v1

latestOpenAPI 3.0.3Apache 2.02026-07-1756158355.3 KB
identity

List an Identity's Sessions

This endpoint returns all sessions that belong to the given Identity.

get/admin/identities/{id}/sessions

Path parameters

idstring required

ID is the identity's ID.

Query parameters

per_pageinteger

Deprecated Items per Page

DEPRECATED: Please use page_token instead. This parameter will be removed in the future.

This is the number of items per page.

pageinteger

Deprecated Pagination Page

DEPRECATED: Please use page_token instead. This parameter will be removed in the future.

This value is currently an integer, but it is not sequential. The value is not the page number, but a reference. The next page can be any number and some numbers might return an empty list.

For example, page 2 might not follow after page 1. And even if page 3 and 5 exist, but page 4 might not exist. The first page can be retrieved by omitting this parameter. Following page pointers will be returned in the Link header.

page_sizeinteger

Page Size

This is the number of items per page to return. For details on pagination please head over to the pagination documentation.

page_tokenstring

Next Page Token

The next page token. For details on pagination please head over to the pagination documentation.

activeboolean

Active is a boolean flag that filters out sessions based on the state. If no value is provided, all sessions are returned.

Response

List Identity Sessions Response

activeboolean

Active state. If false the session is no longer active.

authenticated_atstring date-time

The Session Authentication Timestamp

When this session was authenticated at. If multi-factor authentication was used this is the time when the last factor was authenticated (e.g. the TOTP code challenge was completed).

authenticator_assurance_level'aal0' | 'aal1' | 'aal2' | 'aal3'

The authenticator assurance level can be one of "aal1", "aal2", or "aal3". A higher number means that it is harder for an attacker to compromise the account.

Generally, "aal1" implies that one authentication factor was used while AAL2 implies that two factors (e.g. password + TOTP) have been used.

To learn more about these levels please head over to: https://www.ory.sh/kratos/docs/concepts/credentials

expires_atstring date-time

The Session Expiry

When this session expires at.

idstring uuid required

Session ID

issued_atstring date-time

The Session Issuance Timestamp

When this session was issued at. Usually equal or close to authenticated_at.

tokenizedstring

Tokenized is the tokenized (e.g. JWT) version of the session.

It is only set when the tokenize_as query parameter was set to a valid tokenize template during calls to /session/whoami.

Example response

[
  {
    "tokenized": "tokenized",
    "expires_at": "2000-01-23T04:56:07.000+00:00",
    "devices": [
      {
        "location": "location",
        "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
        "ip_address": "ip_address",
        "user_agent": "user_agent"
      },
      {
        "location": "location",
        "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
        "ip_address": "ip_address",
        "user_agent": "user_agent"
      }
    ],
    "authentication_methods": [
      {
        "completed_at": "2000-01-23T04:56:07.000+00:00",
        "method": "password",
        "provider": "provider",
        "organization": "organization",
        "aal": "aal0"
      },
      {
        "completed_at": "2000-01-23T04:56:07.000+00:00",
        "method": "password",
        "provider": "provider",
        "organization": "organization",
        "aal": "aal0"
      }
    ],
    "authenticator_assurance_level": null,
    "identity": {
      "traits": "",
      "credentials": {
        "key": {
          "updated_at": "2000-01-23T04:56:07.000+00:00",
          "identifiers": [
            "identifiers",
            "identifiers"
          ],
          "created_at": "2000-01-23T04:56:07.000+00:00",
          "type": "password",
          "config": "{}",
          "version": 0
        }
      },
      "state_changed_at": "2000-01-23T04:56:07.000+00:00",
      "created_at": "2000-01-23T04:56:07.000+00:00",
      "external_id": "external_id",
      "recovery_addresses": [
        {
          "updated_at": "2000-01-23T04:56:07.000+00:00",
          "created_at": "2000-01-23T04:56:07.000+00:00",
          "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
          "value": "value",
          "via": "via"
        },
        {
          "updated_at": "2000-01-23T04:56:07.000+00:00",
          "created_at": "2000-01-23T04:56:07.000+00:00",
          "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
          "value": "value",
          "via": "via"
        }
      ],
      "metadata_admin": "",
      "updated_at": "2000-01-23T04:56:07.000+00:00",
      "verifiable_addresses": [
        {
          "updated_at": "2014-01-01T23:28:56.782Z",
          "verified_at": "2000-01-23T04:56:07.000+00:00",
          "verified": true,
          "created_at": "2014-01-01T23:28:56.782Z",
          "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
          "value": "value",
          "status": "status",
          "via": "email"
        },
        {
          "updated_at": "2014-01-01T23:28:56.782Z",
          "verified_at": "2000-01-23T04:56:07.000+00:00",
          "verified": true,
          "created_at": "2014-01-01T23:28:56.782Z",
          "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
          "value": "value",
          "status": "status",
          "via": "email"
        }
      ],
      "organization_id": "organization_id",
      "schema_id": "schema_id",
      "schema_url": "schema_url",
      "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
      "state": "active",
      "metadata_public": ""
    },
    "authenticated_at": "2000-01-23T04:56:07.000+00:00",
    "active": true,
    "id": "046b6c7f-0b8a-43b9-b35d-6489e6daee91",
    "issued_at": "2000-01-23T04:56:07.000+00:00"
  }
]