create_test_end_users
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/create_test_end_users, with a bearer credential and the action's payload as the JSON body.
Contract description
Create test end users on one of your application's sign-in realms, so your tool can test sign-in with no person and no mailbox. Name one to twenty `labels`: each becomes an end user with the verified address `<label>@synthetic.turnzero.ai`, which receives no mail, and an optional `expires_in_days` (1 to 30; 7 where absent) sets when the platform removes it. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on.
The development realm admits test end users from its creation; the production realm only after a person approves `admit_test_end_users`. Answers `test_signin_page`, the realm's test sign-in page, and per label the user's `id`, `email`, `expires_at`, and `created`. A label an unexpired test end user already holds answers that user with `created` false and creates nothing, so repeating the call is safe; an expired one is removed and created afresh.
Sign one in at the test sign-in page with its address, read its code with `read_test_signin_code`, and type the code; the session is a real one, and the application's code runs unchanged. Test end users count toward no user count or limit. Refused `test_end_users_not_admitted` where the realm does not admit them; the detail names the remedy. Refused `test_end_users_ceiling_reached` past twenty standing on the realm or fifty created within the hour, `not_test_end_user` for a label whose address a real end user holds, and `test_end_users_disabled` while the platform's `TEST_END_USERS` setting is off.
Access and action metadata
{
"name": "create_test_end_users",
"resource": "realm",
"tier": "reversible",
"summary": "Create up to twenty test end users on one realm of the calling account's own application, `application` and `environment` both required: each a user row holding one verified `email` identity `<label>@synthetic.turnzero.ai`, expiring `expires_in_days` from now (one to thirty, seven where absent), signed in through the realm's own emailed-code route with its code held for `read_test_signin_code` and never sent, and counted as no user; a label an unexpired test end user of the realm holds answers that user unchanged with `created` false, so a retry creates nothing, and a label whose row has expired is removed and created afresh. Refused `test_end_users_not_admitted` on a production realm before `admit_test_end_users` and on a workforce application, `test_end_users_ceiling_reached` past twenty unexpired test end users on the realm or fifty created by the application's realms within the hour, `not_test_end_user` for a label whose address another end user of the realm holds, and `test_end_users_disabled` while the control plane's `TEST_END_USERS` setting reads `off`.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "create_test_end_users",
"tier": "reversible",
"summary": "Create test end users on one of your application's sign-in realms, so your tool can test sign-in with no person and no mailbox. Name one to twenty `labels`: each becomes an end user with the verified address `<label>@synthetic.turnzero.ai`, which receives no mail, and an optional `expires_in_days` (1 to 30; 7 where absent) sets when the platform removes it. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on.\n\nThe development realm admits test end users from its creation; the production realm only after a person approves `admit_test_end_users`. Answers `test_signin_page`, the realm's test sign-in page, and per label the user's `id`, `email`, `expires_at`, and `created`. A label an unexpired test end user already holds answers that user with `created` false and creates nothing, so repeating the call is safe; an expired one is removed and created afresh.\n\nSign one in at the test sign-in page with its address, read its code with `read_test_signin_code`, and type the code; the session is a real one, and the application's code runs unchanged. Test end users count toward no user count or limit. Refused `test_end_users_not_admitted` where the realm does not admit them; the detail names the remedy. Refused `test_end_users_ceiling_reached` past twenty standing on the realm or fifty created within the hour, `not_test_end_user` for a label whose address a real end user holds, and `test_end_users_disabled` while the platform's `TEST_END_USERS` setting is off.",
"owners": [
"ACS-L0-21",
"ACS-L0-20",
"PLD-L0-40"
],
"scenario": "ACS-L0-21"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","environment","labels"] Additional properties: false |
| / |
The application id, from `list_applications`; one of the calling account's own. Type: string |
| / |
Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement). Type: string Pattern: ^(development|production)$ |
| / |
One to twenty labels, each the local part of a test end user's address at the fixture domain `synthetic.turnzero.ai`: a lowercase letter, then lowercase letters, digits, and hyphens, three to forty characters. A label an unexpired test end user of the realm holds answers that user unchanged; one whose row has expired is removed and created afresh; one whose address another end user of the realm holds is refused 409 `not_test_end_user`. Type: array Minimum items: 1 Maximum items: 20 |
| / |
Type: string Pattern: ^[a-z][a-z0-9-]{2,39}$ |
| / |
Optional. The days from now at which the platform removes each created test end user, 1 to 30; 7 where absent. A label answered unchanged keeps its own expiry. Type: integer Minimum: 1 Maximum: 30 |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","realm","application","environment","test_signin_page","test_end_users"] Additional properties: false |
| / |
Required value: 1 |
| / |
The realm identifier: the application id for production, `<id>:development` for development. Type: string |
| / |
Type: string |
| / |
Type: string Pattern: ^(development|production)$ |
| / |
The realm's test sign-in page, `/__account/signin/test` on the environment's hostname, which offers the emailed-code form to a test end user on every admitting realm with a non-empty route set. Type: string |
| / |
One entry per label, in the request's order. Type: array Minimum items: 1 Maximum items: 20 |
| / |
Type: object Required fields: ["id","label","email","expires_at","created"] Additional properties: false |
| / |
The test end user's opaque identifier, the one `list_end_users` answers. Type: string |
| / |
Type: string |
| / |
`<label>@synthetic.turnzero.ai`, the verified address the user signs in with. Type: string |
| / |
The instant from which the platform's expiry pass removes the user, within ten minutes. Type: string |
| / |
True where this call created the row, false where an unexpired test end user already held the label and was answered unchanged. Type: boolean |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"environment",
"labels"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`; one of the calling account's own."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement)."
},
"labels": {
"type": "array",
"minItems": 1,
"maxItems": 20,
"items": {
"type": "string",
"pattern": "^[a-z][a-z0-9-]{2,39}$"
},
"description": "One to twenty labels, each the local part of a test end user's address at the fixture domain `synthetic.turnzero.ai`: a lowercase letter, then lowercase letters, digits, and hyphens, three to forty characters. A label an unexpired test end user of the realm holds answers that user unchanged; one whose row has expired is removed and created afresh; one whose address another end user of the realm holds is refused 409 `not_test_end_user`."
},
"expires_in_days": {
"type": "integer",
"minimum": 1,
"maximum": 30,
"description": "Optional. The days from now at which the platform removes each created test end user, 1 to 30; 7 where absent. A label answered unchanged keeps its own expiry."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"realm",
"application",
"environment",
"test_signin_page",
"test_end_users"
],
"properties": {
"contract_version": {
"const": 1
},
"realm": {
"type": "string",
"description": "The realm identifier: the application id for production, `<id>:development` for development."
},
"application": {
"type": "string"
},
"environment": {
"type": "string",
"pattern": "^(development|production)$"
},
"test_signin_page": {
"type": "string",
"description": "The realm's test sign-in page, `/__account/signin/test` on the environment's hostname, which offers the emailed-code form to a test end user on every admitting realm with a non-empty route set."
},
"test_end_users": {
"type": "array",
"minItems": 1,
"maxItems": 20,
"description": "One entry per label, in the request's order.",
"items": {
"type": "object",
"required": [
"id",
"label",
"email",
"expires_at",
"created"
],
"properties": {
"id": {
"type": "string",
"description": "The test end user's opaque identifier, the one `list_end_users` answers."
},
"label": {
"type": "string"
},
"email": {
"type": "string",
"description": "`<label>@synthetic.turnzero.ai`, the verified address the user signs in with."
},
"expires_at": {
"type": "string",
"description": "The instant from which the platform's expiry pass removes the user, within ten minutes."
},
"created": {
"type": "boolean",
"description": "True where this call created the row, false where an unexpired test end user already held the label and was answered unchanged."
}
},
"additionalProperties": false
}
},
"detail": {
"type": "string"
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md