API reference · Access and identity
API tokens, members and sessions
12 operations of the Ankra Cloud API: API tokens, members, invitations and sessions.
List API tokens, newest first (revoked tokens are not listed)#
/v1/api-tokens- Operation
list_api_tokens- Credentials
- Portal session
- Requires
- Permission
tokens.manage
Session-only, like every route under /v1/api-tokens and /v1/members: an API token gets 403 here, so a leaked token can neither mint another nor invite anyone.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
cursor | query | string | The next_cursor of the previous page. |
Responses
200A page of API tokens.application/json · ApiTokenList
| Field | Type | Description |
|---|---|---|
itemsrequired | array of ApiToken | |
idrequired | string | |
namerequired | string | |
prefixrequired | string | The first 8 characters of the token (act_ plus 4). |
scoperequired | string | read (any read the role allows, no writes), read_write (everything the role allows), or a comma-separated list of permissions from read, operate, billing.read, billing.manage and self, stored in that order; a list always includes read and self. tokens.manage and members.manage cannot be granted. |
created_by_emailrequired | string | |
created_atrequired | string (date-time) | |
last_used_atrequired | string (date-time) | null | |
expires_atrequired | string (date-time) | |
next_cursorrequired | string | null | Pass as ?cursor= for the next page; null on the last page. |
- 400The request is invalid;
detailsays why. - 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl 'https://cloud.ankra.app/v1/api-tokens' \
-b "ankracloud_session=$SESSION"Create an API token#
/v1/api-tokens- Operation
create_api_token- Credentials
- Portal session
- Requires
- Permission
tokens.manage
The plaintext token is returned only here. A support session gets 403.
Request bodyapplication/json
| Field | Type | Description |
|---|---|---|
namerequired | string | |
scoperequired | string | read (any read the role allows, no writes), read_write (everything the role allows), or a comma-separated list of permissions from read, operate, billing.read, billing.manage and self, stored in that order; a list always includes read and self. tokens.manage and members.manage cannot be granted. |
expires_at | string (date-time) | In the future and at most 365 days away; 90 days when omitted. An explicit null is refused with 400. |
Responses
201The token.application/json
| Field | Type | Description |
|---|---|---|
api_tokenrequired | ApiToken | |
idrequired | string | |
namerequired | string | |
prefixrequired | string | The first 8 characters of the token (act_ plus 4). |
scoperequired | string | read (any read the role allows, no writes), read_write (everything the role allows), or a comma-separated list of permissions from read, operate, billing.read, billing.manage and self, stored in that order; a list always includes read and self. tokens.manage and members.manage cannot be granted. |
created_by_emailrequired | string | |
created_atrequired | string (date-time) | |
last_used_atrequired | string (date-time) | null | |
expires_atrequired | string (date-time) | |
tokenrequired | string | act_ plus 32 random bytes, base64url. |
- 400The request is invalid;
detailsays why. - 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl -X POST 'https://cloud.ankra.app/v1/api-tokens' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN" \
-H 'Content-Type: application/json' \
-d '{
"name": "string",
"scope": "read,operate,self"
}'Revoke an API token#
/v1/api-tokens/{id}- Operation
revoke_api_token- Credentials
- Portal session
- Requires
- Permission
tokens.manage
Parameters
| Name | In | Type | Description |
|---|---|---|---|
idrequired | path | string |
Responses
204Revoked.
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 404No such resource in the caller's account.
- defaultAny other error, usually 500.
Example
curl -X DELETE 'https://cloud.ankra.app/v1/api-tokens/<id>' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN"List the account's members, oldest first#
/v1/members- Operation
list_members- Credentials
- Portal session
- Requires
- Permission
read
Parameters
| Name | In | Type | Description |
|---|---|---|---|
cursor | query | string | The next_cursor of the previous page. |
limit | query | integer | Page size; the server applies its default and maximum. |
Responses
200A page of members.application/json · MemberList
| Field | Type | Description |
|---|---|---|
itemsrequired | array of Member | |
idrequired | string | |
emailrequired | string | |
rolerequired | string | One of owner, admin, member, viewer |
created_atrequired | string (date-time) | |
last_login_atrequired | string (date-time) | null | |
is_current_userrequired | boolean | |
next_cursorrequired | string | null | Pass as ?cursor= for the next page; null on the last page. |
- 400The request is invalid;
detailsays why. - 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl 'https://cloud.ankra.app/v1/members' \
-b "ankracloud_session=$SESSION"Change a member's role#
/v1/members/{id}- Operation
change_member_role- Credentials
- Portal session
- Requires
- Permission
members.manage
403 for the owner, and for a support session.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
idrequired | path | string |
Request bodyapplication/json
| Field | Type | Description |
|---|---|---|
rolerequired | string | Nobody can be made owner through the API.One of admin, member, viewer |
Responses
200The member.application/json
| Field | Type | Description |
|---|---|---|
memberrequired | Member | |
idrequired | string | |
emailrequired | string | |
rolerequired | string | One of owner, admin, member, viewer |
created_atrequired | string (date-time) | |
last_login_atrequired | string (date-time) | null | |
is_current_userrequired | boolean |
- 400The request is invalid;
detailsays why. - 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 404No such resource in the caller's account.
- defaultAny other error, usually 500.
Example
curl -X PATCH 'https://cloud.ankra.app/v1/members/<id>' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN" \
-H 'Content-Type: application/json' \
-d '{
"role": "admin"
}'Remove a member with their sessions and API tokens#
/v1/members/{id}- Operation
remove_member- Credentials
- Portal session
- Requires
- Permission
members.manage
403 for the owner, and for a support session; 409 for yourself.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
idrequired | path | string |
Responses
204Removed.
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 404No such resource in the caller's account.
- 409The resource's state does not allow this now.
- defaultAny other error, usually 500.
Example
curl -X DELETE 'https://cloud.ankra.app/v1/members/<id>' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN"List pending invitations (`next_cursor` is always null)#
/v1/members/invitations- Operation
list_invitations- Credentials
- Portal session
- Requires
- Permission
members.manage
Responses
200Every pending invitation.application/json · InvitationList
| Field | Type | Description |
|---|---|---|
itemsrequired | array of Invitation | |
idrequired | string | |
emailrequired | string | |
rolerequired | string | One of owner, admin, member, viewer |
invited_by_emailrequired | string | |
created_atrequired | string (date-time) | |
expires_atrequired | string (date-time) | |
next_cursorrequired | string | null | Pass as ?cursor= for the next page; null on the last page. |
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl 'https://cloud.ankra.app/v1/members/invitations' \
-b "ankracloud_session=$SESSION"Invite someone to the account#
/v1/members/invitations- Operation
invite_member- Credentials
- Portal session
- Requires
- Permission
members.manage
409 when the email is already a member of this account. A support session gets 403.
Request bodyapplication/json
| Field | Type | Description |
|---|---|---|
emailrequired | string (email) | |
rolerequired | string | Nobody can be made owner through the API.One of admin, member, viewer |
Responses
201The invitation and its single-use signup link (valid 7 days).application/json
| Field | Type | Description |
|---|---|---|
invitationrequired | Invitation | |
idrequired | string | |
emailrequired | string | |
rolerequired | string | One of owner, admin, member, viewer |
invited_by_emailrequired | string | |
created_atrequired | string (date-time) | |
expires_atrequired | string (date-time) | |
tokenrequired | string | The aci_… invitation token. |
signup_pathrequired | string |
- 400The request is invalid;
detailsays why. - 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 409The resource's state does not allow this now.
- defaultAny other error, usually 500.
Example
curl -X POST 'https://cloud.ankra.app/v1/members/invitations' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN" \
-H 'Content-Type: application/json' \
-d '{
"email": "string",
"role": "admin"
}'Revoke a pending invitation#
/v1/members/invitations/{id}- Operation
revoke_invitation- Credentials
- Portal session
- Requires
- Permission
members.manage
Parameters
| Name | In | Type | Description |
|---|---|---|---|
idrequired | path | string |
Responses
204Revoked.
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 404No such resource in the caller's account.
- defaultAny other error, usually 500.
Example
curl -X DELETE 'https://cloud.ankra.app/v1/members/invitations/<id>' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN"The caller's unexpired sessions, newest first (`next_cursor` is always null)#
/v1/sessions- Operation
list_sessions- Credentials
- API token, Portal session
- Requires
- Permission
self
Responses
200Every session of the caller.application/json · SessionList
| Field | Type | Description |
|---|---|---|
itemsrequired | array of Session | |
idrequired | string | |
created_atrequired | string (date-time) | |
last_seen_atrequired | string (date-time) | |
expires_atrequired | string (date-time) | |
is_currentrequired | boolean | |
is_support_sessionrequired | boolean | |
staff_emailrequired | string | null | Null unless is_support_session. |
next_cursorrequired | string | null | Pass as ?cursor= for the next page; null on the last page. |
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl 'https://cloud.ankra.app/v1/sessions' \
-H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"End one of the caller's sessions#
/v1/sessions/{id}- Operation
revoke_session- Credentials
- API token, Portal session
- Requires
- Permission
self
Ending the current session also clears its cookies.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
idrequired | path | string |
Responses
204Ended.
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 404No such resource in the caller's account.
- defaultAny other error, usually 500.
Example
curl -X DELETE 'https://cloud.ankra.app/v1/sessions/<id>' \
-H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"End every session of the user except the one making the call#
/v1/sessions/revoke-others- Operation
revoke_other_sessions- Credentials
- API token, Portal session
- Requires
- Permission
self
Responses
200How many sessions were ended.application/json
| Field | Type | Description |
|---|---|---|
revokedrequired | integer |
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl -X POST 'https://cloud.ankra.app/v1/sessions/revoke-others' \
-H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"