Skip to main content
Authentication and session management. Browser login goes through the server-rendered OIDC redirects (/v1/auth/login/{provider}); this resource covers the session, device flow (for CLIs), and self-service account security — all session-authenticated endpoints. Reach it as client.auth on a QumoClient.

verifyInvitation

Looks up the invitation an invite-link token belongs to. Public — no auth required. Types: InvitationData

getSession

Returns the caller’s session: user, active workspace and role. Types: Session

logout

Ends the caller’s session (session cookie or device-flow bearer token).

listProviders

Lists the OIDC/SSO providers advertised on the public login screen (plus “dev” when dev-login is compiled in). Public — no auth required. Types: OIDCProvider

verifyDeviceCode

Authorizes a pending device-flow code from an authenticated browser session (the second step of device login after the user is already logged in). 200 with no body on success.

deleteAccount

Permanently deletes the caller’s user account and clears the session cookie server-side. Irreversible.

completeOnboarding

Marks creator onboarding complete: the final action of the first-session wizard. Flips Session.onboarding_required to false on the next getSession call. Idempotent.

exportUserData

Exports the caller’s personal data (GDPR/self-service) as a JSON blob. The server sets Content-Disposition: attachment, but we return the body as a Blob rather than parsing it — the caller triggers a browser download. Uses QumoClient.requestRaw because the response is a file download, not a JSON object to parse.

listSessions

Lists the caller’s active sessions, marking the current one. Types: UserSession

revokeSession

Ends one of the caller’s other sessions, by the id handle from listSessions. The current session is ended with logout instead.

revokeOtherSessions

Ends every session of the caller except the current one.

setupTOTP

Starts TOTP enrolment: returns a provisional secret (as an otpauth:// URI) plus one-time backup codes. Nothing activates until enable(code) verifies a code from the user’s authenticator app. Types: TOTPSetup

enableTOTP

Verifies a code against the provisional secret and activates TOTP.

disableTOTP

Verifies a code and removes TOTP from the account.

verifyTOTPChallenge

Verifies a TOTP code submitted during the OIDC → TOTP challenge flow (the login screen, not account settings). On success the server mints a full session and sets the session cookie; 200 with no body. Distinct from enableTOTP/disableTOTP, which target the already-authenticated account routes under /v1/auth/totp/*.

disconnectGithub

Unlinks the caller’s GitHub identity (204, no body).

listPersonalTokens

Lists the caller’s active personal access tokens (metadata only). Types: PersonalToken

createPersonalToken

Creates a personal access token (qumo_pat_…), the credential to pass as token or QUMO_TOKEN in CI. Session-only: a token cannot mint tokens. value is returned once and never retrievable again. Types: CreatedPersonalToken

revokePersonalToken

Revokes one of the caller’s personal access tokens by id.

startDeviceFlow

Starts an OAuth device-flow sign-in (RFC 8628). Most callers want AuthResource.loginWithDeviceFlow, which also polls for the token. Types: DeviceCodeResponse

exchangeDeviceCode

Polls once for the device-flow token. Throws an APIError with authorization_pending until the user approves, or slow_down when polling too fast. Types: TokenResponse

getMemberships

Lists the workspaces the caller belongs to, with their role in each. Types: TenantMembership

loginWithDeviceFlow

Orchestrates OAuth 2.0 Device Flow login: starts the flow, surfaces the verification instructions via output, and polls the token endpoint until a token is returned (honouring authorization_pending / slow_down). Gives up with an expired_token error once the code’s expires_in has passed; any other server error (access_denied, …) is rethrown as is. Types: TokenResponse