Applications API
Manage applications (SaaS products) that clients and RBAC are scoped to.
Base path: /api/admin/applications
Deployment-global entities
Applications, modules, roles, permissions, and claim definitions are shared across every organization. Creating, changing, or deleting them can affect all organizations that use the application. See the Core ownership model.
Create Application
POST /api/admin/applications| Field | Type | Required | Description |
|---|---|---|---|
name | string | ✅ | Application display name |
slug | string | URL slug (auto-generated from name) | |
description | string | Description of the application |
{
"name": "ERP System",
"description": "Enterprise resource planning application"
}Response: 201 Created
List Applications
GET /api/admin/applicationsSupports page, pageSize, search, status, sort, order parameters.
Response: 200 OK — Paginated list of applications.
Get Application
GET /api/admin/applications/:idResponse: 200 OK — Full application object.
Update Application
PUT /api/admin/applications/:id| Field | Type | Description |
|---|---|---|
name | string | Display name |
description | string | Description |
Response: 200 OK
Activate / Deactivate
POST /api/admin/applications/:id/activate
POST /api/admin/applications/:id/deactivateResponse: 200 OK — Updated application with new status.
Application Modules
Modules are logical groupings within an application (e.g., CRM, Invoicing, HR).
Add Module
POST /api/admin/applications/:id/modules| Field | Type | Required | Description |
|---|---|---|---|
name | string | ✅ | Module name |
slug | string | Module slug | |
description | string | Module description |
List Modules
GET /api/admin/applications/:id/modulesUpdate Module
PUT /api/admin/applications/:id/modules/:moduleIdDeactivate Module
POST /api/admin/applications/:id/modules/:moduleId/deactivateDelete Module
DELETE /api/admin/applications/:appId/modules/:moduleIdPermanently deletes the module and cascades to its permissions and dependent links.
Permission: admin:module:delete
Response: 204 No Content
Delete Application
DELETE /api/admin/applications/:idPermanently deletes the deployment-global application and its modules, clients, roles, permissions, claim definitions, and dependent security data. Affected sessions and protocol authority are revoked.
Permission: admin:app:delete
Response: 204 No Content