An Admin User API is a protected REST API used to manage users from an administrator account. In a React Native application, an admin can use this API to view users, create users, update user information, change roles, and remove users according to the permissions allowed by the system.
An Admin User API provides endpoints for administrators to manage users.
Admin Mobile App
↓
JWT Token
↓
Admin User API
↓
Authentication
↓
Authorization
↓
MySQL
Only authorized users should be able to perform administrative operations.
A mobile application may need a separate administration system for managing users and application data.
Request
↓
JWT Token
↓
Verify Authentication
↓
Identify User
↓
Check Admin Role
↓
Allow / Reject
↓
Admin Operation
The authorization check should happen before accessing protected data.
A simple users table can contain user information and the user's role.
CREATE TABLE users (
id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(100) NOT NULL,
email VARCHAR(150) NOT NULL UNIQUE,
password VARCHAR(255) NOT NULL,
role VARCHAR(30) NOT NULL DEFAULT 'student',
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
);
id | name | email | role
------------------------------------------
1 | Rahul | rahul@example.com | admin
2 | Amit | amit@example.com | teacher
3 | Neha | neha@example.com | student
4 | Pooja | pooja@example.com | student
The role determines which administrative operations the user can perform.
The admin can retrieve a list of users using a GET request.
GET /api/admin/users.php
The endpoint should verify the administrator's JWT before returning users.
$stmt = $pdo->query(
"SELECT id, name, email, role, created_at
FROM users
ORDER BY id DESC"
);
$users = $stmt->fetchAll(PDO::FETCH_ASSOC);
Never include the password column in an administrator's normal user list.
{
"success": true,
"message": "Users retrieved successfully",
"data": [
{
"id": 1,
"name": "Rahul",
"email": "rahul@example.com",
"role": "admin"
},
{
"id": 2,
"name": "Amit",
"email": "amit@example.com",
"role": "student"
}
]
}
Before processing the request, the API should verify the JWT.
require_once '../middleware/auth.php';
$user = requireAuth();
The authentication middleware should return the authenticated user's trusted information after successful verification.
if ($user['role'] !== 'admin') {
http_response_code(403);
echo json_encode([
"success" => false,
"message" => "Admin access required",
"data" => null
]);
exit;
}
Authentication and authorization should both be enforced by the server.
An administrator can create a new user with a POST request.
POST /api/admin/users.php
The request body can contain the name, email, password, and role.
{
"name": "Ravi",
"email": "ravi@example.com",
"password": "StrongPassword123",
"role": "student"
}
The password should be hashed before storing it in the database.
$input = json_decode(
file_get_contents("php://input"),
true
);
$name = trim($input['name'] ?? '');
$email = trim($input['email'] ?? '');
$password = $input['password'] ?? '';
$role = trim($input['role'] ?? 'student');
Always validate the received values before inserting them into the database.
Do not allow arbitrary role values from the client.
$allowedRoles = [
'admin',
'teacher',
'student'
];
if (!in_array($role, $allowedRoles, true)) {
$errors['role'] = "Invalid role";
}
An allowlist prevents unexpected role values from entering the system.
Passwords should never be stored as plain text.
Store the generated hash in the database instead of the original password.
Prepared statements help protect the database from SQL injection.
http_response_code(201);
echo json_encode([
"success" => true,
"message" => "User created successfully",
"data" => [
"id" => $userId,
"name" => $name,
"email" => $email,
"role" => $role
]
]);
Never return the user's password or password hash.
PUT can be used to update a user's information.
PUT /api/admin/users.php?id=10
The API should verify that the requested user exists and that the current user has permission to update it.
$stmt = $pdo->prepare(
"UPDATE users
SET name = ?, email = ?, role = ?
WHERE id = ?"
);
$stmt->execute([
$name,
$email,
$role,
$userId
]);
Password updates should normally be handled separately so that an administrator does not accidentally overwrite the existing password.
An administrator can delete a user using a DELETE request.
DELETE /api/admin/users.php?id=10
The endpoint must verify the administrator's permissions before deleting data.
Many applications prevent an administrator from accidentally deleting their own account.
if ((int)$userId === (int)$user['id']) {
http_response_code(400);
echo json_encode([
"success" => false,
"message" => "You cannot delete your own account"
]);
exit;
}
An admin API can support search using a query parameter.
GET /api/admin/users.php?search=rahul
$search = trim($_GET['search'] ?? '');
$stmt = $pdo->prepare(
"SELECT id, name, email, role
FROM users
WHERE name LIKE ?
OR email LIKE ?
ORDER BY id DESC"
);
$term = "%" . $search . "%";
$stmt->execute([
$term,
$term
]);
const response = await fetch(
"https://example.com/api/admin/users.php",
{
method: "GET",
headers: {
"Authorization": `Bearer ${token}`,
"Content-Type": "application/json"
}
}
);
const result = await response.json();
if (result.success) {
setUsers(result.data);
}
The mobile application can display the returned users in a FlatList.
if (response.status === 403) {
Alert.alert(
"Access Denied",
"You do not have admin permission."
);
return;
}
This improves the user experience, but the server remains responsible for enforcing the permission.
api/
│
├── middleware/
│ ├── auth.php
│ └── role.php
│
├── admin/
│ └── users.php
│
├── login.php
├── register.php
└── profile.php
Separating administration endpoints helps keep the API organized.
React Native Admin App
↓
Bearer JWT
↓
Verify JWT Token
↓
Identify Admin
↓
Check Admin Role
↓
Validate Request
↓
MySQL CRUD
↓
Standard JSON
Response
Every sensitive operation should pass through the required security checks.
Question: Which check should an Admin User API perform to ensure that only administrators can access protected admin operations?