Users, tokens & admin
Methods for managing users, personal access tokens, integrations, uploads, tenants, and health checks on the Istari Digital Platform.
Methods below are on the Client instance. batch_resolve_users() is the exception: it is on V3Client. Parameters marked (required) must be provided. See Enums for valid enum values and Pagination for page/size defaults.
To manage the identity service's tenants, memberships, role grants and principal keys, use IstariAdmin.identity. Identity administration documents it, and lists the deprecated v1 key methods with their replacements.
Users
get_user()
Retrieve a user from the registry.
This is a convenience wrapper around getuser_by_id, provided for naming consistency with other get* methods (e.g., get_model, get_artifact, etc.).
-
Parameters: user_id (str) – Unique identifier of the user to retrieve.
-
Return Type: User
get_user_by_id()
Gets a user by id.
-
Parameters:
- user_id (str) – The id of the user. (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: User
get_current_user()
Gets the current user.
-
Parameters: http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: User
list_users()
Lists all users a user has access to.
-
Parameters:
- user_state (UserStateOption) – Filter users by state. One of:
active,all. Default:active. - user_type (UserType) – Filter users by type. One of:
human,agent,all. Default:all. - http_request_timeout_secs (int , optional) – timeout setting for this request
- user_state (UserStateOption) – Filter users by state. One of:
-
Return Type: List[User]
batch_resolve_users()
Resolves registry users from identity-service principal ids. Call it on V3Client.
-
Parameters:
- batch_resolve_users_request (
BatchResolveUsersRequest) – (required).principal_idsis 1 to 100 ids. Duplicates are ignored. - http_request_timeout_secs (int, optional)
- batch_resolve_users_request (
-
Return Type:
BatchResolveUsersResponse.usersare the registry users that resolved.unresolvedlists requested ids the caller cannot see.
Personal access tokens
create_personal_access_token()
Creates a personal access token.
-
Parameters:
- name (str) – The name of the personal access token. (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: PersonalAccessToken
create_agent_personal_access_token()
Creates an agent personal access token.
-
Parameters:
- name (str) – The name of the personal access token. (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: PersonalAccessToken
list_personal_access_tokens()
Lists all personal access tokens a user has access to.
-
Parameters:
- page (int) – Page number
- size (int) – Page size
- sort (str)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: PagePersonalAccessToken
delete_personal_access_token()
Deletes a personal access token.
-
Parameters:
- pat_id (str) – The personal access token id. (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: object
revoke_all_personal_access_tokens()
Revokes all personal access tokens.
-
Parameters: http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: object
Auth integrations
create_auth_integration()
Create a new authentication integration.
This method registers an authentication integration by uploading a registration file. The registration file typically contains OAuth credentials or other provider-specific configuration.
-
Parameters:
- auth_integration_type (AuthIntegrationType) – The type of authentication provider. One of:
google_accounts,windchill,teamwork_cloud,dassault_3d_passport,ping_id,microsoft_entra. (required) - auth_type (FunctionAuthType) – The authentication mechanism. One of:
jwt,token,basic,oauth1,oauth2,cas_delegated_3dx. (required) - auth_registration_path (PathLike) – Filesystem path to the registration configuration file. (required)
- auth_integration_type (AuthIntegrationType) – The type of authentication provider. One of:
-
Return Type: AuthIntegration
update_auth_integration()
Update an existing authentication integration.
This method updates an authentication integration's type, auth mechanism, and/or registration file. If a new registration file is provided, its contents replace the existing registration revision.
-
Parameters:
- auth_integration_id (UUID) – Identifier of the authentication integration to update. (required)
- auth_integration_type (AuthIntegrationType | None) – Optional updated provider type. One of:
google_accounts,windchill,teamwork_cloud,dassault_3d_passport,ping_id,microsoft_entra. - function_auth_type (FunctionAuthType | None) – Optional updated authentication mechanism. One of:
jwt,token,basic,oauth1,oauth2,cas_delegated_3dx. - auth_registration_path (PathLike | None) – Optional filesystem path to a new registration configuration file.
-
Return Type: AuthIntegration
get_auth_integration()
Retrieves an AuthIntegration.
-
Parameters:
- auth_integration_id (str) – The unique name of the AuthIntegration to update (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: AuthIntegration
list_auth_integrations()
Lists all AuthIntegrations a user has access to.
-
Parameters:
- auth_integration_type (AuthIntegrationType) – Filter by provider type. One of:
google_accounts,windchill,teamwork_cloud,dassault_3d_passport,ping_id,microsoft_entra. - auth_type (FunctionAuthType) – Filter by auth mechanism. One of:
jwt,token,basic,oauth1,oauth2,cas_delegated_3dx. - archive_status (ArchiveStatus) – Filter results by archive status. One of:
active,archived,all. Default:active. - page (int) – Page number
- size (int) – Page size
- http_request_timeout_secs (int , optional) – timeout setting for this request
- auth_integration_type (AuthIntegrationType) – Filter by provider type. One of:
-
Return Type: PageAuthIntegration
add_function_auth_secret()
Create a new function authentication secret from a file.
This method uploads a secret from a file and registers it as a function auth secret of the specified type. You may optionally associate it with an authentication integration and set an expiration date.
-
Parameters:
- function_auth_type (FunctionAuthType) – The type of function authentication. One of:
jwt,token,basic,oauth1,oauth2,cas_delegated_3dx. (required) - path (PathLike) – Filesystem path to the file containing the secret.
- auth_integration_id (Optional [**str ]) – Optional identifier of the associated authentication integration.
- expiration (Optional [**datetime ]) – Optional expiration date/time of the secret.
- function_auth_type (FunctionAuthType) – The type of function authentication. One of:
-
Return Type: FunctionAuthSecret
fetch_function_auth_secret()
Gets a function auth secret by id.
-
Parameters:
- auth_secret_id (str) – The function auth secret ID to get. (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: FunctionAuthSecret
find_function_auth_secret()
Lists all function auth secrets that a user has access to.
-
Parameters:
- auth_integration_type (AuthIntegrationType) – Filter by authentication provider type. One of:
google_accounts,windchill,teamwork_cloud,dassault_3d_passport,ping_id,microsoft_entra. - function_auth_type (FunctionAuthType) – Filter by authentication mechanism. One of:
jwt,token,basic,oauth1,oauth2,cas_delegated_3dx. - expiration (datetime)
- latest (bool)
- http_request_timeout_secs (int , optional) – timeout setting for this request
- auth_integration_type (AuthIntegrationType) – Filter by authentication provider type. One of:
-
Return Type: List[FunctionAuthSecret]
get_integration_catalog()
Lists the integrations an administrator can configure.
-
Parameters:
- http_request_timeout_secs (int, optional)
-
Return Type: list of
IntegrationCatalogEntry
check_auth_integration_health()
Health-checks a stored auth integration.
-
Parameters:
- auth_integration_id (str) – Auth integration to check. (required)
- http_request_timeout_secs (int, optional)
-
Return Type:
IntegrationHealthReport
check_auth_integration_config_health()
Health-checks a candidate configuration before it is saved. Exactly one of oidc_provider_data or oauth1_provider_data selects the standard. For OAuth 1.0a the secret is the consumer secret. When client_secret is omitted and auth_integration_id names an existing integration, the stored secret is used.
-
Parameters:
- oidc_config_health_check_request (
OidcConfigHealthCheckRequest) – (required). Fields:oidc_provider_data,oauth1_provider_data,client_secret,auth_integration_id. - http_request_timeout_secs (int, optional)
- oidc_config_health_check_request (
-
Return Type:
IntegrationHealthReport
archive_auth_integration()
Removes an auth integration. The request is an HTTP DELETE. There is no restore method.
-
Parameters:
- auth_integration_id (str) – Auth integration to remove. (required)
- http_request_timeout_secs (int, optional)
-
Return Type: AuthIntegration
get_auth_integration_control_taggings()
Returns the control tags currently on an auth integration.
-
Parameters:
- auth_integration_id (str) – (required)
- http_request_timeout_secs (int, optional)
-
Return Type: list of
AuthIntegrationControlTagging
get_auth_integration_control_tagging_history()
Returns the control-tag history for an auth integration.
-
Parameters:
- auth_integration_id (str) – (required)
- http_request_timeout_secs (int, optional)
-
Return Type: list of
AuthIntegrationControlTagging
patch_auth_integration_control_taggings()
Adds or removes control tags on an auth integration.
-
Parameters:
- auth_integration_id (str) – (required)
- request_body (list of str) – Control tag ids. (required)
- patch_op (PatchOp) –
setordelete. - reason (str, optional)
- http_request_timeout_secs (int, optional)
-
Return Type: list of
AuthIntegrationControlTagging
Storage and uploads
Uploading a Resource from a filesystem path is add_model() on Client, or create_resource() on V3Client. The calls in this section are the presigned URL, multipart, and tenant-key operations on Client.
generate_upload_url()
Returns a temporary upload url for token with sha
-
Parameters:
- sha (str) – (required)
- model_id (str)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: TemporaryURL
generate_download_url()
Returns a temporary download url for tokenized resource with SHA value
-
Parameters:
- sha (str) – (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: TemporaryURL
create_multipart_upload()
Returns the metadata needed to perform a multipart upload for a given token with the SHA
-
Parameters:
- create_multipart_upload_request (CreateMultipartUploadRequest) – (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: CreateMultipartUploadResponse
finalize_multipart_upload()
Finalize a multipart upload for a given token with the SHA
-
Parameters:
- finalize_multipart_upload_request (FinalizeMultipartUploadRequest) – (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: object
create_tenant_public_key()
Creates a tenant public key.
-
Parameters:
- public_key_file (bytearray) – (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: TenantPublicKey
get_tenant_public_key()
Gets a tenant public key.
-
Parameters: http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: TenantPublicKey
list_tenants()
Lists tenants in the registry. Which tenants the caller gets depends on their role:
- On installations with tenant management: a Platform Administrator (role
admin) gets every tenant, and a Tenant Administrator (roletenant_admin) gets only their own. - On other installations: the caller must hold the
customer_adminrole, and gets every tenant.
The registry builds this list from your sign-in provider's organizations. On an installation with tenant management, a tenant created with admin.identity.tenants.create() has no organization, so it does not appear here. To list the identity service's tenants, use admin.identity.tenants.list().
-
Parameters:
- page (int) – Page number
- size (int) – Page size
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: PageTenant
generate_upload_urls_bulk()
Returns a temporary upload URL for each SHA.
-
Parameters:
- request_body (list of str) – SHA values. (required)
- model_id (str, optional)
- http_request_timeout_secs (int, optional)
-
Return Type: list of TemporaryURL
update_tenant_public_key()
Replaces the tenant public key.
-
Parameters:
- public_key_file (bytes or str or a (filename, bytes) tuple) – (required)
- http_request_timeout_secs (int, optional)
-
Return Type: TenantPublicKey
delete_tenant_public_key()
Deletes the tenant public key.
-
Parameters:
- http_request_timeout_secs (int, optional)
-
Return Type:
None
Upstream remotes
list_upstream_remotes()
Retrieves a list of upstream remotes that a user has access to.
-
Parameters:
- page (int) – Page number
- size (int) – Page size
- sort (str)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: PageUpstreamRemote
sync_upstream_remotes()
Triggers a data sync with an upstream remote.
-
Parameters:
- create_upstream_remote_sync (CreateUpstreamRemoteSync) – (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: UpstreamRemoteSync
get_upstream_remote_sync()
Retrieves the status of an upstream remote sync.
-
Parameters:
- upstream_remote_sync_id (str) – (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: UpstreamRemoteSync
check_upstream_remote_compatibility()
Check this registry's compatibility with every configured upstream remote. Returns the per-remote compatibility result so you can verify versions before triggering sync_upstream_remotes.
-
Parameters: http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: UpstreamRemoteCompatibilityResult
Health and metrics
customer_usage_metrics()
Is for customers to query their data for usage metrics.
-
Parameters:
- start (date) – YYYY-MM-DD (required)
- end (date) – YYYY-MM-DD (required)
- http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: str
liveness_check()
Liveness probe
-
Parameters: http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: HealthcheckReport
readiness_check()
Readiness probe
-
Parameters: http_request_timeout_secs (int , optional) – timeout setting for this request
-
Return Type: HealthcheckReport