Admin API

Administrative endpoints for managing organization-level settings, external integrations, and operational infrastructure. Most procedures require elevated permissions (org_owner, tenant_admin, or site_admin roles).

Billing

Read-only billing information and plan enforcement. Stripe integration handles checkout sessions and payment methods.

Plan hierarchy: free → starter → pro → enterprise

Endpoints


GET /api/v1/admin/billing/subscription

Get the current organization’s subscription plan and Stripe subscription information.

tRPC: billing.getSubscription Auth: Bearer token required (scope: read:items) or session cookie. Role: org_owner only. Org context: Required

Response:

{
  "plan": "pro",
  "status": "active",
  "stripeCustomerId": "cus_xxx",
  "stripeSubscriptionId": "sub_xxx",
  "currentPeriodEnd": "2026-05-01T00:00:00.000Z",
  "limits": {
    "maxMembers": 50,
    "maxBoards": 100,
    "maxWorkspaces": 10
  }
}

GET /api/v1/admin/billing/feature-gate

Check if the current plan allows a specific gated feature.

tRPC: billing.checkFeatureGate Auth: Bearer token required or session cookie Org context: Required

Parameters:

NameTypeRequiredDescription
featurestringYesFeature to check: automations, kpis, templates, csv_import, escalation, sso, api_access, custom_branding, advanced_analytics, audit_log

SSO Configuration

Per-tenant Single Sign-On configuration supporting OIDC and SAML identity providers. The OIDC client secret is never returned in API responses.

tRPC-Only SSO Procedures

ProcedureTypeDescription
sso.getConfigqueryGet SSO configuration (admin only, secret masked)
sso.saveConfigmutationCreate or update SSO config (upsert)
sso.deleteConfigmutationRemove SSO configuration entirely
sso.testConnectionmutationVerify OIDC config by fetching .well-known
sso.activatemutationEnable SSO after readiness check
sso.deactivatemutationDisable SSO and turn off enforcement
sso.toggleEnforcementmutationEnable/disable SSO-only login enforcement

Supported providers: OIDC (any OpenID Connect provider), SAML (with IdP metadata parsing and SP metadata generation)


API Keys

Manage programmatic API keys for REST and MCP access. Keys follow the pattern probeya_sk_live_{40 hex chars} with bcrypt-hashed storage.

Endpoints


POST /api/v1/admin/api-keys

Generate a new API key. The full key is returned once in the response and never again.

tRPC: apiKeys.create Auth: Session cookie only (not API key). Role: manage_settings permission required. Org context: Required

Parameters:

NameTypeRequiredDescription
namestringYesHuman-readable label (e.g., “iOS App”, “CI Pipeline”)
scopesstring[]NoPermission scopes to restrict access (empty = full access)
expiresAtstringNoExpiration date (ISO 8601)

Response:

{
  "key": "probeya_sk_live_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0",
  "apiKey": {
    "id": "clx9ak001",
    "name": "CI Pipeline",
    "prefix": "a1b2c3d4",
    "scopes": ["read:items", "write:items"],
    "expiresAt": "2027-01-01T00:00:00.000Z",
    "createdAt": "2026-04-01T10:00:00.000Z"
  }
}

The full API key is shown only once at creation time. Store it securely — it cannot be retrieved later.

tRPC-Only API Key Procedures

ProcedureTypeDescription
apiKeys.listqueryList all API keys (hash never returned, prefix shown)
apiKeys.revokemutationPermanently revoke a key (irreversible)
apiKeys.rotatemutationAtomically revoke old key and create new one
apiKeys.deletemutationHard-delete a key record

Webhooks

Outgoing webhook management for event-driven integrations. Secrets are auto-generated using 256-bit entropy.

Lifecycle: created → active → disabled (after 10 failures or manual) → re-enabled → deleted

Endpoints


POST /api/v1/webhooks

Register a new webhook endpoint with auto-generated HMAC signing secret.

tRPC: webhooks.create Auth: Session cookie. Role: manage_settings permission required. Org context: Required

Parameters:

NameTypeRequiredDescription
urlstringYesHTTPS endpoint URL for POST notifications
eventsstring[]YesEvent types to subscribe to (min 1)

tRPC-Only Webhook Procedures

ProcedureTypeDescription
webhooks.listqueryList all webhooks for the organization
webhooks.getqueryGet webhook with delivery log
webhooks.updatemutationUpdate URL, events, or enabled status
webhooks.deletemutationHard-delete a webhook
webhooks.testmutationSend a synthetic event to verify the endpoint

Integrations (Slack & Teams)

Manage Slack and Microsoft Teams integrations via incoming webhook URLs.

tRPC-Only Integration Procedures

ProcedureTypeDescription
integrations.listqueryList all messaging integrations
integrations.createmutationRegister Slack or Teams integration with webhook URL
integrations.updatemutationUpdate name, URL, or subscribed events
integrations.deletemutationRemove an integration
integrations.togglemutationEnable or disable an integration
integrations.testmutationSend a test message to verify the webhook

Connectors

External system connectors for SAP S/4HANA, MES, QMS, generic REST APIs, and webhook receivers.

Connector lifecycle: pending_setup → active → error | disabled

tRPC-Only Connector Procedures

ProcedureTypeDescription
connectors.createmutationRegister a new connector with type, config, sync frequency
connectors.updatemutationUpdate connector configuration
connectors.deletemutationRemove a connector
connectors.listqueryPaginated list with type and status filters
connectors.getByIdqueryConnector detail with sync history
connectors.testConnectionmutationVerify connectivity using the adapter health check

Site Agents (IoT Gateway)

Industrial edge gateways connecting PLCs, SCADA systems, and IoT devices via OPC-UA, MQTT, S7comm, Modbus, and REST protocols.

Agent lifecycle: offline → online → error | maintenance

tRPC-Only Site Agent Procedures

ProcedureTypeDescription
siteAgents.createAgentmutationRegister an edge gateway with protocol and data points
siteAgents.listAgentsqueryList agents with site, status, protocol filters
siteAgents.getAgentqueryAgent detail with recent data points
siteAgents.updateAgentmutationUpdate agent config, data points, status
siteAgents.deleteAgentmutationRemove an agent registration
siteAgents.ingestDataPointmutationPush a tag reading from an agent
siteAgents.listDataPointsqueryQuery time-series data points for an agent

Protocols: opcua, mqtt, s7comm, modbus, rest


Report Schedules

Automated PDF report generation and email delivery on daily, weekly, or monthly cadence.

tRPC-Only Report Schedule Procedures

ProcedureTypeDescription
reportSchedules.listqueryList all report schedules
reportSchedules.createmutationCreate a schedule with frequency, recipients, and parameters
reportSchedules.updatemutationUpdate schedule settings
reportSchedules.deletemutationDelete a schedule
reportSchedules.togglemutationEnable or disable a schedule
reportSchedules.runNowmutationManually trigger a schedule for testing

Error Codes

CodeDescription
400Invalid input (e.g., unknown feature name, invalid URL)
401Missing or invalid authentication
403Insufficient permissions (admin role required for most operations)
404Entity not found in this organization
409Conflict (e.g., duplicate SSO configuration)