Skip to main content
Version: 3.3.0

cmind/users/v1/user_management_service.proto

Package: cmind.users.v1

Messages​

PlatformUser​

PlatformUser is a user known to the identity provider, with their tenant memberships. Admin-gated — computing memberships is a Keycloak round-trip per user.

FieldTypeNumberDescription
userIdstring1
usernamestring2
emailstring3
tenantsrepeated UserTenantMembership4Tenants the user belongs to, each with their role. Empty for a user who holds no tenant membership.
enabledbool5
systemAccountbool6Internal service accounts are read-only in user management.

UserTenantMembership​

FieldTypeNumberDescription
tenantIdstring1
tenantNamestring2
rolecmind.tenants.v1.TenantRole3

ListPlatformUsersRequest​

FieldTypeNumberDescription
pagecmind.common.v1.PageRequest1
searchstring2Optional: return only users whose username or email contains this substring (case-insensitive, Keycloak's native search).

ListPlatformUsersResponse​

FieldTypeNumberDescription
usersrepeated PlatformUser1
pagecmind.common.v1.PageInfo2

CreatePlatformUserRequest​

The password is always temporary. The user must replace it at first login. Creating a user does not send email or change an existing account.

FieldTypeNumberDescription
usernamestring1
passwordstring2
emailoptional string3

CreatePlatformUserResponse​

FieldTypeNumberDescription
userIdstring1

GetPlatformUserRequest​

FieldTypeNumberDescription
userIdstring1

GetPlatformUserResponse​

FieldTypeNumberDescription
userPlatformUser1

UpdatePlatformUserRequest​

FieldTypeNumberDescription
userIdstring1
emailoptional string2Omit to keep the current value; an empty email clears it.
enabledoptional bool3

UpdatePlatformUserResponse​

SetPlatformUserPasswordRequest​

FieldTypeNumberDescription
userIdstring1
passwordstring2Always temporary; the user must replace it at their next login.

SetPlatformUserPasswordResponse​

DeletePlatformUserRequest​

FieldTypeNumberDescription
userIdstring1

DeletePlatformUserResponse​

Services​

UserManagementService​

UserManagementService administers user accounts at platform scope. User self-service operations belong in a separate service in this package.

ListPlatformUsers​

POST /cmind.users.v1.UserManagementService/ListPlatformUsers

Lists every user in the identity provider realm, with their tenant memberships. Platform-admin operation.

Request: ListPlatformUsersRequest

Response: ListPlatformUsersResponse

CreatePlatformUser​

POST /cmind.users.v1.UserManagementService/CreatePlatformUser

Creates an enabled account with a temporary password. Tenant memberships are managed separately. Existing accounts are never modified.

Request: CreatePlatformUserRequest

Response: CreatePlatformUserResponse

GetPlatformUser​

GET /cmind.users.v1.UserManagementService/GetPlatformUser

Request: GetPlatformUserRequest

Response: GetPlatformUserResponse

UpdatePlatformUser​

POST /cmind.users.v1.UserManagementService/UpdatePlatformUser

Request: UpdatePlatformUserRequest

Response: UpdatePlatformUserResponse

SetPlatformUserPassword​

POST /cmind.users.v1.UserManagementService/SetPlatformUserPassword

Request: SetPlatformUserPasswordRequest

Response: SetPlatformUserPasswordResponse

DeletePlatformUser​

POST /cmind.users.v1.UserManagementService/DeletePlatformUser

Removes a user account. The caller and internal service accounts are protected.

Request: DeletePlatformUserRequest

Response: DeletePlatformUserResponse