RestoreEventStream.

Field Type
eventStream EventStream!

Autogenerated return type of RestoreOrganization.

Field Type
organization Organization!

Autogenerated return type of RestoreProvider.

Field Type
provider Provider!

Autogenerated return type of RestoreSignInPolicy.

Field Type
signInPolicy SignInPolicy!

Autogenerated return type of RevokeConnection.

Field Type
connection Connection!

Autogenerated return type of RevokeConsent.

Field Type
consent Consent!

Autogenerated return type of RevokeDelegation.

Field Type
delegation Delegation!

Autogenerated return type of RevokePasskey.

Field Type
actor Actor!

Autogenerated return type of RevokeProvisioningToken.

Field Type
provisioningToken ProvisioningToken!

Autogenerated return type of RevokeSession.

Field Type
session Session!

Autogenerated return type of RevokeToken.

Field Type
revoked Int!
token Token!

Autogenerated return type of RotateClientSecret.

Field Type
client Client!
secret String!

Autogenerated return type of RotateEventStreamSecret.

Field Type
eventStream EventStream!
secret String!

Autogenerated return type of RotateSigningKey.

Field Type
signingKey SigningKey!

Autogenerated return type of ServeDomain.

Field Type
tenant Tenant!
Field Type
id ID!
actor Actor!
device Device
userAgent String
ipAddress String
authenticatedAt ISO8601DateTime
expiresAt ISO8601DateTime!
revokedAt ISO8601DateTime
createdAt ISO8601DateTime!

Autogenerated return type of SetActorScopes.

Field Type
actor Actor!

Autogenerated return type of SetMemberRole.

Field Type
membership Membership!

Autogenerated return type of SetProviderOrganization.

Field Type
provider Provider!
Field Type Description
key ID!
name String!
signup Boolean!
nickname String!
email String!
emailVerified Boolean!
phone String!
phoneVerified Boolean!
passwordMinimum Int!
refuseCommonPasswords Boolean!
firstFactors [String!]!
secondFactors [String!]!
secondFactorRequired Boolean!
appsRequireSecondFactor Boolean!
refuseBreachedPasswords Boolean!
riskStepUpAt Int
riskRefuseAt Int
sessionLifetime Int Seconds a session lasts after signing in, or null for 14 days.
sessionIdleTimeout Int Seconds of inactivity that end a session, or null.
emailDomains [String!]!
providers [String!]
confirmation String!
hidden Boolean!
signupScopes [String!]!
clients [Client!]!
default Boolean!
archivedAt ISO8601DateTime
createdAt ISO8601DateTime

Autogenerated return type of SignOutActor.

Field Type
actor Actor!

Autogenerated return type of SignOutDevice.

Field Type
device Device!
Field Type
kid ID!
algorithm String!
activatedAt ISO8601DateTime
retiredAt ISO8601DateTime
state String!
createdAt ISO8601DateTime!

Autogenerated return type of StageSigningKey.

Field Type
signingKey SigningKey!

Autogenerated return type of SuspendActor.

Field Type
actor Actor!
Field Type Description
actors Int!
clients Int!
devices Int!
organizations Int! Organizations that are not archived.
Field Type Description
uuid ID!
subdomain String!
customHost String The host sign-in is also served from, within a proven domain.
origins [String!]! Every origin this tenant answers on, each its own issuer.
name String!
namedBy String!
browsersOnly Boolean!
blockedAgents String
mails Boolean!
texts Boolean!
signInPolicy SignInPolicy
dynamicRegistration String!
dynamicClientScopes [String!]
suspendAfter Int
deleteAfter Int
riskyNetworks String Address ranges that add to a sign-in’s risk score, one per line.
eventRetentionDays Int! Days events are kept before they are deleted.
createdAt ISO8601DateTime!
signingKeys [SigningKey!]!

Autogenerated return type of TestAdapter.

Field Type
delivered Boolean!
failure String

Autogenerated return type of TestEventStream.

Field Type
delivered Boolean!
failure String
Field Type
id ID!
kind String!
actor Actor
client Client
device Device
session Session
scopes [String!]!
audience [String!]!
live Boolean!
parentId ID
authenticatedAt ISO8601DateTime
expiresAt ISO8601DateTime!
consumedAt ISO8601DateTime
createdAt ISO8601DateTime!

Autogenerated return type of UnblockDevice.

Field Type
device Device!

Autogenerated return type of UnblockDevices.

Field Type
count Int!

Autogenerated return type of UpdateActor.

Field Type
actor Actor!

Autogenerated return type of UpdateAdapter.

Field Type
adapter Adapter!

Autogenerated return type of UpdateClient.

Field Type
client Client!

Autogenerated return type of UpdateDomainClaim.

Field Type
domainClaim DomainClaim!

Autogenerated return type of UpdateEventStream.

Field Type
eventStream EventStream!

Autogenerated return type of UpdateMailTemplate.

Field Type
mailTemplate MailTemplate!

Autogenerated return type of UpdateOrganization.

Field Type
organization Organization!

Autogenerated return type of UpdateProvider.

Field Type
provider Provider!

Autogenerated return type of UpdateSignInPolicy.

Field Type
signInPolicy SignInPolicy!

Autogenerated return type of UpdateTenant.

Field Type
tenant Tenant!

Autogenerated return type of UploadAvatar.

Field Type
actor Actor!

Autogenerated return type of VerifyEmail.

Field Type
actor Actor!
delivered Boolean!
url String

An ISO 8601-encoded date

A scalar. Serialized as a string unless a client says otherwise.

An ISO 8601-encoded datetime

A scalar. Serialized as a string unless a client says otherwise.

Represents untyped JSON

A scalar. Serialized as a string unless a client says otherwise.

A scalar. Serialized as a string unless a client says otherwise.