---
title: Provision UNS Account
slug: api-docs/provision-uns-account
docTags: 
createdAt: 2026-05-11T22:11:15.550Z
---

# Provision a UNS MQTT Account

**UI trigger**: LUNS -> Security -> *Create Account* -> *Add Permissions*.

Creates an MQTT account on the LitmusUNS broker, sets its ACL rules (which topic paths it can subscribe/publish to), and enables it. All LUNS calls are GraphQL POSTs to a single endpoint - the operation is selected by the GraphQL query/mutation, not by URL.

## URL pattern

Every step is `POST {{uns_url}}/mqtt/gql` with header `Authorization: Bearer <UNS_TOKEN>`. The token is obtained once per session via the LUNS OAuth2 password grant at `{{uns_url}}/auth/realms/standalone/protocol/openid-connect/token`.

## Step table

| Step         | Name in Collection | GraphQL operation                   | Input                                                                                               | Output / What to capture                   |
| ------------ | ------------------ | ----------------------------------- | --------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| 1 (optional) | Get Accounts       | `query Account { account { ... } }` | --                                                                                                  | Existing accounts - avoid name collision   |
| 2            | Create Account     | mutation `createAccount`            | `{ username, password, acType: "General", enabled: false }`                                         | Account `id` (UUID)                        |
| 3            | Add Account Rules  | mutation `addAccountRules`          | `{ accountId: <from step 2>, rules: [{ path: "<topic_path>", perm: "Sub" \| "Pub" \| "PubSub" }] }` | Rules attached                             |
| 4            | Enable Account     | mutation `enableAccount`            | `{ accountId: <from step 2> }`                                                                      | Account active                             |
| 5 (verify)   | Account Details    | `query account(id: ...)`            | Account `id`                                                                                        | Final state with rules + connected clients |

## Variants

- **For binding a Litmus Edge to UNS**: replace step 2 with `Create LitmusEdge Activation Token` (mutation that returns a token the LE uses during enrollment). Steps 3-5 then operate on the auto-created account once the LE connects.
- **Cleanup**: `Disable Account`, `Remove Account Rules`, `Remove Account`, or `Reset Account Password` all share the same endpoint with their respective mutations.

## All LUNS endpoints

Every LUNS operation (Dashboard, UNS, Security, MQTT, Integrations, Tools - 28 total) targets the same `/mqtt/gql` URL. Section grouping is purely organizational. The operation is in the GraphQL body.

## See also

- [Litmus UNS product overview](#)
- [Security reference](#)
