AnkraDocs
Console

API reference · Access and identity

Support access

7 operations of the Ankra Cloud API: The customer's control over Ankra support access.

How elevated support sessions may be opened for this account#

GET/v1/account/support-access
Operation
get_support_access
Credentials
Portal session
Requires
Permission members.manage

Responses

200The standing decision.application/json · SupportAccessSetting

200 response fields
FieldTypeDescription
support_accessrequiredstringOne of consent_required, always_allowed
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/account/support-access' \
  -b "ankracloud_session=$SESSION"

Change how elevated support sessions may be opened (owner only)#

PUT/v1/account/support-access
Operation
set_support_access
Credentials
Portal session
Requires
Permission members.manage

Session-only. consent_required (the default) makes staff ask for a consent code before every elevated session; always_allowed lets admin staff open one without asking. Read-only support sessions never need consent. Audited as support.access_changed.

Request bodyapplication/json · SupportAccessSetting

Request body fields
FieldTypeDescription
support_accessrequiredstringOne of consent_required, always_allowed

Responses

200Changed.application/json · SupportAccessSetting

200 response fields
FieldTypeDescription
support_accessrequiredstringOne of consent_required, always_allowed
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl -X PUT 'https://cloud.ankra.app/v1/account/support-access' \
  -b "ankracloud_session=$SESSION" \
  -H "X-CSRF-Token: $CSRF_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "support_access": "consent_required"
}'

The account's newest consent codes, open and closed (`next_cursor` is always null)#

GET/v1/account/support-consents
Operation
list_support_consents
Credentials
Portal session
Requires
Permission members.manage

Responses

200Up to 50 consents, newest first.application/json · SupportConsentList

200 response fields
FieldTypeDescription
itemsrequiredarray of SupportConsent
idrequiredstring
created_by_emailrequiredstring
created_atrequiredstring (date-time)
expires_atrequiredstring (date-time)
used_atrequiredstring (date-time) | null
used_by_staff_emailrequiredstring | null
revoked_atrequiredstring (date-time) | null
is_openrequiredbooleanNot used, not revoked and not expired.
next_cursorrequiredstring | nullPass as ?cursor= for the next page; null on the last page.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/account/support-consents' \
  -b "ankracloud_session=$SESSION"

The support sessions open in the account, newest first (`next_cursor` is always null)#

GET/v1/account/support-sessions
Operation
list_support_sessions
Credentials
API token, Portal session
Requires
Permission read

Responses

200Every unexpired support session, with the staff member, mode and reason.application/json · SupportSessionList

200 response fields
FieldTypeDescription
itemsrequiredarray of SupportSession
idrequiredstring
acting_as_emailrequiredstringThe account user the staff member acts as.
staff_emailrequiredstring
staff_namerequiredstring
reasonrequiredstring
moderequiredstringread_only sessions change nothing and read no credential (database passwords, object storage keys, the console, instance metadata, payment methods). elevated sessions act like the customer, except that no support session manages API tokens, members, payment methods or support consents.One of read_only, elevated
created_atrequiredstring (date-time)
expires_atrequiredstring (date-time)
last_seen_atrequiredstring (date-time)
next_cursorrequiredstring | nullPass as ?cursor= for the next page; null on the last page.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/account/support-sessions' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

End a support session now#

DELETE/v1/account/support-sessions/{id}
Operation
end_support_session
Credentials
Portal session
Requires
Permission members.manage

Session-only; the staff browser is signed out of the account at once. Audited as support.session_ended by the customer.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

204Ended.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/account/support-sessions/<id>' \
  -b "ankracloud_session=$SESSION" \
  -H "X-CSRF-Token: $CSRF_TOKEN"