oap user-identity
Manage UserIdentity resources (per-user credential catalogs)
oap user-identity apply <path>
Server-side apply a UserIdentity YAML
oap user-identity delete <name>
Delete a UserIdentity
Flags:
--cascade-secrets Also delete each credential's master Secret in the identities namespace (default: leave Secrets intact)
oap user-identity delete-token <name> <credential>
Remove the named credential from a UserIdentity's spec.credentials and delete that credential's backing Secret in the identities namespace, leaving the identity's other credentials (and their Secrets) intact.
Use this to unlink a credential that was linked to the wrong account — for example an "anthropic-oauth" token captured against the wrong workspace — so it can be re-linked. The next agent session that needs this credential will re-prompt the user to re-link it via the "Connect your accounts" flow.
<name> is the UserIdentity metadata.name (the "u-…" hash, as shown by "oap user-identity list"); <credential> is the credential name to remove.
oap user-identity list
List UserIdentity CRs
oap user-identity put-token
Seed a UserIdentity with a static token for one credential name
Flags:
--credential-name string Credential name (must match what tools declare)
--display-name string Human-friendly label for the UserIdentity
--skip-verify Skip live verification of the token against the provider (format check still applies)
--subject string Canonical SpiceDB subject, e.g. user:<base64(email)>
--token string The token value
oap user-identity show <name>
Show details of a UserIdentity