seed_synthetic_accounts

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/seed_synthetic_accounts, with a bearer credential and the action's payload as the JSON body.

Contract description

Create synthetic accounts. Platform operator or its harness (the `synthetic_estate` grant, the `synthetic_seed_purge` grant, or `super_admin`) only. The accounts are the operator's own test fixtures, each with the `synthetic` flag, an identity no sign-in admits, the developer product's profile, and standing `active`. With `sign_in: true`, each also has a fixture email identity whose sign-in code is held for `read_synthetic_signin_code` and never sent. The platform's synthetic-account mode, a platform-wide setting of `off`, `compat`, or `stress`, sets how many accounts each call may create. A call creates up to that count, and mints one account-scoped token per account with no grant, the required expiry `token_expires_in_days` within the mode's bound, and the label `<label_prefix><n>`.

Each token value is answered once, here, and never again; the tokens are ordinary minted tokens, shown by `list_tokens` and ended by `revoke_token`. Every seed records a batch answered as `batch`, whose accounts the platform purges at the mode's lifetime, or under the `synthetic_seed_purge` grant after one day.

Refused `synthetic_estate_disabled` while that mode is off, `synthetic_posture_refuses` past a per-call bound, and `synthetic_ceiling_reached` at a ceiling. A repeat with the same `request_id` answers the same batch's account ids without token values. Under the `synthetic_seed_purge` grant, one call creates one account with a token of at most one day and no `products`, refused `synthetic_posture_refuses` otherwise, and a `request_id` another credential's batch carries refuses `invalid_request`. Under that grant a seed is also refused `synthetic_ceiling_reached` while twelve synthetic accounts the calling credential seeded still stand. An account seeded under that grant holds one application, on the Free plan, and is refused a paid plan `synthetic_ceiling_reached`. Prefer the wire route for a harness, so token values pass through no assistant transcript.

Access and action metadata

{
  "name": "seed_synthetic_accounts",
  "resource": "account",
  "tier": "reversible",
  "grant": "synthetic_estate",
  "switch": "synthetic_estate",
  "admits": [
    "synthetic_seed_purge"
  ],
  "summary": "Create synthetic accounts — the company's own test fixtures, each one user row of the builder realm with the `synthetic` flag, one identity under the provider `synthetic` that no sign-in method admits and, with `sign_in: true`, one `email` identity at the reserved fixture domain `synthetic.turnzero.ai` whose emailed code is held for `read_synthetic_signin_code` and never sent, the developer product's profile, and standing `active` — up to the mode's per-call count (25 under `compat`, 100 under `stress`), and mint one account-scoped token per account through `mint_token`'s own path, carrying no grant, the given expiry (`token_expires_in_days`, required, at most the mode's bound: 3 days under `compat`, 30 under `stress`), and the label `<label_prefix><n>`; every seed records a batch, answered as `batch`, whose accounts expire at the mode's lifetime from the seeding instant and whose seeding credential is the caller's, so the lifetime sweep purges them and a token a synthetic grant bounds purges its own batches alone; each token value is answered here and nowhere afterward, and each created account and each minted token is one action record naming the credential. Admitted to a credential holding `synthetic_estate` or `super_admin`, and to a token the `synthetic_seed_purge` grant bounds, which seeds one account for each call with a token of at most one day and no `products`, while the control plane's `SYNTHETIC_ESTATE` mode is not `off`: refused `synthetic_estate_disabled` ahead of every other check while it is `off`, `synthetic_posture_refuses` past the mode's per-call count or expiry bound or past the `synthetic_seed_purge` grant's own bounds, and `synthetic_ceiling_reached` at the mode's standing-accounts or per-day ceiling, or at the `synthetic_seed_purge` grant's own ceiling of twelve standing accounts the calling credential seeded; a repeat carrying the same `request_id` from the same operator answers the same batch's account ids without token values and creates nothing. Under the `synthetic_seed_purge` grant a `request_id` that another credential's batch carries refuses `invalid_request`. Under that grant a batch expires with its seeded token, one day at most, in place of the mode's lifetime, so the lifetime sweep purges an account left standing after its day. An account seeded under that grant holds one application, on the Free plan: `create_application` and `set_plan` refuse it a paid plan `synthetic_ceiling_reached`.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": false,
    "openWorldHint": false
  }
}

MCP catalog entry

{
  "name": "seed_synthetic_accounts",
  "tier": "reversible",
  "scenario": "API-L0-12",
  "summary": "Create synthetic accounts. Platform operator or its harness (the `synthetic_estate` grant, the `synthetic_seed_purge` grant, or `super_admin`) only. The accounts are the operator's own test fixtures, each with the `synthetic` flag, an identity no sign-in admits, the developer product's profile, and standing `active`. With `sign_in: true`, each also has a fixture email identity whose sign-in code is held for `read_synthetic_signin_code` and never sent. The platform's synthetic-account mode, a platform-wide setting of `off`, `compat`, or `stress`, sets how many accounts each call may create. A call creates up to that count, and mints one account-scoped token per account with no grant, the required expiry `token_expires_in_days` within the mode's bound, and the label `<label_prefix><n>`.\n\nEach token value is answered once, here, and never again; the tokens are ordinary minted tokens, shown by `list_tokens` and ended by `revoke_token`. Every seed records a batch answered as `batch`, whose accounts the platform purges at the mode's lifetime, or under the `synthetic_seed_purge` grant after one day.\n\nRefused `synthetic_estate_disabled` while that mode is off, `synthetic_posture_refuses` past a per-call bound, and `synthetic_ceiling_reached` at a ceiling. A repeat with the same `request_id` answers the same batch's account ids without token values. Under the `synthetic_seed_purge` grant, one call creates one account with a token of at most one day and no `products`, refused `synthetic_posture_refuses` otherwise, and a `request_id` another credential's batch carries refuses `invalid_request`. Under that grant a seed is also refused `synthetic_ceiling_reached` while twelve synthetic accounts the calling credential seeded still stand. An account seeded under that grant holds one application, on the Free plan, and is refused a paid plan `synthetic_ceiling_reached`. Prefer the wire route for a harness, so token values pass through no assistant transcript.",
  "owners": [
    "MAPI-16",
    "API-L0-05",
    "MAPI-04",
    "ACB-L0-79",
    "ACS-L0-12",
    "ACB-L0-76"
  ]
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["count","token_expires_in_days"]
/properties/count The synthetic accounts to create, 1 to 100 by shape. The standing mode bounds the count per call — 25 under `compat`, 100 under `stress` — refusing `synthetic_posture_refuses` past it, and the mode's standing-accounts and per-day ceilings refuse `synthetic_ceiling_reached`. A count outside the shape's bound refuses `invalid_request`. Under the `synthetic_seed_purge` grant one call creates one account, refusing `synthetic_posture_refuses` past it. Under that grant a seed is also refused `synthetic_ceiling_reached` while twelve synthetic accounts the calling credential seeded still stand.

Type: integer
Minimum: 1
Maximum: 100
/properties/label_prefix The prefix of each minted token's label; the n-th account's token is labelled `<label_prefix><n>`, counted from one. `synthetic-` by default.

Type: string
Minimum length: 1
Maximum length: 100
/properties/token_expires_in_days Required: the days each minted token lives, 1 to 3650 by shape, at most the mode's bound — 3 under `compat`, 30 under `stress` — refusing `synthetic_posture_refuses` past it; the seed mints no token without an expiry. Under the `synthetic_seed_purge` grant the bound is one day.

Type: integer
Minimum: 1
Maximum: 3650
/properties/request_id Your request identity for this call: any string you choose, matched by equality with the operator's own account and never interpreted. One form is reserved: a value opening `first-sign-in:` is refused 400 `invalid_request`, since the batch a first sign-in at the fixture domain writes at its confirmation carries that form. A repeat carrying the same value answers the same batch's account ids and labels with `repeated: true` and no token value, and creates nothing. The token values were answered once, at the first call, so a batch whose values were lost is purged and seeded again. Under the `synthetic_seed_purge` grant a value another credential's batch carries refuses `invalid_request`: choose another.

Type: string
/properties/sign_in true binds a second identity under the `email` provider at the reserved fixture domain `synthetic.turnzero.ai` — the local part the account id, `email_verified` true — inside the seed's own transaction beside the `synthetic` identity. So the account signs in through the emailed-code route on the platform's own sign-in page, its code held for `read_synthetic_signin_code` and never sent. Absent or false binds the `synthetic` identity alone. No further identity ever joins the account (`synthetic_account_fixed`).

Type: boolean
/properties/products Optional: the product profiles each seeded account holds, as `read_account` names them under `profiles[].product` — `cloud` always among them, `["cloud"]` where absent, `["cloud", "blueprint"]` for a fixture that reads what Turn Zero Blueprint access opens as a holder. The fixture is purged with the estate, so the profile is no person's access. Under the `synthetic_seed_purge` grant the member refuses `synthetic_posture_refuses`: leave it out.

Type: array
Minimum items: 1
uniqueItems: true
/properties/products/items Allowed values: ["cloud","blueprint"]

response

JSON pointer Description and constraints
"" (root) The batch: one member per created account with its token value, answered once (API-L0-05). Each created account and each minted token is one action record naming the operator credential (MAPI-06). Refused 403 `synthetic_estate_disabled` ahead of every other check while the `SYNTHETIC_ESTATE` setting is off (MAPI-16).

Type: object
Required fields: ["contract_version","accounts","count","repeated"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/accounts Type: array
/properties/accounts/items Type: object
Required fields: ["account","label"]
Additional properties: false
/properties/accounts/items/properties/account The created account's id, the id every other action takes as `subject_account` and the purge takes in `accounts`.

Type: string
/properties/accounts/items/properties/label Type: ["string","null"]
/properties/accounts/items/properties/token The minted token's value, answered here and nowhere afterward (API-L0-05); absent on a repeat.

Type: string
/properties/accounts/items/properties/token_id The token's identity, the one `list_tokens` shows and `revoke_token` takes; absent on a repeat.

Type: string
/properties/accounts/items/properties/expires_at The token's expiry instant; absent on a repeat.

Type: ["string","null"]
/properties/accounts/items/properties/email The fixture address the seed bound with `sign_in: true`, `<account id>@synthetic.turnzero.ai`; null where the seed bound none.

Type: ["string","null"]
/properties/count Type: integer
/properties/repeated true where the call carried a `request_id` an earlier seed from the same operator carried, the answer being that batch without token values.

Type: boolean
/properties/detail Type: string
/properties/batch The batch's identity, server-minted, one per seed call and answered on a repeat as the same value: the key the purge's scoping under a synthetic grant and the lifetime sweep read, its accounts expiring at the mode's lifetime from the seeding instant (MAPI-16). Under the `synthetic_seed_purge` grant they expire with the seeded token, one day at most.

Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "count",
      "token_expires_in_days"
    ],
    "properties": {
      "count": {
        "type": "integer",
        "minimum": 1,
        "maximum": 100,
        "description": "The synthetic accounts to create, 1 to 100 by shape. The standing mode bounds the count per call — 25 under `compat`, 100 under `stress` — refusing `synthetic_posture_refuses` past it, and the mode's standing-accounts and per-day ceilings refuse `synthetic_ceiling_reached`. A count outside the shape's bound refuses `invalid_request`. Under the `synthetic_seed_purge` grant one call creates one account, refusing `synthetic_posture_refuses` past it. Under that grant a seed is also refused `synthetic_ceiling_reached` while twelve synthetic accounts the calling credential seeded still stand."
      },
      "label_prefix": {
        "type": "string",
        "minLength": 1,
        "maxLength": 100,
        "description": "The prefix of each minted token's label; the n-th account's token is labelled `<label_prefix><n>`, counted from one. `synthetic-` by default."
      },
      "token_expires_in_days": {
        "type": "integer",
        "minimum": 1,
        "maximum": 3650,
        "description": "Required: the days each minted token lives, 1 to 3650 by shape, at most the mode's bound — 3 under `compat`, 30 under `stress` — refusing `synthetic_posture_refuses` past it; the seed mints no token without an expiry. Under the `synthetic_seed_purge` grant the bound is one day."
      },
      "request_id": {
        "type": "string",
        "description": "Your request identity for this call: any string you choose, matched by equality with the operator's own account and never interpreted. One form is reserved: a value opening `first-sign-in:` is refused 400 `invalid_request`, since the batch a first sign-in at the fixture domain writes at its confirmation carries that form. A repeat carrying the same value answers the same batch's account ids and labels with `repeated: true` and no token value, and creates nothing. The token values were answered once, at the first call, so a batch whose values were lost is purged and seeded again. Under the `synthetic_seed_purge` grant a value another credential's batch carries refuses `invalid_request`: choose another."
      },
      "sign_in": {
        "type": "boolean",
        "description": "true binds a second identity under the `email` provider at the reserved fixture domain `synthetic.turnzero.ai` — the local part the account id, `email_verified` true — inside the seed's own transaction beside the `synthetic` identity. So the account signs in through the emailed-code route on the platform's own sign-in page, its code held for `read_synthetic_signin_code` and never sent. Absent or false binds the `synthetic` identity alone. No further identity ever joins the account (`synthetic_account_fixed`)."
      },
      "products": {
        "type": "array",
        "minItems": 1,
        "uniqueItems": true,
        "items": {
          "enum": [
            "cloud",
            "blueprint"
          ]
        },
        "description": "Optional: the product profiles each seeded account holds, as `read_account` names them under `profiles[].product` — `cloud` always among them, `[\"cloud\"]` where absent, `[\"cloud\", \"blueprint\"]` for a fixture that reads what Turn Zero Blueprint access opens as a holder. The fixture is purged with the estate, so the profile is no person's access. Under the `synthetic_seed_purge` grant the member refuses `synthetic_posture_refuses`: leave it out."
      }
    }
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "accounts",
      "count",
      "repeated"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "accounts": {
        "type": "array",
        "items": {
          "type": "object",
          "required": [
            "account",
            "label"
          ],
          "properties": {
            "account": {
              "type": "string",
              "description": "The created account's id, the id every other action takes as `subject_account` and the purge takes in `accounts`."
            },
            "label": {
              "type": [
                "string",
                "null"
              ]
            },
            "token": {
              "type": "string",
              "description": "The minted token's value, answered here and nowhere afterward (API-L0-05); absent on a repeat."
            },
            "token_id": {
              "type": "string",
              "description": "The token's identity, the one `list_tokens` shows and `revoke_token` takes; absent on a repeat."
            },
            "expires_at": {
              "type": [
                "string",
                "null"
              ],
              "description": "The token's expiry instant; absent on a repeat."
            },
            "email": {
              "type": [
                "string",
                "null"
              ],
              "description": "The fixture address the seed bound with `sign_in: true`, `<account id>@synthetic.turnzero.ai`; null where the seed bound none."
            }
          },
          "additionalProperties": false
        }
      },
      "count": {
        "type": "integer"
      },
      "repeated": {
        "type": "boolean",
        "description": "true where the call carried a `request_id` an earlier seed from the same operator carried, the answer being that batch without token values."
      },
      "detail": {
        "type": "string"
      },
      "batch": {
        "type": "string",
        "description": "The batch's identity, server-minted, one per seed call and answered on a repeat as the same value: the key the purge's scoping under a synthetic grant and the lifetime sweep read, its accounts expiring at the mode's lifetime from the seeding instant (MAPI-16). Under the `synthetic_seed_purge` grant they expire with the seeded token, one day at most."
      }
    },
    "additionalProperties": false,
    "description": "The batch: one member per created account with its token value, answered once (API-L0-05). Each created account and each minted token is one action record naming the operator credential (MAPI-06). Refused 403 `synthetic_estate_disabled` ahead of every other check while the `SYNTHETIC_ESTATE` setting is off (MAPI-16)."
  }
}

Shared contracts