API reference · Access and identity
Linked identities
2 operations of the Ankra Cloud API: The signed-in user's linked sign-in identities.
List the identity provider identities you sign in with#
GET
/v1/account/identities- Operation
list_account_identities- Credentials
- API token, Portal session
- Requires
- Permission
self
The signed-in user's linked identities (Google, Microsoft, GitHub or the provider's own accounts), oldest first; the same list GET /v1/auth/me carries in identities. Empty when no identity provider was ever used.
Responses
200The linked identities.application/json · LinkedIdentityList
| Field | Type | Description |
|---|---|---|
itemsrequired | array of LinkedIdentity | |
idrequired | string | |
providerrequired | string | The issuer URL. |
provider_namerequired | string | The upstream provider, from the subject's connection prefix: Google (google-oauth2), GitHub (github), Microsoft (waad, windowslive, microsoft), the provider's own accounts for auth0 or no prefix (the display name, default "Ankra account"), else the prefix itself. |
subject_hintrequired | string | The connection and the last characters of the subject; never the subject itself. |
linked_atrequired | string (date-time) | |
last_login_atrequired | string (date-time) | null | |
next_cursorrequired | string | null | Pass as ?cursor= for the next page; null on the last page. |
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - defaultAny other error, usually 500.
Example
curl 'https://cloud.ankra.app/v1/account/identities' \
-H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"Unlink one of your sign-in identities#
DELETE
/v1/account/identities/{id}- Operation
unlink_account_identity- Credentials
- Portal session
- Requires
- Permission
self
The provider account can no longer sign in as you. Your last way to sign in is never removed: a user without a password keeps their only identity (409). Session-only; a support session is refused (403). The unlink and its audit event (auth.identity_unlink) are stored together.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
idrequired | path | string |
Responses
200The identity was unlinked.application/json
| Field | Type | Description |
|---|---|---|
identityrequired | LinkedIdentity | |
idrequired | string | |
providerrequired | string | The issuer URL. |
provider_namerequired | string | The upstream provider, from the subject's connection prefix: Google (google-oauth2), GitHub (github), Microsoft (waad, windowslive, microsoft), the provider's own accounts for auth0 or no prefix (the display name, default "Ankra account"), else the prefix itself. |
subject_hintrequired | string | The connection and the last characters of the subject; never the subject itself. |
linked_atrequired | string (date-time) | |
last_login_atrequired | string (date-time) | null |
- 401Not signed in, or the credential is invalid or expired.
- 403The role lacks the permission, the token is read-only (a read-only token also gets
reason: read_only_token_cannot_read_credentialson every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified). - 404No such resource in the caller's account.
- 409The resource's state does not allow this now.
- defaultAny other error, usually 500.
Example
curl -X DELETE 'https://cloud.ankra.app/v1/account/identities/<id>' \
-b "ankracloud_session=$SESSION" \
-H "X-CSRF-Token: $CSRF_TOKEN"