read_test_signin_code
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/read_test_signin_code, with a bearer credential and the action's payload as the JSON body. It also accepts GET.
Contract description
Read the sign-in code held for one of your test end users, by `end_user` (its id) or `email` (its address), instead of a mailbox. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on. Answers the unspent codes newest first, each with `issued_at`, `expires_at`, its `binding` hash, and `attempts_remaining`; pass `binding` (base64url of the SHA-256 of the binding cookie your sign-in start received) to get that start's code alone. A code lives ten minutes, admits five attempts, and confirms only in the browser that started the sign-in. Admitted to your own account's session or tokens for your own application and to nobody else. Refused `not_test_end_user` for a user who is not an unexpired test end user of that realm. Works while the platform's `TEST_END_USERS` setting is off. Every read is an action record; no code reaches any record.
Access and action metadata
{
"name": "read_test_signin_code",
"resource": "realm",
"tier": "observe",
"summary": "Read the unspent emailed sign-in codes held for one test end user of one realm of the calling account's own application, by `end_user` or `email`, `application` and `environment` both required: newest first, each with its issued and expiry instants, its binding hash, and the attempts remaining, or one ticket's code alone where `binding` names the reader's own binding hash (base64url of the SHA-256 of the binding cookie's value). Admitted to the account's session, its account-wide token, or a token bounded to that application and to no other credential, `super_admin` widening it to no other account's application; refused `not_test_end_user` for a user who is not an unexpired test end user of the realm; readable while `TEST_END_USERS` reads `off`, every read one action record, and no code reaching any record.",
"annotations": {
"readOnlyHint": true,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "read_test_signin_code",
"tier": "observe",
"summary": "Read the sign-in code held for one of your test end users, by `end_user` (its id) or `email` (its address), instead of a mailbox. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on. Answers the unspent codes newest first, each with `issued_at`, `expires_at`, its `binding` hash, and `attempts_remaining`; pass `binding` (base64url of the SHA-256 of the binding cookie your sign-in start received) to get that start's code alone. A code lives ten minutes, admits five attempts, and confirms only in the browser that started the sign-in. Admitted to your own account's session or tokens for your own application and to nobody else. Refused `not_test_end_user` for a user who is not an unexpired test end user of that realm. Works while the platform's `TEST_END_USERS` setting is off. Every read is an action record; no code reaches any record.",
"owners": [
"ACS-L0-21",
"ACS-L0-20",
"ACS-L0-12",
"PLD-L0-40"
],
"scenario": "ACS-L0-21"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","environment"] Additional properties: false |
| / |
The application id, from `list_applications`; one of the calling account's own. Type: string |
| / |
Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement). Type: string Pattern: ^(development|production)$ |
| / |
The test end user's opaque identifier, as `create_test_end_users` or `list_end_users` answered it; one of `end_user` and `email` is required, and never both. Type: string |
| / |
The test end user's address at the fixture domain, lowercased; one of `end_user` and `email` is required, and never both. Type: string Format: email |
| / |
Optional: the reader's own binding hash, base64url of the SHA-256 of the binding cookie's value the sign-in start set, selecting that ticket's code alone; absent, every unspent code is answered newest first. Type: string |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","realm","end_user","codes"] Additional properties: false |
| / |
Required value: 1 |
| / |
The realm identifier: the application id for production, `<id>:development` for development. Type: string |
| / |
The test end user the codes are held for. Type: string |
| / |
The unspent codes the route holds for the user, newest first; empty where none is held, where every code is spent or expired, or where `binding` names no held ticket. Type: array |
| / |
Type: object Required fields: ["code","issued_at","expires_at","binding","attempts_remaining"] |
| / |
The six-digit code the person types on the code page. Type: string Pattern: ^[0-9]{6}$ |
| / |
Type: string |
| / |
The ticket's expiry, ten minutes after the start (ACS-L0-12). Type: string |
| / |
The ticket's binding hash, the browser that started the sign-in. Type: string |
| / |
The confirmations the code still admits, five at issue (ACS-L0-12). Type: integer Minimum: 0 |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"environment"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`; one of the calling account's own."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement)."
},
"end_user": {
"type": "string",
"description": "The test end user's opaque identifier, as `create_test_end_users` or `list_end_users` answered it; one of `end_user` and `email` is required, and never both."
},
"email": {
"type": "string",
"format": "email",
"description": "The test end user's address at the fixture domain, lowercased; one of `end_user` and `email` is required, and never both."
},
"binding": {
"type": "string",
"description": "Optional: the reader's own binding hash, base64url of the SHA-256 of the binding cookie's value the sign-in start set, selecting that ticket's code alone; absent, every unspent code is answered newest first."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"realm",
"end_user",
"codes"
],
"properties": {
"contract_version": {
"const": 1
},
"realm": {
"type": "string",
"description": "The realm identifier: the application id for production, `<id>:development` for development."
},
"end_user": {
"type": "string",
"description": "The test end user the codes are held for."
},
"codes": {
"type": "array",
"description": "The unspent codes the route holds for the user, newest first; empty where none is held, where every code is spent or expired, or where `binding` names no held ticket.",
"items": {
"type": "object",
"required": [
"code",
"issued_at",
"expires_at",
"binding",
"attempts_remaining"
],
"properties": {
"code": {
"type": "string",
"pattern": "^[0-9]{6}$",
"description": "The six-digit code the person types on the code page."
},
"issued_at": {
"type": "string"
},
"expires_at": {
"type": "string",
"description": "The ticket's expiry, ten minutes after the start (ACS-L0-12)."
},
"binding": {
"type": "string",
"description": "The ticket's binding hash, the browser that started the sign-in."
},
"attempts_remaining": {
"type": "integer",
"minimum": 0,
"description": "The confirmations the code still admits, five at issue (ACS-L0-12)."
}
}
}
},
"detail": {
"type": "string"
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md