CockroachDB SQLUsers API
Manage SQL users for a cluster, including creating users, listing users, and updating SQL user passwords.
Manage SQL users for a cluster, including creating users, listing users, and updating SQL user passwords.
openapi: 3.1.0
info:
title: CockroachDB Cloud APIKeys SQLUsers API
description: The CockroachDB Cloud API is a REST interface that provides programmatic access to manage the lifecycle of clusters within a CockroachDB Cloud organization. It enables developers and operators to create, configure, scale, and delete CockroachDB Serverless and Dedicated clusters without using the web console. The API supports cluster provisioning, node management, network authorization, customer-managed encryption keys, backup and restore, log and metric export, role management, and folder organization. Authentication is handled via bearer tokens, and the API is rate-limited to 10 requests per second per user.
version: '2024-09-16'
contact:
name: Cockroach Labs Support
url: https://support.cockroachlabs.com
termsOfService: https://www.cockroachlabs.com/cloud-terms-and-conditions/
servers:
- url: https://cockroachlabs.cloud
description: CockroachDB Cloud Production Server
security:
- bearerAuth: []
tags:
- name: SQLUsers
description: Manage SQL users for a cluster, including creating users, listing users, and updating SQL user passwords.
paths:
/api/v1/clusters/{cluster_id}/sql-users:
get:
operationId: ListSQLUsers
summary: List SQL users
description: Returns a list of SQL users for the specified cluster. Accessible to users with CLUSTER_ADMIN, CLUSTER_OPERATOR_WRITER, or CLUSTER_DEVELOPER roles.
tags:
- SQLUsers
parameters:
- $ref: '#/components/parameters/clusterId'
- $ref: '#/components/parameters/paginationPage'
- $ref: '#/components/parameters/paginationLimit'
- $ref: '#/components/parameters/paginationAsOfTime'
- $ref: '#/components/parameters/paginationSortOrder'
responses:
'200':
description: List of SQL users returned successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/ListSQLUsersResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
post:
operationId: CreateSQLUser
summary: Create a SQL user
description: Creates a new SQL user for the specified cluster. Requires CLUSTER_ADMIN role at organization, folder, or cluster scope.
tags:
- SQLUsers
parameters:
- $ref: '#/components/parameters/clusterId'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CreateSQLUserRequest'
responses:
'200':
description: SQL user created successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/SQLUser'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
/api/v1/clusters/{cluster_id}/sql-users/{name}:
delete:
operationId: DeleteSQLUser
summary: Delete a SQL user
description: Deletes a SQL user from the specified cluster by username. Requires CLUSTER_ADMIN role.
tags:
- SQLUsers
parameters:
- $ref: '#/components/parameters/clusterId'
- $ref: '#/components/parameters/sqlUserName'
responses:
'200':
description: SQL user deleted successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/SQLUser'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
/api/v1/clusters/{cluster_id}/sql-users/{name}/password:
put:
operationId: UpdateSQLUserPassword
summary: Update SQL user password
description: Updates the password for the specified SQL user on the given cluster. Requires CLUSTER_ADMIN role at organization, folder, or cluster scope.
tags:
- SQLUsers
parameters:
- $ref: '#/components/parameters/clusterId'
- $ref: '#/components/parameters/sqlUserName'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateSQLUserPasswordRequest'
responses:
'200':
description: SQL user password updated successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/SQLUser'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
components:
responses:
BadRequest:
description: The request body or parameters are invalid.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Unauthorized:
description: Authentication credentials are missing or invalid.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
NotFound:
description: The requested resource was not found.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
parameters:
paginationSortOrder:
name: pagination.sort_order
in: query
description: Sort direction for paginated results. Accepted values are ASC and DESC.
schema:
type: string
enum:
- ASC
- DESC
paginationAsOfTime:
name: pagination.as_of_time
in: query
description: RFC3339 timestamp to return results as they were at a specific point in time (time-travel query).
schema:
type: string
format: date-time
sqlUserName:
name: name
in: path
required: true
description: Username of the SQL user.
schema:
type: string
clusterId:
name: cluster_id
in: path
required: true
description: Unique identifier of the CockroachDB Cloud cluster.
schema:
type: string
paginationLimit:
name: pagination.limit
in: query
description: Maximum number of results to return per page.
schema:
type: integer
format: int32
minimum: 1
maximum: 500
paginationPage:
name: pagination.page
in: query
description: Page number for paginated results, starting from 1.
schema:
type: string
schemas:
CreateSQLUserRequest:
type: object
description: Request body for creating a new SQL user.
required:
- name
- password
properties:
name:
type: string
description: Username for the new SQL user.
password:
type: string
description: Initial password for the SQL user.
format: password
ListSQLUsersResponse:
type: object
description: Paginated list of SQL users for a cluster.
properties:
users:
type: array
description: Array of SQL user objects.
items:
$ref: '#/components/schemas/SQLUser'
pagination:
$ref: '#/components/schemas/PaginationResponse'
Error:
type: object
description: Standard error response returned by the API.
properties:
code:
type: integer
description: HTTP status code of the error.
message:
type: string
description: Human-readable description of the error.
details:
type: array
description: Additional detail objects providing error context.
items:
type: object
UpdateSQLUserPasswordRequest:
type: object
description: Request body for updating a SQL user's password.
required:
- password
properties:
password:
type: string
description: New password for the SQL user.
format: password
SQLUser:
type: object
description: Represents a SQL user on a CockroachDB cluster.
properties:
name:
type: string
description: Username of the SQL user.
PaginationResponse:
type: object
description: Pagination metadata included in list responses.
properties:
next:
type: string
description: Token or cursor for retrieving the next page of results.
last:
type: string
description: Token or cursor for the last page of results.
time:
type: string
format: date-time
description: Server time at which the paginated query was executed.
securitySchemes:
bearerAuth:
type: http
scheme: bearer
description: Bearer token authentication. Generate a token in the CockroachDB Cloud Console under Organization Settings > API Access.
externalDocs:
description: CockroachDB Cloud API Documentation
url: https://www.cockroachlabs.com/docs/cockroachcloud/cloud-api