Parameters
No parameters required
This endpoint takes no path, query, header or body parameters.
Returns every authorised shop__contact_login_identity row for the current user — browser sessions and AI-agent credentials both. API keys are excluded (external-integration credentials owned by the organisation, not personal seats). Powers the settings > security > active sessions grid; the currentSessionId field identifies which row belongs to the calling browser.
No parameters required
This endpoint takes no path, query, header or body parameters.
1 status code documented
itemCountnumberRequiredTotal number of active sessions returned.
currentSessionIdnumber | nullRequiredInternal id of the row backing the caller's current session, or null when the caller is not authenticated by a cookie.
itemsobject[]RequiredidnumberRequiredInternal id of the shop__contact_login_identity row (the only wire handle for logout).
kind"human" | "ai_agent"RequiredBrowser session vs. AI-agent credential provisioned via /bff/ai-agent/provision.
agentChildCountnumberRequiredCount of active AI-agent rows whose parent_identity_id points at this session. Always 0 for ai_agent rows themselves.
insertedDatestringRequiredISO datetime when the session was created (login or provisioning).
expirationDatestringRequiredISO datetime when the session will expire on its own (~3 months for humans, 30 days for agents).
lastActivityDatestring | nullRequiredISO datetime of the last request that used this identity, or null if never used.
devicestring | nullRequiredParsed device label from the User-Agent, if available.
userAgentstring | nullRequiredRaw User-Agent header captured at creation.
ipstringRequiredAccepted formats:
1.1.1.1 (4 octets, 0–255, no leading zeros).2001:0db8:0000:0000:0000:0000:0000:0001, zero-compressed 2001:db8::1, IPv4-mapped ::ffff:1.2.3.4, or scoped literals. Both upper- and lower-case hex are accepted.Server-side canonicalization (ipNormalize in core/src/lib/network/ipNormalize.ts):
::ffff:X.X.X.X is unwrapped to plain IPv4 (RFC 4291 §2.5.5.2) so 1.2.3.4 and ::ffff:1.2.3.4 share one brj__geo_ip row.::1, 0.0.0.0, localhost, empty string) collapse to 127.0.0.1.127.0.0.1 (loopback).On the wire: every response returns the canonicalized form — clients can safely rely on lowercase IPv6 and the plain-IPv4 unwrap when de-duping or joining. Server-originated writers (activity log, session log, ban list) resolve the visitor IP via resolveClientIp / resolveClientIpOrNull — always native IPv6 on Vercel Edge (there is no auto-mapping to ::ffff:X.X.X.X).
Enrichment: the system resolves reverse DNS, geolocation, ASN, mobile/proxy/hosting/Tor flags via our VikiTron GEO/IP resolver for both address families. Learn more
1.1.1.12001:4860:4860::8888hostnamestring | nullRequiredReverse-DNS hostname of the IP.
citystring | nullRequiredCity resolved from GeoIP.
countrystring | nullRequiredISO country code resolved from GeoIP.
countryRegionstring | nullRequiredRegion/state resolved from GeoIP.
asnstring | nullRequiredASN of the network owning the IP.
asnOrganizationstring | nullRequiredASN owner organisation name.
ispstring | nullRequiredISP name from the GeoIP database.
mobilebooleanRequiredTrue if the IP belongs to a mobile carrier.
proxybooleanRequiredTrue if the IP is a known anonymising proxy.
hostingbooleanRequiredTrue if the IP belongs to a hosting/cloud provider.
torbooleanRequiredTrue if the IP is a known Tor exit node.
{
"itemCount": 0,
"items": [
{
"id": 0,
"agentChildCount": 0,
"insertedDate": "example_insertedDate",
"expirationDate": "example_expirationDate",
"ip": "1.1.1.1",
"mobile": false,
"proxy": false,
"hosting": false,
"tor": false
}
]
}GET /bff/account/active-sessions
curl -X GET "https://api.bizkithub.com/bff/account/active-sessions" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_KEY"All BizKitHub public API endpoints require authentication via API key.