Skip to main content

Users

Admin → Users (https://admin.finmatch.io/users/). Requires admin:users.

This page is the auth-credentials registry: admin staff, partners, and per-merchant auth users. It is not the merchant profile table. The page subtitle is User management and access control. The stamp line defaults to Auth version: —. Pages & Permissions subtitle: This is the full catalog of pages we can restrict (used by the admin UI).

What you see​

ColumnMeaning
UsernameAuth login id
Display NameShown in the admin chrome
Roleadmin, partner, merchant, or similar
StatusActive / deactivated
Partner/Merchant IDLinkage for partner and merchant users
API KeyMasked value plus row actions. Merchant rows: Copy FA and Credentials. Partner rows: Copy. Do not paste live keys onto this public page.
Created / Last LoginFrom auth-api
PermissionsPage grants (admin:merchants, admin:analytics, …)

Idle users table: Loading users.... Empty: No users found. Load failure: Failed to load users: plus the error. Empty Pages & Permissions table: No permissions found. Idle permissions table: Loading permissions....

There is no Create User form on this page. It is a registry, not an onboarding wizard. There is no deactivate control here either — Status is a column, not an action.

Banners sit under Pages & Permissions: #usersError (stays until the next success or a later load clears it) and #usersSuccess (clears after four seconds). Copy / Revoke failures use that error banner, not a window.alert.

Copy, Credentials, and Revoke​

Copy FA (merchant) and Copy (partner) reveal the key to the clipboard after an admin password prompt (Enter admin password to revoke a credential: on revoke; Enter your admin password for sensitive actions: on copy). Success: Finance Assistant key copied to clipboard. / Partner API key copied to clipboard. The prompt is session-elevated (same token as merchant-page Copy). Do not paste the revealed value into /docs/.

Credentials expands the merchant row. If that merchant has active sandbox preview links, the button reads Credentials (N preview). Empty expander: No typed credentials yet (legacy apiKey only).

Typed-credential table columns: Type, Label, Status, Created, Expires, Masked, then row buttons.

Type labelWhat it is
Finance Assistant keyEnquiry / start-application bearer. Copy on an active row is the same reveal as Copy FA.
Sandbox preview linkTyped spv_… preview credential. Generated from the merchant Sandbox preview row (show-once). Not re-revealable here.
Merchant API keyPartner-API class of merchant key.

Footer under the table: Sandbox preview links are generated from the merchant detail Sandbox panel (show-once). Finance Assistant keys remain revealable via Copy.

Revoke on an active credential asks Revoke this credential? Active preview links using it will stop working. Success: Credential revoked. Copy on the merchant Overview card still heals a missing Finance Assistant user; revoke is for a typed key that already exists.

Sandbox preview: Sandbox preview.

Sync Merchant API Keys​

Sync Merchant API Keys backfills the historical class of merchant profiles that never got a merchant-{id} auth user. Copy on the merchant Finance Assistant API key (or Copy FA here) heals one merchant; Sync heals the class.

Busy status: Syncing merchant API keys…. Result: Synced: N created, N updated, N skipped. After a key is created, updated, or revoked, auth-api writes the Cloudflare KV mirror when credentials are configured. There is no Users-page button for KV coverage or backfill.

Full contract: Merchant users & FA keys.

Pages & Permissions​

Pages & Permissions is the catalog of admin pages the UI can restrict. It is not the user table above; it is the grant list those Permissions cells refer to.

ColumnMeaning
PageCatalog label (Merchants, Analytics, Lenders (write credit products), User Management, …)
PathCatalog path from auth-api. Live values still use an /admin/… prefix (/admin/merchants/). That is not a production bookmark — live URLs are site-root (/merchants/). See Admin URLs.
PermissionGrant string (admin:merchants, admin:lenders:write, admin:users, …)

Lenders (write credit products) (admin:lenders:write) is the extra grant for Add Credit Product / edit. Without it (and not an admin role), those actions alert You do not have permission to edit credit products. See Credit products.

Applications (admin:applications) is the grant for the left-nav Applications ledger. Without it the item is hidden and a direct URL is refused. Applications.

Partner webhooks (admin:partner-webhooks) is the grant for the left-nav Partner webhooks page. Granted by hand; sign out and back in. Partner webhooks.

Emails and Monitoring are in the left nav with no permission gate in nav-builder.js. They are not rows in this catalog.

Errors and elevation​

Live chrome on this page. There is no create or deactivate action — do not hunt for those buttons.

WhenWhat you see
admin-elevation.js did not load, then Copy, Copy FA, or RevokeAdmin elevation module not loaded.
Users GET returns Unauthorized (localhost vs 127.0.0.1, or a stale session)Banner plus table cell Failed to load users: Unauthorized. You are likely logged in on a different host (localhost vs 127.0.0.1) or your session is stale. Click Sign Out and sign in again as an admin on this exact URL/host.
Other users-load failureSame Failed to load users: prefix, then the API error / message, then (If this is a 404/Forbidden, deploy auth-api with the new /admin/users endpoint.)
No localStorage username (Copy / Sync / load)Missing local username. Please sign in again.
Revoke with a missing merchant or key idMissing merchantId or keyId.
Password prompt cancelledAdmin password required.
Elevate succeeded but returned no tokenFailed to verify admin password.
Reveal returned an empty keyMerchant API key not available. / Partner API key not available.
Clipboard given an empty stringNothing to copy.
Copy / Revoke missing ids before the requestMissing merchant ID. / Missing partner username.

Sync failure paints #usersError with the API message and clears the Syncing merchant API keys… stamp. Success toasts stay on Finance Assistant key copied to clipboard. / Partner API key copied to clipboard. / Credential revoked.

Do not paste live keys into these docs. gs://finmatch-admin is public.