Skip to content

Revoke superuser role

POST
/api/v1/users/{id}/revoke-superuser
curl --request POST \
--url http://localhost:3000/api/v1/users/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/revoke-superuser \
--header 'X-API-Key: <X-API-Key>'

Revokes superuser (system admin) role from a user. Requires Super Admin privileges.

id
required
string format: uuid

User UUID

Superuser role revoked successfully

Media type application/json
object
id
required

Unique user identifier

string format: uuid
email
required

User email address

string format: email
name

User display name

string
active
required

Whether the user account is active

boolean
emailVerified
required

Whether the user email has been verified

boolean
isSuperAdmin
required

Whether the user is a super admin with platform-wide privileges

boolean
createdAt
required

When the user was created

string format: date-time
updatedAt
required

When the user was last updated

string format: date-time
lastLoginAt

When the user last logged in

string format: date-time
identityProvider

FM-1069: the Keycloak identity-provider alias the user last authenticated through (e.g. the Entra broker alias), or null for a local realm login.

string
isFederated
required

FM-1069: whether the user authenticates through an external identity provider (federated). The UI hides the password-reset action when true, since federated users have no local password to reset.

boolean
Example
{
"id": "550e8400-e29b-41d4-a716-446655440000",
"email": "john.doe@example.com",
"name": "John Doe",
"active": true,
"emailVerified": true,
"isSuperAdmin": false,
"createdAt": "2024-01-15T10:30:00Z",
"updatedAt": "2024-06-20T14:45:00Z",
"lastLoginAt": "2024-12-20T09:15:00Z",
"identityProvider": "entra",
"isFederated": false
}

User does not have superuser role

Unauthorized

Forbidden - Super Admin required

User not found