# Identities

> The identities in the signed-in workspace; One identity: its key fingerprint, hostname and card; Erase one identity: its object, its media, and its routing row

## The identities in the signed-in workspace

`GET /v1/identities` · operation `listIdentities`

Requires the `batondeck:identities:read` permission (action `identity:list`).

**Responses**

| Status | Meaning |
|---|---|
| 200 | The identities in the signed-in workspace |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "identities": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "slug": {
            "type": "string"
          },
          "account_id": {
            "type": "string"
          },
          "fingerprint": {
            "type": "string"
          },
          "status": {
            "type": "string"
          },
          "hostname": {
            "type": "string"
          },
          "certified": {
            "type": "boolean"
          },
          "created_at": {
            "type": "number"
          }
        },
        "required": [
          "slug",
          "account_id",
          "fingerprint",
          "status",
          "hostname",
          "certified",
          "created_at"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "identities"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/identities' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## One identity: its key fingerprint, hostname and card

`GET /v1/identities/{slug}` · operation `getIdentity`

Requires the `batondeck:identities:read` permission (action `identity:read`).

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 200 | One identity: its key fingerprint, hostname and card |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "slug": {
      "type": "string"
    },
    "account_id": {
      "type": "string"
    },
    "fingerprint": {
      "type": "string"
    },
    "status": {
      "type": "string"
    },
    "hostname": {
      "type": "string"
    },
    "certified": {
      "type": "boolean"
    },
    "created_at": {
      "type": "number"
    },
    "card": {
      "type": "string"
    }
  },
  "required": [
    "slug",
    "account_id",
    "fingerprint",
    "status",
    "hostname",
    "certified",
    "created_at",
    "card"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/identities/:slug' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## Erase one identity: its object, its media, and its routing row

`DELETE /v1/identities/{slug}` · operation `deleteIdentity`

Requires the `batondeck:identities:manage` permission (action `identity:delete`).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. **Not reachable with an API key** — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 204 | Done. No body. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

```sh
curl -X DELETE 'https://api.batondeck.com/v1/identities/:slug' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```
