Users & Access Keys API
Lioran S3 includes native user identity and credential management APIs accessible via client.users and client.accessKeys.
1. User Management (client.users)
:::info Administrative Privileges
Creating, updating, disabling, deleting users, or resetting passwords requires an authenticated account with the admin role.
:::
Create a User Account
import { BastionClient, type UserRole } from "@liorans3/driver";
const client = new BastionClient("bastion://admin:YOUR_PASSWORD@127.0.0.1:27118");
const newUser = await client.users.create({
username: "ci-bot",
password: "StrongPasswordHere123!",
role: "readwrite", // "admin" | "readwrite" | "readonly"
});
console.log(`Created user ${newUser.username} with role ${newUser.role}`);
List All Users
const users = await client.users.list();
for (const u of users) {
console.log(`User: ${u.username} | Role: ${u.role} | Active: ${u.is_active} | Must Change Pass: ${u.must_change_password}`);
}
Update User Role & Status
// Promote user to admin
await client.users.update("developer", {
role: "admin",
isActive: true,
});
// Or use helper methods:
await client.users.disable("temp-contractor");
await client.users.enable("temp-contractor");
Self-Service Password Change
Any authenticated user can change their own password without administrator intervention:
const message = await client.users.changePassword(
"CurrentPassword123!",
"NewSecurePassword456!"
);
console.log("Result:", message);
Administrative Password Reset
Administrators can reset any user's password and optionally require them to change it on their next login:
await client.users.resetPassword("developer", "TemporaryPassword789!", {
mustChangePassword: true,
});
Delete a User Account
const deleted = await client.users.delete("obsolete-user");
console.log("Deleted:", deleted);
2. Programmatic Access Keys (client.accessKeys)
Programmatic Access Keys are ideal for backend services, daemon processes, and CI/CD pipelines.
Create an Access Key
const key = await client.accessKeys.create({
name: "production-backup-service",
expiresAt: new Date(Date.now() + 90 * 86400 * 1000), // 90-day expiration
});
console.log("Key ID:", key.id); // e.g. "bk_live_0192a7b8c9d0"
console.log("Secret Key:", key.secret); // e.g. "sk_live_9f83a21b4c7e..."
console.log("Owner:", key.owner);
:::warning Secret Displayed Once
The secret field is returned only once during initial creation or rotation. It cannot be retrieved later.
:::
List Access Keys
// List current user's keys
const myKeys = await client.accessKeys.list();
// Admin: Filter keys by specific owner
const userKeys = await client.accessKeys.list({ user: "ci-bot" });
for (const k of userKeys) {
console.log(`Key ID: ${k.id} (${k.name}) - Revoked: ${k.is_revoked}`);
}
Rotate an Access Key
Rotating a key immediately revokes the old secret and generates a new secret for the same Key ID:
const rotated = await client.accessKeys.rotate("bk_live_0192a7b8c9d0");
console.log("Key ID:", rotated.id);
console.log("New Secret Key:", rotated.secret);
Revoke / Delete an Access Key
const deleted = await client.accessKeys.delete("bk_live_0192a7b8c9d0");
console.log("Access key revoked:", deleted);