Auth actions
50 actions. Each action calls the same API route with the same scopes on every surface.
account_security
Section titled “account_security”Get account security settings.
| Route | GET /api/v1/auth/me/security |
| Tool name | calternal_api_account_security |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response json |
calternal action run account_security --input '{}' --jsonadd_start
Section titled “add_start”Start adding a passkey Requires a recent account confirmation..
| Route | POST /api/v1/auth/passkeys/add/start |
| Tool name | calternal_api_add_start |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
calternal action run add_start --input '{}' --confirm --jsonapproval_page
Section titled “approval_page”Get the CLI sign-in approval page.
| Route | GET /api/v1/auth/cli/approve |
| Tool name | calternal_api_approval_page |
| Surfaces | none (browser flow only) |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response text |
query
| Field | Type | Required | Description |
|---|---|---|---|
user_code |
string |
yes |
approve
Section titled “approve”Approve a CLI sign-in request.
| Route | POST /api/v1/auth/cli/approve |
| Tool name | calternal_api_approve |
| Surfaces | none (browser flow only) |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response text |
assert_finish
Section titled “assert_finish”Complete a passkey check. Body fields: credential, flow..
| Route | POST /api/v1/auth/assert/finish |
| Tool name | calternal_api_assert_finish |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
credential |
any |
yes | |
flow |
string |
yes |
calternal action run assert_finish --input '{}' --confirm --jsonassert_start
Section titled “assert_start”Start a passkey check.
| Route | POST /api/v1/auth/assert/start |
| Tool name | calternal_api_assert_start |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
calternal action run assert_start --input '{}' --confirm --jsonauth_options
Section titled “auth_options”Get sign-in options.
| Route | GET /api/v1/auth/options |
| Tool name | calternal_api_auth_options |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | read only |
| Encoding | request none, response json |
cli_logout
Section titled “cli_logout”End a CLI session.
| Route | DELETE /api/v1/auth/cli/session |
| Tool name | calternal_api_cli_logout |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
calternal action run cli_logout --input '{}' --confirm --jsoncreate_app_password
Section titled “create_app_password”Create an App Password. Body fields: expires_at, home_prefix, name, plugin_scope, scopes. Requires a recent account confirmation..
| Route | POST /api/v1/auth/app-passwords |
| Tool name | calternal_api_create_app_password |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
expires_at |
integer | null, int64 |
no | |
home_prefix |
string | null |
no | |
name |
string |
yes | |
plugin_scope |
object or null |
no | |
scopes |
array of object |
no |
calternal action run create_app_password --input '{}' --confirm --jsoncreate_app_password_profiles
Section titled “create_app_password_profiles”Create App Password setup links. Body fields: password. Requires a recent account confirmation..
| Route | POST /api/v1/auth/app-passwords/{id}/profiles |
| Tool name | calternal_api_create_app_password_profiles |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string, uuid |
yes |
body
| Field | Type | Required | Description |
|---|---|---|---|
password |
string |
yes | The secret is sent only over the authenticated session and is never written to Security state or logs. |
calternal action run create_app_password_profiles --input '{"path":{"id":"<id>"}}' --confirm --jsoncreate_invite
Section titled “create_invite”Create an Invite link. Body fields: quota_override_bytes, role, ttl_secs. Requires a recent account confirmation..
| Route | POST /api/v1/auth/invites |
| Tool name | calternal_api_create_invite |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
quota_override_bytes |
integer | null, int64 (0–) |
no | None inherits the Instance default; zero means unlimited. |
role |
"owner" | "admin" | "member" | "guest" |
yes | |
ttl_secs |
integer, int64 |
yes |
calternal action run create_invite --input '{}' --confirm --jsoncurrent_user
Section titled “current_user”Get the current User.
| Route | GET /api/v1/auth/me |
| Tool name | calternal_api_current_user |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response json |
calternal action run current_user --input '{}' --jsondownload_app_password_profile
Section titled “download_app_password_profile”Download an App Password setup profile.
| Route | GET /api/v1/auth/app-password-profiles/{token} |
| Tool name | calternal_api_download_app_password_profile |
| Surfaces | cli, mcp, webmcp |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request none, response base64 |
path
| Field | Type | Required | Description |
|---|---|---|---|
token |
string |
yes |
calternal action run download_app_password_profile --input '{"path":{"token":"<token>"}}' --confirm --jsonexchange
Section titled “exchange”Exchange a CLI sign-in code. Body fields: device_code, verifier..
| Route | POST /api/v1/auth/cli/token |
| Tool name | calternal_api_exchange |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
device_code |
string |
yes | |
verifier |
string |
yes |
invite_start
Section titled “invite_start”Start passkey registration with an invite. Body fields: display_name, token, username..
| Route | POST /api/v1/auth/invites/start |
| Tool name | calternal_api_invite_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
display_name |
string |
yes | |
token |
string | null |
no | |
username |
string |
yes |
list_app_passwords
Section titled “list_app_passwords”List App Passwords.
| Route | GET /api/v1/auth/app-passwords |
| Tool name | calternal_api_list_app_passwords |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response json |
calternal action run list_app_passwords --input '{}' --jsonlist_invites
Section titled “list_invites”List Invite links.
| Route | GET /api/v1/auth/invites |
| Tool name | calternal_api_list_invites |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | read only |
| Encoding | request none, response json |
calternal action run list_invites --input '{}' --jsonlist_passkeys
Section titled “list_passkeys”List passkeys.
| Route | GET /api/v1/auth/passkeys |
| Tool name | calternal_api_list_passkeys |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response json |
calternal action run list_passkeys --input '{}' --jsonlist_sessions
Section titled “list_sessions”List sessions.
| Route | GET /api/v1/auth/sessions |
| Tool name | calternal_api_list_sessions |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response json |
calternal action run list_sessions --input '{}' --jsonlist_users
Section titled “list_users”List Users.
| Route | GET /api/v1/auth/users |
| Tool name | calternal_api_list_users |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | read only |
| Encoding | request none, response json |
calternal action run list_users --input '{}' --jsonlogin_finish
Section titled “login_finish”Complete passkey sign-in. Body fields: credential, flow, installation_name, kind..
| Route | POST /api/v1/auth/passkeys/login/finish |
| Tool name | calternal_api_login_finish |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
credential |
any |
yes | |
flow |
string |
yes | |
installation_name |
string | null |
no | |
kind |
"web" | "installation" |
yes |
login_start
Section titled “login_start”Start passkey sign-in.
| Route | POST /api/v1/auth/passkeys/login/start |
| Tool name | calternal_api_login_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
oidc_browser_callback
Section titled “oidc_browser_callback”Complete OpenID Connect sign-in in the browser The server checks freshness only when this callback links an identity to an existing session..
| Route | GET /api/v1/auth/oidc/{provider}/callback |
| Tool name | calternal_api_oidc_browser_callback |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
provider |
string |
yes |
query
| Field | Type | Required | Description |
|---|---|---|---|
code |
string |
no | |
error |
string |
no | |
state |
string |
no |
oidc_callback
Section titled “oidc_callback”Complete OpenID Connect sign-in. Body fields: code, installation_name, kind, state..
| Route | POST /api/v1/auth/oidc/{provider}/callback |
| Tool name | calternal_api_oidc_callback |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
provider |
string |
yes |
body
| Field | Type | Required | Description |
|---|---|---|---|
code |
string |
yes | |
installation_name |
string | null |
no | |
kind |
"web" | "installation" or null |
no | |
state |
string |
yes |
oidc_link_start
Section titled “oidc_link_start”Start linking an OpenID Connect identity Requires a recent account confirmation..
| Route | POST /api/v1/auth/oidc/{provider}/link/start |
| Tool name | calternal_api_oidc_link_start |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
provider |
string |
yes |
calternal action run oidc_link_start --input '{"path":{"provider":"<provider>"}}' --confirm --jsonoidc_reauth_start
Section titled “oidc_reauth_start”Start sign-in to confirm an OpenID Connect identity.
| Route | POST /api/v1/auth/oidc/{provider}/reauth/start |
| Tool name | calternal_api_oidc_reauth_start |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
provider |
string |
yes |
calternal action run oidc_reauth_start --input '{"path":{"provider":"<provider>"}}' --confirm --jsonoidc_start
Section titled “oidc_start”Start OpenID Connect sign-in.
| Route | POST /api/v1/auth/oidc/{provider}/start |
| Tool name | calternal_api_oidc_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
provider |
string |
yes |
oidc_unlink
Section titled “oidc_unlink”Unlink an OpenID Connect identity Requires a recent account confirmation..
| Route | DELETE /api/v1/auth/oidc/{provider}/link |
| Tool name | calternal_api_oidc_unlink |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
provider |
string |
yes |
calternal action run oidc_unlink --input '{"path":{"provider":"<provider>"}}' --confirm --jsonrecovery_key
Section titled “recovery_key”Get the recovery key Requires a recent account confirmation..
| Route | POST /api/v1/auth/recovery/key |
| Tool name | calternal_api_recovery_key |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
calternal action run recovery_key --input '{}' --confirm --jsonrecovery_start
Section titled “recovery_start”Start passkey recovery. Body fields: key, username..
| Route | POST /api/v1/auth/passkeys/recovery/start |
| Tool name | calternal_api_recovery_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
key |
string |
yes | |
username |
string |
yes |
reenrol_issue
Section titled “reenrol_issue”Issue a passkey re-enrolment link. Body fields: ttl_secs, user_id. Requires a recent account confirmation..
| Route | POST /api/v1/auth/passkeys/reenrol/issue |
| Tool name | calternal_api_reenrol_issue |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
ttl_secs |
integer, int64 |
yes | |
user_id |
string, uuid |
yes |
calternal action run reenrol_issue --input '{}' --confirm --jsonreenrol_start
Section titled “reenrol_start”Start passkey re-enrolment. Body fields: token..
| Route | POST /api/v1/auth/passkeys/reenrol/start |
| Tool name | calternal_api_reenrol_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
token |
string |
yes |
register_finish
Section titled “register_finish”Complete passkey registration. Body fields: credential, flow, name..
| Route | POST /api/v1/auth/passkeys/registration/finish |
| Tool name | calternal_api_register_finish |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
credential |
any |
yes | |
flow |
string |
yes | |
name |
string |
yes |
remove_finish
Section titled “remove_finish”Complete passkey removal. Body fields: credential, flow..
| Route | POST /api/v1/auth/passkeys/remove/finish |
| Tool name | calternal_api_remove_finish |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
credential |
any |
yes | |
flow |
string |
yes |
calternal action run remove_finish --input '{}' --confirm --jsonremove_start
Section titled “remove_start”Start removing a passkey.
| Route | POST /api/v1/auth/passkeys/remove/start/{id} |
| Tool name | calternal_api_remove_start |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string |
yes |
calternal action run remove_start --input '{"path":{"id":"<id>"}}' --confirm --jsonrename_passkey
Section titled “rename_passkey”Rename a passkey. Body fields: name..
| Route | PATCH /api/v1/auth/passkeys/{id} |
| Tool name | calternal_api_rename_passkey |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string |
yes |
body
| Field | Type | Required | Description |
|---|---|---|---|
name |
string |
yes |
calternal action run rename_passkey --input '{"path":{"id":"<id>"}}' --confirm --jsonrevoke_all
Section titled “revoke_all”Revoke all sessions. Body fields: keep_current. Requires a recent account confirmation..
| Route | POST /api/v1/auth/sessions/revoke-all |
| Tool name | calternal_api_revoke_all |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response text |
body
| Field | Type | Required | Description |
|---|---|---|---|
keep_current |
boolean |
yes |
calternal action run revoke_all --input '{}' --confirm --jsonrevoke_app_password
Section titled “revoke_app_password”Revoke an App Password Requires a recent account confirmation..
| Route | DELETE /api/v1/auth/app-passwords/{id} |
| Tool name | calternal_api_revoke_app_password |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string, uuid |
yes |
calternal action run revoke_app_password --input '{"path":{"id":"<id>"}}' --confirm --jsonrevoke_invite
Section titled “revoke_invite”Revoke an Invite link Requires a recent account confirmation..
| Route | DELETE /api/v1/auth/invites/{id} |
| Tool name | calternal_api_revoke_invite |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string |
yes |
calternal action run revoke_invite --input '{"path":{"id":"<id>"}}' --confirm --jsonrevoke_session
Section titled “revoke_session”Revoke a session Requires a recent account confirmation..
| Route | DELETE /api/v1/auth/sessions/{id} |
| Tool name | calternal_api_revoke_session |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string |
yes |
calternal action run revoke_session --input '{"path":{"id":"<id>"}}' --confirm --jsonset_share_invites_setting
Section titled “set_share_invites_setting”Fresh admin assertion protects the Instance signup policy (#1035, §21). Requires a recent account confirmation..
| Route | POST /api/v1/auth/settings/share-invites |
| Tool name | calternal_api_set_share_invites_setting |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body: boolean
calternal action run set_share_invites_setting --input '{}' --confirm --jsonset_signup
Section titled “set_signup”Set the sign-up setting. Body fields: open_signup. Requires a recent account confirmation..
| Route | POST /api/v1/auth/settings/signup |
| Tool name | calternal_api_set_signup |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
open_signup |
boolean |
yes |
calternal action run set_signup --input '{}' --confirm --jsonsetup_start
Section titled “setup_start”Start passkey setup. Body fields: display_name, token, username..
| Route | POST /api/v1/auth/setup/start |
| Tool name | calternal_api_setup_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
display_name |
string |
yes | |
token |
string | null |
no | |
username |
string |
yes |
share_invites_setting
Section titled “share_invites_setting”Share dialog policy; this returns no User data (DESIGN §54, #1035)..
| Route | GET /api/v1/auth/settings/share-invites |
| Tool name | calternal_api_share_invites_setting |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | read only |
| Encoding | request none, response json |
calternal action run share_invites_setting --input '{}' --jsonsign_out
Section titled “sign_out”End the current session.
| Route | DELETE /api/v1/auth/session |
| Tool name | calternal_api_sign_out |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request none, response json |
calternal action run sign_out --input '{}' --confirm --jsonStart CLI sign-in. Body fields: challenge, installation_name, redirect_uri..
| Route | POST /api/v1/auth/cli/start |
| Tool name | calternal_api_start |
| Surfaces | none (browser flow only) |
| Scopes | none |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
challenge |
string |
yes | |
installation_name |
string |
yes | |
redirect_uri |
string | null |
no |
update_disabled
Section titled “update_disabled”Set a User’s sign-in status. Body fields: disabled. Requires a recent account confirmation..
| Route | PATCH /api/v1/auth/users/{id}/disabled |
| Tool name | calternal_api_update_disabled |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string, uuid |
yes |
body
| Field | Type | Required | Description |
|---|---|---|---|
disabled |
boolean |
yes |
calternal action run update_disabled --input '{"path":{"id":"<id>"}}' --confirm --jsonupdate_profile
Section titled “update_profile”Update profile. Body fields: display_name, username..
| Route | PATCH /api/v1/auth/me/profile |
| Tool name | calternal_api_update_profile |
| Surfaces | cli, mcp, webmcp |
| Scopes | account |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
body
| Field | Type | Required | Description |
|---|---|---|---|
display_name |
string |
yes | |
username |
string |
yes |
calternal action run update_profile --input '{}' --confirm --jsonupdate_quota
Section titled “update_quota”Update a User’s quota. Body fields: quota_override_bytes. Requires a recent account confirmation..
| Route | PATCH /api/v1/auth/users/{id}/quota |
| Tool name | calternal_api_update_quota |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string, uuid |
yes |
body
| Field | Type | Required | Description |
|---|---|---|---|
quota_override_bytes |
integer | null, int64 (0–) |
no | null inherits the Instance default; zero means unlimited. |
calternal action run update_quota --input '{"path":{"id":"<id>"}}' --confirm --jsonupdate_role
Section titled “update_role”Update a User’s Role. Body fields: role. Requires a recent account confirmation..
| Route | PATCH /api/v1/auth/users/{id}/role |
| Tool name | calternal_api_update_role |
| Surfaces | cli, mcp, webmcp |
| Scopes | admin |
| Effect | destructive, needs --confirm |
| Encoding | request json, response json |
path
| Field | Type | Required | Description |
|---|---|---|---|
id |
string, uuid |
yes |
body
| Field | Type | Required | Description |
|---|---|---|---|
role |
"owner" | "admin" | "member" | "guest" |
yes |
calternal action run update_role --input '{"path":{"id":"<id>"}}' --confirm --json