What this is about
Not every account is created through CIAS registration. Some existed before CIAS was introduced, others were created by an operator in the Keycloak console. CIAS does not know such accounts: there is no user record, so they do not appear in any list and cannot be suspended.
The import creates records for these accounts.
The set diagram
flowchart LR
subgraph K["Accounts in Keycloak"]
direction TB
A["already known in CIAS"]
B["unknown, active"]
C["unknown, inactive"]
D["unknown, but cannot be imported"]
end
A -- "stays unchanged" --> R1["alreadyKnown"]
B -- "record, ACTIVE" --> R2["activated"]
C -- "record, PENDING" --> R3["recorded"]
D -- "with reason" --> R4["skipped"]
The flow
-
1Admin→CIASstarts the import, without a body
-
2CIASPlatform administrator?otherwise 403
-
3CIAS→Keycloakreads all accounts, in pages of 200
-
4CIASFor each account: already known? Then skip to the next
-
5CIASDetermine the home tenant, create the record, set it to
ACTIVEif the account is active -
6CIAS→AdminReport
The import only runs when you trigger it, never on its own. The hub’s admin UI offers a button for this in the user list.
What happens to each account
When: The account is enabled in Keycloak and the address is verified.
CIAS creates a record and sets it to ACTIVE. The display name comes from first and last name.
Result: Counts as recorded and activated.
When: The account is disabled or the address is not verified.
CIAS creates a record, but leaves it at PENDING.
Result: Counts as recorded.
When: A record already exists for the account.
Nothing happens. The import does not overwrite an existing record.
Result: Counts as alreadyKnown.
When: The account cannot be assigned unambiguously.
Two reasons: the account is a member of several organizations, so there is no clear home tenant. Or the address already belongs to another account in CIAS.
Result: Listed in skipped with address and reason.
The home tenant
CIAS reads the home tenant from the membership in an organization: if the account is a member of exactly one organization, its alias becomes the home tenant. Without an organization, the person gets no home tenant.
The report
POST /cias/admin/users/import{
"found": 120,
"recorded": 14,
"activated": 12,
"alreadyKnown": 104,
"skipped": [
{ "email": "ben@example.org", "reason": "belongs to several organizations (nordbau, suedlogistik)" },
{ "email": "cara@example.org", "reason": "…" }
]
}| Field | Meaning |
|---|---|
found | accounts in Keycloak |
recorded | newly created records, including the activated ones |
activated | of these, set to ACTIVE right away |
alreadyKnown | already known before |
skipped | not imported, with reason |
Each account is saved on its own. If a run aborts, you simply start it again. Accounts that were already imported then count as alreadyKnown.