Admin Settings
The admin's own profile and the editable system settings: read them, change them, or reset them to the environment values.
Get the current admin profile
/api/admin/profileAuthentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Admin profile. | AdminProfileResponseDto |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Update the admin profile
/api/admin/profileOnly preferredName is writable. Send null to clear it; omit it to leave it unchanged. Discord-owned fields cannot be changed here.
Authentication: Admin session token (Authorization: Bearer <token>)
Request body (JSON, required): UpdateAdminProfileDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | Updated profile. | AdminProfileResponseDto |
400 | Invalid field. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Get effective system settings
/api/admin/settingsReturns settings grouped by category. Each value carries editable; secrets are represented only as { isSet }.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Current settings. | EffectiveSettingsDto |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Update editable settings
/api/admin/settingsPersists the provided editable knobs and applies them without a restart. Any non-editable key is rejected by the validation pipe.
Authentication: Admin session token (Authorization: Bearer <token>)
Request body (JSON, required): UpdateSettingsDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | Updated settings. | EffectiveSettingsDto |
400 | Invalid or non-editable field. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Reset editable settings to environment defaults
/api/admin/settings/resetClears every stored override; read-only config is untouched.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Settings after reset. | EffectiveSettingsDto |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Schemas
AdminProfileResponseDto schema
| Field | Type | Required | Description |
|---|---|---|---|
avatar | string or null | yes | |
displayName | string or null | yes | Discord guild nickname, rewritten on every sync |
email | string or null | yes | |
globalName | string or null | yes | |
id | string | yes | |
isSystemAdmin | boolean | yes | |
preferredName | string or null | yes | Admin-set override; takes precedence in the UI when present |
username | string | yes |
CacheSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
permissionTtlMs | SettingValueDto | yes | |
projectAccessTtlMs | SettingValueDto | yes | |
projectAuthTtlMs | SettingValueDto | yes | |
statsTtlMs | SettingValueDto | yes |
DiscordSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
callbackUrl | SettingValueDto | yes | |
clientId | SettingValueDto | yes | |
clientSecret | SecretSettingDto | yes | |
guildId | SettingValueDto | yes | |
token | SecretSettingDto | yes |
EffectiveSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
cache | CacheSettingsDto | yes | |
discord | DiscordSettingsDto | yes | |
meta | SettingsMetaDto | yes | |
preferences | PreferencesSettingsDto | yes | |
rateLimit | RateLimitSettingsDto | yes | |
security | SecuritySettingsDto | yes |
PreferencesSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
memberActivityThresholdDays | SettingValueDto | yes |
RateLimitSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
globalLimit | SettingValueDto | yes | |
globalTtlMs | SettingValueDto | yes | |
maxWebhooksPerProject | SettingValueDto | yes |
SecretSettingDto schema
| Field | Type | Required | Description |
|---|---|---|---|
editable | false | yes | Secrets are never editable here |
isSet | boolean | yes | Whether a non-empty value is configured |
SecuritySettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
sessionTtlSec | SettingValueDto | yes | |
ssoTtlSec | SettingValueDto | yes | |
webhookEncryptionKey | SecretSettingDto | yes |
SettingValueDto schema
| Field | Type | Required | Description |
|---|---|---|---|
editable | boolean | yes | Whether PATCH /api/admin/settings accepts it |
value | object | yes | Current effective value |
SettingsMetaDto schema
| Field | Type | Required | Description |
|---|---|---|---|
updatedAt | string or null | yes | When a knob was last written |
updatedBy | string or null | yes | Admin member id of last writer |
UpdateAdminProfileDto schema
| Field | Type | Required | Description |
|---|---|---|---|
preferredName | string or null | no | Local display-name override (1-255 chars). Send null to clear it and fall back to the Discord-synced name. Omit the key to leave it unchanged. |
UpdateCacheSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
permissionTtlMs | number | no | |
statsTtlMs | number | no |
UpdatePreferencesSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
memberActivityThresholdDays | number | no |
UpdateRateLimitSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
maxWebhooksPerProject | number | no |
UpdateSettingsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
cache | UpdateCacheSettingsDto | no | |
preferences | UpdatePreferencesSettingsDto | no | |
rateLimit | UpdateRateLimitSettingsDto | no |
Source: apps/api/openapi.json.