Get session
Returns a previously created session, identified by `sessionId` or by `kuid` together with the product. Pass `etag` to make the read conditional: the session is returned only if it changed since the etag was issued, and an unchanged session responds `NOT_MODIFIED` instead. Poll with the etag rather than refetching the whole session. An `ACTIVE` status means the player meets the product's requirements, and the response carries the permissions in force for them. The etag covers the whole rendered response, including the `permissions`, `ageStatus` and `ageCategory` derived from your product and jurisdiction configuration — so a configuration change moves the etag even when the session itself did not change.
Authorization
api-key In: header
Query Parameters
The session ID of the player session
^[A-z0-9]{8}-[A-z0-9]{4}-[A-z0-9]{4}-[A-z0-9]{4}-[A-z0-9]{12}$uuidThe k-ID user ID of the player
^[A-z0-9]{8}-[A-z0-9]{4}-[A-z0-9]{4}-[A-z0-9]{4}-[A-z0-9]{12}$uuidThe etag from an earlier session response
Response Body
application/json
application/json
curl -X GET "https://example.com/session/get"{ "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672", "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d", "ageStatus": "LEGAL_ADULT", "ageCategory": "adult", "etag": "e889efb9e8a985308e82bed78c5aef7f37f50cf36b7337bf654980d0bab7a574", "status": "ACTIVE", "dateOfBirth": "2005-04-15", "jurisdiction": "US-CA", "managedBy": "PLAYER", "permissions": [ { "name": "text-chat-public", "enabled": false, "managedBy": "GUARDIAN" }, { "name": "text-chat-private", "enabled": true, "managedBy": "PLAYER" }, { "name": "forums", "enabled": false, "managedBy": "PROHIBITED" } ], "allowances": [ { "name": "3516-7b2e", "numericalValue": 5, "type": "numerical" }, { "name": "63d3-90ac", "selectionValue": "733c-ca11", "type": "selection" } ]}{ "error": "NOT_FOUND", "errorMessage": "Session not found"}Delete session POST
Deletes a player session by its session ID. The session must belong to the calling product. By default this is a soft delete: the session is marked revoked, is no longer queryable, and its player ID becomes reusable, but the record itself is retained. **Irreversible.** Setting `hardDelete` to `true` instead permanently deletes the session and its embedded consent — this cannot be undone. Available only to developers explicitly enabled for hard delete.
Set guardian-managed session permissions POST
Updates the permissions on a session that a guardian is allowed to manage. Permissions the product does not expose to guardians are ignored rather than rejected, so a request may legitimately change fewer permissions than it names. The response is the resulting permission set — read it back rather than assuming the request applied verbatim.