# uip admin organizations & tenants

> Syntax and options for `uip admin organizations` and `uip admin tenants`, which manage the caller's organization, its provisionable services, and the lifecycle of tenants within it.

`uip admin organizations` reads and updates the caller's organization record, inspects async OMS (Organization Management Service) operations, and manages organization-level service provisioning. `uip admin tenants` manages the lifecycle of tenants within that organization — create, list, get, update, soft-delete, enable/disable — plus tenant-level service provisioning. Both command groups are part of `uip admin` (package `@uipath/admin-tool`), which registers all of its sub-packages' commands directly on the `admin` top-level command with no further nesting — the real invocation is always `uip admin <verb>`.

## Concepts

- **One organization per login.** There is no `<organization-id>` argument anywhere in this group — every command resolves the organization from your current login context. Switch organizations by logging in again against a different one.
- **Tenant ID defaults to your login's tenant.** Every `tenants` verb that takes a tenant ID accepts it as an *optional* positional argument (or `--tenant-id` on the `services` subcommands); omit it and the command uses the tenant your login session is scoped to. If your login isn't scoped to any tenant and you don't pass one, the command fails with an explicit error rather than silently guessing.
- **Deletion is always soft.** `tenants delete` soft-deletes (reversible via a restore flow elsewhere in the platform) — there is no `--hard` flag anywhere in this group.
- **Async operations.** `tenants create`, `update`, and `delete` are asynchronous — they return an `operationId` immediately; poll it with [`organizations operation get`](#uip-admin-organizations-operation-get). `tenants enable`/`disable` and every `services` verb are synchronous.
- **Service catalog vs. provisioned services.** `services list-available` returns the *catalog* of services that could be provisioned (at the organization or tenant level, filterable by region); `services list` returns what's *actually provisioned* right now. Provisioning a service uses `services add`/`enable`, not a `create` verb.
- **Client-side filtering.** Several list/filter flags (`--service`, `--region` on `services list`; `--filter`, `--environment` on `tenants list`) are applied client-side after fetching the full result set — the underlying OMS endpoints have no server-side filters for most of these. `--status` on `tenants list` is sent as a query parameter *and* re-applied client-side, because the service currently ignores the query parameter.
- **Stale environment tags default to `Production`.** Tenants created before the environment-tag feature shipped have a null `environment` field; `tenants list`/`get` normalize it to `"Production"` before returning, so `--environment` filtering and downstream consumers see a consistent value.

## Synopsis

```text
uip admin organizations get [--full]
uip admin organizations update [--name <name>] [--logical-name <name>] [--language <code>] [--file <path>]
uip admin organizations regions list
uip admin organizations operation get <operationId>
uip admin organizations services list [--service <type>] [--status <status>] [--region <region>]
uip admin organizations services list-available

uip admin tenants list [--filter <fragment>] [--service <type>] [--status <status>] [--environment <env>] [--include-services]
uip admin tenants get [tenant-id]
uip admin tenants create [--name <name>] [--region <region>] [--environment <env>] [--file <path>]
uip admin tenants update [tenant-id] [--name <name>] [--region <region>] [--environment <env>] [--file <path>]
uip admin tenants delete [tenant-id]
uip admin tenants enable [tenant-id]
uip admin tenants disable [tenant-id] [--reason <text>]
uip admin tenants services list [--tenant-id <guid>] [--service <type>] [--region <region>]
uip admin tenants services list-available --region <region>
uip admin tenants services add [--tenant-id <guid>] [--service <type> | --file <path>]
uip admin tenants services remove [--tenant-id <guid>] [--service <type> | --file <path>]
uip admin tenants services enable [--tenant-id <guid>] --service <type>
uip admin tenants services disable [--tenant-id <guid>] --service <type>
```

Every verb also accepts `--login-validity <minutes>` (override the interactive-login token lifetime for that one call — rarely needed).

## uip admin organizations get

Fetch the caller's organization record.

### Options

| Long | Value | Description |
|---|---|---|
| `--full` | flag | Return the richer bundle (organization + tenants + available service catalog + logos) in one call instead of the bare organization record. |

### Examples

```bash
uip admin organizations get
```

```bash
uip admin organizations get --full
```

### Data shape (--output json)

```json
{
  "Code": "OmsOrganizationGet",
  "Data": {
    "id": "<org-guid>",
    "name": "Acme",
    "logicalName": "acme",
    "country": "US",
    "region": "UnitedStates",
    "status": "Active",
    "tenantsUrl": "https://cloud.uipath.com/acme",
    "language": "en-US",
    "createdOn": "<iso-date>",
    "organizationServiceInstances": []
  }
}
```

With `--full`, `Data` is `{ organization, tenants, services, logos }` instead.

## uip admin organizations update

Update editable fields of the caller's organization: `--name`, `--logical-name`, `--language` inline, or `--file <path>` with the full `UpdateOrganizationCommand` body. Inline flags and `--file` are mutually exclusive; passing neither fails before any network call.

### Options

| Long | Value | Description |
|---|---|---|
| `--name <name>` | string | New display name. |
| `--logical-name <name>` | string | New logical name (URL slug). |
| `--language <code>` | string | New language code, e.g. `en-US`, `fr-FR`. |
| `--file <path>` | path | Full `UpdateOrganizationCommand` JSON body. Mutually exclusive with the inline flags. |

### Examples

```bash
uip admin organizations update --name "New Org Name"
```

```bash
uip admin organizations update --file ./org-patch.json
```

### Data shape (--output json)

```json
{ "Code": "OmsOrganizationUpdated", "Data": {} }
```

## uip admin organizations regions list

List the regions in which Portal can be provisioned for the caller's company.

### Example

```bash
uip admin organizations regions list
```

### Data shape (--output json)

```json
{ "Code": "OmsRegionsList", "Data": [{ "region": "UnitedStates" }, { "region": "Europe" }] }
```

## uip admin organizations operation

Inspect async OMS operations (the kind `tenants create`/`update`/`delete` return an `operationId` for).

### uip admin organizations operation get

#### Arguments

| Name | Required | Purpose |
|---|---|---|
| `<operationId>` | yes | Operation UUID returned from a previous async call. |

#### Example

```bash
uip admin organizations operation get 11111111-2222-3333-4444-555555555555
```

#### Data shape (--output json)

```json
{
  "Code": "OmsOperationGet",
  "Data": {
    "id": "11111111-2222-3333-4444-555555555555",
    "entityType": "Tenant",
    "entityId": "<entity-guid>",
    "operationStatus": "Completed",
    "errorMessage": null
  }
}
```

## uip admin organizations services

Manage organization-level services (provisioning, catalog, status).

### uip admin organizations services list

List currently provisioned organization-level service instances.

#### Options

| Long | Value | Description |
|---|---|---|
| `--service <type>` | string | Exact match on `serviceType` (e.g. `orchestrator`). Client-side filter. |
| `--status <status>` | enum | Exact match on service-instance status. Client-side filter. |
| `--region <region>` | enum | Exact match on service-instance region. Client-side filter. |

#### Example

```bash
uip admin organizations services list
```

#### Data shape (--output json)

```json
{
  "Code": "OmsOrgServicesList",
  "Data": [
    {
      "id": "<service-instance-guid>",
      "serviceType": "orchestrator",
      "region": "UnitedStates",
      "status": "Enabled",
      "url": "https://cloud.uipath.com/acme/portal_",
      "isVisible": true
    }
  ]
}
```

### uip admin organizations services list-available

List the catalog of services that can be provisioned at the organization level. No options.

#### Example

```bash
uip admin organizations services list-available
```

#### Data shape (--output json)

```json
{
  "Code": "OmsOrgServicesAvailable",
  "Data": [
    {
      "id": "<service-guid>",
      "name": "orchestrator",
      "provisioningMode": "Implicit",
      "supportedRegions": ["UnitedStates", "Europe"],
      "defaultRegion": "UnitedStates",
      "isVisible": true,
      "isAlwaysProvision": false
    }
  ]
}
```

## uip admin tenants list

List tenants in the caller's organization. Use this to look up a tenant's UUID by name before calling `get`/`update`/`delete`/etc.

### Options

| Long | Value | Description |
|---|---|---|
| `--filter <fragment>` | string | Case-insensitive substring filter on tenant name. Client-side. |
| `--service <type>` | string | Only tenants that have the given service provisioned. Server-side. |
| `--status <status>` | enum: `Enabled`, `Disabled`, `Updating`, `Failed`, `Maintenance`, `Deleted` | Only tenants whose lifecycle status matches. Sent as a query param *and* re-applied client-side, since the service currently ignores the query param. |
| `--environment <env>` | enum: `Production`, `Staging`, `Development` | Only tenants with the given environment tag. Client-side; missing/null tags default to `Production` before filtering. |
| `--include-services` | flag | Include each tenant's `services` array inline in the response. |

### Examples

```bash
uip admin tenants list
```

```bash
uip admin tenants list --filter Default
```

```bash
uip admin tenants list --status Enabled --service orchestrator --include-services
```

### Data shape (--output json)

```json
{
  "Code": "OmsTenantsList",
  "Data": [
    {
      "id": "<tenant-guid>",
      "name": "DefaultTenant",
      "color": "#1f8feb",
      "region": "UnitedStates",
      "status": "Enabled",
      "tenantUrl": "https://cloud.uipath.com/acme/DefaultTenant",
      "environment": "Production",
      "isCanaryTenant": false,
      "createdBy": "<user-guid>",
      "createdOn": "<iso-date>"
    }
  ]
}
```

## uip admin tenants get

Fetch a single tenant by ID.

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `[tenant-id]` | no | Tenant UUID. Defaults to the current login's tenant. |

### Example

```bash
uip admin tenants get 11111111-2222-3333-4444-555555555555
```

### Data shape (--output json)

```json
{
  "Code": "OmsTenantGet",
  "Data": {
    "id": "11111111-2222-3333-4444-555555555555",
    "name": "DefaultTenant",
    "color": "#1f8feb",
    "region": "UnitedStates",
    "status": "Enabled",
    "tenantUrl": "https://cloud.uipath.com/acme/DefaultTenant",
    "environment": "Production",
    "isCanaryTenant": false,
    "createdBy": "<user-guid>",
    "createdOn": "<iso-date>",
    "updatedBy": "<user-guid>",
    "updatedOn": "<iso-date>",
    "tenantServiceInstances": []
  }
}
```

## uip admin tenants create

Create a tenant in the caller's organization. Asynchronous — poll the returned `operationId` via `organizations operation get`.

### Options

| Long | Value | Description |
|---|---|---|
| `--name <name>` | string | Tenant display name. Required in inline mode. |
| `--region <region>` | enum | Region to provision the tenant in. |
| `--environment <env>` | enum: `Production`, `Staging`, `Development` | Environment tag. |
| `--file <path>` | path | Full `CreateTenantRequestDto` body — needed for fields not exposed inline (`services[]`, `customProperties`, `color`, `isDefaultTenant`). Mutually exclusive with the inline flags. |

### Example

```bash
uip admin tenants create --file ./tenant.json
```

### Data shape (--output json)

```json
{
  "Code": "OmsTenantCreated",
  "Data": { "id": "<new-tenant-guid>", "name": "<name>", "status": "Updating", "operationId": "<operation-guid>" }
}
```

## uip admin tenants update

Patch editable fields of a tenant. Asynchronous — poll `operationId`.

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `[tenant-id]` | no | Tenant UUID. Defaults to the current login's tenant. |

### Options

| Long | Value | Description |
|---|---|---|
| `--name <name>` | string | New display name. |
| `--region <region>` | enum | New region. |
| `--environment <env>` | enum | New environment tag. |
| `--file <path>` | path | Full `TenantUpdateDto` body — needed for `services{}`, `customProperties`, `color`. Mutually exclusive with the inline flags. |

### Example

```bash
uip admin tenants update 11111111-2222-3333-4444-555555555555 --file ./tenant-patch.json
```

### Data shape (--output json)

```json
{ "Code": "OmsTenantUpdated", "Data": { "operationId": "<operation-guid>" } }
```

## uip admin tenants delete

Soft-delete a tenant by ID (reversible via the restore flow). Asynchronous — poll `operationId`. No hard-delete option.

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `[tenant-id]` | no | Tenant UUID. Defaults to the current login's tenant. |

### Example

```bash
uip admin tenants delete 11111111-2222-3333-4444-555555555555
```

### Data shape (--output json)

```json
{ "Code": "OmsTenantDeleted", "Data": { "operationId": "<operation-guid>" } }
```

## uip admin tenants enable / disable

Enable or disable a tenant. Synchronous (unlike `create`/`update`/`delete`).

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `[tenant-id]` | no | Tenant UUID. Defaults to the current login's tenant. |

### Options (disable only)

| Long | Value | Description |
|---|---|---|
| `--reason <text>` | string | Free-text reason recorded with the disable action. |

### Examples

```bash
uip admin tenants enable 11111111-2222-3333-4444-555555555555
```

```bash
uip admin tenants disable 11111111-2222-3333-4444-555555555555 --reason "scheduled maintenance"
```

### Data shape (--output json)

```json
{ "Code": "OmsTenantEnabled", "Data": {} }
```

`Code` is `OmsTenantDisabled` for `disable`.

## uip admin tenants services

Manage tenant-level services (provisioning, status, per-region catalog). All verbs accept `--tenant-id <guid>`, defaulting to the current login's tenant.

### uip admin tenants services list

#### Options

| Long | Value | Description |
|---|---|---|
| `--tenant-id <guid>` | GUID | Target tenant. Defaults to login tenant. |
| `--service <type>` | string | Exact match on `serviceType`. Client-side. |
| `--region <region>` | enum | Exact match on region. Client-side. |

#### Example

```bash
uip admin tenants services list --tenant-id 11111111-2222-3333-4444-555555555555
```

#### Data shape (--output json)

```json
{
  "Code": "OmsTenantServicesList",
  "Data": [
    { "serviceType": "orchestrator", "region": "UnitedStates", "organizationId": "<org-guid>", "serviceInstanceSettings": {}, "licenseList": [] }
  ]
}
```

### uip admin tenants services list-available

#### Options

| Long | Value | Required | Description |
|---|---|---|---|
| `--region <region>` | enum | **yes** | Region whose service catalog to query. |

#### Example

```bash
uip admin tenants services list-available --region UnitedStates
```

#### Data shape (--output json)

```json
{
  "Code": "OmsTenantServicesAvailable",
  "Data": [
    { "id": "<service-guid>", "name": "orchestrator", "provisioningMode": "Implicit", "supportedRegions": ["UnitedStates"], "defaultRegion": "UnitedStates", "isVisible": true, "isAlwaysProvision": false }
  ]
}
```

### uip admin tenants services add / remove

Provision or soft-remove tenant-level services. Synchronous. `--service` (single) and `--file` (multiple, `AddRemoveTenantServiceRequestDto` body: `{ "services": { "<type>": true|false } }`) are mutually exclusive; a `--file` for `add` must have every value `true`, and for `remove` every value `false` — a mismatched value fails client-side before the call.

#### Options

| Long | Value | Description |
|---|---|---|
| `--tenant-id <guid>` | GUID | Target tenant. Defaults to login tenant. |
| `--service <type>` | string | Single service type to add/remove. |
| `--file <path>` | path | Multi-service `AddRemoveTenantServiceRequestDto` body. |

#### Examples

```bash
uip admin tenants services add --tenant-id 11111111-2222-3333-4444-555555555555 --service orchestrator
```

```bash
uip admin tenants services remove --tenant-id 11111111-2222-3333-4444-555555555555 --file ./remove-services.json
```

#### Data shape (--output json)

```json
{ "Code": "OmsTenantServicesAdded", "Data": {} }
```

`Code` is `OmsTenantServicesRemoved` for `remove`.

### uip admin tenants services enable / disable

Enable or disable one tenant-level service instance. Synchronous.

#### Options

| Long | Value | Required | Description |
|---|---|---|---|
| `--tenant-id <guid>` | GUID | no | Target tenant. Defaults to login tenant. |
| `--service <type>` | string | **yes** | Service type identifier, e.g. `orchestrator`. |

#### Examples

```bash
uip admin tenants services enable --tenant-id 11111111-2222-3333-4444-555555555555 --service orchestrator
```

```bash
uip admin tenants services disable --tenant-id 11111111-2222-3333-4444-555555555555 --service orchestrator
```

#### Data shape (--output json)

```json
{ "Code": "OmsTenantServiceEnabled", "Data": {} }
```

`Code` is `OmsTenantServiceDisabled` for `disable`.

## See also

- [Global options](./global-options.md)
- [Exit codes](./exit-codes.md)
