EndpointsSessions

Update jurisdiction

Moves an existing session to a new jurisdiction and re-evaluates it under that jurisdiction's rules. The response is the updated session, or a challenge when the new jurisdiction requires guardian approval the player does not yet have.

POST
/session/update-jurisdiction
AuthorizationBearer <token>

In: header

Request Body

application/json

Update jurisdiction request

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

curl -X POST "https://example.com/session/update-jurisdiction" \  -H "Content-Type: application/json" \  -d '{    "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672",    "jurisdiction": "US-CA"  }'
{  "session": {    "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672",    "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d",    "etag": "e889efb9e8a985308e82bed78c5aef7f37f50cf36b7337bf654980d0bab7a574",    "status": "ACTIVE",    "permissions": [      {        "name": "public-profile",        "enabled": true,        "managedBy": "PLAYER",        "verifiedAgeThreshold": 18      }    ],    "allowances": [      {        "name": "string",        "type": "numerical",        "numericalValue": 0.1      }    ],    "ageStatus": "DIGITAL_MINOR",    "ageCategory": "digital-minor",    "dateOfBirth": "2005-04-15",    "jurisdiction": "US-CA",    "managedBy": "PLAYER",    "hasApproverEmail": true,    "ageVerification": {      "verifiedAge": 18,      "platformName": "apple-ios",      "declarationType": "confirmed",      "verificationId": "a50f4f73-3c0c-4720-a8b3-ec57ccb0aa34",      "verifiedAt": "2026-03-14T00:00:00Z",      "verifiedDob": "2008-03-15"    },    "requiredDataProcessingConsentFor": [      "string"    ]  },  "challenge": {    "challengeId": "ae6d4729-af32-42ea-8ef2-ff46c7664802",    "type": "CHALLENGE_PARENTAL_CONSENT",    "url": "https://example.com/challenge",    "oneTimePassword": "123456",    "childLiteAccessEnabled": true,    "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d",    "jurisdiction": "US-CA",    "age": 13,    "dateOfBirth": "2005-04-15",    "otpExpiresAt": "2022-01-01T00:00:00Z",    "materialChange": {      "presentedDocuments": [        "string"      ],      "issuedAt": "2019-08-24T14:15:22Z",      "actionedAt": "2019-08-24T14:15:22Z",      "acceptanceDeadline": "2019-08-24T14:15:22Z"    },    "documents": [      {        "id": "privacy-policy",        "name": "Privacy Policy",        "url": "https://example.com/privacy",        "isDataNotice": false      }    ]  }}

Unlink a parent from a session POST

Unlinks a parent from a player session that was previously linked via the `/invite-parent` flow. On success the call wipes any parent-set preferences on the session and fires the `Session.Unlink` webhook. Permissions and existing player data are left intact. The endpoint is idempotent on `sessionId`. A second call after the link is already removed returns 200 with the original `unlinkedAt`.

Upgrade session POST

Upgrades a player's session to an active one, creating challenges where the requested permissions need guardian consent. Identify the session by `sessionId`, by `kuid`, or by both — both together associate that user with an existing session. Passing neither is a bad request. Use `options` to tune age assurance for any challenge this call mints, and `materialChange` to name the exact legal documents to present for consent. Setting `materialChange.acceptanceDeadline` makes the upgrade deadline-bound: the guardian is emailed an approve-request link and must accept by that timestamp. Any future UTC timestamp is honoured exactly as supplied — there is no minimum window and no rounding — so a deadline minutes away stays minutes away. Omit it to present the documents with no deadline. Set `priorChallengeId` to re-consent when documents change. The new challenge supersedes a pending or in-progress one and adds to its documents (additive only), and any earlier link resolves to the latest. `requestedPermissions` may be empty. On a session that still has data notices awaiting guardian acceptance, an empty array requests that re-consent on its own: with a guardian already on file the response carries a `CHALLENGE_MATERIAL_CHANGE` scoped to exactly the outstanding notices, and with no guardian on file it carries a full `CHALLENGE_PARENTAL_CONSENT` that collects the guardian and presents the product's whole picture. On a session with nothing outstanding an empty array returns the session unchanged and no challenge. Pair it with `priorChallengeId` to supersede a challenge that is already pending rather than adding another alongside it. `priorChallengeId` only takes effect when the call mints a challenge; on a request that mints none, such as one asking only for player-managed permissions, it is still validated but the prior challenge is left as it is. A one-time password on a returned challenge expires. Call `/challenge/generate-otp` when you are ready to display it, and regenerate it periodically until the challenge is in progress.