Skip to main content

Introducing Liquid Nitrogen!

To take administrative actions like managing users, connected apps and permissions, it is recommended that you use The Nitrogen Project instead of rolling your own admin management portal. Nitrogen seamlessly connects with any Liquid instance with minimal configuration and uses the same administrative APIs under the hood.

If you still want to use the admin APIs for some reason, all of them are documented in this page.

Liquid Nitrogen

 

Admin APIs

Restricted to system admins. Super Admin role has access to all these APIs. To provide access to other users, Super Admin needs to explicitly provide permissions using POST user/admin-api/access API. Needs an authorization_code grant login.

tip

For web applications and admin tools, you can use the official liquid-js-sdk package to call all Admin APIs with zero boilerplate and full TypeScript support (liquid.admin.users.*, liquid.admin.oauth.*, liquid.admin.roles.*, liquid.admin.system.*).

Access Provisioning​


Add or remove scopes in user profiles.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:access:write (or) role = super_admin

Before You Start​

Read more about access control here.

URL​

POST /user/admin-api/access

Request Body​

ParameterTypeDescriptionRequired / Optional
targetsarrayArray of user IDs.Required
targetTypeenum(user, client)Type of target.Required
scopearrayArray of scope names. See full list hereRequired
operationenum(set, add, del)Specifies the type of modification.Required

Request Sample (JSON)​

{
"targets": ["507f1f77bcf86cd799439011"],
"targetType": "user",
"scope": ["admin:profile:read", "admin:profile:write"],
"operation": "set"
}

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

Create Users​


Creates users using a given array of user details.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:create:write

URL​

POST /user/admin-api/create

Request Body (Array Skeleton)​

ParameterTypeDescriptionRequired / Optional
usernamestringUsername for the user. Contains text, numbers and _ and at least 8 lettersRequired
firstNamestringFirst name of the user.Required
lastNamestringLast name of the user.Required
emailstringEmail address of the user.Required
passwordstringPassword for the user.Required
rolestringRole of the user. Target role be ranked less than the user calling the API or must be a super admin.Optional
phoneCountryCodestringValid country code.Optional
phonestringPhone number of the user.Optional

Request Sample (JSON)​

[
{
"username": "john_doe",
"firstName": "John",
"lastName": "Doe",
"role": "user",
"phoneCountryCode": "+00",
"phone": "0000000000",
"email": "user@example.com",
"password": "$uper&ecurePassw0rd"
}
]

Response Parameters​

ParameterTypeDescription
okinteger0 or 1
insertedCountintegerNumber of users created.

Response Sample​

{
"ok": 1,
"insertedCount": 1
}

Create Application​


Creates an application client.

Authentication​

Requires delegated authentication.

Scope​

  • admin:system:internal-client:write
  • admin:system:external-client:write

URL​

POST /client/admin-api/create

Request Body (Array Skeleton)​

ParameterTypeDescriptionRequired / Optional
idstringID of the client.Required
grantsarray[enum(client_credentials, authorization_code, refresh_token, password)]Grants allowed for the clientRequired
redirectUrisarrayRedirect URIs authorized for the client.Required
isPublicbooleanSet to true for public clients (SPAs/Mobile apps). Defaults to false.Optional
secretstringThe client secret. Required if isPublic is false or omitted.Required for confidential clients
roleenum(internal_client, external_client)Role of the client.Required
scopearrayArray of scopeRequired
displayNamestringDisplay name of the client.Required

Request Sample (JSON)​

[
{
"id": "external_client",
"grants": ["client_credentials"],
"redirectUris": ["https://redirect.uri"],
"isPublic": false,
"secret": "super-secure-client-secret",
"role": "external_client",
"scope": ["client:profile:read", "client:social:all"],
"displayName": "My External Client"
}
]

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

Update Application​


Updates an application client.

Authentication​

Requires delegated authentication.

Scope​

  • admin:system:internal-client:write
  • admin:system:external-client:write

URL​

PATCH /client/admin-api/update

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstringDBID of the client.Required
idstringID of the client.Required
grantsarray[enum(client_credentials, authorization_code, refresh_token, password)]Grants allowed for the clientRequired
redirectUrisarrayRedirect URIs authorized for the client.Required
secretstringThe client secret.Required
roleenum(internal_client, external_client)Role of the client.Required
scopearrayArray of scopeRequired
displayNamestringDisplay name of the client.Required

Request Sample (JSON)​

{
"target: "507f1f77bcf86cd799439011"
"id": "external_client",
"grants": ["client_credentials"],
"redirectUris": ["https://redirect.uri"],
"secret": "super-secure-client-secret",
"role": "external_client",
"scope": ["client:profile:read", "client:social:all"],
"displayName": "My External Client"
}

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

Delete Application​


Deletes an application client.

Authentication​

Requires delegated authentication.

Scope​

  • admin:system:internal-client:delete
  • admin:system:external-client:delete

URL​

DELETE /client/admin-api/delete

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstringDBID of the client.Required

Request Sample (JSON)​

{
"target": "507f1f77bcf86cd799439011"
}

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

List Applications​


List applications/clients in the system.

Authentication​

Requires delegated authentication.

Scope​

admin:system:client:read

URL​

GET /client/admin-api/list

Query Parameters​

ParameterTypeDescriptionRequired / Optional
limitintegerRecords per pageOptional
offsetinteger_id field of last record in the previous page.Optional

Response Data Parameters​

ParameterTypeDescription
applicationsarrayArray of applications.

Response Sample​

{
"ok": 1,
"data": [
{
"id": "external_client",
"grants": ["client_credentials"],
"redirectUris": ["https://redirect.uri"],
"secret": "super-secure-client-secret",
"role": "external_client",
"scope": ["client:profile:read", "client:social:all"],
"displayName": "My External Client"
}
]
}

List Roles​


Retrieves a list of roles available in the system.

Authentication​

Requires delegated authentication.

Scope​

delegated:roles:read

URL​

GET /roles/list

Response Parameters​

ParameterTypeDescription
rolesarrayArray of role objects.

Response Sample​

{
"roles": [
{
"id": "role1",
"displayName": "Role 1",
"ranking": 1,
"description": "This is a description"
"system": true
},
{
"id": "role2",
"displayName": "Role 2",
"ranking": 2,
"description": "This is another description"
"system": true
}
]
}

Error Responses​

Error CodeDescription
InternalErrorAn internal server error occurred.

Error Response Sample​

InternalError

{
"error": "Internal server error"
}

Create Role​


Creates a new role in the system.

Authentication​

Requires delegated authentication.

Scope​

admin:roles:write

URL​

POST /roles/admin-api/create

Request Body​

ParameterTypeDescriptionRequired / Optional
idstringUnique identifier for the role. Must be alphanumeric and can include underscores. Length between 1 and 128 characters.Required
displayNamestringDisplay name for the role. Length between 1 and 128 characters.Required
rankingnumberRanking for the role. Must be an integer greater than or equal to 1. Lower the number, higher the rankingRequired
descriptionstringOptional description for the role. Length between 1 and 512 characters.Optional

Request Sample (JSON)​

{
"id": "example_role",
"displayName": "Example Role",
"ranking": 1,
"description": "This is an example role."
}

Response Parameters​

ParameterTypeDescription
roleobjectThe newly created role.

Response Sample​

{
"role": {
"id": "example_role",
"displayName": "Example Role",
"ranking": 1,
"description": "This is an example role."
}
}

Error Responses​

Error CodeDescription
DuplicateResourceThe role ID already exists.
InternalErrorAn internal server error occurred.

Error Response Samples​

DuplicateResource

{
"error": "Resource already exists."
}

InternalError

{
"error": "An internal server error occurred."
}

Update Role​


Updates an existing role with the provided details.

Authentication​

Requires delegated authentication.

Scope​

admin:roles:write

URL​

PATCH /roles/admin-api/update

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstringThe ID of the role to update.Required
displayNamestringThe new display name for the role. Length between 1 and 128 characters.Optional
rankingnumberThe new ranking for the role. Must be an integer greater than or equal to 1. Lower the number, higher the ranking.Optional
descriptionstringThe new description for the role. Length between 1 and 512 characters.Optional

Request Sample (JSON)​

{
"target": "example_role",
"displayName": "Updated Role",
"ranking": 2,
"description": "This is an updated description for the role."
}

Response Parameters​

ParameterTypeDescription
roleobjectThe updated role object

Response Sample​

{
"role": {
"id": "example_role",
"displayName": "Updated Role",
"ranking": 2,
"description": "This is an updated description for the role."
}
}

Error Responses​

Error CodeDescription
SystemRoleUpdateSystem roles cannot be updated.
NotFoundRole not found.
InternalErrorAn internal server error occurred.

Error Response Samples​

SystemRoleUpdate

{
"message": "System roles cannot be updated."
}

NotFound

{
"message": "Role not found."
}

InternalError

{
"message": "Internal server error."
}

Delete Role​


Deletes a user role.

Authentication​

Requires delegated authentication.

Scope​

admin:roles:delete

URL​

DELETE /roles/admin-api/delete

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstringThe ID of the role to delete.Required

Request Sample (JSON)​

{
"target": "roleId"
}

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

Error Responses​

Error CodeDescription
SystemRoleDeleteThe role is a system role and cannot be deleted.
InternalErrorAn internal server error occurred.

Error Response Samples​

SystemRoleDelete

{
"error": "The role is a system role and cannot be deleted."
}

InternalError

{
"error": "An internal server error occurred."
}

List Users​


List users in the system.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:read

URL​

GET /user/admin-api/list

Query Parameters​

ParameterTypeDescriptionRequired / Optional
limitintegerRecords per pageOptional
offsetinteger_id field of last record in the previous page.Optional

Response Data Parameters​

ParameterTypeDescription
usersarrayArray of users.

Response Sample​

{
"ok": 1,
"data": {
"users": [
{
"_id": "507f1f77bcf86cd799439011",
"firstName": "John",
"middleName": null,
"lastName": "Doe",
"gender": "male",
"username": "john_doe",
"role": "user",
"bio": "Grab a straw, because you suck.",
"designation": "Software Engineer",
"profilePictureUrl": "https://image.com/url",
"pronouns": "he/him",
"verified": true,
"verifiedDate": "2023-09-09T13:45:52.505Z",
"customLink": "https://custom.link",
"followingCount": 250,
"followerCount": 1058,
"isPrivate": true,
"isSubscribed": true,
"subscriptionTier": "basic",
"subscriptionExpiry": "2023-09-09T13:45:52.505Z",
"isBanned": false,
"isRestricted": false,
"email": "john.doe@example.com",
"phone": "0000000000",
"customData": {}
}
]
}
}

Get User Info​


Get information about a user from their ID.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:read

URL​

POST /user/admin-api/retrieve-user-info

Request Body​

ParameterTypeDescriptionRequired / Optional
targetsstringArray of user IDs or emailsRequired
fieldboolean (_id, email, sanitizedEmail)Optional

Response Data Parameters​

ParameterTypeDescription
usersarrayArray of users.

Response Sample​

{
"ok": 1,
"data": {
"users": [
{
"_id": "507f1f77bcf86cd799439011",
"firstName": "John",
"middleName": null,
"lastName": "Doe",
"gender": "male",
"username": "john_doe",
"role": "user",
"bio": "Grab a straw, because you suck.",
"designation": "Software Engineer",
"profilePictureUrl": "https://image.com/url",
"pronouns": "he/him",
"verified": true,
"verifiedDate": "2023-09-09T13:45:52.505Z",
"customLink": "https://custom.link",
"followingCount": 250,
"followerCount": 1058,
"isPrivate": true,
"isSubscribed": true,
"subscriptionTier": "basic",
"subscriptionExpiry": "2023-09-09T13:45:52.505Z",
"isBanned": false,
"isRestricted": false,
"email": "john.doe@example.com",
"phone": "0000000000",
"customData": {}
}
]
}
}

Update User Info​


Updates a user's profile details.

Authentication​

Requires delegated authentication.

Scope​

  • admin:profile:write
  • admin:profile:sensitive:extreme:write
  • admin:profile:sensitive:high:write
  • admin:profile:sensitive:medium:write
  • admin:profile:sensitive:low:write

Before You Start​

Read about editing users here

URL​

PATCH /user/admin-api/update

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstring_id of the user.Optional
usernamestringUsername for the user. Contains text, numbers and _ and at least 8 lettersOptional
firstNamestringFirst name of the user.Optional
lastNamestringLast name of the user.Optional
emailstringEmail address of the user.Optional
passwordstringPassword for the user.Optional
rolestringRole of the user.Optional
phoneCountryCodestringValid country code.Optional
phonestringPhone number of the user.Optional

Request Sample (JSON)​

{
"target": "507f1f77bcf86cd799439011",
"username": "john_doe",
"firstName": "John",
"lastName": "Doe",
"role": "user",
"phoneCountryCode": "+00",
"phone": "0000000000",
"email": "user@example.com",
"password": "$uper&ecurePassw0rd"
}

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

Update User Custom Data​


Updates a user's custom data.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:custom-data:write

Before You Start​

Read about custom data here

URL​

PUT /user/admin-api/custom-data

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstring_id of the user.Required
customDataobjectJSON data objectRequired

Request Sample (JSON)​

{
"target": "507f1f77bcf86cd799439011",
"customData": {
"themePreference": "dark",
"nestedKey": {
"integer": 1
}
}
}

Response Parameters​

ParameterTypeDescription
okinteger0 or 1

Response Sample​

{
"ok": 1
}

Get Editable Fields​


Get the field names you can edit while using PATCH /user/admin-api/user.

Authentication​

Requires delegated authentication.

Scope​

admin:configuration:read

URL​

POST /user/admin-api/create

Request Body​

ParameterTypeDescription
editableFieldsarrayArray of fields that are editable by the current user.

Response Sample​

{
"data": {
"editableFields": ["string"]
}
}

Ban User​


Suspend a user from logging into Liquid.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:ban:write

URL​

POST /user/admin-api/ban

Request Body​

ParameterTypeDescription
targetarray_id of the user to be banned or unbanned.
statebooleanBan status.

Request Sample​

{
"target": "507f1f77bcf86cd799439011",
"state": true
}

Response Sample​

{
"ok": 1
}

Restrict User​


Marks a user as restricted.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:restrict:write

URL​

POST /user/admin-api/restrict

Request Body​

ParameterTypeDescription
targetarray_id of the user to be restricted or unrestricted.
statebooleanBan status.

Request Sample​

{
"target": "507f1f77bcf86cd799439011",
"state": true
}

Response Sample​

{
"ok": 1
}

Verify User​


Marks a user as verified.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:verifications:write

URL​

POST /user/admin-api/verify

Request Body​

ParameterTypeDescription
targetarray_id of the user to be verified or unverified.
statebooleanBan status.

Request Sample​

{
"target": "507f1f77bcf86cd799439011",
"state": true
}

Response Sample​

{
"ok": 1
}

Update User Credits​


Update credits of a user. Credits are usually similar to virtual money that you can use for controlling paid features. You can also use this as a reward points system.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:credits:write

Special Instructions​

  • Adjust the number of credits that a user has while signing up using the option user.account-creation.initial-credit-count.

URL​

POST /user/admin-api/credits

Request Body​

ParameterTypeDescription
targetarray_id of the user to be verified or unverified.
typeenum(increment, decrement, set)Operation to be performed on the credit value.

Request Sample​

{
"target": "6291396efe7079829e49b723",
"operation": "increment",
"value": 50
}

Response Sample​

{
"ok": 1
}

Get Invite Codes​


Retrieves invite codes for a user.

Authentication​

Requires a delegated authentication

Scope​

admin:social:invite-code:read

URL​

GET /user/admin-api/invite-codes

Before You Start​

Read more about the Invite-Only system here.

Query Parameters​

ParameterTypeDescription
targetarrayArray of invite codes. Absence of targetId parameter in objects means the invite code is not used.

Response Sample​

{
"ok": 1,
"data": {
"inviteCodes": [
{
"code": "GU-2526-1687389089010",
"createdAt": "2023-06-21T16:31:29.012Z",
"updatedAt": "2023-09-06T15:07:42.794Z",
"targetId": "64f895bec011931326757de6"
},
{
"code": "IE-2949-1687895089010",
"createdAt": "2023-06-21T16:31:29.012Z",
"updatedAt": "2023-06-21T16:31:29.012Z"
},
{
"code": "RN-9486-1687365089009",
"createdAt": "2023-06-21T16:31:29.012Z",
"updatedAt": "2023-06-22T16:48:48.622Z"
},
{
"code": "AX-4751-1687286989010",
"createdAt": "2023-06-21T16:31:29.012Z",
"updatedAt": "2023-06-21T16:31:29.012Z"
},
{
"code": "PJ-5631-1689673089010",
"createdAt": "2023-06-21T16:31:29.012Z",
"updatedAt": "2023-06-21T16:31:29.012Z"
}
]
}
}

Manage Subscription​


Activate, deactivate or modify a user's subscription.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:subscriptions:write or role = super_admin

URL​

POST /user/admin-api/subscription

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstringUser ID of the target userRequired
statebooleanWhether the subscription is activeRequired
expirystring (ISO date)Expiration date for the subscriptionRequired if state=true
tierstringThe subscription tier (from configuration)Optional
subscriptionIdentifierstring or numberExternal identifier for the subscriptionOptional

Request Sample​

{
"target": "507f1f77bcf86cd799439011",
"state": true,
"expiry": "2026-07-28T00:00:00.000Z",
"tier": "premium",
"subscriptionIdentifier": "subscription_12345"
}

Response Sample​

{
"ok": 1
}

Cancel Subscription​


Cancel or revoke cancellation of a user's subscription.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:subscriptions:write or role = super_admin

URL​

POST /user/admin-api/subscription-cancel

Request Body​

ParameterTypeDescriptionRequired / Optional
targetstringUser ID of the target userRequired
cancelledbooleanWhether the subscription is cancelledRequired

Request Sample​

{
"target": "507f1f77bcf86cd799439011",
"cancelled": true
}

Response Sample​

{
"ok": 1
}

Get Subscription Tiers​


Retrieve the list of available subscription tiers.

Authentication​

Requires delegated authentication.

Scope​

admin:profile:subscriptions:read or role = super_admin

URL​

GET /user/admin-api/subscription-tiers

Response Sample​

{
"ok": 1,
"data": {
"subscriptionTiers": [
{
"name": "basic",
"isBaseTier": true
},
{
"name": "premium",
"isBaseTier": false
},
{
"name": "enterprise",
"isBaseTier": false
}
]
}
}

Search Users​


Returns a list of users for a search query

Authentication​

Requires delegated authentication.

Scope​

admin:profile:search

URL​

POST /user/admin-api/search

Request Body​

ParameterTypeDescriptionRequired / Optional
querystring or objectSearch query. Can be a simple text (freestyle search) or a MongoDB query object (e.g. { "role": "admin" }).Required

Supported Operators​

The following MongoDB operators are supported in object queries:

  • Comparison: $eq, $gt, $gte, $lt, $lte, $ne, $in, $nin
  • Logical: $or, $and, $not
  • Element: $exists
  • Evaluation: $regex, $options

Request Sample (Simple String)​

{
"query": "rick"
}

Request Sample (Query Objects)​

{
"query": {
"$or": [{ "role": "admin" }, { "role": "moderator" }],
"username": { "$regex": "^john", "$options": "i" }
}
}

Response Data Parameters​

ParameterTypeDescription
resultsarrayArray of users.

Response Sample​

{
"ok": 1,
"data": {
"results": [
{
"_id": "507f1f77bcf86cd799439011",
"firstName": "Rick",
"lastName": "Asthley",
"username": "rick_asthley",
"role": "user",
"email": "rick@example.com"
}
]
}
}