OUTCOME · Reconcile
What changes
Read-only projection; it grants no mutation, settlement, traffic, or authority change.
v2User Profile Data
/api/v2/me/authentication-eventsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this when an identity, compliance, relying-party, or trust agent workflow needs to reconcile the chronology and current state of authentication events so it can make a purpose-limited identity or assurance decision with current policy and lifecycle state.
OUTCOME · Reconcile
Read-only projection; it grants no mutation, settlement, traffic, or authority change.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the sessions:read scope.EXAMPLEBearer hc_live_…
cursorqueryOptionalintegrity-protected opaque stringCursor returned by the preceding page. Modified or fabricated cursors are rejected.
limitqueryOptionalinteger · 1–100Maximum successful authentication records to return; defaults to 50.EXAMPLE50
RESPONSES
{
"items": [
{
"event_id": "9b51ed4c9c8f4aec85d1bd5520e40557",
"event_type": "SESSION_CREATED",
"outcome": "SUCCEEDED",
"authentication_method": "federated_github",
"device": {
"name": "Production CLI",
"platform": "server"
},
"session_status": "REVOKED",
"current_session": false,
"occurred_at": "2026-08-13T20:00:00Z",
"last_seen_at": "2026-08-13T20:10:00Z",
"revoked_at": "2026-08-13T20:15:00Z"
}
],
"next_cursor": "NDIuYWJj…"
}{
"code": "invalid_profile_request",
"message": "The cursor is malformed or fails integrity verification."
}invalid_profile_request{
"code": "invalid_credentials",
"message": "The bearer credential is missing, expired, or invalid."
}invalid_credentials{
"code": "profile_action_forbidden",
"message": "The session lacks sessions:read."
}profile_action_forbidden{
"code": "invalid_limit",
"message": "The requested page size is outside 1–100."
}invalid_limit{
"code": "identity_unavailable",
"message": "The authoritative Identity session history is unavailable."
}identity_unavailableOPERATIONAL NOTES
UPGRADING FROM V1
If you maintain an older integration, use this map to find the V2 replacement. Do not translate the old request field-for-field: rebuild it from the V2 parameters and schemas above because identity, authorization, replay protection, and response semantics may have changed.
/api/v1/profile/last_loginsPROFILE: Get Last LoginsThis route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗