Administrators

Who may use the admin portal and admin OAuth scope.

Allowlist

Who may receive the admin OAuth scope (portal + APIs). Entries here are stored in DynamoDB. Environment list is from Lambda config (ADMIN_ALLOWED_EMAILS / ADMIN_ALLOWED_SUBS) — change only by redeploy; use it to bootstrap the first admin.

From environment

KindValue

From DynamoDB

KindValueAdded (UTC)

Add allowlist entry