v1

latestOpenAPI 3.0.12026-07-24310590875.6 KB
partner

API login as user

Sign in to a created organization as a created user of that organization. In the response, your API session is created and a generated sessionId is available for organization-level BILL API operations.

This endpoint is required for a specific BILL partner-level workflow.

  1. Sign in to your partner account with API partner login.
  2. Create a child BILL organization with POST /v3/partner/organizations. In the response, a BILL-generated organization id is available.
  3. Create a user for the child BILL organization with POST /v3/partner/users. In the response, a BILL-generated user id is available.
  4. Sign in to the created organization as the created user of that organization with POST /v3/partner/login-as-user. After signing in, you can perform organization-level BILL API operations, such as creating a bill or paying a vendor. All organization-level BILL API operations require a devKey and sessionId.

Note: When you create an organization and then create a user for that organization, it is important that you initiate risk verification with POST /v3/risk-verifications. See Initiate risk verification for an organization for more information.

This operation requires partner-level permissions.

You can sign out with POST /v3/logout. If your API session is inactive for 35 minutes, the session expires and you are automatically signed out.

MFA-trusted API session

Set both rememberMeId and device as additional fields in your POST /v3/partner/login-as-user request to create an MFA-trusted API session.

post/v3/partner/login-as-user

Headers

sessionIdstring nullable

API session ID generated with /v3/partner/login

Example:{{partner_session_id}}
appKeystring nullable

Application key sent to you by BILL when you create a partner account

Example:{{app_key}}

Request body

userIdstring required

BILL-generated ID of the user you want to sign in as

organizationIdstring required

BILL-generated ID of the organization you want to sign in to

rememberMeIdstring

MFA ID. Set this field for creating an MFA-trusted API session.

This MFA ID is generated when you set rememberMe as true in your POST /v3/mfa/challenge/validate request. This value expires in 30 days.

See Validate MFA challenge for more information.

devicestring

Mobile device name. This is a nickname for your mobile device. This field is required when you set rememberMeId.

Example request

{
  "userId": "{{partner_user_id}}",
  "organizationId": "{{partner_organization_id}}"
}

Response

API login as user response

sessionIdstring

API session ID. Use this value in all subsequent API calls to confirm that you are in a signed-in session.

trustedboolean

This field is set as true if the current API session is MFA-trusted