Security and audit
List sessions
Returns the app sessions (signed-in browsers) of the workspace’s members, or only your own. Use the id to sign a session out. The list is not paginated.
- Bearer API key
- Scope:
adminonly - or app session
- Workspace:
X-Tenant-ID(optional with a key)
Headers
AuthorizationstringrequiredYour API key as
Bearer <key>. The wordBearerand the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.X-Tenant-IDuuidoptionalWorkspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass
?tenant=<id>instead.
Query parameters
scopeenumoptionalmefor your own sessions,workspacefor the sessions of every member. Defaults toworkspacefor owners and admins and tomefor agents; agents always get only their own sessions.
Response
200 OKapplication/json
itemsarray<Session>Signed-in sessions.
Show child attributesHide child attributes15
iduuidSession id. Use it to sign the session out.
user_iduuidThe signed-in user.
user_namestringTheir name.
emailstringTheir email address.
ipstringIP address the session signed in from, or
""for older sessions.locationstringCity and country of the IP address, for example
Ljubljana, SI, or only the country (SI).""when unknown.countrystringTwo-letter country code of the IP address, or
"".citystringCity of the IP address, or
"".devicestringBrowser and operating system, for example
Chrome on macOS, or"".methodstringHow it signed in:
password,google,invite,signup, or""when unknown.created_attimestampWhen the session signed in.
last_seen_attimestampnullableLast request made with the session, updated at most every 5 minutes.
nullwhen not recorded yet.expires_attimestampWhen the session ends unless it is signed out first.
currentbooleantruefor the session that made this request.can_revokebooleantruewhen you may sign this session out.
Status codes
- 200OK. The sessions.
- 400Bad request. Session requests only: no workspace was selected (
workspace required (X-Tenant-ID)). - 401Unauthorized. The API key is unknown, revoked or expired (
invalid or expired API key), or there is no key and no signed-in session (unauthorized). - 403Forbidden. The API key does not have the
adminscope (this endpoint needs an API key with the admin scope:readandwritekeys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address,code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace,forbidden). - 500Server error. Something went wrong on our side. Retry with backoff.