intentic
Download the app
Download the app
Models and accounts

Accounts

Subscriptions this sandbox holds itself, for any provider, with the provider in the address

On this page(7 sections)

One route family for every provider whose credential lives in this daemon's own auth tree — sign in, finish or abandon a sign-in, list what is connected with how full each account's limits were, rename one, disconnect one. The provider is a parameter rather than a group of its own because the operations are the same six for all of them; what differs is each provider's mechanism, which its own module declares. The translator group next door is the other shape of the same idea, for subscriptions a proxy holds and re-serves. No answer here can carry a credential: the account rows have no field one could ride in, and a sign-in's proof never leaves the sandbox.

7 calls. Pick one to open it, or use the list on the right.

POST/accounts/{provider}/login/startBegin connecting an account

Hands back the page to sign in on, and the code it will ask for where there is one. The sandbox holds the proof and finishes what it can itself: a device sign-in lands in the account list on its own, a paste or a redirect needs one thing brought back to the finishing call.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
variantWhich estate to sign in tostringbody

What comes back

FieldType
urlThe page to open and sign…string
codeThe one-time code the page will…string
stateFor a redirect sign-in, the marker…string
flowHow this attempt ends"device" | "redirect" | "paste"
variantWhich of the provider's estates this…string
handshakeThis attempt's id, for finishing or…string
expiresAtWhen this attempt stops being answerable,…number
catchersWho is watching for where the…object[]
kind"device" | "browser"
labelstring
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/accounts/claude/login/start" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"variant":"…"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.start({
  "provider": "claude",
  "variant": "…"
});
POST/accounts/{provider}/login/completeFinish a sign-in with what the page handed back

Takes the code the page showed, or the address a redirect landed on, and finishes the attempt. Answers with the account where the exchange ends here; otherwise the sandbox still has a mint to do and the row appears in the account list.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
handshakerequiredWhich attempt this belongs tostringbody
codeThe code the sign-in page showed,…stringbody
redirectUrlThe address the browser was sent…stringbody
labelWhat to call the accountstringbody

What comes back

FieldType
accountThe account it connected, where the…object
idThe account's id, which is what…string
labelWhat it is called here, which…string
emailWho it signs in as, in…string
organizationWhich organisation it belongs to, where…string
variantWhich of the provider's estates it…string
scopeWhat the credential is permitted to…string
connectedAtWhen it was connected, in millisecondsnumber
needsReauthIts stored credential can no longer…boolean
detailWhy, in words a person can…string
seatRefusalIts organisation has switched it off…string
usageHow full its plan limits were…object
windowsobject[]
kindstring
labelstring
utilizationnumber
resetsAtnumber
gates"all" | "none" | object
measuredAtnumber
unreadPresent while re-reading this account keeps…object
sinceWhen re-reading this account first failed,…number
reasonWhy, in the provider's own words…string
stateWhether it can serve a turn…object
when kind is "ready"shape
roomHow much of the fullest pool…number
when kind is "spent"shape
reopensAtWhen every full pool has reopened,…number
when kind is "blocked"shape
fixWho can make it serve again:…"reconnect" | "admin" | "verify" | "wait"
reasonWhy, in words a person can…string
untilWhen waiting lifts it, in epoch…number
urlThe provider's page where the account's…string
when kind is "unknown"shape
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/accounts/claude/login/complete" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"handshake":"…","code":"…","redirectUrl":"https://sandbox-a1b2c3d4e5f6.intentic.dev","label":"Nightly changelog"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.complete({
  "provider": "claude",
  "handshake": "…",
  "code": "…",
  "redirectUrl": "https://sandbox-a1b2c3d4e5f6.intentic.dev",
  "label": "Nightly changelog"
});
GET/accounts/{provider}/login/statusRead a sign-in attempt

Whether this exact attempt is still waiting, has connected an account, or failed. Tied to the attempt, not to the account list, so adding a second account is told apart from the first already being there. An attempt that finishes by itself on a device or browser of yours ends here.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
handshakerequiredWhich attemptstringquery

What comes back

FieldType
when status is "wait"shape
when status is "ok"shape
accountThe account it connectedobject
idThe account's id, which is what…string
labelWhat it is called here, which…string
emailWho it signs in as, in…string
organizationWhich organisation it belongs to, where…string
variantWhich of the provider's estates it…string
scopeWhat the credential is permitted to…string
connectedAtWhen it was connected, in millisecondsnumber
needsReauthIts stored credential can no longer…boolean
detailWhy, in words a person can…string
seatRefusalIts organisation has switched it off…string
usageHow full its plan limits were…object
windowsobject[]
measuredAtnumber
unreadPresent while re-reading this account keeps…object
stateWhether it can serve a turn…object
kind"ready"
roomHow much of the fullest pool…number
when status is "error"shape
errorWhy it failed, to show as…string
Try itanswered in this tab
curl
curl "$SANDBOX/accounts/claude/login/status?handshake=%E2%80%A6" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.status({
  "provider": "claude",
  "handshake": "…"
});
POST/accounts/{provider}/login/cancelAbandon a sign-in

Stops waiting on a sign-in nobody completed. An abandoned attempt also expires on its own.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
handshakerequiredWhich attempt to stop waiting onstringbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/accounts/claude/login/cancel" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"handshake":"…"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.cancel({
  "provider": "claude",
  "handshake": "…"
});
GET/accounts/{provider}Connected accounts of a provider

Each connected account with how full its plan limits were when last measured, where the provider publishes any. Ask for a fresh measurement and it takes one before answering, which is slower. The credentials themselves never travel: being in this list is what connected means.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
forceMeasure the plan limits again before…stringquery

What comes back

FieldType
accountsThe connected accountsobject[]
idThe account's id, which is what…string
labelWhat it is called here, which…string
emailWho it signs in as, in…string
organizationWhich organisation it belongs to, where…string
variantWhich of the provider's estates it…string
scopeWhat the credential is permitted to…string
connectedAtWhen it was connected, in millisecondsnumber
needsReauthIts stored credential can no longer…boolean
detailWhy, in words a person can…string
seatRefusalIts organisation has switched it off…string
usageHow full its plan limits were…object
windowsobject[]
kindstring
labelstring
utilizationnumber
resetsAtnumber
gates"all" | "none" | object
measuredAtnumber
unreadPresent while re-reading this account keeps…object
sinceWhen re-reading this account first failed,…number
reasonWhy, in the provider's own words…string
stateWhether it can serve a turn…object
when kind is "ready"shape
roomHow much of the fullest pool…number
when kind is "spent"shape
reopensAtWhen every full pool has reopened,…number
when kind is "blocked"shape
fixWho can make it serve again:…"reconnect" | "admin" | "verify" | "wait"
reasonWhy, in words a person can…string
untilWhen waiting lifts it, in epoch…number
urlThe provider's page where the account's…string
when kind is "unknown"shape
Try itanswered in this tab
curl
curl "$SANDBOX/accounts/claude" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.accounts({
  "provider": "claude"
});
POST/accounts/{provider}/renameRename an account

Changes the label one account shows under, so several are tellable apart. Blank restores the one derived from the sign-in.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
idrequiredWhich accountstringbody
labelrequiredThe new namestringbody

What comes back

FieldType
idThe account's id, which is what…string
labelWhat it is called here, which…string
emailWho it signs in as, in…string
organizationWhich organisation it belongs to, where…string
variantWhich of the provider's estates it…string
scopeWhat the credential is permitted to…string
connectedAtWhen it was connected, in millisecondsnumber
needsReauthIts stored credential can no longer…boolean
detailWhy, in words a person can…string
seatRefusalIts organisation has switched it off…string
usageHow full its plan limits were…object
windowsobject[]
kindstring
labelstring
utilizationnumber
resetsAtnumber
gates"all" | "none" | object
measuredAtnumber
unreadPresent while re-reading this account keeps…object
sinceWhen re-reading this account first failed,…number
reasonWhy, in the provider's own words…string
stateWhether it can serve a turn…object
when kind is "ready"shape
roomHow much of the fullest pool…number
when kind is "spent"shape
reopensAtWhen every full pool has reopened,…number
when kind is "blocked"shape
fixWho can make it serve again:…"reconnect" | "admin" | "verify" | "wait"
reasonWhy, in words a person can…string
untilWhen waiting lifts it, in epoch…number
urlThe provider's page where the account's…string
when kind is "unknown"shape
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/accounts/claude/rename" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"id":"a1b2c3d4","label":"Nightly changelog"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.rename({
  "provider": "claude",
  "id": "a1b2c3d4",
  "label": "Nightly changelog"
});
POST/accounts/{provider}/disconnectDisconnect an account

Clears one stored credential, and stops any sign-in still in flight for this provider. The others stay connected.

What you send

FieldTypeWhere
providerrequired"claude" | "codex" | "grok" | "kimi" … (8)address
idrequiredWhich accountstringbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/accounts/claude/disconnect" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"id":"a1b2c3d4"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.accounts.disconnect({
  "provider": "claude",
  "id": "a1b2c3d4"
});
More in Models and accounts

Type to search every page, in the docs and the API reference.