API SpecificationPRIVATExeonr.auth.private.v1.PasswordService
Get Session
Checks if a session token is valid and returns user info. Used to show 'Continue as X' UI.
Authentication: None required
Authorization
BearerAuth AuthorizationBearer <token>
JWT access token for internal API access. Requires 'private' scope for most endpoints, 'admin' scope for administrative operations.
In: header
Header Parameters
Connect-Protocol-Version*number
Define the version of the Connect protocol
Value in
1Connect-Timeout-Ms?number
Define the timeout, in ms
Request Body
application/json
sessionToken?string
Session token from cookie
Length
1 <= length[key: string]?never
Response Body
application/json
application/json
curl -X POST "https://auth.xeonr.io/xeonr.auth.private.v1.PasswordService/GetSession" \ -H "Connect-Protocol-Version: 1" \ -H "Content-Type: application/json" \ -d '{}'{
"valid": true,
"email": "[email protected]",
"suggestedUsername": "john.doe"
}{
"code": "not_found",
"message": "string",
"details": [
{
"type": "string",
"value": "string",
"debug": {}
}
]
}Enroll TOTP POST
Generates a TOTP secret for 2FA enrollment. Returns the secret and provisioning URI for QR code display. **Required scopes:** `auth:account:edit`
Get TOTP Status POST
Returns the current TOTP 2FA status including whether it is enabled and remaining recovery codes. **Required scopes:** `auth:account:read`