Skip to content

Auth actions

50 actions. Each action calls the same API route with the same scopes on every surface.

Get account security settings.

Route GET /api/v1/auth/me/security
Tool name calternal_api_account_security
Surfaces cli, mcp, webmcp
Scopes account
Effect read only
Encoding request none, response json
Terminal window
calternal action run account_security --input '{}' --json

Start adding a passkey Requires a recent account confirmation..

Route POST /api/v1/auth/passkeys/add/start
Tool name calternal_api_add_start
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json
Terminal window
calternal action run add_start --input '{}' --confirm --json

Get the CLI sign-in approval page.

Route GET /api/v1/auth/cli/approve
Tool name calternal_api_approval_page
Surfaces none (browser flow only)
Scopes account
Effect read only
Encoding request none, response text

query

Field Type Required Description
user_code string yes

Approve a CLI sign-in request.

Route POST /api/v1/auth/cli/approve
Tool name calternal_api_approve
Surfaces none (browser flow only)
Scopes account
Effect destructive, needs --confirm
Encoding request none, response text

Complete a passkey check. Body fields: credential, flow..

Route POST /api/v1/auth/assert/finish
Tool name calternal_api_assert_finish
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
credential any yes
flow string yes
Terminal window
calternal action run assert_finish --input '{}' --confirm --json

Start a passkey check.

Route POST /api/v1/auth/assert/start
Tool name calternal_api_assert_start
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json
Terminal window
calternal action run assert_start --input '{}' --confirm --json

Get sign-in options.

Route GET /api/v1/auth/options
Tool name calternal_api_auth_options
Surfaces none (browser flow only)
Scopes none
Effect read only
Encoding request none, response json

End a CLI session.

Route DELETE /api/v1/auth/cli/session
Tool name calternal_api_cli_logout
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json
Terminal window
calternal action run cli_logout --input '{}' --confirm --json

Create an App Password. Body fields: expires_at, home_prefix, name, plugin_scope, scopes. Requires a recent account confirmation..

Route POST /api/v1/auth/app-passwords
Tool name calternal_api_create_app_password
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
expires_at integer | null, int64 no
home_prefix string | null no
name string yes
plugin_scope object or null no
scopes array of object no
Terminal window
calternal action run create_app_password --input '{}' --confirm --json

Create App Password setup links. Body fields: password. Requires a recent account confirmation..

Route POST /api/v1/auth/app-passwords/{id}/profiles
Tool name calternal_api_create_app_password_profiles
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response json

path

Field Type Required Description
id string, uuid yes

body

Field Type Required Description
password string yes The secret is sent only over the authenticated session and is never written to Security state or logs.
Terminal window
calternal action run create_app_password_profiles --input '{"path":{"id":"<id>"}}' --confirm --json

Create an Invite link. Body fields: quota_override_bytes, role, ttl_secs. Requires a recent account confirmation..

Route POST /api/v1/auth/invites
Tool name calternal_api_create_invite
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
quota_override_bytes integer | null, int64 (0–) no None inherits the Instance default; zero means unlimited.
role "owner" | "admin" | "member" | "guest" yes
ttl_secs integer, int64 yes
Terminal window
calternal action run create_invite --input '{}' --confirm --json

Get the current User.

Route GET /api/v1/auth/me
Tool name calternal_api_current_user
Surfaces cli, mcp, webmcp
Scopes account
Effect read only
Encoding request none, response json
Terminal window
calternal action run current_user --input '{}' --json

Download an App Password setup profile.

Route GET /api/v1/auth/app-password-profiles/{token}
Tool name calternal_api_download_app_password_profile
Surfaces cli, mcp, webmcp
Scopes none
Effect destructive, needs --confirm
Encoding request none, response base64

path

Field Type Required Description
token string yes
Terminal window
calternal action run download_app_password_profile --input '{"path":{"token":"<token>"}}' --confirm --json

Exchange a CLI sign-in code. Body fields: device_code, verifier..

Route POST /api/v1/auth/cli/token
Tool name calternal_api_exchange
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
device_code string yes
verifier string yes

Start passkey registration with an invite. Body fields: display_name, token, username..

Route POST /api/v1/auth/invites/start
Tool name calternal_api_invite_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
display_name string yes
token string | null no
username string yes

List App Passwords.

Route GET /api/v1/auth/app-passwords
Tool name calternal_api_list_app_passwords
Surfaces cli, mcp, webmcp
Scopes account
Effect read only
Encoding request none, response json
Terminal window
calternal action run list_app_passwords --input '{}' --json

List Invite links.

Route GET /api/v1/auth/invites
Tool name calternal_api_list_invites
Surfaces cli, mcp, webmcp
Scopes admin
Effect read only
Encoding request none, response json
Terminal window
calternal action run list_invites --input '{}' --json

List passkeys.

Route GET /api/v1/auth/passkeys
Tool name calternal_api_list_passkeys
Surfaces cli, mcp, webmcp
Scopes account
Effect read only
Encoding request none, response json
Terminal window
calternal action run list_passkeys --input '{}' --json

List sessions.

Route GET /api/v1/auth/sessions
Tool name calternal_api_list_sessions
Surfaces cli, mcp, webmcp
Scopes account
Effect read only
Encoding request none, response json
Terminal window
calternal action run list_sessions --input '{}' --json

List Users.

Route GET /api/v1/auth/users
Tool name calternal_api_list_users
Surfaces cli, mcp, webmcp
Scopes admin
Effect read only
Encoding request none, response json
Terminal window
calternal action run list_users --input '{}' --json

Complete passkey sign-in. Body fields: credential, flow, installation_name, kind..

Route POST /api/v1/auth/passkeys/login/finish
Tool name calternal_api_login_finish
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
credential any yes
flow string yes
installation_name string | null no
kind "web" | "installation" yes

Start passkey sign-in.

Route POST /api/v1/auth/passkeys/login/start
Tool name calternal_api_login_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request none, response json

Complete OpenID Connect sign-in in the browser The server checks freshness only when this callback links an identity to an existing session..

Route GET /api/v1/auth/oidc/{provider}/callback
Tool name calternal_api_oidc_browser_callback
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
provider string yes

query

Field Type Required Description
code string no
error string no
state string no

Complete OpenID Connect sign-in. Body fields: code, installation_name, kind, state..

Route POST /api/v1/auth/oidc/{provider}/callback
Tool name calternal_api_oidc_callback
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

path

Field Type Required Description
provider string yes

body

Field Type Required Description
code string yes
installation_name string | null no
kind "web" | "installation" or null no
state string yes

Start linking an OpenID Connect identity Requires a recent account confirmation..

Route POST /api/v1/auth/oidc/{provider}/link/start
Tool name calternal_api_oidc_link_start
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
provider string yes
Terminal window
calternal action run oidc_link_start --input '{"path":{"provider":"<provider>"}}' --confirm --json

Start sign-in to confirm an OpenID Connect identity.

Route POST /api/v1/auth/oidc/{provider}/reauth/start
Tool name calternal_api_oidc_reauth_start
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
provider string yes
Terminal window
calternal action run oidc_reauth_start --input '{"path":{"provider":"<provider>"}}' --confirm --json

Start OpenID Connect sign-in.

Route POST /api/v1/auth/oidc/{provider}/start
Tool name calternal_api_oidc_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
provider string yes

Unlink an OpenID Connect identity Requires a recent account confirmation..

Route DELETE /api/v1/auth/oidc/{provider}/link
Tool name calternal_api_oidc_unlink
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
provider string yes
Terminal window
calternal action run oidc_unlink --input '{"path":{"provider":"<provider>"}}' --confirm --json

Get the recovery key Requires a recent account confirmation..

Route POST /api/v1/auth/recovery/key
Tool name calternal_api_recovery_key
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json
Terminal window
calternal action run recovery_key --input '{}' --confirm --json

Start passkey recovery. Body fields: key, username..

Route POST /api/v1/auth/passkeys/recovery/start
Tool name calternal_api_recovery_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
key string yes
username string yes

Issue a passkey re-enrolment link. Body fields: ttl_secs, user_id. Requires a recent account confirmation..

Route POST /api/v1/auth/passkeys/reenrol/issue
Tool name calternal_api_reenrol_issue
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
ttl_secs integer, int64 yes
user_id string, uuid yes
Terminal window
calternal action run reenrol_issue --input '{}' --confirm --json

Start passkey re-enrolment. Body fields: token..

Route POST /api/v1/auth/passkeys/reenrol/start
Tool name calternal_api_reenrol_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
token string yes

Complete passkey registration. Body fields: credential, flow, name..

Route POST /api/v1/auth/passkeys/registration/finish
Tool name calternal_api_register_finish
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
credential any yes
flow string yes
name string yes

Complete passkey removal. Body fields: credential, flow..

Route POST /api/v1/auth/passkeys/remove/finish
Tool name calternal_api_remove_finish
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
credential any yes
flow string yes
Terminal window
calternal action run remove_finish --input '{}' --confirm --json

Start removing a passkey.

Route POST /api/v1/auth/passkeys/remove/start/{id}
Tool name calternal_api_remove_start
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
id string yes
Terminal window
calternal action run remove_start --input '{"path":{"id":"<id>"}}' --confirm --json

Rename a passkey. Body fields: name..

Route PATCH /api/v1/auth/passkeys/{id}
Tool name calternal_api_rename_passkey
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response json

path

Field Type Required Description
id string yes

body

Field Type Required Description
name string yes
Terminal window
calternal action run rename_passkey --input '{"path":{"id":"<id>"}}' --confirm --json

Revoke all sessions. Body fields: keep_current. Requires a recent account confirmation..

Route POST /api/v1/auth/sessions/revoke-all
Tool name calternal_api_revoke_all
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response text

body

Field Type Required Description
keep_current boolean yes
Terminal window
calternal action run revoke_all --input '{}' --confirm --json

Revoke an App Password Requires a recent account confirmation..

Route DELETE /api/v1/auth/app-passwords/{id}
Tool name calternal_api_revoke_app_password
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
id string, uuid yes
Terminal window
calternal action run revoke_app_password --input '{"path":{"id":"<id>"}}' --confirm --json

Revoke an Invite link Requires a recent account confirmation..

Route DELETE /api/v1/auth/invites/{id}
Tool name calternal_api_revoke_invite
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
id string yes
Terminal window
calternal action run revoke_invite --input '{"path":{"id":"<id>"}}' --confirm --json

Revoke a session Requires a recent account confirmation..

Route DELETE /api/v1/auth/sessions/{id}
Tool name calternal_api_revoke_session
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json

path

Field Type Required Description
id string yes
Terminal window
calternal action run revoke_session --input '{"path":{"id":"<id>"}}' --confirm --json

Fresh admin assertion protects the Instance signup policy (#1035, §21). Requires a recent account confirmation..

Route POST /api/v1/auth/settings/share-invites
Tool name calternal_api_set_share_invites_setting
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

body: boolean

Terminal window
calternal action run set_share_invites_setting --input '{}' --confirm --json

Set the sign-up setting. Body fields: open_signup. Requires a recent account confirmation..

Route POST /api/v1/auth/settings/signup
Tool name calternal_api_set_signup
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
open_signup boolean yes
Terminal window
calternal action run set_signup --input '{}' --confirm --json

Start passkey setup. Body fields: display_name, token, username..

Route POST /api/v1/auth/setup/start
Tool name calternal_api_setup_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
display_name string yes
token string | null no
username string yes

Share dialog policy; this returns no User data (DESIGN §54, #1035)..

Route GET /api/v1/auth/settings/share-invites
Tool name calternal_api_share_invites_setting
Surfaces cli, mcp, webmcp
Scopes account
Effect read only
Encoding request none, response json
Terminal window
calternal action run share_invites_setting --input '{}' --json

End the current session.

Route DELETE /api/v1/auth/session
Tool name calternal_api_sign_out
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request none, response json
Terminal window
calternal action run sign_out --input '{}' --confirm --json

Start CLI sign-in. Body fields: challenge, installation_name, redirect_uri..

Route POST /api/v1/auth/cli/start
Tool name calternal_api_start
Surfaces none (browser flow only)
Scopes none
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
challenge string yes
installation_name string yes
redirect_uri string | null no

Set a User’s sign-in status. Body fields: disabled. Requires a recent account confirmation..

Route PATCH /api/v1/auth/users/{id}/disabled
Tool name calternal_api_update_disabled
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

path

Field Type Required Description
id string, uuid yes

body

Field Type Required Description
disabled boolean yes
Terminal window
calternal action run update_disabled --input '{"path":{"id":"<id>"}}' --confirm --json

Update profile. Body fields: display_name, username..

Route PATCH /api/v1/auth/me/profile
Tool name calternal_api_update_profile
Surfaces cli, mcp, webmcp
Scopes account
Effect destructive, needs --confirm
Encoding request json, response json

body

Field Type Required Description
display_name string yes
username string yes
Terminal window
calternal action run update_profile --input '{}' --confirm --json

Update a User’s quota. Body fields: quota_override_bytes. Requires a recent account confirmation..

Route PATCH /api/v1/auth/users/{id}/quota
Tool name calternal_api_update_quota
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

path

Field Type Required Description
id string, uuid yes

body

Field Type Required Description
quota_override_bytes integer | null, int64 (0–) no null inherits the Instance default; zero means unlimited.
Terminal window
calternal action run update_quota --input '{"path":{"id":"<id>"}}' --confirm --json

Update a User’s Role. Body fields: role. Requires a recent account confirmation..

Route PATCH /api/v1/auth/users/{id}/role
Tool name calternal_api_update_role
Surfaces cli, mcp, webmcp
Scopes admin
Effect destructive, needs --confirm
Encoding request json, response json

path

Field Type Required Description
id string, uuid yes

body

Field Type Required Description
role "owner" | "admin" | "member" | "guest" yes
Terminal window
calternal action run update_role --input '{"path":{"id":"<id>"}}' --confirm --json