> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Account and access

> Your account, its limits, sign-ins, API tokens, device keys, data export and deletion.

Your account, its limits, sign-ins, API tokens, device keys, data export and deletion.

## Get your account

`GET /v1/me`

The account the request is signed in as.

```bash
curl -sS "https://kiste.run/v1/me" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [UserResponse](https://docs.kiste.run/api/schemas.md#userresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Get limits and usage

`GET /v1/status`

Your account's limits (Kisten, disk, running machines, vCPU and memory), what is in use, and which features are available. `kiste limits` shows the same.

```bash
curl -sS "https://kiste.run/v1/status" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [ControlPlaneStatusResponse](https://docs.kiste.run/api/schemas.md#controlplanestatusresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## List sign-ins

`GET /v1/sessions`

Your browser and CLI sign-ins, with the one making this request marked `current`. API keys are not sign-ins; they are listed under API keys.

```bash
curl -sS "https://kiste.run/v1/sessions" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [SignInList](https://docs.kiste.run/api/schemas.md#signinlist)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Sign out one sign-in

`DELETE /v1/sessions/{id}`

Ends one browser or CLI sign-in.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | yes | The object's ID. |

```bash
curl -sS -X DELETE "https://kiste.run/v1/sessions/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [DeletedSession](https://docs.kiste.run/api/schemas.md#deletedsession)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Sign out everywhere

`POST /v1/sessions/revoke-all`

Ends every browser and CLI sign-in of the account, including the one making the request, and closes open desktops and terminals. API keys stay valid; revoke them separately.

```bash
curl -sS -X POST "https://kiste.run/v1/sessions/revoke-all" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [SessionRevocation](https://docs.kiste.run/api/schemas.md#sessionrevocation)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## List API keys

`GET /v1/api-tokens`

Your API keys with label, a non-secret hint, expiry and last use. The keys themselves are never shown again.

```bash
curl -sS "https://kiste.run/v1/api-tokens" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: list of [ApiTokenResponse](https://docs.kiste.run/api/schemas.md#apitokenresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Create an API key

`POST /v1/api-tokens`

Creates an API key (`ksta_…`) with a label and a lifetime between 300 seconds and one year. The key is in this answer only; Kiste stores just a hash. At most 10 active keys. An API key cannot create further API keys.

```bash
curl -sS -X POST "https://kiste.run/v1/api-tokens" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"label":"ci-github","expires_in_seconds":2592000}'
```

**Request body:** [CreateApiTokenRequest](https://docs.kiste.run/api/schemas.md#createapitokenrequest)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `expires_in_seconds` | integer (int32) | yes |  |
| `label` | string | yes |  |

**Responses:**

- `200` OK. Body: [CreatedApiTokenResponse](https://docs.kiste.run/api/schemas.md#createdapitokenresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Get an API key

`GET /v1/api-tokens/{id}`

The metadata of one API key.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | yes | The object's ID. |

```bash
curl -sS "https://kiste.run/v1/api-tokens/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [ApiTokenResponse](https://docs.kiste.run/api/schemas.md#apitokenresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Revoke an API key

`DELETE /v1/api-tokens/{id}`

Revokes an API key at once.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | yes | The object's ID. |

```bash
curl -sS -X DELETE "https://kiste.run/v1/api-tokens/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [DeletedApiTokenResponse](https://docs.kiste.run/api/schemas.md#deletedapitokenresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Sign out

`POST /v1/auth/logout`

Revokes the credential that makes the request: a CLI sign-in or an API key. Desktops and terminals that are open stay open; sign out everywhere ends them too.

```bash
curl -sS -X POST "https://kiste.run/v1/auth/logout" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [LogoutResponse](https://docs.kiste.run/api/schemas.md#logoutresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Unlock password sign-in

`POST /v1/auth/unlock`

Lifts the account-wide lock on password sign-in from unknown browsers that repeated failed attempts set. It accepts a CLI sign-in or an API key of the account, never a browser session.

```bash
curl -sS -X POST "https://kiste.run/v1/auth/unlock" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [UnlockResponse](https://docs.kiste.run/api/schemas.md#unlockresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## List device keys

`GET /v1/device-keys`

The SSH keys of the computers you signed in from. Every Kiste of the account accepts each of them.

```bash
curl -sS "https://kiste.run/v1/device-keys" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [DeviceKeyList](https://docs.kiste.run/api/schemas.md#devicekeylist)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Add a device key

`POST /v1/device-keys`

Adds a computer's SSH public key to your account; `kiste login` does this for you. Browser sessions cannot add keys.

```bash
curl -sS -X POST "https://kiste.run/v1/device-keys" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name":"laptop","public_key":"ssh-ed25519 AAAA... you@laptop"}'
```

**Request body:** [RegisterDeviceKeyRequest](https://docs.kiste.run/api/schemas.md#registerdevicekeyrequest)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | yes |  |
| `public_key` | string | yes |  |

**Responses:**

- `200` OK. Body: [DeviceKey](https://docs.kiste.run/api/schemas.md#devicekey)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Remove a device key

`DELETE /v1/device-keys/{id}`

Removes a computer's key. Your Kisten stop accepting it the next time a tunnel opens or a Kiste starts.

**Path parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | yes | The object's ID. |

```bash
curl -sS -X DELETE "https://kiste.run/v1/device-keys/ID" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [DeletedDeviceKey](https://docs.kiste.run/api/schemas.md#deleteddevicekey)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Export your data

`POST /v1/me/export`

Creates a download link for a JSON export of everything Kiste stores about your account. The link works for ten minutes and only for the same account.

```bash
curl -sS -X POST "https://kiste.run/v1/me/export" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `201` OK. Body: [AccountExportLink](https://docs.kiste.run/api/schemas.md#accountexportlink)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Download your data export

`GET /v1/me/export/download`

Downloads the export with the link from the call above.

**Query parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `token` | string | yes | The token from the export link. |

```bash
curl -sS "https://kiste.run/v1/me/export/download" \
  -H "Authorization: Bearer $KISTE_TOKEN"
```

**Responses:**

- `200` OK. Body: [AccountExportFile](https://docs.kiste.run/api/schemas.md#accountexportfile)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Delete your account

`DELETE /v1/me`

Deletes your account and everything in it: Kisten, snapshots, published ports, keys, sign-ins and the subscription. Needs your password and your e-mail address typed as confirmation, from your own sign-in: an API key cannot do it (`A30`). Sign-in ends at once; the rest finishes in the background and the answer shows its progress.

```bash
curl -sS -X DELETE "https://kiste.run/v1/me" \
  -H "Authorization: Bearer $KISTE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"confirm":"you@example.com","password":"your-password"}'
```

**Request body:** [DeleteAccountRequest](https://docs.kiste.run/api/schemas.md#deleteaccountrequest)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `confirm` | string | yes | The account's e-mail address, typed as confirmation. |
| `password` | string | yes |  |

**Responses:**

- `202` OK. Body: [AccountDeletion](https://docs.kiste.run/api/schemas.md#accountdeletion)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Related topics

- [Overview](https://docs.kiste.run/api.md)
- [Conventions](https://docs.kiste.run/api/conventions.md)
- [Kisten](https://docs.kiste.run/api/instances.md)
- [Commands](https://docs.kiste.run/api/commands.md)
- [Snapshots](https://docs.kiste.run/api/snapshots.md)
- [SSH and terminal](https://docs.kiste.run/api/ssh-and-terminal.md)
- [Desktop](https://docs.kiste.run/api/desktop.md)
- [Kiste Stream](https://docs.kiste.run/api/stream.md)
- [Images and environments](https://docs.kiste.run/api/images.md)
- [Events, webhooks and alerts](https://docs.kiste.run/api/events.md)
- [Sign-in and platform](https://docs.kiste.run/api/platform.md)
- [Schemas](https://docs.kiste.run/api/schemas.md)
- Previous: [Events, webhooks and alerts](https://docs.kiste.run/api/events.md)
- Next: [Sign-in and platform](https://docs.kiste.run/api/platform.md)
