---
title: "Accounts · intentic sandbox API"
description: "Subscriptions this sandbox holds itself, for any provider, with the provider in the address. Every route in the accounts group of the intentic sandbox API."
url: "https://intentic.dev/api/accounts/"
---

Models and accounts

# Accounts

Subscriptions this sandbox holds itself, for any provider, with the provider in the address

**On this page (7 sections)**

- [Begin connecting an account](#accounts-start)
- [Finish a sign-in with what the page handed back](#accounts-complete)
- [Read a sign-in attempt](#accounts-status)
- [Abandon a sign-in](#accounts-cancel)
- [Connected accounts of a provider](#accounts-accounts)
- [Rename an account](#accounts-rename)
- [Disconnect an account](#accounts-disconnect)

One route family for every provider whose credential lives in this daemon's own auth tree — sign in, finish or abandon a sign-in, list what is connected with how full each account's limits were, rename one, disconnect one. The provider is a parameter rather than a group of its own because the operations are the same six for all of them; what differs is each provider's mechanism, which its own module declares. The translator group next door is the other shape of the same idea, for subscriptions a proxy holds and re-serves. No answer here can carry a credential: the account rows have no field one could ride in, and a sign-in's proof never leaves the sandbox.

7 calls. Pick one to open it, or use the list on the right.

**POST`/accounts/{provider}/login/start` Begin connecting an account**

Hands back the page to sign in on, and the code it will ask for where there is one. The sandbox holds the proof and finishes what it can itself: a device sign-in lands in the account list on its own, a paste or a redirect needs one thing brought back to the finishing call.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `variant` Which estate to sign in to | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `url` The page to open and sign… | string |
| `code` The one-time code the page will… | string |
| `state` For a redirect sign-in, the marker… | string |
| `flow` How this attempt ends | "device" | "redirect" | "paste" |
| `variant` Which of the provider's estates this… | string |
| `handshake` This attempt's id, for finishing or… | string |
| `expiresAt` When this attempt stops being answerable,… | number |
| `catchers` Who is watching for where the… | object[] |
| `kind` | "device" | "browser" |
| `label` | string |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/accounts/claude/login/start" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"variant":"…"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.start({
 "provider": "claude",
 "variant": "…"
});
```

**POST`/accounts/{provider}/login/complete` Finish a sign-in with what the page handed back**

Takes the code the page showed, or the address a redirect landed on, and finishes the attempt. Answers with the account where the exchange ends here; otherwise the sandbox still has a mint to do and the row appears in the account list.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `handshake` required Which attempt this belongs to | string | body |
| `code` The code the sign-in page showed,… | string | body |
| `redirectUrl` The address the browser was sent… | string | body |
| `label` What to call the account | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `account` The account it connected, where the… | object |
| `id` The account's id, which is what… | string |
| `label` What it is called here, which… | string |
| `email` Who it signs in as, in… | string |
| `organization` Which organisation it belongs to, where… | string |
| `variant` Which of the provider's estates it… | string |
| `scope` What the credential is permitted to… | string |
| `connectedAt` When it was connected, in milliseconds | number |
| `needsReauth` Its stored credential can no longer… | boolean |
| `detail` Why, in words a person can… | string |
| `seatRefusal` Its organisation has switched it off… | string |
| `usage` How full its plan limits were… | object |
| `windows` | object[] |
| `kind` | string |
| `label` | string |
| `utilization` | number |
| `resetsAt` | number |
| `gates` | "all" | "none" | object |
| `measuredAt` | number |
| `unread` Present while re-reading this account keeps… | object |
| `since` When re-reading this account first failed,… | number |
| `reason` Why, in the provider's own words… | string |
| `state` Whether it can serve a turn… | object |
| `when kind is "ready"` | shape |
| `room` How much of the fullest pool… | number |
| `when kind is "spent"` | shape |
| `reopensAt` When every full pool has reopened,… | number |
| `when kind is "blocked"` | shape |
| `fix` Who can make it serve again:… | "reconnect" | "admin" | "verify" | "wait" |
| `reason` Why, in words a person can… | string |
| `until` When waiting lifts it, in epoch… | number |
| `url` The provider's page where the account's… | string |
| `when kind is "unknown"` | shape |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/accounts/claude/login/complete" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"handshake":"…","code":"…","redirectUrl":"https://sandbox-a1b2c3d4e5f6.intentic.dev","label":"Nightly changelog"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.complete({
 "provider": "claude",
 "handshake": "…",
 "code": "…",
 "redirectUrl": "https://sandbox-a1b2c3d4e5f6.intentic.dev",
 "label": "Nightly changelog"
});
```

**GET`/accounts/{provider}/login/status` Read a sign-in attempt**

Whether this exact attempt is still waiting, has connected an account, or failed. Tied to the attempt, not to the account list, so adding a second account is told apart from the first already being there. An attempt that finishes by itself on a device or browser of yours ends here.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `handshake` required Which attempt | string | query |

### What comes back

| Field | Type |
| --- | --- |
| `when status is "wait"` | shape |
| `when status is "ok"` | shape |
| `account` The account it connected | object |
| `id` The account's id, which is what… | string |
| `label` What it is called here, which… | string |
| `email` Who it signs in as, in… | string |
| `organization` Which organisation it belongs to, where… | string |
| `variant` Which of the provider's estates it… | string |
| `scope` What the credential is permitted to… | string |
| `connectedAt` When it was connected, in milliseconds | number |
| `needsReauth` Its stored credential can no longer… | boolean |
| `detail` Why, in words a person can… | string |
| `seatRefusal` Its organisation has switched it off… | string |
| `usage` How full its plan limits were… | object |
| `windows` | object[] |
| `measuredAt` | number |
| `unread` Present while re-reading this account keeps… | object |
| `state` Whether it can serve a turn… | object |
| `kind` | "ready" |
| `room` How much of the fullest pool… | number |
| `when status is "error"` | shape |
| `error` Why it failed, to show as… | string |

Try it answered in this tab

curl

```bash
curl "$SANDBOX/accounts/claude/login/status?handshake=%E2%80%A6" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.status({
 "provider": "claude",
 "handshake": "…"
});
```

**POST`/accounts/{provider}/login/cancel` Abandon a sign-in**

Stops waiting on a sign-in nobody completed. An abandoned attempt also expires on its own.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `handshake` required Which attempt to stop waiting on | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/accounts/claude/login/cancel" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"handshake":"…"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.cancel({
 "provider": "claude",
 "handshake": "…"
});
```

**GET`/accounts/{provider}` Connected accounts of a provider**

Each connected account with how full its plan limits were when last measured, where the provider publishes any. Ask for a fresh measurement and it takes one before answering, which is slower. The credentials themselves never travel: being in this list is what connected means.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `force` Measure the plan limits again before… | string | query |

### What comes back

| Field | Type |
| --- | --- |
| `accounts` The connected accounts | object[] |
| `id` The account's id, which is what… | string |
| `label` What it is called here, which… | string |
| `email` Who it signs in as, in… | string |
| `organization` Which organisation it belongs to, where… | string |
| `variant` Which of the provider's estates it… | string |
| `scope` What the credential is permitted to… | string |
| `connectedAt` When it was connected, in milliseconds | number |
| `needsReauth` Its stored credential can no longer… | boolean |
| `detail` Why, in words a person can… | string |
| `seatRefusal` Its organisation has switched it off… | string |
| `usage` How full its plan limits were… | object |
| `windows` | object[] |
| `kind` | string |
| `label` | string |
| `utilization` | number |
| `resetsAt` | number |
| `gates` | "all" | "none" | object |
| `measuredAt` | number |
| `unread` Present while re-reading this account keeps… | object |
| `since` When re-reading this account first failed,… | number |
| `reason` Why, in the provider's own words… | string |
| `state` Whether it can serve a turn… | object |
| `when kind is "ready"` | shape |
| `room` How much of the fullest pool… | number |
| `when kind is "spent"` | shape |
| `reopensAt` When every full pool has reopened,… | number |
| `when kind is "blocked"` | shape |
| `fix` Who can make it serve again:… | "reconnect" | "admin" | "verify" | "wait" |
| `reason` Why, in words a person can… | string |
| `until` When waiting lifts it, in epoch… | number |
| `url` The provider's page where the account's… | string |
| `when kind is "unknown"` | shape |

Try it answered in this tab

curl

```bash
curl "$SANDBOX/accounts/claude" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.accounts({
 "provider": "claude"
});
```

**POST`/accounts/{provider}/rename` Rename an account**

Changes the label one account shows under, so several are tellable apart. Blank restores the one derived from the sign-in.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `id` required Which account | string | body |
| `label` required The new name | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `id` The account's id, which is what… | string |
| `label` What it is called here, which… | string |
| `email` Who it signs in as, in… | string |
| `organization` Which organisation it belongs to, where… | string |
| `variant` Which of the provider's estates it… | string |
| `scope` What the credential is permitted to… | string |
| `connectedAt` When it was connected, in milliseconds | number |
| `needsReauth` Its stored credential can no longer… | boolean |
| `detail` Why, in words a person can… | string |
| `seatRefusal` Its organisation has switched it off… | string |
| `usage` How full its plan limits were… | object |
| `windows` | object[] |
| `kind` | string |
| `label` | string |
| `utilization` | number |
| `resetsAt` | number |
| `gates` | "all" | "none" | object |
| `measuredAt` | number |
| `unread` Present while re-reading this account keeps… | object |
| `since` When re-reading this account first failed,… | number |
| `reason` Why, in the provider's own words… | string |
| `state` Whether it can serve a turn… | object |
| `when kind is "ready"` | shape |
| `room` How much of the fullest pool… | number |
| `when kind is "spent"` | shape |
| `reopensAt` When every full pool has reopened,… | number |
| `when kind is "blocked"` | shape |
| `fix` Who can make it serve again:… | "reconnect" | "admin" | "verify" | "wait" |
| `reason` Why, in words a person can… | string |
| `until` When waiting lifts it, in epoch… | number |
| `url` The provider's page where the account's… | string |
| `when kind is "unknown"` | shape |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/accounts/claude/rename" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"id":"a1b2c3d4","label":"Nightly changelog"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.rename({
 "provider": "claude",
 "id": "a1b2c3d4",
 "label": "Nightly changelog"
});
```

**POST`/accounts/{provider}/disconnect` Disconnect an account**

Clears one stored credential, and stops any sign-in still in flight for this provider. The others stay connected.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `provider` required | "claude" | "codex" | "grok" | "kimi" … (8) | address |
| `id` required Which account | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/accounts/claude/disconnect" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"id":"a1b2c3d4"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.disconnect({
 "provider": "claude",
 "id": "a1b2c3d4"
});
```

More in Models and accounts

[Next Routed providers →](https://intentic.dev/api/translator/)
