SDK User Management
The dypai.users module provides administrative operations for your project's login accounts. Calls use the authenticated caller's session and require the manage_users permission. An authorized admin dashboard can use its user's session; a server can use an appropriately authorized credential.
Never expose a service-role token or project secret in browser code. Hiding an admin button is not authorization: the engine checks the caller's permissions.
These methods require the user's role to have the manage_users permission enabled in system.roles. The "admin" role has it enabled by default. For other roles, you can enable it from the Auth > Roles section of the dashboard. See the Permission System for details.
List Users
Retrieve a paginated list of all users in your project.
const { data, error } = await dypai.users.list({
page: 1,
per_page: 20
});
if (data) {
console.log('Users:', data.users);
console.log('Total:', data.total_count);
}
Normalized role
Each user in data.users exposes its application role as user.role (the SDK extracts it from app_metadata.role). You can manage these users and roles visually under Auth → Users and Auth → Roles in the dashboard — see Authentication.
Create User
Create a login account through the engine's administrative POST /api/v0/admin/users API. This is independent of public signup. It does not send an invitation email. email_confirm: true marks the email verified; choose this policy deliberately.
The SDK requires email and password. Supply the display name in user_metadata.name and the application role in app_metadata.role. The target role must exist in system.roles. The variables below come from the current submission; never hardcode or log a password.
const { data, error } = await dypai.users.create({
email,
password,
email_confirm: true,
user_metadata: { name },
app_metadata: { role: 'viewer' }
});
if (error || !data?.id) {
console.error('Failed to create user:', error?.message || 'No account ID returned');
return;
}
console.log('Created user:', data.id);
Auth IDs are opaque TEXT strings. Store them as text when linking business profiles; do not cast them to UUID.
Account creation with employee or creator profiles
For a form that also creates profiles, workspace membership, or assignments, put the operation behind an authenticated backend endpoint. Fix the target role on the backend, for example viewer; do not accept an elevated role from the form. The frontend calls that endpoint with its session.
The MCP manage_users tool is for an agent/operator managing the project. It is not an application runtime API and cannot replace the endpoint called by a customer's form.
Flow capability availability
The new dypai_auth operation create_user is usable only when the deployed engine advertises it in its capability catalog. Check availability and validate the Flow before using it. The SDK API above already exists; installing a newer client SDK alone does not enable a missing engine operation.
The Flow operation accepts email, password, name, role, and idempotency_key, and returns id, user_id, email, name, role, created, and replayed. Restrict the endpoint with .http({ method: 'POST', auth: 'jwt', roles: ['admin'] }); the runtime caller must also have manage_users. Set role: 'viewer' in the backend configuration.
Idempotency is scoped to the authenticated actor, project, and node operation. Reuse the same opaque key for retries of one submission. An email already owned by an unrelated operation is a conflict; do not adopt that account. The existing SDK users.create method does not itself expose this Flow idempotency contract.
Profile/link creation still needs its own backend idempotency and recovery. Do not delete an auth account from a browser catch block after a profile failure. Backend compensation must prove ownership by the failed operation and absence of valid links; otherwise reconcile the incomplete operation. Never persist passwords in logs, workflow diagnostics, request snapshots, frontend storage, or recovery/idempotency records.
Update User
Update an existing user's profile data.
const { data, error } = await dypai.users.update(userId, {
user_metadata: { name: 'Jane Doe' }
});
if (error) {
console.error('Failed to update user:', error.message);
return;
}
console.log('Updated user:', data?.email);
Delete User
Permanently delete a user from your project.
const { data, error } = await dypai.users.delete(userId);
if (error) {
console.error('Failed to delete user:', error.message);
return;
}
console.log('User deleted:', data?.success);
Method Reference
| Method | Description |
|---|---|
list({ page, per_page }) | List users with pagination. Returns { users, total_count? }. |
create({ email, password, email_confirm?, user_metadata?, app_metadata? }) | Create a login account. Returns the created User. |
update(userId, { user_metadata, app_metadata? }) | Update user metadata and, when supplied, the application role. Returns the updated User. |
delete(userId) | Delete a user permanently. Returns { success: boolean }. |