Skip to content

How an account is kept safe

GET
/console/users/{id}/security
curl --request GET \
--url https://example.com/console/users/example/security \
--cookie bottle.session_token=<bottle.session_token>

Two-step sign-in and its method, whether there is a password and when it was last set, sessions open, and the last sign-in with its browser and system. Never a secret.

id
required
string
>= 1 characters

Security

Media typeapplication/json
object
twoFactor
required
object
enabled
required
boolean
method
required
string | null
Allowed values: totp otp
since
required
string | null format: date-time
hasPassword
required
boolean
passwordChangedAt
required
string | null format: date-time
activeSessions
required
integer
lastSignInAt
required
string | null format: date-time
lastDevice
required
object
browser
required
string | null
os
required
string | null
app
required
boolean
staffSince
required
string | null format: date-time
staffFromSettings
required
boolean
Example
{
"twoFactor": {
"method": "totp"
}
}

Not signed in

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Not Bottle staff, no two-step sign-in, or a console role too low for this

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

No such person

Media typeapplication/json
object
error
required
string
message
required
string
Example
{
"error": "not_found",
"message": "Customer not found"
}

Validation failed

Media typeapplication/json
object
error
required
string
Allowed values: validation
message
required
string
issues
required
Array<object>
object
path
required
string
message
required
string
Example
{
"error": "validation",
"issues": [
{
"path": "email",
"message": "Invalid email"
}
]
}