API reference

Admin

The admin surface is operator-token-gated tenant onboarding. It lets an operator bootstrap a new tenant, its initial admin user, and an initial API key without running SQL.

Operator token#

The bearer token must equal the LIROVO_ADMIN_TOKEN Worker secret, not a tenant API key. When that secret is unset, the route is hidden and returns 404 (code NOT_FOUND) like an unmounted path. A bearer that is present but is not the configured admin token returns 403. Public signup is deferred to its own scope; this is the persistent operator and B2B path.

Create a tenant#

POST/v1/admin/tenants
Create a tenant plus an initial admin user and an initial API key. Returns 201. The response includes the plaintext initial API key, shown once.
namerequired
string

Tenant name, 1 to 200 characters.

admin_emailrequired
string (email)

Initial admin user email, up to 254 characters.

plan
string

One of free, starter, pro, teams, enterprise. Defaults to free.

region
string

One of us, eu. Defaults to us.

The 201 response carries { tenant, admin_user, initial_api_key }, where initial_api_key includes the one-time secret alongside its id, prefix, and scopes.

bash
curl -X POST https://api.lirovo.ai/v1/admin/tenants \
  -H "Authorization: Bearer $LIROVO_ADMIN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Acme Inc",
    "admin_email": "ops@acme.example",
    "plan": "pro",
    "region": "us"
  }'
Capture the initial key
The initial_api_key.secret is the plaintext key, shown only in this response. Capture it client-side; subsequent reads expose only the prefix.