A valid request URL is required to generate request examples{
"events": [
{
"type": "contact.signed_in",
"method": "<string>",
"ip": "<string>",
"user_agent": "<string>",
"sequence": 123,
"created_at": "2023-11-07T05:31:56Z"
}
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}One contact's authentication history
Requires customers:read. What happened to this account: every sign-in, how it happened and where from, newest first (100 most recent).
It is the answer to the support conversation that starts with “was that me?”
ip and user_agent are attributes of the request a session was minted on: what the proxy left, and a string the caller chose. They are for a person to recognise their own device, never for an authorization decision.
Anonymous visitors never appear. The widget mints one on every page load, none of them is an account, and a history full of them is a history nobody reads.
A valid request URL is required to generate request examples{
"events": [
{
"type": "contact.signed_in",
"method": "<string>",
"ip": "<string>",
"user_agent": "<string>",
"sequence": 123,
"created_at": "2023-11-07T05:31:56Z"
}
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Authorizations
A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.
Headers
The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.
Path Parameters
Query Parameters
Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.
live, test Response
The history.
Show child attributes
Show child attributes