create_persona_user
Create password-less users for persona login mode, enabling local development and testing authentication through identity selection in the interactive login UI, without password-based or OAuth grant access.
Instructions
Create a password-less user for persona login mode (local dev/testing convenience, 'login.mode: persona' in settings). The user can only authenticate by identity selection in the interactive login UI - never via password-mode login or the OAuth password grant. To keep 'create_user' unambiguous (always creates a normal, password-protected user), this is a separate tool rather than an optional password on create_user.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| No | Email address (optional) | ||
| roles | No | List of roles (optional, default: ['USER']) | |
| groups | No | List of groups (optional) | |
| tenant | No | Tenant identifier (optional, default: 'default') | |
| username | Yes | Username for the new persona-mode-only user | |
| attributes | No | Custom key-value attributes (optional) | |
| source_acl | No | Source ACL entries for document-level security | |
| description | No | Display-only note shown in the persona login picker (optional, max 200 chars) | |
| entitlements | No | List of entitlements | |
| identity_class | No | Identity class (e.g., INTERNAL, EXTERNAL) |