Upgrade session
Upgrades a player's session to an active one, creating challenges where the requested permissions need guardian consent. Identify the session by `sessionId`, by `kuid`, or by both — both together associate that user with an existing session. Passing neither is a bad request. Use `options` to tune age assurance for any challenge this call mints, and `materialChange` to name the exact legal documents to present for consent. Setting `materialChange.acceptanceDeadline` makes the upgrade deadline-bound: the guardian is emailed an approve-request link and must accept by that timestamp. Any future UTC timestamp is honoured exactly as supplied — there is no minimum window and no rounding — so a deadline minutes away stays minutes away. Omit it to present the documents with no deadline. Set `priorChallengeId` to re-consent when documents change. The new challenge supersedes a pending or in-progress one and adds to its documents (additive only), and any earlier link resolves to the latest. `requestedPermissions` may be empty. On a session that still has data notices awaiting guardian acceptance, an empty array requests that re-consent on its own: with a guardian already on file the response carries a `CHALLENGE_MATERIAL_CHANGE` scoped to exactly the outstanding notices, and with no guardian on file it carries a full `CHALLENGE_PARENTAL_CONSENT` that collects the guardian and presents the product's whole picture. On a session with nothing outstanding an empty array returns the session unchanged and no challenge. Pair it with `priorChallengeId` to supersede a challenge that is already pending rather than adding another alongside it. `priorChallengeId` only takes effect when the call mints a challenge; on a request that mints none, such as one asking only for player-managed permissions, it is still validated but the prior challenge is left as it is. A one-time password on a returned challenge expires. Call `/challenge/generate-otp` when you are ready to display it, and regenerate it periodically until the challenge is in progress.
Authorization
api-key In: header
Request Body
application/json
Upgrade session request
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
curl -X POST "https://example.com/session/upgrade" \ -H "Content-Type: application/json" \ -d '{ "requestedPermissions": [ { "name": "public-profile" }, { "name": "voice-chat" }, { "name": "online-status" } ] }'{ "sessionId": "b1a6482d-5242-4b4a-aa88-3fa52595a672", "kuid": "12b9fa0e-6d6d-4903-a1fc-f2233027b71d", "ageStatus": "LEGAL_ADULT", "ageCategory": "adult", "etag": "e889efb9e8a985308e82bed78c5aef7f37f50cf36b7337bf654980d0bab7a574", "status": "ACTIVE", "dateOfBirth": "2005-04-15", "jurisdiction": "US-CA", "managedBy": "PLAYER", "permissions": [ { "name": "text-chat-public", "enabled": false, "managedBy": "GUARDIAN" }, { "name": "text-chat-private", "enabled": true, "managedBy": "PLAYER" }, { "name": "forums", "enabled": false, "managedBy": "PROHIBITED" } ], "allowances": [ { "name": "3516-7b2e", "numericalValue": 5, "type": "numerical" }, { "name": "63d3-90ac", "selectionValue": "733c-ca11", "type": "selection" } ]}{ "error": "NOT_FOUND", "errorMessage": "Session not found"}Update jurisdiction POST
Moves an existing session to a new jurisdiction and re-evaluates it under that jurisdiction's rules. The response is the updated session, or a challenge when the new jurisdiction requires guardian approval the player does not yet have.
Cancel a parent invite POST
Cancels an in-flight parent-invite challenge before the parent has completed it. Used when the player cancels their pending invite from inside your application while the parent is mid-verification. On cancel the challenge transitions to FAIL with `failureReason: "cancelled-by-initiator"` and any parent currently viewing the hosted widget sees the "invite canceled" state. Only `CHALLENGE_PARENT_INVITE` challenges may be cancelled via this endpoint.