read_account
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/read_account, with a bearer credential and the action's payload as the JSON body. It also accepts GET.
Contract description
Read the account this connection represents: its sign-in identities (provider and verified subject), account standing (`active` or `suspended`), and product profiles. For a session credential, it also reads the provider-verified address (`address`), the credential's grants (`grants`), the sign-in instant it carries (`signed_in_at`, null for a bearer at this revision), and the passkey standing (`passkeys`). The passkey standing is counts only: how many of the account's passkeys sign in on this host as `held`, and how many were registered for another as `stranded`. It is null where no passkey ceremony is served. An application-bounded token receives none of the four.
Access and action metadata
{
"name": "read_account",
"resource": "account",
"tier": "observe",
"clients": [
"bearer",
"browser_session"
],
"summary": "The connected identity and its standing. For the session credential and the browser session it also answers the provider-verified address (`address`, null where none is held), the acting credential's grants (`grants`), and the sign-in instant the credential carries (`signed_in_at`: the API cookie's own for a browser session, null for a bearer at this revision), so a page can render a sign-in link in place of each control once the freshness window has passed, and the account's passkey standing (`passkeys`: the counts `held` and `stranded` and nothing of a credential, null where no passkey ceremony is served); the platform credential and an application-bounded minted token receive none of the four.",
"annotations": {
"readOnlyHint": true,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "read_account",
"tier": "observe",
"scenario": "CHI-L0-04",
"summary": "Read the account this connection represents: its sign-in identities (provider and verified subject), account standing (`active` or `suspended`), and product profiles. For a session credential, it also reads the provider-verified address (`address`), the credential's grants (`grants`), the sign-in instant it carries (`signed_in_at`, null for a bearer at this revision), and the passkey standing (`passkeys`). The passkey standing is counts only: how many of the account's passkeys sign in on this host as `held`, and how many were registered for another as `stranded`. It is null where no passkey ceremony is served. An application-bounded token receives none of the four.",
"owners": []
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Additional properties: false |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","account"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
Type: object Required fields: ["id","created_at","standing","identities","synthetic","unbilled"] |
| / |
Type: string |
| / |
Type: string |
| / |
Type: string |
| / |
Type: array |
| / |
Type: object Required fields: ["provider","subject"] |
| / |
Type: string |
| / |
Type: string |
| / |
The product profiles the account carries, one per product the person took up (ACB-L0-76): the product code name and the stamp its first run added it. Type: array |
| / |
Type: object Required fields: ["product","created_at"] Additional properties: false |
| / |
Type: string |
| / |
Type: string |
| / |
true on a synthetic account — a test fixture seed_synthetic_accounts created, which no sign-in creates and no billing or product analytics counts (ACB-L0-79) — and false on every account a sign-in created. Type: boolean |
| / |
true on an account a super-admin has marked unbilled, the company's own or a complimentary one — free of the per-account application limits and never charged (ACB-L0-84) — and false on every other account. Type: boolean |
| / |
The provider-verified address an identity of the account carries, or null; answered to the session credential and the browser session alone (MAPI-03; WEB-L0-17). Type: ["string","null"] |
| / |
The acting credential's grant markings (MAPI-09: `super_admin`); answered to the session kinds alone. Type: array |
| / |
Type: string |
| / |
The sign-in instant the credential carries, ISO 8601: the API cookie's own for a browser session, null for a bearer at this revision; answered to the session kinds alone, so a page renders a sign-in link once the freshness window has passed (WEB-L0-16). Type: ["string","null"] |
| / |
The account's passkey standing: two counts and nothing of a credential — no identifier, name, or date. A page and a connected tool read whether a passkey is set without the passkey page's fresh-session read. It is null where the platform serves no passkey ceremony on this host. It is answered to the session kinds alone (ACS-L0-10). Type: ["object","null"] Required fields: ["held","stranded"] Additional properties: false |
| / |
How many of the account's passkeys sign in on this host: the ones registered under the current relying-party identifier. Type: integer Minimum: 0 |
| / |
How many of the account's passkeys do not sign in on this host: the ones registered for another host, or before the host was recorded; no browser offers them here, and the passkey page removes them. Type: integer Minimum: 0 |
Complete payload contract
{
"request": {
"type": "object",
"properties": {},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"account"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"account": {
"type": "object",
"required": [
"id",
"created_at",
"standing",
"identities",
"synthetic",
"unbilled"
],
"properties": {
"id": {
"type": "string"
},
"created_at": {
"type": "string"
},
"standing": {
"type": "string"
},
"identities": {
"type": "array",
"items": {
"type": "object",
"required": [
"provider",
"subject"
],
"properties": {
"provider": {
"type": "string"
},
"subject": {
"type": "string"
}
}
}
},
"profiles": {
"type": "array",
"description": "The product profiles the account carries, one per product the person took up (ACB-L0-76): the product code name and the stamp its first run added it.",
"items": {
"type": "object",
"required": [
"product",
"created_at"
],
"properties": {
"product": {
"type": "string"
},
"created_at": {
"type": "string"
}
},
"additionalProperties": false
}
},
"synthetic": {
"type": "boolean",
"description": "true on a synthetic account — a test fixture seed_synthetic_accounts created, which no sign-in creates and no billing or product analytics counts (ACB-L0-79) — and false on every account a sign-in created."
},
"unbilled": {
"type": "boolean",
"description": "true on an account a super-admin has marked unbilled, the company's own or a complimentary one — free of the per-account application limits and never charged (ACB-L0-84) — and false on every other account."
},
"address": {
"type": [
"string",
"null"
],
"description": "The provider-verified address an identity of the account carries, or null; answered to the session credential and the browser session alone (MAPI-03; WEB-L0-17)."
},
"grants": {
"type": "array",
"items": {
"type": "string"
},
"description": "The acting credential's grant markings (MAPI-09: `super_admin`); answered to the session kinds alone."
},
"signed_in_at": {
"type": [
"string",
"null"
],
"description": "The sign-in instant the credential carries, ISO 8601: the API cookie's own for a browser session, null for a bearer at this revision; answered to the session kinds alone, so a page renders a sign-in link once the freshness window has passed (WEB-L0-16)."
},
"passkeys": {
"type": [
"object",
"null"
],
"required": [
"held",
"stranded"
],
"additionalProperties": false,
"properties": {
"held": {
"type": "integer",
"minimum": 0,
"description": "How many of the account's passkeys sign in on this host: the ones registered under the current relying-party identifier."
},
"stranded": {
"type": "integer",
"minimum": 0,
"description": "How many of the account's passkeys do not sign in on this host: the ones registered for another host, or before the host was recorded; no browser offers them here, and the passkey page removes them."
}
},
"description": "The account's passkey standing: two counts and nothing of a credential — no identifier, name, or date. A page and a connected tool read whether a passkey is set without the passkey page's fresh-session read. It is null where the platform serves no passkey ceremony on this host. It is answered to the session kinds alone (ACS-L0-10)."
}
}
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md