Skip to content

Security and audit

List sessions

Returns the app sessions (signed-in browsers) of the workspace’s members, or only your own. Use the id to sign a session out. The list is not paginated.

GET/api/v1/security/sessions
  • Bearer API key
  • Scope: admin only
  • or app session
  • Workspace: X-Tenant-ID (optional with a key)

Headers

  • Authorizationstringrequired

    Your API key as Bearer <key>. The word Bearer and the space are case-sensitive. Browser clients signed in to the app use the session cookie instead.

    Constraints
    Keys start with pk_live_ and are 56 characters long.
    Example
    Bearer pk_live_…
  • X-Tenant-IDuuidoptional

    Workspace id. Optional with an API key (a key always acts in its own workspace); if you send it, it must match the key’s workspace. Required with a session cookie. You can pass ?tenant=<id> instead.

    Example
    8d0f6c2e-3b1a-4c55-9a7e-2f4b6d1e9c30

Query parameters

  • scopeenumoptional

    me for your own sessions, workspace for the sessions of every member. Defaults to workspace for owners and admins and to me for agents; agents always get only their own sessions.

    Example
    workspace

Response

200 OKapplication/json

  • itemsarray<Session>

    Signed-in sessions.

    Show child attributesHide child attributes15
    • iduuid

      Session id. Use it to sign the session out.

    • user_iduuid

      The signed-in user.

    • user_namestring

      Their name.

    • emailstring

      Their email address.

    • ipstring

      IP address the session signed in from, or "" for older sessions.

    • locationstring

      City and country of the IP address, for example Ljubljana, SI, or only the country (SI). "" when unknown.

    • countrystring

      Two-letter country code of the IP address, or "".

    • citystring

      City of the IP address, or "".

    • devicestring

      Browser and operating system, for example Chrome on macOS, or "".

    • methodstring

      How it signed in: password, google, invite, signup, or "" when unknown.

    • created_attimestamp

      When the session signed in.

    • last_seen_attimestampnullable

      Last request made with the session, updated at most every 5 minutes. null when not recorded yet.

    • expires_attimestamp

      When the session ends unless it is signed out first.

    • currentboolean

      true for the session that made this request.

    • can_revokeboolean

      true when you may sign this session out.

Status codes

  • 200OK. The sessions.
  • 400Bad request. Session requests only: no workspace was selected (workspace required (X-Tenant-ID)).
  • 401Unauthorized. The API key is unknown, revoked or expired (invalid or expired API key), or there is no key and no signed-in session (unauthorized).
  • 403Forbidden. The API key does not have the admin scope (this endpoint needs an API key with the admin scope: read and write keys cannot read security data); the key is limited to other IP addresses (this API key is not allowed from your IP address, code: "ip_not_allowed"); or the key or user belongs to another workspace (API key belongs to a different workspace, forbidden).
  • 500Server error. Something went wrong on our side. Retry with backoff.