Your account
const url = 'https://api.sloose.com/auth/account';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.sloose.com/auth/account \ --header 'Authorization: Bearer <token>'The person behind the session: their email and name, the sign-in methods linked to the account, and every session they hold — this one flagged. One row per browser: a CRM tab’s own session belongs to the browser session it was minted from, ends with it, and is not listed apart. Session only.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”The account.
object
object
object
zoho-<dc> for a Zoho sign-in linked to this account. A magic link needs no linked provider and is always available to the email.
object
When the session last slid its expiry.
The org the session is working in, if any.
A Sloose staff member’s time-boxed view of an org as this person. Listed so it is seen; it ends by its own clock, or when the person ends it here, since it acts as them.
Example
{ "methods": [ { "provider": "zoho-au" } ]}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}