EndpointsSessions

Upgrade session

Upgrades a player's session to an active one, creating challenges where the requested permissions need guardian consent. Identify the session by `sessionId`, by `kuid`, or by both — both together associate that user with an existing session. Passing neither is a bad request. Use `options` to tune age assurance for any challenge this call mints, and `materialChange` to name the exact legal documents to present for consent. Setting `materialChange.acceptanceDeadline` makes the upgrade deadline-bound: the guardian is emailed an approve-request link and must accept by that timestamp. Any future UTC timestamp is honoured exactly as supplied — there is no minimum window and no rounding — so a deadline minutes away stays minutes away. Omit it to present the documents with no deadline. Set `priorChallengeId` to re-consent when documents change. The new challenge supersedes a pending or in-progress one and adds to its documents (additive only), and any earlier link resolves to the latest. `requestedPermissions` may be empty. On a session that still has data notices awaiting guardian acceptance, an empty array requests that re-consent on its own: with a guardian already on file the response carries a `CHALLENGE_MATERIAL_CHANGE` scoped to exactly the outstanding notices, and with no guardian on file it carries a full `CHALLENGE_PARENTAL_CONSENT` that collects the guardian and presents the product's whole picture. On a session with nothing outstanding an empty array returns the session unchanged and no challenge. Pair it with `priorChallengeId` to supersede a challenge that is already pending rather than adding another alongside it. `priorChallengeId` only takes effect when the call mints a challenge; on a request that mints none, such as one asking only for player-managed permissions, it is still validated but the prior challenge is left as it is. A one-time password on a returned challenge expires. Call `/challenge/generate-otp` when you are ready to display it, and regenerate it periodically until the challenge is in progress.

POST
/session/upgrade
AuthorizationBearer <token>

In: header

Request Body

application/json

Upgrade session request

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X POST "https://example.com/session/upgrade" \  -H "Content-Type: application/json" \  -d '{    "requestedPermissions": [      {        "name": "public-profile"      },      {        "name": "voice-chat"      },      {        "name": "online-status"      }    ]  }'

{  "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672",  "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d",  "ageStatus": "LEGAL_ADULT",  "ageCategory": "adult",  "etag": "e889efb9e8a985308e82bed78c5aef7f37f50cf36b7337bf654980d0bab7a574",  "status": "ACTIVE",  "dateOfBirth": "2005-04-15",  "jurisdiction": "US-CA",  "managedBy": "PLAYER",  "permissions": [    {      "name": "text-chat-public",      "enabled": false,      "managedBy": "GUARDIAN"    },    {      "name": "text-chat-private",      "enabled": true,      "managedBy": "PLAYER"    },    {      "name": "forums",      "enabled": false,      "managedBy": "PROHIBITED"    }  ],  "allowances": [    {      "name": "3516-7b2e",      "numericalValue": 5,      "type": "numerical"    },    {      "name": "63d3-90ac",      "selectionValue": "733c-ca11",      "type": "selection"    }  ]}