Ordinary Wallkit identity

Use authorization for email/password sign-in, or social-authorization for an already linked provider identity. Use registration to add a member to a resource. Confirmation and reset have separate code flows. OAuth and external authentication use an already configured integration. Firebase identity is separate. Follow the ordinary identity-to-access guide to connect member context to content permission.

Choose the identity context

Use the API base and resource public key supplied for the integration. The request table for each operation distinguishes guest input, member credentials, authorization/reset/confirmation codes and server-only client secrets. Keep these credentials separate. Firebase identity uses its own flow.

Shared context errors apply where initialization, permission and session checks run; an operation’s exclusions do not guarantee session or provider success. The examples are synthetic; see sample runtimes.

Operations

OperationMethod / path
Sign in with email and passwordPOST /api/v1/authorization
Refresh an existing Wallkit credentialPOST /api/v1/authorization/refresh
Log out the resolved sessionGET /api/v1/logout
Sign in through an existing social accountPOST /api/v1/social-authorization
Register a resource memberPOST /api/v1/registration
Confirm a reset code and establish a sessionPOST /api/v1/confirm-password
Request a password resetPOST /api/v1/reset-password
Request another confirmation messagePOST /api/v1/resend-confirmation
Confirm an email codePOST /api/v1/confirm-email
Validate email availability in a resourcePOST /api/v1/email-validation
Exchange an ordinary authorization codePOST /api/v1/oauth/token
Establish identity through external authenticationGET /api/v1/auth/external/{token}

Sign in with email and password

POST /api/v1/authorization

Establish a Wallkit member session for an existing account. Use this ordinary flow for an integration whose identity configuration uses Wallkit email/password. Choose the resource context your integration supplies; a password for one resource may differ from the global account password. This call does not register a new global account.

Sign-in creates a session and records login activity. It can attach an existing user to the selected resource, add its configured default subscription and merge earlier guest content access. Resource device/compromised-session policies can affect other sessions or lock the resource relationship. It also changes refresh-token records; the returned refresh value is not guaranteed reusable by this path. Do not treat sign-in as a read or promise that repeating it is harmless.

Before you call

Use the API base/resource public key supplied by the integration and an existing member’s email/password. The global account must be active and any existing resource relationship must not be locked or suspended. Guest permission permits the sign-in action; no existing Wallkit member token is required for the ordinary request. A resource is the publication/integration context, not a user credential.

The action can run without a resolved resource for the ordinary token branch; supply the correct resource for scoped identity/password/relationship behavior. Code/code_and_token responses need a resource. This guide’s ordinary example assumes Firebase authentication is disabled for that resource; Firebase-enabled initialization follows its separate identity configuration.

Request

Accepts application/json or form fields (application/x-www-form-urlencoded). Form fields take precedence when present; send one encoding. The example uses JSON. Response media type is JSON.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringsupplied integration contextPublic resource key selecting scoped sign-in; not the secret. Not an action-level mandatory-resource guard for default token mode.
sessionheaderstringoptionalExisting guest-session identifier when the integration intends to merge earlier guest content access. Not a password or member token.
source-typeheaderstringoptionalIntegration session-source label; do not infer a fixed accepted enum.
emailbodystringrequired, nonempty valid emailExisting account email; trimmed/lowercased before lookup.
passwordbodystringrequired, nonemptyExisting resource password when configured, otherwise global account password; trimmed. No registration password-length rule implied here.
response_typebodystringoptional, default tokentoken, code or code_and_token when paired with nonempty redirect_uri validation. Unsupported combinations are not a supported recipe; omit for ordinary session mode.
redirect_uribodystringconditional redirect/code flowValidated together with nonempty response_type; existing resource host/configuration controls permitted redirect input. It adds a destination to JSON; no HTTP redirect.

Result

HTTP 200 returns the ordinary sign-in fields and resource-aware user at the top level. A token-mode result includes token, expiration, refresh value and session details along with the complete user projection. Use the returned token in the custom token header on member API requests; token_type:bearer does not introduce a Bearer Authorization header.

The session’s expires is Unix seconds, not a guaranteed usable lifetime. The returned refresh value does not establish a reusable refresh session on this sign-in path; handle refresh rejection with the integration’s existing sign-in flow rather than assuming automatic refresh succeeds.

Example: establish a reader session

reader@example.com is an existing active member in the selected ordinary Wallkit resource. These requests use the same JSON fields. Supply WALLKIT_API_BASE (scheme/host only) and RESOURCE_KEY from the existing integration. See sample runtimes.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/authorization" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/authorization", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "email": "reader@example.com",
  "password": "EXAMPLE_PASSWORD_DO_NOT_USE"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/authorization")
body = {'email': 'reader@example.com', 'password': 'EXAMPLE_PASSWORD_DO_NOT_USE'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "id": 1001,
  "email": "reader@example.com",
  "active": true,
  "token_type": "bearer",
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
  "refresh_token": "EXAMPLE_WALLKIT_REFRESH_TOKEN",
  "session_id": 3001,
  "subscriptions": [],
  "teams": []
}

The session token establishes member context. Empty subscriptions/teams do not deny or grant the article: obtain the actual content access decision. Expiration, profile and conditional relationships are omitted from this excerpt but defined in the linked object tables.

Alternate result: credentials rejected

For an unknown account email, HTTP 401 can return this excerpt:

{
  "error": "authorization_fail",
  "error_description": "Wrong email or password.",
  "req_guid": "example-request"
}

Do not create a logged-in UI or proceed to member access calls. Check the user-supplied identity and correct resource context. The same code also covers wrong password and account restrictions; interpret the explanation without promising an account-existence check from this error.

Recovery

HTTP statusAPI codeCauseNext action
409invalid_email / invalid_passwordMissing/malformed required input.Supply nonempty email/password; correct email syntax.
409invalid_response_type / invalid_redirect_uriPaired redirect/code inputs fail validation.Use an established resource-host redirect configuration and supported response type, or omit both for ordinary token sign-in.
401authorization_failUnknown email or wrong password.Check credentials and selected resource password context; use the documented reset flow if needed when that operation is available.
401authorization_failInactive global account or locked/suspended resource relationship.Ask the integration administrator to resolve that account state; repeating sign-in does not repair it.
401exceptionSign-in orchestration fails.Contact the administrator/support with req_guid. Do not assume session or relationship writes were rolled back.
409initialize_failedIntegration context initialization fails.Check resource/identity configuration with the administrator; provide req_guid to support.
401 / 403accessShared role/action checks reject context.Check the identity mode and permitted action context; do not substitute an elevated secret.

Next task

Follow ordinary identity to content access to place the returned session token in the member request and handle allow:false separately from sign-in failure.

Refresh an existing Wallkit credential

POST /api/v1/authorization/refresh

Exchange a stored Wallkit refresh record for new authentication parameters. This POST creates credentials and normally deletes the submitted refresh record after issuance. Optional Firebase flags can contact the configured provider. It is not a Firebase refresh-token exchange.

Before you call

Use a refresh token backed by an existing Wallkit refresh record and the intended resource context. Ordinary password sign-in does not establish reuse of its returned refresh value. The default response mode creates a code and token and needs a resource; this example explicitly selects token mode.

Request

JSON or form; form fields take precedence. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringintegration contextPublic resource key; preserve intended member/code/resource context.
refresh_tokenbodystringrequired, nonemptyExisting Wallkit refresh value; trimmed.
response_typebodystringoptional; code_and_token defaulttoken, code or code_and_token; no action-level inclusion validator here. Use a supported mode.
reusable_refreshbodyJSON booleanoptional; false defaultOnly true boolean preserves the submitted record; form string true does not satisfy the strict type check.
redirect_uribodystringconditional code responseWith nonempty response_type and code mode, adds JSON destination; this action does not apply sign-in redirect validation.
with_firebase_tokenbodytruthy inputoptionalRequests Firebase ID token when configured and linked; failures can omit it.
with_firebase_custom_tokenbodytruthy inputoptionalRequests Firebase custom token, not ID token; failures can omit it.
with_has_resource_passwordbodytruthy inputoptionalAdds whether the selected resource relationship has a password.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
auth fieldsmode-dependentauthentication fields only; no user profile in this response. Its refresh value is created by this exchange; no automatic success/lifetime guarantee.
firebase-token, firebase-custom-tokenstring; requested and availableFirebase ID/custom tokens respectively; may be omitted on caught provider/configuration failure.
has-resource-passwordboolean; requestedPresence of a selected resource password.

Example

Exchange the existing Wallkit refresh value in token mode. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/authorization/refresh" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"refresh_token":"EXAMPLE_EXISTING_REFRESH_TOKEN","response_type":"token"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/authorization/refresh", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "refresh_token": "EXAMPLE_EXISTING_REFRESH_TOKEN",
  "response_type": "token"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/authorization/refresh")
body = {'refresh_token': 'EXAMPLE_EXISTING_REFRESH_TOKEN', 'response_type': 'token'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "token_type": "bearer",
  "token": "EXAMPLE_NEW_WALLKIT_TOKEN",
  "refresh_token": "EXAMPLE_NEW_REFRESH_TOKEN"
}

Alternate result

A supplied refresh value has no stored record. Re-establish identity; do not automatically reuse the ordinary sign-in refresh value.

HTTP 406 response excerpt:

{
  "error": "incorrect_refresh_token",
  "error_description": "Incorrect refresh token."
}

Recovery

HTTP statusAPI codeCauseNext action
406incorrect_refresh_tokenMissing or unknown refresh record.Use the existing identity flow for a valid refresh value or sign in again; do not loop retries.
404incorrect_refresh_tokenRefresh record has no related user.Re-establish identity and ask support to inspect the stale record.
401incorrect_refresh_tokenCredential construction fails.Check resource/mode configuration; re-establish identity if necessary.

See identity context and shared errors for checks that apply before this operation.

Next task

If refresh is rejected, sign in again. After successful refresh, use the returned member token for the access decision.

Log out the resolved session

GET /api/v1/logout

End the resolved Wallkit session. This GET changes session state and records logout activity. With resource setting remove_all_session_on_logout (default true), it also deletes other sessions for the user in this resource; it does not promise global/provider logout.

Before you call

Supply an existing session token and matching resource context. The shared session check is excluded for this controller, but a session must still resolve.

Request

No request body. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringintegration contextPublic resource key; preserve intended member/code/resource context.
tokenheaderstringresolved member sessionExisting Wallkit session token.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
resultbooleanResolved session marked inactive; no account deletion or provider revocation is established.

Example

End the resolved member session. See identity context for configuration and sample conventions.

cURL

curl "${WALLKIT_API_BASE}/api/v1/logout" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "token: ${USER_TOKEN}"

JavaScript

// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
  const url = new URL("/api/v1/logout", process.env.WALLKIT_API_BASE);
  const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
  const response = await fetch(url, { method: "GET", headers });
  const body = await response.json();
  console.log(response.status, body);
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/logout")
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "result": true
}

Alternate result

No session resolves from the supplied context. Clear unusable local session state and use the existing sign-in flow.

HTTP 401 response excerpt:

{
  "error": "incorrect_token",
  "error_description": "Incorrect token"
}

Recovery

HTTP statusAPI codeCauseNext action
401incorrect_tokenNo resolved session.Clear unusable local session state and use the appropriate identity flow; a resource key alone is insufficient.

See identity context and shared errors for checks that apply before this operation.

Next task

Sign in through the configured identity flow when the member returns.

Sign in through an existing social account

POST /api/v1/social-authorization

Establish Wallkit identity from an existing linked Google or Facebook account. This POST calls the selected provider and creates a Wallkit session, can attach a resource/default membership and merge guest access, and records login activity. It does not create an unlinked social account.

Before you call

Use the provider account ID/access token obtained by the existing integration’s provider flow. The Wallkit account must already carry that social ID and be active/unrestricted. Provider compatibility is not verified here.

Request

JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringintegration contextPublic resource key; preserve intended member/code/resource context.
methodbodystringrequired outer fieldgoogle or facebook; these are the implemented account branches.
databodyobjectoptionalWhen supplied, nested object contains all fields below; method remains outer.
idbodystringnecessary supported branchExisting linked provider account identifier.
access_tokenbodystringnecessary provider checkProvider access token, not Wallkit token.
response_typebodystringoptional; token defaulttoken/code/code_and_token modes, read inside data when nested.
redirect_uribodystringconditionalAdds JSON destination for code modes when both inputs nonempty; no sign-in-style redirect validator here.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
user and authtop-level objectresource-aware user and relationships plus mode-dependent authentication fields. Unlike ordinary password sign-in, no all-user refresh cleanup is performed here; credential lifetime/reuse still depends on later state/checks.

Example

Sign in with the already-linked Google identity. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/social-authorization" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"method":"google","data":{"id":"EXAMPLE_GOOGLE_ACCOUNT_ID","access_token":"EXAMPLE_GOOGLE_ACCESS_TOKEN"}}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/social-authorization", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "method": "google",
  "data": {
    "id": "EXAMPLE_GOOGLE_ACCOUNT_ID",
    "access_token": "EXAMPLE_GOOGLE_ACCESS_TOKEN"
  }
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/social-authorization")
body = {'method': 'google', 'data': {'id': 'EXAMPLE_GOOGLE_ACCOUNT_ID', 'access_token': 'EXAMPLE_GOOGLE_ACCESS_TOKEN'}}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "id": 1001,
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
  "token_type": "bearer"
}

Alternate result

The supplied Google ID is not linked to a Wallkit account. Use the existing linking/registration flow rather than retrying provider sign-in.

HTTP 401 response excerpt:

{
  "error": "account_error",
  "error_description": "You dont have google account"
}

Recovery

HTTP statusAPI codeCauseNext action
400incorrect_dataMissing JSON/method.Send the outer method and appropriate JSON account fields.
401account_errorProvider ID is not linked to a Wallkit account.Use the integration’s account-linking/registration flow instead of assuming this call registers it.
406invalid_social_idProvider-confirmed ID differs.Obtain matching provider ID/access token from the existing provider flow.
401authorization_failAccount inactive or resource relationship locked/suspended.Resolve account state with the administrator.
401exceptionIdentity orchestration fails.Contact support with req_guid; do not assume earlier writes were undone.

See identity context and shared errors for checks that apply before this operation.

Next task

Use the Wallkit token for the member access step after provider identity succeeds.

Register a resource member

POST /api/v1/registration

Create or reuse a global user and attach them to this resource. This POST saves user/resource/session/confirmation records, may attach default/invited membership, queue confirmation/marketing events and call configured social/Firebase/Firestore services. It is not a confirmed-email or completed-payment guarantee. A validation response does not establish that no later writes occurred.

Before you call

Resource context is required. Use a new-to-resource email that satisfies resource domain policy, an ordinary password with matching confirmation, or the distinct guest_email branch. This example uses password registration without invite/provider extras.

Request

JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringrequiredPublic resource key; preserve intended member/code/resource context.
emailbodystringrequiredValid email, length5–60; uniqueness in resource and domain policy apply.
passwordbodystringordinary branchLength6–40, nonempty; trimmed before storing resource password.
password_confirmbodystringordinary branchMust match password.
guest_emailbodystringoptional alternate branchNonempty value replaces email and bypasses password requirement; initial email validation still applies. Missing country may be derived from location.
nick_namebodystringoptionalNickname validation applies; stored nickname is not guaranteed to equal supplied value. Avoid relying on it without reading returned profile.
subscription_idbodyID or IDs accepted by validatoroptionalExisting Pricing IDs validated; response may echo selected ID. This input alone is not proof of a new paid membership.
invitebodystringoptionalExisting invite validated for email/resource and can activate team/Pricing relationships.
first_name, last_name, country, company, job, phonebodystringsoptional; max120 eachStored profile text.
city, statebodystringsoptional; max50 eachProfile location text.
zipbodystringoptional; max20Postal text.
ipbodystringoptional; max15Stored IP input, otherwise inferred request IP; no IP validity guarantee.
facebook_id, google_idbodystringsoptional; max120Provider ID; checks duplicates and provider correspondence when nonnull.
social_tokenbodystringconditional social IDsProvider credential for matching email/ID checks, not Wallkit session token.
extrabodyobjectoptionalResource-specific extra properties; extra.firestore can supply configured Firestore data.
campaignmonitorbodyobjectoptionalsubscriptions list feeds configured synchronization event; no delivery/synchronization completion promise.

Result

HTTP 201 JSON.

Field / projectionType / presenceMeaning
user/session/refreshmerged top-level fieldsresource-aware user and relationships without last_action, plus session projection and refresh_token string. Here the later user merge makes id the user ID, not session ID.
subscription_idstored ID / integer; conditionalInvite Pricing ID or supplied subscription ID; not a purchase/membership proof.

Example

Register new-reader@example.com in this resource. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/registration" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"new-reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE","password_confirm":"EXAMPLE_PASSWORD_DO_NOT_USE"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/registration", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "email": "new-reader@example.com",
  "password": "EXAMPLE_PASSWORD_DO_NOT_USE",
  "password_confirm": "EXAMPLE_PASSWORD_DO_NOT_USE"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/registration")
body = {'email': 'new-reader@example.com', 'password': 'EXAMPLE_PASSWORD_DO_NOT_USE', 'password_confirm': 'EXAMPLE_PASSWORD_DO_NOT_USE'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 201 response excerpt:

{
  "id": 1001,
  "email": "new-reader@example.com",
  "confirm": false,
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN"
}

Alternate result

The email is already linked in this resource. Use the existing sign-in flow.

HTTP 409 response excerpt:

{
  "error": "invalid_email",
  "error_description": "This email is already used."
}

Recovery

HTTP statusAPI codeCauseNext action
400incorrect_dataNo JSON body.Send supported JSON fields.
422invalid_<field>Input validation fails.Correct named fields; inspect existing profile state before retrying because this response does not prove absence of later writes.
409invalid_emailEmail already linked in this resource.Use the existing sign-in/account flow.
400account_errorSocial account already used.Use the matching existing linked account flow.
406invalid_email / invalid_social_idProvider correspondence mismatch.Obtain matching provider identity details.
406team_registration_fail / incorrect_subscription / accept_invite_failInvite/team/Pricing processing fails.Check configured invite/Pricing with administrator; do not infer provider effects rolled back.
406registration_failRegistration orchestration fails.Contact support and inspect account state before repeating writes.
404resource_not_existsRequired resource is unknown.Correct public resource key and integration context.

See identity context and shared errors for checks that apply before this operation.

Next task

Complete the applicable confirmation flow using the received code; registration itself is not confirmation.

Confirm a reset code and establish a session

POST /api/v1/confirm-password

Use an existing reset code to establish identity for a password-reset flow. This POST clears the resource password and, unless the user is an administrator anywhere, clears the global password; sets global user confirmation true, saves it, cleans refresh records and creates a session/refresh value. It does not accept or set a new password, and does not establish one-use invalidation of this code.

Before you call

Required resource context and an active stored code from the reset flow. No existing member token required. The code lookup itself is not resource-bound; keep the original intended context.

For an existing resource relationship, reset also sets resource confirmation false and clears its language, settings and Firebase UID. Global user confirmation becomes true, but the resource-aware response reads the relationship confirmation and therefore shows false for this scenario. Existing extra data is preserved. Clearing the Firebase UID can disrupt provider/member resolution; do not assume the newly issued session gives an uninterrupted Firebase-enabled flow.

Request

Use JSON. Apparent form compatibility is not a reliable contract for this action. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringrequiredPublic resource key; preserve intended member/code/resource context.
codebodystringrequired, nonemptyExisting reset code; trimmed. No new_password input.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
user/session/refreshmerged top-levelresource-aware user and relationships without last_action; session projection overwrites top-level id with session ID; refresh_token string. It is identity establishment, not a new-password result. For an existing resource relationship, confirm is false despite global user confirmation true; without that relationship, the global confirmation fallback applies.

Example

Exchange the received reset code for a session; set the new password separately. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/confirm-password" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"code":"EXAMPLE_RESET_CODE"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/confirm-password", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "code": "EXAMPLE_RESET_CODE"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/confirm-password")
body = {'code': 'EXAMPLE_RESET_CODE'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
  "confirm": false
}

Alternate result

No reset record matches the supplied code. Request a new reset code rather than treating this as a password update.

HTTP 422 response excerpt:

{
  "error": "invalid_reset_code",
  "error_description": "Your confirmation code has expired. Please request a new one."
}

Recovery

HTTP statusAPI codeCauseNext action
409invalid_reset_codeEmpty code or inactive record.Request a current code through reset initiation; do not reuse an inactive record.
422invalid_reset_codeNo matching reset record.Request a new code.
406update_user_failPassword/account update fails.Contact support and check account state before repeating.
404resource_not_existsResource missing.Correct the selected resource public key.

See identity context and shared errors for checks that apply before this operation.

Next task

Set the new resource password using the returned Wallkit session token in token and the same resource public key; for a Firebase-enabled member context, reset has cleared the relationship Firebase UID, so first resolve the configured identity/link context before relying on matching Firebase credentials. No uninterrupted provider-member continuation is guaranteed. The initial-password operation requires an existing resource relationship with no stored resource password, plus password/password_confirm. Reset-code confirmation clears applicable passwords and establishes a session; it does not set the replacement password. Read the password operation’s provider/default-setting effects before calling it.

Request a password reset

POST /api/v1/reset-password

Initiate recovery for an existing email. This POST saves a reset record and dispatches a reset_password event. It does not change the password or prove email delivery.

Before you call

Resource public key required; email must identify an active global user. The reset count check is per user across the preceding hour.

Request

JSON or form; form takes precedence. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringrequiredPublic resource key; preserve intended member/code/resource context.
emailbodystringrequiredValid nonempty email, max60; normalized for account lookup.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
resultbooleanReset record/event requested. Not password completion or confirmed mail delivery.

Example

Request a reset for reader@example.com. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/reset-password" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"reader@example.com"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/reset-password", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "email": "reader@example.com"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/reset-password")
body = {'email': 'reader@example.com'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "result": true
}

Alternate result

No global user matches the requested email. Check the intended account; no reset was requested through this branch.

HTTP 409 response excerpt:

{
  "error": "invalid_email",
  "error_description": "Requested e-mail not found"
}

Recovery

HTTP statusAPI codeCauseNext action
409invalid_emailInvalid input or no matching email.Check email syntax/identity and resource context; do not assume success.
409auth_access_failInactive global user.Resolve account suspension with administrator.
406requests_limit_exceededAt least 10 reset records for user in preceding hour.Stop repeated initiation; wait for the count window or contact support. No retry-after value is established.
404resource_not_existsResource missing.Correct public resource key.

See identity context and shared errors for checks that apply before this operation.

Next task

Use the code received through the existing reset delivery flow to establish the reset session; initiation alone does not reset a password.

Request another confirmation message

POST /api/v1/resend-confirmation

Request confirmation for the current member’s email. This POST saves a confirmation record and dispatches a resend_confirmation event. Success means requested, not delivered or confirmed.

Before you call

Required member token/resource relationship. Email must still be unconfirmed for the resource.

To send the confirmation message, the integration administrator must configure the resend_confirmation event’s mail handler and template. See the operator Automations guide for event and email configuration. This setup is separate from requesting or completing confirmation.

Request

No request body. Response is JSON. Guest ACL permits this action, but it explicitly requires active user/resource context.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringrequiredPublic resource key; preserve intended member/code/resource context.
tokenheaderstringresolved member sessionExisting Wallkit session token.
firebase-tokenheaderstringFirebase-enabled memberConfigured Firebase ID token alongside Wallkit token.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
resultbooleanConfirmation request created/event dispatched; no delivery guarantee.

Example

Request another confirmation for the resolved member. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/resend-confirmation" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "token: ${USER_TOKEN}"

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/resend-confirmation", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      token: process.env.USER_TOKEN,

    }
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/resend-confirmation")
request = Request(
    url,
    headers={"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "result": true
}

Alternate result

The current resource relationship is already confirmed. Continue the confirmed account flow.

HTTP 409 response excerpt:

{
  "error": "already_confirmed",
  "error_description": "The user has already confirmed the email."
}

Recovery

HTTP statusAPI codeCauseNext action
409already_confirmedResource email already confirmed.Continue the confirmed account flow rather than requesting another message.
429requests_limit_exceededAt least 5 records per user/resource during preceding hour.Stop repeated requests; allow the count window to pass or contact support.
401auth_failed / auth_access_failRequired identity missing or restricted.Supply existing member context or resolve inactive/locked account with administrator.
404resource_not_existsMissing resource.Correct resource public key.

If the request is accepted but no message arrives, ask the integration administrator to check the configured event, template and mail integration. Another accepted request does not prove delivery; avoid repeated requests while investigating.

See identity context and shared errors for checks that apply before this operation.

Next task

Confirm with the code received through the configured message flow.

Confirm an email code

POST /api/v1/confirm-email

Complete the matching confirmation record. This POST can update the global email, save global/resource confirmation, update configured Firebase email and mark the confirmation used; it dispatches a confirmed_email event. No session token is returned.

Before you call

Use a code supplied by the existing registration/resend/email-change confirmation flow. The code’s record selects its resource/user; no member token requirement is added by this action.

Request

JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringintegration contextPublic resource key; preserve intended member/code/resource context.
codebodystringrequired, nonemptyConfirmation hash; trimmed. Distinct from reset or OAuth code.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
resultbooleanConfirmation completed through this action, not a new sign-in token.

Example

Submit the email-confirmation code received through the configured flow. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/confirm-email" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"code":"EXAMPLE_EMAIL_CONFIRMATION_CODE"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/confirm-email", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "code": "EXAMPLE_EMAIL_CONFIRMATION_CODE"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/confirm-email")
body = {'code': 'EXAMPLE_EMAIL_CONFIRMATION_CODE'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "result": true
}

Alternate result

The submitted confirmation code is empty. Supply the code received by the configured confirmation flow.

HTTP 422 response excerpt:

{
  "error": "invalid_confirm_code_format",
  "error_description": "Confirmation code incorrect format"
}

Recovery

HTTP statusAPI codeCauseNext action
400incorrect_dataMissing JSON.Send JSON code.
422invalid_confirm_code_format / invalid_confirm_codeEmpty/unknown confirmation hash.Use the received code or request a new confirmation.
409invalid_already_activatedRecord already confirmed.Continue the confirmed account flow; do not promise repeat success.
409invalid_confirm_codeUser/reference/save failure or new email already used.Check intended account/email with administrator.
406requests_limit_exceededIP flood check rejects request.Stop repeated calls and contact support if unexpected.
406update_user_failEmail/provider update fails.Check current account state with support; no cross-provider rollback guarantee.

See identity context and shared errors for checks that apply before this operation.

Next task

Establish member identity through the configured sign-in flow when needed; confirmation returns no session.

Validate email availability in a resource

POST /api/v1/email-validation

Check a prospective registration email against resource availability/domain policy. Validation may dispatch configured domain-policy notifications and records request activity. It is not sign-in or reservation of an email.

Before you call

Required resource context. An email already linked in this resource is rejected by validation rather than a normal exists_in_resource:true success recipe.

Request

JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringrequiredPublic resource key; preserve intended member/code/resource context.
emailbodystringrequiredValid nonempty email; normalized for lookup.
subscription_idbodyinteger IDoptionalPolicy context for an existing paid Pricing’s domain-policy exception; no registration/purchase occurs.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
existsbooleanGlobal account exists after input/resource validation passes.
exists_in_resourcebooleanRelated account in resource; already-linked inputs normally fail validation first. No identity proof.

Example

Check new-reader@example.com before choosing registration. See identity context for configuration and sample conventions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/email-validation" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"email":"new-reader@example.com"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/email-validation", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "email": "new-reader@example.com"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/email-validation")
body = {'email': 'new-reader@example.com'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "exists": false,
  "exists_in_resource": false
}

Alternate result

The email is already linked to this resource and fails availability validation. Use sign-in instead of presenting it as an available registration email.

HTTP 422 response excerpt:

{
  "error": "invalid_email",
  "error_description": "This email is already used."
}

Recovery

HTTP statusAPI codeCauseNext action
406incorrect_dataMissing JSON.Send valid JSON email.
422invalid_emailBad email, already-resource-linked email or prohibited domain.Use existing sign-in for a linked account; check domain policy with administrator.
406requests_limit_exceededResource/IP flood check rejects.Stop repeated checks; contact support if needed.
404resource_not_existsResource missing.Correct public resource key.

See identity context and shared errors for checks that apply before this operation.

Next task

Register only after availability/policy acceptance; this read does not reserve the address.

Exchange an ordinary authorization code

POST /api/v1/oauth/token

Exchange a resource-bound Wallkit authorization code for member credentials. This POST creates session/refresh records, records code authorization and deletes the code after success. Perform the client-secret exchange in trusted server code.

Before you call

Use a code from the existing code-mode identity flow, resource public client_id and server-only client_secret. Redirect must match established resource-host configuration. Do not send this secret from browser code.

Request

JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringintegration contextPublic resource key; preserve intended member/code/resource context.
codebodystringrequiredExisting matching resource code; validator rejects expiry.
grant_typebodystringrequiredUse authorization_code. Although refresh_token passes inclusion validation, this action still follows code exchange; it does not establish a refresh-token grant.
redirect_uribodystringrequiredEstablished resource-host destination; validated.
client_idbodystringrequiredResource public key selecting code/client context.
client_secretbodystringrequired; server-onlyResource secret validated against selected resource.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
user/session/refreshmerged top-levelresource-aware user and relationships without last_action plus session projection; id is overwritten by session ID. User projection resource follows header context, while exchanged session follows client_id resource: keep them consistent. refresh_token string; no token_type or session_id addition from this serializer.

Example

For this synthetic scenario, RESOURCE_KEY corresponds to EXAMPLE_RESOURCE_PUBLIC_KEY, and the callback belongs to the configured resource host. Replace both client and header context consistently in trusted server code. See runtime assumptions.

cURL

curl -X POST "${WALLKIT_API_BASE}/api/v1/oauth/token" \
  -H "resource: ${RESOURCE_KEY}" \
  -H "Content-Type: application/json" \
  --data '{"code":"EXAMPLE_AUTHORIZATION_CODE","grant_type":"authorization_code","redirect_uri":"https://example.com/callback","client_id":"EXAMPLE_RESOURCE_PUBLIC_KEY","client_secret":"EXAMPLE_RESOURCE_SECRET_DO_NOT_USE"}'

JavaScript

// Node.js 18+; built-in fetch.
async function main() {
  const url = new URL("/api/v1/oauth/token", process.env.WALLKIT_API_BASE);
  const response = await fetch(url, {
    method: "POST",
    headers: {
      resource: process.env.RESOURCE_KEY,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
  "code": "EXAMPLE_AUTHORIZATION_CODE",
  "grant_type": "authorization_code",
  "redirect_uri": "https://example.com/callback",
  "client_id": "EXAMPLE_RESOURCE_PUBLIC_KEY",
  "client_secret": "EXAMPLE_RESOURCE_SECRET_DO_NOT_USE"
})
  });
  console.log(response.status, await response.json());
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/oauth/token")
body = {'code': 'EXAMPLE_AUTHORIZATION_CODE', 'grant_type': 'authorization_code', 'redirect_uri': 'https://example.com/callback', 'client_id': 'EXAMPLE_RESOURCE_PUBLIC_KEY', 'client_secret': 'EXAMPLE_RESOURCE_SECRET_DO_NOT_USE'}
request = Request(
    url,
    data=json.dumps(body).encode("utf-8"),
    headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
    method="POST",
)
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "id": 3001,
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
  "refresh_token": "EXAMPLE_WALLKIT_REFRESH_TOKEN"
}

Alternate result

The code is unavailable for this resource exchange. Obtain a current code through the existing flow; do not treat rejection as successful token issuance.

HTTP 409 response excerpt:

{
  "error": "invalid_code",
  "error_description": "Incorrect code"
}

Recovery

HTTP statusAPI codeCauseNext action
406incorrect_dataMissing JSON.Send JSON in trusted server code.
409invalid_<field> / invalid_codeRequired/client-secret/redirect/code/expiry validation fails.Correct the named existing client/code configuration; obtain a new code when stale or consumed.
401auth_access_failInactive user.Resolve account state with administrator.

See identity context and shared errors for checks that apply before this operation.

Next task

Use the returned Wallkit token for member requests in the same resource context.

Establish identity through external authentication

GET /api/v1/auth/external/{token}

Use the existing external-identity integration to obtain Wallkit member context. This GET calls the configured external auth URL and can create/update users, resource/default membership, sessions, extra data and configured Firebase/Firestore records; it records login/signup activity. No read-only, one-use or expiry guarantee for the external token is established here.

Before you call

Required resource and configured external_auth_url. Obtain the external token through that integration’s own flow; it is not an existing Wallkit token or Firebase ID token. External service must return acceptable identity data.

Request

No request body. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.

NameLocationTypeRequirement / defaultMeaning and constraint
resourceheaderstringrequiredPublic resource key; preserve intended member/code/resource context.
tokenpathstringrequiredExternal credential, URL-encoded as one path segment; do not use a Wallkit session token here.

Result

HTTP 200 JSON.

Field / projectionType / presenceMeaning
tokenstringNew Wallkit member-session token.
firebase_custom_tokenstring; conditionalConfigured Firebase custom token; not an ID token. Absent when service is inactive. No full user/expiry/refresh projection returned.

Example

Exchange the external integration’s credential for a Wallkit token. See identity context for configuration and sample conventions.

cURL

curl "${WALLKIT_API_BASE}/api/v1/auth/external/EXAMPLE_EXTERNAL_AUTH_TOKEN" \
  -H "resource: ${RESOURCE_KEY}"

JavaScript

// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
  const url = new URL("/api/v1/auth/external/EXAMPLE_EXTERNAL_AUTH_TOKEN", process.env.WALLKIT_API_BASE);
  const headers = { resource: process.env.RESOURCE_KEY };
  const response = await fetch(url, { method: "GET", headers });
  const body = await response.json();
  console.log(response.status, body);
}
main().catch(console.error);

Python

# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen

url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/auth/external/EXAMPLE_EXTERNAL_AUTH_TOKEN")
headers = {"resource": os.environ["RESOURCE_KEY"]}
request = Request(url, headers=headers, method="GET")
try:
    with urlopen(request) as response:
        print(response.status, json.load(response))
except HTTPError as error:
    print(error.code, json.load(error))

HTTP 200 response excerpt:

{
  "token": "EXAMPLE_WALLKIT_SESSION_TOKEN"
}

Alternate result

No external auth URL is configured for this resource. Ask the administrator to configure that existing integration before attempting external identity.

HTTP 409 response excerpt:

{
  "error": "empty_external_auth_url",
  "error_description": "Empty external auth url"
}

Recovery

HTTP statusAPI codeCauseNext action
409resource_requiredNo resource context.Supply correct public resource key.
409invalid_emailExternal payload email invalid.Ask the external integration owner to correct identity data.
409empty_external_auth_urlResource external URL unset.Ask administrator to configure the existing external identity integration.
409external_auth_errorExternal request/response or identity orchestration failure.Contact integration owner/support; inspect account state before repeating write-producing GET.

See identity context and shared errors for checks that apply before this operation.

Next task

Use the returned member token for the content decision, keeping external/provider credentials separate.

Full diagram

Use the arrow keys to scroll. Escape closes this view.

Search documentation

Enter at least 2 characters.

    ↑ ↓ move through results · Enter opens · Escape closes