---
title: "Create initial admin account"
method: POST
path: "/auth/setup"
tags: ["auth"]
---

# Create initial admin account

`POST /auth/setup`

Creates the first admin user during initial setup. Only available when no users exist. Returns a JWT token for immediate login.

## Query parameters

- `remoteNode` string

## Request body

- SetupRequest — Request body for initial admin account setup
  - `username` string, required — Admin username
  - `password` string, required — Admin password

## Response `200`

Admin account created successfully

- LoginResponse — Response containing authentication token
  - `token` string, required — JWT authentication token
  - `expiresAt` string, date-time, required — Token expiration timestamp
  - `user` User, required — User information
    - `id` string, required — Unique user identifier
    - `username` string, required — User's username
    - `role` 'admin' | 'manager' | 'developer' | 'operator' | 'viewer', required — User role determining access permissions. admin: full access including user management, manager: DAG CRUD and execution with audit log access, developer: DAG CRUD and execution, operator: DAG execution only, viewer: read-only
    - `workspaceAccess` WorkspaceAccess, required — Workspace access policy. all=true grants the top-level role in every workspace. all=false requires explicit workspace grants and a top-level viewer role.
      - `all` boolean, required — Whether this identity can access all workspaces
      - `grants` WorkspaceGrant[], required — Workspace-specific grants used when all=false — unresolved $ref
    - `authProvider` 'builtin' | 'oidc' | 'proxy' — Authentication provider for a user account
    - `isDisabled` boolean — Whether the user account is disabled
    - `createdAt` string, date-time, required — Account creation timestamp
    - `updatedAt` string, date-time, required — Last update timestamp

## Other responses

- `400` — Invalid request (e.g., weak password)
- `403` — Setup already completed (users exist)
- `default` — Unexpected error

---

[API](https://skmtc.net/dagucloud/apis/dagu.md) · [All operations](https://skmtc.net/dagucloud/apis/dagu/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/dagucloud/dagu/revisions/f8982f33e540/schema)
