Identity response objects

These definitions explain the fields returned by Wallkit identity operations. A session token, refresh token, authorization code and Firebase token have different uses. Use the field definition linked by the operation. Tokens shown in examples are placeholders.

Ordinary sign-in

The ordinary sign-in response merges the resource-aware user with these authentication fields at the top level. No universal user/data wrapper.

FieldType / presenceMeaning and conditions
token_typestringThe label bearer. Subsequent Wallkit API calls still use the custom token header; this label does not change their transport.
tokenstring; token/code_and_token responseWallkit member-session token. Send it in token with the matching resource context.
expiresinteger; token/code_and_token responseSession expiration as Unix timestamp seconds, not a relative lifetime. Account/session restrictions can reject the token earlier.
refresh_tokenstring; token/code_and_token responseReturned refresh value. This ordinary sign-in path does not establish its reusability; do not build an automatic refresh loop around it.
session_idstored integer ID; token/code_and_token responseNewly created Wallkit session record.
devicestring; token/code_and_token responseInferred device label; unknown when unavailable. Not an access permission.
codestring; code/code_and_token responseAuthorization code for the separate OAuth exchange, not a member token. Requires resource context.
redirect_uristring; code/code_and_token with nonempty redirect inputReturned redirect destination with auth parameters appended. It is a JSON field, not an HTTP redirect response. Treat it as credential-bearing data.

The default response type is token. A code-only result omits the session token/refresh/expiry/session ID/device fields. Supplying code with redirect_uri adds the returned destination but keeps other top-level user/auth fields. No automatic redirect or code expiry promise is added by this definition.

Resource-aware user

Ordinary sign-in begins with the full user projection. All base fields and conditional admin fields there apply, with these resource-context differences and requested relationships:

FieldType / presenceMeaning and conditions
extradynamic objectSelected resource relationship’s extra properties; empty object without a relationship/context. No fixed key schema.
uidstring / nullResource-scoped user identifier, if set.
user_resource_created_attimestamp string / nullCreation time of the resource relationship, if present.
lockedstored flag / falseSelected relationship lock flag, false without a relationship.
languageobject / nullSelected language with id (stored integer), slug/title/description (stored text), is_default/active (stored flags), sort (stored numeric rank), created_at/updated_at (timestamps). Null when no valid configured language.
active, confirmbooleanWith a selected resource relationship, active is true when neither suspended nor locked; confirm resolves the relationship confirmation flag. Without a relationship, both resolve the global user state.
settings, roledynamic value/null and string; admin context onlyResource settings and resolved role, not universally included for ordinary members.
subscriptionsarray; ordinary sign-inIdentity membership records for this resource. Empty if none; failed/missing relationships can be omitted. No active-membership-only guarantee.
teamsarray; ordinary sign-inActive teams attached to this member within the resource’s partner, using identity team. Empty without matching resource context.
last_actiontimestamp string / null; ordinary sign-inMost recently selected session update time, or null; no ordering relationship with other activity fields is guaranteed.

User IDs and global active/confirm/locked values normalize during fetch/save; resource relationship extra/settings decode during fetch and after save. Stored resource flags are not all explicitly cast. Returned identity data does not itself authorize a content item: make the access check.

Identity membership

Starts with the complete general Pricing, including its compact plan and bounded next/downgrade projections. Adds:

FieldType / presenceMeaning and conditions
subscription_start_date, subscription_updated_datetimestamp stringsMembership creation/update times.
subscription_end_datetimestamp string / nullMembership expiration.
subscription_is_externalbooleanMembership marked externally managed.
autorenew, is_trial, is_team_subscription, is_allowed_next_subscriptionbooleanMembership renewal choice, trial state, team state and next-Pricing permission. Do not infer a parent-membership fallback guarantee.
sponsored_subscription_slotobject / nullSponsorship slot when attached; projection below.

A sponsorship slot contains id, sponsored_subscription_id, recipient_id (stored numeric references), recipient_email, activation_code (stored text), activated_id (stored reference), activated_at (nullable timestamp), created_at and updated_at (timestamps). It adds sponsored_subscription (null or the sponsored subscription base plus membership dates/settings and sponsor full-user). That nested sponsorship omits subscription and slots expansions. This slot projection does not add recipient. Missing mapping can omit an entire membership; none of these fields is a token required by the sign-in request.

Identity team

FieldType / presenceMeaning and conditions
idintegerTeam identifier.
name, descriptionstored strings / nullableTeam display name and description.
activebooleanTeam activation state; only active teams selected.
typestored stringConfigured team category; no closed enum here.
ownershort user; only with owner referenceShort user, not the full resource-aware user.
users_count, invites_countintegerCount of attached user relationships and invites; not an allowed-seat limit.
role, statusstored strings / nullableThis member’s team relationship role/status; no closed enum here.

This public team projection excludes membership expiration, seat limit, allowed email expressions and record timestamps from the broader team serializer.

Session projection

Code exchange, registration and reset-code confirmation use these fields from the session serializer. Merge order is operation-specific: OAuth/reset confirmation overwrite user id with session id, while registration’s later user merge retains user id.

FieldType / presenceMeaning
idstored integer IDSession ID when not overwritten by later user merge.
tokenstringWallkit session credential for custom token header.
ipstring / nullableRecorded request IP.
device, browser, platformstored strings / nullableInferred client/device details; not permissions.
expiresintegerUnix timestamp seconds for stored session expiration; not a guaranteed valid lifetime.
compromisedstored flagSession compromise state; no extra boolean conversion claimed by this serializer.
source_typestored string / nullableIntegration session-source label.

The separate refresh_token field is a string from the refresh serializer. Issuance/consumption differs by operation; the ordinary sign-in refresh caveat must not be generalized to every exchange. Refresh responses contain only authentication parameters, not the user/session-projection union.

Full diagram

Use the arrow keys to scroll. Escape closes this view.

Search documentation

Enter at least 2 characters.

    ↑ ↓ move through results · Enter opens · Escape closes