Ga naar inhoud

List active sessions

GET
/api/v1/sessions
curl --request GET \
--url https://example.com/api/v1/sessions \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E

Sessions of the UI and of bl: your own, or as admin everyone’s. current marks the session of the request.

OK.

Media typeapplication/json

A page of a list. next_cursor is null on the last page.

object
items
required
Array<object>

A session as Actieve sessies shows it: never its id, which is the secret in the cookie, but a handle derived from it.

object
handle
required

Identifies the session for revoking it; never the session id itself.

string
subject
required
string
name
required
string
email
string | null
roles
required
Array<string>
kind
required

ui or cli.

string
client

The browser, or the machine and version of bl.

string | null
created_at
required
string format: date-time
checked_at
required

The login or the last check with the IdP (within 10 minutes of the last use).

string format: date-time
checks_with_idp
required

Checks back with the IdP; otherwise a fixed session of 8 hours.

boolean
current
required

The session of the request that asks.

boolean
next_cursor

Pass as cursor for the next page.

string | null

Example generated

{
"items": [
{
"handle": "example",
"subject": "example",
"name": "example",
"email": "example",
"roles": [
"example"
],
"kind": "example",
"client": "example",
"created_at": "2026-04-15T12:00:00Z",
"checked_at": "2026-04-15T12:00:00Z",
"checks_with_idp": true,
"current": true
}
],
"next_cursor": "example"
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}