API reference

Account and access

Your account, its limits, sign-ins, API tokens, device keys, data export and deletion.

Your account, its limits, sign-ins, API tokens, device keys, data export and deletion.

Get your account

GET /v1/me

The account the request is signed in as.

curl -sS "https://kiste.run/v1/me" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Get limits and usage

GET /v1/status

Your account's limits (Kisten, disk, running machines, vCPU and memory), what is in use, and which features are available. kiste limits shows the same.

curl -sS "https://kiste.run/v1/status" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

List sign-ins

GET /v1/sessions

Your browser and CLI sign-ins, with the one making this request marked current. API keys are not sign-ins; they are listed under API keys.

curl -sS "https://kiste.run/v1/sessions" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Sign out one sign-in

DELETE /v1/sessions/{id}

Ends one browser or CLI sign-in.

Path parameters:

NameTypeRequiredDescription
idstringyesThe object's ID.
curl -sS -X DELETE "https://kiste.run/v1/sessions/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Sign out everywhere

POST /v1/sessions/revoke-all

Ends every browser and CLI sign-in of the account, including the one making the request, and closes open desktops and terminals. API keys stay valid; revoke them separately.

curl -sS -X POST "https://kiste.run/v1/sessions/revoke-all" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

List API keys

GET /v1/api-tokens

Your API keys with label, a non-secret hint, expiry and last use. The keys themselves are never shown again.

curl -sS "https://kiste.run/v1/api-tokens" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Create an API key

POST /v1/api-tokens

Creates an API key (ksta_…) with a label and a lifetime between 300 seconds and one year. The key is in this answer only; Kiste stores just a hash. At most 10 active keys. An API key cannot create further API keys.

curl -sS -X POST "https://kiste.run/v1/api-tokens" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"label":"ci-github","expires_in_seconds":2592000}'

Request body: CreateApiTokenRequest

FieldTypeRequiredDescription
expires_in_secondsinteger (int32)yes
labelstringyes

Responses:

Errors use the error envelope.

Get an API key

GET /v1/api-tokens/{id}

The metadata of one API key.

Path parameters:

NameTypeRequiredDescription
idstringyesThe object's ID.
curl -sS "https://kiste.run/v1/api-tokens/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Revoke an API key

DELETE /v1/api-tokens/{id}

Revokes an API key at once.

Path parameters:

NameTypeRequiredDescription
idstringyesThe object's ID.
curl -sS -X DELETE "https://kiste.run/v1/api-tokens/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Sign out

POST /v1/auth/logout

Revokes the credential that makes the request: a CLI sign-in or an API key. Desktops and terminals that are open stay open; sign out everywhere ends them too.

curl -sS -X POST "https://kiste.run/v1/auth/logout" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Unlock password sign-in

POST /v1/auth/unlock

Lifts the account-wide lock on password sign-in from unknown browsers that repeated failed attempts set. It accepts a CLI sign-in or an API key of the account, never a browser session.

curl -sS -X POST "https://kiste.run/v1/auth/unlock" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

List device keys

GET /v1/device-keys

The SSH keys of the computers you signed in from. Every Kiste of the account accepts each of them.

curl -sS "https://kiste.run/v1/device-keys" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Add a device key

POST /v1/device-keys

Adds a computer's SSH public key to your account; kiste login does this for you. Browser sessions cannot add keys.

curl -sS -X POST "https://kiste.run/v1/device-keys" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name":"laptop","public_key":"ssh-ed25519 AAAA... you@laptop"}'

Request body: RegisterDeviceKeyRequest

FieldTypeRequiredDescription
namestringyes
public_keystringyes

Responses:

Errors use the error envelope.

Remove a device key

DELETE /v1/device-keys/{id}

Removes a computer's key. Your Kisten stop accepting it the next time a tunnel opens or a Kiste starts.

Path parameters:

NameTypeRequiredDescription
idstringyesThe object's ID.
curl -sS -X DELETE "https://kiste.run/v1/device-keys/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Export your data

POST /v1/me/export

Creates a download link for a JSON export of everything Kiste stores about your account. The link works for ten minutes and only for the same account.

curl -sS -X POST "https://kiste.run/v1/me/export" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Download your data export

GET /v1/me/export/download

Downloads the export with the link from the call above.

Query parameters:

NameTypeRequiredDescription
tokenstringyesThe token from the export link.
curl -sS "https://kiste.run/v1/me/export/download" \
  -H "Authorization: Bearer $KISTE_TOKEN"

Responses:

Errors use the error envelope.

Delete your account

DELETE /v1/me

Deletes your account and everything in it: Kisten, snapshots, published ports, keys, sign-ins and the subscription. Needs your password and your e-mail address typed as confirmation, from your own sign-in: an API key cannot do it (A30). Sign-in ends at once; the rest finishes in the background and the answer shows its progress.

curl -sS -X DELETE "https://kiste.run/v1/me" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"confirm":"you@example.com","password":"your-password"}'

Request body: DeleteAccountRequest

FieldTypeRequiredDescription
confirmstringyesThe account's e-mail address, typed as confirmation.
passwordstringyes

Responses:

Errors use the error envelope.

On this page