The caller's sign-in methods (ACCT-2, Settings → Sign-in methods)
Required scope: `account:read` (personal access tokens; sessions have every scope).
Required scope: account:read (personal access tokens; sessions have every scope).
Authorization
bearerAuth Authorization: Bearer <token>: a mobile session token, or a personal access token
(srp_…) created in Account → API tokens (DEV-1).
Personal access tokens:
- Act as their user. The household comes from
X-SpendRock-Household, else the user's default. - Carry scopes (DEV-2), and each operation's description names the one it needs:
budget:read/budget:write(months, groups, items, funds, favorites, harvest),transactions:read/transactions:write(transactions, merchant suggestions),households:read/households:manage(households, members, invites),account:read/account:write(me, settings). A write scope includes its read scope. A call outside the token's scopes gets 403insufficient_scope, with the needed scope indetails.required_scope. - Can't manage tokens or passwords (403
session_required). - May expire (401
unauthenticatedafterwards). - Are rate-limited (DEV-3): 120 requests/minute per token with bursts up to 120. Every
response carries
X-RateLimit-Limit,X-RateLimit-Remaining, andX-RateLimit-Reset(seconds until the bucket is full again); over the limit the answer is 429rate_limitedwithRetry-After(seconds). Limits are kept per server instance, so they're approximate.
Sessions (web cookie or mobile bearer) have every scope and aren't limited this way. Cross-origin browser calls (CORS, for the API docs playground) must use a bearer token; cookies are never accepted cross-origin.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/me/sign-in-methods"{ "email": "string", "email_verified": true, "password": true, "password_pending": true, "google": [ { "email": "string", "linked_at": "2019-08-24T14:15:22Z" } ]}Set a new password from a reset link (ACCT-3) POST
Also marks the email verified (the link proves it) and signs out every session of the account. It doesn't sign in; sign in with the new password. No authentication needed.
Add or change the caller's password (ACCT-2) PUT
Changing an existing password needs `current_password` (401 `bad_credentials`). If the account's email isn't verified yet, a verification link is emailed and the password works once it's verified (`verification_sent`). Needs a signed-in session: personal access tokens get 403 `session_required`.