create_test_end_users

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/create_test_end_users, with a bearer credential and the action's payload as the JSON body.

Contract description

Create test end users on one of your application's sign-in realms, so your tool can test sign-in with no person and no mailbox. Name one to twenty `labels`: each becomes an end user with the verified address `<label>@synthetic.turnzero.ai`, which receives no mail, and an optional `expires_in_days` (1 to 30; 7 where absent) sets when the platform removes it. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on.

The development realm admits test end users from its creation; the production realm only after a person approves `admit_test_end_users`. Answers `test_signin_page`, the realm's test sign-in page, and per label the user's `id`, `email`, `expires_at`, and `created`. A label an unexpired test end user already holds answers that user with `created` false and creates nothing, so repeating the call is safe; an expired one is removed and created afresh.

Sign one in at the test sign-in page with its address, read its code with `read_test_signin_code`, and type the code; the session is a real one, and the application's code runs unchanged. Test end users count toward no user count or limit. Refused `test_end_users_not_admitted` where the realm does not admit them; the detail names the remedy. Refused `test_end_users_ceiling_reached` past twenty standing on the realm or fifty created within the hour, `not_test_end_user` for a label whose address a real end user holds, and `test_end_users_disabled` while the platform's `TEST_END_USERS` setting is off.

Access and action metadata

{
  "name": "create_test_end_users",
  "resource": "realm",
  "tier": "reversible",
  "summary": "Create up to twenty test end users on one realm of the calling account's own application, `application` and `environment` both required: each a user row holding one verified `email` identity `<label>@synthetic.turnzero.ai`, expiring `expires_in_days` from now (one to thirty, seven where absent), signed in through the realm's own emailed-code route with its code held for `read_test_signin_code` and never sent, and counted as no user; a label an unexpired test end user of the realm holds answers that user unchanged with `created` false, so a retry creates nothing, and a label whose row has expired is removed and created afresh. Refused `test_end_users_not_admitted` on a production realm before `admit_test_end_users` and on a workforce application, `test_end_users_ceiling_reached` past twenty unexpired test end users on the realm or fifty created by the application's realms within the hour, `not_test_end_user` for a label whose address another end user of the realm holds, and `test_end_users_disabled` while the control plane's `TEST_END_USERS` setting reads `off`.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": false,
    "openWorldHint": false,
    "idempotentHint": true
  }
}

MCP catalog entry

{
  "name": "create_test_end_users",
  "tier": "reversible",
  "summary": "Create test end users on one of your application's sign-in realms, so your tool can test sign-in with no person and no mailbox. Name one to twenty `labels`: each becomes an end user with the verified address `<label>@synthetic.turnzero.ai`, which receives no mail, and an optional `expires_in_days` (1 to 30; 7 where absent) sets when the platform removes it. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on.\n\nThe development realm admits test end users from its creation; the production realm only after a person approves `admit_test_end_users`. Answers `test_signin_page`, the realm's test sign-in page, and per label the user's `id`, `email`, `expires_at`, and `created`. A label an unexpired test end user already holds answers that user with `created` false and creates nothing, so repeating the call is safe; an expired one is removed and created afresh.\n\nSign one in at the test sign-in page with its address, read its code with `read_test_signin_code`, and type the code; the session is a real one, and the application's code runs unchanged. Test end users count toward no user count or limit. Refused `test_end_users_not_admitted` where the realm does not admit them; the detail names the remedy. Refused `test_end_users_ceiling_reached` past twenty standing on the realm or fifty created within the hour, `not_test_end_user` for a label whose address a real end user holds, and `test_end_users_disabled` while the platform's `TEST_END_USERS` setting is off.",
  "owners": [
    "ACS-L0-21",
    "ACS-L0-20",
    "PLD-L0-40"
  ],
  "scenario": "ACS-L0-21"
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["application","environment","labels"]
Additional properties: false
/properties/application The application id, from `list_applications`; one of the calling account's own.

Type: string
/properties/environment Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement).

Type: string
Pattern: ^(development|production)$
/properties/labels One to twenty labels, each the local part of a test end user's address at the fixture domain `synthetic.turnzero.ai`: a lowercase letter, then lowercase letters, digits, and hyphens, three to forty characters. A label an unexpired test end user of the realm holds answers that user unchanged; one whose row has expired is removed and created afresh; one whose address another end user of the realm holds is refused 409 `not_test_end_user`.

Type: array
Minimum items: 1
Maximum items: 20
/properties/labels/items Type: string
Pattern: ^[a-z][a-z0-9-]{2,39}$
/properties/expires_in_days Optional. The days from now at which the platform removes each created test end user, 1 to 30; 7 where absent. A label answered unchanged keeps its own expiry.

Type: integer
Minimum: 1
Maximum: 30

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","realm","application","environment","test_signin_page","test_end_users"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/realm The realm identifier: the application id for production, `<id>:development` for development.

Type: string
/properties/application Type: string
/properties/environment Type: string
Pattern: ^(development|production)$
/properties/test_signin_page The realm's test sign-in page, `/__account/signin/test` on the environment's hostname, which offers the emailed-code form to a test end user on every admitting realm with a non-empty route set.

Type: string
/properties/test_end_users One entry per label, in the request's order.

Type: array
Minimum items: 1
Maximum items: 20
/properties/test_end_users/items Type: object
Required fields: ["id","label","email","expires_at","created"]
Additional properties: false
/properties/test_end_users/items/properties/id The test end user's opaque identifier, the one `list_end_users` answers.

Type: string
/properties/test_end_users/items/properties/label Type: string
/properties/test_end_users/items/properties/email `<label>@synthetic.turnzero.ai`, the verified address the user signs in with.

Type: string
/properties/test_end_users/items/properties/expires_at The instant from which the platform's expiry pass removes the user, within ten minutes.

Type: string
/properties/test_end_users/items/properties/created True where this call created the row, false where an unexpired test end user already held the label and was answered unchanged.

Type: boolean
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "application",
      "environment",
      "labels"
    ],
    "properties": {
      "application": {
        "type": "string",
        "description": "The application id, from `list_applications`; one of the calling account's own."
      },
      "environment": {
        "type": "string",
        "pattern": "^(development|production)$",
        "description": "Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement)."
      },
      "labels": {
        "type": "array",
        "minItems": 1,
        "maxItems": 20,
        "items": {
          "type": "string",
          "pattern": "^[a-z][a-z0-9-]{2,39}$"
        },
        "description": "One to twenty labels, each the local part of a test end user's address at the fixture domain `synthetic.turnzero.ai`: a lowercase letter, then lowercase letters, digits, and hyphens, three to forty characters. A label an unexpired test end user of the realm holds answers that user unchanged; one whose row has expired is removed and created afresh; one whose address another end user of the realm holds is refused 409 `not_test_end_user`."
      },
      "expires_in_days": {
        "type": "integer",
        "minimum": 1,
        "maximum": 30,
        "description": "Optional. The days from now at which the platform removes each created test end user, 1 to 30; 7 where absent. A label answered unchanged keeps its own expiry."
      }
    },
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "realm",
      "application",
      "environment",
      "test_signin_page",
      "test_end_users"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "realm": {
        "type": "string",
        "description": "The realm identifier: the application id for production, `<id>:development` for development."
      },
      "application": {
        "type": "string"
      },
      "environment": {
        "type": "string",
        "pattern": "^(development|production)$"
      },
      "test_signin_page": {
        "type": "string",
        "description": "The realm's test sign-in page, `/__account/signin/test` on the environment's hostname, which offers the emailed-code form to a test end user on every admitting realm with a non-empty route set."
      },
      "test_end_users": {
        "type": "array",
        "minItems": 1,
        "maxItems": 20,
        "description": "One entry per label, in the request's order.",
        "items": {
          "type": "object",
          "required": [
            "id",
            "label",
            "email",
            "expires_at",
            "created"
          ],
          "properties": {
            "id": {
              "type": "string",
              "description": "The test end user's opaque identifier, the one `list_end_users` answers."
            },
            "label": {
              "type": "string"
            },
            "email": {
              "type": "string",
              "description": "`<label>@synthetic.turnzero.ai`, the verified address the user signs in with."
            },
            "expires_at": {
              "type": "string",
              "description": "The instant from which the platform's expiry pass removes the user, within ten minutes."
            },
            "created": {
              "type": "boolean",
              "description": "True where this call created the row, false where an unexpired test end user already held the label and was answered unchanged."
            }
          },
          "additionalProperties": false
        }
      },
      "detail": {
        "type": "string"
      }
    },
    "additionalProperties": false
  }
}

Shared contracts