Ordinary Wallkit identity
Use authorization for email/password sign-in, or social-authorization for an already linked provider identity. Use registration to add a member to a resource. Confirmation and reset have separate code flows. OAuth and external authentication use an already configured integration. Firebase identity is separate. Follow the ordinary identity-to-access guide to connect member context to content permission.
Choose the identity context
Use the API base and resource public key supplied for the integration. The request table for each operation distinguishes guest input, member credentials, authorization/reset/confirmation codes and server-only client secrets. Keep these credentials separate. Firebase identity uses its own flow.
Shared context errors apply where initialization, permission and session checks run; an operation’s exclusions do not guarantee session or provider success. The examples are synthetic; see sample runtimes.
Operations
| Operation | Method / path |
|---|---|
| Sign in with email and password | POST /api/v1/authorization |
| Refresh an existing Wallkit credential | POST /api/v1/authorization/refresh |
| Log out the resolved session | GET /api/v1/logout |
| Sign in through an existing social account | POST /api/v1/social-authorization |
| Register a resource member | POST /api/v1/registration |
| Confirm a reset code and establish a session | POST /api/v1/confirm-password |
| Request a password reset | POST /api/v1/reset-password |
| Request another confirmation message | POST /api/v1/resend-confirmation |
| Confirm an email code | POST /api/v1/confirm-email |
| Validate email availability in a resource | POST /api/v1/email-validation |
| Exchange an ordinary authorization code | POST /api/v1/oauth/token |
| Establish identity through external authentication | GET /api/v1/auth/external/{token} |
Sign in with email and password
POST /api/v1/authorization
Establish a Wallkit member session for an existing account. Use this ordinary flow for an integration whose identity configuration uses Wallkit email/password. Choose the resource context your integration supplies; a password for one resource may differ from the global account password. This call does not register a new global account.
Sign-in creates a session and records login activity. It can attach an existing user to the selected resource, add its configured default subscription and merge earlier guest content access. Resource device/compromised-session policies can affect other sessions or lock the resource relationship. It also changes refresh-token records; the returned refresh value is not guaranteed reusable by this path. Do not treat sign-in as a read or promise that repeating it is harmless.
Before you call
Use the API base/resource public key supplied by the integration and an existing member’s email/password. The global account must be active and any existing resource relationship must not be locked or suspended. Guest permission permits the sign-in action; no existing Wallkit member token is required for the ordinary request. A resource is the publication/integration context, not a user credential.
The action can run without a resolved resource for the ordinary token branch; supply the correct resource for scoped identity/password/relationship behavior. Code/code_and_token responses need a resource. This guide’s ordinary example assumes Firebase authentication is disabled for that resource; Firebase-enabled initialization follows its separate identity configuration.
Request
Accepts application/json or form fields (application/x-www-form-urlencoded). Form fields take precedence when present; send one encoding. The example uses JSON. Response media type is JSON.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | supplied integration context | Public resource key selecting scoped sign-in; not the secret. Not an action-level mandatory-resource guard for default token mode. |
session | header | string | optional | Existing guest-session identifier when the integration intends to merge earlier guest content access. Not a password or member token. |
source-type | header | string | optional | Integration session-source label; do not infer a fixed accepted enum. |
email | body | string | required, nonempty valid email | Existing account email; trimmed/lowercased before lookup. |
password | body | string | required, nonempty | Existing resource password when configured, otherwise global account password; trimmed. No registration password-length rule implied here. |
response_type | body | string | optional, default token | token, code or code_and_token when paired with nonempty redirect_uri validation. Unsupported combinations are not a supported recipe; omit for ordinary session mode. |
redirect_uri | body | string | conditional redirect/code flow | Validated together with nonempty response_type; existing resource host/configuration controls permitted redirect input. It adds a destination to JSON; no HTTP redirect. |
Result
HTTP 200 returns the ordinary sign-in fields and resource-aware user at the top level. A token-mode result includes token, expiration, refresh value and session details along with the complete user projection. Use the returned token in the custom token header on member API requests; token_type:bearer does not introduce a Bearer Authorization header.
The session’s expires is Unix seconds, not a guaranteed usable lifetime. The returned refresh value does not establish a reusable refresh session on this sign-in path; handle refresh rejection with the integration’s existing sign-in flow rather than assuming automatic refresh succeeds.
Example: establish a reader session
reader@example.com is an existing active member in the selected ordinary Wallkit resource. These requests use the same JSON fields. Supply WALLKIT_API_BASE (scheme/host only) and RESOURCE_KEY from the existing integration. See sample runtimes.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/authorization" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/authorization", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"email": "reader@example.com",
"password": "EXAMPLE_PASSWORD_DO_NOT_USE"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/authorization")
body = {'email': 'reader@example.com', 'password': 'EXAMPLE_PASSWORD_DO_NOT_USE'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"id": 1001,
"email": "reader@example.com",
"active": true,
"token_type": "bearer",
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
"refresh_token": "EXAMPLE_WALLKIT_REFRESH_TOKEN",
"session_id": 3001,
"subscriptions": [],
"teams": []
}
The session token establishes member context. Empty subscriptions/teams do not deny or grant the article: obtain the actual content access decision. Expiration, profile and conditional relationships are omitted from this excerpt but defined in the linked object tables.
Alternate result: credentials rejected
For an unknown account email, HTTP 401 can return this excerpt:
{
"error": "authorization_fail",
"error_description": "Wrong email or password.",
"req_guid": "example-request"
}
Do not create a logged-in UI or proceed to member access calls. Check the user-supplied identity and correct resource context. The same code also covers wrong password and account restrictions; interpret the explanation without promising an account-existence check from this error.
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 409 | invalid_email / invalid_password | Missing/malformed required input. | Supply nonempty email/password; correct email syntax. |
| 409 | invalid_response_type / invalid_redirect_uri | Paired redirect/code inputs fail validation. | Use an established resource-host redirect configuration and supported response type, or omit both for ordinary token sign-in. |
| 401 | authorization_fail | Unknown email or wrong password. | Check credentials and selected resource password context; use the documented reset flow if needed when that operation is available. |
| 401 | authorization_fail | Inactive global account or locked/suspended resource relationship. | Ask the integration administrator to resolve that account state; repeating sign-in does not repair it. |
| 401 | exception | Sign-in orchestration fails. | Contact the administrator/support with req_guid. Do not assume session or relationship writes were rolled back. |
| 409 | initialize_failed | Integration context initialization fails. | Check resource/identity configuration with the administrator; provide req_guid to support. |
| 401 / 403 | access | Shared role/action checks reject context. | Check the identity mode and permitted action context; do not substitute an elevated secret. |
Next task
Follow ordinary identity to content access to place the returned session token in the member request and handle allow:false separately from sign-in failure.
Refresh an existing Wallkit credential
POST /api/v1/authorization/refresh
Exchange a stored Wallkit refresh record for new authentication parameters. This POST creates credentials and normally deletes the submitted refresh record after issuance. Optional Firebase flags can contact the configured provider. It is not a Firebase refresh-token exchange.
Before you call
Use a refresh token backed by an existing Wallkit refresh record and the intended resource context. Ordinary password sign-in does not establish reuse of its returned refresh value. The default response mode creates a code and token and needs a resource; this example explicitly selects token mode.
Request
JSON or form; form fields take precedence. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | integration context | Public resource key; preserve intended member/code/resource context. |
| refresh_token | body | string | required, nonempty | Existing Wallkit refresh value; trimmed. |
| response_type | body | string | optional; code_and_token default | token, code or code_and_token; no action-level inclusion validator here. Use a supported mode. |
| reusable_refresh | body | JSON boolean | optional; false default | Only true boolean preserves the submitted record; form string true does not satisfy the strict type check. |
| redirect_uri | body | string | conditional code response | With nonempty response_type and code mode, adds JSON destination; this action does not apply sign-in redirect validation. |
| with_firebase_token | body | truthy input | optional | Requests Firebase ID token when configured and linked; failures can omit it. |
| with_firebase_custom_token | body | truthy input | optional | Requests Firebase custom token, not ID token; failures can omit it. |
| with_has_resource_password | body | truthy input | optional | Adds whether the selected resource relationship has a password. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| auth fields | mode-dependent | authentication fields only; no user profile in this response. Its refresh value is created by this exchange; no automatic success/lifetime guarantee. |
| firebase-token, firebase-custom-token | string; requested and available | Firebase ID/custom tokens respectively; may be omitted on caught provider/configuration failure. |
| has-resource-password | boolean; requested | Presence of a selected resource password. |
Example
Exchange the existing Wallkit refresh value in token mode. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/authorization/refresh" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"refresh_token":"EXAMPLE_EXISTING_REFRESH_TOKEN","response_type":"token"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/authorization/refresh", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"refresh_token": "EXAMPLE_EXISTING_REFRESH_TOKEN",
"response_type": "token"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/authorization/refresh")
body = {'refresh_token': 'EXAMPLE_EXISTING_REFRESH_TOKEN', 'response_type': 'token'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"token_type": "bearer",
"token": "EXAMPLE_NEW_WALLKIT_TOKEN",
"refresh_token": "EXAMPLE_NEW_REFRESH_TOKEN"
}
Alternate result
A supplied refresh value has no stored record. Re-establish identity; do not automatically reuse the ordinary sign-in refresh value.
HTTP 406 response excerpt:
{
"error": "incorrect_refresh_token",
"error_description": "Incorrect refresh token."
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 406 | incorrect_refresh_token | Missing or unknown refresh record. | Use the existing identity flow for a valid refresh value or sign in again; do not loop retries. |
| 404 | incorrect_refresh_token | Refresh record has no related user. | Re-establish identity and ask support to inspect the stale record. |
| 401 | incorrect_refresh_token | Credential construction fails. | Check resource/mode configuration; re-establish identity if necessary. |
See identity context and shared errors for checks that apply before this operation.
Next task
If refresh is rejected, sign in again. After successful refresh, use the returned member token for the access decision.
Log out the resolved session
GET /api/v1/logout
End the resolved Wallkit session. This GET changes session state and records logout activity. With resource setting remove_all_session_on_logout (default true), it also deletes other sessions for the user in this resource; it does not promise global/provider logout.
Before you call
Supply an existing session token and matching resource context. The shared session check is excluded for this controller, but a session must still resolve.
Request
No request body. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | integration context | Public resource key; preserve intended member/code/resource context. |
| token | header | string | resolved member session | Existing Wallkit session token. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| result | boolean | Resolved session marked inactive; no account deletion or provider revocation is established. |
Example
End the resolved member session. See identity context for configuration and sample conventions.
cURL
curl "${WALLKIT_API_BASE}/api/v1/logout" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/logout", process.env.WALLKIT_API_BASE);
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/logout")
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"result": true
}
Alternate result
No session resolves from the supplied context. Clear unusable local session state and use the existing sign-in flow.
HTTP 401 response excerpt:
{
"error": "incorrect_token",
"error_description": "Incorrect token"
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 401 | incorrect_token | No resolved session. | Clear unusable local session state and use the appropriate identity flow; a resource key alone is insufficient. |
See identity context and shared errors for checks that apply before this operation.
Next task
Sign in through the configured identity flow when the member returns.
Sign in through an existing social account
POST /api/v1/social-authorization
Establish Wallkit identity from an existing linked Google or Facebook account. This POST calls the selected provider and creates a Wallkit session, can attach a resource/default membership and merge guest access, and records login activity. It does not create an unlinked social account.
Before you call
Use the provider account ID/access token obtained by the existing integration’s provider flow. The Wallkit account must already carry that social ID and be active/unrestricted. Provider compatibility is not verified here.
Request
JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | integration context | Public resource key; preserve intended member/code/resource context. |
| method | body | string | required outer field | google or facebook; these are the implemented account branches. |
| data | body | object | optional | When supplied, nested object contains all fields below; method remains outer. |
| id | body | string | necessary supported branch | Existing linked provider account identifier. |
| access_token | body | string | necessary provider check | Provider access token, not Wallkit token. |
| response_type | body | string | optional; token default | token/code/code_and_token modes, read inside data when nested. |
| redirect_uri | body | string | conditional | Adds JSON destination for code modes when both inputs nonempty; no sign-in-style redirect validator here. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| user and auth | top-level object | resource-aware user and relationships plus mode-dependent authentication fields. Unlike ordinary password sign-in, no all-user refresh cleanup is performed here; credential lifetime/reuse still depends on later state/checks. |
Example
Sign in with the already-linked Google identity. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/social-authorization" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"method":"google","data":{"id":"EXAMPLE_GOOGLE_ACCOUNT_ID","access_token":"EXAMPLE_GOOGLE_ACCESS_TOKEN"}}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/social-authorization", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"method": "google",
"data": {
"id": "EXAMPLE_GOOGLE_ACCOUNT_ID",
"access_token": "EXAMPLE_GOOGLE_ACCESS_TOKEN"
}
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/social-authorization")
body = {'method': 'google', 'data': {'id': 'EXAMPLE_GOOGLE_ACCOUNT_ID', 'access_token': 'EXAMPLE_GOOGLE_ACCESS_TOKEN'}}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"id": 1001,
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
"token_type": "bearer"
}
Alternate result
The supplied Google ID is not linked to a Wallkit account. Use the existing linking/registration flow rather than retrying provider sign-in.
HTTP 401 response excerpt:
{
"error": "account_error",
"error_description": "You dont have google account"
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 400 | incorrect_data | Missing JSON/method. | Send the outer method and appropriate JSON account fields. |
| 401 | account_error | Provider ID is not linked to a Wallkit account. | Use the integration’s account-linking/registration flow instead of assuming this call registers it. |
| 406 | invalid_social_id | Provider-confirmed ID differs. | Obtain matching provider ID/access token from the existing provider flow. |
| 401 | authorization_fail | Account inactive or resource relationship locked/suspended. | Resolve account state with the administrator. |
| 401 | exception | Identity orchestration fails. | Contact support with req_guid; do not assume earlier writes were undone. |
See identity context and shared errors for checks that apply before this operation.
Next task
Use the Wallkit token for the member access step after provider identity succeeds.
Register a resource member
POST /api/v1/registration
Create or reuse a global user and attach them to this resource. This POST saves user/resource/session/confirmation records, may attach default/invited membership, queue confirmation/marketing events and call configured social/Firebase/Firestore services. It is not a confirmed-email or completed-payment guarantee. A validation response does not establish that no later writes occurred.
Before you call
Resource context is required. Use a new-to-resource email that satisfies resource domain policy, an ordinary password with matching confirmation, or the distinct guest_email branch. This example uses password registration without invite/provider extras.
Request
JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | required | Public resource key; preserve intended member/code/resource context. |
| body | string | required | Valid email, length5–60; uniqueness in resource and domain policy apply. | |
| password | body | string | ordinary branch | Length6–40, nonempty; trimmed before storing resource password. |
| password_confirm | body | string | ordinary branch | Must match password. |
| guest_email | body | string | optional alternate branch | Nonempty value replaces email and bypasses password requirement; initial email validation still applies. Missing country may be derived from location. |
| nick_name | body | string | optional | Nickname validation applies; stored nickname is not guaranteed to equal supplied value. Avoid relying on it without reading returned profile. |
| subscription_id | body | ID or IDs accepted by validator | optional | Existing Pricing IDs validated; response may echo selected ID. This input alone is not proof of a new paid membership. |
| invite | body | string | optional | Existing invite validated for email/resource and can activate team/Pricing relationships. |
| first_name, last_name, country, company, job, phone | body | strings | optional; max120 each | Stored profile text. |
| city, state | body | strings | optional; max50 each | Profile location text. |
| zip | body | string | optional; max20 | Postal text. |
| ip | body | string | optional; max15 | Stored IP input, otherwise inferred request IP; no IP validity guarantee. |
| facebook_id, google_id | body | strings | optional; max120 | Provider ID; checks duplicates and provider correspondence when nonnull. |
| social_token | body | string | conditional social IDs | Provider credential for matching email/ID checks, not Wallkit session token. |
| extra | body | object | optional | Resource-specific extra properties; extra.firestore can supply configured Firestore data. |
| campaignmonitor | body | object | optional | subscriptions list feeds configured synchronization event; no delivery/synchronization completion promise. |
Result
HTTP 201 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| user/session/refresh | merged top-level fields | resource-aware user and relationships without last_action, plus session projection and refresh_token string. Here the later user merge makes id the user ID, not session ID. |
| subscription_id | stored ID / integer; conditional | Invite Pricing ID or supplied subscription ID; not a purchase/membership proof. |
Example
Register new-reader@example.com in this resource. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/registration" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"new-reader@example.com","password":"EXAMPLE_PASSWORD_DO_NOT_USE","password_confirm":"EXAMPLE_PASSWORD_DO_NOT_USE"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/registration", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"email": "new-reader@example.com",
"password": "EXAMPLE_PASSWORD_DO_NOT_USE",
"password_confirm": "EXAMPLE_PASSWORD_DO_NOT_USE"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/registration")
body = {'email': 'new-reader@example.com', 'password': 'EXAMPLE_PASSWORD_DO_NOT_USE', 'password_confirm': 'EXAMPLE_PASSWORD_DO_NOT_USE'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 201 response excerpt:
{
"id": 1001,
"email": "new-reader@example.com",
"confirm": false,
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN"
}
Alternate result
The email is already linked in this resource. Use the existing sign-in flow.
HTTP 409 response excerpt:
{
"error": "invalid_email",
"error_description": "This email is already used."
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 400 | incorrect_data | No JSON body. | Send supported JSON fields. |
| 422 | invalid_<field> | Input validation fails. | Correct named fields; inspect existing profile state before retrying because this response does not prove absence of later writes. |
| 409 | invalid_email | Email already linked in this resource. | Use the existing sign-in/account flow. |
| 400 | account_error | Social account already used. | Use the matching existing linked account flow. |
| 406 | invalid_email / invalid_social_id | Provider correspondence mismatch. | Obtain matching provider identity details. |
| 406 | team_registration_fail / incorrect_subscription / accept_invite_fail | Invite/team/Pricing processing fails. | Check configured invite/Pricing with administrator; do not infer provider effects rolled back. |
| 406 | registration_fail | Registration orchestration fails. | Contact support and inspect account state before repeating writes. |
| 404 | resource_not_exists | Required resource is unknown. | Correct public resource key and integration context. |
See identity context and shared errors for checks that apply before this operation.
Next task
Confirm a reset code and establish a session
POST /api/v1/confirm-password
Use an existing reset code to establish identity for a password-reset flow. This POST clears the resource password and, unless the user is an administrator anywhere, clears the global password; sets global user confirmation true, saves it, cleans refresh records and creates a session/refresh value. It does not accept or set a new password, and does not establish one-use invalidation of this code.
Before you call
Required resource context and an active stored code from the reset flow. No existing member token required. The code lookup itself is not resource-bound; keep the original intended context.
For an existing resource relationship, reset also sets resource confirmation false and clears its language, settings and Firebase UID. Global user confirmation becomes true, but the resource-aware response reads the relationship confirmation and therefore shows false for this scenario. Existing extra data is preserved. Clearing the Firebase UID can disrupt provider/member resolution; do not assume the newly issued session gives an uninterrupted Firebase-enabled flow.
Request
Use JSON. Apparent form compatibility is not a reliable contract for this action. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | required | Public resource key; preserve intended member/code/resource context. |
| code | body | string | required, nonempty | Existing reset code; trimmed. No new_password input. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| user/session/refresh | merged top-level | resource-aware user and relationships without last_action; session projection overwrites top-level id with session ID; refresh_token string. It is identity establishment, not a new-password result. For an existing resource relationship, confirm is false despite global user confirmation true; without that relationship, the global confirmation fallback applies. |
Example
Exchange the received reset code for a session; set the new password separately. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/confirm-password" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"code":"EXAMPLE_RESET_CODE"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/confirm-password", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"code": "EXAMPLE_RESET_CODE"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/confirm-password")
body = {'code': 'EXAMPLE_RESET_CODE'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
"confirm": false
}
Alternate result
No reset record matches the supplied code. Request a new reset code rather than treating this as a password update.
HTTP 422 response excerpt:
{
"error": "invalid_reset_code",
"error_description": "Your confirmation code has expired. Please request a new one."
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 409 | invalid_reset_code | Empty code or inactive record. | Request a current code through reset initiation; do not reuse an inactive record. |
| 422 | invalid_reset_code | No matching reset record. | Request a new code. |
| 406 | update_user_fail | Password/account update fails. | Contact support and check account state before repeating. |
| 404 | resource_not_exists | Resource missing. | Correct the selected resource public key. |
See identity context and shared errors for checks that apply before this operation.
Next task
Set the new resource password using the returned Wallkit session token in token and the same resource public key; for a Firebase-enabled member context, reset has cleared the relationship Firebase UID, so first resolve the configured identity/link context before relying on matching Firebase credentials. No uninterrupted provider-member continuation is guaranteed. The initial-password operation requires an existing resource relationship with no stored resource password, plus password/password_confirm. Reset-code confirmation clears applicable passwords and establishes a session; it does not set the replacement password. Read the password operation’s provider/default-setting effects before calling it.
Request a password reset
POST /api/v1/reset-password
Initiate recovery for an existing email. This POST saves a reset record and dispatches a reset_password event. It does not change the password or prove email delivery.
Before you call
Resource public key required; email must identify an active global user. The reset count check is per user across the preceding hour.
Request
JSON or form; form takes precedence. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | required | Public resource key; preserve intended member/code/resource context. |
| body | string | required | Valid nonempty email, max60; normalized for account lookup. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| result | boolean | Reset record/event requested. Not password completion or confirmed mail delivery. |
Example
Request a reset for reader@example.com. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/reset-password" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"reader@example.com"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/reset-password", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"email": "reader@example.com"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/reset-password")
body = {'email': 'reader@example.com'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"result": true
}
Alternate result
No global user matches the requested email. Check the intended account; no reset was requested through this branch.
HTTP 409 response excerpt:
{
"error": "invalid_email",
"error_description": "Requested e-mail not found"
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 409 | invalid_email | Invalid input or no matching email. | Check email syntax/identity and resource context; do not assume success. |
| 409 | auth_access_fail | Inactive global user. | Resolve account suspension with administrator. |
| 406 | requests_limit_exceeded | At least 10 reset records for user in preceding hour. | Stop repeated initiation; wait for the count window or contact support. No retry-after value is established. |
| 404 | resource_not_exists | Resource missing. | Correct public resource key. |
See identity context and shared errors for checks that apply before this operation.
Next task
Request another confirmation message
POST /api/v1/resend-confirmation
Request confirmation for the current member’s email. This POST saves a confirmation record and dispatches a resend_confirmation event. Success means requested, not delivered or confirmed.
Before you call
Required member token/resource relationship. Email must still be unconfirmed for the resource.
To send the confirmation message, the integration administrator must configure the resend_confirmation event’s mail handler and template. See the operator Automations guide for event and email configuration. This setup is separate from requesting or completing confirmation.
Request
No request body. Response is JSON. Guest ACL permits this action, but it explicitly requires active user/resource context.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | required | Public resource key; preserve intended member/code/resource context. |
| token | header | string | resolved member session | Existing Wallkit session token. |
| firebase-token | header | string | Firebase-enabled member | Configured Firebase ID token alongside Wallkit token. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| result | boolean | Confirmation request created/event dispatched; no delivery guarantee. |
Example
Request another confirmation for the resolved member. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/resend-confirmation" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/resend-confirmation", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
token: process.env.USER_TOKEN,
}
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/resend-confirmation")
request = Request(
url,
headers={"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"result": true
}
Alternate result
The current resource relationship is already confirmed. Continue the confirmed account flow.
HTTP 409 response excerpt:
{
"error": "already_confirmed",
"error_description": "The user has already confirmed the email."
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 409 | already_confirmed | Resource email already confirmed. | Continue the confirmed account flow rather than requesting another message. |
| 429 | requests_limit_exceeded | At least 5 records per user/resource during preceding hour. | Stop repeated requests; allow the count window to pass or contact support. |
| 401 | auth_failed / auth_access_fail | Required identity missing or restricted. | Supply existing member context or resolve inactive/locked account with administrator. |
| 404 | resource_not_exists | Missing resource. | Correct resource public key. |
If the request is accepted but no message arrives, ask the integration administrator to check the configured event, template and mail integration. Another accepted request does not prove delivery; avoid repeated requests while investigating.
See identity context and shared errors for checks that apply before this operation.
Next task
Confirm with the code received through the configured message flow.
Confirm an email code
POST /api/v1/confirm-email
Complete the matching confirmation record. This POST can update the global email, save global/resource confirmation, update configured Firebase email and mark the confirmation used; it dispatches a confirmed_email event. No session token is returned.
Before you call
Use a code supplied by the existing registration/resend/email-change confirmation flow. The code’s record selects its resource/user; no member token requirement is added by this action.
Request
JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | integration context | Public resource key; preserve intended member/code/resource context. |
| code | body | string | required, nonempty | Confirmation hash; trimmed. Distinct from reset or OAuth code. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| result | boolean | Confirmation completed through this action, not a new sign-in token. |
Example
Submit the email-confirmation code received through the configured flow. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/confirm-email" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"code":"EXAMPLE_EMAIL_CONFIRMATION_CODE"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/confirm-email", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"code": "EXAMPLE_EMAIL_CONFIRMATION_CODE"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/confirm-email")
body = {'code': 'EXAMPLE_EMAIL_CONFIRMATION_CODE'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"result": true
}
Alternate result
The submitted confirmation code is empty. Supply the code received by the configured confirmation flow.
HTTP 422 response excerpt:
{
"error": "invalid_confirm_code_format",
"error_description": "Confirmation code incorrect format"
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 400 | incorrect_data | Missing JSON. | Send JSON code. |
| 422 | invalid_confirm_code_format / invalid_confirm_code | Empty/unknown confirmation hash. | Use the received code or request a new confirmation. |
| 409 | invalid_already_activated | Record already confirmed. | Continue the confirmed account flow; do not promise repeat success. |
| 409 | invalid_confirm_code | User/reference/save failure or new email already used. | Check intended account/email with administrator. |
| 406 | requests_limit_exceeded | IP flood check rejects request. | Stop repeated calls and contact support if unexpected. |
| 406 | update_user_fail | Email/provider update fails. | Check current account state with support; no cross-provider rollback guarantee. |
See identity context and shared errors for checks that apply before this operation.
Next task
Validate email availability in a resource
POST /api/v1/email-validation
Check a prospective registration email against resource availability/domain policy. Validation may dispatch configured domain-policy notifications and records request activity. It is not sign-in or reservation of an email.
Before you call
Required resource context. An email already linked in this resource is rejected by validation rather than a normal exists_in_resource:true success recipe.
Request
JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | required | Public resource key; preserve intended member/code/resource context. |
| body | string | required | Valid nonempty email; normalized for lookup. | |
| subscription_id | body | integer ID | optional | Policy context for an existing paid Pricing’s domain-policy exception; no registration/purchase occurs. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| exists | boolean | Global account exists after input/resource validation passes. |
| exists_in_resource | boolean | Related account in resource; already-linked inputs normally fail validation first. No identity proof. |
Example
Check new-reader@example.com before choosing registration. See identity context for configuration and sample conventions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/email-validation" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"email":"new-reader@example.com"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/email-validation", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"email": "new-reader@example.com"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/email-validation")
body = {'email': 'new-reader@example.com'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"exists": false,
"exists_in_resource": false
}
Alternate result
The email is already linked to this resource and fails availability validation. Use sign-in instead of presenting it as an available registration email.
HTTP 422 response excerpt:
{
"error": "invalid_email",
"error_description": "This email is already used."
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 406 | incorrect_data | Missing JSON. | Send valid JSON email. |
| 422 | invalid_email | Bad email, already-resource-linked email or prohibited domain. | Use existing sign-in for a linked account; check domain policy with administrator. |
| 406 | requests_limit_exceeded | Resource/IP flood check rejects. | Stop repeated checks; contact support if needed. |
| 404 | resource_not_exists | Resource missing. | Correct public resource key. |
See identity context and shared errors for checks that apply before this operation.
Next task
Register only after availability/policy acceptance; this read does not reserve the address.
Exchange an ordinary authorization code
POST /api/v1/oauth/token
Exchange a resource-bound Wallkit authorization code for member credentials. This POST creates session/refresh records, records code authorization and deletes the code after success. Perform the client-secret exchange in trusted server code.
Before you call
Use a code from the existing code-mode identity flow, resource public client_id and server-only client_secret. Redirect must match established resource-host configuration. Do not send this secret from browser code.
Request
JSON only. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | integration context | Public resource key; preserve intended member/code/resource context. |
| code | body | string | required | Existing matching resource code; validator rejects expiry. |
| grant_type | body | string | required | Use authorization_code. Although refresh_token passes inclusion validation, this action still follows code exchange; it does not establish a refresh-token grant. |
| redirect_uri | body | string | required | Established resource-host destination; validated. |
| client_id | body | string | required | Resource public key selecting code/client context. |
| client_secret | body | string | required; server-only | Resource secret validated against selected resource. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| user/session/refresh | merged top-level | resource-aware user and relationships without last_action plus session projection; id is overwritten by session ID. User projection resource follows header context, while exchanged session follows client_id resource: keep them consistent. refresh_token string; no token_type or session_id addition from this serializer. |
Example
For this synthetic scenario, RESOURCE_KEY corresponds to EXAMPLE_RESOURCE_PUBLIC_KEY, and the callback belongs to the configured resource host. Replace both client and header context consistently in trusted server code. See runtime assumptions.
cURL
curl -X POST "${WALLKIT_API_BASE}/api/v1/oauth/token" \
-H "resource: ${RESOURCE_KEY}" \
-H "Content-Type: application/json" \
--data '{"code":"EXAMPLE_AUTHORIZATION_CODE","grant_type":"authorization_code","redirect_uri":"https://example.com/callback","client_id":"EXAMPLE_RESOURCE_PUBLIC_KEY","client_secret":"EXAMPLE_RESOURCE_SECRET_DO_NOT_USE"}'
JavaScript
// Node.js 18+; built-in fetch.
async function main() {
const url = new URL("/api/v1/oauth/token", process.env.WALLKIT_API_BASE);
const response = await fetch(url, {
method: "POST",
headers: {
resource: process.env.RESOURCE_KEY,
"Content-Type": "application/json"
},
body: JSON.stringify({
"code": "EXAMPLE_AUTHORIZATION_CODE",
"grant_type": "authorization_code",
"redirect_uri": "https://example.com/callback",
"client_id": "EXAMPLE_RESOURCE_PUBLIC_KEY",
"client_secret": "EXAMPLE_RESOURCE_SECRET_DO_NOT_USE"
})
});
console.log(response.status, await response.json());
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/oauth/token")
body = {'code': 'EXAMPLE_AUTHORIZATION_CODE', 'grant_type': 'authorization_code', 'redirect_uri': 'https://example.com/callback', 'client_id': 'EXAMPLE_RESOURCE_PUBLIC_KEY', 'client_secret': 'EXAMPLE_RESOURCE_SECRET_DO_NOT_USE'}
request = Request(
url,
data=json.dumps(body).encode("utf-8"),
headers={"resource": os.environ["RESOURCE_KEY"], "Content-Type": "application/json"},
method="POST",
)
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"id": 3001,
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN",
"refresh_token": "EXAMPLE_WALLKIT_REFRESH_TOKEN"
}
Alternate result
The code is unavailable for this resource exchange. Obtain a current code through the existing flow; do not treat rejection as successful token issuance.
HTTP 409 response excerpt:
{
"error": "invalid_code",
"error_description": "Incorrect code"
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 406 | incorrect_data | Missing JSON. | Send JSON in trusted server code. |
| 409 | invalid_<field> / invalid_code | Required/client-secret/redirect/code/expiry validation fails. | Correct the named existing client/code configuration; obtain a new code when stale or consumed. |
| 401 | auth_access_fail | Inactive user. | Resolve account state with administrator. |
See identity context and shared errors for checks that apply before this operation.
Next task
Use the returned Wallkit token for member requests in the same resource context.
Establish identity through external authentication
GET /api/v1/auth/external/{token}
Use the existing external-identity integration to obtain Wallkit member context. This GET calls the configured external auth URL and can create/update users, resource/default membership, sessions, extra data and configured Firebase/Firestore records; it records login/signup activity. No read-only, one-use or expiry guarantee for the external token is established here.
Before you call
Required resource and configured external_auth_url. Obtain the external token through that integration’s own flow; it is not an existing Wallkit token or Firebase ID token. External service must return acceptable identity data.
Request
No request body. Response is JSON. Guest ACL permits the action, subject to the context and input requirements above.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
| resource | header | string | required | Public resource key; preserve intended member/code/resource context. |
| token | path | string | required | External credential, URL-encoded as one path segment; do not use a Wallkit session token here. |
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| token | string | New Wallkit member-session token. |
| firebase_custom_token | string; conditional | Configured Firebase custom token; not an ID token. Absent when service is inactive. No full user/expiry/refresh projection returned. |
Example
Exchange the external integration’s credential for a Wallkit token. See identity context for configuration and sample conventions.
cURL
curl "${WALLKIT_API_BASE}/api/v1/auth/external/EXAMPLE_EXTERNAL_AUTH_TOKEN" \
-H "resource: ${RESOURCE_KEY}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/auth/external/EXAMPLE_EXTERNAL_AUTH_TOKEN", process.env.WALLKIT_API_BASE);
const headers = { resource: process.env.RESOURCE_KEY };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/auth/external/EXAMPLE_EXTERNAL_AUTH_TOKEN")
headers = {"resource": os.environ["RESOURCE_KEY"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"token": "EXAMPLE_WALLKIT_SESSION_TOKEN"
}
Alternate result
No external auth URL is configured for this resource. Ask the administrator to configure that existing integration before attempting external identity.
HTTP 409 response excerpt:
{
"error": "empty_external_auth_url",
"error_description": "Empty external auth url"
}
Recovery
| HTTP status | API code | Cause | Next action |
|---|---|---|---|
| 409 | resource_required | No resource context. | Supply correct public resource key. |
| 409 | invalid_email | External payload email invalid. | Ask the external integration owner to correct identity data. |
| 409 | empty_external_auth_url | Resource external URL unset. | Ask administrator to configure the existing external identity integration. |
| 409 | external_auth_error | External request/response or identity orchestration failure. | Contact integration owner/support; inspect account state before repeating write-producing GET. |
See identity context and shared errors for checks that apply before this operation.