Skip to content
Docs
Sessions

List sessions

List sessions

GET/zones/{zoneId}/sessions

Returns sessions in the specified zone. By default, returns entry sessions (app user sessions with an initiator that are roots or direct children of a root user session). Use include_nested=true to include nested sessions. Can be filtered by session type, status, and user.

Path ParametersExpand Collapse
zoneId: string
Query ParametersExpand Collapse
active: optional "true"
after: optional string

Cursor for forward pagination

minLength1
maxLength255
before: optional string

Cursor for backward pagination

minLength1
maxLength255
"expand[]": optional "total_count" or array of "total_count"
Accepts one of the following:
UnionMember0 = "total_count"
UnionMember1 = array of "total_count"
include_nested: optional "true"

Include nested sessions. When false (default), only returns entry sessions (direct children of root user sessions). When true, returns all sessions with an initiator, including nested sessions.

limit: optional number

Maximum number of items to return

minimum1
maximum100
session_type: optional "user" or "application"
Accepts one of the following:
"user"
"application"
status: optional "active" or "expired" or "revoked"
Accepts one of the following:
"active"
"expired"
"revoked"
user_id: optional string

Filter by user ID

ReturnsExpand Collapse
items: array of Session
Accepts one of the following:
IamUserSessionType = object { session_type, user_id, id, 19 more }

User session type-specific fields

session_type: "user"
user_id: string

User ID

id: optional string

Session ID

Deprecatedactive: optional boolean

Whether the session is currently active (deprecated - use status instead)

Deprecatedapplication: optional Application { id, consent, created_at, 11 more }

An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).

id: string

Unique identifier of the application

Accepts one of the following:
created_at: string

Entity creation timestamp

formatdate-time
dependencies_count: number

Number of resource dependencies

identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this application

owner_type: "platform" or "customer"

Who owns this application. Platform-owned applications cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this application belongs to

description: optional string

Human-readable description

maxLength2048
metadata: optional Metadata { docs_url, icon_url }

Entity metadata

docs_url: optional string

Documentation URL

formaturi
maxLength2048
icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2 }

Protocol-specific configuration

oauth2: optional object { post_logout_redirect_uris, redirect_uris }

OAuth 2.0 protocol configuration

post_logout_redirect_uris: optional array of string

OAuth 2.0 post-logout redirect URIs for this application

redirect_uris: optional array of string

OAuth 2.0 redirect URIs for this application

application_id: optional string

Application ID that initiated this session

authenticated_at: optional string

Date when the session was authenticated

formatdate-time
created_at: optional string

Entity creation timestamp

formatdate-time
expires_at: optional string

Date when session expires

formatdate-time
issuer: optional string

Issuer URL from IdP

formaturi
metadata: optional object { name }

Session metadata

name: string

Name of the initiating application or user agent

organization_id: optional string

Organization that owns this session

parent_id: optional string

Parent session ID for hierarchical sessions (user sessions only). When null, this is a web session - a top-level session initiated directly by a user. When set, this is a child session derived from the parent, used for token refresh or delegation. Application sessions cannot have parents.

provider_id: optional string

Provider ID

session_data: optional map[unknown]

Session claims data (ID token claims for users, application claims for applications)

status: optional "active" or "expired" or "revoked"
Accepts one of the following:
"active"
"expired"
"revoked"
subject: optional string

Subject claim from IdP

updated_at: optional string

Entity update timestamp

formatdate-time
Deprecateduser: optional User { id, created_at, email, 14 more }

An authenticated user entity

id: string

Unique identifier of the user

created_at: string

Entity creation timestamp

formatdate-time
email: string

Email address of the user

formatemail
email_verified: boolean

Whether the email address has been verified

identifier: string

Zone-scoped user identifier. Defaults to the user's Keycard ID. When the provider has user_identifier_claim configured, the value is set from that claim at user creation time.

organization_id: string

Organization that owns this user

status: "active" or "disabled"

Status of the user. Disabled users cannot authenticate.

Accepts one of the following:
"active"
"disabled"
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this user belongs to

authenticated_at: optional string

Date when the user was last authenticated

credentials: optional array of object { created_at, provider_id, type, 4 more } or object { created_at, type, updated_at }

Authentication credentials for this user, each carrying its identity provider for federation credentials. Populated only when expand[]=credentials is set on the listing endpoint.

Accepts one of the following:
IamUserCredentialFederation = object { created_at, provider_id, type, 4 more }

Federation credential: the user authenticates through an identity provider.

created_at: string

Entity creation timestamp

formatdate-time
provider_id: string

ID of the identity provider backing this credential. null when the source provider has been deleted.

type: "federation"
updated_at: string

Entity update timestamp

formatdate-time
issuer: optional string

Issuer identifier of the identity provider.

provider: optional Provider { id, created_at, identifier, 12 more }

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

id: string

Unique identifier of the provider

created_at: string

Entity creation timestamp

formatdate-time
identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this provider

owner_type: "platform" or "customer"

Who owns this provider. Platform-owned providers cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this provider belongs to

client_id: optional string

OAuth 2.0 client identifier

client_secret_set: optional boolean

Indicates whether a client secret is configured

description: optional string

Human-readable description

maxLength2048
metadata: optional object { icon_url }

Provider metadata

icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2, openid }

Protocol-specific configuration

oauth2: optional object { issuer, authorization_endpoint, authorization_parameters, 10 more }

OAuth 2.0 protocol configuration

issuer: string

OIDC issuer URL used for discovery and token validation.

formaturi
authorization_endpoint: optional string
formaturi
authorization_parameters: optional map[string]

Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

authorization_resource_enabled: optional boolean

Whether to include the resource parameter in authorization requests.

authorization_resource_parameter: optional string

The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

code_challenge_methods_supported: optional array of string
jwks_uri: optional string
formaturi
registration_endpoint: optional string
formaturi
scope_parameter: optional string

The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

scope_separator: optional string

The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

scopes_supported: optional array of string
token_endpoint: optional string
formaturi
token_response_access_token_pointer: optional string

Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

openid: optional object { scopes, single_logout_enabled, user_identifier_claim, userinfo_endpoint }

OpenID Connect protocol configuration

scopes: optional array of string

Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).

single_logout_enabled: optional boolean

When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.

user_identifier_claim: optional string

Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.

userinfo_endpoint: optional string
formaturi
type: optional "external" or "keycard-vault" or "keycard-sts"
Accepts one of the following:
"external"
"keycard-vault"
"keycard-sts"
subject: optional string

Subject identifier from the identity provider.

IamUserCredentialPassword = object { created_at, type, updated_at }

Password credential: the user authenticates with email and password. The email lives on the user.

created_at: string

Entity creation timestamp

formatdate-time
type: "password"
updated_at: string

Entity update timestamp

formatdate-time
grant_count: optional number

Delegated-grant count for this user. Populated only when expand[]=grant_count is set on the listing endpoint.

minimum0
issuer: optional string

Issuer identifier of the identity provider

provider_id: optional string

Reference to the identity provider. This field is undefined when the source identity provider is deleted but the user is not deleted.

role_assignments: optional array of object { role_id, role_identifier, role_owner_type, scope }

Role grants for this user within the zone. Populated only when expand[]=role-assignments is set on the listing endpoint.

role_id: string

ID of the assigned role

role_identifier: string

Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

minLength1
maxLength255
role_owner_type: "platform" or "customer"

Owner type of the granted role. Disambiguates roles that share an identifier across owner types.

Accepts one of the following:
"platform"
"customer"
scope: object { id, type }

The resource this grant is scoped to, or null when the grant is unscoped (applies to the owning zone itself).

id: string

The ID of the scoped resource.

type: string

The kind of resource this grant is scoped to (e.g. zone).

session_count: optional number

Session count for this user. Populated only when expand[]=session_count is set on the listing endpoint.

minimum0
subject: optional string

Subject identifier from the identity provider

Deprecateduser_agent: optional UserAgent { id, created_at, identifier, 5 more }

A User Agent represents a user agent (browser, desktop app, CLI tool) that can initiate user sessions via OAuth 2.0 Dynamic Client Registration.

id: string

Unique identifier of the user agent

created_at: string

Entity creation timestamp

formatdate-time
identifier: string

User agent identifier (serves as OAuth client_id). Format: ua:{sha256_hash}

name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this user agent

slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this user agent belongs to

user_agent_id: optional string

User agent ID (browser/client) that initiated this session

zone_id: optional string

Zone this session belongs to

IamApplicationSessionType = object { application_id, issuer, provider_id, 14 more }

Application session type-specific fields

application_id: string

Application ID that initiated this session

issuer: string

Issuer URL from IdP

formaturi
provider_id: string

Provider ID

session_type: "application"
subject: string

Subject claim from IdP

id: optional string

Session ID

Deprecatedactive: optional boolean

Whether the session is currently active (deprecated - use status instead)

Deprecatedapplication: optional Application { id, consent, created_at, 11 more }

An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).

id: string

Unique identifier of the application

Accepts one of the following:
created_at: string

Entity creation timestamp

formatdate-time
dependencies_count: number

Number of resource dependencies

identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this application

owner_type: "platform" or "customer"

Who owns this application. Platform-owned applications cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this application belongs to

description: optional string

Human-readable description

maxLength2048
metadata: optional Metadata { docs_url, icon_url }

Entity metadata

docs_url: optional string

Documentation URL

formaturi
maxLength2048
icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2 }

Protocol-specific configuration

oauth2: optional object { post_logout_redirect_uris, redirect_uris }

OAuth 2.0 protocol configuration

post_logout_redirect_uris: optional array of string

OAuth 2.0 post-logout redirect URIs for this application

redirect_uris: optional array of string

OAuth 2.0 redirect URIs for this application

authenticated_at: optional string

Date when the session was authenticated

formatdate-time
created_at: optional string

Entity creation timestamp

formatdate-time
expires_at: optional string

Date when session expires

formatdate-time
metadata: optional object { name }

Session metadata

name: string

Name of the initiating application or user agent

organization_id: optional string

Organization that owns this session

session_data: optional map[unknown]

Session claims data (ID token claims for users, application claims for applications)

status: optional "active" or "expired" or "revoked"
Accepts one of the following:
"active"
"expired"
"revoked"
updated_at: optional string

Entity update timestamp

formatdate-time
zone_id: optional string

Zone this session belongs to

List sessions

curl https://api.keycard.ai/zones/$ZONE_ID/sessions \
    -H "Authorization: Bearer $KEYCARD_API_API_KEY"
{
  "items": [
    {
      "session_type": "user",
      "user_id": "user_id",
      "id": "id",
      "active": true,
      "application": {
        "id": "id",
        "consent": "implicit",
        "created_at": "2019-12-27T18:11:19.117Z",
        "dependencies_count": 0,
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "description": "description",
        "metadata": {
          "docs_url": "https://example.com",
          "icon_url": "https://example.com"
        },
        "protocols": {
          "oauth2": {
            "post_logout_redirect_uris": [
              "https://example.com"
            ],
            "redirect_uris": [
              "https://example.com"
            ]
          }
        }
      },
      "application_id": "application_id",
      "authenticated_at": "2019-12-27T18:11:19.117Z",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "issuer": "https://example.com",
      "metadata": {
        "name": "name"
      },
      "organization_id": "organization_id",
      "parent_id": "parent_id",
      "provider_id": "provider_id",
      "session_data": {
        "foo": "bar"
      },
      "status": "active",
      "subject": "subject",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "user": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "email": "dev@stainless.com",
        "email_verified": true,
        "identifier": "identifier",
        "organization_id": "organization_id",
        "status": "active",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "authenticated_at": "authenticated_at",
        "credentials": [
          {
            "created_at": "2019-12-27T18:11:19.117Z",
            "provider_id": "provider_id",
            "type": "federation",
            "updated_at": "2019-12-27T18:11:19.117Z",
            "issuer": "issuer",
            "provider": {
              "id": "id",
              "created_at": "2019-12-27T18:11:19.117Z",
              "identifier": "x",
              "name": "x",
              "organization_id": "organization_id",
              "owner_type": "platform",
              "slug": "slug",
              "updated_at": "2019-12-27T18:11:19.117Z",
              "zone_id": "zone_id",
              "client_id": "client_id",
              "client_secret_set": true,
              "description": "description",
              "metadata": {
                "icon_url": "https://example.com"
              },
              "protocols": {
                "oauth2": {
                  "issuer": "https://example.com",
                  "authorization_endpoint": "https://example.com",
                  "authorization_parameters": {
                    "foo": "string"
                  },
                  "authorization_resource_enabled": true,
                  "authorization_resource_parameter": "authorization_resource_parameter",
                  "code_challenge_methods_supported": [
                    "string"
                  ],
                  "jwks_uri": "https://example.com",
                  "registration_endpoint": "https://example.com",
                  "scope_parameter": "scope_parameter",
                  "scope_separator": "scope_separator",
                  "scopes_supported": [
                    "string"
                  ],
                  "token_endpoint": "https://example.com",
                  "token_response_access_token_pointer": "token_response_access_token_pointer"
                },
                "openid": {
                  "scopes": [
                    "string"
                  ],
                  "single_logout_enabled": true,
                  "user_identifier_claim": "user_identifier_claim",
                  "userinfo_endpoint": "https://example.com"
                }
              },
              "type": "external"
            },
            "subject": "subject"
          }
        ],
        "grant_count": 0,
        "issuer": "issuer",
        "provider_id": "provider_id",
        "role_assignments": [
          {
            "role_id": "role_id",
            "role_identifier": "role_identifier",
            "role_owner_type": "platform",
            "scope": {
              "id": "id",
              "type": "type"
            }
          }
        ],
        "session_count": 0,
        "subject": "subject"
      },
      "user_agent": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "identifier",
        "name": "x",
        "organization_id": "organization_id",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id"
      },
      "user_agent_id": "user_agent_id",
      "zone_id": "zone_id"
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}
Returns Examples
{
  "items": [
    {
      "session_type": "user",
      "user_id": "user_id",
      "id": "id",
      "active": true,
      "application": {
        "id": "id",
        "consent": "implicit",
        "created_at": "2019-12-27T18:11:19.117Z",
        "dependencies_count": 0,
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "description": "description",
        "metadata": {
          "docs_url": "https://example.com",
          "icon_url": "https://example.com"
        },
        "protocols": {
          "oauth2": {
            "post_logout_redirect_uris": [
              "https://example.com"
            ],
            "redirect_uris": [
              "https://example.com"
            ]
          }
        }
      },
      "application_id": "application_id",
      "authenticated_at": "2019-12-27T18:11:19.117Z",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "issuer": "https://example.com",
      "metadata": {
        "name": "name"
      },
      "organization_id": "organization_id",
      "parent_id": "parent_id",
      "provider_id": "provider_id",
      "session_data": {
        "foo": "bar"
      },
      "status": "active",
      "subject": "subject",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "user": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "email": "dev@stainless.com",
        "email_verified": true,
        "identifier": "identifier",
        "organization_id": "organization_id",
        "status": "active",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "authenticated_at": "authenticated_at",
        "credentials": [
          {
            "created_at": "2019-12-27T18:11:19.117Z",
            "provider_id": "provider_id",
            "type": "federation",
            "updated_at": "2019-12-27T18:11:19.117Z",
            "issuer": "issuer",
            "provider": {
              "id": "id",
              "created_at": "2019-12-27T18:11:19.117Z",
              "identifier": "x",
              "name": "x",
              "organization_id": "organization_id",
              "owner_type": "platform",
              "slug": "slug",
              "updated_at": "2019-12-27T18:11:19.117Z",
              "zone_id": "zone_id",
              "client_id": "client_id",
              "client_secret_set": true,
              "description": "description",
              "metadata": {
                "icon_url": "https://example.com"
              },
              "protocols": {
                "oauth2": {
                  "issuer": "https://example.com",
                  "authorization_endpoint": "https://example.com",
                  "authorization_parameters": {
                    "foo": "string"
                  },
                  "authorization_resource_enabled": true,
                  "authorization_resource_parameter": "authorization_resource_parameter",
                  "code_challenge_methods_supported": [
                    "string"
                  ],
                  "jwks_uri": "https://example.com",
                  "registration_endpoint": "https://example.com",
                  "scope_parameter": "scope_parameter",
                  "scope_separator": "scope_separator",
                  "scopes_supported": [
                    "string"
                  ],
                  "token_endpoint": "https://example.com",
                  "token_response_access_token_pointer": "token_response_access_token_pointer"
                },
                "openid": {
                  "scopes": [
                    "string"
                  ],
                  "single_logout_enabled": true,
                  "user_identifier_claim": "user_identifier_claim",
                  "userinfo_endpoint": "https://example.com"
                }
              },
              "type": "external"
            },
            "subject": "subject"
          }
        ],
        "grant_count": 0,
        "issuer": "issuer",
        "provider_id": "provider_id",
        "role_assignments": [
          {
            "role_id": "role_id",
            "role_identifier": "role_identifier",
            "role_owner_type": "platform",
            "scope": {
              "id": "id",
              "type": "type"
            }
          }
        ],
        "session_count": 0,
        "subject": "subject"
      },
      "user_agent": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "identifier",
        "name": "x",
        "organization_id": "organization_id",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id"
      },
      "user_agent_id": "user_agent_id",
      "zone_id": "zone_id"
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}