@acl-identity/admin
v0.1.1
Published
Server-side admin client for the ACL Identity platform
Readme
@acl-identity/admin
Server-side admin client for the ACL Identity platform. Provides full access to user management, sessions, roles, RBAC, tenants, OAuth2 clients, identity providers, audit logs, and platform settings.
This package is server-only. It will throw at import time if loaded in a browser bundle.
Installation
npm install @acl-identity/admin
# or
pnpm add @acl-identity/adminQuick start
Client credentials (machine-to-machine)
import { ACLAdminClient } from '@acl-identity/admin';
const admin = new ACLAdminClient({
baseUrl: 'https://auth.example.com',
clientId: process.env.ADMIN_CLIENT_ID,
clientSecret: process.env.ADMIN_CLIENT_SECRET,
});Delegated token (e.g. NextAuth session)
const admin = new ACLAdminClient({
baseUrl: 'https://auth.example.com',
tokenGetter: async () => session.accessToken,
});Resources
// Users
const users = await admin.users.list({ page: 0, size: 25 });
await admin.users.get(userId);
await admin.users.create({ email: '[email protected]', orgSlug: 'my-org' });
await admin.users.update(userId, { displayName: 'Ada Lovelace' });
await admin.users.delete(userId);
// Sessions
const sessions = await admin.sessions.list({ userId });
await admin.sessions.revoke(sessionId);
await admin.sessions.revokeAll({ userId });
// Roles & RBAC
const roles = await admin.roles.list();
await admin.roles.create({ name: 'editor', permissions: ['posts:write'] });
await admin.rbac.assignRole(userId, roleId);
// OAuth2 clients
const clients = await admin.clients.list();
await admin.clients.create({ name: 'My App', grantTypes: ['authorization_code'] });
// Tenants
const tenants = await admin.tenants.list();
await admin.tenants.create({ slug: 'acme', displayName: 'Acme Corp' });
// Identity providers
await admin.identityProviders.list();
await admin.identityProviders.create({ type: 'oidc', ... });
// Audit logs
const logs = await admin.auditLogs.list({ page: 0, size: 50 });
// Dashboard stats
const stats = await admin.dashboard.getSummary();
// Security settings
await admin.security.getPolicy();
await admin.security.updatePolicy({ mfaRequired: true });
// Platform settings
await admin.settings.get();
await admin.settings.update({ allowSelfRegistration: false });Configuration
| Option | Type | Description |
|---|---|---|
| baseUrl | string | Base URL of your ACL Identity server |
| clientId | string | Client credentials OAuth2 client ID |
| clientSecret | string | Client credentials OAuth2 client secret |
| tokenGetter | () => Promise<string> | Alternatively, supply a token directly |
| orgSlug | string | Scope requests to a specific organization |
| timeout | number | HTTP request timeout in milliseconds |
| fetchImpl | typeof fetch | Custom fetch implementation |
Either clientId + clientSecret or tokenGetter is required.
License
MIT
