List own active refresh sessions
Returns family identifiers, creation, refresh-expiry, User-Agent, IP and last login/refresh activity for the authenticated active membership in this tenant. No tokens or hashes. User-Agent is untrusted client metadata; IP is the container remote address. Current is determined by the signed session_id claim (legacy tokens have no current marker). Stable newest-first pagination.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
page?integerZero-based page number
int320size?integerPage size from 1 to 100
int3220OK
*/*- response
hasMore?booleanitems?array<>page?integerint32size?integerint32curl -X GET 'https://api.monetaryai.uz/api/v1/me/sessions'{ "hasMore": true, "items": [ { "createdAt": "2019-08-24T14:15:22Z", "current": true, "expiresAt": "2019-08-24T14:15:22Z", "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "ipAddress": "string", "lastActivityAt": "2019-08-24T14:15:22Z", "userAgent": "string" } ], "page": 0, "size": 0}Get the current authenticated user GET
Returns identity, membership, tenant, and role claims after signature and host-to-tenant validation.
Accept an invitation or activate an invited identity POST
Proves an existing identity's current password, or creates a new identity with a chosen password only for an email-only invitation. Token consumption and membership roles are atomic. For identities with email 2FA, returns a 202 challenge without tokens; complete /auth/login with the current password, challengeId and emailed code on this tenant host. For Google Authenticator users, returns 202 channel=TOTP; complete login on this tenant with password and totpCode or recoveryCode. Otherwise issues the session atomically.