read_account

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/read_account, with a bearer credential and the action's payload as the JSON body. It also accepts GET.

Contract description

Read the account this connection represents: its sign-in identities (provider and verified subject), account standing (`active` or `suspended`), and product profiles. For a session credential, it also reads the provider-verified address (`address`), the credential's grants (`grants`), the sign-in instant it carries (`signed_in_at`, null for a bearer at this revision), and the passkey standing (`passkeys`). The passkey standing is counts only: how many of the account's passkeys sign in on this host as `held`, and how many were registered for another as `stranded`. It is null where no passkey ceremony is served. An application-bounded token receives none of the four.

Access and action metadata

{
  "name": "read_account",
  "resource": "account",
  "tier": "observe",
  "clients": [
    "bearer",
    "browser_session"
  ],
  "summary": "The connected identity and its standing. For the session credential and the browser session it also answers the provider-verified address (`address`, null where none is held), the acting credential's grants (`grants`), and the sign-in instant the credential carries (`signed_in_at`: the API cookie's own for a browser session, null for a bearer at this revision), so a page can render a sign-in link in place of each control once the freshness window has passed, and the account's passkey standing (`passkeys`: the counts `held` and `stranded` and nothing of a credential, null where no passkey ceremony is served); the platform credential and an application-bounded minted token receive none of the four.",
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "openWorldHint": false,
    "idempotentHint": true
  }
}

MCP catalog entry

{
  "name": "read_account",
  "tier": "observe",
  "scenario": "CHI-L0-04",
  "summary": "Read the account this connection represents: its sign-in identities (provider and verified subject), account standing (`active` or `suspended`), and product profiles. For a session credential, it also reads the provider-verified address (`address`), the credential's grants (`grants`), the sign-in instant it carries (`signed_in_at`, null for a bearer at this revision), and the passkey standing (`passkeys`). The passkey standing is counts only: how many of the account's passkeys sign in on this host as `held`, and how many were registered for another as `stranded`. It is null where no passkey ceremony is served. An application-bounded token receives none of the four.",
  "owners": []
}

request

JSON pointer Description and constraints
"" (root) Type: object
Additional properties: false

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","account"]
/properties/contract_version Required value: 1
/properties/reference The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call.

Type: string
Pattern: ^[0-9a-f]{10}$
/properties/account Type: object
Required fields: ["id","created_at","standing","identities","synthetic","unbilled"]
/properties/account/properties/id Type: string
/properties/account/properties/created_at Type: string
/properties/account/properties/standing Type: string
/properties/account/properties/identities Type: array
/properties/account/properties/identities/items Type: object
Required fields: ["provider","subject"]
/properties/account/properties/identities/items/properties/provider Type: string
/properties/account/properties/identities/items/properties/subject Type: string
/properties/account/properties/profiles The product profiles the account carries, one per product the person took up (ACB-L0-76): the product code name and the stamp its first run added it.

Type: array
/properties/account/properties/profiles/items Type: object
Required fields: ["product","created_at"]
Additional properties: false
/properties/account/properties/profiles/items/properties/product Type: string
/properties/account/properties/profiles/items/properties/created_at Type: string
/properties/account/properties/synthetic true on a synthetic account — a test fixture seed_synthetic_accounts created, which no sign-in creates and no billing or product analytics counts (ACB-L0-79) — and false on every account a sign-in created.

Type: boolean
/properties/account/properties/unbilled true on an account a super-admin has marked unbilled, the company's own or a complimentary one — free of the per-account application limits and never charged (ACB-L0-84) — and false on every other account.

Type: boolean
/properties/account/properties/address The provider-verified address an identity of the account carries, or null; answered to the session credential and the browser session alone (MAPI-03; WEB-L0-17).

Type: ["string","null"]
/properties/account/properties/grants The acting credential's grant markings (MAPI-09: `super_admin`); answered to the session kinds alone.

Type: array
/properties/account/properties/grants/items Type: string
/properties/account/properties/signed_in_at The sign-in instant the credential carries, ISO 8601: the API cookie's own for a browser session, null for a bearer at this revision; answered to the session kinds alone, so a page renders a sign-in link once the freshness window has passed (WEB-L0-16).

Type: ["string","null"]
/properties/account/properties/passkeys The account's passkey standing: two counts and nothing of a credential — no identifier, name, or date. A page and a connected tool read whether a passkey is set without the passkey page's fresh-session read. It is null where the platform serves no passkey ceremony on this host. It is answered to the session kinds alone (ACS-L0-10).

Type: ["object","null"]
Required fields: ["held","stranded"]
Additional properties: false
/properties/account/properties/passkeys/properties/held How many of the account's passkeys sign in on this host: the ones registered under the current relying-party identifier.

Type: integer
Minimum: 0
/properties/account/properties/passkeys/properties/stranded How many of the account's passkeys do not sign in on this host: the ones registered for another host, or before the host was recorded; no browser offers them here, and the passkey page removes them.

Type: integer
Minimum: 0

Complete payload contract

{
  "request": {
    "type": "object",
    "properties": {},
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "account"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "reference": {
        "type": "string",
        "pattern": "^[0-9a-f]{10}$",
        "description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
      },
      "account": {
        "type": "object",
        "required": [
          "id",
          "created_at",
          "standing",
          "identities",
          "synthetic",
          "unbilled"
        ],
        "properties": {
          "id": {
            "type": "string"
          },
          "created_at": {
            "type": "string"
          },
          "standing": {
            "type": "string"
          },
          "identities": {
            "type": "array",
            "items": {
              "type": "object",
              "required": [
                "provider",
                "subject"
              ],
              "properties": {
                "provider": {
                  "type": "string"
                },
                "subject": {
                  "type": "string"
                }
              }
            }
          },
          "profiles": {
            "type": "array",
            "description": "The product profiles the account carries, one per product the person took up (ACB-L0-76): the product code name and the stamp its first run added it.",
            "items": {
              "type": "object",
              "required": [
                "product",
                "created_at"
              ],
              "properties": {
                "product": {
                  "type": "string"
                },
                "created_at": {
                  "type": "string"
                }
              },
              "additionalProperties": false
            }
          },
          "synthetic": {
            "type": "boolean",
            "description": "true on a synthetic account — a test fixture seed_synthetic_accounts created, which no sign-in creates and no billing or product analytics counts (ACB-L0-79) — and false on every account a sign-in created."
          },
          "unbilled": {
            "type": "boolean",
            "description": "true on an account a super-admin has marked unbilled, the company's own or a complimentary one — free of the per-account application limits and never charged (ACB-L0-84) — and false on every other account."
          },
          "address": {
            "type": [
              "string",
              "null"
            ],
            "description": "The provider-verified address an identity of the account carries, or null; answered to the session credential and the browser session alone (MAPI-03; WEB-L0-17)."
          },
          "grants": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "The acting credential's grant markings (MAPI-09: `super_admin`); answered to the session kinds alone."
          },
          "signed_in_at": {
            "type": [
              "string",
              "null"
            ],
            "description": "The sign-in instant the credential carries, ISO 8601: the API cookie's own for a browser session, null for a bearer at this revision; answered to the session kinds alone, so a page renders a sign-in link once the freshness window has passed (WEB-L0-16)."
          },
          "passkeys": {
            "type": [
              "object",
              "null"
            ],
            "required": [
              "held",
              "stranded"
            ],
            "additionalProperties": false,
            "properties": {
              "held": {
                "type": "integer",
                "minimum": 0,
                "description": "How many of the account's passkeys sign in on this host: the ones registered under the current relying-party identifier."
              },
              "stranded": {
                "type": "integer",
                "minimum": 0,
                "description": "How many of the account's passkeys do not sign in on this host: the ones registered for another host, or before the host was recorded; no browser offers them here, and the passkey page removes them."
              }
            },
            "description": "The account's passkey standing: two counts and nothing of a credential — no identifier, name, or date. A page and a connected tool read whether a passkey is set without the passkey page's fresh-session read. It is null where the platform serves no passkey ceremony on this host. It is answered to the session kinds alone (ACS-L0-10)."
          }
        }
      }
    }
  }
}

Shared contracts