> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open-cluster.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Bootstrap local admin



## OpenAPI

````yaml /api/openapi.yaml post /api/v1/auth/local/bootstrap
openapi: 3.1.0
info:
  title: OpenCluster Control Plane API
  version: 0.1.0
  description: HTTP contract for the OpenCluster product API and inbound webhook endpoints.
  license:
    name: Apache-2.0
servers:
  - url: http://localhost:8080
    description: Local self-hosted deployment
security: []
tags:
  - name: Authentication
  - name: Organizations
  - name: Members
  - name: Sessions
  - name: Policy
  - name: Audit
  - name: Integration Types
  - name: Integrations
  - name: Relays
  - name: Incidents
  - name: Investigations
  - name: Conversations
  - name: Postmortems
  - name: Webhook Deliveries
  - name: Webhook Intake
  - name: Metadata
paths:
  /api/v1/auth/local/bootstrap:
    post:
      tags:
        - Authentication
      summary: Bootstrap local admin
      operationId: bootstrapLocalAdmin
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LocalBootstrapRequest'
        required: true
      responses:
        '201':
          $ref: '#/components/responses/BootstrapCreated'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
      security:
        - BootstrapToken: []
components:
  schemas:
    LocalBootstrapRequest:
      type: object
      additionalProperties: false
      required:
        - email
        - password
      properties:
        email:
          type: string
          format: email
          maxLength: 254
          example: operator@example.invalid
        displayName:
          type: string
          minLength: 1
          maxLength: 256
          example: On-call Operator
        password:
          type: string
          format: password
          minLength: 12
          maxLength: 1024
          writeOnly: true
          example: correct-horse-placeholder
    BootstrapResult:
      type: object
      additionalProperties: false
      required:
        - bootstrapped
      properties:
        bootstrapped:
          type: boolean
          const: true
    Error:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          type: string
          minLength: 1
          maxLength: 1024
          example: the selected Organization is not available to this caller
        reason:
          type: string
          enum:
            - credential_rejected
            - session_expired
            - session_revoked
        requires:
          type: string
          minLength: 1
          maxLength: 128
  responses:
    BootstrapCreated:
      description: Initial local User and membership-free session created atomically.
      headers:
        Set-Cookie:
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/BootstrapResult'
    BadRequest:
      description: Invalid request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Missing or rejected credential.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Conflict:
      description: The requested state conflicts with durable state.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    RateLimited:
      description: A bounded concurrency or request limit was reached.
      headers:
        Retry-After:
          schema:
            type: integer
            minimum: 1
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    BootstrapToken:
      type: http
      scheme: bearer
      description: Deployment bootstrap credential; accepted only until bootstrap succeeds.

````