---
title: "Create first admin (one-time setup)"
method: POST
path: "/users:create-admin"
tags: ["Users"]
---

# Create first admin (one-time setup)

`POST /users:create-admin`

First-run setup: create the first admin user and auto-login.

Unauthenticated by design — there is no admin to authenticate as yet. The
operation self-closes once any user exists (returns 410 ``setup_already_complete``
thereafter), so it is safe to expose only during first boot.

## Request body

- CreateAdminRequest — Payload for first-run admin creation (one-time setup).
  - `email` string, required
  - `first_name` string
  - `last_name` string
  - `password` string, required

## Response `200`

Successful Response

- LoginResponse — JWT token response after successful authentication.
  - `access_token` string, required
  - `expires_in` integer, required
  - `must_change_password` boolean, required
  - `token_type` string, required

## Other responses

- `400` — Bad Request
- `410` — Setup already complete — the first admin exists and this endpoint is closed.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-07-01** `d65fcba0d25a` — 1 info
  - endpoint added
- **2026-04-13** `76e8f6063728` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/users:create-admin/post.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/jentic/jentic-control-plane-api/revisions/f4594f50f4d3/schema)
