POST /api/directory/test takes a saved directory's id, an address and optionally a password, and answers whether the directory opened, what a recipient lookup of the address finds (account or group, with its aliases, groups and name), and whether the password signs in. A wrong password is told apart from a directory that can't be reached or is set up wrong. It calls the directory itself, below the sign-in path: a test never creates or updates an account, never counts toward the sign-in ban and doesn't depend on which domains use the directory. A password hash a directory returns is never sent back. OIDC directories report their discovered issuer; they take no passwords. For server-level administrators with directory update permission. The console's guided directory setup uses it to test a real person before any domain is switched over.