read_test_signin_code

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/read_test_signin_code, with a bearer credential and the action's payload as the JSON body. It also accepts GET.

Contract description

Read the sign-in code held for one of your test end users, by `end_user` (its id) or `email` (its address), instead of a mailbox. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on. Answers the unspent codes newest first, each with `issued_at`, `expires_at`, its `binding` hash, and `attempts_remaining`; pass `binding` (base64url of the SHA-256 of the binding cookie your sign-in start received) to get that start's code alone. A code lives ten minutes, admits five attempts, and confirms only in the browser that started the sign-in. Admitted to your own account's session or tokens for your own application and to nobody else. Refused `not_test_end_user` for a user who is not an unexpired test end user of that realm. Works while the platform's `TEST_END_USERS` setting is off. Every read is an action record; no code reaches any record.

Access and action metadata

{
  "name": "read_test_signin_code",
  "resource": "realm",
  "tier": "observe",
  "summary": "Read the unspent emailed sign-in codes held for one test end user of one realm of the calling account's own application, by `end_user` or `email`, `application` and `environment` both required: newest first, each with its issued and expiry instants, its binding hash, and the attempts remaining, or one ticket's code alone where `binding` names the reader's own binding hash (base64url of the SHA-256 of the binding cookie's value). Admitted to the account's session, its account-wide token, or a token bounded to that application and to no other credential, `super_admin` widening it to no other account's application; refused `not_test_end_user` for a user who is not an unexpired test end user of the realm; readable while `TEST_END_USERS` reads `off`, every read one action record, and no code reaching any record.",
  "annotations": {
    "readOnlyHint": true,
    "destructiveHint": false,
    "openWorldHint": false,
    "idempotentHint": true
  }
}

MCP catalog entry

{
  "name": "read_test_signin_code",
  "tier": "observe",
  "summary": "Read the sign-in code held for one of your test end users, by `end_user` (its id) or `email` (its address), instead of a mailbox. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on. Answers the unspent codes newest first, each with `issued_at`, `expires_at`, its `binding` hash, and `attempts_remaining`; pass `binding` (base64url of the SHA-256 of the binding cookie your sign-in start received) to get that start's code alone. A code lives ten minutes, admits five attempts, and confirms only in the browser that started the sign-in. Admitted to your own account's session or tokens for your own application and to nobody else. Refused `not_test_end_user` for a user who is not an unexpired test end user of that realm. Works while the platform's `TEST_END_USERS` setting is off. Every read is an action record; no code reaches any record.",
  "owners": [
    "ACS-L0-21",
    "ACS-L0-20",
    "ACS-L0-12",
    "PLD-L0-40"
  ],
  "scenario": "ACS-L0-21"
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["application","environment"]
Additional properties: false
/properties/application The application id, from `list_applications`; one of the calling account's own.

Type: string
/properties/environment Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement).

Type: string
Pattern: ^(development|production)$
/properties/end_user The test end user's opaque identifier, as `create_test_end_users` or `list_end_users` answered it; one of `end_user` and `email` is required, and never both.

Type: string
/properties/email The test end user's address at the fixture domain, lowercased; one of `end_user` and `email` is required, and never both.

Type: string
Format: email
/properties/binding Optional: the reader's own binding hash, base64url of the SHA-256 of the binding cookie's value the sign-in start set, selecting that ticket's code alone; absent, every unspent code is answered newest first.

Type: string

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","realm","end_user","codes"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/realm The realm identifier: the application id for production, `<id>:development` for development.

Type: string
/properties/end_user The test end user the codes are held for.

Type: string
/properties/codes The unspent codes the route holds for the user, newest first; empty where none is held, where every code is spent or expired, or where `binding` names no held ticket.

Type: array
/properties/codes/items Type: object
Required fields: ["code","issued_at","expires_at","binding","attempts_remaining"]
/properties/codes/items/properties/code The six-digit code the person types on the code page.

Type: string
Pattern: ^[0-9]{6}$
/properties/codes/items/properties/issued_at Type: string
/properties/codes/items/properties/expires_at The ticket's expiry, ten minutes after the start (ACS-L0-12).

Type: string
/properties/codes/items/properties/binding The ticket's binding hash, the browser that started the sign-in.

Type: string
/properties/codes/items/properties/attempts_remaining The confirmations the code still admits, five at issue (ACS-L0-12).

Type: integer
Minimum: 0
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "application",
      "environment"
    ],
    "properties": {
      "application": {
        "type": "string",
        "description": "The application id, from `list_applications`; one of the calling account's own."
      },
      "environment": {
        "type": "string",
        "pattern": "^(development|production)$",
        "description": "Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement)."
      },
      "end_user": {
        "type": "string",
        "description": "The test end user's opaque identifier, as `create_test_end_users` or `list_end_users` answered it; one of `end_user` and `email` is required, and never both."
      },
      "email": {
        "type": "string",
        "format": "email",
        "description": "The test end user's address at the fixture domain, lowercased; one of `end_user` and `email` is required, and never both."
      },
      "binding": {
        "type": "string",
        "description": "Optional: the reader's own binding hash, base64url of the SHA-256 of the binding cookie's value the sign-in start set, selecting that ticket's code alone; absent, every unspent code is answered newest first."
      }
    },
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "realm",
      "end_user",
      "codes"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "realm": {
        "type": "string",
        "description": "The realm identifier: the application id for production, `<id>:development` for development."
      },
      "end_user": {
        "type": "string",
        "description": "The test end user the codes are held for."
      },
      "codes": {
        "type": "array",
        "description": "The unspent codes the route holds for the user, newest first; empty where none is held, where every code is spent or expired, or where `binding` names no held ticket.",
        "items": {
          "type": "object",
          "required": [
            "code",
            "issued_at",
            "expires_at",
            "binding",
            "attempts_remaining"
          ],
          "properties": {
            "code": {
              "type": "string",
              "pattern": "^[0-9]{6}$",
              "description": "The six-digit code the person types on the code page."
            },
            "issued_at": {
              "type": "string"
            },
            "expires_at": {
              "type": "string",
              "description": "The ticket's expiry, ten minutes after the start (ACS-L0-12)."
            },
            "binding": {
              "type": "string",
              "description": "The ticket's binding hash, the browser that started the sign-in."
            },
            "attempts_remaining": {
              "type": "integer",
              "minimum": 0,
              "description": "The confirmations the code still admits, five at issue (ACS-L0-12)."
            }
          }
        }
      },
      "detail": {
        "type": "string"
      }
    },
    "additionalProperties": false
  }
}

Shared contracts