---
title: Charmhub | Deploy Kratos using Charmhub - The Open Operator Collection
description: Deploy the latest version of Kratos as a Kubernetes Operator on any cloud.
url: https://charmhub.io/kratos/actions
---

# Kratos

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

stable 565

```
juju deploy kratos
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [create-admin-account](https://charmhub.io/kratos/actions#create-admin-account)
* [delete-identity](https://charmhub.io/kratos/actions#delete-identity)
* [get-identity](https://charmhub.io/kratos/actions#get-identity)
* [invalidate-identity-sessions](https://charmhub.io/kratos/actions#invalidate-identity-sessions)
* [list-oidc-accounts](https://charmhub.io/kratos/actions#list-oidc-accounts)
* [reset-identity-mfa](https://charmhub.io/kratos/actions#reset-identity-mfa)
* [reset-password](https://charmhub.io/kratos/actions#reset-password)
* [run-migration](https://charmhub.io/kratos/actions#run-migration)
* [unlink-oidc-account](https://charmhub.io/kratos/actions#unlink-oidc-account)

[Learn about actions >](https://juju.is/docs/juju/action)

* create-admin-account

  Create an admin user. If no password was provided, the command will return a
  magic link where the user will be able to set their password.

  Params

  + email
    string

    The admin's email, this email must not be associated with any other account
    (user or admin)
  + name
    string

    The admin's name
  + password-secret-id
    string

    The juju secret that contains the admin's password
  + phone-number
    string

    The admin's phone number
  + username
    string

    The admin username

  Required

  username,
  email
* delete-identity

  Delete a user using the identity ID or the user email.

  Params

  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID
* get-identity

  Get a user using either the identity ID or the user email.

  Params

  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID
* invalidate-identity-sessions

  Invalidate all user sessions using the identity ID or the user email.

  Params

  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID
* list-oidc-accounts

  Retrieve the list of OIDC accounts identifiers linked to an identity using the identity ID or the user email.

  Params

  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID
* reset-identity-mfa

  Reset identity's second authentication factor using the identity ID or the user email.

  Params

  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID
  + mfa-type
    string

    The type of credentials to be removed, one of `totp`, `lookup_secret` or `webauthn`.

  Required

  mfa-type
* reset-password

  Reset password of an identity using the identity ID or the user email.

  Params

  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID
  + password-secret-id
    string

    The juju secret that contains the password to set for an identity. If
    not provided, a self-service recovery link will be returned.
* run-migration

  Run a migration, this is needed after upgrades. This is a non-reversible operation.
  Run this after backing up the database.

  Params

  + timeout
    number

    Timeout after which the migration will be canceled
* unlink-oidc-account

  Unlink a user's external identity provider account from their identity using the identity ID or the user email.

  Params

  + credential-id
    string

    The OIDC credential ID to unlink. Run `list-identity-linked-oidc-accounts` to list available credentials.
  + email
    string

    The user's email
  + identity-id
    string

    The Identity ID

  Required

  credential-id
