Skip to main content

GraphQL reference: user-management-admin

Generated from the schema this service serves, so it cannot fall behind it. The same schema is published as a file for tools and agents.

Endpointhttps://<your-host>/api/user-management/admin/graphql
Auth planeidentity — Instance-scoped administration. Takes the identity token login returns BEFORE a tenant is selected, and is authorized for the superuser or an operator. A tenant access token is rejected here.
Authorize withidentity token
Schema file/schema/user-management-admin.graphql
Described340 of 340 elements

Queries​

auditEvents · authorities · deadLetter · deadLetters · functionalAreas · governanceDimensions · identities · oauthClients · ping · roles · tenantDeletion · tenantDeletions · tenantTiers · tenants · tierColorPalette

auditEvents​

Searches the audit journal of sign-ins, token refreshes and administrative changes, across all tenants, newest first. Requires audit:read.

Returns AdminAuditEventSearchResults!

ArgumentTypeDescription
criteriaAdminAuditEventSearchCriteria!Filters and paging for the search.

authorities​

The authorities that can be granted to a role, sorted, including *. With a scope, only the authorities a role of that scope may grant, since a role cannot be granted an authority that belongs to the other scope. Fails if scope is neither system nor tenant. Requires role:read.

Returns [String!]!

ArgumentTypeDescription
scopeStringsystem or tenant. Omit it to list every authority.

deadLetter​

One dead-letter record by its id. Returns null if there is none; fails if the id is not a number. Requires audit:read.

Returns DeadLetter

ArgumentTypeDescription
idID!Id of the record, as returned in the id field.

deadLetters​

Searches the work the platform accepted and gave up on, across all tenants, newest first. Requires audit:read.

Returns DeadLetterSearchResults!

ArgumentTypeDescription
criteriaDeadLetterSearchCriteria!Filters and paging for the search.

functionalAreas​

The names of the functional areas deployed on this instance, so a client can tell a feature that was never deployed from a server that is failing. It reports what the operator enabled, not whether each area is healthy. Requires only a valid identity token.

Returns [String!]!

governanceDimensions​

The governance dimensions the platform defines, so an editor can offer exactly the settings a tier or tenant may carry. The answer does not depend on the tenant. Requires tenant:read.

Returns [AdminGovernanceDimension!]!

identities​

Every identity on the instance, with its system roles and memberships. The list is not paged. Requires user:read.

Returns [AdminIdentity!]!

oauthClients​

The registered OAuth clients. Requires client:read.

Returns [AdminOAuthClient!]!

ping​

Liveness check. Always returns the string "pong".

Returns String!

roles​

The role catalog, optionally limited to one scope. Fails if scope is neither system nor tenant. Requires role:read.

Returns [AdminRole!]!

ArgumentTypeDescription
scopeStringsystem or tenant. Omit it to list roles of both scopes.

tenantDeletion​

The deletion record for one tenant token, with the progress of each storage system. Returns null if there is no such record. Requires tenant:read.

Returns TenantDeletion

ArgumentTypeDescription
epochStringThe epoch of the deletion, as returned in the epoch field, to select a particular past deletion. Omit it to get the deletion currently in progress for the token. It must be an RFC 3339 timestamp and is matched exactly, fractional seconds included.
tokenString!Token of the deleted tenant.

tenantDeletions​

Tenant deletion records, newest first, including those that have finished. They cover the whole instance and outlive the tenants they describe. Requires tenant:read.

Returns TenantDeletionSearchResults!

ArgumentTypeDescription
criteriaTenantDeletionSearchCriteria!Paging and an optional filter on whether the deletion has finished.

tenantTiers​

The tier catalog in the operator's listing order. Requires tenant:read.

Returns [AdminTenantTier!]!

tenants​

Every tenant, including any that are being deleted. The list is not paged. Requires tenant:read.

Returns [AdminTenant!]!

tierColorPalette​

The color names a tier may be given. Requires tenant:read.

Returns TierColorPalette!

Mutations​

addMembership · createIdentity · createOauthClient · createRole · createTenant · createTenantTier · deleteIdentity · deleteOauthClient · deleteRole · deleteTenant · deleteTenantTier · removeMembership · reorderTenantTiers · rotateOauthClientSecret · setIdentityEnabled · setMembershipEnabled · setMembershipRoles · setOauthClientEnabled · setPassword · setSystemRoles · setTenantEnabled · updateOauthClient · updateRole · updateTenant · updateTenantTier

addMembership​

Adds an identity to a tenant with the given tenant roles and returns the identity. The membership starts enabled. Fails if the identity or tenant does not exist, if the tenant is being deleted, if a role does not exist with tenant scope, or if the identity is already a member of the tenant (error code CONFLICT). Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
roleTokens[String!]!Tokens of the tenant roles to grant in the tenant.
tenantString!Token of the tenant.

createIdentity​

Creates an identity with the given system roles and returns it. Fails if the email is already in use (error code CONFLICT), if the password is empty, or if a system role does not exist. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
requestAdminIdentityCreateRequest!The identity to create.

createOauthClient​

Registers an OAuth client and returns it. The client starts enabled. For a confidential client the response also carries its secret, shown only this once. Fails if the clientId is invalid or already used (error code CONFLICT), or a redirect address or scope is not acceptable. Requires client:write.

Returns AdminOAuthClientSecret!

ArgumentTypeDescription
requestAdminOAuthClientCreateRequest!The client to register.

createRole​

Creates a role and returns it. Fails if the scope is not system or tenant, if an authority is unknown or belongs to the other scope, or if the token is already used in that scope (error code CONFLICT). Requires role:write.

Returns AdminRole!

ArgumentTypeDescription
requestAdminRoleCreateRequest!The role to create.

createTenant​

Creates a tenant at the given tier and returns it. The tenant starts enabled. Fails if the tier does not exist, a limit is out of range, the token is already used by an active tenant (error code CONFLICT), or the token is reserved by a tenant that is still being deleted. Requires tenant:write.

Returns AdminTenant!

ArgumentTypeDescription
requestAdminTenantCreateRequest!The tenant to create.

createTenantTier​

Creates a tier and returns it. It is placed at display order 0. Fails if the config has an unknown key or an out-of-range value, if the color is not in the palette, or if the token is already used (error code CONFLICT). The catalog holds at most 100 tiers; a create beyond that is refused with error code LIMIT_EXCEEDED. Requires tenant:write.

Returns AdminTenantTier!

ArgumentTypeDescription
requestAdminTenantTierCreateRequest!The tier to create.

deleteIdentity​

Deletes an identity together with its memberships. Returns true if one was deleted and false if there was no such identity. Its sessions end with it, and an identity later created with the same email does not inherit them. Requires user:write.

Returns Boolean!

ArgumentTypeDescription
emailString!Email of the identity.

deleteOauthClient​

Deletes a client. Returns true if it was deleted and false if there was no such client. Requires client:write.

Returns Boolean!

ArgumentTypeDescription
clientIdString!The clientId of the client to delete.

deleteRole​

Deletes a role and removes it from everything it was assigned to. Returns true if it was deleted and false if there was no such role. The superuser system role cannot be deleted, so the instance cannot be locked out of this API. Requires role:write.

Returns Boolean!

ArgumentTypeDescription
scopeString!system or tenant: the scope of the role to delete.
tokenString!Token of the role to delete.

deleteTenant​

Begins permanently deleting a tenant, which cannot be undone. Sign-ins and token refreshes for the tenant are refused at once for its members (a superuser can still enter, to operate the deletion), and its data is then erased from every storage system in the background; track that with tenantDeletion. Returning true means the deletion has started, not that the data is already gone. The tenant's token stays reserved until the deletion completes (see tenantDeletion). Returns false, changing nothing, if there is no such tenant or it is already being deleted. Fails (error code REFERENCE_VIOLATION) while any identity still has a membership in the tenant: remove the memberships first. Requires tenant:write.

Returns Boolean!

ArgumentTypeDescription
tokenString!Token of the tenant to delete.

deleteTenantTier​

Deletes a tier. Returns true if it was deleted and false if there was no such tier. Fails (error code REFERENCE_VIOLATION) while any tenant is still at the tier. Requires tenant:write.

Returns Boolean!

ArgumentTypeDescription
tokenString!Token of the tier to delete.

removeMembership​

Removes an identity's membership in a tenant and returns the identity. Fails if the identity has no membership in the tenant. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
tenantString!Token of the tenant.

reorderTenantTiers​

Sets the listing order of the tiers and returns them in the new order. The list must name every existing tier exactly once; if it omits, repeats or invents a tier the request fails and nothing changes, which also catches a client working from a stale list. A list longer than 100 (the catalog's own bound), or a token longer than 128 characters, is refused with error code LIMIT_EXCEEDED. It changes only how tiers are ordered in lists, not what any tier grants. Requires tenant:write.

Returns [AdminTenantTier!]!

ArgumentTypeDescription
orderedTokens[String!]!Tokens of every tier, in the desired order, first to last.

rotateOauthClientSecret​

Generates a new secret for a client and returns it once, invalidating the previous secret. Rotating the secret of a public client makes it a confidential client. Fails if the client does not exist. Requires client:write.

Returns AdminOAuthClientSecret!

ArgumentTypeDescription
clientIdString!The clientId of the client.

setIdentityEnabled​

Enables or disables an identity and returns it. A disabled identity cannot sign in. Disabling also ends every session the identity has, so re-enabling does not revive them; tokens already issued stop working when they expire (15 minutes by default). Fails if the identity does not exist. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
enabledBoolean!True to enable, false to disable.

setMembershipEnabled​

Enables or disables an identity's membership in a tenant and returns the identity. A disabled membership cannot be used to enter the tenant. Fails if the identity has no membership in the tenant. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
enabledBoolean!True to enable, false to disable.
tenantString!Token of the tenant.

setMembershipRoles​

Replaces the tenant roles an identity holds in a tenant with exactly those given and returns the identity. Fails if the identity has no membership in the tenant or a role does not exist with tenant scope. Already-issued access tokens keep their old authorities until they expire; a refresh picks up the change. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
roleTokens[String!]!Tokens of the tenant roles the identity should hold in the tenant.
tenantString!Token of the tenant.

setOauthClientEnabled​

Enables or disables a client and returns it. A disabled client is rejected at the authorization and token endpoints. Fails if the client does not exist. Requires client:write.

Returns AdminOAuthClient!

ArgumentTypeDescription
clientIdString!The clientId of the client.
enabledBoolean!True to enable, false to disable.

setPassword​

Replaces an identity's password and returns the identity. This also ends every session the identity has, so it must sign in again; tokens already issued stop working when they expire (15 minutes by default). Fails if the password is empty or the identity does not exist. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
passwordString!The new password. It must not be empty.

setSystemRoles​

Replaces the identity's system roles with exactly those given and returns the identity. An empty list removes them all. Fails if the identity does not exist or a role does not exist with system scope. Requires user:write.

Returns AdminIdentity!

ArgumentTypeDescription
emailString!Email of the identity.
roleTokens[String!]!Tokens of the system roles the identity should hold.

setTenantEnabled​

Enables or disables a tenant and returns it. Members of a disabled tenant cannot enter it (a superuser still can); sessions already open are refused at their next refresh. Fails if the tenant does not exist. Requires tenant:write.

Returns AdminTenant!

ArgumentTypeDescription
enabledBoolean!True to enable, false to disable.
tokenString!Token of the tenant.

updateOauthClient​

Applies a partial update to a client and returns it. Neither the redirect addresses nor the scopes may be emptied. Fails if the client does not exist or a value is not acceptable. Requires client:write.

Returns AdminOAuthClient!

ArgumentTypeDescription
clientIdString!The clientId of the client to update.
requestAdminOAuthClientUpdateRequest!The changes to apply.

updateRole​

Applies a partial update to a role and returns it. Fails if the role does not exist or the resulting authorities are not valid for its scope. Requires role:write.

Returns AdminRole!

ArgumentTypeDescription
requestAdminRoleUpdateRequest!The changes to apply.
scopeString!system or tenant: the scope of the role to update.
tokenString!Token of the role to update.

updateTenant​

Applies a partial update to a tenant and returns it. If any value is invalid the whole update is rejected and nothing is changed. Fails if the tenant does not exist. Requires tenant:write.

Returns AdminTenant!

ArgumentTypeDescription
requestAdminTenantUpdateRequest!The changes to apply.
tokenString!Token of the tenant to update.

updateTenantTier​

Applies a partial update to a tier and returns it. This changes the limits of every tenant at the tier, taking effect within about a minute and without a deployment. Fails if the tier does not exist, the config has an unknown key or an out-of-range value, or the color is not in the palette. Requires tenant:write.

Returns AdminTenantTier!

ArgumentTypeDescription
requestAdminTenantTierUpdateRequest!The changes to apply.
tokenString!Token of the tier to update.

Objects​

AdminAuditEvent · AdminAuditEventSearchResults · AdminBurstSetting · AdminGovernanceDimension · AdminIdentity · AdminMembership · AdminOAuthClient · AdminOAuthClientSecret · AdminRateSetting · AdminRole · AdminTenant · AdminTenantSetting · AdminTenantTier · DeadLetter · DeadLetterSearchResults · SearchResultsPagination · TenantDeletion · TenantDeletionSearchResults · TenantDeletionStore · TierColorPalette

AdminAuditEvent​

object

One entry in the instance's audit journal: either a sign-in or token refresh, or a change to one of this service's records (identities, roles, tenants, memberships and the like), including a tenant's own self-service changes. The journal covers the whole instance, not one tenant.

FieldTypeDescription
actorString!Who performed the action: the subject of the token that made the request, which is the user's email address for a person, system for an action the platform took itself, or an empty string when it was not recorded. Emptied for a tenant that has been deleted.
categoryString!auth for a sign-in or token refresh, or mutation for a change to stored data.
entityLabelStringA readable label for the changed record, such as a role or tenant token or an identity's email, when one is available. Null otherwise, and always cleared for a tenant that has been deleted, so the journal keeps the fact of the deletion but not what was deleted.
entityPkStringIdentifier of the changed record, when a single record was changed. Null otherwise.
idID!Server-assigned identifier of the entry.
occurredTimeString!When the event happened, as an RFC 3339 timestamp.
operationString!What happened: login, login_failed or refresh for an auth entry; create, update or delete for a mutation entry.
rowsAffectedInt!How many records the change affected.
tableNameStringQualified name of the stored collection that was changed. Null for an auth entry.
tenantStringToken of the tenant the entry belongs to. Null for events that belong to no tenant, such as signing in before a tenant is chosen.

AdminAuditEventSearchResults​

object

One page of audit journal entries, newest first.

FieldTypeDescription
paginationSearchResultsPagination!Where this page sits in the full result set.
results[AdminAuditEvent!]!The entries on this page, newest first.

AdminBurstSetting​

object

The burst allowance that applies to a tenant for one dimension, with where it came from. It is the same as AdminRateSetting except that a burst is a whole count.

FieldTypeDescription
overrideIntThe tenant's own override for this dimension. Null if it has none.
sourceString!Which level supplied the value: override, tier or platform-default, as for AdminRateSetting.
tierIntWhat the tenant's tier sets for this dimension. Null if the tier sets none.
valueIntThe burst allowance in force. Null when source is platform-default; null does not mean unlimited.

AdminGovernanceDimension​

object

A kind of usage the platform limits per tenant, expressed as a sustained rate plus a burst allowance. A tier or a tenant may set limits for each dimension.

FieldTypeDescription
burstFieldString!Name of the setting that holds this dimension's burst allowance, used the same way as rateField.
labelString!Human-readable heading for the dimension, such as "Ingest".
nameString!Short stable identifier of the dimension, such as ingest.
rateFieldString!Name of the setting that holds this dimension's rate. It is both the key used in a tier's config and the name of the matching field on tenants and tenant requests.
rateUnitString!The unit the rate is expressed in, such as readings/sec or requests/min. Bursts are plain counts of the same thing and carry no unit.

AdminIdentity​

object

A user account, which exists once across the whole instance and is identified by its email address. It can belong to any number of tenants through memberships.

FieldTypeDescription
createdAtStringWhen the identity was created, as an RFC 3339 timestamp.
emailString!The identity's email address, stored lower-cased. It is the sign-in name and cannot be changed.
enabledBoolean!False when the identity is disabled and cannot sign in.
firstNameStringFirst name. Null when none has been set.
idID!Server-assigned identifier. Address an identity by its email, not by this.
lastNameStringLast name. Null when none has been set.
memberships[AdminMembership!]!The tenants the identity belongs to, each with its roles there.
systemRoles[String!]!Tokens of the system roles the identity holds. System roles grant instance-level authorities, such as administering tenants or users, rather than authority inside a tenant.
updatedAtStringWhen the identity was last changed, as an RFC 3339 timestamp.

AdminMembership​

object

An identity's membership in one tenant: whether it is active and which tenant roles the identity holds there.

FieldTypeDescription
enabledBoolean!False when the membership is disabled, so the identity cannot enter the tenant through it.
roles[String!]!Tokens of the tenant-scoped roles the identity holds in this tenant.
tenantString!Token of the tenant.

AdminOAuthClient​

object

A client application registered to sign users in through the platform's OAuth 2.1 authorization flow. A client can only use the redirect addresses and scopes registered here. The client's secret is never readable.

FieldTypeDescription
clientIdString!The client's public identifier, as presented in authorization requests. It cannot be changed.
createdAtStringWhen the client was registered, as an RFC 3339 timestamp.
descriptionStringFree-text description. Null when none has been set.
enabledBoolean!False when the client is disabled; the authorization and token endpoints then reject it.
hasSecretBoolean!True for a confidential client, which authenticates with a secret. False for a public client, which authenticates with PKCE instead.
idID!Server-assigned identifier. Address a client by its clientId, not by this.
nameStringHuman-readable name. Null when none has been set.
redirectUris[String!]!The redirect addresses the client may use. A request must match one of them exactly.
scopes[String!]!The scopes the client may request.
updatedAtStringWhen the client was last changed, as an RFC 3339 timestamp.

AdminOAuthClientSecret​

object

The result of registering a client or rotating its secret. This is the only time the secret is shown.

FieldTypeDescription
clientAdminOAuthClient!The registered client as it now stands.
clientSecretStringThe client's secret in clear text, returned only in this response and stored only as a hash, so it cannot be retrieved again; keep it now. Null when the client is public.

AdminRateSetting​

object

The rate limit that applies to a tenant for one dimension, with where it came from, so you can see both the result and the levels behind it.

FieldTypeDescription
overrideFloatThe tenant's own override for this dimension. Null if it has none.
sourceString!Which level supplied the value: override (the tenant's own setting), tier (its tier's setting) or platform-default (neither sets one).
tierFloatWhat the tenant's tier sets for this dimension. Null if the tier sets none.
valueFloatThe rate in force, in the dimension's rate unit. Null when source is platform-default: each service applies its own built-in default, which this API does not report. Null does not mean unlimited.

AdminRole​

object

A named bundle of authorities that can be granted to identities. A system role carries instance-level authorities and is assigned to an identity; a tenant role carries authorities within one tenant and is assigned to a membership.

FieldTypeDescription
authorities[String!]!The authorities the role grants, such as device:write. The single value * grants every authority available at the role's scope. May be empty.
createdAtStringWhen the role was created, as an RFC 3339 timestamp.
descriptionStringFree-text description. Null when none has been set.
idID!Server-assigned identifier. Address a role by its scope and token, not by this.
nameStringHuman-readable name. Null when none has been set.
scopeString!Either system or tenant: who the role can be assigned to and which authorities it can grant.
tokenString!Identifier of the role, unique within its scope.
updatedAtStringWhen the role was last changed, as an RFC 3339 timestamp.

AdminTenant​

object

A tenant: an isolated customer environment that has its own devices and data. This is the operator's view of the tenant's registry entry, its limits and its deletion status.

FieldTypeDescription
aiExternalEnabledBooleanWhether the tenant has agreed to have its data sent to an external AI model provider. Null and false both mean it has not; only true allows it.
aiInferenceBurstIntThe tenant's own override of its AI inference burst allowance, in requests. Null means no override.
aiInferenceRequestsPerMinuteFloatThe tenant's own override of its sustained AI inference rate, in requests per minute. Null means no override: the tier's value applies, then the platform default; it never means unlimited.
configStringFree-form settings for the tenant as a JSON object serialized to a string. The platform stores it as given. Null when the tenant has none.
createdAtStringWhen the tenant was created, as an RFC 3339 timestamp.
effectiveSettings[AdminTenantSetting!]!What the tenant is actually limited to for each governance dimension, and which level set it. This is the result of applying the tenant's own overrides on top of its tier; use it to see the limit in force rather than to read the override fields.
enabledBoolean!False when the tenant is disabled. Members cannot enter a disabled tenant, though a superuser still can.
geoFenceCeilingIntThe tenant's own override of the most geofences it may have. Null means no override: the tier's value applies, then the platform default.
geoFencePositionBudgetIntThe tenant's own override of the most positions its geofences may have in total, summed across all fences. Null means no override: the tier's value applies, then the platform default.
geoFencePositionCeilingIntThe tenant's own override of the most positions one geofence may have, counted across all of its rings. Null means no override: the tier's value applies, then the platform default. It never means unlimited.
heldCommandCeilingIntThe tenant's own override of how many commands may be held waiting for offline devices. Null means no override: the tier's value applies, then the command service's default. It never means unlimited.
idID!Server-assigned identifier. Address a tenant by its token, not by this.
ingestBurstIntThe tenant's own override of its ingest burst allowance, in readings. Null means no override.
ingestReadingsPerSecondFloatThis tenant's own ingest ceiling override, in readings (decoded samples) per second. Null means the tenant inherits its tier's ceiling, then the platform default.
nameStringHuman-readable name. Null when none has been set.
outboundBurstIntThe tenant's own override of its outbound burst allowance, in calls. Null means no override.
outboundCallsPerSecondFloatThis tenant's own outbound ceiling override, in connector calls dispatched per second. Null means the tenant inherits its tier's ceiling, then the platform default.
purgeEpochStringWhen deletion of the tenant was requested, as an RFC 3339 timestamp. Null while the tenant is active. Together with the token it identifies this deletion in tenantDeletion.
purgeStateString!Where the tenant is in its deletion lifecycle: active normally, or purging once deleteTenant has been called. A purging tenant stays in the registry, and keeps its token reserved, until the deletion completes: its data erased everywhere and the settling and token-hold periods over; the entry then disappears.
shedPriorityIntThe tenant's own override of its overload-protection priority, a whole number from 1 to 100, higher meaning the tenant's traffic is refused later when the platform is overloaded. Null means no override: the tier's value applies, then the platform default.
tierAdminTenantTier!The tier the tenant is packaged at. Every tenant has exactly one.
tokenString!Unique identifier of the tenant on this instance. It cannot be changed.
updatedAtStringWhen the tenant was last changed, as an RFC 3339 timestamp.

AdminTenantSetting​

object

The limits in force for a tenant on one governance dimension.

FieldTypeDescription
burstAdminBurstSetting!The burst allowance.
dimensionAdminGovernanceDimension!The dimension these limits apply to.
rateAdminRateSetting!The sustained rate limit.

AdminTenantTier​

object

A named packaging level, such as gold, silver or bronze, that an operator assigns to tenants. A tier supplies default limits for the tenants at it, and a tenant's own settings override them. Editing a tier changes every tenant at it.

FieldTypeDescription
colorStringName of the color the console shows for this tier, one of those listed by tierColorPalette, or null for no color. Presentation only.
configStringThe tier's settings as a JSON object serialized to a string, or null when it has none. The keys are the governance setting names listed by governanceDimensions (the rate and burst fields) together with shedPriority, heldCommandCeiling, geoFencePositionCeiling, geoFenceCeiling and geoFencePositionBudget. A tenant that has no setting of its own for a key takes the tier's value.
createdAtStringWhen the tier was created, as an RFC 3339 timestamp.
descriptionStringFree-text description of the tier. Null when none has been set.
displayOrderInt!Position of the tier in the operator's listing order, counting up from 0. It only orders lists: a higher position does not make a tier a superset of a lower one. A new tier starts at 0 and tiers with the same position are listed alphabetically by token, until the order is set with reorderTenantTiers.
idID!Server-assigned identifier. Address a tier by its token, not by this.
nameStringHuman-readable name of the tier. Null when none has been set.
tenantCountInt!The number of active tenants at this tier, not counting tenants being deleted. A tier cannot be deleted while any tenant, including one still being deleted, is at it.
tokenString!Unique identifier of the tier.
updatedAtStringWhen the tier was last changed, as an RFC 3339 timestamp.

DeadLetter​

object

A unit of work the platform accepted and then gave up on, recorded so that the failure can be seen and diagnosed. The record is informational: the work is not retried from it, and the consequence of the failure stands.

FieldTypeDescription
attemptsInt!How many delivery attempts were made before giving up.
correlationStringIdentifier of the request the work belonged to, for matching against logs. Null when not recorded.
detailStringThe underlying error text. It can name destinations a tenant configured, so treat it as operator-only. Null when there is nothing to add.
idID!Server-assigned identifier of the record, as accepted by the deadLetter query.
kindString!What kind of work was given up on: detection-action, notification, command-response, connector-dispatch, event, command or control-fact. For connector-dispatch the record is only an index entry, with no copy of the request.
occurredTimeString!When the platform gave up, as an RFC 3339 timestamp.
reasonString!Why the work was given up on: exhausted (retried up to the limit), unprocessable (accepted, but can never be completed), shed (refused because the tenant stayed over its rate limit for too long; the work itself was fine and was never attempted) or no-outcome (every delivery ended without an outcome being recorded, so the work may in fact have happened).
referenceStringIdentifier of the specific thing that failed within its kind, such as a rule, alarm or command token. Null when not recorded.
sequenceStringPosition of the original message in its stream, as a decimal string because the value can exceed what a GraphQL Int holds. Null when not recorded.
sourceString!Name of the functional area that gave up.
subjectStringWhere the original message was published, for locating it while the platform still retains it. Null when not recorded.
summaryString!A fixed sentence describing the class of failure. Safe to show to anyone.
tenantString!Token of the tenant whose work this was.

DeadLetterSearchResults​

object

One page of dead letters, newest first.

FieldTypeDescription
paginationSearchResultsPagination!Where this page sits in the full result set.
results[DeadLetter!]!The records on this page, newest first.

SearchResultsPagination​

object

Where a page of search results sits in the full result set. Positions are 1-based and inclusive.

FieldTypeDescription
pageEndIntPosition of the last result on this page within the full result set (1-based, inclusive).
pageStartIntPosition of the first result on this page within the full result set (1-based).
totalRecordsIntNumber of records matching the criteria across all pages.

TenantDeletion​

object

The durable record of one tenant deletion. It outlives the tenant: once the deletion completes the tenant is gone, and this record is the evidence that its data was erased. It deliberately holds no tenant name.

FieldTypeDescription
awaitingDeletionWait!What the deletion is currently waiting on.
blockedBy[String!]!One sentence for each storage system that is not yet clean, in that system's own words. Empty means nothing is blocking, which is not the same as finished: the deletion may still be waiting out a settling period or the token hold.
completedAtStringWhen every storage system had reported clean and the token was released, as an RFC 3339 timestamp. Null while the deletion is in progress.
elapsesAtStringWhen the current waiting period ends, as an RFC 3339 timestamp. Null when the wait is not a timed period: while awaiting is STORES the deletion waits on the systems, not on a clock, and when awaiting is NONE nothing is pending.
epochString!When the deletion was requested, as an RFC 3339 timestamp with fractional seconds. With the token it identifies the record; pass it back exactly as returned.
rowsErasedInt!Total number of records erased across all storage systems.
stores[TenantDeletionStore!]!One line per storage system, ordered by name.
tokenString!Token of the deleted tenant. A token can be reused after a deletion finishes, so it identifies a deletion only together with epoch.

TenantDeletionSearchResults​

object

One page of tenant deletion records, newest first.

FieldTypeDescription
paginationSearchResultsPagination!Where this page sits in the full result set.
results[TenantDeletion!]!The deletion records on this page, newest first.

TenantDeletionStore​

object

One storage system's line in a tenant deletion's progress record.

FieldTypeDescription
attemptedAtStringWhen this storage system was last checked, as an RFC 3339 timestamp. Null if it has not been checked yet.
cleanSinceStringWhen this storage system first reported clean and has stayed clean on every check since, as an RFC 3339 timestamp. Null unless it is clean now.
completeBoolean!True once this storage system has reported that it holds nothing for the tenant.
lastErrorStringA sentence describing why the latest pass could not confirm this storage system is clean. Null when it succeeded. Unlike retaining, this is expected to clear by itself on a later pass.
noteStringA sentence describing something this storage system deliberately did not examine, or why it reported clean while erasing nothing, such as a store that does not exist on this instance. It qualifies a clean result and is not a problem to act on.
retainingStringA sentence describing data this storage system still holds and has not erased. Null means it holds nothing outstanding. While set it blocks the deletion from finishing and does not clear by itself; something has to change first.
rowsErasedInt!How much this storage system has erased so far, in records, counted across all passes. It shows that erasure ran; it is not a percentage of progress.
storeString!Short key of the storage system this line reports on, such as rdb for the relational database or blob for the object store.

TierColorPalette​

object

The fixed set of color names a tier may be given.

FieldTypeDescription
colors[String!]!The color names, in the order a picker should present them.

Input types​

AdminAuditEventSearchCriteria · AdminIdentityCreateRequest · AdminOAuthClientCreateRequest · AdminOAuthClientUpdateRequest · AdminRoleCreateRequest · AdminRoleUpdateRequest · AdminTenantCreateRequest · AdminTenantTierCreateRequest · AdminTenantTierUpdateRequest · AdminTenantUpdateRequest · DeadLetterSearchCriteria · TenantDeletionSearchCriteria

AdminAuditEventSearchCriteria​

input

Filters and paging for searching the audit journal. Every filter is optional and filters are combined with AND.

Input fieldTypeDescription
actorStringOnly entries whose actor contains this text. The match ignores case.
categoryStringOnly entries of this category, auth or mutation. Exact match.
endTimeStringOnly entries at or before this time, as an RFC 3339 timestamp.
operationStringOnly entries of this operation, such as login or update. Exact match.
pageNumberInt!Page to return, starting at 1.
pageSizeInt!Results per page. Below 1 means the default of 100; above 1000 is capped at 1000.
startTimeStringOnly entries at or after this time, as an RFC 3339 timestamp.
tenantStringOnly entries belonging to the tenant with this token. Exact match. Entries that belong to no tenant are excluded when this is set.

AdminIdentityCreateRequest​

input

Fields for a new identity.

Input fieldTypeDescription
emailString!The identity's email address. It becomes the sign-in name, is stored lower-cased and cannot be changed. It must not already be in use.
enabledBoolean!Whether the identity may sign in. Send false to create it disabled.
firstNameStringGiven name, shown in the console. A blank value is stored as unset.
lastNameStringFamily name, shown in the console. A blank value is stored as unset.
passwordString!The initial password. It must not be empty. It is stored hashed and cannot be read back.
systemRoles[String!]!Tokens of the system roles to assign. Each must name an existing role with system scope; an empty list assigns none.

AdminOAuthClientCreateRequest​

input

Fields for registering an OAuth client.

Input fieldTypeDescription
clientIdString!The client's public identifier: letters, digits, -, _ and ., at most 128 characters. It cannot be changed.
confidentialBooleanTrue to register a confidential client, for which a secret is generated and returned once. False or omitted registers a public client that uses PKCE.
descriptionStringFree-text description.
nameStringHuman-readable name.
redirectUris[String!]!The redirect addresses the client may use; at least one and at most 16, each at most 2048 characters. Each must be an absolute https URL with no fragment and no embedded credentials. Plain http is accepted only for loopback hosts (localhost, 127.0.0.1, ::1). A longer list or entry is refused with error code LIMIT_EXCEEDED.
scopes[String!]!The scopes the client may request; at least one and at most 16, each at most 64 characters. Supported scopes are read-only and location. A longer list or entry is refused with error code LIMIT_EXCEEDED.

AdminOAuthClientUpdateRequest​

input

A partial update to an OAuth client. Omit a field to keep it, send a value to set it, or send null to clear it. The client is named by the mutation's clientId argument, which cannot be changed.

Input fieldTypeDescription
descriptionStringNew description, or null to clear it.
nameStringNew name, or null to clear it.
redirectUris[String!]The complete new list of redirect addresses, replacing the current list and validated as for registration, including its bounds (at most 16, each at most 2048 characters; more is refused with error code LIMIT_EXCEEDED). It cannot be emptied: null or an empty list is rejected, so to keep the list unchanged omit the field.
scopes[String!]The complete new list of scopes the client may request, replacing the current list and validated as for registration, including its bounds (at most 16, each at most 64 characters; more is refused with error code LIMIT_EXCEEDED). It cannot be emptied: null or an empty list is rejected, so to keep the list unchanged omit the field.

AdminRoleCreateRequest​

input

Fields for a new role.

Input fieldTypeDescription
authorities[String!]!The authorities to grant, as listed by the authorities query for the same scope; * is allowed at either scope. An unknown authority, or one that belongs to the other scope, rejects the request. An empty list creates a role that grants nothing.
descriptionStringFree-text description.
nameStringHuman-readable name.
scopeString!system or tenant. A role's scope cannot be changed afterwards.
tokenString!Identifier for the role, unique within its scope.

AdminRoleUpdateRequest​

input

A partial update to a role. Omit a field to keep it, send a value to set it, or send null to clear it. The role is named by the mutation's scope and token arguments, which cannot be changed.

Input fieldTypeDescription
authorities[String!]The complete new set of authorities, replacing the current set. Null and an empty list both leave the role granting nothing. Validated as for creation; an unknown authority, or one that belongs to the other scope, rejects the whole update.
descriptionStringNew description, or null to clear it.
nameStringNew name, or null to clear it.

AdminTenantCreateRequest​

input

Fields for a new tenant.

Input fieldTypeDescription
aiExternalEnabledBooleanRecords the tenant's agreement to have its data sent to an external AI model provider. Omit it for not agreed.
aiInferenceBurstIntOverride of the AI inference burst allowance, in requests. Must be positive. Omit to inherit.
aiInferenceRequestsPerMinuteFloatOverride of the sustained AI inference rate in requests per minute. Must be positive. Omit to inherit.
configStringFree-form settings as a JSON object serialized to a string. Omit it, or send an empty string or {}, for none.
geoFenceCeilingIntOverride of the most geofences the tenant may have. A positive whole number of at most 4000; a larger value is rejected, not clamped. Omit to inherit.
geoFencePositionBudgetIntOverride of the most positions the tenant's geofences may have in total. A positive whole number of at most 128000; a larger value is rejected, not clamped. Omit to inherit.
geoFencePositionCeilingIntOverride of the most positions one geofence may have, across all of its rings. A positive whole number of at most 1024; a larger value is rejected, not clamped. Omit to inherit.
heldCommandCeilingIntOverride of how many commands may be held waiting for offline devices. Any positive whole number. Omit to inherit the tier's value, then the command service's default.
ingestBurstIntOverride of the ingest burst allowance, in readings. Must be positive. Omit to inherit.
ingestReadingsPerSecondFloatIngest ceiling override, in readings (decoded samples) per second. Must be positive; omit it to inherit the tier's ceiling, then the platform default.
nameStringHuman-readable name.
outboundBurstIntOverride of the outbound burst allowance, in calls. Must be positive. Omit to inherit.
outboundCallsPerSecondFloatOutbound ceiling override, in connector calls dispatched per second. Must be positive; omit it to inherit the tier's ceiling, then the platform default.
shedPriorityIntOverride of the overload-protection priority: a whole number from 1 to 100, higher meaning the tenant's traffic is refused later when the platform is overloaded; 80 to 100 is never refused. Omit to inherit the tier's value, then the platform default.
tierTokenString!Token of the tier to package the tenant at. The tier must exist.
tokenString!Unique identifier for the tenant: letters, digits, hyphens and underscores, starting with a letter or digit, at most 128 characters. It cannot be changed. A token that belongs to a tenant being deleted is reserved and is refused until that deletion finishes.

AdminTenantTierCreateRequest​

input

Fields for a new tenant tier.

Input fieldTypeDescription
colorStringA color name from tierColorPalette. Omit it, or send null or an empty string, for no color; an unknown name rejects the request.
configStringThe tier's settings as a JSON object serialized to a string, using the keys described on AdminTenantTier.config. An unknown key, or a value outside its allowed range, rejects the request. Omit it, or send an empty string or {}, for a tier with no settings.
descriptionStringFree-text description.
nameStringHuman-readable name.
tokenString!Unique identifier for the tier: letters, digits, hyphens and underscores, starting with a letter or digit, at most 128 characters.

AdminTenantTierUpdateRequest​

input

A partial update to a tier. Omit a field to keep it, send a value to set it, or send null to clear it. The tier is named by the mutation's token argument. Changes apply to every tenant at the tier.

Input fieldTypeDescription
colorStringA color name from tierColorPalette, trimmed of surrounding spaces. Null or an empty string clears it; an unknown name rejects the request.
configStringThe tier's settings as a JSON object serialized to a string, replacing the current settings entirely. Null, an empty string or {} removes all of them, so every tenant at the tier then falls back to the platform defaults. An unknown key, or a value outside its allowed range, rejects the request.
descriptionStringNew description, or null to clear it.
nameStringNew name, or null to clear it.

AdminTenantUpdateRequest​

input

A partial update to a tenant. For every field, omitting it keeps the stored value, sending a value sets it, and sending null clears it. Clearing a limit removes the tenant's own override, so the tier's value applies, then the platform default; it never makes the tenant unlimited. The tenant is named by the mutation's token argument. Limits are validated as for creation.

Input fieldTypeDescription
aiExternalEnabledBooleanWhether the tenant has agreed to have its data sent to an external AI model provider. Null clears the record, which counts as not agreed.
aiInferenceBurstIntOverride of the AI inference burst allowance, in requests. Must be positive.
aiInferenceRequestsPerMinuteFloatOverride of the sustained AI inference rate, in requests per minute. Must be positive.
configStringFree-form settings as a JSON object serialized to a string, replacing the current ones. Null, an empty string or {} clears them.
geoFenceCeilingIntOverride of the most geofences the tenant may have. A positive whole number of at most 4000.
geoFencePositionBudgetIntOverride of the most positions the tenant's geofences may have in total. A positive whole number of at most 128000.
geoFencePositionCeilingIntOverride of the most positions one geofence may have. A positive whole number of at most 1024.
heldCommandCeilingIntOverride of how many commands may be held waiting for offline devices. A positive whole number.
ingestBurstIntOverride of the ingest burst allowance, in readings. Must be positive. Omitted leaves it as it is; null removes it so the tenant inherits.
ingestReadingsPerSecondFloatIngest ceiling override, in readings (decoded samples) per second. Omitted leaves it as it is; null removes it so the tenant inherits; a value must be positive.
nameStringNew name, or null to clear it.
outboundBurstIntOverride of the outbound burst allowance, in calls. Must be positive. Omitted leaves it as it is; null removes it so the tenant inherits.
outboundCallsPerSecondFloatOutbound ceiling override, in connector calls dispatched per second. Omitted leaves it as it is; null removes it so the tenant inherits; a value must be positive.
shedPriorityIntOverride of the overload-protection priority, a whole number from 1 to 100.
tierTokenStringToken of the tier to move the tenant to; the change takes effect within about a minute. Omit it to keep the current tier. Null is rejected, because every tenant has a tier.

DeadLetterSearchCriteria​

input

Filters and paging for searching dead letters. Every filter is optional and filters are combined with AND.

Input fieldTypeDescription
kindStringOnly records of this kind. Exact match.
pageNumberInt!Page to return, starting at 1.
pageSizeInt!Results per page. Below 1 means the default of 100; above 1000 is capped at 1000.
sinceStringOnly records that occurred at or after this time, as an RFC 3339 timestamp. A value that cannot be parsed is an error, not ignored.
sourceStringOnly records from this functional area. Exact match.
tenantStringOnly records for the tenant with this token. Exact match.
untilStringOnly records that occurred at or before this time, as an RFC 3339 timestamp. A value that cannot be parsed is an error, not ignored.

TenantDeletionSearchCriteria​

input

Paging and an optional completion filter for listing tenant deletions.

Input fieldTypeDescription
completedBooleanTrue for deletions that have finished, false for those still in progress. Omit it for both.
pageNumberInt!Page to return, starting at 1.
pageSizeInt!Results per page. Below 1 means the default of 100; above 1000 is capped at 1000.

Enums​

DeletionWait

DeletionWait​

enum

What a tenant deletion is currently waiting on.

ValueDescription
STORESAt least one storage system has not reported clean. This is the only wait that needs a person; blockedBy says which system and why.
SETTLEEvery storage system is clean but has not yet stayed clean for the required settling period.
TOKEN_HOLDEverything is clean and settled, but the deletion is not yet old enough to release the tenant's token for reuse.
NONENothing is outstanding.