Users
Admin → Users (https://admin.finmatch.io/users/). Requires
admin:users.
This page is the auth-credentials registry: admin staff, partners, and per-merchant auth users. It is not the merchant profile table. The page subtitle is User management and access control. The stamp line defaults to Auth version: —. Pages & Permissions subtitle: This is the full catalog of pages we can restrict (used by the admin UI).
What you see
| Column | Meaning |
|---|---|
| Username | Auth login id |
| Display Name | Shown in the admin chrome |
| Role | admin, partner, merchant, or similar |
| Status | Active / deactivated |
| Partner/Merchant ID | Linkage for partner and merchant users |
| API Key | Masked value plus row actions. Merchant rows: Copy FA and Credentials. Partner rows: Copy. Do not paste live keys onto this public page. |
| Created / Last Login | From auth-api |
| Permissions | Page grants (admin:merchants, admin:analytics, …) |
Idle users table: Loading users.... Empty: No users found. Load failure: Failed to load users: plus the error. Empty Pages & Permissions table: No permissions found. Idle permissions table: Loading permissions....
There is no Create User form on this page. It is a registry, not an onboarding wizard. There is no deactivate control here either — Status is a column, not an action.
Banners sit under Pages & Permissions: #usersError (stays until the
next success or a later load clears it) and #usersSuccess (clears
after four seconds). Copy / Revoke failures use that error banner, not
a window.alert.
Copy, Credentials, and Revoke
Copy FA (merchant) and Copy (partner) reveal the key to the
clipboard after an admin password prompt
(Enter admin password to revoke a credential: on revoke;
Enter your admin password for sensitive actions: on copy). Success:
Finance Assistant key copied to clipboard. / Partner API key
copied to clipboard. The prompt is session-elevated (same token as
merchant-page Copy). Do not paste the revealed value into /docs/.
Credentials expands the merchant row. If that merchant has active sandbox preview links, the button reads Credentials (N preview). Empty expander: No typed credentials yet (legacy apiKey only).
Typed-credential table columns: Type, Label, Status, Created, Expires, Masked, then row buttons.
| Type label | What it is |
|---|---|
| Finance Assistant key | Enquiry / start-application bearer. Copy on an active row is the same reveal as Copy FA. |
| Sandbox preview link | Typed spv_… preview credential. Generated from the merchant Sandbox preview row (show-once). Not re-revealable here. |
| Merchant API key | Partner-API class of merchant key. |
Footer under the table: Sandbox preview links are generated from the merchant detail Sandbox panel (show-once). Finance Assistant keys remain revealable via Copy.
Revoke on an active credential asks Revoke this credential? Active preview links using it will stop working. Success: Credential revoked. Copy on the merchant Overview card still heals a missing Finance Assistant user; revoke is for a typed key that already exists.
Sandbox preview: Sandbox preview.
Sync Merchant API Keys
Sync Merchant API Keys backfills the historical class of merchant
profiles that never got a merchant-{id} auth user. Copy on the
merchant Finance Assistant API key (or Copy FA here) heals one
merchant; Sync heals the class.
Busy status: Syncing merchant API keys…. Result:
Synced: N created, N updated, N skipped.
After a key is created, updated, or revoked, auth-api writes the
Cloudflare KV mirror when credentials are configured. There is no
Users-page button for KV coverage or backfill.
Full contract: Merchant users & FA keys.
Pages & Permissions
Pages & Permissions is the catalog of admin pages the UI can restrict. It is not the user table above; it is the grant list those Permissions cells refer to.
| Column | Meaning |
|---|---|
| Page | Catalog label (Merchants, Analytics, Lenders (write credit products), User Management, …) |
| Path | Catalog path from auth-api. Live values still use an /admin/… prefix (/admin/merchants/). That is not a production bookmark — live URLs are site-root (/merchants/). See Admin URLs. |
| Permission | Grant string (admin:merchants, admin:lenders:write, admin:users, …) |
Lenders (write credit products) (admin:lenders:write) is the extra
grant for Add Credit Product / edit. Without it (and not an admin
role), those actions alert You do not have permission to edit credit
products. See Credit products.
Applications (admin:applications) is the grant for the left-nav
Applications ledger. Without it the item is hidden and a direct
URL is refused. Applications.
Partner webhooks (admin:partner-webhooks) is the grant for the
left-nav Partner webhooks page. Granted by hand; sign out and back
in. Partner webhooks.
Emails and Monitoring are in the left nav with no permission
gate in nav-builder.js. They are not rows in this catalog.
Errors and elevation
Live chrome on this page. There is no create or deactivate action — do not hunt for those buttons.
| When | What you see |
|---|---|
admin-elevation.js did not load, then Copy, Copy FA, or Revoke | Admin elevation module not loaded. |
Users GET returns Unauthorized (localhost vs 127.0.0.1, or a stale session) | Banner plus table cell Failed to load users: Unauthorized. You are likely logged in on a different host (localhost vs 127.0.0.1) or your session is stale. Click Sign Out and sign in again as an admin on this exact URL/host. |
| Other users-load failure | Same Failed to load users: prefix, then the API error / message, then (If this is a 404/Forbidden, deploy auth-api with the new /admin/users endpoint.) |
No localStorage username (Copy / Sync / load) | Missing local username. Please sign in again. |
| Revoke with a missing merchant or key id | Missing merchantId or keyId. |
| Password prompt cancelled | Admin password required. |
| Elevate succeeded but returned no token | Failed to verify admin password. |
| Reveal returned an empty key | Merchant API key not available. / Partner API key not available. |
| Clipboard given an empty string | Nothing to copy. |
| Copy / Revoke missing ids before the request | Missing merchant ID. / Missing partner username. |
Sync failure paints #usersError with the API message and clears
the Syncing merchant API keys… stamp. Success toasts stay on
Finance Assistant key copied to clipboard. /
Partner API key copied to clipboard. / Credential revoked.
Do not paste live keys into these docs. gs://finmatch-admin is public.