List active sessions
const url = 'https://example.com/api/v1/sessions';const options = { method: 'GET', headers: {cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/sessions \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3ESessions of the UI and of bl: your own, or as admin everyone’s. current marks the session of the request.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK.
A page of a list. next_cursor is null on the last page.
object
A session as Actieve sessies shows it: never its id, which is the secret in the cookie, but a handle derived from it.
object
Identifies the session for revoking it; never the session id itself.
ui or cli.
The browser, or the machine and version of bl.
The login or the last check with the IdP (within 10 minutes of the last use).
Checks back with the IdP; otherwise a fixed session of 8 hours.
The session of the request that asks.
Pass as cursor for the next page.
Example generated
{ "items": [ { "handle": "example", "subject": "example", "name": "example", "email": "example", "roles": [ "example" ], "kind": "example", "client": "example", "created_at": "2026-04-15T12:00:00Z", "checked_at": "2026-04-15T12:00:00Z", "checks_with_idp": true, "current": true } ], "next_cursor": "example"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}