Update jurisdiction
Moves an existing session to a new jurisdiction and re-evaluates it under that jurisdiction's rules. The response is the updated session, or a challenge when the new jurisdiction requires guardian approval the player does not yet have.
Authorization
api-key In: header
Request Body
application/json
Update jurisdiction request
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
curl -X POST "https://example.com/session/update-jurisdiction" \ -H "Content-Type: application/json" \ -d '{ "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672", "jurisdiction": "US-CA" }'{ "session": { "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672", "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d", "etag": "e889efb9e8a985308e82bed78c5aef7f37f50cf36b7337bf654980d0bab7a574", "status": "ACTIVE", "permissions": [ { "name": "public-profile", "enabled": true, "managedBy": "PLAYER", "verifiedAgeThreshold": 18 } ], "allowances": [ { "name": "string", "type": "numerical", "numericalValue": 0.1 } ], "ageStatus": "DIGITAL_MINOR", "ageCategory": "digital-minor", "dateOfBirth": "2005-04-15", "jurisdiction": "US-CA", "managedBy": "PLAYER", "hasApproverEmail": true, "ageVerification": { "verifiedAge": 18, "platformName": "apple-ios", "declarationType": "confirmed", "verificationId": "a50f4f73-3c0c-4720-a8b3-ec57ccb0aa34", "verifiedAt": "2026-03-14T00:00:00Z", "verifiedDob": "2008-03-15" }, "requiredDataProcessingConsentFor": [ "string" ] }, "challenge": { "challengeId": "ae6d4729-af32-42ea-8ef2-ff46c7664802", "type": "CHALLENGE_PARENTAL_CONSENT", "url": "https://example.com/challenge", "oneTimePassword": "123456", "childLiteAccessEnabled": true, "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d", "jurisdiction": "US-CA", "age": 13, "dateOfBirth": "2005-04-15", "otpExpiresAt": "2022-01-01T00:00:00Z", "materialChange": { "presentedDocuments": [ "string" ], "issuedAt": "2019-08-24T14:15:22Z", "actionedAt": "2019-08-24T14:15:22Z", "acceptanceDeadline": "2019-08-24T14:15:22Z" }, "documents": [ { "id": "privacy-policy", "name": "Privacy Policy", "url": "https://example.com/privacy", "isDataNotice": false } ] }}Unlink a parent from a session POST
Unlinks a parent from a player session that was previously linked via the `/invite-parent` flow. On success the call wipes any parent-set preferences on the session and fires the `Session.Unlink` webhook. Permissions and existing player data are left intact. The endpoint is idempotent on `sessionId`. A second call after the link is already removed returns 200 with the original `unlinkedAt`.
Upgrade session POST
Upgrades a player's session to an active one, creating challenges where the requested permissions need guardian consent. Identify the session by `sessionId`, by `kuid`, or by both — both together associate that user with an existing session. Passing neither is a bad request. Use `options` to tune age assurance for any challenge this call mints, and `materialChange` to name the exact legal documents to present for consent. Setting `materialChange.acceptanceDeadline` makes the upgrade deadline-bound: the guardian is emailed an approve-request link and must accept by that timestamp. Any future UTC timestamp is honoured exactly as supplied — there is no minimum window and no rounding — so a deadline minutes away stays minutes away. Omit it to present the documents with no deadline. Set `priorChallengeId` to re-consent when documents change. The new challenge supersedes a pending or in-progress one and adds to its documents (additive only), and any earlier link resolves to the latest. `requestedPermissions` may be empty. On a session that still has data notices awaiting guardian acceptance, an empty array requests that re-consent on its own: with a guardian already on file the response carries a `CHALLENGE_MATERIAL_CHANGE` scoped to exactly the outstanding notices, and with no guardian on file it carries a full `CHALLENGE_PARENTAL_CONSENT` that collects the guardian and presents the product's whole picture. On a session with nothing outstanding an empty array returns the session unchanged and no challenge. Pair it with `priorChallengeId` to supersede a challenge that is already pending rather than adding another alongside it. `priorChallengeId` only takes effect when the call mints a challenge; on a request that mints none, such as one asking only for player-managed permissions, it is still validated but the prior challenge is left as it is. A one-time password on a returned challenge expires. Call `/challenge/generate-otp` when you are ready to display it, and regenerate it periodically until the challenge is in progress.