openapi: 3.0.3 info: title: Stytch B2B Authentication Application Session API version: 2.0.0 description: Stytch's B2B API for multi-tenant authentication. Supports Organizations, Members, SSO (SAML/OIDC), Magic Links, OTP, OAuth, Discovery, Sessions, B2B RBAC, SCIM, TOTP, Recovery Codes, Passwords, Impersonation, and the B2B IDP. contact: name: Stytch url: https://stytch.com/docs license: name: Proprietary servers: - url: https://api.stytch.com description: Production - url: https://test.stytch.com description: Test tags: - name: Session paths: /v1/b2b/sessions: get: summary: Get operationId: api_b2b_session_v1_Get tags: - Session description: Retrieves all active Sessions for a Member. parameters: - name: organization_id in: query required: true schema: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. - name: member_id in: query required: true schema: type: string description: Globally unique UUID that identifies a specific Member. The `member_id` is critical to perform operations on a Member, so be sure to preserve this value. You may use an external_id here if one is set for the member. responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_GetResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// GET /v1/b2b/sessions\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n member_id: \"${memberId}\",\n};\n\nclient.Sessions.Get(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// GET /v1/b2b/sessions\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.GetParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tMemberID: \"${memberId}\",\n\t}\n\n\tresp, err := client.Sessions.Get(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// GET /v1/b2b/sessions\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.GetRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n GetRequest params = new GetRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setMemberId(\"${memberId}\");\n\n Object result = StytchB2BClient.getSessions().get(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// GET /v1/b2b/sessions\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.GetRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.get(\n GetRequest(\n organizationId = \"${organizationId}\",\n memberId = \"${memberId}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// GET /v1/b2b/sessions\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n member_id: \"${memberId}\",\n};\n\nclient.sessions.get(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->get([\n 'organization_id' => '${organizationId}',\n 'member_id' => '${memberId}',\n]);" - lang: python label: Python source: "# GET /v1/b2b/sessions\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.get(\n organization_id=\"${organizationId}\",\n member_id=\"${memberId}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# GET /v1/b2b/sessions\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.get(\n organization_id: \"${organizationId}\",\n member_id: \"${memberId}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// GET /v1/b2b/sessions\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::GetRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.get(\n GetRequest{\n organization_id: \"${organizationId}\",\n member_id: \"${memberId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# GET /v1/b2b/sessions\ncurl --request GET \\\n --url https://test.stytch.com/v1/b2b/sessions \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n --get \\\n --data-urlencode 'organization_id=${organizationId}' \\\n --data-urlencode 'member_id=${memberId}'" /v1/b2b/sessions/authenticate: post: summary: Authenticate operationId: api_b2b_session_v1_Authenticate tags: - Session description: 'Authenticates a Session and updates its lifetime by the specified `session_duration_minutes`. If the `session_duration_minutes` is not specified, a Session will not be extended. This endpoint requires either a `session_jwt` or `session_token` be included in the request. It will return an error if both are present. You may provide a JWT that needs to be refreshed and is expired according to its `exp` claim. A new JWT will be returned if both the signature and the underlying Session are still valid. See our [How to use Stytch Session JWTs](https://stytch.com/docs/b2b/guides/sessions/resources/using-jwts) guide for more information. If an `authorization_check` object is passed in, this method will also check if the Member is authorized to perform the given action on the given Resource in the specified Organization. A Member is authorized if their Member Session contains a Role, assigned [explicitly or implicitly](https://stytch.com/docs/b2b/guides/rbac/role-assignment), with adequate permissions. In addition, the `organization_id` passed in the authorization check must match the Member''s Organization. If the Member is not authorized to perform the specified action on the specified Resource, or if the `organization_id` does not match the Member''s Organization, a 403 error will be thrown. Otherwise, the response will contain a list of Roles that satisfied the authorization check.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_AuthenticateRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_AuthenticateResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sessions/authenticate\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n};\n\nclient.Sessions.Authenticate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sessions/authenticate\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.AuthenticateParams{\n\t\tSessionToken: \"${sessionToken}\",\n\t}\n\n\tresp, err := client.Sessions.Authenticate(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sessions/authenticate\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.AuthenticateRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n AuthenticateRequest params = new AuthenticateRequest();\n params.setSessionToken(\"${sessionToken}\");\n\n Object result = StytchB2BClient.getSessions().authenticate(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sessions/authenticate\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.AuthenticateRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.authenticate(\n AuthenticateRequest(\n sessionToken = \"${sessionToken}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sessions/authenticate\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n};\n\nclient.sessions.authenticate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->authenticate([\n 'session_token' => '${sessionToken}',\n]);" - lang: python label: Python source: "# POST /v1/b2b/sessions/authenticate\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.authenticate(\n session_token=\"${sessionToken}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sessions/authenticate\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.authenticate(\n session_token: \"${sessionToken}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sessions/authenticate\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::AuthenticateRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.authenticate(\n AuthenticateRequest{\n session_token: Some(String::from(\"${sessionToken}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sessions/authenticate\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sessions/authenticate \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"session_token\": \"${sessionToken}\"\n }'" /v1/b2b/sessions/revoke: post: summary: Revoke operationId: api_b2b_session_v1_Revoke tags: - Session description: Revoke a Session and immediately invalidate all its tokens. To revoke a specific Session, pass either the `member_session_id`, `session_token`, or `session_jwt`. To revoke all Sessions for a Member, pass the `member_id`. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_RevokeRequest' parameters: - name: X-Stytch-Member-Session in: header required: false description: A Stytch session that can be used to run the request with the given member's permissions. schema: type: string - name: X-Stytch-Member-SessionJWT in: header required: false description: A Stytch Session JSON Web Token (JWT) that can be used to run the request with the given member's permissions. schema: type: string responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_RevokeResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sessions/revoke\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n member_id: \"${memberId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.Sessions.Revoke(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sessions/revoke\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/methodoptions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.RevokeParams{\n\t\tMemberID: \"${memberId}\",\n\t}\n\n\toptions := &sessions.RevokeParamsOptions{\n\t\tAuthorization: methodoptions.Authorization{\n\t\t\tSessionToken: \"${sessionToken}\",\n\t\t},\n\t}\n\n\tresp, err := client.Sessions.Revoke(context.Background(), params, options)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sessions/revoke\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.RevokeRequest;\nimport com.stytch.java.b2b.models.sessions.RevokeRequestOptions;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.methodoptions.Authorization;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n RevokeRequest params = new RevokeRequest();\n params.setMemberId(\"${memberId}\");\n\n RevokeRequestOptions options = new RevokeRequestOptions();\n Authorization authorization = new Authorization();\n authorization.setSessionToken(\"${sessionToken}\");\n options.setAuthorization(authorization);\n\n Object result = StytchB2BClient.getSessions().revoke(params, options);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sessions/revoke\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.RevokeRequest\nimport com.stytch.java.b2b.models.sessions.RevokeRequestOptions\nimport com.stytch.java.common.methodoptions.Authorization\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.revoke(\n RevokeRequest(\n memberId = \"${memberId}\",\n ),\n RevokeRequestOptions(\n Authorization(\n sessionToken = \"${sessionToken}\",\n ),\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sessions/revoke\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n member_id: \"${memberId}\",\n};\n\nconst options = {\n authorization: {\n session_token: '${sessionToken}',\n },\n};\n\nclient.sessions.revoke(params, options)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->revoke([\n 'member_id' => '${memberId}',\n], [\n 'authorization' => ['session_token' => '${sessionToken}'],\n\n]);" - lang: python label: Python source: "# POST /v1/b2b/sessions/revoke\nfrom stytch import B2BClient\nfrom stytch.b2b.models.sessions import RevokeRequestOptions\nfrom stytch.shared.method_options import Authorization\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.revoke(\n member_id=\"${memberId}\",\n method_options=RevokeRequestOptions(\n authorization=Authorization(\n session_token=\"${sessionToken}\",\n ),\n ),\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sessions/revoke\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.revoke(\n member_id: \"${memberId}\",\n method_options: StytchB2B::Sessions::RevokeRequestOptions.new(\n authorization: Stytch::MethodOptions::Authorization.new(session_token: '${sessionToken}')\n )\n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sessions/revoke\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::RevokeRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.revoke(\n RevokeRequest{\n member_id: Some(String::from(\"${memberId}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sessions/revoke\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sessions/revoke \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -H \"X-Stytch-Member-Session: ${sessionToken}\" \\\n -d '{\n \"member_id\": \"${memberId}\"\n }'" /v1/b2b/sessions/exchange: post: summary: Exchange operationId: api_b2b_session_v1_Exchange tags: - Session description: 'Use this endpoint to exchange a Member''s existing session for another session in a different Organization. This can be used to accept an invite, but not to create a new member via domain matching. To create a new member via email domain JIT Provisioning, use the [Exchange Intermediate Session](https://stytch.com/docs/b2b/api/exchange-intermediate-session) flow instead. If the user **has** already satisfied the authentication requirements of the Organization they are trying to switch into, this API will return `member_authenticated: true` and a `session_token` and `session_jwt`. If the user **has not** satisfied the primary or secondary authentication requirements of the Organization they are attempting to switch into, this API will return `member_authenticated: false` and an `intermediate_session_token`. If `primary_required` is set, prompt the user to fulfill the Organization''s auth requirements using the options returned in `primary_required.allowed_auth_methods`. If `primary_required` is null and `mfa_required` is set, check `mfa_required.member_options` to determine if the Member has SMS OTP or TOTP set up for MFA and prompt accordingly. If the Member has SMS OTP, check `mfa_required.secondary_auth_initiated` to see if the OTP has already been sent. Include the `intermediate_session_token` returned above when calling the `authenticate()` method that the user needed to perform. Once the user has completed the authentication requirements they were missing, they will be granted a full `session_token` and `session_jwt` to indicate they have successfully logged into the Organization. The `intermediate_session_token` can also be used with the [Exchange Intermediate Session endpoint](https://stytch.com/docs/b2b/api/exchange-intermediate-session) or the [Create Organization via Discovery endpoint](https://stytch.com/docs/b2b/api/create-organization-via-discovery) to join a different Organization or create a new one. The `session_duration_minutes` and `session_custom_claims` parameters will be ignored.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_ExchangeRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_ExchangeResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sessions/exchange\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n session_token: \"${sessionToken}\",\n};\n\nclient.Sessions.Exchange(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sessions/exchange\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.ExchangeParams{\n\t\tOrganizationID: \"${organizationId}\",\n\t\tSessionToken: \"${sessionToken}\",\n\t}\n\n\tresp, err := client.Sessions.Exchange(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sessions/exchange\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.ExchangeRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n ExchangeRequest params = new ExchangeRequest();\n params.setOrganizationId(\"${organizationId}\");\n params.setSessionToken(\"${sessionToken}\");\n\n Object result = StytchB2BClient.getSessions().exchange(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sessions/exchange\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.ExchangeRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.exchange(\n ExchangeRequest(\n organizationId = \"${organizationId}\",\n sessionToken = \"${sessionToken}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sessions/exchange\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n organization_id: \"${organizationId}\",\n session_token: \"${sessionToken}\",\n};\n\nclient.sessions.exchange(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->exchange([\n 'organization_id' => '${organizationId}',\n 'session_token' => '${sessionToken}',\n]);" - lang: python label: Python source: "# POST /v1/b2b/sessions/exchange\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.exchange(\n organization_id=\"${organizationId}\",\n session_token=\"${sessionToken}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sessions/exchange\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.exchange(\n organization_id: \"${organizationId}\",\n session_token: \"${sessionToken}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sessions/exchange\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::ExchangeRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.exchange(\n ExchangeRequest{\n organization_id: \"${organizationId}\",\n session_token: Some(String::from(\"${sessionToken}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sessions/exchange\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sessions/exchange \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"organization_id\": \"${organizationId}\",\n \"session_token\": \"${sessionToken}\"\n }'" /v1/b2b/sessions/exchange_access_token: post: summary: Exchangeaccesstoken operationId: api_b2b_session_v1_ExchangeAccessToken tags: - Session description: "Use this endpoint to exchange a Connected Apps Access Token back into a Member Session for the underlying Member. \nThis session can be used with the Stytch SDKs and APIs.\n\nThe Access Token must contain the `full_access` scope (only available to First Party clients) and must not be more than 5 minutes old. Access Tokens may only be exchanged a single time.\n\nBecause the Member previously completed MFA and satisfied all Organization authentication requirements at the time of the original Access Token issuance, this endpoint will never return an `intermediate_session_token` or require MFA." requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_ExchangeAccessTokenRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_ExchangeAccessTokenResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sessions/exchange_access_token\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n access_token: \"${sessionJwt}\",\n};\n\nclient.Sessions.ExchangeAccessToken(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sessions/exchange_access_token\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.ExchangeAccessTokenParams{\n\t\tAccessToken: \"${sessionJwt}\",\n\t}\n\n\tresp, err := client.Sessions.ExchangeAccessToken(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sessions/exchange_access_token\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.ExchangeAccessTokenRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n ExchangeAccessTokenRequest params = new ExchangeAccessTokenRequest();\n params.setAccessToken(\"${sessionJwt}\");\n\n Object result = StytchB2BClient.getSessions().exchangeAccessToken(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sessions/exchange_access_token\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.ExchangeAccessTokenRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.exchangeAccessToken(\n ExchangeAccessTokenRequest(\n accessToken = \"${sessionJwt}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sessions/exchange_access_token\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n access_token: \"${sessionJwt}\",\n};\n\nclient.sessions.exchangeAccessToken(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->exchange_access_token([\n 'access_token' => '${sessionJwt}',\n]);" - lang: python label: Python source: "# POST /v1/b2b/sessions/exchange_access_token\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.exchange_access_token(\n access_token=\"${sessionJwt}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sessions/exchange_access_token\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.exchange_access_token(\n access_token: \"${sessionJwt}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sessions/exchange_access_token\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::ExchangeAccessTokenRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.exchange_access_token(\n ExchangeAccessTokenRequest{\n access_token: \"${sessionJwt}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sessions/exchange_access_token\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sessions/exchange_access_token \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"access_token\": \"${sessionJwt}\"\n }'" /v1/b2b/sessions/attest: post: summary: Attest operationId: api_b2b_session_v1_Attest tags: - Session description: Exchange an auth token issued by a trusted identity provider for a Stytch session. You must first register a Trusted Auth Token profile in the Stytch dashboard [here](https://stytch.com/dashboard/trusted-auth-tokens). If a session token or session JWT is provided, it will add the trusted auth token as an authentication factor to the existing session. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_AttestRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_AttestResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sessions/attest\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n organization_id: \"${organizationId}\",\n};\n\nclient.Sessions.Attest(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sessions/attest\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.AttestParams{\n\t\tProfileID: \"${profileId}\",\n\t\tToken: \"${trustedAuthToken}\",\n\t\tOrganizationID: \"${organizationId}\",\n\t}\n\n\tresp, err := client.Sessions.Attest(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sessions/attest\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.AttestRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n AttestRequest params = new AttestRequest();\n params.setProfileId(\"${profileId}\");\n params.setToken(\"${trustedAuthToken}\");\n params.setOrganizationId(\"${organizationId}\");\n\n Object result = StytchB2BClient.getSessions().attest(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sessions/attest\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.AttestRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.attest(\n AttestRequest(\n profileId = \"${profileId}\",\n token = \"${trustedAuthToken}\",\n organizationId = \"${organizationId}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sessions/attest\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n organization_id: \"${organizationId}\",\n};\n\nclient.sessions.attest(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->attest([\n 'profile_id' => '${profileId}',\n 'token' => '${trustedAuthToken}',\n 'organization_id' => '${organizationId}',\n]);" - lang: python label: Python source: "# POST /v1/b2b/sessions/attest\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.attest(\n profile_id=\"${profileId}\",\n token=\"${trustedAuthToken}\",\n organization_id=\"${organizationId}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sessions/attest\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.attest(\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n organization_id: \"${organizationId}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sessions/attest\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::AttestRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.attest(\n AttestRequest{\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n organization_id: Some(String::from(\"${organizationId}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sessions/attest\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sessions/attest \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"profile_id\": \"${profileId}\",\n \"token\": \"${trustedAuthToken}\",\n \"organization_id\": \"${organizationId}\"\n }'" /v1/b2b/sessions/migrate: post: summary: Migrate operationId: api_b2b_session_v1_Migrate tags: - Session description: 'Migrate a session from an external OIDC compliant endpoint. Stytch will call the external UserInfo endpoint defined in your Stytch Project settings in the [Dashboard](https://stytch.com/dashboard/migrations), and then perform a lookup using the `session_token`. If the response contains a valid email address, Stytch will attempt to match that email address with an existing Member in your Organization and create a Stytch Session. You will need to create the member before using this endpoint.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_MigrateRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_MigrateResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/b2b/sessions/migrate\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n organization_id: \"${organizationId}\",\n};\n\nclient.Sessions.Migrate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/b2b/sessions/migrate\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.MigrateParams{\n\t\tSessionToken: \"${sessionToken}\",\n\t\tOrganizationID: \"${organizationId}\",\n\t}\n\n\tresp, err := client.Sessions.Migrate(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/b2b/sessions/migrate\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.MigrateRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n MigrateRequest params = new MigrateRequest();\n params.setSessionToken(\"${sessionToken}\");\n params.setOrganizationId(\"${organizationId}\");\n\n Object result = StytchB2BClient.getSessions().migrate(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/b2b/sessions/migrate\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.MigrateRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.migrate(\n MigrateRequest(\n sessionToken = \"${sessionToken}\",\n organizationId = \"${organizationId}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/b2b/sessions/migrate\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n organization_id: \"${organizationId}\",\n};\n\nclient.sessions.migrate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->migrate([\n 'session_token' => '${sessionToken}',\n 'organization_id' => '${organizationId}',\n]);" - lang: python label: Python source: "# POST /v1/b2b/sessions/migrate\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.migrate(\n session_token=\"${sessionToken}\",\n organization_id=\"${organizationId}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/b2b/sessions/migrate\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.migrate(\n session_token: \"${sessionToken}\",\n organization_id: \"${organizationId}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/b2b/sessions/migrate\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::MigrateRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.migrate(\n MigrateRequest{\n session_token: \"${sessionToken}\",\n organization_id: \"${organizationId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/b2b/sessions/migrate\ncurl --request POST \\\n --url https://test.stytch.com/v1/b2b/sessions/migrate \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"session_token\": \"${sessionToken}\",\n \"organization_id\": \"${organizationId}\"\n }'" /v1/b2b/sessions/jwks/{project_id}: get: summary: Getjwks operationId: api_b2b_session_v1_GetJWKS tags: - Session description: 'Get the JSON Web Key Set (JWKS) for a project. Within the JWKS, the JSON Web Keys are rotated every ~6 months. Upon rotation, new JWTs will be signed using the new key, and both keys will be returned by this endpoint for a period of 1 month. JWTs have a set lifetime of 5 minutes, so there will be a 5 minute period where some JWTs will be signed by the old keys, and some JWTs will be signed by the new keys. The correct key to use for validation is determined by matching the `kid` value of the JWT and key. If you''re using one of our [backend SDKs](https://stytch.com/docs/b2b/sdks), the JSON Web Key (JWK) rotation will be handled for you. If you''re using your own JWT validation library, many have built-in support for JWK rotation, and you''ll just need to supply this API endpoint. If not, your application should decide which JWK to use for validation by inspecting the `kid` value. See our [How to use Stytch Session JWTs](https://stytch.com/docs/b2b/guides/sessions/resources/using-jwts) guide for more information.' parameters: - name: project_id in: path required: true schema: type: string description: The `project_id` to get the JWKS for. description: The `project_id` to get the JWKS for. responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_b2b_session_v1_GetJWKSResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// GET /v1/b2b/sessions/jwks/{project_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n project_id: \"${projectId}\",\n};\n\nclient.Sessions.GetJWKS(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// GET /v1/b2b/sessions/jwks/{project_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/b2bstytchapi\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/b2b/sessions\"\n)\n\nfunc main() {\n\tclient, err := b2bstytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.GetJWKSParams{\n\t\tProjectID: \"${projectId}\",\n\t}\n\n\tresp, err := client.Sessions.GetJWKS(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// GET /v1/b2b/sessions/jwks/{project_id}\npackage com.example;\n\nimport com.stytch.java.b2b.models.sessions.GetJWKSRequest;\nimport com.stytch.java.b2b.StytchB2BClient;\nimport com.stytch.java.common.StytchResult;\n\npublic class Main {\n public static void main(String[] args) {\n StytchB2BClient.configure(\"${projectId}\", \"${secret}\");\n\n GetJWKSRequest params = new GetJWKSRequest();\n params.setProjectId(\"${projectId}\");\n\n Object result = StytchB2BClient.getSessions().getJWKS(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// GET /v1/b2b/sessions/jwks/{project_id}\npackage com.example\n\nimport com.stytch.java.b2b.StytchB2BClient\nimport com.stytch.java.b2b.models.sessions.GetJWKSRequest\n\nfun main() {\n StytchB2BClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchB2BClient.sessions.getJWKS(\n GetJWKSRequest(\n projectId = \"${projectId}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// GET /v1/b2b/sessions/jwks/{project_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.B2BClient({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n project_id: \"${projectId}\",\n};\n\nclient.sessions.getJWKS(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->get_jwks([\n 'project_id' => '${projectId}',\n]);" - lang: python label: Python source: "# GET /v1/b2b/sessions/jwks/{project_id}\nfrom stytch import B2BClient\n\nclient = B2BClient(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.get_jwks(\n project_id=\"${projectId}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# GET /v1/b2b/sessions/jwks/{project_id}\nrequire 'stytch'\n\nclient = StytchB2B::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.get_jwks(\n project_id: \"${projectId}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// GET /v1/b2b/sessions/jwks/{project_id}\nuse stytch::b2b::client::Client;\nuse stytch::b2b::sessions::GetJWKSRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.get_jwks(\n GetJWKSRequest{\n project_id: \"${projectId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# GET /v1/b2b/sessions/jwks/{project_id}\ncurl --request GET \\\n --url https://test.stytch.com/v1/b2b/sessions/jwks/${projectId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json'" /v1/sessions: get: summary: Get operationId: api_session_v1_Get tags: - Session description: List all active Sessions for a given `user_id`. All timestamps are formatted according to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. parameters: - name: user_id in: query required: true schema: type: string description: The `user_id` to get active Sessions for. You may use an `external_id` here if one is set for the user. responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_GetResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// GET /v1/sessions\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n user_id: \"${userId}\",\n};\n\nclient.Sessions.Get(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// GET /v1/sessions\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/stytchapi\"\n)\n\nfunc main() {\n\tclient, err := stytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.GetParams{\n\t\tUserID: \"${userId}\",\n\t}\n\n\tresp, err := client.Sessions.Get(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// GET /v1/sessions\npackage com.example;\n\nimport com.stytch.java.common.StytchResult;\nimport com.stytch.java.consumer.models.sessions.GetRequest;\nimport com.stytch.java.consumer.StytchClient;\n\npublic class Main {\n public static void main(String[] args) {\n StytchClient.configure(\"${projectId}\", \"${secret}\");\n\n GetRequest params = new GetRequest();\n params.setUserId(\"${userId}\");\n\n Object result = StytchClient.getSessions().get(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// GET /v1/sessions\npackage com.example\n\nimport com.stytch.java.consumer.StytchClient\nimport com.stytch.java.consumer.models.sessions.GetRequest\n\nfun main() {\n StytchClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchClient.sessions.get(\n GetRequest(\n userId = \"${userId}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// GET /v1/sessions\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n user_id: \"${userId}\",\n};\n\nclient.sessions.get(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->get([\n 'user_id' => '${userId}',\n]);" - lang: python label: Python source: "# GET /v1/sessions\nfrom stytch import Client\n\nclient = Client(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.get(\n user_id=\"${userId}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# GET /v1/sessions\nrequire 'stytch'\n\nclient = Stytch::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.get(\n user_id: \"${userId}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// GET /v1/sessions\nuse stytch::consumer::client::Client;\nuse stytch::consumer::sessions::GetRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.get(\n GetRequest{\n user_id: \"${userId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# GET /v1/sessions\ncurl --request GET \\\n --url https://test.stytch.com/v1/sessions \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n --get \\\n --data-urlencode 'user_id=${userId}'" /v1/sessions/authenticate: post: summary: Authenticate operationId: api_session_v1_Authenticate tags: - Session description: 'Authenticate a session token or session JWT and retrieve associated session data. If `session_duration_minutes` is included, update the lifetime of the session to be that many minutes from now. All timestamps are formatted according to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. This endpoint requires exactly one `session_jwt` or `session_token` as part of the request. If both are included, you will receive a `too_many_session_arguments` error. You may provide a JWT that needs to be refreshed and is expired according to its `exp` claim. A new JWT will be returned if both the signature and the underlying Session are still valid. See our [How to use Stytch Session JWTs](https://stytch.com/docs/guides/sessions/using-jwts) guide for more information.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_session_v1_AuthenticateRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_AuthenticateResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 /v1/sessions/revoke: post: summary: Revoke operationId: api_session_v1_Revoke tags: - Session description: 'Revoke a Session, immediately invalidating all of its session tokens. You can revoke a session in three ways: using its ID, or using one of its session tokens, or one of its JWTs. This endpoint requires exactly one of those to be included in the request. It will return an error if multiple are present.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_session_v1_RevokeRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_RevokeResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/sessions/revoke\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n};\n\nclient.Sessions.Revoke(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/sessions/revoke\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/stytchapi\"\n)\n\nfunc main() {\n\tclient, err := stytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.RevokeParams{\n\t\tSessionToken: \"${sessionToken}\",\n\t}\n\n\tresp, err := client.Sessions.Revoke(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/sessions/revoke\npackage com.example;\n\nimport com.stytch.java.common.StytchResult;\nimport com.stytch.java.consumer.models.sessions.RevokeRequest;\nimport com.stytch.java.consumer.StytchClient;\n\npublic class Main {\n public static void main(String[] args) {\n StytchClient.configure(\"${projectId}\", \"${secret}\");\n\n RevokeRequest params = new RevokeRequest();\n params.setSessionToken(\"${sessionToken}\");\n\n Object result = StytchClient.getSessions().revoke(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/sessions/revoke\npackage com.example\n\nimport com.stytch.java.consumer.StytchClient\nimport com.stytch.java.consumer.models.sessions.RevokeRequest\n\nfun main() {\n StytchClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchClient.sessions.revoke(\n RevokeRequest(\n sessionToken = \"${sessionToken}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/sessions/revoke\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n};\n\nclient.sessions.revoke(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->revoke([\n 'session_token' => '${sessionToken}',\n]);" - lang: python label: Python source: "# POST /v1/sessions/revoke\nfrom stytch import Client\n\nclient = Client(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.revoke(\n session_token=\"${sessionToken}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/sessions/revoke\nrequire 'stytch'\n\nclient = Stytch::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.revoke(\n session_token: \"${sessionToken}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/sessions/revoke\nuse stytch::consumer::client::Client;\nuse stytch::consumer::sessions::RevokeRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.revoke(\n RevokeRequest{\n session_token: Some(String::from(\"${sessionToken}\")),\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/sessions/revoke\ncurl --request POST \\\n --url https://test.stytch.com/v1/sessions/revoke \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"session_token\": \"${sessionToken}\"\n }'" /v1/sessions/migrate: post: summary: Migrate operationId: api_session_v1_Migrate tags: - Session description: Migrate a session from an external OIDC compliant endpoint. Stytch will call the external UserInfo endpoint defined in your Stytch Project settings in the [Dashboard](https://stytch.com/dashboard), and then perform a lookup using the `session_token`. If the response contains a valid email address, Stytch will attempt to match that email address with an existing User and create a Stytch Session. You will need to create the user before using this endpoint. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_session_v1_MigrateRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_MigrateResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/sessions/migrate\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n};\n\nclient.Sessions.Migrate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/sessions/migrate\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/stytchapi\"\n)\n\nfunc main() {\n\tclient, err := stytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.MigrateParams{\n\t\tSessionToken: \"${sessionToken}\",\n\t}\n\n\tresp, err := client.Sessions.Migrate(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/sessions/migrate\npackage com.example;\n\nimport com.stytch.java.common.StytchResult;\nimport com.stytch.java.consumer.models.sessions.MigrateRequest;\nimport com.stytch.java.consumer.StytchClient;\n\npublic class Main {\n public static void main(String[] args) {\n StytchClient.configure(\"${projectId}\", \"${secret}\");\n\n MigrateRequest params = new MigrateRequest();\n params.setSessionToken(\"${sessionToken}\");\n\n Object result = StytchClient.getSessions().migrate(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/sessions/migrate\npackage com.example\n\nimport com.stytch.java.consumer.StytchClient\nimport com.stytch.java.consumer.models.sessions.MigrateRequest\n\nfun main() {\n StytchClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchClient.sessions.migrate(\n MigrateRequest(\n sessionToken = \"${sessionToken}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/sessions/migrate\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n session_token: \"${sessionToken}\",\n};\n\nclient.sessions.migrate(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->migrate([\n 'session_token' => '${sessionToken}',\n]);" - lang: python label: Python source: "# POST /v1/sessions/migrate\nfrom stytch import Client\n\nclient = Client(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.migrate(\n session_token=\"${sessionToken}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/sessions/migrate\nrequire 'stytch'\n\nclient = Stytch::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.migrate(\n session_token: \"${sessionToken}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/sessions/migrate\nuse stytch::consumer::client::Client;\nuse stytch::consumer::sessions::MigrateRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.migrate(\n MigrateRequest{\n session_token: \"${sessionToken}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/sessions/migrate\ncurl --request POST \\\n --url https://test.stytch.com/v1/sessions/migrate \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"session_token\": \"${sessionToken}\"\n }'" /v1/sessions/exchange_access_token: post: summary: Exchangeaccesstoken operationId: api_session_v1_ExchangeAccessToken tags: - Session description: "Use this endpoint to exchange a Connected Apps Access Token back into a Stytch Session for the underlying User. \nThis session can be used with the Stytch SDKs and APIs.\n\nThe Access Token must contain the `full_access` scope (only available to First Party clients) and must not be more than 5 minutes old. Access Tokens may only be exchanged a single time." requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_session_v1_ExchangeAccessTokenRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_ExchangeAccessTokenResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/sessions/exchange_access_token\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n access_token: \"${sessionJwt}\",\n};\n\nclient.Sessions.ExchangeAccessToken(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/sessions/exchange_access_token\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/stytchapi\"\n)\n\nfunc main() {\n\tclient, err := stytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.ExchangeAccessTokenParams{\n\t\tAccessToken: \"${sessionJwt}\",\n\t}\n\n\tresp, err := client.Sessions.ExchangeAccessToken(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/sessions/exchange_access_token\npackage com.example;\n\nimport com.stytch.java.common.StytchResult;\nimport com.stytch.java.consumer.models.sessions.ExchangeAccessTokenRequest;\nimport com.stytch.java.consumer.StytchClient;\n\npublic class Main {\n public static void main(String[] args) {\n StytchClient.configure(\"${projectId}\", \"${secret}\");\n\n ExchangeAccessTokenRequest params = new ExchangeAccessTokenRequest();\n params.setAccessToken(\"${sessionJwt}\");\n\n Object result = StytchClient.getSessions().exchangeAccessToken(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/sessions/exchange_access_token\npackage com.example\n\nimport com.stytch.java.consumer.StytchClient\nimport com.stytch.java.consumer.models.sessions.ExchangeAccessTokenRequest\n\nfun main() {\n StytchClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchClient.sessions.exchangeAccessToken(\n ExchangeAccessTokenRequest(\n accessToken = \"${sessionJwt}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/sessions/exchange_access_token\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n access_token: \"${sessionJwt}\",\n};\n\nclient.sessions.exchangeAccessToken(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->exchange_access_token([\n 'access_token' => '${sessionJwt}',\n]);" - lang: python label: Python source: "# POST /v1/sessions/exchange_access_token\nfrom stytch import Client\n\nclient = Client(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.exchange_access_token(\n access_token=\"${sessionJwt}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/sessions/exchange_access_token\nrequire 'stytch'\n\nclient = Stytch::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.exchange_access_token(\n access_token: \"${sessionJwt}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/sessions/exchange_access_token\nuse stytch::consumer::client::Client;\nuse stytch::consumer::sessions::ExchangeAccessTokenRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.exchange_access_token(\n ExchangeAccessTokenRequest{\n access_token: \"${sessionJwt}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/sessions/exchange_access_token\ncurl --request POST \\\n --url https://test.stytch.com/v1/sessions/exchange_access_token \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"access_token\": \"${sessionJwt}\"\n }'" /v1/sessions/jwks/{project_id}: get: summary: Getjwks operationId: api_session_v1_GetJWKS tags: - Session description: 'Get the JSON Web Key Set (JWKS) for a project. Within the JWKS, the JSON Web Keys are rotated every ~6 months. Upon rotation, new JWTs will be signed using the new key, and both keys will be returned by this endpoint for a period of 1 month. JWTs have a set lifetime of 5 minutes, so there will be a 5 minute period where some JWTs will be signed by the old keys, and some JWTs will be signed by the new keys. The correct key to use for validation is determined by matching the `kid` value of the JWT and key. If you''re using one of our [backend SDKs](https://stytch.com/docs/b2b/sdks), the JSON Web Key (JWK) rotation will be handled for you. If you''re using your own JWT validation library, many have built-in support for JWK rotation, and you''ll just need to supply this API endpoint. If not, your application should decide which JWK to use for validation by inspecting the `kid` value. See our [How to use Stytch Session JWTs](https://stytch.com/docs/guides/sessions/using-jwts) guide for more information.' parameters: - name: project_id in: path required: true schema: type: string description: The `project_id` to get the JWKS for. description: The `project_id` to get the JWKS for. responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_GetJWKSResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// GET /v1/sessions/jwks/{project_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n project_id: \"${projectId}\",\n};\n\nclient.Sessions.GetJWKS(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// GET /v1/sessions/jwks/{project_id}\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/stytchapi\"\n)\n\nfunc main() {\n\tclient, err := stytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.GetJWKSParams{\n\t\tProjectID: \"${projectId}\",\n\t}\n\n\tresp, err := client.Sessions.GetJWKS(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// GET /v1/sessions/jwks/{project_id}\npackage com.example;\n\nimport com.stytch.java.common.StytchResult;\nimport com.stytch.java.consumer.models.sessions.GetJWKSRequest;\nimport com.stytch.java.consumer.StytchClient;\n\npublic class Main {\n public static void main(String[] args) {\n StytchClient.configure(\"${projectId}\", \"${secret}\");\n\n GetJWKSRequest params = new GetJWKSRequest();\n params.setProjectId(\"${projectId}\");\n\n Object result = StytchClient.getSessions().getJWKS(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// GET /v1/sessions/jwks/{project_id}\npackage com.example\n\nimport com.stytch.java.consumer.StytchClient\nimport com.stytch.java.consumer.models.sessions.GetJWKSRequest\n\nfun main() {\n StytchClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchClient.sessions.getJWKS(\n GetJWKSRequest(\n projectId = \"${projectId}\",\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// GET /v1/sessions/jwks/{project_id}\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n project_id: \"${projectId}\",\n};\n\nclient.sessions.getJWKS(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->get_jwks([\n 'project_id' => '${projectId}',\n]);" - lang: python label: Python source: "# GET /v1/sessions/jwks/{project_id}\nfrom stytch import Client\n\nclient = Client(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.get_jwks(\n project_id=\"${projectId}\",\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# GET /v1/sessions/jwks/{project_id}\nrequire 'stytch'\n\nclient = Stytch::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.get_jwks(\n project_id: \"${projectId}\"\n \n)\n\nputs resp" - lang: rust label: Rust source: "// GET /v1/sessions/jwks/{project_id}\nuse stytch::consumer::client::Client;\nuse stytch::consumer::sessions::GetJWKSRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.get_jwks(\n GetJWKSRequest{\n project_id: \"${projectId}\",\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# GET /v1/sessions/jwks/{project_id}\ncurl --request GET \\\n --url https://test.stytch.com/v1/sessions/jwks/${projectId} \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json'" /v1/sessions/attest: post: summary: Attest operationId: api_session_v1_Attest tags: - Session description: Exchange an auth token issued by a trusted identity provider for a Stytch session. You must first register a Trusted Auth Token profile in the Stytch dashboard [here](https://stytch.com/dashboard/trusted-auth-tokens). If a session token or session JWT is provided, it will add the trusted auth token as an authentication factor to the existing session. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/api_session_v1_AttestRequest' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/api_session_v1_AttestResponse' '400': description: Bad request '401': description: Unauthorized content: application/json: example: status_code: 401 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: unauthorized_credentials error_message: Unauthorized credentials. error_url: https://stytch.com/docs/api/errors/401 '429': description: Too Many Requests content: application/json: example: status_code: 429 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: too_many_requests error_message: Too many requests have been made. error_url: https://stytch.com/docs/api/errors/429 '500': description: Internal server error content: application/json: example: status_code: 500 request_id: request-id-test-b05c992f-ebdc-489d-a754-c7e70ba13141 error_type: internal_server_error error_message: Oops, something seems to have gone wrong, please reach out to support@stytch.com to let us know what went wrong. error_url: https://stytch.com/docs/api/errors/500 x-code-samples: - lang: csharp label: C# source: "// POST /v1/sessions/attest\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n session_duration_minutes: 60,\n};\n\nclient.Sessions.Attest(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: go label: Go source: "// POST /v1/sessions/attest\npackage main\n\nimport (\n\t\"context\"\n\t\"log\"\n\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/sessions\"\n\t\"github.com/stytchauth/stytch-go/v17/stytch/consumer/stytchapi\"\n)\n\nfunc main() {\n\tclient, err := stytchapi.NewClient(\n\t\t\"${projectId}\",\n\t\t\"${secret}\",\n\t)\n\tif err != nil {\n\t\tlog.Fatalf(\"error instantiating client: %v\", err)\n\t}\n\n\tparams := &sessions.AttestParams{\n\t\tProfileID: \"${profileId}\",\n\t\tToken: \"${trustedAuthToken}\",\n\t\tSessionDurationMinutes: 60,\n\t}\n\n\tresp, err := client.Sessions.Attest(context.Background(), params)\n\tif err != nil {\n\t\tlog.Fatalf(\"error in method call: %v\", err)\n\t}\n\n\tlog.Println(resp)\n}\n" - lang: java label: Java source: "// POST /v1/sessions/attest\npackage com.example;\n\nimport com.stytch.java.common.StytchResult;\nimport com.stytch.java.consumer.models.sessions.AttestRequest;\nimport com.stytch.java.consumer.StytchClient;\n\npublic class Main {\n public static void main(String[] args) {\n StytchClient.configure(\"${projectId}\", \"${secret}\");\n\n AttestRequest params = new AttestRequest();\n params.setProfileId(\"${profileId}\");\n params.setToken(\"${trustedAuthToken}\");\n params.setSessionDurationMinutes(60);\n\n Object result = StytchClient.getSessions().attest(params);\n if (result instanceof StytchResult.Success) {\n System.out.println(((StytchResult.Success) result).getValue());\n } else {\n System.out.println(((StytchResult.Error) result).getException());\n }\n }\n}" - lang: kotlin label: Kotlin source: "// POST /v1/sessions/attest\npackage com.example\n\nimport com.stytch.java.consumer.StytchClient\nimport com.stytch.java.consumer.models.sessions.AttestRequest\n\nfun main() {\n StytchClient.configure(\n projectId = \"${projectId}\",\n secret = \"${secret}\",\n )\n\n when (\n val result =\n StytchClient.sessions.attest(\n AttestRequest(\n profileId = \"${profileId}\",\n token = \"${trustedAuthToken}\",\n sessionDurationMinutes = 60,\n ),\n )\n ) {\n is StytchResult.Success -> println(result.value)\n is StytchResult.Error -> println(result.exception)\n }\n}\n" - lang: javascript label: Node.js source: "// POST /v1/sessions/attest\nconst stytch = require('stytch');\n\nconst client = new stytch.Client({\n project_id: '${projectId}',\n secret: '${secret}',\n});\n\nconst params = {\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n session_duration_minutes: 60,\n};\n\nclient.sessions.attest(params)\n .then(resp => { console.log(resp) })\n .catch(err => { console.log(err) });" - lang: php label: PHP source: "$response = $client->sessions->attest([\n 'profile_id' => '${profileId}',\n 'token' => '${trustedAuthToken}',\n 'session_duration_minutes' => 60,\n]);" - lang: python label: Python source: "# POST /v1/sessions/attest\nfrom stytch import Client\n\nclient = Client(\n project_id=\"${projectId}\",\n secret=\"${secret}\",\n)\n\nresp = client.sessions.attest(\n profile_id=\"${profileId}\",\n token=\"${trustedAuthToken}\",\n session_duration_minutes=60,\n)\n\nprint(resp)\n" - lang: ruby label: Ruby source: "# POST /v1/sessions/attest\nrequire 'stytch'\n\nclient = Stytch::Client.new(\n project_id: \"${projectId}\",\n secret: \"${secret}\"\n)\n\nresp = client.sessions.attest(\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n session_duration_minutes: 60\n \n)\n\nputs resp" - lang: rust label: Rust source: "// POST /v1/sessions/attest\nuse stytch::consumer::client::Client;\nuse stytch::consumer::sessions::AttestRequest;\n\nfn main() {\n let client = Client::new(\"${projectId}\", \"${secret}\").unwrap();\n let resp = client.sessions.attest(\n AttestRequest{\n profile_id: \"${profileId}\",\n token: \"${trustedAuthToken}\",\n session_duration_minutes: 60,\n ..Default::default()\n }\n ).await;\n println!(\"The response is {:?}\", resp);\n}" - lang: bash label: cURL source: "# POST /v1/sessions/attest\ncurl --request POST \\\n --url https://test.stytch.com/v1/sessions/attest \\\n -u '${projectId}:${secret}' \\\n -H 'Content-Type: application/json' \\\n -d '{\n \"profile_id\": \"${profileId}\",\n \"token\": \"${trustedAuthToken}\",\n \"session_duration_minutes\": 60\n }'" components: schemas: api_session_v1_SlackOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_session_v1_HubspotOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_session_v1_RevokeRequest: type: object properties: session_id: type: string description: The `session_id` to revoke. session_token: type: string description: The session token to revoke. session_jwt: type: string description: A JWT for the session to revoke. description: Request type api_b2b_session_v1_GetJWKSResponse: type: object properties: keys: type: array items: $ref: '#/components/schemas/api_session_v1_JWK' description: The list of JWKs associated with the project. request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - keys - request_id - status_code api_session_v1_DiscordOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_MigrateRequest: type: object properties: session_token: type: string description: The authorization token Stytch will pass in to the external userinfo endpoint. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will not be created." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To delete a key, supply a null value.\n\n Custom claims made with reserved claims (\"iss\", \"sub\", \"aud\", \"exp\", \"nbf\", \"iat\", \"jti\") will be ignored. Total custom claims size cannot exceed four kilobytes." telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the User. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - session_token api_session_v1_SalesforceOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_user_v1_TOTP: type: object properties: totp_id: type: string description: The unique ID for a TOTP instance. verified: type: boolean description: The verified boolean denotes whether or not this send method, e.g. phone number, email address, etc., has been successfully authenticated by the User. required: - totp_id - verified api_b2b_session_v1_MigrateRequest: type: object properties: session_token: type: string description: The authorization token Stytch will pass in to the external userinfo endpoint. organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration. If you don't want\n to use the Stytch session product, you can ignore the session fields in the response." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in\n `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To\n delete a key, supply a null value. Custom claims made with reserved claims (`iss`, `sub`, `aud`, `exp`, `nbf`, `iat`, `jti`) will be ignored.\n Total custom claims size cannot exceed four kilobytes." description: Request type required: - session_token - organization_id api_b2b_session_v1_PrimaryRequired: type: object properties: allowed_auth_methods: type: array items: type: string description: Details the auth method that the member must also complete to fulfill the primary authentication requirements of the Organization. For example, a value of `[magic_link]` indicates that the Member must also complete a magic link authentication step. If you have an intermediate session token, you must pass it into that primary authentication step. required: - allowed_auth_methods api_b2b_mfa_v1_MemberOptions: type: object properties: mfa_phone_number: type: string description: The Member's MFA phone number. totp_registration_id: type: string description: The Member's MFA TOTP registration ID. required: - mfa_phone_number - totp_registration_id api_b2b_session_v1_AuthorizationCheck: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The Organization's ID must match the Member's Organization resource_id: type: string description: "A unique identifier of the RBAC Resource, provided by the developer and intended to be human-readable.\n\n A `resource_id` is not allowed to start with `stytch`, which is a special prefix used for Stytch default Resources with reserved `resource_id`s. These include:\n\n * `stytch.organization`\n * `stytch.member`\n * `stytch.sso`\n * `stytch.self`\n\n Check out the [guide on Stytch default Resources](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " action: type: string description: An action to take on a Resource. required: - organization_id - resource_id - action api_session_v1_SAMLSSOFactor: type: object properties: id: type: string description: The unique ID of an SSO Registration. provider_id: type: string description: Globally unique UUID that identifies a specific SAML Connection. external_id: type: string description: The ID of the member given by the identity provider. required: - id - provider_id - external_id api_organization_v1_CustomRole: type: object properties: role_id: type: string description: type: string permissions: type: array items: $ref: '#/components/schemas/api_organization_v1_CustomRolePermission' required: - role_id - description - permissions api_session_v1_ImpersonatedFactor: type: object properties: impersonator_id: type: string description: For impersonated sessions initiated via the Stytch Dashboard, the `impersonator_id` will be the impersonator's Stytch Dashboard `member_id`. impersonator_email_address: type: string description: The email address of the impersonator. required: - impersonator_id - impersonator_email_address api_session_v1_TikTokOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_CoinbaseOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_user_v1_OAuthProvider: type: object properties: provider_type: type: string description: Denotes the OAuth identity provider that the user has authenticated with, e.g. Google, Facebook, GitHub etc. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the "sub" or "Subject field" in OAuth protocols. profile_picture_url: type: string description: If available, the `profile_picture_url` is a url of the User's profile picture set in OAuth identity the provider that the User has authenticated with, e.g. Facebook profile picture. locale: type: string description: If available, the `locale` is the User's locale set in the OAuth identity provider that the user has authenticated with. oauth_user_registration_id: type: string description: The unique ID for an OAuth registration. required: - provider_type - provider_subject - profile_picture_url - locale - oauth_user_registration_id api_b2b_session_v1_AuthorizationVerdict: type: object properties: authorized: type: boolean description: Whether the Member was authorized to perform the specified action on the specified Resource. Always true if the request succeeds. granting_roles: type: array items: type: string description: The complete list of Roles that gave the Member permission to perform the specified action on the specified Resource. required: - authorized - granting_roles api_b2b_session_v1_AuthenticateResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_session: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: The [Session object](https://stytch.com/docs/b2b/api/session-object). session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. member: $ref: '#/components/schemas/api_organization_v1_Member' description: The [Member object](https://stytch.com/docs/b2b/api/member-object) organization: $ref: '#/components/schemas/api_organization_v1_Organization' description: The [Organization object](https://stytch.com/docs/b2b/api/organization-object). status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. verdict: $ref: '#/components/schemas/api_b2b_session_v1_AuthorizationVerdict' description: "If an `authorization_check` is provided in the request and the check succeeds, this field will return\n information about why the Member was granted permission." required: - request_id - member_session - session_token - session_jwt - member - organization - status_code api_b2b_mfa_v1_MfaRequired: type: object properties: member_options: $ref: '#/components/schemas/api_b2b_mfa_v1_MemberOptions' description: Information about the Member's options for completing MFA. secondary_auth_initiated: type: string description: If null, indicates that no secondary authentication has been initiated. If equal to "sms_otp", indicates that the Member has a phone number, and a one time passcode has been sent to the Member's phone number. No secondary authentication will be initiated during calls to the discovery authenticate or list organizations endpoints, even if the Member has a phone number. api_organization_v1_SSORegistration: type: object properties: connection_id: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. external_id: type: string description: The ID of the member given by the identity provider. registration_id: type: string description: The unique ID of an SSO Registration. sso_attributes: type: object additionalProperties: true description: An object for storing SSO attributes brought over from the identity provider. required: - connection_id - external_id - registration_id api_organization_v1_RetiredEmail: type: object properties: email_id: type: string description: The globally unique UUID of a Member's email. email_address: type: string description: The email address of the Member. required: - email_id - email_address api_b2b_session_v1_AttestResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_id: type: string description: Globally unique UUID that identifies a specific Member. member_session: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: The [Session object](https://stytch.com/docs/b2b/api/session-object). session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. member: $ref: '#/components/schemas/api_organization_v1_Member' description: The [Member object](https://stytch.com/docs/b2b/api/member-object) organization: $ref: '#/components/schemas/api_organization_v1_Organization' description: The [Organization object](https://stytch.com/docs/b2b/api/organization-object). status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. member_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `member_device` response field will contain information about the member's device attributes. required: - request_id - member_id - member_session - session_token - session_jwt - member - organization - status_code api_session_v1_AuthenticateRequest: type: object properties: session_token: type: string description: The session token to authenticate. session_duration_minutes: type: integer format: int32 description: Set the session lifetime to be this many minutes from now; minimum of 5 and a maximum of 527040 minutes (366 days). Note that a successful authentication will continue to extend the session this many minutes. session_jwt: type: string description: The JWT to authenticate. You may provide a JWT that has expired according to its `exp` claim and needs to be refreshed. If the signature is valid and the underlying session is still active then Stytch will return a new JWT. session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To delete a key, supply a null value.\n\n Custom claims made with reserved claims (\"iss\", \"sub\", \"aud\", \"exp\", \"nbf\", \"iat\", \"jti\") will be ignored. Total custom claims size cannot exceed four kilobytes." authorization_check: $ref: '#/components/schemas/api_session_v1_AuthorizationCheck' description: "If an `authorization_check` object is passed in, this endpoint will also check if the User is\n authorized to perform the given action on the given Resource. A User is authorized if they are assigned a Role with adequate permissions.\n\n If the User is not authorized to perform the specified action on the specified Resource, a 403 error will be thrown.\n Otherwise, the response will contain a list of Roles that satisfied the authorization check." description: Request type api_organization_v1_MemberRole: type: object properties: role_id: type: string description: "The unique identifier of the RBAC Role, provided by the developer and intended to be human-readable.\n\n Reserved `role_id`s that are predefined by Stytch include:\n\n * `stytch_member`\n * `stytch_admin`\n\n Check out the [guide on Stytch default Roles](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " sources: type: array items: $ref: '#/components/schemas/api_organization_v1_MemberRoleSource' description: A list of sources for this role assignment. A role assignment can come from multiple sources - for example, the Role could be both explicitly assigned and implicitly granted from the Member's email domain. required: - role_id - sources api_session_v1_AuthorizationCheck: type: object properties: resource_id: type: string description: "A unique identifier of the RBAC Resource, provided by the developer and intended to be human-readable.\n\n A `resource_id` is not allowed to start with `stytch`, which is a special prefix used for Stytch default Resources with reserved `resource_id`s.\n " action: type: string description: An action to take on a Resource. required: - resource_id - action api_session_v1_EmbeddableMagicLinkFactor: type: object properties: embedded_id: type: string required: - embedded_id api_b2b_scim_v1_SCIMAttributes: type: object properties: user_name: type: string id: type: string external_id: type: string active: type: boolean groups: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Group' display_name: type: string nick_name: type: string profile_url: type: string user_type: type: string title: type: string preferred_language: type: string locale: type: string timezone: type: string emails: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Email' phone_numbers: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_PhoneNumber' addresses: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Address' ims: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_IMs' photos: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Photo' entitlements: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Entitlement' roles: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_Role' x509certificates: type: array items: $ref: '#/components/schemas/api_b2b_scim_v1_X509Certificate' name: $ref: '#/components/schemas/api_b2b_scim_v1_Name' enterprise_extension: $ref: '#/components/schemas/api_b2b_scim_v1_EnterpriseExtension' required: - user_name - id - external_id - active - groups - display_name - nick_name - profile_url - user_type - title - preferred_language - locale - timezone - emails - phone_numbers - addresses - ims - photos - entitlements - roles - x509certificates api_b2b_session_v1_MemberSession: type: object properties: member_session_id: type: string description: Globally unique UUID that identifies a specific Session. member_id: type: string description: Globally unique UUID that identifies a specific Member. started_at: type: string description: The timestamp when the Session was created. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. last_accessed_at: type: string description: The timestamp when the Session was last accessed. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. expires_at: type: string description: The timestamp when the Session expires. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. authentication_factors: type: array items: $ref: '#/components/schemas/api_session_v1_AuthenticationFactor' description: An array of different authentication factors that comprise a Session. organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. roles: type: array items: type: string organization_slug: type: string description: 'The unique URL slug of the Organization. The slug only accepts alphanumeric characters and the following reserved characters: `-` `.` `_` `~`. Must be between 2 and 128 characters in length. Wherever an organization_id is expected in a path or request parameter, you may also use the organization_slug as a convenience.' custom_claims: type: object additionalProperties: true description: The custom claims map for a Session. Claims can be added to a session during a Sessions authenticate call. required: - member_session_id - member_id - started_at - last_accessed_at - expires_at - authentication_factors - organization_id - roles - organization_slug api_device_history_v1_DeviceInfo: type: object properties: visitor_id: type: string description: The `visitor_id` (a unique identifier) of the user's device. See the [Device Fingerprinting documentation](https://stytch.com/docs/fraud/guides/device-fingerprinting/fingerprints) for more details on the `visitor_id`. visitor_id_details: $ref: '#/components/schemas/api_device_history_v1_DeviceAttributeDetails' description: Information about the `visitor_id`. ip_address: type: string description: The IP address of the user's device. ip_address_details: $ref: '#/components/schemas/api_device_history_v1_DeviceAttributeDetails' description: Information about the `ip_address`. ip_geo_city: type: string description: The city where the IP address is located. ip_geo_region: type: string description: The region where the IP address is located. ip_geo_country: type: string description: The country code where the IP address is located. ip_geo_country_details: $ref: '#/components/schemas/api_device_history_v1_DeviceAttributeDetails' description: Information about the `ip_geo_country`. required: - visitor_id api_user_v1_BiometricRegistration: type: object properties: biometric_registration_id: type: string description: The unique ID for a biometric registration. verified: type: boolean description: The verified boolean denotes whether or not this send method, e.g. phone number, email address, etc., has been successfully authenticated by the User. required: - biometric_registration_id - verified api_b2b_scim_v1_Entitlement: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_session_v1_BitbucketOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_organization_v1_SCIMRegistration: type: object properties: connection_id: type: string description: The ID of the SCIM connection. registration_id: type: string description: The unique ID of a SCIM Registration. external_id: type: string description: The ID of the member given by the identity provider. scim_attributes: $ref: '#/components/schemas/api_b2b_scim_v1_SCIMAttributes' description: An object for storing SCIM attributes brought over from the identity provider. required: - connection_id - registration_id api_session_v1_YahooOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_TwitterOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_scim_v1_Email: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_organization_v1_Organization: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. organization_name: type: string description: The name of the Organization. Must be between 1 and 128 characters in length. organization_logo_url: type: string description: The image URL of the Organization logo. organization_slug: type: string description: 'The unique URL slug of the Organization. The slug only accepts alphanumeric characters and the following reserved characters: `-` `.` `_` `~`. Must be between 2 and 128 characters in length. Wherever an organization_id is expected in a path or request parameter, you may also use the organization_slug as a convenience.' sso_jit_provisioning: type: string description: "The authentication setting that controls the JIT provisioning of Members when authenticating via SSO. The accepted values are:\n \n `ALL_ALLOWED` – the default setting, new Members will be automatically provisioned upon successful authentication via any of the Organization's `sso_active_connections`.\n \n `RESTRICTED` – only new Members with SSO logins that comply with `sso_jit_provisioning_allowed_connections` can be provisioned upon authentication.\n \n `NOT_ALLOWED` – disable JIT provisioning via SSO.\n " sso_jit_provisioning_allowed_connections: type: array items: type: string description: "An array of `connection_id`s that reference [SAML Connection objects](https://stytch.com/docs/b2b/api/saml-connection-object).\n Only these connections will be allowed to JIT provision Members via SSO when `sso_jit_provisioning` is set to `RESTRICTED`." sso_active_connections: type: array items: $ref: '#/components/schemas/api_organization_v1_ActiveSSOConnection' description: An array of active [SAML Connection references](https://stytch.com/docs/b2b/api/saml-connection-object) or [OIDC Connection references](https://stytch.com/docs/b2b/api/oidc-connection-object). email_allowed_domains: type: array items: type: string description: "An array of email domains that allow invites or JIT provisioning for new Members. This list is enforced when either `email_invites` or `email_jit_provisioning` is set to `RESTRICTED`.\n \n \n Common domains such as `gmail.com` are not allowed. See the [common email domains resource](https://stytch.com/docs/b2b/api/common-email-domains) for the full list." email_jit_provisioning: type: string description: "The authentication setting that controls how a new Member can be provisioned by authenticating via Email Magic Link or OAuth. The accepted values are:\n \n `RESTRICTED` – only new Members with verified emails that comply with `email_allowed_domains` can be provisioned upon authentication via Email Magic Link or OAuth.\n \n `NOT_ALLOWED` – the default setting, disables JIT provisioning via Email Magic Link and OAuth.\n " email_invites: type: string description: "The authentication setting that controls how a new Member can be invited to an organization by email. The accepted values are:\n \n `ALL_ALLOWED` – any new Member can be invited to join via email.\n \n `RESTRICTED` – only new Members with verified emails that comply with `email_allowed_domains` can be invited via email.\n \n `NOT_ALLOWED` – disable email invites.\n " auth_methods: type: string description: "The setting that controls which authentication methods can be used by Members of an Organization. The accepted values are:\n \n `ALL_ALLOWED` – the default setting which allows all authentication methods to be used.\n \n `RESTRICTED` – only methods that comply with `allowed_auth_methods` can be used for authentication. This setting does not apply to Members with `is_breakglass` set to `true`.\n " allowed_auth_methods: type: array items: type: string description: "An array of allowed authentication methods. This list is enforced when `auth_methods` is set to `RESTRICTED`.\n The list's accepted values are: `sso`, `magic_link`, `email_otp`, `password`, `google_oauth`, `microsoft_oauth`, `slack_oauth`, `github_oauth`, and `hubspot_oauth`.\n " mfa_policy: type: string description: "The setting that controls the MFA policy for all Members in the Organization. The accepted values are:\n \n `REQUIRED_FOR_ALL` – All Members within the Organization will be required to complete MFA every time they wish to log in. However, any active Session that existed prior to this setting change will remain valid.\n \n `OPTIONAL` – The default value. The Organization does not require MFA by default for all Members. Members will be required to complete MFA only if their `mfa_enrolled` status is set to true.\n " rbac_email_implicit_role_assignments: type: array items: $ref: '#/components/schemas/api_organization_v1_EmailImplicitRoleAssignment' description: "Implicit role assignments based off of email domains.\n For each domain-Role pair, all Members whose email addresses have the specified email domain will be granted the\n associated Role, regardless of their login method. See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment)\n for more information about role assignment." mfa_methods: type: string description: "The setting that controls which MFA methods can be used by Members of an Organization. The accepted values are:\n \n `ALL_ALLOWED` – the default setting which allows all authentication methods to be used.\n \n `RESTRICTED` – only methods that comply with `allowed_mfa_methods` can be used for authentication. This setting does not apply to Members with `is_breakglass` set to `true`.\n " allowed_mfa_methods: type: array items: type: string description: "An array of allowed MFA authentication methods. This list is enforced when `mfa_methods` is set to `RESTRICTED`.\n The list's accepted values are: `sms_otp` and `totp`.\n " oauth_tenant_jit_provisioning: type: string description: "The authentication setting that controls how a new Member can JIT provision into an organization by tenant. The accepted values are:\n \n `RESTRICTED` – only new Members with tenants in `allowed_oauth_tenants` can JIT provision via tenant.\n \n `NOT_ALLOWED` – the default setting, disables JIT provisioning by OAuth Tenant.\n " claimed_email_domains: type: array items: type: string description: A list of email domains that are claimed by the Organization. first_party_connected_apps_allowed_type: type: string description: "The authentication setting that sets the Organization's policy towards first party Connected Apps. The accepted values are:\n \n `ALL_ALLOWED` – the default setting, any first party Connected App in the Project is permitted for use by Members.\n \n `RESTRICTED` – only first party Connected Apps with IDs in `allowed_first_party_connected_apps` can be used by Members.\n \n `NOT_ALLOWED` – no first party Connected Apps are permitted.\n " allowed_first_party_connected_apps: type: array items: type: string description: An array of first party Connected App IDs that are allowed for the Organization. Only used when the Organization's `first_party_connected_apps_allowed_type` is `RESTRICTED`. third_party_connected_apps_allowed_type: type: string description: "The authentication setting that sets the Organization's policy towards third party Connected Apps. The accepted values are:\n \n `ALL_ALLOWED` – the default setting, any third party Connected App in the Project is permitted for use by Members.\n \n `RESTRICTED` – only third party Connected Apps with IDs in `allowed_first_party_connected_apps` can be used by Members.\n \n `NOT_ALLOWED` – no third party Connected Apps are permitted.\n " allowed_third_party_connected_apps: type: array items: type: string description: An array of third party Connected App IDs that are allowed for the Organization. Only used when the Organization's `third_party_connected_apps_allowed_type` is `RESTRICTED`. custom_roles: type: array items: $ref: '#/components/schemas/api_organization_v1_CustomRole' trusted_metadata: type: object additionalProperties: true description: An arbitrary JSON object for storing application-specific data or identity-provider-specific data. created_at: type: string description: The timestamp of the Organization's creation. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. updated_at: type: string description: The timestamp of when the Organization was last updated. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. organization_external_id: type: string description: A unique identifier for the organization. sso_default_connection_id: type: string description: The default connection used for SSO when there are multiple active connections. scim_active_connection: $ref: '#/components/schemas/api_organization_v1_ActiveSCIMConnection' description: An active [SCIM Connection references](https://stytch.com/docs/b2b/api/scim-connection-object). allowed_oauth_tenants: type: object additionalProperties: true description: A map of allowed OAuth tenants. If this field is not passed in, the Organization will not allow JIT provisioning by OAuth Tenant. Allowed keys are "slack", "hubspot", and "github". required: - organization_id - organization_name - organization_logo_url - organization_slug - sso_jit_provisioning - sso_jit_provisioning_allowed_connections - sso_active_connections - email_allowed_domains - email_jit_provisioning - email_invites - auth_methods - allowed_auth_methods - mfa_policy - rbac_email_implicit_role_assignments - mfa_methods - allowed_mfa_methods - oauth_tenant_jit_provisioning - claimed_email_domains - first_party_connected_apps_allowed_type - allowed_first_party_connected_apps - third_party_connected_apps_allowed_type - allowed_third_party_connected_apps - custom_roles api_session_v1_SpotifyOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_session_v1_MigrateResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_id: type: string description: Globally unique UUID that identifies a specific Member. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. member: $ref: '#/components/schemas/api_organization_v1_Member' description: The [Member object](https://stytch.com/docs/b2b/api/member-object) organization: $ref: '#/components/schemas/api_organization_v1_Organization' description: The [Organization object](https://stytch.com/docs/b2b/api/organization-object). status_code: type: integer format: int32 member_session: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: The [Session object](https://stytch.com/docs/b2b/api/session-object). required: - request_id - member_id - session_token - session_jwt - member - organization - status_code api_user_v1_CryptoWallet: type: object properties: crypto_wallet_id: type: string description: The unique ID for a crypto wallet crypto_wallet_address: type: string description: The actual blockchain address of the User's crypto wallet. crypto_wallet_type: type: string description: The blockchain that the User's crypto wallet operates on, e.g. Ethereum, Solana, etc. verified: type: boolean description: The verified boolean denotes whether or not this send method, e.g. phone number, email address, etc., has been successfully authenticated by the User. required: - crypto_wallet_id - crypto_wallet_address - crypto_wallet_type - verified api_session_v1_GitLabOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_RevokeResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - status_code api_organization_v1_ActiveSSOConnection: type: object properties: connection_id: type: string description: Globally unique UUID that identifies a specific SSO `connection_id` for a Member. display_name: type: string description: A human-readable display name for the connection. identity_provider: type: string required: - connection_id - display_name - identity_provider api_session_v1_AuthenticationFactor: type: object properties: type: $ref: '#/components/schemas/api_session_v1_AuthenticationFactorType' description: "The type of authentication factor. The possible values are: `email_otp`, `impersonated`, `imported`,\n `magic_link`, `oauth`, `otp`, `password`, `recovery_codes`, `sso`, `trusted_auth_token`, or `totp`." delivery_method: $ref: '#/components/schemas/api_session_v1_AuthenticationFactorDeliveryMethod' description: "The method that was used to deliver the authentication factor. The possible values depend on the `type`:\n \n `email_otp` – Only `email`.\n \n `impersonated` – Only `impersonation`.\n \n `imported` – Only `imported_auth0`.\n \n `magic_link` – Only `email`.\n \n `oauth` – The delivery method is determined by the specific OAuth provider used. The possible values are `oauth_google`, `oauth_microsoft`, `oauth_hubspot`, `oauth_slack`, or `oauth_github`.\n \n In addition, you may see an 'exchange' delivery method when a non-email-verifying OAuth factor originally authenticated in one organization is exchanged for a factor in another organization.\n This can happen during authentication flows such as [session exchange](https://stytch.com/docs/b2b/api/exchange-session).\n The non-email-verifying OAuth providers are Hubspot, Slack, and Github.\n Google is also considered non-email-verifying when the HD claim is empty.\n The possible exchange values are `oauth_exchange_google`, `oauth_exchange_hubspot`, `oauth_exchange_slack`, or `oauth_exchange_github`.\n \n The final possible value is `oauth_access_token_exchange`, if this factor came from an [access token exchange flow](https://stytch.com/docs/b2b/api/connected-app-access-token-exchange).\n \n `otp` – Only `sms`.\n \n `password` – Only `knowledge`.\n \n `recovery_codes` – Only `recovery_code`.\n \n `sso` – Either `sso_saml` or `sso_oidc`.\n \n `trusted_auth_token` – Only `trusted_token_exchange`.\n \n `totp` – Only `authenticator_app`.\n " last_authenticated_at: type: string description: The timestamp when the factor was last authenticated. created_at: type: string description: The timestamp when the factor was initially authenticated. updated_at: type: string description: The timestamp when the factor was last updated. email_factor: $ref: '#/components/schemas/api_session_v1_EmailFactor' description: Information about the email factor, if one is present. phone_number_factor: $ref: '#/components/schemas/api_session_v1_PhoneNumberFactor' description: Information about the phone number factor, if one is present. google_oauth_factor: $ref: '#/components/schemas/api_session_v1_GoogleOAuthFactor' description: Information about the Google OAuth factor, if one is present. microsoft_oauth_factor: $ref: '#/components/schemas/api_session_v1_MicrosoftOAuthFactor' description: Information about the Microsoft OAuth factor, if one is present. apple_oauth_factor: $ref: '#/components/schemas/api_session_v1_AppleOAuthFactor' webauthn_factor: $ref: '#/components/schemas/api_session_v1_WebAuthnFactor' authenticator_app_factor: $ref: '#/components/schemas/api_session_v1_AuthenticatorAppFactor' description: Information about the TOTP-backed Authenticator App factor, if one is present. github_oauth_factor: $ref: '#/components/schemas/api_session_v1_GithubOAuthFactor' description: Information about the Github OAuth factor, if one is present. recovery_code_factor: $ref: '#/components/schemas/api_session_v1_RecoveryCodeFactor' facebook_oauth_factor: $ref: '#/components/schemas/api_session_v1_FacebookOAuthFactor' crypto_wallet_factor: $ref: '#/components/schemas/api_session_v1_CryptoWalletFactor' amazon_oauth_factor: $ref: '#/components/schemas/api_session_v1_AmazonOAuthFactor' bitbucket_oauth_factor: $ref: '#/components/schemas/api_session_v1_BitbucketOAuthFactor' coinbase_oauth_factor: $ref: '#/components/schemas/api_session_v1_CoinbaseOAuthFactor' discord_oauth_factor: $ref: '#/components/schemas/api_session_v1_DiscordOAuthFactor' figma_oauth_factor: $ref: '#/components/schemas/api_session_v1_FigmaOAuthFactor' git_lab_oauth_factor: $ref: '#/components/schemas/api_session_v1_GitLabOAuthFactor' instagram_oauth_factor: $ref: '#/components/schemas/api_session_v1_InstagramOAuthFactor' linked_in_oauth_factor: $ref: '#/components/schemas/api_session_v1_LinkedInOAuthFactor' shopify_oauth_factor: $ref: '#/components/schemas/api_session_v1_ShopifyOAuthFactor' slack_oauth_factor: $ref: '#/components/schemas/api_session_v1_SlackOAuthFactor' description: Information about the Slack OAuth factor, if one is present. snapchat_oauth_factor: $ref: '#/components/schemas/api_session_v1_SnapchatOAuthFactor' spotify_oauth_factor: $ref: '#/components/schemas/api_session_v1_SpotifyOAuthFactor' steam_oauth_factor: $ref: '#/components/schemas/api_session_v1_SteamOAuthFactor' tik_tok_oauth_factor: $ref: '#/components/schemas/api_session_v1_TikTokOAuthFactor' twitch_oauth_factor: $ref: '#/components/schemas/api_session_v1_TwitchOAuthFactor' twitter_oauth_factor: $ref: '#/components/schemas/api_session_v1_TwitterOAuthFactor' embeddable_magic_link_factor: $ref: '#/components/schemas/api_session_v1_EmbeddableMagicLinkFactor' biometric_factor: $ref: '#/components/schemas/api_session_v1_BiometricFactor' saml_sso_factor: $ref: '#/components/schemas/api_session_v1_SAMLSSOFactor' description: Information about the SAML SSO factor, if one is present. oidc_sso_factor: $ref: '#/components/schemas/api_session_v1_OIDCSSOFactor' description: Information about the OIDC SSO factor, if one is present. salesforce_oauth_factor: $ref: '#/components/schemas/api_session_v1_SalesforceOAuthFactor' yahoo_oauth_factor: $ref: '#/components/schemas/api_session_v1_YahooOAuthFactor' hubspot_oauth_factor: $ref: '#/components/schemas/api_session_v1_HubspotOAuthFactor' description: Information about the Hubspot OAuth factor, if one is present. slack_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_SlackOAuthExchangeFactor' description: Information about the Slack OAuth Exchange factor, if one is present. hubspot_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_HubspotOAuthExchangeFactor' description: Information about the Hubspot OAuth Exchange factor, if one is present. github_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_GithubOAuthExchangeFactor' description: Information about the Github OAuth Exchange factor, if one is present. google_oauth_exchange_factor: $ref: '#/components/schemas/api_session_v1_GoogleOAuthExchangeFactor' description: Information about the Google OAuth Exchange factor, if one is present. impersonated_factor: $ref: '#/components/schemas/api_session_v1_ImpersonatedFactor' description: Information about the impersonated factor, if one is present. oauth_access_token_exchange_factor: $ref: '#/components/schemas/api_session_v1_OAuthAccessTokenExchangeFactor' description: Information about the access token exchange factor, if one is present. trusted_auth_token_factor: $ref: '#/components/schemas/api_session_v1_TrustedAuthTokenFactor' description: Information about the trusted auth token factor, if one is present. required: - type - delivery_method api_session_v1_PhoneNumberFactor: type: object properties: phone_id: type: string description: The globally unique UUID of the Member's phone number. phone_number: type: string description: The phone number of the Member. required: - phone_id - phone_number api_b2b_scim_v1_Manager: type: object properties: value: type: string ref: type: string display_name: type: string required: - value - ref - display_name api_user_v1_Email: type: object properties: email_id: type: string description: The unique ID of a specific email address. email: type: string description: The email address. verified: type: boolean description: The verified boolean denotes whether or not this send method, e.g. phone number, email address, etc., has been successfully authenticated by the User. required: - email_id - email - verified api_session_v1_RecoveryCodeFactor: type: object properties: totp_recovery_code_id: type: string required: - totp_recovery_code_id api_session_v1_ExchangeAccessTokenResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. user_id: type: string description: The unique ID of the affected User. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. user: $ref: '#/components/schemas/api_user_v1_User' description: The `user` object affected by this API call. See the [Get user endpoint](https://stytch.com/docs/api/get-user) for complete response field details. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. session: $ref: '#/components/schemas/api_session_v1_Session' description: "If you initiate a Session, by including `session_duration_minutes` in your authenticate call, you'll receive a full Session object in the response.\n\n See [Session object](https://stytch.com/docs/api/session-object) for complete response fields.\n " user_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `user_device` response field will contain information about the user's device attributes. required: - request_id - user_id - session_token - session_jwt - user - status_code api_session_v1_HubspotOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_organization_v1_Member: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. member_id: type: string description: Globally unique UUID that identifies a specific Member. The `member_id` is critical to perform operations on a Member, so be sure to preserve this value. You may use an external_id here if one is set for the member. email_address: type: string description: The email address of the Member. status: type: string description: 'The status of the Member. The possible values are: `pending`, `invited`, `active`, or `deleted`.' name: type: string description: The name of the Member. sso_registrations: type: array items: $ref: '#/components/schemas/api_organization_v1_SSORegistration' description: An array of registered [SAML Connection](https://stytch.com/docs/b2b/api/saml-connection-object) or [OIDC Connection](https://stytch.com/docs/b2b/api/oidc-connection-object) objects the Member has authenticated with. is_breakglass: type: boolean description: Identifies the Member as a break glass user - someone who has permissions to authenticate into an Organization by bypassing the Organization's settings. A break glass account is typically used for emergency purposes to gain access outside of normal authentication procedures. Refer to the [Organization object](https://stytch.com/docs/b2b/api/organization-object) and its `auth_methods` and `allowed_auth_methods` fields for more details. member_password_id: type: string description: Globally unique UUID that identifies a Member's password. oauth_registrations: type: array items: $ref: '#/components/schemas/api_organization_v1_OAuthRegistration' description: A list of OAuth registrations for this member. email_address_verified: type: boolean description: Whether or not the Member's email address is verified. mfa_phone_number_verified: type: boolean description: Whether or not the Member's phone number is verified. is_admin: type: boolean description: "Whether or not the Member has the `stytch_admin` Role. This Role is automatically granted to Members\n who create an Organization through the [discovery flow](https://stytch.com/docs/b2b/api/create-organization-via-discovery). See the\n [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for more details on this Role." totp_registration_id: type: string description: Globally unique UUID that identifies a TOTP instance. retired_email_addresses: type: array items: $ref: '#/components/schemas/api_organization_v1_RetiredEmail' description: "\n A list of retired email addresses for this member.\n A previously active email address can be marked as retired in one of two ways:\n - It's replaced with a new primary email address during an explicit Member update.\n - A new email address is surfaced by an OAuth, SAML or OIDC provider. In this case the new email address becomes the\n Member's primary email address and the old primary email address is retired.\n \n A retired email address cannot be used by other Members in the same Organization. However, unlinking retired email\n addresses allows them to be subsequently re-used by other Organization Members. Retired email addresses can be unlinked\n using the [Unlink Retired Email endpoint](https://stytch.com/docs/b2b/api/unlink-retired-member-email).\n " is_locked: type: boolean description: Whether the Member is temporarily locked due to too many failed authentication attempts. See the [User Locking Guide](https://stytch.com/docs/resources/platform/user-locks) for more information. mfa_enrolled: type: boolean description: Sets whether the Member is enrolled in MFA. If true, the Member must complete an MFA step whenever they wish to log in to their Organization. If false, the Member only needs to complete an MFA step if the Organization's MFA policy is set to `REQUIRED_FOR_ALL`. mfa_phone_number: type: string description: The Member's phone number. A Member may only have one phone number. The phone number should be in E.164 format (i.e. +1XXXXXXXXXX). default_mfa_method: type: string description: The Member's default MFA method. This value is used to determine which secondary MFA method to use in the case of multiple methods registered for a Member. The current possible values are `sms_otp` and `totp`. roles: type: array items: $ref: '#/components/schemas/api_organization_v1_MemberRole' description: "Explicit or implicit Roles assigned to this Member, along with details about the role assignment source.\n See the [RBAC guide](https://stytch.com/docs/b2b/guides/rbac/role-assignment) for more information about role assignment." trusted_metadata: type: object additionalProperties: true description: An arbitrary JSON object for storing application-specific data or identity-provider-specific data. untrusted_metadata: type: object additionalProperties: true description: "An arbitrary JSON object of application-specific data. These fields can be edited directly by the\n frontend SDK, and should not be used to store critical information. See the [Metadata resource](https://stytch.com/docs/b2b/api/metadata)\n for complete field behavior details." created_at: type: string description: The timestamp of the Member's creation. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. updated_at: type: string description: The timestamp of when the Member was last updated. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. scim_registration: $ref: '#/components/schemas/api_organization_v1_SCIMRegistration' description: A scim member registration, referencing a [SCIM Connection](https://stytch.com/docs/b2b/api/scim-connection-object) object in use for the Member creation. external_id: type: string description: The ID of the member given by the identity provider. lock_created_at: type: string description: When the member lock was created, if there is one. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. lock_expires_at: type: string description: When the member lock expires, if there is one. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. required: - organization_id - member_id - email_address - status - name - sso_registrations - is_breakglass - member_password_id - oauth_registrations - email_address_verified - mfa_phone_number_verified - is_admin - totp_registration_id - retired_email_addresses - is_locked - mfa_enrolled - mfa_phone_number - default_mfa_method - roles api_b2b_scim_v1_Address: type: object properties: formatted: type: string street_address: type: string locality: type: string region: type: string postal_code: type: string country: type: string type: type: string primary: type: boolean required: - formatted - street_address - locality - region - postal_code - country - type - primary api_user_v1_WebAuthnRegistration: type: object properties: webauthn_registration_id: type: string description: The unique ID for the Passkey or WebAuthn registration. domain: type: string description: The `domain` on which Passkey or WebAuthn registration was started. This will be the domain of your app. user_agent: type: string description: The user agent of the User. verified: type: boolean description: The verified boolean denotes whether or not this send method, e.g. phone number, email address, etc., has been successfully authenticated by the User. authenticator_type: type: string description: The `authenticator_type` string displays the requested authenticator type of the Passkey or WebAuthn device. The two valid types are "platform" and "cross-platform". If no value is present, the Passkey or WebAuthn device was created without an authenticator type preference. name: type: string description: The `name` of the Passkey or WebAuthn registration. required: - webauthn_registration_id - domain - user_agent - verified - authenticator_type - name api_session_v1_BiometricFactor: type: object properties: biometric_registration_id: type: string required: - biometric_registration_id api_b2b_scim_v1_Group: type: object properties: value: type: string display: type: string required: - value - display api_b2b_scim_v1_Photo: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_session_v1_GetJWKSResponse: type: object properties: keys: type: array items: $ref: '#/components/schemas/api_session_v1_JWK' description: The list of JWKs associated with the project. request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - keys - request_id - status_code api_session_v1_TwitchOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_scim_v1_IMs: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_b2b_session_v1_ExchangeAccessTokenRequest: type: object properties: access_token: type: string description: The access token to exchange for a Stytch Session. Must be granted the `full_access` scope. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration. If you don't want\n to use the Stytch session product, you can ignore the session fields in the response." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in\n `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To\n delete a key, supply a null value. Custom claims made with reserved claims (`iss`, `sub`, `aud`, `exp`, `nbf`, `iat`, `jti`) will be ignored.\n Total custom claims size cannot exceed four kilobytes." telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the Member. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - access_token api_organization_v1_MemberRoleSource: type: object properties: type: type: string description: "The type of role assignment. The possible values are:\n \n `direct_assignment` – an explicitly assigned Role.\n\n Directly assigned roles can be updated by passing in the `roles` argument to the\n [Update Member](https://stytch.com/docs/b2b/api/update-member) endpoint.\n \n `email_assignment` – an implicit Role granted by the Member's email domain, regardless of their login method.\n\n Email implicit role assignments can be updated by passing in the `rbac_email_implicit_role_assignments` argument to\n the [Update Organization](https://stytch.com/docs/b2b/api/update-organization) endpoint.\n \n `sso_connection` – an implicit Role granted by the Member's SSO connection. This is currently only available\n for SAML connections and not for OIDC. If the Member has a SAML Member registration with the given connection, this\n role assignment will appear in the list. However, for authorization check purposes (in\n [sessions authenticate](https://stytch.com/docs/b2b/api/authenticate-session) or in any endpoint that enforces RBAC with session\n headers), the Member will only be granted the Role if their session contains an authentication factor with the\n specified SAML connection.\n\n SAML connection implicit role assignments can be updated by passing in the\n `saml_connection_implicit_role_assignments` argument to the\n [Update SAML connection](https://stytch.com/docs/b2b/api/update-saml-connection) endpoint.\n \n `sso_connection_group` – an implicit Role granted by the Member's SSO connection and group. This is currently only\n available for SAML connections and not for OIDC. If the Member has a SAML Member registration with the given\n connection, and belongs to a specific group within the IdP, this role assignment will appear in the list. However,\n for authorization check purposes (in [sessions authenticate](https://stytch.com/docs/b2b/api/authenticate-session) or in any endpoint\n that enforces RBAC with session headers), the Member will only be granted the role if their session contains an\n authentication factor with the specified SAML connection.\n\n SAML group implicit role assignments can be updated by passing in the `saml_group_implicit_role_assignments`\n argument to the [Update SAML connection](https://stytch.com/docs/b2b/api/update-saml-connection) endpoint.\n\n `scim_connection_group` – an implicit Role granted by the Member's SCIM connection and group. If the Member has\n a SCIM Member registration with the given connection, and belongs to a specific group within the IdP, this role assignment will appear in the list.\n\n SCIM group implicit role assignments can be updated by passing in the `scim_group_implicit_role_assignments`\n argument to the [Update SCIM connection](https://stytch.com/docs/b2b/api/update-scim-connection) endpoint.\n " details: type: object additionalProperties: true description: "An object containing additional metadata about the source assignment. The fields will vary depending\n on the role assignment type as follows:\n \n `direct_assignment` – no additional details.\n \n `email_assignment` – will contain the email domain that granted the assignment.\n \n `sso_connection` – will contain the `connection_id` of the SAML connection that granted the assignment.\n \n `sso_connection_group` – will contain the `connection_id` of the SAML connection and the name of the `group`\n that granted the assignment.\n \n `scim_connection_group` – will contain the `connection_id` of the SAML connection and the `group_id`\n that granted the assignment.\n " required: - type api_session_v1_AttestRequest: type: object properties: profile_id: type: string description: The ID of the trusted auth token profile to use for attestation. token: type: string description: The trusted auth token to authenticate. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will not be created." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To delete a key, supply a null value.\n\n Custom claims made with reserved claims (\"iss\", \"sub\", \"aud\", \"exp\", \"nbf\", \"iat\", \"jti\") will be ignored. Total custom claims size cannot exceed four kilobytes." session_token: type: string description: The `session_token` for the session that you wish to add the trusted auth token authentication factor to. session_jwt: type: string description: The `session_jwt` for the session that you wish to add the trusted auth token authentication factor to. telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the User. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - profile_id - token api_session_v1_GetResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. sessions: type: array items: $ref: '#/components/schemas/api_session_v1_Session' description: An array of [Session objects](https://stytch.com/docs/api/session-object). status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - sessions - status_code api_session_v1_AmazonOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_user_v1_Name: type: object properties: first_name: type: string description: The first name of the user. middle_name: type: string description: The middle name(s) of the user. last_name: type: string description: The last name of the user. api_user_v1_PhoneNumber: type: object properties: phone_id: type: string description: The unique ID for the phone number. phone_number: type: string description: The phone number. verified: type: boolean description: The verified boolean denotes whether or not this send method, e.g. phone number, email address, etc., has been successfully authenticated by the User. required: - phone_id - phone_number - verified api_b2b_session_v1_ExchangeAccessTokenResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_id: type: string description: Globally unique UUID that identifies a specific Member. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. member: $ref: '#/components/schemas/api_organization_v1_Member' description: The [Member object](https://stytch.com/docs/b2b/api/member-object) organization: $ref: '#/components/schemas/api_organization_v1_Organization' description: The [Organization object](https://stytch.com/docs/b2b/api/organization-object). status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. member_session: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: The [Session object](https://stytch.com/docs/b2b/api/session-object). member_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `member_device` response field will contain information about the member's device attributes. required: - request_id - member_id - session_token - session_jwt - member - organization - status_code api_b2b_session_v1_AuthenticateRequest: type: object properties: session_token: type: string description: A secret token for a given Stytch Session. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration. If you don't want\n to use the Stytch session product, you can ignore the session fields in the response." session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in\n `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To\n delete a key, supply a null value. Custom claims made with reserved claims (`iss`, `sub`, `aud`, `exp`, `nbf`, `iat`, `jti`) will be ignored.\n Total custom claims size cannot exceed four kilobytes." authorization_check: $ref: '#/components/schemas/api_b2b_session_v1_AuthorizationCheck' description: "If an `authorization_check` object is passed in, this endpoint will also check if the Member is\n authorized to perform the given action on the given Resource in the specified Organization. A Member is authorized if\n their Member Session contains a Role, assigned\n [explicitly or implicitly](https://stytch.com/docs/b2b/guides/rbac/role-assignment), with adequate permissions.\n In addition, the `organization_id` passed in the authorization check must match the Member's Organization.\n\n The Roles on the Member Session may differ from the Roles you see on the Member object - Roles that are implicitly\n assigned by SSO connection or SSO group will only be valid for a Member Session if there is at least one authentication\n factor on the Member Session from the specified SSO connection.\n\n If the Member is not authorized to perform the specified action on the specified Resource, or if the\n `organization_id` does not match the Member's Organization, a 403 error will be thrown.\n Otherwise, the response will contain a list of Roles that satisfied the authorization check." description: Request type api_user_v1_Password: type: object properties: password_id: type: string description: The unique ID of a specific password requires_reset: type: boolean description: Indicates whether this password requires a password reset required: - password_id - requires_reset api_session_v1_CryptoWalletFactor: type: object properties: crypto_wallet_id: type: string crypto_wallet_address: type: string crypto_wallet_type: type: string required: - crypto_wallet_id - crypto_wallet_address - crypto_wallet_type api_session_v1_Session: type: object properties: session_id: type: string description: A unique identifier for a specific Session. user_id: type: string description: The unique ID of the affected User. authentication_factors: type: array items: $ref: '#/components/schemas/api_session_v1_AuthenticationFactor' description: An array of different authentication factors that comprise a Session. roles: type: array items: type: string started_at: type: string description: The timestamp when the Session was created. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. last_accessed_at: type: string description: The timestamp when the Session was last accessed. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. expires_at: type: string description: The timestamp when the Session expires. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. attributes: $ref: '#/components/schemas/api_attribute_v1_Attributes' description: Provided attributes help with fraud detection. custom_claims: type: object additionalProperties: true description: The custom claims map for a Session. Claims can be added to a session during a Sessions authenticate call. required: - session_id - user_id - authentication_factors - roles api_session_v1_OIDCSSOFactor: type: object properties: id: type: string description: The unique ID of an SSO Registration. provider_id: type: string description: Globally unique UUID that identifies a specific OIDC Connection. external_id: type: string description: The ID of the member given by the identity provider. required: - id - provider_id - external_id api_session_v1_GithubOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_session_v1_LinkedInOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_organization_v1_OAuthRegistration: type: object properties: provider_type: type: string description: Denotes the OAuth identity provider that the user has authenticated with, e.g. Google, Microsoft, GitHub etc. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. member_oauth_registration_id: type: string description: The unique ID of an OAuth registration. profile_picture_url: type: string description: If available, the `profile_picture_url` is a URL of the User's profile picture set in OAuth identity the provider that the User has authenticated with, e.g. Google profile picture. locale: type: string description: If available, the `locale` is the Member's locale set in the OAuth identity provider that the user has authenticated with. required: - provider_type - provider_subject - member_oauth_registration_id api_organization_v1_ActiveSCIMConnection: type: object properties: connection_id: type: string description: The ID of the SCIM connection. display_name: type: string description: A human-readable display name for the connection. bearer_token_last_four: type: string bearer_token_expires_at: type: string required: - connection_id - display_name - bearer_token_last_four api_session_v1_GithubOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_b2b_session_v1_GetResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_sessions: type: array items: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: An array of [Session objects](https://stytch.com/docs/b2b/api/session-object). status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - member_sessions - status_code api_session_v1_FacebookOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_session_v1_RevokeResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. required: - request_id - status_code api_session_v1_AuthenticatorAppFactor: type: object properties: totp_id: type: string description: Globally unique UUID that identifies a TOTP instance. required: - totp_id api_session_v1_ExchangeAccessTokenRequest: type: object properties: access_token: type: string description: The access token to exchange for a Stytch Session. Must be granted the `full_access` scope. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will not be created." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To delete a key, supply a null value.\n\n Custom claims made with reserved claims (\"iss\", \"sub\", \"aud\", \"exp\", \"nbf\", \"iat\", \"jti\") will be ignored. Total custom claims size cannot exceed four kilobytes." telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the User. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - access_token api_b2b_session_v1_RevokeRequest: type: object properties: member_session_id: type: string description: Globally unique UUID that identifies a specific Session in the Stytch API. The `member_session_id` is critical to perform operations on an Session, so be sure to preserve this value. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. member_id: type: string description: Globally unique UUID that identifies a specific Member. The `member_id` is critical to perform operations on a Member, so be sure to preserve this value. description: Request type api_b2b_scim_v1_Name: type: object properties: formatted: type: string family_name: type: string given_name: type: string middle_name: type: string honorific_prefix: type: string honorific_suffix: type: string required: - formatted - family_name - given_name - middle_name - honorific_prefix - honorific_suffix api_session_v1_AuthorizationVerdict: type: object properties: authorized: type: boolean description: Whether the User was authorized to perform the specified action on the specified Resource. Always true if the request succeeds. granting_roles: type: array items: type: string description: The complete list of Roles that gave the User permission to perform the specified action on the specified Resource. required: - authorized - granting_roles api_session_v1_EmailFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. email_address: type: string description: The email address of the Member. required: - email_id - email_address api_session_v1_SteamOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_session_v1_ExchangeRequestLocale: type: string enum: - en - es - pt-br - fr - it - de-DE - zh-Hans - ca-ES api_b2b_session_v1_ExchangeResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. member_id: type: string description: Globally unique UUID that identifies a specific Member. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. member: $ref: '#/components/schemas/api_organization_v1_Member' description: The [Member object](https://stytch.com/docs/b2b/api/member-object) organization: $ref: '#/components/schemas/api_organization_v1_Organization' description: The [Organization object](https://stytch.com/docs/b2b/api/organization-object). member_authenticated: type: boolean description: Indicates whether the Member is fully authenticated. If false, the Member needs to complete an MFA step to log in to the Organization. intermediate_session_token: type: string description: The returned Intermediate Session Token contains any Email Magic Link or OAuth factors from the original member session that are valid for the target Organization. If this value is non-empty, the member must complete an MFA step to finish logging in to the Organization. The token can be used with the [OTP SMS Authenticate endpoint](https://stytch.com/docs/b2b/api/authenticate-otp-sms), [TOTP Authenticate endpoint](https://stytch.com/docs/b2b/api/authenticate-totp), or [Recovery Codes Recover endpoint](https://stytch.com/docs/b2b/api/recovery-codes-recover) to complete an MFA flow and log in to the Organization. The token has a default expiry of 10 minutes. It can also be used with the [Exchange Intermediate Session endpoint](https://stytch.com/docs/b2b/api/exchange-intermediate-session) to join a specific Organization that allows the factors represented by the intermediate session token; or the [Create Organization via Discovery endpoint](https://stytch.com/docs/b2b/api/create-organization-via-discovery) to create a new Organization and Member. Intermediate Session Tokens have a default expiry of 10 minutes. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. member_session: $ref: '#/components/schemas/api_b2b_session_v1_MemberSession' description: The [Session object](https://stytch.com/docs/b2b/api/session-object). mfa_required: $ref: '#/components/schemas/api_b2b_mfa_v1_MfaRequired' description: Information about the MFA requirements of the Organization and the Member's options for fulfilling MFA. primary_required: $ref: '#/components/schemas/api_b2b_session_v1_PrimaryRequired' description: Information about the primary authentication requirements of the Organization. member_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `member_device` response field will contain information about the member's device attributes. required: - request_id - member_id - session_token - session_jwt - member - organization - member_authenticated - intermediate_session_token - status_code api_b2b_scim_v1_X509Certificate: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_session_v1_OAuthAccessTokenExchangeFactor: type: object properties: client_id: type: string description: The ID of the Connected App client. required: - client_id api_session_v1_TrustedAuthTokenFactor: type: object properties: token_id: type: string description: The ID of the trusted auth token. required: - token_id api_session_v1_AppleOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_ShopifyOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_attribute_v1_Attributes: type: object properties: ip_address: type: string description: The IP address of the user. user_agent: type: string description: The user agent of the User. api_session_v1_JWK: type: object properties: kty: type: string use: type: string key_ops: type: array items: type: string alg: type: string kid: type: string x5c: type: array items: type: string x5tS256: type: string n: type: string e: type: string required: - kty - use - key_ops - alg - kid - x5c - x5tS256 - n - e api_session_v1_AuthenticationFactorDeliveryMethod: type: string enum: - email - sms - whatsapp - embedded - oauth_google - oauth_microsoft - oauth_apple - webauthn_registration - authenticator_app - oauth_github - recovery_code - oauth_facebook - crypto_wallet - oauth_amazon - oauth_bitbucket - oauth_coinbase - oauth_discord - oauth_figma - oauth_gitlab - oauth_instagram - oauth_linkedin - oauth_shopify - oauth_slack - oauth_snapchat - oauth_spotify - oauth_steam - oauth_tiktok - oauth_twitch - oauth_twitter - knowledge - biometric - sso_saml - sso_oidc - oauth_salesforce - oauth_yahoo - oauth_hubspot - imported_auth0 - oauth_exchange_slack - oauth_exchange_hubspot - oauth_exchange_github - oauth_exchange_google - impersonation - oauth_access_token_exchange - trusted_token_exchange api_session_v1_AuthenticationFactorType: type: string enum: - magic_link - otp - oauth - webauthn - totp - crypto - password - signature_challenge - sso - imported - recovery_codes - email_otp - impersonated - trusted_auth_token api_session_v1_AttestResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. user_id: type: string description: The unique ID of the affected User. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. user: $ref: '#/components/schemas/api_user_v1_User' description: The `user` object affected by this API call. See the [Get user endpoint](https://stytch.com/docs/api/get-user) for complete response field details. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. session: $ref: '#/components/schemas/api_session_v1_Session' description: "If you initiate a Session, by including `session_duration_minutes` in your authenticate call, you'll receive a full Session object in the response.\n\n See [Session object](https://stytch.com/docs/api/session-object) for complete response fields.\n " user_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `user_device` response field will contain information about the user's device attributes. required: - request_id - user_id - session_token - session_jwt - user - status_code api_session_v1_GoogleOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject api_organization_v1_EmailImplicitRoleAssignment: type: object properties: domain: type: string description: Email domain that grants the specified Role. role_id: type: string description: "The unique identifier of the RBAC Role, provided by the developer and intended to be human-readable.\n\n Reserved `role_id`s that are predefined by Stytch include:\n\n * `stytch_member`\n * `stytch_admin`\n\n Check out the [guide on Stytch default Roles](https://stytch.com/docs/b2b/guides/rbac/stytch-default) for a more detailed explanation.\n\n " required: - domain - role_id api_user_v1_User: type: object properties: user_id: type: string description: The unique ID of the affected User. emails: type: array items: $ref: '#/components/schemas/api_user_v1_Email' description: An array of email objects for the User. status: type: string description: The status of the User. The possible values are `pending` and `active`. phone_numbers: type: array items: $ref: '#/components/schemas/api_user_v1_PhoneNumber' description: An array of phone number objects linked to the User. webauthn_registrations: type: array items: $ref: '#/components/schemas/api_user_v1_WebAuthnRegistration' description: An array that contains a list of all Passkey or WebAuthn registrations for a given User in the Stytch API. providers: type: array items: $ref: '#/components/schemas/api_user_v1_OAuthProvider' description: An array of OAuth `provider` objects linked to the User. totps: type: array items: $ref: '#/components/schemas/api_user_v1_TOTP' description: An array containing a list of all TOTP instances for a given User in the Stytch API. crypto_wallets: type: array items: $ref: '#/components/schemas/api_user_v1_CryptoWallet' description: An array contains a list of all crypto wallets for a given User in the Stytch API. biometric_registrations: type: array items: $ref: '#/components/schemas/api_user_v1_BiometricRegistration' description: An array that contains a list of all biometric registrations for a given User in the Stytch API. is_locked: type: boolean description: Whether the User is temporarily locked due to too many failed authentication attempts. See the [User Locking Guide](https://stytch.com/docs/resources/platform/user-locks) for more information. roles: type: array items: type: string description: "Roles assigned to this User.\n See the [RBAC guide](https://stytch.com/docs/guides/rbac/role-assignment) for more information about role assignment." name: $ref: '#/components/schemas/api_user_v1_Name' description: The name of the User. Each field in the `name` object is optional. created_at: type: string description: The timestamp of the User's creation. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. password: $ref: '#/components/schemas/api_user_v1_Password' description: The password object is returned for users with a password. trusted_metadata: type: object additionalProperties: true description: The `trusted_metadata` field contains an arbitrary JSON object of application-specific data. See the [Metadata](https://stytch.com/docs/api/metadata) reference for complete field behavior details. untrusted_metadata: type: object additionalProperties: true description: The `untrusted_metadata` field contains an arbitrary JSON object of application-specific data. Untrusted metadata can be edited by end users directly via the SDK, and **cannot be used to store critical information.** See the [Metadata](https://stytch.com/docs/api/metadata) reference for complete field behavior details. external_id: type: string description: An identifier that can be used in most API calls where a `member_id` is expected. This is a string consisting of alphanumeric, `.`, `_`, `-`, or `|` characters with a maximum length of 128 characters. External IDs must be unique within the project. lock_created_at: type: string description: When the user lock was created, if there is one. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. lock_expires_at: type: string description: When the user lock expires, if there is one. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. required: - user_id - emails - status - phone_numbers - webauthn_registrations - providers - totps - crypto_wallets - biometric_registrations - is_locked - roles api_device_history_v1_DeviceAttributeDetails: type: object properties: is_new: type: boolean description: Whether this `ip_geo_country` has been seen before for this user. first_seen_at: type: string description: When this `ip_geo_country` was first seen for this user. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. last_seen_at: type: string description: When this `ip_geo_country` was last seen for this user. Values conform to the RFC 3339 standard and are expressed in UTC, e.g. `2021-12-29T12:33:09Z`. required: - is_new api_session_v1_FigmaOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_b2b_scim_v1_Role: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_b2b_scim_v1_PhoneNumber: type: object properties: value: type: string type: type: string primary: type: boolean required: - value - type - primary api_session_v1_SnapchatOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_AuthenticateResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. session: $ref: '#/components/schemas/api_session_v1_Session' description: "If you initiate a Session, by including `session_duration_minutes` in your authenticate call, you'll receive a full Session object in the response.\n\n See [Session object](https://stytch.com/docs/api/session-object) for complete response fields.\n " session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. user: $ref: '#/components/schemas/api_user_v1_User' description: The `user` object affected by this API call. See the [Get user endpoint](https://stytch.com/docs/api/get-user) for complete response field details. status_code: type: integer format: int32 description: The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors. verdict: $ref: '#/components/schemas/api_session_v1_AuthorizationVerdict' description: "If an `authorization_check` is provided in the request and the check succeeds, this field will return\n information about why the User was granted permission." required: - request_id - session - session_token - session_jwt - user - status_code api_organization_v1_CustomRolePermission: type: object properties: resource_id: type: string actions: type: array items: type: string required: - resource_id - actions api_b2b_session_v1_ExchangeRequest: type: object properties: organization_id: type: string description: Globally unique UUID that identifies a specific Organization. The `organization_id` is critical to perform operations on an Organization, so be sure to preserve this value. You may also use the organization_slug or organization_external_id here as a convenience. session_token: type: string description: The `session_token` belonging to the member that you wish to associate the email with. session_jwt: type: string description: The `session_jwt` belonging to the member that you wish to associate the email with. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration. If you don't want\n to use the Stytch session product, you can ignore the session fields in the response." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in\n `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To\n delete a key, supply a null value. Custom claims made with reserved claims (`iss`, `sub`, `aud`, `exp`, `nbf`, `iat`, `jti`) will be ignored.\n Total custom claims size cannot exceed four kilobytes." locale: $ref: '#/components/schemas/api_b2b_session_v1_ExchangeRequestLocale' description: 'If the Member needs to complete an MFA step, and the Member has a phone number, this endpoint will pre-emptively send a one-time passcode (OTP) to the Member''s phone number. The locale argument will be used to determine which language to use when sending the passcode. Parameter is an [IETF BCP 47 language tag](https://www.w3.org/International/articles/language-tags/), e.g. `"en"`. Currently supported languages are English (`"en"`), Spanish (`"es"`), and Brazilian Portuguese (`"pt-br"`); if no value is provided, the copy defaults to English. Request support for additional languages [here](https://docs.google.com/forms/d/e/1FAIpQLScZSpAu_m2AmLXRT3F3kap-s_mcV6UTBitYn6CdyWP0-o7YjQ/viewform?usp=sf_link")! ' telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the Member. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - organization_id api_session_v1_InstagramOAuthFactor: type: object properties: id: type: string provider_subject: type: string email_id: type: string required: - id - provider_subject api_session_v1_GoogleOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_session_v1_WebAuthnFactor: type: object properties: webauthn_registration_id: type: string domain: type: string user_agent: type: string required: - webauthn_registration_id - domain api_b2b_scim_v1_EnterpriseExtension: type: object properties: employee_number: type: string cost_center: type: string division: type: string department: type: string organization: type: string manager: $ref: '#/components/schemas/api_b2b_scim_v1_Manager' required: - employee_number - cost_center - division - department - organization api_session_v1_MigrateResponse: type: object properties: request_id: type: string description: Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue. user_id: type: string description: The unique ID of the affected User. session_token: type: string description: A secret token for a given Stytch Session. session_jwt: type: string description: The JSON Web Token (JWT) for a given Stytch Session. user: $ref: '#/components/schemas/api_user_v1_User' description: The `user` object affected by this API call. See the [Get user endpoint](https://stytch.com/docs/api/get-user) for complete response field details. status_code: type: integer format: int32 session: $ref: '#/components/schemas/api_session_v1_Session' description: "If you initiate a Session, by including `session_duration_minutes` in your authenticate call, you'll receive a full Session object in the response.\n\n See [Session object](https://stytch.com/docs/api/session-object) for complete response fields.\n " user_device: $ref: '#/components/schemas/api_device_history_v1_DeviceInfo' description: If a valid `telemetry_id` was passed in the request and the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) returned results, the `user_device` response field will contain information about the user's device attributes. required: - request_id - user_id - session_token - session_jwt - user - status_code api_session_v1_SlackOAuthExchangeFactor: type: object properties: email_id: type: string description: The globally unique UUID of the Member's email. required: - email_id api_b2b_session_v1_AttestRequest: type: object properties: profile_id: type: string description: The ID of the trusted auth token profile to use for attestation. token: type: string description: The trusted auth token to authenticate. The token must have an organization ID claim if JIT provisioning is enabled. organization_id: type: string description: The organization ID that the session should be authenticated in. Must be provided if the trusted auth token does not have an organization ID claim. session_duration_minutes: type: integer format: int32 description: "Set the session lifetime to be this many minutes from now. This will start a new session if one doesn't already exist,\n returning both an opaque `session_token` and `session_jwt` for this session. Remember that the `session_jwt` will have a fixed lifetime of\n five minutes regardless of the underlying session duration, and will need to be refreshed over time.\n\n This value must be a minimum of 5 and a maximum of 527040 minutes (366 days).\n\n If a `session_token` or `session_jwt` is provided then a successful authentication will continue to extend the session this many minutes.\n\n If the `session_duration_minutes` parameter is not specified, a Stytch session will be created with a 60 minute duration. If you don't want\n to use the Stytch session product, you can ignore the session fields in the response." session_custom_claims: type: object additionalProperties: true description: "Add a custom claims map to the Session being authenticated. Claims are only created if a Session is initialized by providing a value in\n `session_duration_minutes`. Claims will be included on the Session object and in the JWT. To update a key in an existing Session, supply a new value. To\n delete a key, supply a null value. Custom claims made with reserved claims (`iss`, `sub`, `aud`, `exp`, `nbf`, `iat`, `jti`) will be ignored.\n Total custom claims size cannot exceed four kilobytes." session_token: type: string description: The `session_token` for the session that you wish to add the trusted auth token authentication factor to. session_jwt: type: string description: The `session_jwt` for the session that you wish to add the trusted auth token authentication factor to. telemetry_id: type: string description: If the `telemetry_id` is passed, as part of this request, Stytch will call the [Fingerprint Lookup API](https://stytch.com/docs/fraud/api/fingerprint-lookup) and store the associated fingerprints and IPGEO information for the Member. Your workspace must be enabled for Device Fingerprinting to use this feature. description: Request type required: - profile_id - token api_session_v1_MicrosoftOAuthFactor: type: object properties: id: type: string description: The unique ID of an OAuth registration. provider_subject: type: string description: The unique identifier for the User within a given OAuth provider. Also commonly called the `sub` or "Subject field" in OAuth protocols. email_id: type: string description: The globally unique UUID of the Member's email. required: - id - provider_subject securitySchemes: basicAuth: type: http scheme: basic