account
#Get account by ID Requires permission: Platform admin, tenant admin, or querying own account
الوسائط
- id!
Accounts, authentication (OTP, passkey, password), sessions, roles, and saved locations.
Get account by ID Requires permission: Platform admin, tenant admin, or querying own account
الوسائط
Authors for the admin picker.
الوسائط
List a tenant's staff accounts (owner + admins) with their config-lock state (platform-admin only). Backs the tenant Staff view where each row has a per-account config-lock toggle.
الوسائط
Most recent admin-panel activity per tenant, across each tenant's
owner/admin staff, batched over tenant_ids (platform-admin only).
Powers the "Last activity" column on the tenant list; tenants with no
panel session are omitted from the result.
الوسائط
List saved addresses for a specific account as admin.
الوسائط
List all roles for a specific account
الوسائط
List accounts for tenant admin panel. Supports filtering by role (customer, driver, vendor, operator), account status, and search term. Results are paginated. # Authorization Requires TenantAdmin or PlatformAdmin role.
الوسائط
List sessions with optional filters (admin only). Requires TenantAdmin or PlatformAdmin role.
الوسائط
The providers connected to the signed-in account.
List all partnerships the current user has access to. Returns partnerships where the user has been granted a role with entity_kind = Partnership. This is used by the client to show a partnership switcher UI.
List the authenticated account's registered passkeys.
الوسائط
List the OAuth app credentials configured for the given owner scope.
Secrets are never returned — each row exposes only has_secret. Platform
scope requires a platform admin; tenant scope is the caller's own tenant.
الوسائط
List staff members of a partnership. Returns all accounts that have been granted roles scoped to the specified partnership. Useful for viewing and managing partnership staff. Requires: TenantAdmin, PlatformAdmin, or operating in the partnership context.
الوسائط
Resolve the RP for the caller.
Preferred path: the SDK sends x-app / x-role headers from
init (they describe the client binary, available regardless of
auth state). The resolver reads RequestContext.app / .role.
The app / role_kind args are a fallback for clients that
haven't migrated to header-based identity yet — they override
the context values when present. Once every client sends the
headers the args can be dropped.
الوسائط
Get a permission set by ID
الوسائط
Get a permission set by code. Uses the tenant from the request context.
الوسائط
List permission sets by context. Uses the tenant from the request context.
الوسائط
الوسائط
Whether each social sign-in provider is actually usable for the calling
tenant, combining the two settings that have to agree: the tenant's
AuthPolicy (which decides whether apps show the button) and the
tenant's OAuth credentials (which decide whether pressing it works).
Both admin console pages read this so each can warn about the half the
admin isn't currently looking at. Exposes no secret material — only
which credential *fields* are missing.
End the current impersonation session (revoke it). Only meaningful
when called from within an impersonation session; writes a
tenant_impersonation_ended audit row attributed to the platform
admin behind the session.
Start a platform-admin impersonation session for a customer tenant.
Restricted to PlatformAdmin and gated on a fresh step-up token
(X-Elevation), exactly like ownership transfer. On success the
caller receives an act-as token pair scoped to the target tenant's
owner; the platform admin behind it is recorded on the session and in
the act claim, and a tenant_impersonation_started audit row is
written with the supplied reason.
الوسائط
Reset an account's password as admin.
If the account has an existing password credential, the hash is updated.
If no password credential exists, one is created.
Requires TenantAdmin or PlatformAdmin role.
الوسائط
Lock or unlock configuration editing for a tenant account (platform-admin only). A locked account keeps its Owner/Admin role for navigation but is barred from persisting tenant config & danger-zone changes. Used by the platform-admin tenant Staff view. Takes effect on the account's next access-token refresh.
الوسائط
Cancel a pending account deletion request
الوسائط
Finish a native "Sign in with Apple": verify the OS-minted id-token and
return the same AuthFlowResponse union as every other login path.
الوسائط
Finish connecting a provider to the account bound at link-start. The
one-time state authenticates the call (the account comes from the
binding stashed by the authenticated startOauthLink), so this works
even when the provider returns via a cross-site POST that wouldn't carry
the session cookie. Issues no tokens.
الوسائط
Finish "Continue with Google/Apple": exchanges the code, resolves the
account (existing link → verified-email auto-link → sign-up/deny), and
returns the same AuthFlowResponse union as password/passkey login.
الوسائط
الوسائط
الوسائط
Confirm a password reset by submitting either the 4-digit code or the opaque URL token, plus the new password. Revokes all active sessions for the account on success.
الوسائط
Create a new account as admin.
الوسائط
Create a new permission set.
الوسائط
الوسائط
Delete the current user's account based on their account type policy
الوسائط
Remove an OAuth app credential for a provider within the given scope.
الوسائط
الوسائط
Delete a permission set by ID.
الوسائط
الوسائط
Grant staff access to a partnership. This allows adding staff members to a partnership. The staff member will be able to switch to this partnership context and perform operations based on their assigned role. Requires: TenantAdmin, PlatformAdmin, PartnershipOwner, or PartnershipManager role.
الوسائط
Grant a role to an account
الوسائط
الوسائط
الوسائط
الوسائط
الوسائط
Start a self-service password reset by email. Always returns success
regardless of whether the email matches an account — clients should
always proceed to the confirm screen and rely on confirmPasswordReset
to validate the code or token.
الوسائط
Mint a single-shot elevation token after re-verifying the
caller's password. Attach the returned token to the
danger-zone mutation as X-Elevation: <token>. The token
expires after 5 minutes or on first successful use, whichever
comes sooner.
الوسائط
Revoke staff access from a partnership. This removes a staff member's role for the partnership. They will no longer be able to switch to this partnership context. Requires: TenantAdmin, PlatformAdmin, PartnershipOwner, or PartnershipManager role.
الوسائط
Revoke a role from an account
الوسائط
الوسائط
الوسائط
الوسائط
Begin a native "Sign in with Apple" (the iOS system sheet). Returns the
raw nonce the client SHA-256 hashes into its ASAuthorization request,
and the state it echoes back on completion. No browser round-trip.
الوسائط
Begin a passwordless email-OTP login. The supplied email must
belong to an existing, phone-registered, email-verified account
in the resolved tenant — anything else returns a typed error
(EMAIL_NOT_REGISTERED / EMAIL_NOT_VERIFIED) and the client
should route the user back to phone-based registration.
الوسائط
Start email verification by sending an OTP code to the provided email. Requires authentication.
الوسائط
Begin connecting a provider to the signed-in account.
الوسائط
Begin "Continue with Google/Apple": returns the provider authorize URL
and the state the website must store and echo on the callback.
الوسائط
الوسائط
Begin enrolling a passkey for the authenticated account.
الوسائط
الوسائط
Switch to a different partnership context or clear partnership context. When switching to a partnership, the system verifies the user has a role with entity_kind=Partnership and entity_id=partnershipId. If authorized, new tokens are issued with the partnership context embedded. Pass null partnershipId to clear partnership context and return to personal account mode.
الوسائط
Transfer the TenantOwner role from the calling account to
another account in the same tenant.
Requires a fresh step-up elevation token (Phase 3). The
client first calls requestStepUp(password) to mint a
5-minute single-shot JWT, then attaches it as
X-Elevation: <token> on this mutation. If the header is
missing, malformed, or the token has already been consumed,
the mutation returns STEP_UP_REQUIRED so the client can
prompt for re-auth.
الوسائط
Disconnect a provider from the signed-in account. Refuses to remove the account's last remaining sign-in method.
الوسائط
Update an account's profile fields as admin.
الوسائط
Update an account's status (Active/Blocked) as admin.
الوسائط
الوسائط
الوسائط
Update an existing permission set.
الوسائط
الوسائط
الوسائط
Create or replace an OAuth app credential (Google/Apple). Platform configs require a platform admin; tenant configs are scoped to the caller's tenant. Secrets are write-only — omit to keep the stored value.
الوسائط
Verify the OTP from startEmailLogin and mint a session. Returns
the same AuthFlowResponse shape as verifyOtp, so the client
can dispatch on AuthSuccess / RestoreAccountRequired without
branching on which channel sent the code.
الوسائط
Verify an email OTP code to confirm the email address. Requires authentication.
الوسائط
الوسائط
صُمم BetterSuite لفرق ترى الخدمة عند الطلب نشاطاً تجارياً — لا ميزة إضافية.