Skip to content
Docs
Sessions

List sessions

List sessions

GET/zones/{zoneId}/sessions

Returns sessions in the specified zone. By default, returns entry sessions (app user sessions with an initiator that are roots or direct children of a root user session). Use include_nested=true to include nested sessions. Can be filtered by session type, status, and user.

Path ParametersExpand Collapse
zoneId: string
Query ParametersExpand Collapse
active: optional "true"
after: optional string

Cursor for forward pagination

minLength1
maxLength255
before: optional string

Cursor for backward pagination

minLength1
maxLength255
"expand[]": optional "total_count" or array of "total_count"
Accepts one of the following:
UnionMember0 = "total_count"
UnionMember1 = array of "total_count"
include_nested: optional "true"

Include nested sessions. When false (default), only returns entry sessions (direct children of root user sessions). When true, returns all sessions with an initiator, including nested sessions.

limit: optional number

Maximum number of items to return

minimum1
maximum100
session_type: optional "user" or "application"
Accepts one of the following:
"user"
"application"
status: optional "active" or "expired" or "revoked"
Accepts one of the following:
"active"
"expired"
"revoked"
user_id: optional string

Filter by user ID

ReturnsExpand Collapse
items: array of Session
Accepts one of the following:
IamUserSessionType = object { session_type, user_id, id, 19 more }

User session type-specific fields

session_type: "user"
user_id: string

User ID

id: optional string

Session ID

Deprecatedactive: optional boolean

Whether the session is currently active (deprecated - use status instead)

Deprecatedapplication: optional Application { id, consent, created_at, 11 more }

An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).

id: string

Unique identifier of the application

Accepts one of the following:
created_at: string

Entity creation timestamp

formatdate-time
dependencies_count: number

Number of resource dependencies

identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this application

owner_type: "platform" or "customer"

Who owns this application. Platform-owned applications cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this application belongs to

description: optional string

Human-readable description

maxLength2048
metadata: optional Metadata { docs_url, icon_url }

Entity metadata

docs_url: optional string

Documentation URL

formaturi
maxLength2048
icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2 }

Protocol-specific configuration

oauth2: optional object { post_logout_redirect_uris, redirect_uris }

OAuth 2.0 protocol configuration

post_logout_redirect_uris: optional array of string

OAuth 2.0 post-logout redirect URIs for this application

redirect_uris: optional array of string

OAuth 2.0 redirect URIs for this application

application_id: optional string

Application ID that initiated this session

authenticated_at: optional string

Date when the session was authenticated

formatdate-time
created_at: optional string

Entity creation timestamp

formatdate-time
expires_at: optional string

Date when session expires

formatdate-time
issuer: optional string

Issuer URL from IdP

formaturi
metadata: optional object { name }

Session metadata

name: string

Name of the initiating application or user agent

organization_id: optional string

Organization that owns this session

parent_id: optional string

Parent session ID for hierarchical sessions (user sessions only). When null, this is a web session - a top-level session initiated directly by a user. When set, this is a child session derived from the parent, used for token refresh or delegation. Application sessions cannot have parents.

provider_id: optional string

Provider ID

session_data: optional map[unknown]

Session claims data (ID token claims for users, application claims for applications)

status: optional "active" or "expired" or "revoked"
Accepts one of the following:
"active"
"expired"
"revoked"
subject: optional string

Subject claim from IdP

updated_at: optional string

Entity update timestamp

formatdate-time
Deprecateduser: optional User { id, created_at, email, 15 more }

An authenticated user entity

id: string

Unique identifier of the user

created_at: string

Entity creation timestamp

formatdate-time
email: string

Email address of the user

formatemail
email_verified: boolean

Whether the email address has been verified

identifier: string

Zone-scoped user identifier. Defaults to the user's Keycard ID. When the provider has user_identifier_claim configured, the value is set from that claim at user creation time.

organization_id: string

Organization that owns this user

status: "active" or "disabled"

Status of the user. Disabled users cannot authenticate.

Accepts one of the following:
"active"
"disabled"
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this user belongs to

authenticated_at: optional string

Date when the user was last authenticated

credentials: optional array of object { created_at, provider_id, type, 4 more } or object { created_at, type, updated_at }

Authentication credentials for this user, each carrying its identity provider for federation credentials. Populated only when expand[]=credentials is set on the listing endpoint.

Accepts one of the following:
IamUserCredentialFederation = object { created_at, provider_id, type, 4 more }

Federation credential: the user authenticates through an identity provider.

created_at: string

Entity creation timestamp

formatdate-time
provider_id: string

ID of the identity provider backing this credential. null when the source provider has been deleted.

type: "federation"
updated_at: string

Entity update timestamp

formatdate-time
issuer: optional string

Issuer identifier of the identity provider.

provider: optional Provider { id, created_at, identifier, 12 more }

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

id: string

Unique identifier of the provider

created_at: string

Entity creation timestamp

formatdate-time
identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this provider

owner_type: "platform" or "customer"

Who owns this provider. Platform-owned providers cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this provider belongs to

client_id: optional string

OAuth 2.0 client identifier

client_secret_set: optional boolean

Indicates whether a client secret is configured

description: optional string

Human-readable description

maxLength2048
metadata: optional object { icon_url }

Provider metadata

icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2, openid }

Protocol-specific configuration

oauth2: optional object { issuer, authorization_endpoint, authorization_parameters, 10 more }

OAuth 2.0 protocol configuration

issuer: string

OIDC issuer URL used for discovery and token validation.

formaturi
authorization_endpoint: optional string
formaturi
authorization_parameters: optional map[string]

Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

authorization_resource_enabled: optional boolean

Whether to include the resource parameter in authorization requests.

authorization_resource_parameter: optional string

The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

code_challenge_methods_supported: optional array of string
jwks_uri: optional string
formaturi
registration_endpoint: optional string
formaturi
scope_parameter: optional string

The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

scope_separator: optional string

The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

scopes_supported: optional array of string
token_endpoint: optional string
formaturi
token_response_access_token_pointer: optional string

Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

openid: optional object { external_id_claim, scopes, single_logout_enabled, 2 more }

OpenID Connect protocol configuration

external_id_claim: optional string

Name of the OIDC claim carrying the stable external id used to correlate logins with externally provisioned (SCIM) users. Defaults to "sub". Set to "oid" for Entra, whose pairwise "sub" differs from the SCIM externalId.

scopes: optional array of string

Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).

single_logout_enabled: optional boolean

When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.

user_identifier_claim: optional string

Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.

userinfo_endpoint: optional string
formaturi
type: optional "external" or "keycard-vault" or "keycard-sts"
Accepts one of the following:
"external"
"keycard-vault"
"keycard-sts"
subject: optional string

Subject identifier from the identity provider.

IamUserCredentialPassword = object { created_at, type, updated_at }

Password credential: the user authenticates with email and password. The email lives on the user.

created_at: string

Entity creation timestamp

formatdate-time
type: "password"
updated_at: string

Entity update timestamp

formatdate-time
grant_count: optional number

Delegated-grant count for this user. Populated only when expand[]=grant_count is set on the listing endpoint.

minimum0
groups: optional array of object { id, identifier, name }

Groups this user belongs to within the zone. Populated only when expand[]=groups is set on the listing endpoint.

id: string

Unique identifier of the group

identifier: string

Zone-unique slug that policy rules match on.

name: string

Human-readable group name

issuer: optional string

Issuer identifier of the identity provider

provider_id: optional string

Reference to the identity provider. This field is undefined when the source identity provider is deleted but the user is not deleted.

role_assignments: optional array of object { role_id, role_identifier, role_owner_type, 3 more }

Role grants for this user within the zone. Populated only when expand[]=role-assignments is set on the listing endpoint.

role_id: string

ID of the assigned role

role_identifier: string

Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

minLength1
maxLength255
role_owner_type: "platform" or "customer"

Owner type of the granted role. Disambiguates roles that share an identifier across owner types.

Accepts one of the following:
"platform"
"customer"
scope: object { id, type }

The resource this grant is scoped to, or null when the grant is unscoped (applies to the owning zone itself).

id: string

The ID of the scoped resource.

type: string

The kind of resource this grant is scoped to (e.g. zone).

source: "user" or "group"

The principal that holds this grant: user when assigned directly to the user, or group when inherited through group membership.

Accepts one of the following:
"user"
"group"
group_id: optional string

ID of the group this grant is inherited from. Present only when source is group.

session_count: optional number

Session count for this user. Populated only when expand[]=session_count is set on the listing endpoint.

minimum0
subject: optional string

Subject identifier from the identity provider

Deprecateduser_agent: optional UserAgent { id, created_at, identifier, 5 more }

A User Agent represents a user agent (browser, desktop app, CLI tool) that can initiate user sessions via OAuth 2.0 Dynamic Client Registration.

id: string

Unique identifier of the user agent

created_at: string

Entity creation timestamp

formatdate-time
identifier: string

User agent identifier (serves as OAuth client_id). Format: ua:{sha256_hash}

name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this user agent

slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this user agent belongs to

user_agent_id: optional string

User agent ID (browser/client) that initiated this session

zone_id: optional string

Zone this session belongs to

IamApplicationSessionType = object { application_id, issuer, provider_id, 14 more }

Application session type-specific fields

application_id: string

Application ID that initiated this session

issuer: string

Issuer URL from IdP

formaturi
provider_id: string

Provider ID

session_type: "application"
subject: string

Subject claim from IdP

id: optional string

Session ID

Deprecatedactive: optional boolean

Whether the session is currently active (deprecated - use status instead)

Deprecatedapplication: optional Application { id, consent, created_at, 11 more }

An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).

id: string

Unique identifier of the application

Accepts one of the following:
created_at: string

Entity creation timestamp

formatdate-time
dependencies_count: number

Number of resource dependencies

identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this application

owner_type: "platform" or "customer"

Who owns this application. Platform-owned applications cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this application belongs to

description: optional string

Human-readable description

maxLength2048
metadata: optional Metadata { docs_url, icon_url }

Entity metadata

docs_url: optional string

Documentation URL

formaturi
maxLength2048
icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2 }

Protocol-specific configuration

oauth2: optional object { post_logout_redirect_uris, redirect_uris }

OAuth 2.0 protocol configuration

post_logout_redirect_uris: optional array of string

OAuth 2.0 post-logout redirect URIs for this application

redirect_uris: optional array of string

OAuth 2.0 redirect URIs for this application

authenticated_at: optional string

Date when the session was authenticated

formatdate-time
created_at: optional string

Entity creation timestamp

formatdate-time
expires_at: optional string

Date when session expires

formatdate-time
metadata: optional object { name }

Session metadata

name: string

Name of the initiating application or user agent

organization_id: optional string

Organization that owns this session

session_data: optional map[unknown]

Session claims data (ID token claims for users, application claims for applications)

status: optional "active" or "expired" or "revoked"
Accepts one of the following:
"active"
"expired"
"revoked"
updated_at: optional string

Entity update timestamp

formatdate-time
zone_id: optional string

Zone this session belongs to

List sessions

curl https://api.keycard.ai/zones/$ZONE_ID/sessions \
    -H "Authorization: Bearer $KEYCARD_API_API_KEY"
{
  "items": [
    {
      "session_type": "user",
      "user_id": "user_id",
      "id": "id",
      "active": true,
      "application": {
        "id": "id",
        "consent": "implicit",
        "created_at": "2019-12-27T18:11:19.117Z",
        "dependencies_count": 0,
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "description": "description",
        "metadata": {
          "docs_url": "https://example.com",
          "icon_url": "https://example.com"
        },
        "protocols": {
          "oauth2": {
            "post_logout_redirect_uris": [
              "https://example.com"
            ],
            "redirect_uris": [
              "https://example.com"
            ]
          }
        }
      },
      "application_id": "application_id",
      "authenticated_at": "2019-12-27T18:11:19.117Z",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "issuer": "https://example.com",
      "metadata": {
        "name": "name"
      },
      "organization_id": "organization_id",
      "parent_id": "parent_id",
      "provider_id": "provider_id",
      "session_data": {
        "foo": "bar"
      },
      "status": "active",
      "subject": "subject",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "user": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "email": "dev@stainless.com",
        "email_verified": true,
        "identifier": "identifier",
        "organization_id": "organization_id",
        "status": "active",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "authenticated_at": "authenticated_at",
        "credentials": [
          {
            "created_at": "2019-12-27T18:11:19.117Z",
            "provider_id": "provider_id",
            "type": "federation",
            "updated_at": "2019-12-27T18:11:19.117Z",
            "issuer": "issuer",
            "provider": {
              "id": "id",
              "created_at": "2019-12-27T18:11:19.117Z",
              "identifier": "x",
              "name": "x",
              "organization_id": "organization_id",
              "owner_type": "platform",
              "slug": "slug",
              "updated_at": "2019-12-27T18:11:19.117Z",
              "zone_id": "zone_id",
              "client_id": "client_id",
              "client_secret_set": true,
              "description": "description",
              "metadata": {
                "icon_url": "https://example.com"
              },
              "protocols": {
                "oauth2": {
                  "issuer": "https://example.com",
                  "authorization_endpoint": "https://example.com",
                  "authorization_parameters": {
                    "foo": "string"
                  },
                  "authorization_resource_enabled": true,
                  "authorization_resource_parameter": "authorization_resource_parameter",
                  "code_challenge_methods_supported": [
                    "string"
                  ],
                  "jwks_uri": "https://example.com",
                  "registration_endpoint": "https://example.com",
                  "scope_parameter": "scope_parameter",
                  "scope_separator": "scope_separator",
                  "scopes_supported": [
                    "string"
                  ],
                  "token_endpoint": "https://example.com",
                  "token_response_access_token_pointer": "token_response_access_token_pointer"
                },
                "openid": {
                  "external_id_claim": "external_id_claim",
                  "scopes": [
                    "string"
                  ],
                  "single_logout_enabled": true,
                  "user_identifier_claim": "user_identifier_claim",
                  "userinfo_endpoint": "https://example.com"
                }
              },
              "type": "external"
            },
            "subject": "subject"
          }
        ],
        "grant_count": 0,
        "groups": [
          {
            "id": "id",
            "identifier": "identifier",
            "name": "name"
          }
        ],
        "issuer": "issuer",
        "provider_id": "provider_id",
        "role_assignments": [
          {
            "role_id": "role_id",
            "role_identifier": "role_identifier",
            "role_owner_type": "platform",
            "scope": {
              "id": "id",
              "type": "type"
            },
            "source": "user",
            "group_id": "group_id"
          }
        ],
        "session_count": 0,
        "subject": "subject"
      },
      "user_agent": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "identifier",
        "name": "x",
        "organization_id": "organization_id",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id"
      },
      "user_agent_id": "user_agent_id",
      "zone_id": "zone_id"
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}
Returns Examples
{
  "items": [
    {
      "session_type": "user",
      "user_id": "user_id",
      "id": "id",
      "active": true,
      "application": {
        "id": "id",
        "consent": "implicit",
        "created_at": "2019-12-27T18:11:19.117Z",
        "dependencies_count": 0,
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "description": "description",
        "metadata": {
          "docs_url": "https://example.com",
          "icon_url": "https://example.com"
        },
        "protocols": {
          "oauth2": {
            "post_logout_redirect_uris": [
              "https://example.com"
            ],
            "redirect_uris": [
              "https://example.com"
            ]
          }
        }
      },
      "application_id": "application_id",
      "authenticated_at": "2019-12-27T18:11:19.117Z",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "issuer": "https://example.com",
      "metadata": {
        "name": "name"
      },
      "organization_id": "organization_id",
      "parent_id": "parent_id",
      "provider_id": "provider_id",
      "session_data": {
        "foo": "bar"
      },
      "status": "active",
      "subject": "subject",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "user": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "email": "dev@stainless.com",
        "email_verified": true,
        "identifier": "identifier",
        "organization_id": "organization_id",
        "status": "active",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "authenticated_at": "authenticated_at",
        "credentials": [
          {
            "created_at": "2019-12-27T18:11:19.117Z",
            "provider_id": "provider_id",
            "type": "federation",
            "updated_at": "2019-12-27T18:11:19.117Z",
            "issuer": "issuer",
            "provider": {
              "id": "id",
              "created_at": "2019-12-27T18:11:19.117Z",
              "identifier": "x",
              "name": "x",
              "organization_id": "organization_id",
              "owner_type": "platform",
              "slug": "slug",
              "updated_at": "2019-12-27T18:11:19.117Z",
              "zone_id": "zone_id",
              "client_id": "client_id",
              "client_secret_set": true,
              "description": "description",
              "metadata": {
                "icon_url": "https://example.com"
              },
              "protocols": {
                "oauth2": {
                  "issuer": "https://example.com",
                  "authorization_endpoint": "https://example.com",
                  "authorization_parameters": {
                    "foo": "string"
                  },
                  "authorization_resource_enabled": true,
                  "authorization_resource_parameter": "authorization_resource_parameter",
                  "code_challenge_methods_supported": [
                    "string"
                  ],
                  "jwks_uri": "https://example.com",
                  "registration_endpoint": "https://example.com",
                  "scope_parameter": "scope_parameter",
                  "scope_separator": "scope_separator",
                  "scopes_supported": [
                    "string"
                  ],
                  "token_endpoint": "https://example.com",
                  "token_response_access_token_pointer": "token_response_access_token_pointer"
                },
                "openid": {
                  "external_id_claim": "external_id_claim",
                  "scopes": [
                    "string"
                  ],
                  "single_logout_enabled": true,
                  "user_identifier_claim": "user_identifier_claim",
                  "userinfo_endpoint": "https://example.com"
                }
              },
              "type": "external"
            },
            "subject": "subject"
          }
        ],
        "grant_count": 0,
        "groups": [
          {
            "id": "id",
            "identifier": "identifier",
            "name": "name"
          }
        ],
        "issuer": "issuer",
        "provider_id": "provider_id",
        "role_assignments": [
          {
            "role_id": "role_id",
            "role_identifier": "role_identifier",
            "role_owner_type": "platform",
            "scope": {
              "id": "id",
              "type": "type"
            },
            "source": "user",
            "group_id": "group_id"
          }
        ],
        "session_count": 0,
        "subject": "subject"
      },
      "user_agent": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "identifier",
        "name": "x",
        "organization_id": "organization_id",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id"
      },
      "user_agent_id": "user_agent_id",
      "zone_id": "zone_id"
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}