Your account

Prompt:

Which account is this tool signed in as?

Also works:

  • "Is my account in good standing?"
  • "Which products does my account have?"
  • "Where can I see my applications in a browser?"

What your tool does

  • Calls read_account first, to confirm which account the connection acts for: its identities, its standing, and the products it has.
  • Reports the standing, active or suspended, and the product profiles the response lists.
  • Where you want to see the account in a browser, gives you the signed-in site's address, https://turnzero.ai/dashboard (step 3).
  • For "end the connection on my old laptop", calls list_connections, then revoke_connection with that row's id.
  • Writes nothing into your project and changes nothing on your account unless you ask it to end a connection.

Before your AI starts

This section is for your AI tool: what it checks and gathers before it begins. You don't need to do these steps yourself.

Steps

1. Read the account

Each account belongs to one person, and each application belongs to the account that created it. Organization ownership, team seats, and organization roles are not available.

read_account identifies the connected account. It lists the account's identities, each a provider and the subject it verified. Identities and passkeys shows how to add and read them.

It also lists profiles, one per product: cloud on every account, and blueprint with Turn Zero Blueprint access. With Blueprint access, the Blueprint and Turn Zero Docs pages appear in the site's header after you sign in at turnzero.ai.

2. Read the standing

The account's standing is active or suspended. Platform staff can suspend and reinstate an account.

Suspension ends the account's sessions and refuses every action that needs your identity. Anonymous public reads still work. Sign-in, sessions, and tokens states how soon a suspension or a reinstatement reaches each part of the platform. After a reinstatement, sign in again.

3. Use the signed-in site

/dashboard on turnzero.ai is the browser view of your account. Its pages show your sign-in address, and the account page shows the identifier read_account returns.

  • Home shows your applications, your secrets, and this month's usage of each included measure, summed across applications.
  • Each application on the home shows each environment it has, each with its deployed version and state. For a deployed application it also shows the last minute its production URL passed a request to your code, from anyone, you included.
  • An application's own page, opened from the home, shows its version, plan, usage, schedules, logs, and database table names.
  • Secrets are listed by name, scope, and times, never by value, with a store control and a rotate control. A secret the platform minted is marked as managed by the platform and has no rotate control.
  • Storage areas and upstreams bound to an application show on its page. An area or upstream declared before binding was required, and not yet bound, shows on no page. Your tool's list_storage_areas and list_upstreams list it.
  • Sign-in & security, /dashboard/sign-in-methods, shows how many passkeys you hold and your other sign-in methods, with a link to the passkey page.

The site's own controls are the plan change (Plan and usage), the secret store and rotate, and a schedule's Run now on the application page. The Account page adds the controls that end connections and the deletion request. The Sign-in & security page adds Sign out everywhere. Your tool performs every other action. A pending action's approval page opens from the link your tool prints.

A change made on the site more than 8 hours after your browser sign-in is refused until you sign in again. The page shows a Sign in again link.

4. Read and end connections

list_connections lists the tools signed in to your account: one row per connection, with its client_id, the sign-in that opened it, its last renewal, and its expiry. revoke_connection ends one by its id: that tool's access and its renewal are refused at once, and every other connection stays open. The Account page, /dashboard/account, lists the same rows with an End this connection button on each.

Sign out in the header ends that browser's session alone and no connection. Sign out everywhere on the Sign-in & security page, or sign_out_everywhere from your tool, ends every connection and every browser session of the account at once, the caller's included. It also ends every token Turn Zero Blueprint's command was given. It returns how many sessions it ended, and how many of those tokens as exchange_tokens_revoked. Every device and tool then signs in again, and your passkeys stay. A token you minted with mint_token stays too. Each clone whose token ended makes the authorization request again (Mint a token).

If the answer is internal and says a token made during the sign-out may still stand, sign in again and run Sign out everywhere once more.

Expected result

read_account returns an account object with its id, created_at, standing, identities, and profiles, with synthetic: false and unbilled: false. Platform staff set unbilled on the company's own accounts and on complimentary ones. Such an account is never charged. The per-account plan limits do not apply to it. Under your session it also returns:

  • address, an address one of the account's identities verified, or null where none has one;
  • the credential's grants;
  • signed_in_at, the sign-in time under a browser session, which is null under the tool's connection;
  • passkeys, the counts held and stranded, or null where passkeys are not offered.

Refusals

A refusal changes nothing on the platform. The status is the one the HTTP route returns, and the Model Context Protocol (MCP) tool returns the same name. The plan and usage refusals are in Plan and usage. Refusals lists every refusal the platform returns.

Refusal Status Cause Remedy
authentication_required 401 No credential matched an account; read_account returns it for a session with no account. Sign in again through your tool.
account_suspended 403 The account is suspended, so actions that need your identity, and sign-ins, are refused. Wait for platform staff to reinstate the account, then sign in again.
fresh_authentication_required 403 A change from the dashboard came more than 8 hours after your browser sign-in. Follow the page's Sign in again link, then repeat the change.
not_found 404 revoke_connection named no live connection of your account. Call list_connections and use a row's id.