Identity response objects
These definitions explain the fields returned by Wallkit identity operations. A session token, refresh token, authorization code and Firebase token have different uses. Use the field definition linked by the operation. Tokens shown in examples are placeholders.
Ordinary sign-in
The ordinary sign-in response merges the resource-aware user with these authentication fields at the top level. No universal user/data wrapper.
| Field | Type / presence | Meaning and conditions |
|---|---|---|
token_type | string | The label bearer. Subsequent Wallkit API calls still use the custom token header; this label does not change their transport. |
token | string; token/code_and_token response | Wallkit member-session token. Send it in token with the matching resource context. |
expires | integer; token/code_and_token response | Session expiration as Unix timestamp seconds, not a relative lifetime. Account/session restrictions can reject the token earlier. |
refresh_token | string; token/code_and_token response | Returned refresh value. This ordinary sign-in path does not establish its reusability; do not build an automatic refresh loop around it. |
session_id | stored integer ID; token/code_and_token response | Newly created Wallkit session record. |
device | string; token/code_and_token response | Inferred device label; unknown when unavailable. Not an access permission. |
code | string; code/code_and_token response | Authorization code for the separate OAuth exchange, not a member token. Requires resource context. |
redirect_uri | string; code/code_and_token with nonempty redirect input | Returned redirect destination with auth parameters appended. It is a JSON field, not an HTTP redirect response. Treat it as credential-bearing data. |
The default response type is token. A code-only result omits the session token/refresh/expiry/session ID/device fields. Supplying code with redirect_uri adds the returned destination but keeps other top-level user/auth fields. No automatic redirect or code expiry promise is added by this definition.
Resource-aware user
Ordinary sign-in begins with the full user projection. All base fields and conditional admin fields there apply, with these resource-context differences and requested relationships:
| Field | Type / presence | Meaning and conditions |
|---|---|---|
extra | dynamic object | Selected resource relationship’s extra properties; empty object without a relationship/context. No fixed key schema. |
uid | string / null | Resource-scoped user identifier, if set. |
user_resource_created_at | timestamp string / null | Creation time of the resource relationship, if present. |
locked | stored flag / false | Selected relationship lock flag, false without a relationship. |
language | object / null | Selected language with id (stored integer), slug/title/description (stored text), is_default/active (stored flags), sort (stored numeric rank), created_at/updated_at (timestamps). Null when no valid configured language. |
active, confirm | boolean | With a selected resource relationship, active is true when neither suspended nor locked; confirm resolves the relationship confirmation flag. Without a relationship, both resolve the global user state. |
settings, role | dynamic value/null and string; admin context only | Resource settings and resolved role, not universally included for ordinary members. |
subscriptions | array; ordinary sign-in | Identity membership records for this resource. Empty if none; failed/missing relationships can be omitted. No active-membership-only guarantee. |
teams | array; ordinary sign-in | Active teams attached to this member within the resource’s partner, using identity team. Empty without matching resource context. |
last_action | timestamp string / null; ordinary sign-in | Most recently selected session update time, or null; no ordering relationship with other activity fields is guaranteed. |
User IDs and global active/confirm/locked values normalize during fetch/save; resource relationship extra/settings decode during fetch and after save. Stored resource flags are not all explicitly cast. Returned identity data does not itself authorize a content item: make the access check.
Identity membership
Starts with the complete general Pricing, including its compact plan and bounded next/downgrade projections. Adds:
| Field | Type / presence | Meaning and conditions |
|---|---|---|
subscription_start_date, subscription_updated_date | timestamp strings | Membership creation/update times. |
subscription_end_date | timestamp string / null | Membership expiration. |
subscription_is_external | boolean | Membership marked externally managed. |
autorenew, is_trial, is_team_subscription, is_allowed_next_subscription | boolean | Membership renewal choice, trial state, team state and next-Pricing permission. Do not infer a parent-membership fallback guarantee. |
sponsored_subscription_slot | object / null | Sponsorship slot when attached; projection below. |
A sponsorship slot contains id, sponsored_subscription_id, recipient_id (stored numeric references), recipient_email, activation_code (stored text), activated_id (stored reference), activated_at (nullable timestamp), created_at and updated_at (timestamps). It adds sponsored_subscription (null or the sponsored subscription base plus membership dates/settings and sponsor full-user). That nested sponsorship omits subscription and slots expansions. This slot projection does not add recipient. Missing mapping can omit an entire membership; none of these fields is a token required by the sign-in request.
Identity team
| Field | Type / presence | Meaning and conditions |
|---|---|---|
id | integer | Team identifier. |
name, description | stored strings / nullable | Team display name and description. |
active | boolean | Team activation state; only active teams selected. |
type | stored string | Configured team category; no closed enum here. |
owner | short user; only with owner reference | Short user, not the full resource-aware user. |
users_count, invites_count | integer | Count of attached user relationships and invites; not an allowed-seat limit. |
role, status | stored strings / nullable | This member’s team relationship role/status; no closed enum here. |
This public team projection excludes membership expiration, seat limit, allowed email expressions and record timestamps from the broader team serializer.
Session projection
Code exchange, registration and reset-code confirmation use these fields from the session serializer. Merge order is operation-specific: OAuth/reset confirmation overwrite user id with session id, while registration’s later user merge retains user id.
| Field | Type / presence | Meaning |
|---|---|---|
id | stored integer ID | Session ID when not overwritten by later user merge. |
token | string | Wallkit session credential for custom token header. |
ip | string / nullable | Recorded request IP. |
device, browser, platform | stored strings / nullable | Inferred client/device details; not permissions. |
expires | integer | Unix timestamp seconds for stored session expiration; not a guaranteed valid lifetime. |
compromised | stored flag | Session compromise state; no extra boolean conversion claimed by this serializer. |
source_type | stored string / nullable | Integration session-source label. |
The separate refresh_token field is a string from the refresh serializer. Issuance/consumption differs by operation; the ordinary sign-in refresh caveat must not be generalized to every exchange. Refresh responses contain only authentication parameters, not the user/session-projection union.