# Sessions

> The caller's own signed-in sessions, across every workspace, newest first; the one this request came in on is marked; Sign one of the caller's other sessions out; it is refused on its next request; Sign out every session of the caller's but the one this request came in on

## The caller's own signed-in sessions, across every workspace, newest first; the one this request came in on is marked

`GET /v1/sessions` · operation `listSessions`

Requires the `batondeck:workspace:read` permission (action `session:list`).

**Responses**

| Status | Meaning |
|---|---|
| 200 | The caller's own signed-in sessions, across every workspace, newest first; the one this request came in on is marked |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "sessions": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string"
          },
          "device": {
            "type": "string"
          },
          "country": {
            "type": "string"
          },
          "created_at": {
            "type": "number"
          },
          "last_seen_at": {
            "type": "number"
          },
          "expires_at": {
            "type": "number"
          },
          "current": {
            "type": "boolean"
          }
        },
        "required": [
          "id",
          "device",
          "country",
          "created_at",
          "last_seen_at",
          "expires_at",
          "current"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "sessions"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/sessions' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## Sign one of the caller's other sessions out; it is refused on its next request

`DELETE /v1/sessions/{id}` · operation `revokeSession`

Requires the `batondeck:workspace:read` permission (action `session:revoke`).

Allowed while the workspace is paused, suspended or on deletion hold: it only takes access away.

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `id` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 204 | Done. No body. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

```sh
curl -X DELETE 'https://api.batondeck.com/v1/sessions/:id' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## Sign out every session of the caller's but the one this request came in on

`POST /v1/sessions/sign-out-others` · operation `revokeOtherSessions`

Requires the `batondeck:workspace:read` permission (action `session:revoke`).

Allowed while the workspace is paused, suspended or on deletion hold: it only takes access away.

**Responses**

| Status | Meaning |
|---|---|
| 200 | Sign out every session of the caller's but the one this request came in on |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "revoked": {
      "type": "number"
    }
  },
  "required": [
    "revoked"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/sessions/sign-out-others' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```
