Skip to main content

Manage site users

This guide manages site users — the people who sign in to your app. It is not for cloud users, organization memberships, invitations, or Console-synchronized site access.

Choose an interface#

You can create, read, update, delete, list, and search site users in TaruviBase Console, JavaScript, Python, Refine, and the REST API.

By default, lists exclude cloud users, superusers, inactive users, and deleted users. To include them, use that interface's filters.

Reading a user that doesn't exist returns 404; check the site and username. Deletion is a soft delete, and users can't delete themselves.

Who can manage users#

Any signed-in user of the site can list and read site users. Creating, updating, and deleting them needs one of:

  • Organization access: an organization owner, admin, or member, or an API key one of them created.
  • A Super Admin app role in one of the site's apps.

Anyone else gets 403 with code FORBIDDEN and a message such as You do not have permission to create users. The JavaScript SDK rejects with ForbiddenError, the Python SDK raises AuthorizationError, and Refine's create, update, and delete hooks fail with ForbiddenError.

Only a superuser can change or delete a superuser, and a Super Admin app role can't change members of your organization. Nobody can make a user a superuser, staff member, or cloud user through the API: those fields are ignored. Assigning roles to existing users needs organization access; see Assign user access.

Create and manage users#

Use an authenticated client that can manage users. These examples use the taruvi client from JavaScript SDK or the client from Python SDK. Updates don't change passwords; users reset their own with Forgot Password on the hosted sign-in page. Deleted users can't be restored through the Console or API; to recover one, contact TaruviBase support with the user's details.

Run the creation sample on a server with TARUVI_NEW_USER_PASSWORD set in its environment.

import {User} from '@taruvi/sdk';

const users = new User(taruvi);
const initialPassword = process.env.TARUVI_NEW_USER_PASSWORD;
if (!initialPassword) throw new Error("Set TARUVI_NEW_USER_PASSWORD");

await users.createUser({
username: "onboarding-user",
password: initialPassword,
confirm_password: initialPassword,
first_name: "Onboarding",
last_name: "User",
});
await users.list({search: "onboarding", page: 1, page_size: 20});
await users.getUser("onboarding-user");
await users.updateUser("onboarding-user", {first_name: "Onboarding"});
await users.getUserApps("onboarding-user");
await users.getUser("me");

Use Assign user access to read roles and apps or assign roles to an existing user.

Remove a site user#

Confirm deletion
  • Affected resource and cascade: Verify the selected site user and every dependent application record before continuing.
  • Reversibility: Deleted users can't be restored through the Console or API. Treat deletion as permanent.
  • Authorization: Deleting users needs organization access or a Super Admin app role in one of the site's apps, and only a superuser can delete a superuser. Confirm you are on the right site.
  • Backup or export: Export the user's record first if you may need it.
  • Confirmation: Confirm the exact user and site before deleting.
  • Success response and postcondition: Confirm the delete response, refresh the list, and verify the user no longer appears in the selected site.
  • Recovery: To recover a deleted user, contact TaruviBase support with the exported record.

Delete the site user only after completing the checks above.

import {User} from '@taruvi/sdk';

const users = new User(taruvi);
await users.deleteUser("onboarding-user");

Refresh the site's user list and confirm the deleted user no longer appears.

For other problems, see troubleshooting.