admit_test_end_users
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/admit_test_end_users, with a bearer credential and the action's payload as the JSON body.
Contract description
Allow test end users on one of your application's production realm. Destructive: needs a credential holding the destructive class (a signed-in session, or a token minted with `destructive`); the call creates a pending action, and the admission stands only after a person approves it in the browser. Approving it means any credential of your account that reaches the application can sign a test end user in on production with no mailbox; their sign-ins and verifications meter as backend actions. The admission lasts until `withdraw_test_end_users` and shows as `test_end_users_admitted_at` in `read_realm`, `configure_realm`, and `export_account`. The development realm needs no admission. Refused `test_end_users_not_admitted` under the workforce audience and `test_end_users_disabled` while the platform's `TEST_END_USERS` setting is off.
Access and action metadata
{
"name": "admit_test_end_users",
"resource": "realm",
"tier": "destructive",
"summary": "Admit test end users on the production realm of one of the calling account's own applications, `application` alone, through the pending action a person of the account approves in a browser: its description states that any credential of the account reaching the application can then sign a test end user in on production with no mailbox. The admission stands until `withdraw_test_end_users`, is answered as `test_end_users_admitted_at` by `read_realm`, `configure_realm`, and `export_account`, and writes one info line to the control plane's stream naming the application and no address. Refused `test_end_users_not_admitted` on a workforce application and `test_end_users_disabled` while `TEST_END_USERS` reads `off`.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "admit_test_end_users",
"tier": "destructive",
"summary": "Allow test end users on one of your application's production realm. Destructive: needs a credential holding the destructive class (a signed-in session, or a token minted with `destructive`); the call creates a pending action, and the admission stands only after a person approves it in the browser. Approving it means any credential of your account that reaches the application can sign a test end user in on production with no mailbox; their sign-ins and verifications meter as backend actions. The admission lasts until `withdraw_test_end_users` and shows as `test_end_users_admitted_at` in `read_realm`, `configure_realm`, and `export_account`. The development realm needs no admission. Refused `test_end_users_not_admitted` under the workforce audience and `test_end_users_disabled` while the platform's `TEST_END_USERS` setting is off.",
"owners": [
"ACS-L0-21",
"API-L0-07",
"MAPI-05",
"PLD-L0-40"
],
"scenario": "ACS-L0-21"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application"] Additional properties: false |
| / |
The application id, from `list_applications`; one of the calling account's own. The act names the application's production realm; the development realm admits test end users with no act. Type: string |
| / |
Your request identity for this pending action: any string you choose. Repeating the call with the same request_id, from the same account, while the earlier pending action is still live — requested, approved, or executing — answers that pending action again and creates no second one. Once it has completed, failed, been declined, or expired, the same request_id starts a new one. Omitted, every call creates a new pending action. Type: string |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | The 202 creation envelope: the pending action and its approval link (API-L0-07); the terminal outcome rides the pending record via read_pending_action. Type: object Required fields: ["contract_version","pending_action","approval_url"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
$ref: #/shapes/pending_action |
| / |
Type: string |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`; one of the calling account's own. The act names the application's production realm; the development realm admits test end users with no act."
},
"request_id": {
"type": "string",
"description": "Your request identity for this pending action: any string you choose. Repeating the call with the same request_id, from the same account, while the earlier pending action is still live — requested, approved, or executing — answers that pending action again and creates no second one. Once it has completed, failed, been declined, or expired, the same request_id starts a new one. Omitted, every call creates a new pending action."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"description": "The 202 creation envelope: the pending action and its approval link (API-L0-07); the terminal outcome rides the pending record via read_pending_action.",
"required": [
"contract_version",
"pending_action",
"approval_url"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"pending_action": {
"$ref": "#/shapes/pending_action"
},
"approval_url": {
"type": "string"
},
"detail": {
"type": "string"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md