Skip to content

Users & admins

Passwords are stored as bcrypt hashes. Generate one, then insert the row:

Terminal window
python3 -c "import bcrypt,getpass;print(bcrypt.hashpw(getpass.getpass().encode(),bcrypt.gensalt()).decode())"

(pip install bcrypt first if needed.)

Terminal window
docker compose -f docker-compose.prod.yml exec db psql -U playdex -d playdex
insert into users (email, password) values ('friend@example.com', '$2b$11$…');

Send them the Web URL and their password. They can connect gaming accounts and set up notifications themselves under Settings.

update users set is_admin = true where email = 'friend@example.com'; -- promote
update users set is_admin = false where email = 'friend@example.com'; -- revoke

Admin checks is_admin against the database on every action, so a revoke takes effect immediately, even for an open session.

update users set password = '$2b$11$…new hash…', updated_at = now() where email = 'friend@example.com';

Existing Web sessions stay valid until their tokens expire: 15 minutes for the access token, 30 days for the refresh token. To sign everyone out at once, change Auth__JwtSecret and restart the API.

delete from users where email = 'friend@example.com';

This cascades to their sessions, integrations, notification channels and AI history.