> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# client.auth

> Authentication and session management.

Authentication and session management. Browser login goes through the
server-rendered OIDC redirects (`/v1/auth/login/{provider}`); this resource
covers the session, device flow (for CLIs), and self-service account
security — all session-authenticated endpoints.

Reach it as `client.auth` on a [`QumoClient`](/sdk/reference/client#qumoclient).

### verifyInvitation

```ts theme={null}
verifyInvitation(token: string): Promise<InvitationData>
```

Looks up the invitation an invite-link token belongs to. Public — no auth required.

Types: [`InvitationData`](/sdk/reference/types#invitationdata)

### getSession

```ts theme={null}
getSession(): Promise<Session>
```

Returns the caller's session: user, active workspace and role.

Types: [`Session`](/sdk/reference/types#session)

### logout

```ts theme={null}
logout(): Promise<void>
```

Ends the caller's session (session cookie or device-flow bearer token).

### listProviders

```ts theme={null}
listProviders(): Promise<OIDCProvider[]>
```

Lists the OIDC/SSO providers advertised on the public login screen
(plus "dev" when dev-login is compiled in). Public — no auth required.

Types: [`OIDCProvider`](/sdk/reference/types#oidcprovider)

### verifyDeviceCode

```ts theme={null}
verifyDeviceCode(userCode: string): Promise<void>
```

Authorizes a pending device-flow code from an authenticated browser
session (the second step of device login after the user is already logged
in). 200 with no body on success.

### deleteAccount

```ts theme={null}
deleteAccount(): Promise<{ status: string }>
```

Permanently deletes the caller's user account and clears the session
cookie server-side. Irreversible.

### completeOnboarding

```ts theme={null}
completeOnboarding(): Promise<{ status: string }>
```

Marks creator onboarding complete: the final action of the first-session
wizard. Flips `Session.onboarding_required` to false on the next
getSession call. Idempotent.

### exportUserData

```ts theme={null}
exportUserData(): Promise<Blob>
```

Exports the caller's personal data (GDPR/self-service) as a JSON blob.
The server sets `Content-Disposition: attachment`, but we return the body
as a `Blob` rather than parsing it — the caller triggers a browser
download. Uses [`QumoClient.requestRaw`](/sdk/reference/client#requestraw) because the response is a
file download, not a JSON object to parse.

### listSessions

```ts theme={null}
listSessions(): Promise<UserSession[]>
```

Lists the caller's active sessions, marking the current one.

Types: [`UserSession`](/sdk/reference/types#usersession)

### revokeSession

```ts theme={null}
revokeSession(id: string): Promise<void>
```

Ends one of the caller's other sessions, by the `id` handle from
listSessions. The current session is ended with logout instead.

### revokeOtherSessions

```ts theme={null}
revokeOtherSessions(): Promise<{ revoked: number }>
```

Ends every session of the caller except the current one.

### setupTOTP

```ts theme={null}
setupTOTP(): Promise<TOTPSetup>
```

Starts TOTP enrolment: returns a provisional secret (as an otpauth:// URI)
plus one-time backup codes. Nothing activates until enable(code) verifies
a code from the user's authenticator app.

Types: [`TOTPSetup`](/sdk/reference/types#totpsetup)

### enableTOTP

```ts theme={null}
enableTOTP(code: string): Promise<{ status: string }>
```

Verifies a code against the provisional secret and activates TOTP.

### disableTOTP

```ts theme={null}
disableTOTP(code: string): Promise<{ status: string }>
```

Verifies a code and removes TOTP from the account.

### verifyTOTPChallenge

```ts theme={null}
verifyTOTPChallenge(code: string): Promise<void>
```

Verifies a TOTP code submitted during the OIDC → TOTP challenge flow
(the login screen, not account settings). On success the server mints a
full session and sets the session cookie; 200 with no body. Distinct from
enableTOTP/disableTOTP, which target the already-authenticated account
routes under /v1/auth/totp/\*.

### disconnectGithub

```ts theme={null}
disconnectGithub(): Promise<void>
```

Unlinks the caller's GitHub identity (204, no body).

### listPersonalTokens

```ts theme={null}
listPersonalTokens(): Promise<PersonalToken[]>
```

Lists the caller's active personal access tokens (metadata only).

Types: [`PersonalToken`](/sdk/reference/types#personaltoken)

### createPersonalToken

```ts theme={null}
createPersonalToken(name: string, scopes: string[]): Promise<CreatedPersonalToken>
```

Creates a personal access token (`qumo_pat_…`), the credential to pass as
`token` or `QUMO_TOKEN` in CI. Session-only: a token cannot mint tokens.
`value` is returned once and never retrievable again.

Types: [`CreatedPersonalToken`](/sdk/reference/types#createdpersonaltoken)

### revokePersonalToken

```ts theme={null}
revokePersonalToken(id: string): Promise<void>
```

Revokes one of the caller's personal access tokens by id.

### startDeviceFlow

```ts theme={null}
startDeviceFlow(): Promise<DeviceCodeResponse>
```

Starts an OAuth device-flow sign-in (RFC 8628). Most callers want
[`AuthResource.loginWithDeviceFlow`](/sdk/reference/auth#loginwithdeviceflow), which also polls for the token.

Types: [`DeviceCodeResponse`](/sdk/reference/types#devicecoderesponse)

### exchangeDeviceCode

```ts theme={null}
exchangeDeviceCode(deviceCode: string): Promise<TokenResponse>
```

Polls once for the device-flow token. Throws an [`APIError`](/sdk/reference/client#apierror) with
`authorization_pending` until the user approves, or `slow_down` when
polling too fast.

Types: [`TokenResponse`](/sdk/reference/types#tokenresponse)

### getMemberships

```ts theme={null}
getMemberships(): Promise<TenantMembership[]>
```

Lists the workspaces the caller belongs to, with their role in each.

Types: [`TenantMembership`](/sdk/reference/types#tenantmembership)

### loginWithDeviceFlow

```ts theme={null}
loginWithDeviceFlow(output: (verificationUri: string, userCode: string) => void, signal?: AbortSignal): Promise<TokenResponse>
```

Orchestrates OAuth 2.0 Device Flow login: starts the flow, surfaces the
verification instructions via `output`, and polls the token endpoint until
a token is returned (honouring `authorization_pending` / `slow_down`).
Gives up with an `expired_token` error once the code's `expires_in` has
passed; any other server error (`access_denied`, …) is rethrown as is.

Types: [`TokenResponse`](/sdk/reference/types#tokenresponse)
