Account and access
Your account, its limits, sign-ins, API tokens, device keys, data export and deletion.
Your account, its limits, sign-ins, API tokens, device keys, data export and deletion.
Get your account
GET /v1/me
The account the request is signed in as.
Responses:
200OK. Body: UserResponse
Errors use the error envelope.
Get limits and usage
GET /v1/status
Your account's limits (Kisten, disk, running machines, vCPU and memory), what is in use, and which features are available. kiste limits shows the same.
Responses:
200OK. Body: ControlPlaneStatusResponse
Errors use the error envelope.
List sign-ins
GET /v1/sessions
Your browser and CLI sign-ins, with the one making this request marked current. API keys are not sign-ins; they are listed under API keys.
Responses:
200OK. Body: SignInList
Errors use the error envelope.
Sign out one sign-in
DELETE /v1/sessions/{id}
Ends one browser or CLI sign-in.
Path parameters:
| Name | Type | Required | Description |
|---|---|---|---|
id | string | yes | The object's ID. |
Responses:
200OK. Body: DeletedSession
Errors use the error envelope.
Sign out everywhere
POST /v1/sessions/revoke-all
Ends every browser and CLI sign-in of the account, including the one making the request, and closes open desktops and terminals. API keys stay valid; revoke them separately.
Responses:
200OK. Body: SessionRevocation
Errors use the error envelope.
List API keys
GET /v1/api-tokens
Your API keys with label, a non-secret hint, expiry and last use. The keys themselves are never shown again.
Responses:
200OK. Body: list of ApiTokenResponse
Errors use the error envelope.
Create an API key
POST /v1/api-tokens
Creates an API key (ksta_…) with a label and a lifetime between 300 seconds and one year. The key is in this answer only; Kiste stores just a hash. At most 10 active keys. An API key cannot create further API keys.
Request body: CreateApiTokenRequest
| Field | Type | Required | Description |
|---|---|---|---|
expires_in_seconds | integer (int32) | yes | |
label | string | yes |
Responses:
200OK. Body: CreatedApiTokenResponse
Errors use the error envelope.
Get an API key
GET /v1/api-tokens/{id}
The metadata of one API key.
Path parameters:
| Name | Type | Required | Description |
|---|---|---|---|
id | string | yes | The object's ID. |
Responses:
200OK. Body: ApiTokenResponse
Errors use the error envelope.
Revoke an API key
DELETE /v1/api-tokens/{id}
Revokes an API key at once.
Path parameters:
| Name | Type | Required | Description |
|---|---|---|---|
id | string | yes | The object's ID. |
Responses:
200OK. Body: DeletedApiTokenResponse
Errors use the error envelope.
Sign out
POST /v1/auth/logout
Revokes the credential that makes the request: a CLI sign-in or an API key. Desktops and terminals that are open stay open; sign out everywhere ends them too.
Responses:
200OK. Body: LogoutResponse
Errors use the error envelope.
Unlock password sign-in
POST /v1/auth/unlock
Lifts the account-wide lock on password sign-in from unknown browsers that repeated failed attempts set. It accepts a CLI sign-in or an API key of the account, never a browser session.
Responses:
200OK. Body: UnlockResponse
Errors use the error envelope.
List device keys
GET /v1/device-keys
The SSH keys of the computers you signed in from. Every Kiste of the account accepts each of them.
Responses:
200OK. Body: DeviceKeyList
Errors use the error envelope.
Add a device key
POST /v1/device-keys
Adds a computer's SSH public key to your account; kiste login does this for you. Browser sessions cannot add keys.
Request body: RegisterDeviceKeyRequest
| Field | Type | Required | Description |
|---|---|---|---|
name | string | yes | |
public_key | string | yes |
Responses:
200OK. Body: DeviceKey
Errors use the error envelope.
Remove a device key
DELETE /v1/device-keys/{id}
Removes a computer's key. Your Kisten stop accepting it the next time a tunnel opens or a Kiste starts.
Path parameters:
| Name | Type | Required | Description |
|---|---|---|---|
id | string | yes | The object's ID. |
Responses:
200OK. Body: DeletedDeviceKey
Errors use the error envelope.
Export your data
POST /v1/me/export
Creates a download link for a JSON export of everything Kiste stores about your account. The link works for ten minutes and only for the same account.
Responses:
201OK. Body: AccountExportLink
Errors use the error envelope.
Download your data export
GET /v1/me/export/download
Downloads the export with the link from the call above.
Query parameters:
| Name | Type | Required | Description |
|---|---|---|---|
token | string | yes | The token from the export link. |
Responses:
200OK. Body: AccountExportFile
Errors use the error envelope.
Delete your account
DELETE /v1/me
Deletes your account and everything in it: Kisten, snapshots, published ports, keys, sign-ins and the subscription. Needs your password and your e-mail address typed as confirmation, from your own sign-in: an API key cannot do it (A30). Sign-in ends at once; the rest finishes in the background and the answer shows its progress.
Request body: DeleteAccountRequest
| Field | Type | Required | Description |
|---|---|---|---|
confirm | string | yes | The account's e-mail address, typed as confirmation. |
password | string | yes |
Responses:
202OK. Body: AccountDeletion
Errors use the error envelope.