> ## Documentation Index
> Fetch the complete documentation index at: https://spreecommerce.org/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Complete first-run setup

> Creates the first admin account and adopts the seeded store, authorized
by the one-time setup token printed at install time (rotate it with
`bin/rails spree:setup:token`). Issues a JWT access token and a
refresh-token cookie exactly like login. Returns 404 once any admin
user exists — the flow is closed permanently after setup.




## OpenAPI

````yaml /api-reference/admin.yaml post /api/v3/admin/auth/setup
openapi: 3.0.3
info:
  title: Admin API
  contact:
    name: Spree Commerce
    url: https://spreecommerce.org
    email: hello@spreecommerce.org
  description: >
    Spree Admin API v3 - Administrative API for managing products, orders, and
    store settings.


    ## Authentication


    The Admin API requires a secret API key passed in the `x-spree-api-key`
    header.

    Secret API keys can be generated in the Spree admin dashboard.


    ## Response Format


    All responses are JSON. List endpoints return paginated responses with
    `data` and `meta` keys.

    Single resource endpoints return a flat JSON object.


    ## Resource IDs


    Every resource is identified by an opaque string ID (e.g. `prod_86Rf07xd4z`,

    `variant_k5nR8xLq`, `or_UkLWZg9DAJ`). Use these IDs everywhere — URL paths,

    request bodies, and Ransack filters all accept them directly.


    ## Error Handling


    Errors return a consistent format:

    ```json

    {
      "error": {
        "code": "validation_error",
        "message": "Validation failed",
        "details": { "name": ["can't be blank"] }
      }
    }

    ```
  version: v3
servers:
  - url: http://{defaultHost}
    variables:
      defaultHost:
        default: localhost:3000
security: []
tags:
  - name: Authentication
    description: Admin user login, logout, token refresh, and current user profile
  - name: Allowed Origins
    description: CORS allowlist for storefront and admin client origins
  - name: API Keys
    description: Secret and publishable API keys
  - name: Categories
    description: >-
      Hierarchical product categories — tree management, repositioning, and
      product assignments
  - name: Channels
    description: >-
      Sales channels, product publication across channels, and per-channel order
      routing rules
  - name: Custom Fields
    description: >-
      Custom field definitions for products, variants, customers, and other
      resources
  - name: Customer Groups
    description: >-
      Customer groups for segmenting customers (e.g. wholesale, VIP) used by
      pricing and promotions
  - name: Customers
    description: Customer profiles, addresses, credit cards, and store credits
  - name: Exports
    description: Async CSV exports of admin resources
  - name: Fulfillments
    description: Order fulfillments — shipments, fulfill, cancel, resume, split
  - name: Gift Cards
    description: Gift cards and gift card batches
  - name: Imports
    description: >-
      Async CSV imports of admin resources, with per-row status and failed-row
      retry
  - name: Markets
    description: >-
      Markets — geographic groupings of countries used for pricing, tax, and
      fulfillment rules
  - name: Option Types
    description: >-
      Option types and option values used to build product variants (e.g. Size,
      Color)
  - name: Orders
    description: Orders, order items, applied gift cards, and applied store credits
  - name: Payment Methods
    description: Configured payment providers and their available types
  - name: Payments
    description: Order payments — list, capture, void
  - name: Pricing
    description: >-
      Prices and price lists for currency-, market-, and customer-group-specific
      pricing
  - name: Products
    description: >-
      Products, taxons/categories, product custom field values, and bulk product
      operations
  - name: Policies
    description: The store's legal documents — terms of service, privacy, returns, shipping
  - name: Reasons
    description: >-
      Merchant-owned vocabularies for why a return, claim, refund or
      cancellation happened
  - name: Promotions
    description: Promotions, promotion rules, promotion actions, and coupon codes
  - name: Refunds
    description: Order refunds
  - name: Settings
    description: Store-level settings — store profile, tags, and configuration
  - name: Staff
    description: Admin users, roles, and invitations to the store
  - name: Stock Locations
    description: Warehouses and physical fulfillment locations
  - name: Store Credits
    description: Prepaid customer balances across all customers, and each balance's ledger
  - name: Variants
    description: >-
      Product variants — the individual SKUs (size/color combinations) sold
      under a product
  - name: Webhooks
    description: Webhook endpoints and webhook delivery history
paths:
  /api/v3/admin/auth/setup:
    post:
      tags:
        - Authentication
      summary: Complete first-run setup
      description: |
        Creates the first admin account and adopts the seeded store, authorized
        by the one-time setup token printed at install time (rotate it with
        `bin/rails spree:setup:token`). Issues a JWT access token and a
        refresh-token cookie exactly like login. Returns 404 once any admin
        user exists — the flow is closed permanently after setup.
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
                - setup_token
                - email
                - password
                - country_code
              properties:
                setup_token:
                  type: string
                  description: One-time token from the install output.
                email:
                  type: string
                  format: email
                  example: owner@example.com
                password:
                  type: string
                  example: Secret123!
                password_confirmation:
                  type: string
                  example: Secret123!
                first_name:
                  type: string
                  example: Olivia
                last_name:
                  type: string
                  example: Owner
                store_name:
                  type: string
                  example: My Store
                country_code:
                  type: string
                  description: >-
                    ISO 3166-1 alpha-2 country the store sells from. Determines
                    the default market, the warehouse, the delivery zones and
                    the currency.
                  example: US
                locale:
                  type: string
                  description: Storefront locale. Defaults to the country's own language.
                  example: en
                currency:
                  type: string
                  description: >-
                    ISO 4217 currency. Defaults to the country's own currency —
                    pass one only when the store prices in something else.
                  example: USD
                sample_data:
                  type: boolean
                  description: >-
                    Load the demo catalog, customers and orders in the
                    background once the admin account exists.
                  example: false
      responses:
        '200':
          description: setup completed
          content:
            application/json:
              example:
                token: >-
                  eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyX2lkIjoxLCJ1c2VyX3R5cGUiOiJhZG1pbiIsImp0aSI6IjZjMjg1ODk5LTExMzUtNDBhMi1hNDBiLTE4NjNiODcwZDRjYyIsImlzcyI6InNwcmVlIiwiYXVkIjoiYWRtaW5fYXBpIiwiZXhwIjoxNzY4NDc4NzAwfQ.Go2eUEiXf7rVD5mwtNMqkWqUGcBfhxk3b7JT8dw8uiE
                user:
                  id: adm_UkLWZg9DAJ
                  email: owner@example.com
                  first_name: Olivia
                  last_name: Owner
                  full_name: Olivia Owner
                  selected_locale: null
                  created_at: '2026-01-15T12:00:00.000Z'
                  updated_at: '2026-01-15T12:00:00.000Z'
                  avatar_url: null
                  roles:
                    - id: role_UkLWZg9DAJ
                      name: admin
                  stores:
                    - id: store_UkLWZg9DAJ
                      name: My Store
                      code: spree_1
        '404':
          description: setup not available
          content:
            application/json:
              example:
                error:
                  code: record_not_found
                  message: Setup is not available

````