API Reference
Complete API reference for managing Strapi admin users and tokens.
Authentication
All endpoints require an admin JWT token. Obtain it by logging into the Strapi Admin Panel or using:
curl -X POST http://localhost:1337/admin/auth/admin/login \
-H "Content-Type: application/json" \
-d '{"email": "admin@example.com", "password": "password"}'Copy the JWT from the response and include it in the Authorization header:
Authorization: Bearer YOUR_JWT_TOKENUsers API
Base URL
/admin-api/usersList All Users
GET /admin-api/users
Lists all admin users with pagination and filtering.
Query Parameters:
start(number, default: 0) - Pagination startlimit(number, default: 25) - Items per pagesort(string, default:createdAt:desc) - Sort fieldpopulate(string) - Populate related data
Example:
curl -X GET http://localhost:1337/admin-api/users \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Response:
{
"data": [
{
"id": 1,
"email": "admin@example.com",
"username": "admin",
"firstName": "Admin",
"lastName": "User",
"isActive": true,
"blocked": false,
"role": {
"id": 1,
"name": "Super Admin",
"code": "super-admin"
},
"createdAt": "2024-01-01T00:00:00.000Z",
"updatedAt": "2024-01-01T00:00:00.000Z"
}
],
"meta": {
"pagination": {
"total": 1,
"page": 1,
"pageSize": 25
}
}
}Get Single User
GET /admin-api/users/:id
Example:
curl -X GET http://localhost:1337/admin-api/users/1 \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Create User
POST /admin-api/users
Request Body:
{
"email": "newuser@example.com",
"username": "newuser",
"password": "SecurePassword123!",
"firstName": "John",
"lastName": "Doe",
"isActive": true
}Example:
curl -X POST http://localhost:1337/admin-api/users \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"email": "newuser@example.com",
"username": "newuser",
"password": "SecurePassword123!",
"firstName": "John",
"lastName": "Doe"
}'Update User
PUT /admin-api/users/:id
Request Body:
{
"firstName": "Jane",
"lastName": "Smith",
"isActive": false
}Delete User
DELETE /admin-api/users/:id
Note: Super-admin users cannot be deleted.
Example:
curl -X DELETE http://localhost:1337/admin-api/users/2 \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Response:
{
"success": true,
"message": "Admin user deleted successfully"
}Reset Password
POST /admin-api/users/:id/reset-password
Request Body:
{
"password": "newSecurePassword456"
}Tokens API
Base URL
/admin-api/tokensList Your Tokens
GET /admin-api/tokens
Lists all authentication tokens for the authenticated user.
Example:
curl -X GET http://localhost:1337/admin-api/tokens \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Create Token
POST /admin-api/tokens
Request Body:
{
"label": "My API Token",
"type": "api",
"expiresAt": "2025-12-31T23:59:59.000Z"
}Parameters:
label(string, required) - Descriptive labeltype(string, optional) - Token type (default:api)expiresAt(string, optional) - ISO 8601 date (default: 30 days)
Example:
curl -X POST http://localhost:1337/admin-api/tokens \
-H "Authorization: Bearer YOUR_JWT_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"label": "My API Token"
}'Response:
{
"id": 1,
"label": "My API Token",
"type": "api",
"expiresAt": "2025-01-31T00:00:00.000Z",
"active": true,
"message": "Token created successfully",
"value": "c2VjdXJlLXRva2VuLXZhbHVlLW9mLW1l..."
}⚠️ Important: Copy the value field immediately! It won't be shown again.
Update Token
PUT /admin-api/tokens/:id
Request Body:
{
"label": "Updated Label",
"type": "webhook"
}Note: The token value cannot be changed. Regenerate the token instead.
Delete Token
DELETE /admin-api/tokens/:id
Example:
curl -X DELETE http://localhost:1337/admin-api/tokens/1 \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Revoke Token
POST /admin-api/tokens/:id/revoke
Revokes a token immediately without deleting it.
Example:
curl -X POST http://localhost:1337/admin-api/tokens/1/revoke \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Response:
{
"success": true,
"message": "Token revoked successfully"
}Refresh Token Expiration
POST /admin-api/tokens/:id/refresh
Extends the token's expiration date (default: +30 days).
Request Body (optional):
{
"expiresAt": "2026-12-31T23:59:59.000Z"
}Example:
curl -X POST http://localhost:1337/admin-api/tokens/1/refresh \
-H "Authorization: Bearer YOUR_JWT_TOKEN"Security Best Practices
- Keep tokens secure - Never commit them to version control
- Rotate regularly - Use the refresh endpoint regularly
- Set reasonable expiration - Especially for API tokens
- Use labels - Identify tokens in different environments
- Revoke immediately - If a token is compromised
- Use RBAC - Restrict access to only necessary operations
- Audit regularly - Check token usage logs
Error Responses
All endpoints return standard HTTP status codes:
200- Success400- Bad request401- Unauthorized (missing or invalid token)404- Not found500- Internal server error
Example error response:
{
"error": {
"status": 401,
"name": "UnauthorizedError",
"message": "Authentication required"
}
}License
MIT