Platform administration
Operate an Openbook server from /admin — growth, agent activity, revenue, plans and Stripe, plus the doors out to the account service for AI, the token allowance and storage.
This page is for the operator running the Openbook server. If you administer a single organization as its owner, you want Organization settings instead.
The platform admin area lives at /admin.
What this admin is, and what it is not
Openbook's admin covers what Openbook does and what Openbook bills for. Accounts and organizations themselves are not Openbook's — they belong to the Bookbag account service, shared by every product — so the platform-wide administration of people and organizations lives there, and this area links out to it.
Concretely:
| Thing | Where it is administered |
|---|---|
| Accounts: pausing, blocking, passwords, deleting | Bookbag account service |
| Organizations: renaming, suspending, members, ownership | Bookbag account service |
| Transactional email: providers, templates, send log | Bookbag account service |
| Files, storage limits, per-account allowances | Bookbag account service |
| The platform's AI provider keys and model catalog | Bookbag account service |
| The token allowance: the default, the window, per-account exceptions | Bookbag account service |
| Openbook's plans, growth, revenue and agent activity | Here, at /admin |
The navigation makes the split visible: Organizations, Platform AI, Model catalog and AI tokens are all outbound links to the account service, and there is no Members page and no Email page here at all.
Who gets in
Two ways, checked on every request:
- The email address is on the
adminsallow-list in the server's environment configuration. This is the bootstrap administrator — the one who exists before anyone has been made an admin anywhere. - The signed-in person's role at the account service is admin.
Anyone else gets a 403 with "Platform admin access required."
Overview
Platform-wide counts — members, new members this week, organizations, spaces, rooms, and archived rooms — plus the five most recent signups. "New this week" means the last seven days.
The platform brain
Models & providers
Nothing is set here. Openbook holds no provider key at all any more — the platform's AI, like its files, is one set of settings shared by every Bookbag product, so it is configured once at the account service rather than once per product. The section carries two outbound links:
- Platform AI ↗ — the account service's
/admin/ai. The platform's own provider keys and models: the key Openbook itself runs on, which today means the concierge, and the model an organization in managed mode answers on. - Model catalog ↗ — the account service's
/admin/model-catalog. What organizations are offered when they choose managed mode. It holds no key and can call nothing; it is reference data.
Both open at the account service. There is no Openbook page behind either, and Openbook has no AI tables left to administer.
What you do there is unchanged in shape: one key per provider, verified against the provider before it is stored and encrypted after; browse the provider's models and add the ones you want; mark them active and star one as the default for its kind. Removing a provider's key removes the models bound to it.
If no platform model is configured at all, two things follow: the concierge refuses, telling the user to ask an admin to set one up; and Managed by us is greyed out on every organization's AI page, because there is nothing for them to be managed by.
The keys are shared by Openbook, Madebook and Bookbag. Changing one there changes it for all three. See AI configuration for what an organization sees of this.
AI tokens
/admin/creditsis gone. Openbook's per-organization credit ledger was retired; every balance was carried across to the account service as one-off headroom first. The full story is in What happened to credits.
AI tokens ↗ in the sidebar is an outbound link to the account service's /admin/tokens. That one page meters Openbook, Madebook and Bookbag against one allowance per account, because there is one place the tokens are actually spent.
There you set:
- The default allowance — the most one account may use per window, across every organization it owns and every product it uses. 1,000,000 tokens until you change it.
- Whether it turns over monthly or weekly. Monthly means the 1st, in UTC. Weekly means seven-day blocks from the most recent Monday, re-anchored the moment you choose it. Changing this changes what the window means from then on; nothing already recorded moves.
- What a generated image costs in tokens. 10,000 until you change it — a conversion rate rather than a measurement, which is why it is a setting.
- A per-account exception, found by the email the person signs in with, with a note saying why. Clearing it puts the account back on the default.
The same page shows the window's totals — billed, accounts spending, what ran on organizations' own keys (recorded, never metered), and how many runs were refused — and the ledger: one row per run, never edited and never deleted, with a refusal kept as a void row so "why did my agent stop at 4pm" stays answerable.
Nothing resets on a schedule. Usage is the sum of ledger rows since the window began, so last window's figure is still readable and changing the period cannot lose history.
What an organization sees of all this is in AI usage & the token allowance.
Storage
Nothing is set here. Openbook has no bucket, no file ledger and no quota of its own any more — files for all the Bookbag products live in the account service, so the numbers that bound them are set there once and apply everywhere. /admin/storage is a door with two links out:
- Limits and per-account allowances, at the account service's
/admin/storage. Two defaults and a list of exceptions:- the per-file ceiling, which is 20MB unless you change it. It takes effect in every product immediately, with no restart. The hard maximum is 1GB, because a whole upload is held in memory while it is decoded.
- the default account allowance, 30MB unless you change it. It applies to every account that has no exception of its own.
- per-account exceptions, set by email address, with a note explaining why. Setting zero or less clears the exception and puts that account back on the default. The list shows each exception's note, who set it, and how much of it that account has used.
- Every file on the platform, at the account service's
/admin/files. Searchable by name, organization, product and source, with the ability to open or remove any of them.
Two things to keep in mind before you change a number:
- An allowance is per account, not per organization and not per product. It is charged to the owner of each organization, and every organization that account owns, in every Bookbag product, draws on the same figure. Raising one person's allowance raises it everywhere they are an owner.
- Only the platform's own storage is metered. An organization that has pointed itself at its own S3 bucket, Dropbox or SharePoint is paying that provider directly, and its bytes are recorded but not counted against anyone's allowance. Telling an organization to bring its own storage is often a better answer than raising an allowance.
What an organization sees of all this, and the two refusals its people will meet, is in Storage and files.
Who is on it
Organizations
An outbound link to the organizations list at the account service, where an organization is renamed, suspended, re-membered or handed to a new owner. The Openbook side of an organization — its plan and its billing — is on the Plans page below.
Growth
Counts of growth events over all time, the last 7 days and the last 30 days; a breakdown of the gates people hit (the top 12), and a daily signup curve for the last 30 days.
The gate breakdown is the useful one. It tells you which limit is actually stopping people — the member cap, the space cap, a Pro-only room type — which is a better guide to pricing than a survey.
What it is doing
Agent activity
Build-agent runs across the platform, over the last 30 days: runs by status, the top eight models, the top fifteen organizations by run count with their metered usage in tokens and their failures, and the forty most recent runs.
These figures are Openbook's measurement, not the bill. They are what Openbook counted on each run. What the platform actually paid for is metered at the account service, against the organization owner's token allowance — and an organization on its own provider key costs the platform nothing and is never capped. For the number that decides anything, use AI tokens ↗. See AI usage & the token allowance.
What it earns
Revenue
Monthly and annual recurring revenue, and a tally of organizations by state: paid, trialing, comped, free and past due, with the paying list itself.
MRR is the plan price times the seat count, with yearly subscriptions divided by twelve, and it counts only real Stripe subscriptions. Comped and trialing organizations contribute nothing, which is the point — this number is money, not optimism.
Plans
Every organization's plan, status, seats, MRR and comp state, each with a link out to that organization at the account service. Per organization you can:
- Extend the trial. The default is 14 days, and the range is 1 to 90. It extends from whichever is later, now or the current trial end. An organization that already has a subscription is refused — a trial would do nothing.
- Change plan — comp an organization onto Free, Pro or Business, optionally for a set number of months (0 to 36, where 0 means no expiry). A time-limited comp reverts on its own when it expires. An organization with a live Stripe subscription is refused: cancel it first.
- Grandfather the organization, which holds it on its older price.
- Cancel the subscription, either at the end of the billing period or immediately. Without Stripe configured this simply drops the organization to Free.
Stripe & plans
Connect Stripe by pasting your Stripe secret key. The key's format is checked, it is verified against Stripe with a live call before it is accepted, and it is stored encrypted. A key the environment supplies takes precedence over one entered here.
The page shows the webhook URL to register in your Stripe dashboard. The events handled are:
checkout.session.completedcustomer.subscription.created,.updatedand.deletedinvoice.payment_failed
No signing secret is needed — an incoming event is verified by re-fetching it from Stripe by its id, so a forged payload cannot get through. Subscription prices are created in the connected Stripe account on the first checkout; you do not need to pre-create products or prices.
You can also override the four prices — Pro monthly and yearly, Business monthly and yearly — in cents. Each must be between $1 and $100,000.
Free mode. Billing has a mode switch: paid, or free. In free mode every organization behaves as though it were on Pro, and nothing is written to their billing rows — trials and comps freeze exactly where they are, so switching back to paid restores the state that was there. It is the right switch for an internal deployment or a pre-launch period.