/v1/auth/login/{provider}); this resource
covers the session, device flow (for CLIs), and self-service account
security — all session-authenticated endpoints.
Reach it as client.auth on a QumoClient.
verifyInvitation
InvitationData
getSession
Session
logout
listProviders
OIDCProvider
verifyDeviceCode
deleteAccount
completeOnboarding
Session.onboarding_required to false on the next
getSession call. Idempotent.
exportUserData
Content-Disposition: attachment, but we return the body
as a Blob rather than parsing it — the caller triggers a browser
download. Uses QumoClient.requestRaw because the response is a
file download, not a JSON object to parse.
listSessions
UserSession
revokeSession
id handle from
listSessions. The current session is ended with logout instead.
revokeOtherSessions
setupTOTP
TOTPSetup
enableTOTP
disableTOTP
verifyTOTPChallenge
disconnectGithub
listPersonalTokens
PersonalToken
createPersonalToken
qumo_pat_…), the credential to pass as
token or QUMO_TOKEN in CI. Session-only: a token cannot mint tokens.
value is returned once and never retrievable again.
Types: CreatedPersonalToken
revokePersonalToken
startDeviceFlow
AuthResource.loginWithDeviceFlow, which also polls for the token.
Types: DeviceCodeResponse
exchangeDeviceCode
APIError with
authorization_pending until the user approves, or slow_down when
polling too fast.
Types: TokenResponse
getMemberships
TenantMembership
loginWithDeviceFlow
output, and polls the token endpoint until
a token is returned (honouring authorization_pending / slow_down).
Gives up with an expired_token error once the code’s expires_in has
passed; any other server error (access_denied, …) is rethrown as is.
Types: TokenResponse