Admin endpoints
These endpoints need a key created by a workspace owner or admin. Members get 403 FORBIDDEN. GET calls need read scope; everything else needs write.
Admin-only operations documented on other pages:
| Operation | Page |
|---|---|
Deprecate or reactivate an entry (PATCH /entries/{entry_id} with status) |
Curation |
Hard-delete an entry (DELETE /entries/{entry_id}) |
Curation |
Delete a pack and its unshared content (DELETE /packs/{pack_id}) |
Curation |
Webhooks (/admin/webhooks) |
Webhooks |
Admins can also release anyone’s check-out lock, delete anyone’s comments and annotations, cancel anyone’s pull jobs and review requests, and override review decisions.
Denylist
Section titled “Denylist”The denylist blocks specific content from entering the library, for example assets that must stay out of the shared library. Denied files are refused at every door: negotiate reports them as denied (and never asks for their bytes), commit holds them and anything depending on them out of the batch, and uploads through PUT /blobs/{content_hash} get 403 DENYLISTED.
| Method and path | Purpose |
|---|---|
GET /admin/denylist |
List rules |
POST /admin/denylist |
Add a rule |
POST /admin/denylist/entry/{entry_id} |
Deny an existing entry in one step |
DELETE /admin/denylist/{denylist_id} |
Remove a rule |
Rule kind |
value |
Blocks |
|---|---|---|
content_hash |
64-character lowercase SHA-256 | These exact bytes. Any edit produces a new hash and gets past it. |
lineage |
A lineage id (guid: plus 32 uppercase hex, or ph: plus 32 lowercase hex) |
Every future version of that prop, including edited ones that keep their identity. |
package_guid |
An Unreal package GUID | Any package carrying that GUID, even if it was never in the library. |
POST /admin/denylist
Section titled “POST /admin/denylist”{ "kind": "lineage", "value": "guid:6F9619FF8B86D011B42D00C04FC964FF", "reason": "Project-only asset, keep out of the library" }reason is optional (up to 1,000 characters). Returns 201 with the rule: {id, kind, value, reason, created_by, created_at}. A duplicate rule is 409 CONFLICT; a malformed value is 422.
POST /admin/denylist/entry/{entry_id}
Section titled “POST /admin/denylist/entry/{entry_id}”Adds all three rules for an entry at once: its lineage, its current version’s hash and, when known, its package GUID. Optional query parameter reason. Returns 201 {"entry_id", "created": [rule]}; rules that already existed are skipped, so it is safe to repeat.
GET /admin/denylist returns {"items": [rule]}. DELETE /admin/denylist/{denylist_id} returns 204.
Group variants automatically
Section titled “Group variants automatically”POST /admin/variant-groups/detect finds ungrouped entries that look like variants of each other by name (same folder and asset class, names differing by one suffix such as _A, _01) and groups them.
{ "dry_run": true }dry_run defaults to true: nothing changes and you get the proposals. Send false to create the groups. Existing groups and labels set by people are never changed, and running it again is safe.
{ "dry_run": true, "groups": 14, "entries": 39, "proposals": [{ "label": "SM_Crate", "folder": "/Game/Props/Crates", "asset_class": "StaticMesh", "members": [500, 501, 502] }]}To group or ungroup specific entries by hand, use POST /entries/variant-group/bulk.
Regenerate previews
Section titled “Regenerate previews”POST /admin/previews/refresh flags existing previews for regeneration. The next time an editor processes the library, it re-exports them. Current previews keep showing until their replacements arrive.
{ "entry_type": "mesh,skeletal_mesh" }entry_type is an optional comma-separated subset of mesh, skeletal_mesh, texture, audio (all of them when omitted). Returns {"requested", "entry_types"} and records a previews.refresh_requested activity event. Repeating it before the editor catches up changes nothing.
