API reference
Account
GET
cookieAuthcookie
odx_session<token>Current account
application/json- response
user*organizations*array<>mfa_required*booleanTrue while the session still needs a second factor; other endpoints return 401 mfa_required.
curl -X GET "https://example.com/account"{ "user": { "id": 0, "email": "string", "name": "string", "locale": "string", "email_verified": true, "mfa_enabled": true, "has_password": true, "created": "2019-08-24T14:15:22Z" }, "organizations": [ { "id": 0, "name": "string", "kind": "personal", "role": "owner", "status": "active" } ], "mfa_required": true}PATCH
cookieAuthcookie
odx_session<token>application/json- body
name?stringLength
1 <= length <= 100locale?stringValue in
"en""de""fa""tr"Updated user
application/json- response
user*curl -X PATCH "https://example.com/account" \ -H "Content-Type: application/json" \ -d '{}'{ "user": { "id": 0, "email": "string", "name": "string", "locale": "string", "email_verified": true, "mfa_enabled": true, "has_password": true, "created": "2019-08-24T14:15:22Z" }}POST
cookieAuthcookie
odx_session<token>application/json- body
current_password?stringRequired when the account has a password
new_password*stringLength
10 <= length <= 128Changed
curl -X POST "https://example.com/account/password" \ -H "Content-Type: application/json" \ -d '{ "new_password": "stringstri" }'Empty
POST
cookieAuthcookie
odx_session<token>Secret to show as a QR code
application/json- response
secret*stringotpauth_url*stringcurl -X POST "https://example.com/account/mfa/totp/setup"{ "secret": "string", "otpauth_url": "string"}POST
cookieAuthcookie
odx_session<token>application/json- body
code*stringEnabled
application/json- response
recovery_codes*array<string>curl -X POST "https://example.com/account/mfa/totp/enable" \ -H "Content-Type: application/json" \ -d '{ "code": "string" }'{ "recovery_codes": [ "string" ]}POST
cookieAuthcookie
odx_session<token>application/json- body
code*stringDisabled
curl -X POST "https://example.com/account/mfa/totp/disable" \ -H "Content-Type: application/json" \ -d '{ "code": "string" }'Empty
GET
cookieAuthcookie
odx_session<token>Sessions
application/json- response
sessions*array<>curl -X GET "https://example.com/account/sessions"{ "sessions": [ { "id": 0, "ip": "string", "user_agent": "string", "current": true, "created": "2019-08-24T14:15:22Z", "last_seen": "2019-08-24T14:15:22Z" } ]}DELETE
cookieAuthcookie
odx_session<token>id*integerFormat
int64Revoked
curl -X DELETE "https://example.com/account/sessions/0"Empty
GET
cookieAuthcookie
odx_session<token>JSON export
application/json- response
[key: string]?anycurl -X GET "https://example.com/account/export"{}POST
Only possible when your personal organization has no resources left and no negative balance. Personal data is erased; invoices and ledger entries are kept as the law requires, without your name.
cookieAuthcookie
odx_session<token>application/json- body
confirm*stringMust be your email address
password?stringRequired when the account has a password
code?stringTOTP code when two-factor authentication is on
Deleted and signed out
curl -X POST "https://example.com/account/delete" \ -H "Content-Type: application/json" \ -d '{ "confirm": "string" }'Empty