Admin
The admin surface is operator-token-gated tenant onboarding. It lets an operator bootstrap a new tenant, its initial admin user, and an initial API key without running SQL.
Operator token#
The bearer token must equal the LIROVO_ADMIN_TOKEN Worker secret, not a tenant API key. When that secret is unset, the route is hidden and returns 404 (code NOT_FOUND) like an unmounted path. A bearer that is present but is not the configured admin token returns 403. Public signup is deferred to its own scope; this is the persistent operator and B2B path.
Create a tenant#
/v1/admin/tenants201. The response includes the plaintext initial API key, shown once.namerequiredTenant name, 1 to 200 characters.
admin_emailrequiredInitial admin user email, up to 254 characters.
planOne of free, starter, pro, teams, enterprise. Defaults to free.
regionOne of us, eu. Defaults to us.
The 201 response carries { tenant, admin_user, initial_api_key }, where initial_api_key includes the one-time secret alongside its id, prefix, and scopes.
curl -X POST https://api.lirovo.ai/v1/admin/tenants \
-H "Authorization: Bearer $LIROVO_ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Acme Inc",
"admin_email": "ops@acme.example",
"plan": "pro",
"region": "us"
}'initial_api_key.secret is the plaintext key, shown only in this response. Capture it client-side; subsequent reads expose only the prefix.