Get session state
Returns the current state of a session including its factors and all currently satisfied assurance levels. `assurance_levels[]` may shrink over time as factor freshness windows expire, without the session itself expiring. Use step-up authentication (a new `auth_attempt` against the same `session_id`) to restore a dropped assurance level.
Returns the current state of a session including its factors and all currently satisfied assurance levels.
assurance_levels[] may shrink over time as factor freshness windows expire,
without the session itself expiring. Use step-up authentication (a new auth_attempt
against the same session_id) to restore a dropped assurance level.
Authorization
oauth2 session.readIn: header
Scope: session.read
Path Parameters
The unique identifier of the session.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/sessions/sess_01J0Z9KX7Y0Q2Y7JX5M9K2YF3C"{ "session_id": "sess_01J0Z9KX7Y0Q2Y7JX5M9K2YF3C", "project_id": "proj_01hexample", "state": "active", "user_id": "user_id_12345", "name": "Ada Lovelace", "email": "ada@example.com", "factors": [ { "method": "password", "verified_at": "2026-04-28T15:32:00Z", "payload": { "user_id": "user_id_12345" } } ], "assurance_levels": [ "urn:nist:aal:1", "urn:nist:aal:2" ], "metadata": {}, "user_agent": { "fingerprint": "fp_abc123", "ip": "203.0.113.42" }, "created_at": "2026-04-29T10:00:00Z", "expires_at": "2026-04-30T10:00:00Z"}{ "code": "string", "message": "string", "details": {}}{ "code": "string", "message": "string", "details": {}}{ "code": "string", "message": "string", "details": {}}{ "code": "auth.unauthorized", "message": "The request lacks valid authentication credentials."}Get my session state GET
Returns the current state of the current session including its factors and all currently satisfied assurance levels. `assurance_levels[]` may shrink over time as factor freshness windows expire, without the session itself expiring. Use step-up authentication (a new `auth_attempt` against the same `session_id`) to restore a dropped assurance level.
Query sessions POST
Returns the sessions of a project, paginated with a cursor. Sessions of every lifecycle state are returned; each carries its `state`. Requires `session.read` permission.