[{"data":1,"prerenderedAt":396},["ShallowReactive",2],{"docs:\u002Fv1\u002Fapi\u002Faccount":3},{"id":4,"title":5,"body":6,"description":388,"extension":389,"meta":390,"navigation":391,"navigationTitle":5,"path":392,"seo":393,"stem":394,"__hash__":395},"docs\u002Fv1\u002Fapi\u002Faccount.md","Account Context and Settings",{"type":7,"value":8,"toc":381},"minimark",[9,14,30,64,69,72,75,174,195,228,237,241,251,258,262,274,328,371],[10,11,13],"h1",{"id":12},"account-context-and-settings","Account context and settings",[15,16,17,21,22,25,26,29],"p",{},[18,19,20],"code",{},"GET \u002Fapi\u002Fv1\u002Fme"," accepts either an owner session or Publishing key and returns ",[18,23,24],{},"{credential,profile,readiness,actions,limits}",". Owner sessions additionally receive ",[18,27,28],{},"{account:{id,email,pendingEmail}}"," and the keys\u002Ffinance\u002Fsettings action URLs. Publishing-key responses omit private email and finance and never expose the full receiving address.",[15,31,32,35,36,39,40,43,44,47,48,51,52,55,56,59,60,63],{},[18,33,34],{},"credential.type"," is ",[18,37,38],{},"owner_session"," or ",[18,41,42],{},"publishing_key","; expiry is ISO time or null, and Publishing credentials include ",[18,45,46],{},"scope: \"posts:publish\"",". Readiness has ",[18,49,50],{},"canPublish"," and ",[18,53,54],{},"{code,field?,action}"," blockers. ",[18,57,58],{},"profile-incomplete"," identifies name\u002Fhandle setup; ",[18,61,62],{},"payout-address-required"," links to the owner address action. Limits include five active keys, 2 MiB images, 250-character bio, 80-character location, two social links, price min\u002Fmax\u002Fprecision and the supported language values. Fix blockers through the appropriate credential family.",[65,66,68],"h2",{"id":67},"change-and-confirm-email","Change and confirm email",[15,70,71],{},"Email is optional. A wallet owner can use all ordinary account and publication flows without it. Adding or confirming email preserves the original UUID and the current wallet session; Nano login remains available after verification.",[15,73,74],{},"These owner-only calls check that the exact session is still active. Publishing keys cannot call them. Responses and confirmation material are private and must never enter logs or caches.",[76,77,78,94],"table",{},[79,80,81],"thead",{},[82,83,84,88,91],"tr",{},[85,86,87],"th",{},"Method and path",[85,89,90],{},"Body",[85,92,93],{},"Persisted result",[95,96,97,121,140,156],"tbody",{},[82,98,99,105,108],{},[100,101,102],"td",{},[18,103,104],{},"GET \u002Fapi\u002Fv1\u002Faccount\u002Femail",[100,106,107],{},"None",[100,109,110,113,114,113,117,120],{},[18,111,112],{},"email",", ",[18,115,116],{},"pendingEmail",[18,118,119],{},"status"," (not_configured, pending or verified)",[82,122,123,128,133],{},[100,124,125],{},[18,126,127],{},"POST \u002Fapi\u002Fv1\u002Faccount\u002Femail",[100,129,130],{},[18,131,132],{},"{email}",[100,134,135,137,138],{},[18,136,119],{}," (confirmation_sent or already_pending), ",[18,139,116],{},[82,141,142,147,149],{},[100,143,144],{},[18,145,146],{},"POST \u002Fapi\u002Fv1\u002Faccount\u002Femail\u002Fresend",[100,148,107],{},[100,150,151,113,154],{},[18,152,153],{},"status:resent",[18,155,116],{},[82,157,158,163,171],{},[100,159,160],{},[18,161,162],{},"POST \u002Fapi\u002Fv1\u002Faccount\u002Femail\u002Fverify",[100,164,165,39,168],{},[18,166,167],{},"{email,code}",[18,169,170],{},"{email,confirmationUrl}",[100,172,173],{},"Current email\u002Fstatus; email sessions may also receive a renewable token pair",[15,175,176,177,180,181,184,185,51,188,39,191,194],{},"The request normalizes email to lowercase and trims whitespace; it supports at most 320 characters and a 64-character local part. Repeating the current\u002Fpending email returns ",[18,178,179],{},"already_pending",". Read GET after response loss. Resend without a pending change returns ",[18,182,183],{},"400 data.code: \"no_pending_email\"",". Invalid\u002Fin-use email errors use ",[18,186,187],{},"400",[18,189,190],{},"data.code: \"invalid_email\"",[18,192,193],{},"\"email_in_use\"",".",[15,196,197,198,113,201,204,205,208,209,212,213,216,217,113,220,223,224,227],{},"Verification requires exactly one six-to-eight-digit code or the complete email-change confirmation URL from the authorized mailbox. It must match the configured Supabase origin, ",[18,199,200],{},"\u002Fauth\u002Fv1\u002Fverify",[18,202,203],{},"type=email_change",", and this owner's pending change. The server checks the token without exposing it or following redirects. Wrong\u002Fexpired\u002Fforeign confirmation returns ",[18,206,207],{},"422","; other URLs are rejected. Provider double-confirmation may leave status ",[18,210,211],{},"pending"," after the first mailbox confirms; complete each required mailbox confirmation and read status until ",[18,214,215],{},"verified",". A lost final success replays as verified for the same final email. For an email session, atomically save any returned ",[18,218,219],{},"accessToken",[18,221,222],{},"refreshToken"," and Unix-seconds ",[18,225,226],{},"expiresAt",". Wallet confirmation returns status without replacing the wallet token pair; keep the existing wallet session and its normal refresh lifecycle.",[15,229,230,231,236],{},"Email request\u002Fresend follow the existing provider\u002Fabuse policy; production limits include five change attempts\u002Fhour and three resends\u002F15 minutes. Verification allows ten attempts\u002Fminute. SMTP, templates, CAPTCHA and session policy must be checked before launch. ",[232,233,235],"a",{"href":234},"\u002Fv1\u002Fapi\u002Fauthentication","Authentication"," covers renewing a session independently of email changes.",[65,238,240],{"id":239},"linked-addresses-and-privacy","Linked addresses and privacy",[15,242,243,246,247,250],{},[18,244,245],{},"GET \u002Fapi\u002Fv1\u002Fnano-addresses"," with owner Bearer returns only owned rows: ",[18,248,249],{},"{id,address,user_id,created_at,updated_at}",". These are read-only linked addresses, distinct from the saved payout address. The ordinary API cannot reassign wallet ownership.",[15,252,253,257],{},[232,254,256],{"href":255},"\u002Fv1\u002Fapi\u002Fengagement#notification-and-privacy-settings","Engagement settings"," expose existing email\u002Fin-app\u002Fpush preference booleans and creator\u002Fsupporter leaderboard visibility. OS or browser push permission and administrator\u002Foperator controls remain outside ordinary account authority.",[65,259,261],{"id":260},"optional-legacy-email-bootstrap","Optional legacy email bootstrap",[15,263,264,265,269,270,273],{},"New integrations should use the owner-session email endpoints above after ",[232,266,268],{"href":267},"\u002Fv1\u002Fapi\u002Fauthentication#nano-login-without-email","Nano login",". The existing ",[18,271,272],{},"\u002Fapi\u002Fv1\u002Faccount\u002Femail\u002Fbootstrap"," family remains a compatibility path for attaching email to a freshly proven wallet without a Bearer header. It is optional; login and publishing are already available before email setup.",[15,275,276,277,280,281,284,285,51,288,291,292,284,295,298,299,39,302,305,306,309,310,113,313,113,315,113,318,39,320,323,324,327],{},"All four calls are POSTs with private ",[18,278,279],{},"loginSecret"," in JSON, without cookies. The continuation lasts 15 minutes after the original claim and retries do not extend it. Start takes ",[18,282,283],{},"{loginSecret,email}","; ",[18,286,287],{},"\u002Fstatus",[18,289,290],{},"\u002Fresend"," take ",[18,293,294],{},"{loginSecret}",[18,296,297],{},"\u002Fverify"," takes ",[18,300,301],{},"{loginSecret,email,code}",[18,303,304],{},"{loginSecret,email,confirmationUrl}",". The proof must belong to that same account's pending mailbox. Status returns ",[18,307,308],{},"{status,userId,email,pendingEmail,bootstrapExpiresAt}"," with ",[18,311,312],{},"awaiting_email",[18,314,211],{},[18,316,317],{},"confirmation_sent",[18,319,215],{},[18,321,322],{},"configuration_blocked",". A verified wallet continuation has ",[18,325,326],{},"nextAction:authenticated"," and returns no replacement pair: keep the wallet pair. Read status after any uncertainty; fresh Nano login recovers the same account after a lost or expired continuation.",[15,329,330,333,334,337,338,333,341,343,344,333,347,350,351,354,355,333,358,350,361,364,365,51,367,370],{},[18,331,332],{},"EMAIL_CONFLICT"," (",[18,335,336],{},"409",") cannot reassign another wallet or mailbox. ",[18,339,340],{},"INVALID_CONFIRMATION",[18,342,207],{},") needs the correct owner's proof. ",[18,345,346],{},"BOOTSTRAP_UNAVAILABLE",[18,348,349],{},"503","\u002F",[18,352,353],{},"429",") needs bounded retry\u002Fstatus read with the same secret. ",[18,356,357],{},"NANO_BOOTSTRAP_EXPIRED",[18,359,360],{},"410",[18,362,363],{},"401",") needs a new wallet proof. ",[18,366,322],{},[18,368,369],{},"EMAIL_CONFIGURATION_BLOCKED"," are not email completion; provider configuration must be repaired. Pending\u002Fconfiguration-blocked optional email does not remove an otherwise valid wallet session's owner authority.",[15,372,373,374,376,377,380],{},"These calls share 120 requests\u002Fminute per ingress IP; each hashed secret\u002Faction allows 30\u002Fminute, except verification at 10\u002Fminute. HTTP ",[18,375,353],{}," can include ",[18,378,379],{},"data.retryAfter"," seconds. Keep secrets and mailbox proof out of URLs and logs.",{"title":382,"searchDepth":383,"depth":383,"links":384},"",2,[385,386,387],{"id":67,"depth":383,"text":68},{"id":239,"depth":383,"text":240},{"id":260,"depth":383,"text":261},"Inspect authority and limits, verify account-email changes and read linked Nano addresses.","md",{},true,"\u002Fv1\u002Fapi\u002Faccount",{"title":5,"description":388},"v1\u002Fapi\u002Faccount","xEscehZN_knD2W4wtMeCohhCUHMcQ6IgiXXrCewRUG8",1791228349708]