Grafana self-managed server administration that the official contract restricts to Basic authentication: global organizations and users, LDAP, quotas, provisioning reloads, settings, passwords, sessions, auth tokens, and the service-account administration routes whose operation prose explicitly requires Basic authentication. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. This pack is intentionally separate because these 33 routes require Basic authentication and are unavailable to Grafana Cloud service-account tokens. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.
What it's allowed to do
Destructive
Web APIs
grafana-server-admin
external change
Read: admin_ldap.get_user_from_ldap · No approvalAdmin: admin_ldap.reload_ldap_cfg · Always asksRead: ldap.status · No approvalAdmin: admin_ldap.post_sync_user_with_ldap · Always asksAdmin: admin_provisioning.admin_provisioning_reload_dashboards · Always asksAdmin: admin_provisioning.admin_provisioning_reload_datasources · Always asksAdmin: admin_provisioning.admin_provisioning_reload_plugins · Always asksRead: admin.admin_get_settings · No approvalRead: admin.admin_get_stats · No approvalAdmin: user.create · Always asksDestructive: admin_users.admin_delete_user · Always asksRead: admin_users.admin_get_user_auth_tokens · No approvalAdmin: admin_users.admin_disable_user · Always asksAdmin: admin_users.admin_enable_user · Always asksAdmin: admin_users.admin_logout_user · Always asksAdmin: admin_users.admin_update_user_password · Always asksAdmin: admin_users.admin_update_user_permissions · Always asksRead: quota.get_user_quota · No approvalAdmin: quota.update_user_quota · Always asksAdmin: admin_users.admin_revoke_user_auth_token · Always asksRead: organization.list · No approvalDestructive: orgs.delete_org_by_id · Always asksRead: orgs.get_org_by_id · No approvalAdmin: orgs.update_org · Always asksAdmin: quota.update_org_quota · Always asksRead: orgs.get_org_users · No approvalRead: orgs.search_org_users · No approvalRead: orgs.get_org_by_name · No approvalAdmin: service_accounts.create_service_account · Always asksRead: service_accounts.list_tokens · No approvalDestructive: service_accounts.delete_token · Always asksRead: signed_in_user.get_signed_in_user_org_list · No approvalAdmin: signed_in_user.change_user_password · Always asks
Data it touches
SurfacesWeb APIs
Tags
pack:grafanagrafanaserver-adminorganizationsusersldapapicomposition