import * as _accelbyte_sdk from '@accelbyte/sdk'; import { AccelByteSDK, SdkSetConfigParam, Response, SdkConstructorParam } from '@accelbyte/sdk'; import * as axios from 'axios'; import { AxiosResponse, AxiosInstance, AxiosRequestConfig } from 'axios'; import { T as TagsGetResponseV3, b as TagCreateRequestV3, a as TagResponse, c as TagUpdateRequestV3, B as BansV3, d as BanReasonsV3, G as GetUserBanV3Response, e as BulkBanCreateRequestV3, L as ListBulkUserBanResponseV3, f as BulkUnbanCreateRequestV3, C as ClientsV3Response, h as ClientCreationV3Request, g as ClientV3Response, i as ClientsUpdateRequestV3, V as V3ClientUpdateSecretRequest, j as ClientUpdateV3Request, k as ClientPermissionsV3, l as ListTemplatesResponse, P as PermissionSetDeleteGroupRequest, m as ListClientPermissionSet, n as ListUpsertModulesRequest, o as ConfigValueResponseV3, p as CountryResponseArray, q as CountryBlacklistResponse, r as CountryBlacklistRequest, D as DevicesResponseV4, s as DeviceBansResponseV4, t as DeviceBanRequestV4, u as DeviceTypesResponseV4, v as DeviceBannedResponseV4, w as DeviceBanResponseV4, x as DeviceBanUpdateRequestV4, y as DeviceUsersResponseV4, z as DeviceIdDecryptResponseV4, I as InputValidationsResponse, A as InputValidationUpdatePayload, E as LoginAllowlistResponse, F as LoginAllowlistRequest, H as TokenThirdPartyResponse, R as RoleOverrideResponse, J as RoleOverrideUpdateRequest, K as RoleOverrideSourceResponse, M as RoleOverrideStatsUpdateRequest, N as RolePermissionResponseV3, O as GetProfileUpdateStrategyConfigResponse, U as UpdateProfileUpdateStrategyConfigRequest, S as SimpleProfileUpdateStrategyConfigs, Q as RoleResponseWithManagersAndPaginationV3, X as RoleCreateV3Request, W as RoleV3, Y as ListRoleV4Response, _ as RoleV4Request, Z as RoleV4Response, $ as RoleResponseV3, a0 as RoleUpdateRequestV3, a1 as RoleAdminStatusResponseV3, a2 as RevokeUserV4Request, a3 as ListAssignedUsersV4Response, a5 as AssignUserV4Request, a4 as AssignedUserV4Response, a6 as RoleMembersRequestV3, a7 as RoleMembersResponseV3, a8 as RoleManagersRequestV3, a9 as RoleManagersResponsesV3, aa as PermissionsV3, ab as SsoPlatformCredentialResponseArray, ac as SsoPlatformCredentialResponse, ad as SsoPlatformCredentialRequest, ae as CheckAvailabilityResponse, af as ThirdPartyLoginPlatformCredentialResponseArray, ag as ThirdPartyLoginPlatformCredentialResponse, ah as ThirdPartyLoginPlatformCredentialRequest, ai as PlatformDomainDeleteRequest, ak as PlatformDomainPatchRequest, aj as PlatformDomainResponse, al as PlatformDomainUpdateRequest, am as UserResponseV3, an as SearchUsersByPlatformIdResponse, ao as UsersUpdateRequestV3, ap as GetUsersResponseWithPaginationV3, aq as GetBulkUserBansRequest, as as AdminBulkUserRequest, ar as ListUserInformationResult, at as CursorGetUserRequest, au as CursorGetUserResponse, aw as InviteUserRequestV3, av as InviteUserResponseV3, ax as SearchUsersResponseWithPaginationV3, ay as UserResponse, az as UserUpdateRequest, aA as UserUpdateRequestV3, aB as AgeRestrictionResponse, aC as AgeRestrictionRequest, aD as AgeRestrictionResponseV3, aE as AgeRestrictionRequestV3, aF as ListEmailAddressRequest, aG as ListUserResponseV3, aI as BanCreateRequest, aH as UserBanResponse, aJ as UserBanResponseArray, aK as UserBanResponseV3, aL as LinkingHistoryResponseWithPaginationV3, aM as VerificationCodeResponse, aN as NamespaceRoleRequest, aO as UserStateResponseV3, aP as UserIDsRequest, aQ as ListBulkUserPlatformsResponse, aR as UpdateUserStatusRequest, aS as DisableUserRequest, aU as CountryAgeRestrictionRequest, aT as Country, aV as UserPasswordUpdateRequest, aW as UserPasswordUpdateV3Request, aX as ListUsersWithPlatformAccountsResponse, aY as UserLinkedPlatformsResponseV3, aZ as CountryAgeRestrictionArray, a_ as CountryV3ResponseArray, a$ as UserVerificationRequest, b0 as PermissionDeleteRequest, b1 as Permissions, b2 as BanUpdateRequest, b3 as GetUserBanSummaryV3, b4 as SendVerificationCodeRequestV3, b5 as PlatformUserIdRequest, b6 as UserPlatforms, b7 as LinkPlatformAccountRequest, b8 as UserDeletionStatusResponse, b9 as UpdateUserDeletionStatusRequest, ba as LoginHistoriesResponse, bb as UserIdentityUpdateRequestV3, bc as DistinctPlatformResponseV3, bd as GetUserMappingArray, be as UpgradeHeadlessAccountWithVerificationCodeRequestV3, bf as UnlinkUserPlatformRequest, bh as CountryAgeRestrictionV3Request, bg as CountryV3Response, bi as UserPlatformLinkHistories, bj as UserPlatformMetadata, bk as TokenThirdPartyLinkStatusResponse, bl as GetUserMappingV3, bm as CreateJusticeUserResponse, bn as InviteUserRequestV4, bo as ListInvitationHistoriesV4Response, bp as EnabledFactorsResponseV4, bq as UserMfaStatusResponseV4, br as BackupCodesResponseV4, bs as DisableMfaRequest, bu as CreateUserRequestV4, bt as CreateUserResponseV4, bv as UserMfaTokenResponseV4, bw as AuthenticatorKeyResponseV4, by as CreateTestUsersRequestV4, bx as CreateTestUsersResponseV4, bz as InvitationHistoryResponse, bA as CheckValidUserIdRequestV4, bB as ListValidUserIdResponseV4, bC as EmailUpdateRequestV4, bD as RemoveUserRoleV4Request, bE as ListUserRolesV4Response, bF as AddUserRoleV4Request, bG as BulkAccountTypeUpdateRequestV4, bH as NamespaceInvitationHistoryUserV4Response, bI as Bans, bJ as BanReasons, bK as ClientResponseArray, bM as ClientCreateRequest, bL as ClientCreationResponse, bN as ClientResponse, bO as ClientUpdateRequest, bP as ClientUpdateSecretRequest, bQ as ClientPermissions, bR as InternalConfigResponseV3, bS as InputValidationsPublicResponse, bT as InputValidationConfigVersion, bU as JwkSet, bV as TokenResponse, bW as RevocationList, bX as TokenWithDeviceCookieResponseV3, bY as TokenResponseV3, bZ as TokenIntrospectResponse, b_ as CountryLocationResponse, b$ as OneTimeLinkingCodeResponse, c0 as OneTimeLinkingCodeValidationResponse, c1 as TargetTokenCodeResponse, c2 as PlatformTokenRefreshResponseV3, c3 as RoleResponseWithManagersArray, c5 as RoleCreateRequest, c4 as Role, c6 as RoleResponse, c7 as RoleUpdateRequest, c8 as RoleNamesResponseV3, c9 as RoleAdminStatusResponse, ca as RoleMembersRequest, cb as RoleMembersResponse, cc as RoleManagersRequest, cd as RoleManagersResponse, ce as UpdatePermissionScheduleRequest, cf as PublicThirdPartyPlatformInfoArray, ch as ForgotPasswordWithoutNamespaceRequestV3, cg as ForgotPasswordResponseV3, ci as PublicOpenIdUserInfoResponse, ck as UserCreateRequest, cj as UserCreateResponse, cl as UserProfileUpdateAllowStatus, cm as GetAdminUsersResponse, cn as SearchUsersResponse, co as OneTimeCodeLinkRedirectionResponse, cp as PublicUserResponse, cq as PublicUserInformationResponseV3, cs as UserCreateRequestV3, cr as UserCreateResponseV3, ct as SendVerificationLinkRequest, cu as PublicUserUpdateRequestV3, cv as GetLinkHeadlessAccountConflictResponse, cw as ResetPasswordRequest, cx as SendVerificationCodeRequest, cy as PublicUsersResponse, cz as ResetPasswordRequestV3, cA as ForgotPasswordRequestV3, cB as UserLinkedPlatformArray, cC as GetPublisherUserResponse, cD as UserResponseArray, cE as PublicUserResponseV3, cF as LinkHeadlessAccountRequest, cH as UsersPlatformInfosRequestV3, cG as UsersPlatformInfosResponse, cI as UserInformation, cJ as ListBulkUserResponse, cK as VerifyRegistrationCode, cL as SendRegisterVerificationCodeRequest, cM as UserVerificationRequestV3, cO as UserInputValidationRequest, cN as UserInputValidationResponse, cP as UpgradeHeadlessAccountV3Request, cQ as UserInformationV3, cR as UpgradeHeadlessAccountRequest, cS as UserInvitationV3, cT as GetUserMappingV3Array, cU as LinkRequest, cV as GetUserMapping, cW as GetUserJusticePlatformAccountResponse, cX as WebLinkingResponse, cY as LinkPlatformAccountWithProgressionRequest, cZ as UpgradeHeadlessAccountWithVerificationCodeRequest, c_ as PublicInviteUserRequestV4, c$ as CreateTestUserRequestV4, d0 as UserPublicInfoResponseV4, d1 as UpgradeHeadlessAccountWithVerificationCodeForwardRequestV4, d3 as UpgradeHeadlessAccountRequestV4, d2 as UserResponseV4, d4 as PlatformUserIdRequestV4, d5 as UpgradeHeadlessAccountWithVerificationCodeRequestV4 } from './UserResponseV4-2meuO34S.js'; import { z } from 'zod'; /** * AUTO GENERATED */ declare function AccountIdentifierTagAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Retrieve Account Identifier Tags. This endpoint allows administrators to retrieve tags that are used to identify and categorize user accounts. Tag Name can be used for partial content search. */ getTags_v3: (queryParams?: { limit?: number; offset?: number; tagName?: string | null; }) => Promise>; /** * Create a new Account Identifier Tag for users. This endpoint allows administrators to create tags that can be used to identify and categorize user accounts. */ createTag_v3: (data: TagCreateRequestV3) => Promise>; /** * Delete an Account Identifier Tag. This endpoint allows administrators to delete a tag that is used to identify and categorize user accounts. */ deleteTag_ByTagId_v3: (tagId: string) => Promise>; /** * Update an existing Account Identifier Tag. This endpoint allows administrators to update the details of a tag that is used to identify and categorize user accounts. */ updateTag_ByTagId_v3: (tagId: string, data: TagUpdateRequestV3) => Promise>; }; /** * AUTO GENERATED */ declare function BansAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Ban type is the code available for ban assignment. It is applicable globally for any namespace. action code : 10201 */ getBans_v3: () => Promise>; /** * Ban reasons is the code available to justify ban assignment. It is applicable globally for any namespace. action code : 10202 */ getBansReasons_v3: () => Promise>; /** * Ban type is the code available for ban assignment. It is applicable globally for any namespace. action code : 10201 */ getBantypes_v3: () => Promise>; /** * Ban type is the code available for ban assignment. It is applicable globally for any namespace. action code : 10201 */ getBansUsers_v3: (queryParams?: { activeOnly?: boolean | null; banType?: string | null; limit?: number; offset?: number; }) => Promise>; /** * Bulk ban user with specific type of ban. Ban types and reason can be queried. The maximum limit value is 100 userIDs action code : 10141 */ createBanUser_v3: (data: BulkBanCreateRequestV3) => Promise>; /** * disable bulk ban user. The maximum limit value is 100 action code : 10142 */ patchBanUserDisabled_v3: (data: BulkUnbanCreateRequestV3) => Promise>; }; /** * AUTO GENERATED */ declare function ClientsAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * action code: 10308 */ getClients_v3: (queryParams?: { clientId?: string | null; clientName?: string | null; clientType?: string | null; limit?: number; offset?: number; skipLoginQueue?: boolean | null; }) => Promise>; /** * Add a new OAuth 2.0 client A new client automatically granted with these scopes: commerce, account, analytics, publishing, social. **Note for Multi Tenant Mode (Confidential Client):** Only Super admin can set permission with resource & action. Studio admin & game admin need set permission with permission module. action code: 10301 **Fields Description:** - **clientId** : The client ID. e.g f815e5c44f364993961be3b3f26a7bf4 - **clientName** : The client name. e.g E-commerce - **secret** : The client's secret. It's empty if the client's type is a public client. Otherwise, the client secret is required - **namespace** : The namespace where the client lives. e.g sample-game - **redirectUri** : Contains the redirect URI used in OAuth callback. e.g https://example.net/platform - **oauthClientType** : The OAuth 2.0 client type. The client type determines whether the authorization needs Proof Of Key Exchange or not. A public client type doesn't have a client secret and should use PKCE flow. A confidential client type has a client secret and don't use PKCE flow Supported oAuthClientType : - **Public** - **Confidential** - **audiences** : List of target client IDs who is intended to receive the token. e.g ["eaaa65618fe24293b00a61454182b435", "40073ee9bc3446d3a051a71b48509a5d"] - **baseUri** : A base URI of the application. It is used for making sure the token is intended to be used by the client. e.g https://example.net/platform - **clientPermissions** : Contains the client's permissions - **deletable** : The flag to identify whether client is deletable (optional). default value: true - **clientPlatform**: available client platform (optional). default value: "" - Playstation - Xbox - Steam - Epic - IOS - GooglePlay - Nintendo - Oculus - **twoFactorEnabled**: The flag to indicate whether 2FA validation is enable for this client. default value: false - **oauthAccessTokenExpiration**: a configurable expiration time for **access_token**, default value: 0 (mean fetch value from environment variable) - **oauthRefreshTokenExpiration**: a configurable expiration time for **refresh_token**, default value: 0 (mean fetch value from environment variable) - **oauthAccessTokenExpirationTimeUnit**: a configurable expiration time unit for **access_token**, default value: SECONDS - **oauthRefreshTokenExpirationTimeUnit**: a configurable expiration time unit for **refresh_token**, default value: SECONDS */ createClient_v3: (data: ClientCreationV3Request) => Promise>; /** * Updates multiple OAuth 2.0 clients. Specify only the fields you want to update in the request payload, e.g. {"ClientName":"E-commerce", "BaseUri":"https://example.net"} **Note for Multi Tenant Mode (Confidential Client):** Only Super admin can set permission with resource & action. Studio admin & game admin need set permission with permission module. action code: 10302 **Fields Description:** - **clientName** : The client name. It should not be empty if the field exists in the body. e.g E-commerce - **namespace** : The namespace where the client lives. e.g sample-game - **redirectUri** : Contains the redirect URI used in OAuth callback. It should not be empty if the field exists in the body. e.g https://example.net/platform - **audiences** : List of target client IDs who is intended to receive the token. e.g ["eaaa65618fe24293b00a61454182b435", "40073ee9bc3446d3a051a71b48509a5d"] - **baseUri** : A base URI of the application. It is used in the audience checking for making sure the token is used by the right resource server. Required if the application type is a server. e.g https://example.net/platform - **clientPermissions** : Contains the client's permissions - **deletable** : The flag to identify whether client is deletable (optional). e.g. true - **clientPlatform** : available client platform (optional). default value: "". - Playstation - Xbox - Steam - Epic - IOS - GooglePlay - Nintendo - Oculus - **twoFactorEnabled**: The flag to indicate whether 2FA validation is enable for this client. default value: false - **oauthAccessTokenExpiration**: a configurable expiration time for **access_token**, default value: 0 (mean fetch value from environment variable) - **oauthRefreshTokenExpiration**: a configurable expiration time for **refresh_token**, default value: 0 (mean fetch value from environment variable) - **oauthAccessTokenExpirationTimeUnit**: a configurable expiration time unit for **access_token**, will use previous value if not specified - **oauthRefreshTokenExpirationTimeUnit**: a configurable expiration time unit for **refresh_token**, will use previous value if not specified - **skipLoginQueue**: a flag to indicate whether this client should be exempted from login queue or not */ updateClient_v3: (data: ClientsUpdateRequestV3) => Promise>; /** * Update Client Secret */ updateSecret_ByClientId_v3: (clientId: string, data: V3ClientUpdateSecretRequest) => Promise>; /** * action code : 10310 */ deleteClient_ByClientId_v3: (clientId: string) => Promise>; /** * action code: 10309 */ getClient_ByClientId_v3: (clientId: string) => Promise>; /** * Updates an OAuth 2.0 client. Specify only the fields you want to update in the request payload, e.g. {"ClientName":"E-commerce", "BaseUri":"https://example.net"} **Note for Multi Tenant Mode (Confidential Client):** Only Super admin can set permission with resource & action. Studio admin & game admin need set permission with permission module. action code: 10302 **Fields Description:** - **clientName** : The client name. It should not be empty if the field exists in the body. e.g E-commerce - **namespace** : The namespace where the client lives. e.g sample-game - **redirectUri** : Contains the redirect URI used in OAuth callback. It should not be empty if the field exists in the body. e.g https://example.net/platform - **audiences** : List of target client IDs who is intended to receive the token. e.g ["eaaa65618fe24293b00a61454182b435", "40073ee9bc3446d3a051a71b48509a5d"] - **baseUri** : A base URI of the application. It is used in the audience checking for making sure the token is used by the right resource server. Required if the application type is a server. e.g https://example.net/platform - **clientPermissions** : Contains the client's permissions - **deletable** : The flag to identify whether client is deletable (optional). e.g. true - **clientPlatform** : available client platform (optional). default value: "". - Playstation - Xbox - Steam - Epic - IOS - GooglePlay - Nintendo - Oculus - **twoFactorEnabled**: The flag to indicate whether 2FA validation is enable for this client. default value: false - **oauthAccessTokenExpiration**: a configurable expiration time for **access_token**, default value: 0 (mean fetch value from environment variable) - **oauthRefreshTokenExpiration**: a configurable expiration time for **refresh_token**, default value: 0 (mean fetch value from environment variable) - **oauthAccessTokenExpirationTimeUnit**: a configurable expiration time unit for **access_token**, will use previous value if not specified - **oauthRefreshTokenExpirationTimeUnit**: a configurable expiration time unit for **refresh_token**, will use previous value if not specified - **skipLoginQueue**: a flag to indicate whether this client should be exempted from login queue or not */ patchClient_ByClientId_v3: (clientId: string, data: ClientUpdateV3Request) => Promise>; /** * **Note for Multi Tenant Mode:** This is for super admin only. action code: 10303 */ updatePermission_ByClientId_v3: (clientId: string, data: ClientPermissionsV3) => Promise>; /** * **Note for Multi Tenant Mode:** This is for super admin only. action code: 10307 */ updatePermission_ByClientId_ByNS_v3: (clientId: string, data: ClientPermissionsV3) => Promise>; /** * **Note for Multi Tenant Mode:** This is for super admin only. action code : 10304 */ deletePermission_ByClientId_ByResource_ByAction_v3: (clientId: string, resource: string, action: number) => Promise>; }; /** * AUTO GENERATED */ declare function ClientsConfigV3AdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * List client templates */ getClientConfigTemplates_v3: () => Promise>; /** * Delete Client config permissions by module and group. */ deleteClientConfigPermission_v3: (data: PermissionSetDeleteGroupRequest, queryParams?: { forceDelete?: boolean | null; }) => Promise>; /** * List Client available permissions */ getClientConfigPermissions_v3: (queryParams?: { excludePermissions?: boolean | null; }) => Promise>; /** * Update Client available permissions, if module or group not exists, it will auto create. */ updateClientConfigPermission_v3: (data: ListUpsertModulesRequest, queryParams?: { forceDelete?: boolean | null; }) => Promise>; }; /** * AUTO GENERATED */ declare function ConfigAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint return the value of config key. The namespace should be publisher namespace or studio namespace. **Supported config key:** * uniqueDisplayNameEnabled * usernameDisabled * mandatoryEmailVerificationEnabled */ getConfig_ByConfigKey_v3: (configKey: string) => Promise>; }; /** * AUTO GENERATED */ declare function CountryAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Admin get country list */ getCountries_v3: (queryParams?: { filterBlacklist?: boolean | null; }) => Promise>; /** * Admin get country blacklist */ getCountriesBlacklist_v3: () => Promise>; /** * Admin update country blacklist */ updateCountryBlacklist_v3: (data: CountryBlacklistRequest) => Promise>; }; /** * AUTO GENERATED */ declare function DevicesV4AdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This is the endpoint for an admin to get devices a user ever used to login */ getDevices_v4: (queryParams?: { userId?: string | null; }) => Promise>; /** * This is the endpoint for an admin to get device bans of user */ getDevicesBans_v4: (queryParams: { userId: string | null; }) => Promise>; /** * This is the endpoint for an admin to ban a device */ createDeviceBan_v4: (data: DeviceBanRequestV4) => Promise>; /** * This is the endpoint for an admin to get device types */ getDevicesTypes_v4: () => Promise>; /** * This is the endpoint for an admin to get banned devices */ getDevicesBanned_v4: (queryParams?: { deviceType?: string | null; endDate?: string | null; limit?: number; offset?: number; startDate?: string | null; }) => Promise>; /** * This is the endpoint for an admin to generate device report */ getDevicesReport_v4: (queryParams: { deviceType: string | null; endDate?: string | null; startDate?: string | null; }) => Promise>; /** * This is the endpoint for an admin to get device ban config */ getDeviceBan_ByBanId_v4: (banId: string) => Promise>; /** * This is the endpoint for an admin to update a device ban config */ updateDeviceBan_ByBanId_v4: (banId: string, data: DeviceBanUpdateRequestV4) => Promise>; /** * This is the endpoint for an admin to get device ban list */ getBans_ByDeviceId_v4: (deviceId: string) => Promise>; /** * This is the endpoint for an admin to unban device */ updateUnban_ByDeviceId_v4: (deviceId: string) => Promise>; /** * This is the endpoint for an admin to get users that ever login on the device */ getUsers_ByDeviceId_v4: (deviceId: string) => Promise>; /** * @deprecated * This is the endpoint for an admin to decrypt device id */ getDecrypt_ByDeviceId_v4: (deviceId: string) => Promise>; }; /** * AUTO GENERATED */ declare class AccountIdentifierTagAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Retrieve Account Identifier Tags. This endpoint allows administrators to retrieve tags that are used to identify and categorize user accounts. Tag Name can be used for partial content search. */ getTags_v3(queryParams?: { limit?: number; offset?: number; tagName?: string | null; }): Promise>; /** * Create a new Account Identifier Tag for users. This endpoint allows administrators to create tags that can be used to identify and categorize user accounts. */ createTag_v3(data: TagCreateRequestV3): Promise>; /** * Delete an Account Identifier Tag. This endpoint allows administrators to delete a tag that is used to identify and categorize user accounts. */ deleteTag_ByTagId_v3(tagId: string): Promise>; /** * Update an existing Account Identifier Tag. This endpoint allows administrators to update the details of a tag that is used to identify and categorize user accounts. */ updateTag_ByTagId_v3(tagId: string, data: TagUpdateRequestV3): Promise>; } /** * AUTO GENERATED */ declare class BansAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Ban type is the code available for ban assignment. It is applicable globally for any namespace. action code : 10201 */ getBans_v3(): Promise>; /** * Ban reasons is the code available to justify ban assignment. It is applicable globally for any namespace. action code : 10202 */ getBansReasons_v3(): Promise>; /** * Ban type is the code available for ban assignment. It is applicable globally for any namespace. action code : 10201 */ getBantypes_v3(): Promise>; /** * Ban type is the code available for ban assignment. It is applicable globally for any namespace. action code : 10201 */ getBansUsers_v3(queryParams?: { activeOnly?: boolean | null; banType?: string | null; limit?: number; offset?: number; }): Promise>; /** * Bulk ban user with specific type of ban. Ban types and reason can be queried. The maximum limit value is 100 userIDs action code : 10141 */ createBanUser_v3(data: BulkBanCreateRequestV3): Promise>; /** * disable bulk ban user. The maximum limit value is 100 action code : 10142 */ patchBanUserDisabled_v3(data: BulkUnbanCreateRequestV3): Promise>; } /** * AUTO GENERATED */ declare class ClientsAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * action code: 10308 */ getClients_v3(queryParams?: { clientId?: string | null; clientName?: string | null; clientType?: string | null; limit?: number; offset?: number; skipLoginQueue?: boolean | null; }): Promise>; /** * Add a new OAuth 2.0 client A new client automatically granted with these scopes: commerce, account, analytics, publishing, social. **Note for Multi Tenant Mode (Confidential Client):** Only Super admin can set permission with resource & action. Studio admin & game admin need set permission with permission module. action code: 10301 **Fields Description:** - **clientId** : The client ID. e.g f815e5c44f364993961be3b3f26a7bf4 - **clientName** : The client name. e.g E-commerce - **secret** : The client's secret. It's empty if the client's type is a public client. Otherwise, the client secret is required - **namespace** : The namespace where the client lives. e.g sample-game - **redirectUri** : Contains the redirect URI used in OAuth callback. e.g https://example.net/platform - **oauthClientType** : The OAuth 2.0 client type. The client type determines whether the authorization needs Proof Of Key Exchange or not. A public client type doesn't have a client secret and should use PKCE flow. A confidential client type has a client secret and don't use PKCE flow Supported oAuthClientType : - **Public** - **Confidential** - **audiences** : List of target client IDs who is intended to receive the token. e.g ["eaaa65618fe24293b00a61454182b435", "40073ee9bc3446d3a051a71b48509a5d"] - **baseUri** : A base URI of the application. It is used for making sure the token is intended to be used by the client. e.g https://example.net/platform - **clientPermissions** : Contains the client's permissions - **deletable** : The flag to identify whether client is deletable (optional). default value: true - **clientPlatform**: available client platform (optional). default value: "" - Playstation - Xbox - Steam - Epic - IOS - GooglePlay - Nintendo - Oculus - **twoFactorEnabled**: The flag to indicate whether 2FA validation is enable for this client. default value: false - **oauthAccessTokenExpiration**: a configurable expiration time for **access_token**, default value: 0 (mean fetch value from environment variable) - **oauthRefreshTokenExpiration**: a configurable expiration time for **refresh_token**, default value: 0 (mean fetch value from environment variable) - **oauthAccessTokenExpirationTimeUnit**: a configurable expiration time unit for **access_token**, default value: SECONDS - **oauthRefreshTokenExpirationTimeUnit**: a configurable expiration time unit for **refresh_token**, default value: SECONDS */ createClient_v3(data: ClientCreationV3Request): Promise>; /** * Updates multiple OAuth 2.0 clients. Specify only the fields you want to update in the request payload, e.g. {"ClientName":"E-commerce", "BaseUri":"https://example.net"} **Note for Multi Tenant Mode (Confidential Client):** Only Super admin can set permission with resource & action. Studio admin & game admin need set permission with permission module. action code: 10302 **Fields Description:** - **clientName** : The client name. It should not be empty if the field exists in the body. e.g E-commerce - **namespace** : The namespace where the client lives. e.g sample-game - **redirectUri** : Contains the redirect URI used in OAuth callback. It should not be empty if the field exists in the body. e.g https://example.net/platform - **audiences** : List of target client IDs who is intended to receive the token. e.g ["eaaa65618fe24293b00a61454182b435", "40073ee9bc3446d3a051a71b48509a5d"] - **baseUri** : A base URI of the application. It is used in the audience checking for making sure the token is used by the right resource server. Required if the application type is a server. e.g https://example.net/platform - **clientPermissions** : Contains the client's permissions - **deletable** : The flag to identify whether client is deletable (optional). e.g. true - **clientPlatform** : available client platform (optional). default value: "". - Playstation - Xbox - Steam - Epic - IOS - GooglePlay - Nintendo - Oculus - **twoFactorEnabled**: The flag to indicate whether 2FA validation is enable for this client. default value: false - **oauthAccessTokenExpiration**: a configurable expiration time for **access_token**, default value: 0 (mean fetch value from environment variable) - **oauthRefreshTokenExpiration**: a configurable expiration time for **refresh_token**, default value: 0 (mean fetch value from environment variable) - **oauthAccessTokenExpirationTimeUnit**: a configurable expiration time unit for **access_token**, will use previous value if not specified - **oauthRefreshTokenExpirationTimeUnit**: a configurable expiration time unit for **refresh_token**, will use previous value if not specified - **skipLoginQueue**: a flag to indicate whether this client should be exempted from login queue or not */ updateClient_v3(data: ClientsUpdateRequestV3): Promise>; /** * Update Client Secret */ updateSecret_ByClientId_v3(clientId: string, data: V3ClientUpdateSecretRequest): Promise>; /** * action code : 10310 */ deleteClient_ByClientId_v3(clientId: string): Promise>; /** * action code: 10309 */ getClient_ByClientId_v3(clientId: string): Promise>; /** * Updates an OAuth 2.0 client. Specify only the fields you want to update in the request payload, e.g. {"ClientName":"E-commerce", "BaseUri":"https://example.net"} **Note for Multi Tenant Mode (Confidential Client):** Only Super admin can set permission with resource & action. Studio admin & game admin need set permission with permission module. action code: 10302 **Fields Description:** - **clientName** : The client name. It should not be empty if the field exists in the body. e.g E-commerce - **namespace** : The namespace where the client lives. e.g sample-game - **redirectUri** : Contains the redirect URI used in OAuth callback. It should not be empty if the field exists in the body. e.g https://example.net/platform - **audiences** : List of target client IDs who is intended to receive the token. e.g ["eaaa65618fe24293b00a61454182b435", "40073ee9bc3446d3a051a71b48509a5d"] - **baseUri** : A base URI of the application. It is used in the audience checking for making sure the token is used by the right resource server. Required if the application type is a server. e.g https://example.net/platform - **clientPermissions** : Contains the client's permissions - **deletable** : The flag to identify whether client is deletable (optional). e.g. true - **clientPlatform** : available client platform (optional). default value: "". - Playstation - Xbox - Steam - Epic - IOS - GooglePlay - Nintendo - Oculus - **twoFactorEnabled**: The flag to indicate whether 2FA validation is enable for this client. default value: false - **oauthAccessTokenExpiration**: a configurable expiration time for **access_token**, default value: 0 (mean fetch value from environment variable) - **oauthRefreshTokenExpiration**: a configurable expiration time for **refresh_token**, default value: 0 (mean fetch value from environment variable) - **oauthAccessTokenExpirationTimeUnit**: a configurable expiration time unit for **access_token**, will use previous value if not specified - **oauthRefreshTokenExpirationTimeUnit**: a configurable expiration time unit for **refresh_token**, will use previous value if not specified - **skipLoginQueue**: a flag to indicate whether this client should be exempted from login queue or not */ patchClient_ByClientId_v3(clientId: string, data: ClientUpdateV3Request): Promise>; /** * **Note for Multi Tenant Mode:** This is for super admin only. action code: 10303 */ updatePermission_ByClientId_v3(clientId: string, data: ClientPermissionsV3): Promise>; /** * **Note for Multi Tenant Mode:** This is for super admin only. action code: 10307 */ updatePermission_ByClientId_ByNS_v3(clientId: string, data: ClientPermissionsV3): Promise>; /** * **Note for Multi Tenant Mode:** This is for super admin only. action code : 10304 */ deletePermission_ByClientId_ByResource_ByAction_v3(clientId: string, resource: string, action: number): Promise>; } /** * AUTO GENERATED */ declare class ClientsConfigV3Admin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * List client templates */ getClientConfigTemplates_v3(): Promise>; /** * Delete Client config permissions by module and group. */ deleteClientConfigPermission_v3(data: PermissionSetDeleteGroupRequest, queryParams?: { forceDelete?: boolean | null; }): Promise>; /** * List Client available permissions */ getClientConfigPermissions_v3(queryParams?: { excludePermissions?: boolean | null; }): Promise>; /** * Update Client available permissions, if module or group not exists, it will auto create. */ updateClientConfigPermission_v3(data: ListUpsertModulesRequest, queryParams?: { forceDelete?: boolean | null; }): Promise>; } /** * AUTO GENERATED */ declare class ConfigAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint return the value of config key. The namespace should be publisher namespace or studio namespace. **Supported config key:** * uniqueDisplayNameEnabled * usernameDisabled * mandatoryEmailVerificationEnabled */ getConfig_ByConfigKey_v3(configKey: string): Promise>; } /** * AUTO GENERATED */ declare class CountryAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Admin get country list */ getCountries_v3(queryParams?: { filterBlacklist?: boolean | null; }): Promise>; /** * Admin get country blacklist */ getCountriesBlacklist_v3(): Promise>; /** * Admin update country blacklist */ updateCountryBlacklist_v3(data: CountryBlacklistRequest): Promise>; } /** * AUTO GENERATED */ declare class DevicesV4Admin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This is the endpoint for an admin to get devices a user ever used to login */ getDevices_v4(queryParams?: { userId?: string | null; }): Promise>; /** * This is the endpoint for an admin to get device bans of user */ getDevicesBans_v4(queryParams: { userId: string | null; }): Promise>; /** * This is the endpoint for an admin to ban a device */ createDeviceBan_v4(data: DeviceBanRequestV4): Promise>; /** * This is the endpoint for an admin to get device types */ getDevicesTypes_v4(): Promise>; /** * This is the endpoint for an admin to get banned devices */ getDevicesBanned_v4(queryParams?: { deviceType?: string | null; endDate?: string | null; limit?: number; offset?: number; startDate?: string | null; }): Promise>; /** * This is the endpoint for an admin to generate device report */ getDevicesReport_v4(queryParams: { deviceType: string | null; endDate?: string | null; startDate?: string | null; }): Promise>; /** * This is the endpoint for an admin to get device ban config */ getDeviceBan_ByBanId_v4(banId: string): Promise>; /** * This is the endpoint for an admin to update a device ban config */ updateDeviceBan_ByBanId_v4(banId: string, data: DeviceBanUpdateRequestV4): Promise>; /** * This is the endpoint for an admin to get device ban list */ getBans_ByDeviceId_v4(deviceId: string): Promise>; /** * This is the endpoint for an admin to unban device */ updateUnban_ByDeviceId_v4(deviceId: string): Promise>; /** * This is the endpoint for an admin to get users that ever login on the device */ getUsers_ByDeviceId_v4(deviceId: string): Promise>; /** * @deprecated * This is the endpoint for an admin to decrypt device id */ getDecrypt_ByDeviceId_v4(deviceId: string): Promise>; } /** * AUTO GENERATED */ declare class InputValidationsAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint is to get list of input validation configuration. <code>regex</code> parameter will be returned if <code>isCustomRegex</code> is true. Otherwise, it will be empty. */ getInputValidations_v3(): Promise>; /** * This endpoint is used to update input validation configuration. Supported <code>field</code>: - displayName - password - username - email - avatar If <code>isCustomRegex</code> is set to true, <code>regex</code> parameter will be used as input validation and the other parameters will be ignored. Otherwise, <code>regex</code> parameter will be ignored and regex for input validation will be generated based on the combination of the other parameters. If <code>allowUnicode</code> is set to true, unicode regex pattern will be use as the input validation and the other parameters will be ignored. Supported <code>letterCase</code>: - lowercase - uppercase - mixed: uppercase and lowercase - any: uppercase and/or lowercase flexible special character non words with <code>allowAllSpecialCharacters</code> if <code>allowAllSpecialCharacters</code> is set to true <code>specialCharacters</code> will forced to empty. Supported <code>specialCharacterLocation</code>: - anywhere - middle If <code>specialCharacters</code> is empty, <code>specialCharacterLocation</code> and <code>maxRepeatingSpecialCharacter</code> will be ignored. <code>minCharType</code> is used to identify how many required criteria in the regex. The supported criteria are number, letter, special character, and letter case. If set to 0 or 1 means all criteria are optional. It can be set as much as the number of criteria enabled. If <code>blockedWord</code> is set by admin, any input from user which contain kind of blocked word(s) will be blocked for create/upgrade/update account If <code>avatarConfig</code> is set, will use this config and skip all the other validation conditions */ updateInputValidation_v3(data: InputValidationUpdatePayload[]): Promise>; /** * This endpoint is used to reset input validation to the default input validation configurations */ deleteInputValidation_ByField_v3(field: string): Promise>; } /** * AUTO GENERATED */ declare class LoginAllowlistAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint return login allowlist configuration from specific namespace. */ getLoginAllowlist_v3(): Promise>; /** * This endpoint update login allowlist configuration from specific game namespace. roleIds: are list of role that allowed to login Note: only accept game namespace */ updateLoginAllowlist_v3(data: LoginAllowlistRequest): Promise>; } /** * AUTO GENERATED */ declare class OAuth20Admin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint revokes all access tokens and refresh tokens a user has prior the revocation time. This endpoint requires authorized requests header with valid access token. It is a convenient feature for the developer (or admin) who wanted to revokes all user's access tokens and refresh tokens generated before some period of time. action code : 10707 */ updateRevokeOauth_ByUserId_v3(userId: string, queryParams?: { includeGameNamespace?: boolean | null; }): Promise>; /** * Admin Retrieve User Third Party Platform Token This endpoint used for retrieving third party platform token for user that login using third party, if user have not link requested platform in game namespace, will try to retrieving third party platform token from publisher namespace. Passing platform group name or it's member will return same access token that can be used across the platform members. If platformUserId provided, IAM will prefer to get platform token by platform user id. Notes: The third party platform and platform group covered for this is: - (psn) ps4web - (psn) ps4 - (psn) ps5 - epicgames - twitch - awscognito - amazon - eaorigin - snapchat - twitch - live */ getPlatformTokenOauth_ByUserId_ByPlatformId_v3(userId: string, platformId: string, queryParams?: { platformUserId?: string | null; }): Promise>; } /** * AUTO GENERATED */ declare class OverrideRoleConfigV3Admin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Get role override config. This API has upsert behavior, if there is no config yet, it will create a new one with inactive status. */ getRoleoverride_v3(queryParams: { identity: 'GAME_ADMIN' | 'USER' | 'VIEW_ONLY'; }): Promise>; /** * This API is for updating role override config. Note: This API has upsert behavior, if there is no config yet, it will create a new one first. */ patchRoleoverride_v3(data: RoleOverrideUpdateRequest, queryParams: { identity: 'GAME_ADMIN' | 'USER' | 'VIEW_ONLY'; }): Promise>; /** * Get role source permission set. */ getRoleoverrideSource_v3(queryParams: { identity: 'GAME_ADMIN' | 'USER' | 'VIEW_ONLY'; }): Promise>; /** * Enable or disable the target role override feature in path namespace. Note: This API has upsert behavior, if there is no config yet, it will create a new one first. */ patchRoleoverrideStatus_v3(data: RoleOverrideStatsUpdateRequest, queryParams: { identity: 'GAME_ADMIN' | 'USER' | 'VIEW_ONLY'; }): Promise>; /** * Get role namespace permission set. */ getPermissions_ByRoleId_v3(roleId: string): Promise>; } /** * AUTO GENERATED */ declare class ProfileUpdateStrategyAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This API is for admin to get profile update strategy by namespace and field. Note: If the config is not found, this API will return a config with unlimited. */ getProfileUpdateStrategies_v3(queryParams?: { field?: 'country' | 'display_name' | 'dob' | 'username'; }): Promise>; /** * This API includes upsert behavior. Note: 1. field 'config'' in request body will only work when type is limited */ updateProfileUpdateStrategy_v3(data: UpdateProfileUpdateStrategyConfigRequest, queryParams: { field: 'country' | 'display_name' | 'dob' | 'username'; }): Promise>; } /** * AUTO GENERATED */ declare class RolesAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * action code: 10414 */ getRoles_v3(queryParams?: { after?: string | null; before?: string | null; isWildcard?: boolean | null; limit?: number; }): Promise>; /** * Create role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - permissions: specify the permission that this role have - managers: specify list of user that will act as the managers of this role - members: specify list of user that will act as the members of this role - adminRole: specify if role is for admin user (default false) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted or not (default true) action code: 10401 */ createRole_v3(data: RoleCreateV3Request): Promise>; /** * action code: 10414 */ getRoles_v4(queryParams?: { adminRole?: boolean | null; isWildcard?: boolean | null; limit?: number; offset?: number; }): Promise>; /** * Create role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - adminRole: specify if role is for admin user (default false) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted (default true) action code: 10401 */ createRole_v4(data: RoleV4Request): Promise>; /** * action code: 10403 */ deleteRole_ByRoleId_v3(roleId: string): Promise>; /** * action code: 10419 */ getRole_ByRoleId_v3(roleId: string): Promise>; /** * Update role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted or not (optional) action code: 10402 */ patchRole_ByRoleId_v3(roleId: string, data: RoleUpdateRequestV3): Promise>; /** * Removes role ID from user's Roles and NamespaceRoles before deleting the role. action code: 10403 */ deleteRole_ByRoleId_v4(roleId: string): Promise>; /** * action code: 10419 */ getRole_ByRoleId_v4(roleId: string): Promise>; /** * Update role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - adminRole: specify if role is for admin user (default false) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted (optional) action code: 10402 */ patchRole_ByRoleId_v4(roleId: string, data: RoleV4Request): Promise>; /** * code: 10413 */ deleteAdmin_ByRoleId_v3(roleId: string): Promise>; /** * Admin roles has its members listed in the role. action code: 10420 */ getAdmin_ByRoleId_v3(roleId: string): Promise>; /** * Admin roles has its members listed in the role. Role can be set as admin role only when it has at least 1 manager. action code: 10412 */ updateAdmin_ByRoleId_v3(roleId: string): Promise>; /** * Current implementation will revoke user from role in all assigned namespaces. Parameters: - userId: string (required) - namespace: string (user’s namespace) (required) action code: 10411 */ deleteUser_ByRoleId_v4(roleId: string, data: RevokeUserV4Request): Promise>; /** * Query all users that has the specified role. action code: 10416 */ getUsers_ByRoleId_v4(roleId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; }): Promise>; /** * Parameters: - **userId**: string (required) - **namespace**: string (user’s namespace) (required) - **assignedNamespaces**: array of string (namespaces to be assigned on role) (required) action code: 10410 */ updateUser_ByRoleId_v4(roleId: string, data: AssignUserV4Request): Promise>; /** * @deprecated * Admin roles has its members listed in the role. Role can only be assigned to other users by the role's manager. action code: 10411 Deprecate: Suggest to use this: AdminRevokeUserFromRoleV4 */ deleteMember_ByRoleId_v3(roleId: string, data: RoleMembersRequestV3): Promise>; /** * Admin roles has its members listed in the role. action code: 10416 */ getMembers_ByRoleId_v3(roleId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; }): Promise>; /** * Admin roles has its members listed in the role. Role can only be assigned to other users by the role's manager. action code: 10410 */ updateMember_ByRoleId_v3(roleId: string, data: RoleMembersRequestV3): Promise>; /** * Role can only be assigned to other users by the role's manager. action code: 10409 */ deleteManager_ByRoleId_v3(roleId: string, data: RoleManagersRequestV3): Promise>; /** * Role can only be assigned to other users by the role's manager. action code: 10415 */ getManagers_ByRoleId_v3(roleId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; }): Promise>; /** * Role can only be assigned to other users by the role's manager. action code: 10408 */ updateManager_ByRoleId_v3(roleId: string, data: RoleManagersRequestV3): Promise>; deletePermission_ByRoleId_v3(roleId: string, data: string[]): Promise>; /** * This endpoint will ATTACH permission(s) into the role action code: 10404 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 1. Minutes: 0-59 * / , - 1. Hours: 0-23 * / , - 1. Day of month: 1-31 * / , - L W 1. Month: 1-12 JAN-DEC * / , - 1. Day of week: 0-6 SUN-SAT * / , - L # 1. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 1. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 1. ,: separate items of a list, e.g. MON,WED,FRI in day of week 1. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 1. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 1. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 1. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_v3(roleId: string, data: PermissionsV3): Promise>; /** * This endpoint will REPLACE role's permissions with the ones defined in body action code: 10405 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 1. Minutes: 0-59 * / , - 1. Hours: 0-23 * / , - 1. Day of month: 1-31 * / , - L W 1. Month: 1-12 JAN-DEC * / , - 1. Day of week: 0-6 SUN-SAT * / , - L # 1. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 1. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 1. ,: separate items of a list, e.g. MON,WED,FRI in day of week 1. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 1. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 1. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 1. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_admin_v3(roleId: string, data: PermissionsV3): Promise>; deletePermission_ByRoleId_v4(roleId: string, data: string[]): Promise>; /** * This endpoint will ATTACH permission(s) into the role action code: 10404 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_v4(roleId: string, data: PermissionsV3): Promise>; /** * This endpoint will REPLACE role's permissions with the ones defined in body action code: 10405 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_admin_v4(roleId: string, data: PermissionsV3): Promise>; /** * action code: 10406 */ deletePermission_ByRoleId_ByResource_ByAction_v3(roleId: string, resource: string, action: number): Promise>; } /** * AUTO GENERATED */ declare class SsoCredentialAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This is the API to Get All Active SSO Platform Credential. */ getPlatformsSso_v3(queryParams?: { limit?: number; offset?: number; }): Promise>; /** * This is the API to Delete SSO Platform Credential. */ deleteSso_ByPlatformId_v3(platformId: string): Promise>; /** * This is the API to Get SSO Platform Credential. */ getSso_ByPlatformId_v3(platformId: string): Promise>; /** * This is the API to Delete SSO Platform Credential. */ patchSso_ByPlatformId_v3(platformId: string, data: SsoPlatformCredentialRequest): Promise>; /** * This is the API to Add SSO Platform Credential. ## Supported platforms: - **discourse** the ssoUrl of the discourse is the discourse forum url. example: https://forum.example.com - **azure with SAML** **appId** is an application identifier in IdP, in azure it's called EntityID **acsUrl** is an endpoint on the service provider where the identity provider will redirect to with its authentication response. example: /iam/v3/sso/saml/azuresaml/authenticate **federationMetadataUrl** is an endpoint on the Identity Provider(IdP) to get IdP federation metadata for service provider to build trust relationship */ createSso_ByPlatformId_v3(platformId: string, data: SsoPlatformCredentialRequest): Promise>; } /** * AUTO GENERATED */ declare class ThirdPartyCredentialAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This is the API to check specific 3rd party platform availability. Passing platform group name or it's member will return same platform availability data Supported third party platform and platform group: - PSN group(psn) - ps4web - ps4 - ps5 */ getAvailability_ByPlatformId_v3(platformId: string): Promise>; /** * This is the API to Get All Active 3rd Platform Credential. */ getPlatformsAllClients_v3(): Promise>; /** * This is the API to Get All Active 3rd Platform Credential. */ getPlatformsAllClientsActive_v3(): Promise>; /** * This is the API to Delete 3rd Platform Credential. */ deleteClient_ByPlatformId_v3(platformId: string): Promise>; /** * This is the API to Get 3rd Platform Credential. */ getClients_ByPlatformId_v3(platformId: string): Promise>; /** * This is the API to Add 3rd Platform Credential. - The secret for **apple** is base64 encoded private key. - No secret for **awscognito**, we only need to configure AWS Cognito Region and User Pool - The secret for **discord** is client secret of the twitch client id. - The secret for **epicgames** is client secret of the epicgames client id. - The secret for **facebook** is client secret of the facebook client id. - The secret for **google** is client secret of the google OAuth client. - No secret for **nintendo**, we only need to configure app id of the game - No secret for **netflix**, we configure the Root, Public, Private Key certificate pem file and target environment; value: [sandbox, production] - The secret for **oculus** is app secret of the oculus app. - The secret for **ps4, ps5, and ps4web** is client secret of the psn web server. - The secret for **steam** is the Steam Web API Key. - The secret for **steamopenid** is the Steam Web API Key. - The secret for **twitch** is client secret of the twitch client. - The secret for **live** is the Relying Party Private Key in base64 encode PEM format. - The secret for **xblwebapi** is client secret of the xbl client. If generic oauth flow is set to true: - Current supported value for TokenAuthenticationType is **code, idToken and bearerToken** - <code>TokenClaimsMapping</code> is used to extract user info from idToken claims or user info endpoint response accessed using bearerToken. Its a JSON format with key should be <code>name</code>, <code>email</code> and <code>avatarUrl</code> since IAM will look up for these key when extracting user info.**default claims keys : userIdentity/sub, name, email and avatarUrl/picture** */ patchClient_ByPlatformId_v3(platformId: string, data: ThirdPartyLoginPlatformCredentialRequest): Promise>; /** * This is the API to Add 3rd Platform Credential. - The secret for **apple** is base64 encoded private key. - No secret for **awscognito**, we only need to configure AWS Cognito Region and User Pool - The secret for **discord** is client secret of the twitch client id. - The secret for **epicgames** is client secret of the epicgames client id. - The secret for **facebook** is client secret of the facebook client id. - The secret for **google** is client secret of the google OAuth client. - No secret for **nintendo**, we only need to configure app id of the game - No secret for **netflix**, we configure the Root, Public, Private Key certificate pem file and target environment; value: [sandbox, production] - The secret for **oculus** is app secret of the oculus app. - The secret for **ps4, ps5, and ps4web** is client secret of the psn web server. - The secret for **steam** is the Steam Web API Key. - The secret for **steamopenid** is the Steam Web API Key. - The secret for **twitch** is client secret of the twitch client. - The secret for **live** is the Relying Party Private Key in base64 encode PEM format. - The secret for **xblwebapi** is client secret of the xbl client. If generic oauth flow is set to true: - Current supported value for TokenAuthenticationType are **code, idToken and bearerToken** - <code>TokenClaimsMapping</code> is used to extract user info from idToken claims or user info endpoint response accessed using bearerToken. Its a JSON format with key should be <code>name</code>, <code>email</code> and <code>avatarUrl</code> since IAM will look up for these key when extracting user info. **default claims keys : userIdentity/sub, name, email and avatarUrl/picture** */ createClient_ByPlatformId_v3(platformId: string, data: ThirdPartyLoginPlatformCredentialRequest): Promise>; /** * This is the API to unregister 3rd Platform domain. If there is a ssoGroups in request body, then this request wil only delete the sso group from the target domain, it will not delete domain. */ deleteClientDomain_ByPlatformId_v3(platformId: string, data: PlatformDomainDeleteRequest): Promise>; /** * This is the API to patch update 3rd Platform domain. This API is a create or partial-update behavior. If it is update, it is a partial update behavior. */ patchClientDomain_ByPlatformId_v3(platformId: string, data: PlatformDomainPatchRequest): Promise>; /** * This is the API to set 3rd Platform domain. This API is a create-or-update behavior. If it is update, it is a replacement behavior. */ updateClientDomain_ByPlatformId_v3(platformId: string, data: PlatformDomainUpdateRequest): Promise>; } /** * AUTO GENERATED */ declare class UsersAdmin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Get my user data action code : 10147 */ getUsersMe_v3(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/search [GET]_** */ getUsers_v2(queryParams: { platformId: string | null; after?: string | null; before?: string | null; displayName?: string | null; limit?: number; loginId?: string | null; platformUserId?: string | null; roleId?: string | null; userId?: string | null; }): Promise>; /** * This endpoint search user who owns the given email address action code : 10132 */ getUsers_v3(queryParams?: { emailAddress?: string | null; }): Promise>; /** * This endpoint support to bulk update users based on given data. ------ Supported fields: * skipLoginQueue */ updateUser_v3(data: UsersUpdateRequestV3): Promise>; /** * List all users that has admin role (role that has admin_role attribute set to true). Endpoint behavior : - if query parameter is defined, endpoint will search users whose email address and display name match with the query - if roleId parameter is defined, endpoint will search users that have the defined roleId - if startDate and endDate parameters is defined, endpoint will search users which created on the certain date range - if startDate parameter is defined, endpoint will search users that created start from the defined date - if endDate parameter is defined, endpoint will search users that created until the defined date In multi tenant mode : - if super admin search in super admin namespace, the result will be all admin users - if super admin search in game studio namespace, the result will be all admin users under the game studio namespace - if studio admin search in their studio namespace, the result will be all admin user in the game studio namespace The endpoint will return all admin from all namespace when called from publisher namespace. When not called from publisher namespace, the endpoint will return all admin from the path namespace. */ getAdmins_v3(queryParams?: { after?: string | null; before?: string | null; endDate?: string | null; limit?: number; query?: string | null; roleId?: string | null; startDate?: string | null; }): Promise>; /** * This endpoint returns user bans of userIDs specified in the payload action code : 10127 */ fetchUserBan_v3(data: GetBulkUserBansRequest, queryParams?: { activeOnly?: boolean | null; banType?: string | null; }): Promise>; /** * List User By User ID This endpoint intended to list user information from the given list of userID and namespace */ createUserBulk_v3(data: AdminBulkUserRequest): Promise>; /** * 1. **Cursor-Based User Retrieval** This API fetches user records ordered by created_at ASC, user_id ASC to ensure a stable pagination order. Pagination is handled using a cursor, which consists of created_at and user_id. 2. **GraphQL-Like Querying** By default, the API only returns the user ID. To include additional fields in the response, specify them in the request body under the fields parameter. ***Supported fields***: ['created_at', 'email_address'] ***Note***: If a value is not in the allowed list, the API will ignore it. 3. **Cursor Mechanics** The cursor consists of created_at and user_id from the last retrieved record. The next query fetches records strictly after the provided cursor. ***The query applies the following ordering logic***: Records with a later created_at timestamp are included. If multiple records have the same created_at, only records with a higher user_id are included. This ensures that records with the exact same created_at as the cursor are excluded from the next page to prevent duplication. 4. **Usage** For the first-time query, the request body does not require a cursor. If the data array is empty, it indicates that the cursor has reached the end of the available records. */ fetchUserCursor_v3(data: CursorGetUserRequest): Promise>; /** * Use this endpoint to invite admin or non-admin user and assign role to them. The role must be scoped to namespace based on the **{namespace}** value in path parameter. An admin user can only assign role to namespaces that the admin user has the required permission. Role is optional, if not specified then it will only assign User role The invited admin will also assigned with "User" role by default. */ createUserInvite_v3(data: InviteUserRequestV3): Promise>; /** * Endpoint behavior : - By default this endpoint searches all users on the specified namespace. - If query parameter is defined, endpoint will search users whose email address, display name, username, or third party partially match with the query. - The query parameter length must be between 3 and 30 characters. For email address queries (i.e., contains '@'), the allowed length is 3 to 40 characters. Otherwise, the database will not be queried. - If startDate and endDate parameters is defined, endpoint will search users which created on the certain date range. - If query, startDate and endDate parameters are defined, endpoint will search users whose email address and display name match and created on the certain date range. - If startDate parameter is defined, endpoint will search users that created start from the defined date. - If endDate parameter is defined, endpoint will search users that created until the defined date. - If platformId parameter is defined and by parameter is using thirdparty, endpoint will search users based on the platformId they have linked to. - If platformBy parameter is defined and by parameter is using thirdparty, endpoint will search users based on the platformUserId or platformDisplayName they have linked to, example value: platformUserId or platformDisplayName. - If limit is not defined, The default limit is 100. GraphQL-Like Querying: - By default, the API only returns the minimum fields -> [displayName, authType, createdAt, uniqueDisplayName, deletionStatus, enabled, emailAddress, skipLoginQueue, testAccount] - To include additional fields in the response, specify them in the request params. - Supported fields: [country, emailVerified, avatarUrl, enabled] - Note: If a value is not in the allowed list, the API will ignore it. In Multi Tenant mode : - If super admin search in super admin namespace, the result will be all game admin user - If super admin search in game studio namespace, the result will be all game admin user and players under the game studio namespace - If super admin search in game namespace, the result will be all game admin users and players under the game namespace - If game admin search in their game studio namespace, the result will be all game admin user in the studio namespace - If game admin search in their game namespace, the result will be all player in the game namespace action code : 10133 */ getUsersSearch_v3(queryParams?: { by?: string | null; endDate?: string | null; includeTotal?: boolean | null; limit?: number; offset?: number; platformBy?: string | null; platformId?: string | null; query?: string | null; roleIds?: string | null; selectedFields?: string | null; skipLoginQueue?: boolean | null; startDate?: string | null; tagIds?: string | null; testAccount?: boolean | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId} [GET]_** */ getUser_ByUserId_v2(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId} [PATCH]_** This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {Country, DisplayName, LanguageTag} Country use ISO3166-1 alpha-2 two letter, e.g. US. **Several case of updating email address** - User want to update email address of which have been verified, NewEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with verified email before. NewEmailAddress response field will be filled with newest email address. */ patchUser_ByUserId_v2(userId: string, data: UserUpdateRequest): Promise>; /** * Admin Get User By User Id */ getUser_ByUserId_v3(userId: string): Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName, tags} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. Admin can set Tags with array string data e.g. ["10e9a46ef6164b7e86d08e86605bd8cf"]. Admin also can reset user tags by sending empty array string e.g. [ ]. Users can have at most 5 tags. No duplicate tags allowed. **Response body logic when user updating email address:** - User want to update email address of which have been verified, NewEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with verified email before. NewEmailAddress response field will be filled with newest email address. action code : 10103 */ patchUser_ByUserId_v3(userId: string, data: UserUpdateRequestV3): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions [GET]_** - **Note:** difference in V3 response, format difference: Pascal case => Camel case */ getAgerestrictions_v2(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions [PATCH]_** */ patchAgerestriction_v2(data: AgeRestrictionRequest): Promise>; /** * action code: 10138 */ getAgerestrictions_v3(): Promise>; /** * action code: 10122 */ patchAgerestriction_v3(data: AgeRestrictionRequestV3): Promise>; /** * This endpoint search user by the list of email addresses action code : 10132 */ fetchUserSearchBulk_v3(data: ListEmailAddressRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [POST]_** */ createBan_ByUserId_v2(userId: string, data: BanCreateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [GET]_** */ getBans_ByUserId_v2(userId: string, queryParams?: { activeOnly?: boolean | null; }): Promise>; /** * This endpoint retrieve the first page of the data if after and before parameters is empty action code : 10126 */ getBans_ByUserId_v3(userId: string, queryParams?: { activeOnly?: boolean | null; after?: string | null; before?: string | null; limit?: number; }): Promise>; /** * Bans a user with specific type of ban. Ban types and reason can be queried. action code : 10141 */ createBan_ByUserId_v3(userId: string, data: BanCreateRequest): Promise>; /** * if limit is not defined, The default limit is 100 */ getUsersLinkhistories_v3(queryParams: { platformId: string | null; limit?: number; offset?: number; platformUserId?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles [PATCH]_** */ updateRole_ByUserId_v2(userId: string, data: string[]): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles [PATCH]_** */ updateRole_ByUserId_ByNS_v2(userId: string, data: string[]): Promise>; /** * This endpoint search admin users which have the roleId Notes : this endpoint only accept admin role. Admin Role is role which have admin status and members. Use endpoint [GET] /roles/{roleId}/admin to check the role status action code : 10140 */ getUsers_ByRoleId_v3(roleId: string, queryParams?: { after?: number; before?: number; limit?: number; }): Promise>; /** * **[WARNING] This endpoint is only for testing purpose.** This endpoint get active user verification code. There are some scenarios of getting verification codes, all of them will be returned on this endpoint: - After account registration - After reset password request - After headless account upgrade - After update email request This API only accept publisher/studio namespace and userId. Action code: 10146 */ getCodes_ByUserId_v3(userId: string): Promise>; /** * Delete User Roles */ deleteRole_ByUserId_v3(userId: string, data: string[]): Promise>; /** * User's roles will be replaced with roles from request body. An admin user can only assign role with **namespace** (in request body) if the admin user has required permission which is same as the required permission of endpoint: [AdminAddUserRoleV4]. */ patchRole_ByUserId_v3(userId: string, data: NamespaceRoleRequest[]): Promise>; /** * Admin Get User State By User Id */ getState_ByUserId_v3(userId: string): Promise>; /** * Notes: - This endpoint bulk get users' basic info by userId, max allowed 100 at a time - If namespace is game, will search by game user Id, other wise will search by publisher namespace */ fetchUserBulkPlatform_v3(data: UserIDsRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** */ updateEnable_ByUserId_v2(userId: string): Promise>; /** * This endpoint disable or enable user account. Set the enable status on the request body to true to enable user account or set to false to disable it. Disable user for **Account Disable** purpose fill the reason with: - **AdminDeactivateAccount** : if your disable account request comes from admin Enable user ignore field 'reason' in the request body. action code : 10143 */ patchStatus_ByUserId_v3(userId: string, data: UpdateUserStatusRequest): Promise>; /** * This endpoint force verify user Note: - namespace: only accept publisher/studio namespace - userId: only accept publisher/studio userId action code: 10118 */ updateVerify_ByUserId_v3(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** For **Deletion Account** purpose fill the reason with: - **DeactivateAccount** : if your deletion request comes from user - **AdminDeactivateAccount** : if your deletion request comes from admin */ updateDisable_ByUserId_v2(userId: string, data: DisableUserRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions/countries/{countryCode} [PATCH]_** */ patchCountry_ByCountryCode_v2(countryCode: string, data: CountryAgeRestrictionRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/password [PUT]_** */ updatePassword_ByUserId_v2(userId: string, data: UserPasswordUpdateRequest): Promise>; /** * Update User Password */ updatePassword_ByUserId_v3(userId: string, data: UserPasswordUpdateV3Request): Promise>; /** * **This endpoint requires publisher namespace.** Returns list of users ID and namespace with their Justice platform account, under a namespace. If user doesn't have Justice platform account, the linkedPlatforms will be empty array.' */ getUsersPlatformsJustice_v3(queryParams?: { limit?: number; offset?: number; }): Promise>; /** * Gets platform accounts that are already linked with user account. Action code : 10128 **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 ## Justice Platform Account The permission ’ADMIN:NAMESPACE:{namespace}:JUSTICE:USER:{userId}’ [READ] is required in order to read the UserID who linked with the user. */ getPlatforms_ByUserId_v3(userId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; platformId?: string | null; targetNamespace?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions/countries [GET]_** */ getCountriesAgerestrictions_v2(): Promise>; /** * action code : 10139 */ getAgerestrictionsCountries_v3(): Promise>; /** * Will verify account and consume code if validateOnly is set false in request body Redeems a verification code sent to a user to verify the user's contact address is correct Available ContactType : **email** or **phone** */ updateCodeVerify_ByUserId_v3(userId: string, data: UserVerificationRequest): Promise>; /** * [WARNING] This endpoint is deleting user data from database directly by skipping GDPR flow */ deleteInformation_ByUserId_v3(userId: string): Promise>; /** * Delete User Permission */ deletePermission_ByUserId_v3(userId: string, data: PermissionDeleteRequest[]): Promise>; /** * This endpoint will APPEND user's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 1. Minutes: 0-59 * / , - 1. Hours: 0-23 * / , - 1. Day of month: 1-31 * / , - L W 1. Month: 1-12 JAN-DEC * / , - 1. Day of week: 0-6 SUN-SAT * / , - L # 1. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 1. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 1. ,: separate items of a list, e.g. MON,WED,FRI in day of week 1. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 1. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 1. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 1. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ createPermission_ByUserId_v3(userId: string, data: Permissions): Promise>; /** * This endpoint will REPLACE user's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByUserId_v3(userId: string, data: Permissions): Promise>; /** * Set ban status for a single user for a specific ban. Retrieve user ban and choose the ban ID. Set the form parameter to true/false to enable or disable the ban. action code : 10142' */ patchBan_ByUserId_ByBanId_v3(userId: string, banId: string, data: BanUpdateRequest): Promise>; /** * This endpoint get user's bans summary' */ getBansSummary_ByUserId_v3(userId: string): Promise>; /** * The verification code is sent to email address. Available contexts for use : - **UserAccountRegistration** a context type used for verifying email address in user account registration. It returns 409 if the email address already verified. **_It is the default context if the Context field is empty_** - **UpdateEmailAddress** a context type used for verify user before updating email address.(Without email address verified checking) - **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the email address is already used by others by returning HTTP Status Code 409. action code: 10116 */ updateCodeRequest_ByUserId_v3(userId: string, data: SendVerificationCodeRequestV3): Promise>; /** * Admin List User ID By Platform User ID This endpoint intended to list game user ID from the given namespace This endpoint return list of user ID by given platform ID and list of platform user ID Supported platform: - steam - steamopenid - ps4web - ps4 - ps5 - live - xblweb - oculus - oculusweb - facebook - google - googleplaygames - twitch - discord - android - ios - apple - device - justice - epicgames - nintendo - awscognito - netflix - snapchat - oidc platform id Note: **nintendo platform user ID**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ fetchUser_ByPlatformId_v3(platformId: string, data: PlatformUserIdRequest, queryParams?: { rawPID?: boolean | null; rawPUID?: boolean | null; }): Promise>; /** * Force linking platform account to user User Account. This endpoint intended for admin to forcefully link account to user. By default, these cases are not allowed - The platform account current is linked by another account - The target account ever linked this platform's another account */ updatePlatformLink_ByUserId_v3(userId: string, data: LinkPlatformAccountRequest, queryParams?: { skipConflict?: boolean | null; }): Promise>; /** * This endpoint removes role from user action code: 10110 */ deleteRole_ByUserId_ByRoleId_v3(userId: string, roleId: string): Promise>; /** * action code: 10109 */ updateRole_ByUserId_ByRoleId_v3(userId: string, roleId: string): Promise>; /** * action code : 10145 */ getDeletionStatus_ByUserId_v3(userId: string): Promise>; /** * action code : 10144 */ patchDeletionStatus_ByUserId_v3(userId: string, data: UpdateUserDeletionStatusRequest): Promise>; /** * Notes for this endpoint: This endpoint retrieve the first page of the data if <code>after</code> and <code>before</code> parameters is empty. - The maximum value of the limit is 100 and the minimum value of the limit is 1. - This endpoint retrieve the next page of the data if we provide <code>after</code> parameters with valid Unix timestamp. - This endpoint retrieve the previous page of the data if we provide <code>before</code> parameter with valid data Unix timestamp." */ getLoginsHistories_ByUserId_v3(userId: string, queryParams?: { after?: number; before?: number; limit?: number; }): Promise>; /** * This endpoint ONLY accept **Client Token** This endpoint is utilized for specific scenarios where **email notifications are disabled** The user's email will be marked as verified Note: - emailAddress or password field are optional - request body can't be empty action code : 10103 */ patchTrustlyIdentity_ByUserId_v3(userId: string, data: UserIdentityUpdateRequestV3): Promise>; /** * This endpoint retrieves platform accounts linked to user. It will query all linked platform accounts and result will be distinct & grouped, same platform we will pick oldest linked one. */ getDistinctPlatforms_ByUserId_v3(userId: string): Promise>; /** * This endpoint gets list justice platform account by providing publisher namespace and publisher userID */ getPlatformsJustice_ByUserId_v3(userId: string): Promise>; /** * This endpoint only retrieves 3rd party platform accounts linked to user. It will query platform accounts and result will be distinct & grouped, same platform we will pick oldest linked one. ------ Supported status: - LINKED - RESTRICTIVELY_UNLINKED - UNLINKED - ALL */ getPlatformsDistinct_ByUserId_v3(userId: string, queryParams?: { status?: string | null; }): Promise>; /** * If validateOnly is set false, will upgrade headless account with verification code The endpoint upgrades a headless account by linking the headless account with the email address and the password. By upgrading the headless account into a full account, the user could use the email address and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the send verification code endpoint. This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. Supported user data fields : - displayName - dateOfBirth : format YYYY-MM-DD, e.g. 2019-04-29 - country : format ISO3166-1 alpha-2 two letter, e.g. US action code : 10124 */ updateHeadlesCodeVerify_ByUserId_v3(userId: string, data: UpgradeHeadlessAccountWithVerificationCodeRequestV3): Promise>; /** * @deprecated * ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **googleplaygames** - **oculus** - **twitch** - **android** - **ios** - **apple** - **device** - **discord** - **awscognito** - **epicgames** - **nintendo** - **snapchat** Unlink user's account from a specific platform. 'justice' platform might have multiple accounts from different namespaces linked. _platformNamespace_ need to be specified when the platform ID is 'justice'. Unlink user's account from justice platform will enable password token grant and password update. If you want to unlink user's account in a game namespace, you have to specify _platformNamespace_ to that game namespace. action code : 10121 */ deletePlatform_ByUserId_ByPlatformId_v3(userId: string, platformId: string, data: UnlinkUserPlatformRequest): Promise>; /** * action code: 10123 */ patchAgerestrictionCountry_ByCountryCode_v3(countryCode: string, data: CountryAgeRestrictionV3Request): Promise>; /** * This API is for admin to get user's link history. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getPlatformsLinkHistories_ByUserId_v3(userId: string, queryParams: { platformId: string | null; }): Promise>; /** * Unlink user's account from third platform in all namespaces. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: to unlink steam third party account, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 Unlink platform account associated with a group: If user unlink platform account associated with a group, the API logic will unlink all of platform account under that group as well. example: if user unlink from ps4, the API logic will unlink ps5 and ps4web as well */ deleteAll_ByUserId_ByPlatformId_v3(userId: string, platformId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms/{platformId} [DELETE]_** ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **oculus** - **twitch** - **android** - **ios** - **device** - **discord** Delete link of user's account with platform. 'justice' platform might have multiple accounts from different namespaces linked. platform_namespace need to be specified when the platform ID is 'justice'. Delete link of justice platform will enable password token grant and password update. */ deleteLink_ByUserId_ByPlatformId_v2(userId: string, platformId: string, data: { platform_namespace?: string | null; }): Promise>; /** * **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **googleplaygames**: The ticket’s value is the authorization code returned by Google play games OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **apple**: The ticket’s value is the authorization code returned by Apple OAuth. - **device**: Every device that does’nt run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. - **awscognito**: The ticket’s value is the aws cognito access token (JWT). - **epicgames**: The ticket’s value is an access-token obtained from Epicgames EOS Account Service. - **nintendo**: The ticket’s value is the authorization code(id_token) returned by Nintendo OAuth. */ postLink_ByUserId_ByPlatformId_v3(userId: string, platformId: string, data: { ticket: string | null; }): Promise>; /** * Get User By Platform User ID This endpoint return user information by given platform ID and platform user ID. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: for steam network platform, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 - **oculus**: if query by app user id, please set the query param **pidType** to **OCULUS_APP_USER_ID** (support game namespace only) */ getUser_ByPlatformId_ByPlatformUserId_v3(platformId: string, platformUserId: string, queryParams?: { pidType?: string | null; }): Promise>; /** * Delete User Permission */ deletePermission_ByUserId_ByResource_ByAction_v3(userId: string, resource: string, action: number): Promise>; /** * This endpoint gets user single platform account metadata. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getMetadata_ByUserId_ByPlatformId_v3(userId: string, platformId: string, queryParams?: { crossNamespace?: boolean | null; }): Promise>; /** * Admin get the link status of the third party platform token with user id. This endpoint is used for checking whether the third party user represented by third party token is linked with the corresponding user id. ## Supported platforms: - **steam**: The platform_token’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the authorization code(id_token) returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. */ postLinkStatu_ByUserId_ByPlatformId_v3(userId: string, platformId: string, data: { platformToken: string | null; }): Promise>; /** * This endpoint will support publisher access to game and game access to publisher If targetNamespace filled with publisher namespace then this endpoint will return its publisher user id and publisher namespace. If targetNamespace filled with game namespace then this endpoint will return its game user id and game namespace. */ getPlatformJustice_ByUserId_ByTargetNamespace_v3(userId: string, targetNamespace: string): Promise>; /** * Create Justice User from Publisher User information. It will check first if Justice User on target namespace already exist. */ createPlatformJustice_ByUserId_ByTargetNamespace_v3(userId: string, targetNamespace: string): Promise>; /** * @deprecated * This API is for admin to delete user's linking history with target platform id. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 ---- **Substitute endpoint**: /v3/admin/namespaces/{namespace}/users/{userId}/platforms/{platformId}/link/restrictions */ deleteLinkHistory_ByUserId_ByPlatformId_v3(userId: string, platformId: string): Promise>; /** * This API is for admin to delete user's linking restriction with target platform id. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ deleteLinkRestriction_ByUserId_ByPlatformId_v3(userId: string, platformId: string): Promise>; } /** * AUTO GENERATED */ declare class UsersV4Admin$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. action code : 10103 */ patchUserMe_v4(data: UserUpdateRequestV3): Promise>; /** * Use this endpoint to invite admin or non-admin user and assign role to them. The role must be scoped to namespace. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of endpoint: [AdminAddUserRoleV4]. Detail request body : - **emailAddresses** is required, List of email addresses that will be invited - **isAdmin** is required, true if user is admin, false if user is not admin - **namespace** is optional. Only works on multi tenant mode, if not specified then it will be assigned Publisher namespace, if specified, it will become that studio/publisher where user is invited to. - **roleId** is optional, if not specified then it will only assign User role. - **assignedNamespaces** is optional, List of namespaces which the Role will be assigned to the user, only works when Role is not empty. The invited admin will also assigned with "User" role by default. */ createUserInvite_v4(data: InviteUserRequestV4): Promise>; /** * @deprecated * Use this endpoint to invite admin or non-admin user and assign role to them. The role must be scoped to namespace. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of endpoint: [AdminAddUserRoleV4]. Detail request body : - Email Address is required, List of email addresses that will be invited - isAdmin is required, true if user is admin, false if user is not admin - Namespace is optional. Only works on multi tenant mode, if not specified then it will be assigned Publisher namespace, if specified, it will become that studio/publisher where user is invited to. - Role is optional, if not specified then it will only assign User role. - Assigned Namespaces is optional, List of namespaces which the Role will be assigned to the user, only works when Role is not empty. The invited admin will also assigned with "User" role by default. Substitute endpoint: /iam/v4/admin/users/invite */ createUserUserInvite_v4(data: InviteUserRequestV4): Promise>; /** * This endpoint is to list all Invitation Histories for new studio namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. Accepted Query: - namespace - offset - limit */ getInvitationHistories_v4(queryParams?: { limit?: number; namespace?: string | null; offset?: number; }): Promise>; /** * This endpoint is used to get user enabled factors. */ getUsersMeMfaFactor_v4(): Promise>; /** * This endpoint is used to make 2FA factor default. */ postUserMeMfaFactor_v4(data: { factor: string | null; }): Promise>; /** * This endpoint will get user's' MFA status. */ getUsersMeMfaStatus_v4(): Promise>; /** * @deprecated * This endpoint will get user's' MFA status. ------------ **Substitute endpoint**: /iam/v4/admin/users/me/mfa/status [GET] */ createUserMeMfaStatus_v4(): Promise>; /** * @deprecated * This endpoint is used to get 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ getUsersMeMfaBackupCode_v4(): Promise>; /** * @deprecated * This endpoint is used to generate 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ createUserMeMfaBackupCode_v4(): Promise>; /** * This endpoint is used to send email code. -------------- Supported actions: * ChangePassword * DisableMFAEmail */ postUserMeMfaEmailCode_v4(data: { action?: string | null; languageTag?: string | null; }): Promise>; /** * This endpoint is used to get 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ getUsersMeMfaBackupCodes_v4(queryParams?: { languageTag?: string | null; }): Promise>; /** * This endpoint is used to generate 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ createUserMeMfaBackupCode_admin_v4(queryParams?: { languageTag?: string | null; }): Promise>; /** * This endpoint is used to enable 2FA email. */ postUserMeMfaEmailEnable_v4(data: { code: string | null; }): Promise>; /** * This endpoint is used to disable 2FA email. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ createUserMeMfaEmailDisable_v4(data: DisableMfaRequest): Promise>; /** * Create a new user with unique email address and username. **Required attributes:** - authType: possible value is EMAILPASSWD - emailAddress: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. - uniqueDisplayName: required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true, please refer to the rule from /v3/public/inputValidations API. **Not required attributes:** - displayName: Please refer to the rule from /v3/public/inputValidations API. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createUser_v4(data: CreateUserRequestV4): Promise>; /** * This endpoint will verify user's' MFA code and generate a MFA token. */ postUserMeMfaChallengeVerify_v4(data: { code?: string | null; factor?: string | null; }): Promise>; /** * This endpoint is used to generate a secret key for 3rd-party authenticator app. A QR code URI is also returned so that frontend can generate QR code image. */ createUserMeMfaAuthenticatorKey_v4(): Promise>; /** * @deprecated * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_v4(): Promise>; /** * This endpoint is used to disable 2FA backup codes. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaBackupCodeDisable_v4(data: DisableMfaRequest): Promise>; /** * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_admin_v4(queryParams?: { languageTag?: string | null; }): Promise>; /** * @deprecated * This endpoint is used to download backup codes. */ getUsersMeMfaBackupCodeDownload_v4(): Promise>; /** * Create test users and not send verification code email. Note: - count : Enter the number of test users you want to create in the count field. The maximum value of the user count is 100. - userInfo(optional) : - country: you can specify country for the test user. Country use ISO3166-1 alpha-2 two letter, e.g. US */ createTestUser_v4(data: CreateTestUsersRequestV4): Promise>; /** * This endpoint is used to enable 2FA authenticator. ---------- Prerequisites: - Generate the secret key/QR code uri by **_/iam/v4/admin/users/me/mfa/authenticator/key_** - Consume the secret key/QR code by an authenticator app - Get the code from the authenticator app */ postUserMeMfaAuthenticatorEnable_v4(data: { code: string | null; }): Promise>; /** * This endpoint is used to disable 2FA authenticator. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaAuthenticatorDisable_v4(data: DisableMfaRequest): Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. action code : 10103 */ updateUser_ByUserId_v4(userId: string, data: UserUpdateRequestV3): Promise>; /** * This endpoint is to Invitation Historiy for specific new studio namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. */ getInvitationHistories_ByNS_v4(): Promise>; /** * Use this endpoint to check if userID exists or not Maximum number of userID to be checked is 50 */ fetchUserBulkValidate_v4(data: CheckValidUserIdRequestV4): Promise>; /** * This is the endpoint for an admin to update a user email address. This endpoint need a valid user token from an admin to verify its identity (email) before updating a user. */ updateEmail_ByUserId_v4(userId: string, data: EmailUpdateRequestV4): Promise>; /** * Remove a role from user's roles. */ deleteRole_ByUserId_v4(userId: string, data: RemoveUserRoleV4Request): Promise>; /** * List roles assigned to a user */ getRoles_ByUserId_v4(userId: string): Promise>; /** * New role will be appended to user's current roles. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of this endpoint. */ updateRole_ByUserId_v4(userId: string, data: AddUserRoleV4Request): Promise>; /** * User's roles will be replaced with roles from request body. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of this endpoint. */ updateRole_ByUserId_ByNS_v4(userId: string, data: AddUserRoleV4Request): Promise>; /** * This endpoint is used to change users account type - set **testAccount** to <code>true</code> to mark user as test account type - set **testAccount** to <code>false</code> to mark user as default account type */ patchUserBulkAccountType_v4(data: BulkAccountTypeUpdateRequestV4): Promise>; /** * This endpoint is to Get list of users Invitation History for specific new studio namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. Accepted Query: - offset - limit */ getInvitationHistoriesUsers_v4(queryParams?: { limit?: number; offset?: number; }): Promise>; /** * **This endpoint is used to get user's 2FA status.** */ getMfaStatus_ByUserId_v4(userId: string): Promise>; /** * This endpoint is used to disable user 2FA. ----------- **Note**: if the factor is not specified, will disable all 2FA methods. */ deleteMfaDisable_ByUserId_v4(userId: string, data: DisableMfaRequest): Promise>; } /** * AUTO GENERATED */ declare function InputValidationsAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint is to get list of input validation configuration. <code>regex</code> parameter will be returned if <code>isCustomRegex</code> is true. Otherwise, it will be empty. */ getInputValidations_v3: () => Promise>; /** * This endpoint is used to update input validation configuration. Supported <code>field</code>: - displayName - password - username - email - avatar If <code>isCustomRegex</code> is set to true, <code>regex</code> parameter will be used as input validation and the other parameters will be ignored. Otherwise, <code>regex</code> parameter will be ignored and regex for input validation will be generated based on the combination of the other parameters. If <code>allowUnicode</code> is set to true, unicode regex pattern will be use as the input validation and the other parameters will be ignored. Supported <code>letterCase</code>: - lowercase - uppercase - mixed: uppercase and lowercase - any: uppercase and/or lowercase flexible special character non words with <code>allowAllSpecialCharacters</code> if <code>allowAllSpecialCharacters</code> is set to true <code>specialCharacters</code> will forced to empty. Supported <code>specialCharacterLocation</code>: - anywhere - middle If <code>specialCharacters</code> is empty, <code>specialCharacterLocation</code> and <code>maxRepeatingSpecialCharacter</code> will be ignored. <code>minCharType</code> is used to identify how many required criteria in the regex. The supported criteria are number, letter, special character, and letter case. If set to 0 or 1 means all criteria are optional. It can be set as much as the number of criteria enabled. If <code>blockedWord</code> is set by admin, any input from user which contain kind of blocked word(s) will be blocked for create/upgrade/update account If <code>avatarConfig</code> is set, will use this config and skip all the other validation conditions */ updateInputValidation_v3: (data: InputValidationUpdatePayload[]) => Promise>; /** * This endpoint is used to reset input validation to the default input validation configurations */ deleteInputValidation_ByField_v3: (field: string) => Promise>; }; /** * AUTO GENERATED */ declare function LoginAllowlistAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint return login allowlist configuration from specific namespace. */ getLoginAllowlist_v3: () => Promise>; /** * This endpoint update login allowlist configuration from specific game namespace. roleIds: are list of role that allowed to login Note: only accept game namespace */ updateLoginAllowlist_v3: (data: LoginAllowlistRequest) => Promise>; }; /** * AUTO GENERATED */ declare function OAuth20AdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint revokes all access tokens and refresh tokens a user has prior the revocation time. This endpoint requires authorized requests header with valid access token. It is a convenient feature for the developer (or admin) who wanted to revokes all user's access tokens and refresh tokens generated before some period of time. action code : 10707 */ updateRevokeOauth_ByUserId_v3: (userId: string, queryParams?: { includeGameNamespace?: boolean | null; }) => Promise>; /** * Admin Retrieve User Third Party Platform Token This endpoint used for retrieving third party platform token for user that login using third party, if user have not link requested platform in game namespace, will try to retrieving third party platform token from publisher namespace. Passing platform group name or it's member will return same access token that can be used across the platform members. If platformUserId provided, IAM will prefer to get platform token by platform user id. Notes: The third party platform and platform group covered for this is: - (psn) ps4web - (psn) ps4 - (psn) ps5 - epicgames - twitch - awscognito - amazon - eaorigin - snapchat - twitch - live */ getPlatformTokenOauth_ByUserId_ByPlatformId_v3: (userId: string, platformId: string, queryParams?: { platformUserId?: string | null; }) => Promise>; }; /** * AUTO GENERATED */ declare function OverrideRoleConfigV3AdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Get role override config. This API has upsert behavior, if there is no config yet, it will create a new one with inactive status. */ getRoleoverride_v3: (queryParams: { identity: "GAME_ADMIN" | "USER" | "VIEW_ONLY"; }) => Promise>; /** * This API is for updating role override config. Note: This API has upsert behavior, if there is no config yet, it will create a new one first. */ patchRoleoverride_v3: (data: RoleOverrideUpdateRequest, queryParams: { identity: "GAME_ADMIN" | "USER" | "VIEW_ONLY"; }) => Promise>; /** * Get role source permission set. */ getRoleoverrideSource_v3: (queryParams: { identity: "GAME_ADMIN" | "USER" | "VIEW_ONLY"; }) => Promise>; /** * Enable or disable the target role override feature in path namespace. Note: This API has upsert behavior, if there is no config yet, it will create a new one first. */ patchRoleoverrideStatus_v3: (data: RoleOverrideStatsUpdateRequest, queryParams: { identity: "GAME_ADMIN" | "USER" | "VIEW_ONLY"; }) => Promise>; /** * Get role namespace permission set. */ getPermissions_ByRoleId_v3: (roleId: string) => Promise>; }; /** * AUTO GENERATED */ declare function ProfileUpdateStrategyAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This API is for admin to get profile update strategy by namespace and field. Note: If the config is not found, this API will return a config with unlimited. */ getProfileUpdateStrategies_v3: (queryParams?: { field?: "country" | "display_name" | "dob" | "username"; }) => Promise>; /** * This API includes upsert behavior. Note: 1. field 'config'' in request body will only work when type is limited */ updateProfileUpdateStrategy_v3: (data: UpdateProfileUpdateStrategyConfigRequest, queryParams: { field: "country" | "display_name" | "dob" | "username"; }) => Promise>; }; /** * AUTO GENERATED */ declare function RolesAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * action code: 10414 */ getRoles_v3: (queryParams?: { after?: string | null; before?: string | null; isWildcard?: boolean | null; limit?: number; }) => Promise>; /** * Create role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - permissions: specify the permission that this role have - managers: specify list of user that will act as the managers of this role - members: specify list of user that will act as the members of this role - adminRole: specify if role is for admin user (default false) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted or not (default true) action code: 10401 */ createRole_v3: (data: RoleCreateV3Request) => Promise>; /** * action code: 10414 */ getRoles_v4: (queryParams?: { adminRole?: boolean | null; isWildcard?: boolean | null; limit?: number; offset?: number; }) => Promise>; /** * Create role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - adminRole: specify if role is for admin user (default false) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted (default true) action code: 10401 */ createRole_v4: (data: RoleV4Request) => Promise>; /** * action code: 10403 */ deleteRole_ByRoleId_v3: (roleId: string) => Promise>; /** * action code: 10419 */ getRole_ByRoleId_v3: (roleId: string) => Promise>; /** * Update role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted or not (optional) action code: 10402 */ patchRole_ByRoleId_v3: (roleId: string, data: RoleUpdateRequestV3) => Promise>; /** * Removes role ID from user's Roles and NamespaceRoles before deleting the role. action code: 10403 */ deleteRole_ByRoleId_v4: (roleId: string) => Promise>; /** * action code: 10419 */ getRole_ByRoleId_v4: (roleId: string) => Promise>; /** * Update role request body: - roleName: specify role name, alphanumeric, cannot have special character (required) - adminRole: specify if role is for admin user (default false) - isWildcard: specify if role can be assigned to wildcard (*) namespace (default false) - deletable: specify if role can be deleted (optional) action code: 10402 */ patchRole_ByRoleId_v4: (roleId: string, data: RoleV4Request) => Promise>; /** * code: 10413 */ deleteAdmin_ByRoleId_v3: (roleId: string) => Promise>; /** * Admin roles has its members listed in the role. action code: 10420 */ getAdmin_ByRoleId_v3: (roleId: string) => Promise>; /** * Admin roles has its members listed in the role. Role can be set as admin role only when it has at least 1 manager. action code: 10412 */ updateAdmin_ByRoleId_v3: (roleId: string) => Promise>; /** * Current implementation will revoke user from role in all assigned namespaces. Parameters: - userId: string (required) - namespace: string (user’s namespace) (required) action code: 10411 */ deleteUser_ByRoleId_v4: (roleId: string, data: RevokeUserV4Request) => Promise>; /** * Query all users that has the specified role. action code: 10416 */ getUsers_ByRoleId_v4: (roleId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; }) => Promise>; /** * Parameters: - **userId**: string (required) - **namespace**: string (user’s namespace) (required) - **assignedNamespaces**: array of string (namespaces to be assigned on role) (required) action code: 10410 */ updateUser_ByRoleId_v4: (roleId: string, data: AssignUserV4Request) => Promise>; /** * @deprecated * Admin roles has its members listed in the role. Role can only be assigned to other users by the role's manager. action code: 10411 Deprecate: Suggest to use this: AdminRevokeUserFromRoleV4 */ deleteMember_ByRoleId_v3: (roleId: string, data: RoleMembersRequestV3) => Promise>; /** * Admin roles has its members listed in the role. action code: 10416 */ getMembers_ByRoleId_v3: (roleId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; }) => Promise>; /** * Admin roles has its members listed in the role. Role can only be assigned to other users by the role's manager. action code: 10410 */ updateMember_ByRoleId_v3: (roleId: string, data: RoleMembersRequestV3) => Promise>; /** * Role can only be assigned to other users by the role's manager. action code: 10409 */ deleteManager_ByRoleId_v3: (roleId: string, data: RoleManagersRequestV3) => Promise>; /** * Role can only be assigned to other users by the role's manager. action code: 10415 */ getManagers_ByRoleId_v3: (roleId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; }) => Promise>; /** * Role can only be assigned to other users by the role's manager. action code: 10408 */ updateManager_ByRoleId_v3: (roleId: string, data: RoleManagersRequestV3) => Promise>; deletePermission_ByRoleId_v3: (roleId: string, data: string[]) => Promise>; /** * This endpoint will ATTACH permission(s) into the role action code: 10404 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 1. Minutes: 0-59 * / , - 1. Hours: 0-23 * / , - 1. Day of month: 1-31 * / , - L W 1. Month: 1-12 JAN-DEC * / , - 1. Day of week: 0-6 SUN-SAT * / , - L # 1. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 1. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 1. ,: separate items of a list, e.g. MON,WED,FRI in day of week 1. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 1. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 1. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 1. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_v3: (roleId: string, data: PermissionsV3) => Promise>; /** * This endpoint will REPLACE role's permissions with the ones defined in body action code: 10405 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 1. Minutes: 0-59 * / , - 1. Hours: 0-23 * / , - 1. Day of month: 1-31 * / , - L W 1. Month: 1-12 JAN-DEC * / , - 1. Day of week: 0-6 SUN-SAT * / , - L # 1. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 1. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 1. ,: separate items of a list, e.g. MON,WED,FRI in day of week 1. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 1. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 1. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 1. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_admin_v3: (roleId: string, data: PermissionsV3) => Promise>; deletePermission_ByRoleId_v4: (roleId: string, data: string[]) => Promise>; /** * This endpoint will ATTACH permission(s) into the role action code: 10404 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_v4: (roleId: string, data: PermissionsV3) => Promise>; /** * This endpoint will REPLACE role's permissions with the ones defined in body action code: 10405 Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByRoleId_admin_v4: (roleId: string, data: PermissionsV3) => Promise>; /** * action code: 10406 */ deletePermission_ByRoleId_ByResource_ByAction_v3: (roleId: string, resource: string, action: number) => Promise>; }; /** * AUTO GENERATED */ declare function SsoCredentialAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This is the API to Get All Active SSO Platform Credential. */ getPlatformsSso_v3: (queryParams?: { limit?: number; offset?: number; }) => Promise>; /** * This is the API to Delete SSO Platform Credential. */ deleteSso_ByPlatformId_v3: (platformId: string) => Promise>; /** * This is the API to Get SSO Platform Credential. */ getSso_ByPlatformId_v3: (platformId: string) => Promise>; /** * This is the API to Delete SSO Platform Credential. */ patchSso_ByPlatformId_v3: (platformId: string, data: SsoPlatformCredentialRequest) => Promise>; /** * This is the API to Add SSO Platform Credential. ## Supported platforms: - **discourse** the ssoUrl of the discourse is the discourse forum url. example: https://forum.example.com - **azure with SAML** **appId** is an application identifier in IdP, in azure it's called EntityID **acsUrl** is an endpoint on the service provider where the identity provider will redirect to with its authentication response. example: /iam/v3/sso/saml/azuresaml/authenticate **federationMetadataUrl** is an endpoint on the Identity Provider(IdP) to get IdP federation metadata for service provider to build trust relationship */ createSso_ByPlatformId_v3: (platformId: string, data: SsoPlatformCredentialRequest) => Promise>; }; /** * AUTO GENERATED */ declare function ThirdPartyCredentialAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This is the API to check specific 3rd party platform availability. Passing platform group name or it's member will return same platform availability data Supported third party platform and platform group: - PSN group(psn) - ps4web - ps4 - ps5 */ getAvailability_ByPlatformId_v3: (platformId: string) => Promise>; /** * This is the API to Get All Active 3rd Platform Credential. */ getPlatformsAllClients_v3: () => Promise>; /** * This is the API to Get All Active 3rd Platform Credential. */ getPlatformsAllClientsActive_v3: () => Promise>; /** * This is the API to Delete 3rd Platform Credential. */ deleteClient_ByPlatformId_v3: (platformId: string) => Promise>; /** * This is the API to Get 3rd Platform Credential. */ getClients_ByPlatformId_v3: (platformId: string) => Promise>; /** * This is the API to Add 3rd Platform Credential. - The secret for **apple** is base64 encoded private key. - No secret for **awscognito**, we only need to configure AWS Cognito Region and User Pool - The secret for **discord** is client secret of the twitch client id. - The secret for **epicgames** is client secret of the epicgames client id. - The secret for **facebook** is client secret of the facebook client id. - The secret for **google** is client secret of the google OAuth client. - No secret for **nintendo**, we only need to configure app id of the game - No secret for **netflix**, we configure the Root, Public, Private Key certificate pem file and target environment; value: [sandbox, production] - The secret for **oculus** is app secret of the oculus app. - The secret for **ps4, ps5, and ps4web** is client secret of the psn web server. - The secret for **steam** is the Steam Web API Key. - The secret for **steamopenid** is the Steam Web API Key. - The secret for **twitch** is client secret of the twitch client. - The secret for **live** is the Relying Party Private Key in base64 encode PEM format. - The secret for **xblwebapi** is client secret of the xbl client. If generic oauth flow is set to true: - Current supported value for TokenAuthenticationType is **code, idToken and bearerToken** - <code>TokenClaimsMapping</code> is used to extract user info from idToken claims or user info endpoint response accessed using bearerToken. Its a JSON format with key should be <code>name</code>, <code>email</code> and <code>avatarUrl</code> since IAM will look up for these key when extracting user info.**default claims keys : userIdentity/sub, name, email and avatarUrl/picture** */ patchClient_ByPlatformId_v3: (platformId: string, data: ThirdPartyLoginPlatformCredentialRequest) => Promise>; /** * This is the API to Add 3rd Platform Credential. - The secret for **apple** is base64 encoded private key. - No secret for **awscognito**, we only need to configure AWS Cognito Region and User Pool - The secret for **discord** is client secret of the twitch client id. - The secret for **epicgames** is client secret of the epicgames client id. - The secret for **facebook** is client secret of the facebook client id. - The secret for **google** is client secret of the google OAuth client. - No secret for **nintendo**, we only need to configure app id of the game - No secret for **netflix**, we configure the Root, Public, Private Key certificate pem file and target environment; value: [sandbox, production] - The secret for **oculus** is app secret of the oculus app. - The secret for **ps4, ps5, and ps4web** is client secret of the psn web server. - The secret for **steam** is the Steam Web API Key. - The secret for **steamopenid** is the Steam Web API Key. - The secret for **twitch** is client secret of the twitch client. - The secret for **live** is the Relying Party Private Key in base64 encode PEM format. - The secret for **xblwebapi** is client secret of the xbl client. If generic oauth flow is set to true: - Current supported value for TokenAuthenticationType are **code, idToken and bearerToken** - <code>TokenClaimsMapping</code> is used to extract user info from idToken claims or user info endpoint response accessed using bearerToken. Its a JSON format with key should be <code>name</code>, <code>email</code> and <code>avatarUrl</code> since IAM will look up for these key when extracting user info. **default claims keys : userIdentity/sub, name, email and avatarUrl/picture** */ createClient_ByPlatformId_v3: (platformId: string, data: ThirdPartyLoginPlatformCredentialRequest) => Promise>; /** * This is the API to unregister 3rd Platform domain. If there is a ssoGroups in request body, then this request wil only delete the sso group from the target domain, it will not delete domain. */ deleteClientDomain_ByPlatformId_v3: (platformId: string, data: PlatformDomainDeleteRequest) => Promise>; /** * This is the API to patch update 3rd Platform domain. This API is a create or partial-update behavior. If it is update, it is a partial update behavior. */ patchClientDomain_ByPlatformId_v3: (platformId: string, data: PlatformDomainPatchRequest) => Promise>; /** * This is the API to set 3rd Platform domain. This API is a create-or-update behavior. If it is update, it is a replacement behavior. */ updateClientDomain_ByPlatformId_v3: (platformId: string, data: PlatformDomainUpdateRequest) => Promise>; }; /** * AUTO GENERATED */ declare function UsersAdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Get my user data action code : 10147 */ getUsersMe_v3: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/search [GET]_** */ getUsers_v2: (queryParams: { platformId: string | null; after?: string | null; before?: string | null; displayName?: string | null; limit?: number; loginId?: string | null; platformUserId?: string | null; roleId?: string | null; userId?: string | null; }) => Promise>; /** * This endpoint search user who owns the given email address action code : 10132 */ getUsers_v3: (queryParams?: { emailAddress?: string | null; }) => Promise>; /** * This endpoint support to bulk update users based on given data. ------ Supported fields: * skipLoginQueue */ updateUser_v3: (data: UsersUpdateRequestV3) => Promise>; /** * List all users that has admin role (role that has admin_role attribute set to true). Endpoint behavior : - if query parameter is defined, endpoint will search users whose email address and display name match with the query - if roleId parameter is defined, endpoint will search users that have the defined roleId - if startDate and endDate parameters is defined, endpoint will search users which created on the certain date range - if startDate parameter is defined, endpoint will search users that created start from the defined date - if endDate parameter is defined, endpoint will search users that created until the defined date In multi tenant mode : - if super admin search in super admin namespace, the result will be all admin users - if super admin search in game studio namespace, the result will be all admin users under the game studio namespace - if studio admin search in their studio namespace, the result will be all admin user in the game studio namespace The endpoint will return all admin from all namespace when called from publisher namespace. When not called from publisher namespace, the endpoint will return all admin from the path namespace. */ getAdmins_v3: (queryParams?: { after?: string | null; before?: string | null; endDate?: string | null; limit?: number; query?: string | null; roleId?: string | null; startDate?: string | null; }) => Promise>; /** * This endpoint returns user bans of userIDs specified in the payload action code : 10127 */ fetchUserBan_v3: (data: GetBulkUserBansRequest, queryParams?: { activeOnly?: boolean | null; banType?: string | null; }) => Promise>; /** * List User By User ID This endpoint intended to list user information from the given list of userID and namespace */ createUserBulk_v3: (data: AdminBulkUserRequest) => Promise>; /** * 1. **Cursor-Based User Retrieval** This API fetches user records ordered by created_at ASC, user_id ASC to ensure a stable pagination order. Pagination is handled using a cursor, which consists of created_at and user_id. 2. **GraphQL-Like Querying** By default, the API only returns the user ID. To include additional fields in the response, specify them in the request body under the fields parameter. ***Supported fields***: ['created_at', 'email_address'] ***Note***: If a value is not in the allowed list, the API will ignore it. 3. **Cursor Mechanics** The cursor consists of created_at and user_id from the last retrieved record. The next query fetches records strictly after the provided cursor. ***The query applies the following ordering logic***: Records with a later created_at timestamp are included. If multiple records have the same created_at, only records with a higher user_id are included. This ensures that records with the exact same created_at as the cursor are excluded from the next page to prevent duplication. 4. **Usage** For the first-time query, the request body does not require a cursor. If the data array is empty, it indicates that the cursor has reached the end of the available records. */ fetchUserCursor_v3: (data: CursorGetUserRequest) => Promise>; /** * Use this endpoint to invite admin or non-admin user and assign role to them. The role must be scoped to namespace based on the **{namespace}** value in path parameter. An admin user can only assign role to namespaces that the admin user has the required permission. Role is optional, if not specified then it will only assign User role The invited admin will also assigned with "User" role by default. */ createUserInvite_v3: (data: InviteUserRequestV3) => Promise>; /** * Endpoint behavior : - By default this endpoint searches all users on the specified namespace. - If query parameter is defined, endpoint will search users whose email address, display name, username, or third party partially match with the query. - The query parameter length must be between 3 and 30 characters. For email address queries (i.e., contains '@'), the allowed length is 3 to 40 characters. Otherwise, the database will not be queried. - If startDate and endDate parameters is defined, endpoint will search users which created on the certain date range. - If query, startDate and endDate parameters are defined, endpoint will search users whose email address and display name match and created on the certain date range. - If startDate parameter is defined, endpoint will search users that created start from the defined date. - If endDate parameter is defined, endpoint will search users that created until the defined date. - If platformId parameter is defined and by parameter is using thirdparty, endpoint will search users based on the platformId they have linked to. - If platformBy parameter is defined and by parameter is using thirdparty, endpoint will search users based on the platformUserId or platformDisplayName they have linked to, example value: platformUserId or platformDisplayName. - If limit is not defined, The default limit is 100. GraphQL-Like Querying: - By default, the API only returns the minimum fields -> [displayName, authType, createdAt, uniqueDisplayName, deletionStatus, enabled, emailAddress, skipLoginQueue, testAccount] - To include additional fields in the response, specify them in the request params. - Supported fields: [country, emailVerified, avatarUrl, enabled] - Note: If a value is not in the allowed list, the API will ignore it. In Multi Tenant mode : - If super admin search in super admin namespace, the result will be all game admin user - If super admin search in game studio namespace, the result will be all game admin user and players under the game studio namespace - If super admin search in game namespace, the result will be all game admin users and players under the game namespace - If game admin search in their game studio namespace, the result will be all game admin user in the studio namespace - If game admin search in their game namespace, the result will be all player in the game namespace action code : 10133 */ getUsersSearch_v3: (queryParams?: { by?: string | null; endDate?: string | null; includeTotal?: boolean | null; limit?: number; offset?: number; platformBy?: string | null; platformId?: string | null; query?: string | null; roleIds?: string | null; selectedFields?: string | null; skipLoginQueue?: boolean | null; startDate?: string | null; tagIds?: string | null; testAccount?: boolean | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId} [GET]_** */ getUser_ByUserId_v2: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId} [PATCH]_** This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {Country, DisplayName, LanguageTag} Country use ISO3166-1 alpha-2 two letter, e.g. US. **Several case of updating email address** - User want to update email address of which have been verified, NewEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with verified email before. NewEmailAddress response field will be filled with newest email address. */ patchUser_ByUserId_v2: (userId: string, data: UserUpdateRequest) => Promise>; /** * Admin Get User By User Id */ getUser_ByUserId_v3: (userId: string) => Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName, tags} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. Admin can set Tags with array string data e.g. ["10e9a46ef6164b7e86d08e86605bd8cf"]. Admin also can reset user tags by sending empty array string e.g. [ ]. Users can have at most 5 tags. No duplicate tags allowed. **Response body logic when user updating email address:** - User want to update email address of which have been verified, NewEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with verified email before. NewEmailAddress response field will be filled with newest email address. action code : 10103 */ patchUser_ByUserId_v3: (userId: string, data: UserUpdateRequestV3) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions [GET]_** - **Note:** difference in V3 response, format difference: Pascal case => Camel case */ getAgerestrictions_v2: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions [PATCH]_** */ patchAgerestriction_v2: (data: AgeRestrictionRequest) => Promise>; /** * action code: 10138 */ getAgerestrictions_v3: () => Promise>; /** * action code: 10122 */ patchAgerestriction_v3: (data: AgeRestrictionRequestV3) => Promise>; /** * This endpoint search user by the list of email addresses action code : 10132 */ fetchUserSearchBulk_v3: (data: ListEmailAddressRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [POST]_** */ createBan_ByUserId_v2: (userId: string, data: BanCreateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [GET]_** */ getBans_ByUserId_v2: (userId: string, queryParams?: { activeOnly?: boolean | null; }) => Promise>; /** * This endpoint retrieve the first page of the data if after and before parameters is empty action code : 10126 */ getBans_ByUserId_v3: (userId: string, queryParams?: { activeOnly?: boolean | null; after?: string | null; before?: string | null; limit?: number; }) => Promise>; /** * Bans a user with specific type of ban. Ban types and reason can be queried. action code : 10141 */ createBan_ByUserId_v3: (userId: string, data: BanCreateRequest) => Promise>; /** * if limit is not defined, The default limit is 100 */ getUsersLinkhistories_v3: (queryParams: { platformId: string | null; limit?: number; offset?: number; platformUserId?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles [PATCH]_** */ updateRole_ByUserId_v2: (userId: string, data: string[]) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles [PATCH]_** */ updateRole_ByUserId_ByNS_v2: (userId: string, data: string[]) => Promise>; /** * This endpoint search admin users which have the roleId Notes : this endpoint only accept admin role. Admin Role is role which have admin status and members. Use endpoint [GET] /roles/{roleId}/admin to check the role status action code : 10140 */ getUsers_ByRoleId_v3: (roleId: string, queryParams?: { after?: number; before?: number; limit?: number; }) => Promise>; /** * **[WARNING] This endpoint is only for testing purpose.** This endpoint get active user verification code. There are some scenarios of getting verification codes, all of them will be returned on this endpoint: - After account registration - After reset password request - After headless account upgrade - After update email request This API only accept publisher/studio namespace and userId. Action code: 10146 */ getCodes_ByUserId_v3: (userId: string) => Promise>; /** * Delete User Roles */ deleteRole_ByUserId_v3: (userId: string, data: string[]) => Promise>; /** * User's roles will be replaced with roles from request body. An admin user can only assign role with **namespace** (in request body) if the admin user has required permission which is same as the required permission of endpoint: [AdminAddUserRoleV4]. */ patchRole_ByUserId_v3: (userId: string, data: NamespaceRoleRequest[]) => Promise>; /** * Admin Get User State By User Id */ getState_ByUserId_v3: (userId: string) => Promise>; /** * Notes: - This endpoint bulk get users' basic info by userId, max allowed 100 at a time - If namespace is game, will search by game user Id, other wise will search by publisher namespace */ fetchUserBulkPlatform_v3: (data: UserIDsRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** */ updateEnable_ByUserId_v2: (userId: string) => Promise>; /** * This endpoint disable or enable user account. Set the enable status on the request body to true to enable user account or set to false to disable it. Disable user for **Account Disable** purpose fill the reason with: - **AdminDeactivateAccount** : if your disable account request comes from admin Enable user ignore field 'reason' in the request body. action code : 10143 */ patchStatus_ByUserId_v3: (userId: string, data: UpdateUserStatusRequest) => Promise>; /** * This endpoint force verify user Note: - namespace: only accept publisher/studio namespace - userId: only accept publisher/studio userId action code: 10118 */ updateVerify_ByUserId_v3: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** For **Deletion Account** purpose fill the reason with: - **DeactivateAccount** : if your deletion request comes from user - **AdminDeactivateAccount** : if your deletion request comes from admin */ updateDisable_ByUserId_v2: (userId: string, data: DisableUserRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions/countries/{countryCode} [PATCH]_** */ patchCountry_ByCountryCode_v2: (countryCode: string, data: CountryAgeRestrictionRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/password [PUT]_** */ updatePassword_ByUserId_v2: (userId: string, data: UserPasswordUpdateRequest) => Promise>; /** * Update User Password */ updatePassword_ByUserId_v3: (userId: string, data: UserPasswordUpdateV3Request) => Promise>; /** * **This endpoint requires publisher namespace.** Returns list of users ID and namespace with their Justice platform account, under a namespace. If user doesn't have Justice platform account, the linkedPlatforms will be empty array.' */ getUsersPlatformsJustice_v3: (queryParams?: { limit?: number; offset?: number; }) => Promise>; /** * Gets platform accounts that are already linked with user account. Action code : 10128 **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 ## Justice Platform Account The permission ’ADMIN:NAMESPACE:{namespace}:JUSTICE:USER:{userId}’ [READ] is required in order to read the UserID who linked with the user. */ getPlatforms_ByUserId_v3: (userId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; platformId?: string | null; targetNamespace?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/agerestrictions/countries [GET]_** */ getCountriesAgerestrictions_v2: () => Promise>; /** * action code : 10139 */ getAgerestrictionsCountries_v3: () => Promise>; /** * Will verify account and consume code if validateOnly is set false in request body Redeems a verification code sent to a user to verify the user's contact address is correct Available ContactType : **email** or **phone** */ updateCodeVerify_ByUserId_v3: (userId: string, data: UserVerificationRequest) => Promise>; /** * [WARNING] This endpoint is deleting user data from database directly by skipping GDPR flow */ deleteInformation_ByUserId_v3: (userId: string) => Promise>; /** * Delete User Permission */ deletePermission_ByUserId_v3: (userId: string, data: PermissionDeleteRequest[]) => Promise>; /** * This endpoint will APPEND user's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 1. Minutes: 0-59 * / , - 1. Hours: 0-23 * / , - 1. Day of month: 1-31 * / , - L W 1. Month: 1-12 JAN-DEC * / , - 1. Day of week: 0-6 SUN-SAT * / , - L # 1. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 1. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 1. ,: separate items of a list, e.g. MON,WED,FRI in day of week 1. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 1. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 1. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 1. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ createPermission_ByUserId_v3: (userId: string, data: Permissions) => Promise>; /** * This endpoint will REPLACE user's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByUserId_v3: (userId: string, data: Permissions) => Promise>; /** * Set ban status for a single user for a specific ban. Retrieve user ban and choose the ban ID. Set the form parameter to true/false to enable or disable the ban. action code : 10142' */ patchBan_ByUserId_ByBanId_v3: (userId: string, banId: string, data: BanUpdateRequest) => Promise>; /** * This endpoint get user's bans summary' */ getBansSummary_ByUserId_v3: (userId: string) => Promise>; /** * The verification code is sent to email address. Available contexts for use : - **UserAccountRegistration** a context type used for verifying email address in user account registration. It returns 409 if the email address already verified. **_It is the default context if the Context field is empty_** - **UpdateEmailAddress** a context type used for verify user before updating email address.(Without email address verified checking) - **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the email address is already used by others by returning HTTP Status Code 409. action code: 10116 */ updateCodeRequest_ByUserId_v3: (userId: string, data: SendVerificationCodeRequestV3) => Promise>; /** * Admin List User ID By Platform User ID This endpoint intended to list game user ID from the given namespace This endpoint return list of user ID by given platform ID and list of platform user ID Supported platform: - steam - steamopenid - ps4web - ps4 - ps5 - live - xblweb - oculus - oculusweb - facebook - google - googleplaygames - twitch - discord - android - ios - apple - device - justice - epicgames - nintendo - awscognito - netflix - snapchat - oidc platform id Note: **nintendo platform user ID**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ fetchUser_ByPlatformId_v3: (platformId: string, data: PlatformUserIdRequest, queryParams?: { rawPID?: boolean | null; rawPUID?: boolean | null; }) => Promise>; /** * Force linking platform account to user User Account. This endpoint intended for admin to forcefully link account to user. By default, these cases are not allowed - The platform account current is linked by another account - The target account ever linked this platform's another account */ updatePlatformLink_ByUserId_v3: (userId: string, data: LinkPlatformAccountRequest, queryParams?: { skipConflict?: boolean | null; }) => Promise>; /** * This endpoint removes role from user action code: 10110 */ deleteRole_ByUserId_ByRoleId_v3: (userId: string, roleId: string) => Promise>; /** * action code: 10109 */ updateRole_ByUserId_ByRoleId_v3: (userId: string, roleId: string) => Promise>; /** * action code : 10145 */ getDeletionStatus_ByUserId_v3: (userId: string) => Promise>; /** * action code : 10144 */ patchDeletionStatus_ByUserId_v3: (userId: string, data: UpdateUserDeletionStatusRequest) => Promise>; /** * Notes for this endpoint: This endpoint retrieve the first page of the data if <code>after</code> and <code>before</code> parameters is empty. - The maximum value of the limit is 100 and the minimum value of the limit is 1. - This endpoint retrieve the next page of the data if we provide <code>after</code> parameters with valid Unix timestamp. - This endpoint retrieve the previous page of the data if we provide <code>before</code> parameter with valid data Unix timestamp." */ getLoginsHistories_ByUserId_v3: (userId: string, queryParams?: { after?: number; before?: number; limit?: number; }) => Promise>; /** * This endpoint ONLY accept **Client Token** This endpoint is utilized for specific scenarios where **email notifications are disabled** The user's email will be marked as verified Note: - emailAddress or password field are optional - request body can't be empty action code : 10103 */ patchTrustlyIdentity_ByUserId_v3: (userId: string, data: UserIdentityUpdateRequestV3) => Promise>; /** * This endpoint retrieves platform accounts linked to user. It will query all linked platform accounts and result will be distinct & grouped, same platform we will pick oldest linked one. */ getDistinctPlatforms_ByUserId_v3: (userId: string) => Promise>; /** * This endpoint gets list justice platform account by providing publisher namespace and publisher userID */ getPlatformsJustice_ByUserId_v3: (userId: string) => Promise>; /** * This endpoint only retrieves 3rd party platform accounts linked to user. It will query platform accounts and result will be distinct & grouped, same platform we will pick oldest linked one. ------ Supported status: - LINKED - RESTRICTIVELY_UNLINKED - UNLINKED - ALL */ getPlatformsDistinct_ByUserId_v3: (userId: string, queryParams?: { status?: string | null; }) => Promise>; /** * If validateOnly is set false, will upgrade headless account with verification code The endpoint upgrades a headless account by linking the headless account with the email address and the password. By upgrading the headless account into a full account, the user could use the email address and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the send verification code endpoint. This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. Supported user data fields : - displayName - dateOfBirth : format YYYY-MM-DD, e.g. 2019-04-29 - country : format ISO3166-1 alpha-2 two letter, e.g. US action code : 10124 */ updateHeadlesCodeVerify_ByUserId_v3: (userId: string, data: UpgradeHeadlessAccountWithVerificationCodeRequestV3) => Promise>; /** * @deprecated * ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **googleplaygames** - **oculus** - **twitch** - **android** - **ios** - **apple** - **device** - **discord** - **awscognito** - **epicgames** - **nintendo** - **snapchat** Unlink user's account from a specific platform. 'justice' platform might have multiple accounts from different namespaces linked. _platformNamespace_ need to be specified when the platform ID is 'justice'. Unlink user's account from justice platform will enable password token grant and password update. If you want to unlink user's account in a game namespace, you have to specify _platformNamespace_ to that game namespace. action code : 10121 */ deletePlatform_ByUserId_ByPlatformId_v3: (userId: string, platformId: string, data: UnlinkUserPlatformRequest) => Promise>; /** * action code: 10123 */ patchAgerestrictionCountry_ByCountryCode_v3: (countryCode: string, data: CountryAgeRestrictionV3Request) => Promise>; /** * This API is for admin to get user's link history. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getPlatformsLinkHistories_ByUserId_v3: (userId: string, queryParams: { platformId: string | null; }) => Promise>; /** * Unlink user's account from third platform in all namespaces. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: to unlink steam third party account, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 Unlink platform account associated with a group: If user unlink platform account associated with a group, the API logic will unlink all of platform account under that group as well. example: if user unlink from ps4, the API logic will unlink ps5 and ps4web as well */ deleteAll_ByUserId_ByPlatformId_v3: (userId: string, platformId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms/{platformId} [DELETE]_** ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **oculus** - **twitch** - **android** - **ios** - **device** - **discord** Delete link of user's account with platform. 'justice' platform might have multiple accounts from different namespaces linked. platform_namespace need to be specified when the platform ID is 'justice'. Delete link of justice platform will enable password token grant and password update. */ deleteLink_ByUserId_ByPlatformId_v2: (userId: string, platformId: string, data: { platform_namespace?: string | null; }) => Promise>; /** * **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **googleplaygames**: The ticket’s value is the authorization code returned by Google play games OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **apple**: The ticket’s value is the authorization code returned by Apple OAuth. - **device**: Every device that does’nt run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. - **awscognito**: The ticket’s value is the aws cognito access token (JWT). - **epicgames**: The ticket’s value is an access-token obtained from Epicgames EOS Account Service. - **nintendo**: The ticket’s value is the authorization code(id_token) returned by Nintendo OAuth. */ postLink_ByUserId_ByPlatformId_v3: (userId: string, platformId: string, data: { ticket: string | null; }) => Promise>; /** * Get User By Platform User ID This endpoint return user information by given platform ID and platform user ID. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: for steam network platform, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 - **oculus**: if query by app user id, please set the query param **pidType** to **OCULUS_APP_USER_ID** (support game namespace only) */ getUser_ByPlatformId_ByPlatformUserId_v3: (platformId: string, platformUserId: string, queryParams?: { pidType?: string | null; }) => Promise>; /** * Delete User Permission */ deletePermission_ByUserId_ByResource_ByAction_v3: (userId: string, resource: string, action: number) => Promise>; /** * This endpoint gets user single platform account metadata. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getMetadata_ByUserId_ByPlatformId_v3: (userId: string, platformId: string, queryParams?: { crossNamespace?: boolean | null; }) => Promise>; /** * Admin get the link status of the third party platform token with user id. This endpoint is used for checking whether the third party user represented by third party token is linked with the corresponding user id. ## Supported platforms: - **steam**: The platform_token’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the authorization code(id_token) returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. */ postLinkStatu_ByUserId_ByPlatformId_v3: (userId: string, platformId: string, data: { platformToken: string | null; }) => Promise>; /** * This endpoint will support publisher access to game and game access to publisher If targetNamespace filled with publisher namespace then this endpoint will return its publisher user id and publisher namespace. If targetNamespace filled with game namespace then this endpoint will return its game user id and game namespace. */ getPlatformJustice_ByUserId_ByTargetNamespace_v3: (userId: string, targetNamespace: string) => Promise>; /** * Create Justice User from Publisher User information. It will check first if Justice User on target namespace already exist. */ createPlatformJustice_ByUserId_ByTargetNamespace_v3: (userId: string, targetNamespace: string) => Promise>; /** * @deprecated * This API is for admin to delete user's linking history with target platform id. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 ---- **Substitute endpoint**: /v3/admin/namespaces/{namespace}/users/{userId}/platforms/{platformId}/link/restrictions */ deleteLinkHistory_ByUserId_ByPlatformId_v3: (userId: string, platformId: string) => Promise>; /** * This API is for admin to delete user's linking restriction with target platform id. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ deleteLinkRestriction_ByUserId_ByPlatformId_v3: (userId: string, platformId: string) => Promise>; }; /** * AUTO GENERATED */ declare function UsersV4AdminApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. action code : 10103 */ patchUserMe_v4: (data: UserUpdateRequestV3) => Promise>; /** * Use this endpoint to invite admin or non-admin user and assign role to them. The role must be scoped to namespace. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of endpoint: [AdminAddUserRoleV4]. Detail request body : - **emailAddresses** is required, List of email addresses that will be invited - **isAdmin** is required, true if user is admin, false if user is not admin - **namespace** is optional. Only works on multi tenant mode, if not specified then it will be assigned Publisher namespace, if specified, it will become that studio/publisher where user is invited to. - **roleId** is optional, if not specified then it will only assign User role. - **assignedNamespaces** is optional, List of namespaces which the Role will be assigned to the user, only works when Role is not empty. The invited admin will also assigned with "User" role by default. */ createUserInvite_v4: (data: InviteUserRequestV4) => Promise>; /** * @deprecated * Use this endpoint to invite admin or non-admin user and assign role to them. The role must be scoped to namespace. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of endpoint: [AdminAddUserRoleV4]. Detail request body : - Email Address is required, List of email addresses that will be invited - isAdmin is required, true if user is admin, false if user is not admin - Namespace is optional. Only works on multi tenant mode, if not specified then it will be assigned Publisher namespace, if specified, it will become that studio/publisher where user is invited to. - Role is optional, if not specified then it will only assign User role. - Assigned Namespaces is optional, List of namespaces which the Role will be assigned to the user, only works when Role is not empty. The invited admin will also assigned with "User" role by default. Substitute endpoint: /iam/v4/admin/users/invite */ createUserUserInvite_v4: (data: InviteUserRequestV4) => Promise>; /** * This endpoint is to list all Invitation Histories for new studio namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. Accepted Query: - namespace - offset - limit */ getInvitationHistories_v4: (queryParams?: { limit?: number; namespace?: string | null; offset?: number; }) => Promise>; /** * This endpoint is used to get user enabled factors. */ getUsersMeMfaFactor_v4: () => Promise>; /** * This endpoint is used to make 2FA factor default. */ postUserMeMfaFactor_v4: (data: { factor: string | null; }) => Promise>; /** * This endpoint will get user's' MFA status. */ getUsersMeMfaStatus_v4: () => Promise>; /** * @deprecated * This endpoint will get user's' MFA status. ------------ **Substitute endpoint**: /iam/v4/admin/users/me/mfa/status [GET] */ createUserMeMfaStatus_v4: () => Promise>; /** * @deprecated * This endpoint is used to get 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ getUsersMeMfaBackupCode_v4: () => Promise>; /** * @deprecated * This endpoint is used to generate 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ createUserMeMfaBackupCode_v4: () => Promise>; /** * This endpoint is used to send email code. -------------- Supported actions: * ChangePassword * DisableMFAEmail */ postUserMeMfaEmailCode_v4: (data: { action?: string | null; languageTag?: string | null; }) => Promise>; /** * This endpoint is used to get 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ getUsersMeMfaBackupCodes_v4: (queryParams?: { languageTag?: string | null; }) => Promise>; /** * This endpoint is used to generate 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ createUserMeMfaBackupCode_admin_v4: (queryParams?: { languageTag?: string | null; }) => Promise>; /** * This endpoint is used to enable 2FA email. */ postUserMeMfaEmailEnable_v4: (data: { code: string | null; }) => Promise>; /** * This endpoint is used to disable 2FA email. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ createUserMeMfaEmailDisable_v4: (data: DisableMfaRequest) => Promise>; /** * Create a new user with unique email address and username. **Required attributes:** - authType: possible value is EMAILPASSWD - emailAddress: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. - uniqueDisplayName: required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true, please refer to the rule from /v3/public/inputValidations API. **Not required attributes:** - displayName: Please refer to the rule from /v3/public/inputValidations API. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createUser_v4: (data: CreateUserRequestV4) => Promise>; /** * This endpoint will verify user's' MFA code and generate a MFA token. */ postUserMeMfaChallengeVerify_v4: (data: { code?: string | null; factor?: string | null; }) => Promise>; /** * This endpoint is used to generate a secret key for 3rd-party authenticator app. A QR code URI is also returned so that frontend can generate QR code image. */ createUserMeMfaAuthenticatorKey_v4: () => Promise>; /** * @deprecated * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_v4: () => Promise>; /** * This endpoint is used to disable 2FA backup codes. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaBackupCodeDisable_v4: (data: DisableMfaRequest) => Promise>; /** * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_admin_v4: (queryParams?: { languageTag?: string | null; }) => Promise>; /** * @deprecated * This endpoint is used to download backup codes. */ getUsersMeMfaBackupCodeDownload_v4: () => Promise>; /** * Create test users and not send verification code email. Note: - count : Enter the number of test users you want to create in the count field. The maximum value of the user count is 100. - userInfo(optional) : - country: you can specify country for the test user. Country use ISO3166-1 alpha-2 two letter, e.g. US */ createTestUser_v4: (data: CreateTestUsersRequestV4) => Promise>; /** * This endpoint is used to enable 2FA authenticator. ---------- Prerequisites: - Generate the secret key/QR code uri by **_/iam/v4/admin/users/me/mfa/authenticator/key_** - Consume the secret key/QR code by an authenticator app - Get the code from the authenticator app */ postUserMeMfaAuthenticatorEnable_v4: (data: { code: string | null; }) => Promise>; /** * This endpoint is used to disable 2FA authenticator. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaAuthenticatorDisable_v4: (data: DisableMfaRequest) => Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. action code : 10103 */ updateUser_ByUserId_v4: (userId: string, data: UserUpdateRequestV3) => Promise>; /** * This endpoint is to Invitation Historiy for specific new studio namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. */ getInvitationHistories_ByNS_v4: () => Promise>; /** * Use this endpoint to check if userID exists or not Maximum number of userID to be checked is 50 */ fetchUserBulkValidate_v4: (data: CheckValidUserIdRequestV4) => Promise>; /** * This is the endpoint for an admin to update a user email address. This endpoint need a valid user token from an admin to verify its identity (email) before updating a user. */ updateEmail_ByUserId_v4: (userId: string, data: EmailUpdateRequestV4) => Promise>; /** * Remove a role from user's roles. */ deleteRole_ByUserId_v4: (userId: string, data: RemoveUserRoleV4Request) => Promise>; /** * List roles assigned to a user */ getRoles_ByUserId_v4: (userId: string) => Promise>; /** * New role will be appended to user's current roles. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of this endpoint. */ updateRole_ByUserId_v4: (userId: string, data: AddUserRoleV4Request) => Promise>; /** * User's roles will be replaced with roles from request body. An admin user can only assign role with **assignedNamespaces** if the admin user has required permission which is same as the required permission of this endpoint. */ updateRole_ByUserId_ByNS_v4: (userId: string, data: AddUserRoleV4Request) => Promise>; /** * This endpoint is used to change users account type - set **testAccount** to <code>true</code> to mark user as test account type - set **testAccount** to <code>false</code> to mark user as default account type */ patchUserBulkAccountType_v4: (data: BulkAccountTypeUpdateRequestV4) => Promise>; /** * This endpoint is to Get list of users Invitation History for specific new studio namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. Accepted Query: - offset - limit */ getInvitationHistoriesUsers_v4: (queryParams?: { limit?: number; offset?: number; }) => Promise>; /** * **This endpoint is used to get user's 2FA status.** */ getMfaStatus_ByUserId_v4: (userId: string) => Promise>; /** * This endpoint is used to disable user 2FA. ----------- **Note**: if the factor is not specified, will disable all 2FA methods. */ deleteMfaDisable_ByUserId_v4: (userId: string, data: DisableMfaRequest) => Promise>; }; declare const AcceptedPoliciesRequest: z.ZodObject<{ isAccepted: z.ZodBoolean; localizedPolicyVersionId: z.ZodString; policyId: z.ZodString; policyVersionId: z.ZodString; }, "strip", z.ZodTypeAny, { isAccepted: boolean; localizedPolicyVersionId: string; policyId: string; policyVersionId: string; }, { isAccepted: boolean; localizedPolicyVersionId: string; policyId: string; policyVersionId: string; }>; interface AcceptedPoliciesRequest extends z.TypeOf { } declare const AccountProgressionInfo: z.ZodObject<{ displayName: z.ZodOptional>; email: z.ZodOptional>; linkedGames: z.ZodArray; platformId: z.ZodOptional>; progressions: z.ZodOptional>>; lastLoginTime: z.ZodOptional>; namespace: z.ZodString; userBan: z.ZodOptional>>; wallets: z.ZodOptional, "many">>>; }, "strip", z.ZodTypeAny, { namespace: string; createdAt: number; lastLoginTime?: number | null | undefined; dlcs?: { totalCount: number; } | null | undefined; userBan?: { ban: string; endDate: number; } | null | undefined; wallets?: { balance: number; currencyCode: string; currencySymbol: string; }[] | null | undefined; }, { namespace: string; createdAt: number; lastLoginTime?: number | null | undefined; dlcs?: { totalCount: number; } | null | undefined; userBan?: { ban: string; endDate: number; } | null | undefined; wallets?: { balance: number; currencyCode: string; currencySymbol: string; }[] | null | undefined; }>, "many">>>; uniqueDisplayName: z.ZodOptional>; userName: z.ZodOptional>; }, "strip", z.ZodTypeAny, { linkedGames: string[]; displayName?: string | null | undefined; email?: string | null | undefined; platformId?: string | null | undefined; uniqueDisplayName?: string | null | undefined; userName?: string | null | undefined; progressions?: { namespace: string; createdAt: number; lastLoginTime?: number | null | undefined; dlcs?: { totalCount: number; } | null | undefined; userBan?: { ban: string; endDate: number; } | null | undefined; wallets?: { balance: number; currencyCode: string; currencySymbol: string; }[] | null | undefined; }[] | null | undefined; }, { linkedGames: string[]; displayName?: string | null | undefined; email?: string | null | undefined; platformId?: string | null | undefined; uniqueDisplayName?: string | null | undefined; userName?: string | null | undefined; progressions?: { namespace: string; createdAt: number; lastLoginTime?: number | null | undefined; dlcs?: { totalCount: number; } | null | undefined; userBan?: { ban: string; endDate: number; } | null | undefined; wallets?: { balance: number; currencyCode: string; currencySymbol: string; }[] | null | undefined; }[] | null | undefined; }>; interface AccountProgressionInfo extends z.TypeOf { } declare const AllowedPermission: z.ZodObject<{ allowedActions: z.ZodArray; resource: z.ZodString; }, "strip", z.ZodTypeAny, { resource: string; allowedActions: number[]; }, { resource: string; allowedActions: number[]; }>; interface AllowedPermission extends z.TypeOf { } declare const AvatarConfig: z.ZodObject<{ allowedPrefixes: z.ZodArray; preferRegex: z.ZodBoolean; regex: z.ZodString; }, "strip", z.ZodTypeAny, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }>; interface AvatarConfig extends z.TypeOf { } declare const Ban: z.ZodObject<{ Ban: z.ZodString; Description: z.ZodString; }, "strip", z.ZodTypeAny, { Ban: string; Description: string; }, { Ban: string; Description: string; }>; interface Ban extends z.TypeOf { } declare const BannedBy: z.ZodObject<{ DisplayName: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { userId: string; DisplayName: string; }, { userId: string; DisplayName: string; }>; interface BannedBy extends z.TypeOf { } declare const BannedByV3: z.ZodObject<{ displayName: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { userId: string; displayName: string; }, { userId: string; displayName: string; }>; interface BannedByV3 extends z.TypeOf { } declare const BanReason: z.ZodObject<{ Description: z.ZodString; Reason: z.ZodString; }, "strip", z.ZodTypeAny, { Reason: string; Description: string; }, { Reason: string; Description: string; }>; interface BanReason extends z.TypeOf { } declare const BanReasonV3: z.ZodObject<{ description: z.ZodString; reason: z.ZodString; }, "strip", z.ZodTypeAny, { description: string; reason: string; }, { description: string; reason: string; }>; interface BanReasonV3 extends z.TypeOf { } declare const BanV3: z.ZodObject<{ ban: z.ZodString; description: z.ZodOptional>; descriptions: z.ZodOptional>>; type: z.ZodString; }, "strip", z.ZodTypeAny, { type: string; ban: string; description?: string | null | undefined; descriptions?: { 'en-US': string; 'zh-CN': string; } | null | undefined; }, { type: string; ban: string; description?: string | null | undefined; descriptions?: { 'en-US': string; 'zh-CN': string; } | null | undefined; }>; interface BanV3 extends z.TypeOf { } declare const ClientModulePermission: z.ZodObject<{ moduleId: z.ZodString; selectedGroups: z.ZodArray; }, "strip", z.ZodTypeAny, { groupId: string; selectedActions: number[]; }, { groupId: string; selectedActions: number[]; }>, "many">; }, "strip", z.ZodTypeAny, { moduleId: string; selectedGroups: { groupId: string; selectedActions: number[]; }[]; }, { moduleId: string; selectedGroups: { groupId: string; selectedActions: number[]; }[]; }>; interface ClientModulePermission extends z.TypeOf { } declare const ClientPermission: z.ZodObject<{ Action: z.ZodNumber; Resource: z.ZodString; }, "strip", z.ZodTypeAny, { Action: number; Resource: string; }, { Action: number; Resource: string; }>; interface ClientPermission extends z.TypeOf { } declare const ClientPermissionSet: z.ZodObject<{ docLink: z.ZodString; groups: z.ZodArray; resource: z.ZodString; }, "strip", z.ZodTypeAny, { resource: string; allowedActions: number[]; }, { resource: string; allowedActions: number[]; }>, "many">; }, "strip", z.ZodTypeAny, { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }, { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }>, "many">; module: z.ZodString; moduleId: z.ZodString; }, "strip", z.ZodTypeAny, { moduleId: string; docLink: string; groups: { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }[]; module: string; }, { moduleId: string; docLink: string; groups: { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }[]; module: string; }>; interface ClientPermissionSet extends z.TypeOf { } declare const ClientPermissionV3: z.ZodObject<{ action: z.ZodNumber; resource: z.ZodString; }, "strip", z.ZodTypeAny, { action: number; resource: string; }, { action: number; resource: string; }>; interface ClientPermissionV3 extends z.TypeOf { } declare const ClientSelectedGroup: z.ZodObject<{ groupId: z.ZodString; selectedActions: z.ZodArray; }, "strip", z.ZodTypeAny, { groupId: string; selectedActions: number[]; }, { groupId: string; selectedActions: number[]; }>; interface ClientSelectedGroup extends z.TypeOf { } declare const ClientTemplate: z.ZodObject<{ basicRequiredPermissions: z.ZodArray; }, "strip", z.ZodTypeAny, { groupId: string; selectedActions: number[]; }, { groupId: string; selectedActions: number[]; }>, "many">; }, "strip", z.ZodTypeAny, { moduleId: string; selectedGroups: { groupId: string; selectedActions: number[]; }[]; }, { moduleId: string; selectedGroups: { groupId: string; selectedActions: number[]; }[]; }>, "many">; defaultValues: z.ZodArray, "many">; description: z.ZodString; id: z.ZodString; requiredFields: z.ZodArray; type: z.ZodString; }, "strip", z.ZodTypeAny, { type: string; id: string; description: string; basicRequiredPermissions: { moduleId: string; selectedGroups: { groupId: string; selectedActions: number[]; }[]; }[]; defaultValues: { field: string; value?: any; }[]; requiredFields: string[]; }, { type: string; id: string; description: string; basicRequiredPermissions: { moduleId: string; selectedGroups: { groupId: string; selectedActions: number[]; }[]; }[]; defaultValues: { field: string; value?: any; }[]; requiredFields: string[]; }>; interface ClientTemplate extends z.TypeOf { } declare const ConflictedUserPlatformAccounts: z.ZodObject<{ platformUserID: z.ZodString; publisherAccounts: z.ZodArray>; platformUserId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }>, "many">; namespace: z.ZodString; uniqueDisplayName: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }>, "many">; }, "strip", z.ZodTypeAny, { platformUserID: string; publisherAccounts: { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }[]; }, { platformUserID: string; publisherAccounts: { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }[]; }>; interface ConflictedUserPlatformAccounts extends z.TypeOf { } declare const CountryAgeRestriction: z.ZodObject<{ AgeRestriction: z.ZodNumber; CountryCode: z.ZodString; CountryName: z.ZodString; Enable: z.ZodBoolean; }, "strip", z.ZodTypeAny, { AgeRestriction: number; Enable: boolean; CountryCode: string; CountryName: string; }, { AgeRestriction: number; Enable: boolean; CountryCode: string; CountryName: string; }>; interface CountryAgeRestriction extends z.TypeOf { } declare const CountryResponse: z.ZodObject<{ code: z.ZodString; name: z.ZodString; }, "strip", z.ZodTypeAny, { code: string; name: string; }, { code: string; name: string; }>; interface CountryResponse extends z.TypeOf { } declare const CreateTestUserResponseV4: z.ZodObject<{ authType: z.ZodString; country: z.ZodString; dateOfBirth: z.ZodString; displayName: z.ZodString; emailAddress: z.ZodString; namespace: z.ZodString; password: z.ZodString; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; username: z.ZodString; verified: z.ZodBoolean; }, "strip", z.ZodTypeAny, { namespace: string; password: string; userId: string; displayName: string; country: string; username: string; authType: string; dateOfBirth: string; emailAddress: string; verified: boolean; uniqueDisplayName?: string | null | undefined; }, { namespace: string; password: string; userId: string; displayName: string; country: string; username: string; authType: string; dateOfBirth: string; emailAddress: string; verified: boolean; uniqueDisplayName?: string | null | undefined; }>; interface CreateTestUserResponseV4 extends z.TypeOf { } declare const CursorGetUserResponseData: z.ZodAny; interface CursorGetUserResponseData extends z.TypeOf { } declare const DefaultFieldValue: z.ZodObject<{ field: z.ZodString; value: z.ZodAny; }, "strip", z.ZodTypeAny, { field: string; value?: any; }, { field: string; value?: any; }>; interface DefaultFieldValue extends z.TypeOf { } declare const DefaultFieldValueValue: z.ZodAny; interface DefaultFieldValueValue extends z.TypeOf { } declare const Description: z.ZodObject<{ 'en-US': z.ZodString; 'zh-CN': z.ZodString; }, "strip", z.ZodTypeAny, { 'en-US': string; 'zh-CN': string; }, { 'en-US': string; 'zh-CN': string; }>; interface Description extends z.TypeOf { } declare const DeviceResponseV4: z.ZodObject<{ ban: z.ZodOptional>>; deviceId: z.ZodString; deviceType: z.ZodString; ext: z.ZodOptional>>; ip: z.ZodString; lastLoginTime: z.ZodNumber; }, "strip", z.ZodTypeAny, { deviceId: string; deviceType: string; ip: string; lastLoginTime: number; ban?: { namespace: string; deviceId: string; enabled: boolean; endDate: number; id: string; reason: string; comment: string; bannedBy: string; deviceType: string; bannedAt: number; disabledAt: number; targetNamespace: string; } | null | undefined; ext?: Record | null | undefined; }, { deviceId: string; deviceType: string; ip: string; lastLoginTime: number; ban?: { namespace: string; deviceId: string; enabled: boolean; endDate: number; id: string; reason: string; comment: string; bannedBy: string; deviceType: string; bannedAt: number; disabledAt: number; targetNamespace: string; } | null | undefined; ext?: Record | null | undefined; }>; interface DeviceResponseV4 extends z.TypeOf { } declare const DeviceTypeResponseV4: z.ZodObject<{ deviceType: z.ZodString; }, "strip", z.ZodTypeAny, { deviceType: string; }, { deviceType: string; }>; interface DeviceTypeResponseV4 extends z.TypeOf { } declare const DeviceUserResponseV4: z.ZodObject<{ ext: z.ZodOptional>>; ip: z.ZodString; lastLoginTime: z.ZodNumber; namespace: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; ip: string; lastLoginTime: number; ext?: Record | null | undefined; }, { namespace: string; userId: string; ip: string; lastLoginTime: number; ext?: Record | null | undefined; }>; interface DeviceUserResponseV4 extends z.TypeOf { } declare const DistinctLinkedPlatformV3: z.ZodObject<{ details: z.ZodOptional>; linkedAt: z.ZodString; namespace: z.ZodString; originNamespace: z.ZodString; platformId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { namespace: string; linkedAt: string; originNamespace: string; displayName?: string | null | undefined; platformId?: string | null | undefined; }, { namespace: string; linkedAt: string; originNamespace: string; displayName?: string | null | undefined; platformId?: string | null | undefined; }>, "many">>>; linkedAt: z.ZodString; logoURL: z.ZodOptional>; platformDisplayName: z.ZodOptional>; platformGroup: z.ZodString; platformName: z.ZodString; platformUserId: z.ZodOptional>; status: z.ZodString; }, "strip", z.ZodTypeAny, { status: string; linkedAt: string; platformGroup: string; platformName: string; platformUserId?: string | null | undefined; details?: { namespace: string; linkedAt: string; originNamespace: string; displayName?: string | null | undefined; platformId?: string | null | undefined; }[] | null | undefined; logoURL?: string | null | undefined; platformDisplayName?: string | null | undefined; }, { status: string; linkedAt: string; platformGroup: string; platformName: string; platformUserId?: string | null | undefined; details?: { namespace: string; linkedAt: string; originNamespace: string; displayName?: string | null | undefined; platformId?: string | null | undefined; }[] | null | undefined; logoURL?: string | null | undefined; platformDisplayName?: string | null | undefined; }>; interface DistinctLinkedPlatformV3 extends z.TypeOf { } declare const DlcAggResponse: z.ZodObject<{ totalCount: z.ZodNumber; }, "strip", z.ZodTypeAny, { totalCount: number; }, { totalCount: number; }>; interface DlcAggResponse extends z.TypeOf { } declare const ErrorResponse: z.ZodObject<{ errorCode: z.ZodNumber; errorMessage: z.ZodString; messageVariables: z.ZodOptional>>; requiredPermission: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { errorCode: number; errorMessage: string; messageVariables?: Record | null | undefined; requiredPermission?: { action: number; resource: string; } | null | undefined; }, { errorCode: number; errorMessage: string; messageVariables?: Record | null | undefined; requiredPermission?: { action: number; resource: string; } | null | undefined; }>; interface ErrorResponse extends z.TypeOf { } declare const ErrorResponseWithConflictedUserPlatformAccounts: z.ZodObject<{ errorCode: z.ZodNumber; errorMessage: z.ZodString; messageVariables: z.ZodOptional>; platformUserId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }>, "many">; namespace: z.ZodString; uniqueDisplayName: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }>, "many">; }, "strip", z.ZodTypeAny, { platformUserID: string; publisherAccounts: { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }[]; }, { platformUserID: string; publisherAccounts: { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }[]; }>>>; previousLinkedPlatformAccount: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { errorCode: number; errorMessage: string; messageVariables?: { platformUserID: string; publisherAccounts: { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }[]; } | null | undefined; previousLinkedPlatformAccount?: { platformDisplayName: string; platformUserID: string; platformID: string; } | null | undefined; }, { errorCode: number; errorMessage: string; messageVariables?: { platformUserID: string; publisherAccounts: { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }[]; } | null | undefined; previousLinkedPlatformAccount?: { platformDisplayName: string; platformUserID: string; platformID: string; } | null | undefined; }>; interface ErrorResponseWithConflictedUserPlatformAccounts extends z.TypeOf { } declare const FailedBanUnbanUserV3: z.ZodObject<{ reason: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { reason: string; userId: string; }, { reason: string; userId: string; }>; interface FailedBanUnbanUserV3 extends z.TypeOf { } declare const FieldUpdateAllowStatus: z.ZodObject<{ field: z.ZodString; nextAvailableEditTime: z.ZodOptional>; remainingTimeInSeconds: z.ZodOptional>; type: z.ZodString; }, "strip", z.ZodTypeAny, { type: string; field: string; nextAvailableEditTime?: number | null | undefined; remainingTimeInSeconds?: number | null | undefined; }, { type: string; field: string; nextAvailableEditTime?: number | null | undefined; remainingTimeInSeconds?: number | null | undefined; }>; interface FieldUpdateAllowStatus extends z.TypeOf { } declare const FilterJson: z.ZodObject<{ bits: z.ZodArray; k: z.ZodNumber; m: z.ZodNumber; }, "strip", z.ZodTypeAny, { bits: number[]; k: number; m: number; }, { bits: number[]; k: number; m: number; }>; interface FilterJson extends z.TypeOf { } declare const GroupAndRoleMappingForPatch: z.ZodObject<{ assignNamespaces: z.ZodOptional>>; group: z.ZodString; roleId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { group: string; roleId?: string | null | undefined; assignNamespaces?: string[] | null | undefined; }, { group: string; roleId?: string | null | undefined; assignNamespaces?: string[] | null | undefined; }>; interface GroupAndRoleMappingForPatch extends z.TypeOf { } declare const GroupAndRoleMappingForUpdate: z.ZodObject<{ assignNamespaces: z.ZodOptional>>; group: z.ZodString; roleId: z.ZodString; }, "strip", z.ZodTypeAny, { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }, { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }>; interface GroupAndRoleMappingForUpdate extends z.TypeOf { } declare const InputValidationData: z.ZodObject<{ field: z.ZodString; validation: z.ZodObject<{ allowAllSpecialCharacters: z.ZodBoolean; allowDigit: z.ZodBoolean; allowLetter: z.ZodBoolean; allowSpace: z.ZodBoolean; allowUnicode: z.ZodBoolean; avatarConfig: z.ZodOptional; preferRegex: z.ZodBoolean; regex: z.ZodString; }, "strip", z.ZodTypeAny, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }>>>; blockedWord: z.ZodArray; description: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>, "many">; isCustomRegex: z.ZodBoolean; letterCase: z.ZodString; maxLength: z.ZodNumber; maxRepeatingAlphaNum: z.ZodNumber; maxRepeatingSpecialCharacter: z.ZodNumber; minCharType: z.ZodNumber; minLength: z.ZodNumber; profanityFilter: z.ZodOptional>; regex: z.ZodString; specialCharacterLocation: z.ZodString; specialCharacters: z.ZodArray; }, "strip", z.ZodTypeAny, { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }, { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }>; }, "strip", z.ZodTypeAny, { validation: { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }; field: string; }, { validation: { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }; field: string; }>; interface InputValidationData extends z.TypeOf { } declare const InputValidationDataPublic: z.ZodObject<{ field: z.ZodString; validation: z.ZodObject<{ allowAllSpecialCharacters: z.ZodBoolean; allowDigit: z.ZodBoolean; allowLetter: z.ZodBoolean; allowSpace: z.ZodBoolean; allowUnicode: z.ZodBoolean; avatarConfig: z.ZodOptional; preferRegex: z.ZodBoolean; regex: z.ZodString; }, "strip", z.ZodTypeAny, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }>>>; blockedWord: z.ZodArray; description: z.ZodObject<{ language: z.ZodString; message: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>; isCustomRegex: z.ZodBoolean; letterCase: z.ZodString; maxLength: z.ZodNumber; maxRepeatingAlphaNum: z.ZodNumber; maxRepeatingSpecialCharacter: z.ZodNumber; minCharType: z.ZodNumber; minLength: z.ZodNumber; profanityFilter: z.ZodOptional>; regex: z.ZodString; specialCharacterLocation: z.ZodString; specialCharacters: z.ZodArray; }, "strip", z.ZodTypeAny, { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }, { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }>; }, "strip", z.ZodTypeAny, { validation: { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }; field: string; }, { validation: { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }; field: string; }>; interface InputValidationDataPublic extends z.TypeOf { } declare const InputValidationDescription: z.ZodObject<{ language: z.ZodString; message: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>; interface InputValidationDescription extends z.TypeOf { } declare const JwkKey: z.ZodObject<{ alg: z.ZodOptional>; e: z.ZodOptional>; kid: z.ZodOptional>; kty: z.ZodString; n: z.ZodOptional>; use: z.ZodOptional>; }, "strip", z.ZodTypeAny, { kty: string; alg?: string | null | undefined; e?: string | null | undefined; kid?: string | null | undefined; n?: string | null | undefined; use?: string | null | undefined; }, { kty: string; alg?: string | null | undefined; e?: string | null | undefined; kid?: string | null | undefined; n?: string | null | undefined; use?: string | null | undefined; }>; interface JwkKey extends z.TypeOf { } declare const JwtBanV3: z.ZodObject<{ ban: z.ZodString; disabledDate: z.ZodOptional>; enabled: z.ZodBoolean; endDate: z.ZodString; targetedNamespace: z.ZodString; }, "strip", z.ZodTypeAny, { ban: string; enabled: boolean; endDate: string; targetedNamespace: string; disabledDate?: string | null | undefined; }, { ban: string; enabled: boolean; endDate: string; targetedNamespace: string; disabledDate?: string | null | undefined; }>; interface JwtBanV3 extends z.TypeOf { } declare const LoginQueueTicketResponse: z.ZodObject<{ cancel: z.ZodObject<{ action: z.ZodString; href: z.ZodString; }, "strip", z.ZodTypeAny, { action: string; href: string; }, { action: string; href: string; }>; estimatedWaitingTimeInSeconds: z.ZodNumber; playerPollingTimeInSeconds: z.ZodNumber; position: z.ZodNumber; reconnectExpiredAt: z.ZodNumber; refresh: z.ZodObject<{ action: z.ZodString; href: z.ZodString; }, "strip", z.ZodTypeAny, { action: string; href: string; }, { action: string; href: string; }>; ticket: z.ZodString; }, "strip", z.ZodTypeAny, { cancel: { action: string; href: string; }; estimatedWaitingTimeInSeconds: number; playerPollingTimeInSeconds: number; position: number; reconnectExpiredAt: number; refresh: { action: string; href: string; }; ticket: string; }, { cancel: { action: string; href: string; }; estimatedWaitingTimeInSeconds: number; playerPollingTimeInSeconds: number; position: number; reconnectExpiredAt: number; refresh: { action: string; href: string; }; ticket: string; }>; interface LoginQueueTicketResponse extends z.TypeOf { } declare const NamespaceRole: z.ZodObject<{ namespace: z.ZodString; roleId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; roleId: string; }, { namespace: string; roleId: string; }>; interface NamespaceRole extends z.TypeOf { } declare const NetflixCertificates: z.ZodObject<{ encryptedPrivateKey: z.ZodString; encryptedPrivateKeyName: z.ZodString; publicCertificate: z.ZodString; publicCertificateName: z.ZodString; rootCertificate: z.ZodString; rootCertificateName: z.ZodString; }, "strip", z.ZodTypeAny, { encryptedPrivateKey: string; encryptedPrivateKeyName: string; publicCertificate: string; publicCertificateName: string; rootCertificate: string; rootCertificateName: string; }, { encryptedPrivateKey: string; encryptedPrivateKeyName: string; publicCertificate: string; publicCertificateName: string; rootCertificate: string; rootCertificateName: string; }>; interface NetflixCertificates extends z.TypeOf { } declare const OverrideRolePermission: z.ZodObject<{ actions: z.ZodArray; resource: z.ZodString; }, "strip", z.ZodTypeAny, { resource: string; actions: number[]; }, { resource: string; actions: number[]; }>; interface OverrideRolePermission extends z.TypeOf { } declare const Pagination: z.ZodObject<{ First: z.ZodString; Last: z.ZodString; Next: z.ZodString; Previous: z.ZodString; }, "strip", z.ZodTypeAny, { First: string; Last: string; Next: string; Previous: string; }, { First: string; Last: string; Next: string; Previous: string; }>; interface Pagination extends z.TypeOf { } declare const PaginationV3: z.ZodObject<{ first: z.ZodString; last: z.ZodString; next: z.ZodString; previous: z.ZodString; }, "strip", z.ZodTypeAny, { first: string; last: string; next: string; previous: string; }, { first: string; last: string; next: string; previous: string; }>; interface PaginationV3 extends z.TypeOf { } declare const Permission: z.ZodObject<{ action: z.ZodNumber; resource: z.ZodString; }, "strip", z.ZodTypeAny, { action: number; resource: string; }, { action: number; resource: string; }>; interface Permission extends z.TypeOf { } declare const PermissionGroup: z.ZodObject<{ group: z.ZodString; groupId: z.ZodString; permissions: z.ZodArray; resource: z.ZodString; }, "strip", z.ZodTypeAny, { resource: string; allowedActions: number[]; }, { resource: string; allowedActions: number[]; }>, "many">; }, "strip", z.ZodTypeAny, { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }, { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }>; interface PermissionGroup extends z.TypeOf { } declare const PermissionSetUpsertRequest: z.ZodObject<{ docLink: z.ZodString; groups: z.ZodArray; resource: z.ZodString; }, "strip", z.ZodTypeAny, { resource: string; allowedActions: number[]; }, { resource: string; allowedActions: number[]; }>, "many">; }, "strip", z.ZodTypeAny, { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }, { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }>, "many">; module: z.ZodString; moduleId: z.ZodString; }, "strip", z.ZodTypeAny, { moduleId: string; docLink: string; groups: { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }[]; module: string; }, { moduleId: string; docLink: string; groups: { permissions: { resource: string; allowedActions: number[]; }[]; groupId: string; group: string; }[]; module: string; }>; interface PermissionSetUpsertRequest extends z.TypeOf { } declare const PermissionV3: z.ZodObject<{ action: z.ZodNumber; resource: z.ZodString; schedAction: z.ZodOptional>; schedCron: z.ZodOptional>; schedRange: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }>; interface PermissionV3 extends z.TypeOf { } declare const PlatformAccount: z.ZodObject<{ namespace: z.ZodString; platformId: z.ZodOptional>; platformUserId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }>; interface PlatformAccount extends z.TypeOf { } declare const PlatformLinkingHistory: z.ZodObject<{ platformDisplayName: z.ZodString; platformID: z.ZodString; platformUserID: z.ZodString; }, "strip", z.ZodTypeAny, { platformDisplayName: string; platformUserID: string; platformID: string; }, { platformDisplayName: string; platformUserID: string; platformID: string; }>; interface PlatformLinkingHistory extends z.TypeOf { } declare const PlatformUserInformation: z.ZodObject<{ DisplayName: z.ZodString; EmailAddress: z.ZodOptional>; LinkedAt: z.ZodString; Namespace: z.ZodString; PlatformID: z.ZodString; PlatformUserID: z.ZodString; XUID: z.ZodOptional>; }, "strip", z.ZodTypeAny, { Namespace: string; DisplayName: string; LinkedAt: string; PlatformID: string; PlatformUserID: string; EmailAddress?: string | null | undefined; XUID?: string | null | undefined; }, { Namespace: string; DisplayName: string; LinkedAt: string; PlatformID: string; PlatformUserID: string; EmailAddress?: string | null | undefined; XUID?: string | null | undefined; }>; interface PlatformUserInformation extends z.TypeOf { } declare const PlatformUserInformationV3: z.ZodObject<{ displayName: z.ZodOptional>; emailAddress: z.ZodOptional>; linkedAt: z.ZodString; namespace: z.ZodString; platformId: z.ZodString; platformUserId: z.ZodString; xboxUserId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { namespace: string; platformUserId: string; platformId: string; linkedAt: string; displayName?: string | null | undefined; emailAddress?: string | null | undefined; xboxUserId?: string | null | undefined; }, { namespace: string; platformUserId: string; platformId: string; linkedAt: string; displayName?: string | null | undefined; emailAddress?: string | null | undefined; xboxUserId?: string | null | undefined; }>; interface PlatformUserInformationV3 extends z.TypeOf { } declare const ProfileUpdateConfig: z.ZodObject<{ minimumAllowedInterval: z.ZodOptional>; }, "strip", z.ZodTypeAny, { minimumAllowedInterval?: number | null | undefined; }, { minimumAllowedInterval?: number | null | undefined; }>; interface ProfileUpdateConfig extends z.TypeOf { } declare const ProgressionInfo: z.ZodObject<{ createdAt: z.ZodNumber; dlcs: z.ZodOptional>>; lastLoginTime: z.ZodOptional>; namespace: z.ZodString; userBan: z.ZodOptional>>; wallets: z.ZodOptional, "many">>>; }, "strip", z.ZodTypeAny, { namespace: string; createdAt: number; lastLoginTime?: number | null | undefined; dlcs?: { totalCount: number; } | null | undefined; userBan?: { ban: string; endDate: number; } | null | undefined; wallets?: { balance: number; currencyCode: string; currencySymbol: string; }[] | null | undefined; }, { namespace: string; createdAt: number; lastLoginTime?: number | null | undefined; dlcs?: { totalCount: number; } | null | undefined; userBan?: { ban: string; endDate: number; } | null | undefined; wallets?: { balance: number; currencyCode: string; currencySymbol: string; }[] | null | undefined; }>; interface ProgressionInfo extends z.TypeOf { } declare const PublicThirdPartyPlatformInfo: z.ZodObject<{ AppId: z.ZodString; ClientId: z.ZodString; Environment: z.ZodString; IsActive: z.ZodBoolean; LogoURL: z.ZodOptional>; PlatformId: z.ZodString; PlatformName: z.ZodString; TokenAuthenticationType: z.ZodString; }, "strip", z.ZodTypeAny, { AppId: string; ClientId: string; Environment: string; IsActive: boolean; PlatformName: string; TokenAuthenticationType: string; PlatformId: string; LogoURL?: string | null | undefined; }, { AppId: string; ClientId: string; Environment: string; IsActive: boolean; PlatformName: string; TokenAuthenticationType: string; PlatformId: string; LogoURL?: string | null | undefined; }>; interface PublicThirdPartyPlatformInfo extends z.TypeOf { } declare const PublicUserInformationV3: z.ZodObject<{ createdAt: z.ZodString; displayName: z.ZodString; namespace: z.ZodString; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; userName: z.ZodString; userPlatformInfos: z.ZodOptional>; platformDisplayName: z.ZodOptional>; platformGroup: z.ZodOptional>; platformId: z.ZodString; platformUserId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }>, "many">>>; }, "strip", z.ZodTypeAny, { namespace: string; createdAt: string; userId: string; displayName: string; userName: string; uniqueDisplayName?: string | null | undefined; userPlatformInfos?: { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }[] | null | undefined; }, { namespace: string; createdAt: string; userId: string; displayName: string; userName: string; uniqueDisplayName?: string | null | undefined; userPlatformInfos?: { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }[] | null | undefined; }>; interface PublicUserInformationV3 extends z.TypeOf { } declare const QueryCursor: z.ZodObject<{ cursorTime: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { userId: string; cursorTime: string; }, { userId: string; cursorTime: string; }>; interface QueryCursor extends z.TypeOf { } declare const RegisteredDomain: z.ZodObject<{ affectedClientIDs: z.ZodArray; domain: z.ZodString; namespaces: z.ZodArray; roleId: z.ZodString; ssoCfg: z.ZodOptional; groupConfigs: z.ZodArray>>; group: z.ZodString; roleId: z.ZodString; }, "strip", z.ZodTypeAny, { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }, { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }>, "many">; }, "strip", z.ZodTypeAny, { googleKey: Record; groupConfigs: { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }[]; }, { googleKey: Record; groupConfigs: { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }[]; }>>>; }, "strip", z.ZodTypeAny, { roleId: string; domain: string; affectedClientIDs: string[]; namespaces: string[]; ssoCfg?: { googleKey: Record; groupConfigs: { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }[]; } | null | undefined; }, { roleId: string; domain: string; affectedClientIDs: string[]; namespaces: string[]; ssoCfg?: { googleKey: Record; groupConfigs: { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }[]; } | null | undefined; }>; interface RegisteredDomain extends z.TypeOf { } declare const ReplaceRolePermission: z.ZodObject<{ replacement: z.ZodObject<{ actions: z.ZodArray; resource: z.ZodString; }, "strip", z.ZodTypeAny, { resource: string; actions: number[]; }, { resource: string; actions: number[]; }>; target: z.ZodString; }, "strip", z.ZodTypeAny, { replacement: { resource: string; actions: number[]; }; target: string; }, { replacement: { resource: string; actions: number[]; }; target: string; }>; interface ReplaceRolePermission extends z.TypeOf { } declare const RoleManager: z.ZodObject<{ DisplayName: z.ZodString; Namespace: z.ZodString; UserId: z.ZodString; }, "strip", z.ZodTypeAny, { Namespace: string; UserId: string; DisplayName: string; }, { Namespace: string; UserId: string; DisplayName: string; }>; interface RoleManager extends z.TypeOf { } declare const RoleManagerV3: z.ZodObject<{ displayName: z.ZodString; namespace: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; displayName: string; }, { namespace: string; userId: string; displayName: string; }>; interface RoleManagerV3 extends z.TypeOf { } declare const RoleMember: z.ZodObject<{ DisplayName: z.ZodString; Namespace: z.ZodString; UserId: z.ZodString; }, "strip", z.ZodTypeAny, { Namespace: string; UserId: string; DisplayName: string; }, { Namespace: string; UserId: string; DisplayName: string; }>; interface RoleMember extends z.TypeOf { } declare const RoleMemberV3: z.ZodObject<{ displayName: z.ZodString; namespace: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; displayName: string; }, { namespace: string; userId: string; displayName: string; }>; interface RoleMemberV3 extends z.TypeOf { } declare const RoleResponseWithManagers: z.ZodObject<{ IsWildcard: z.ZodBoolean; Managers: z.ZodArray, "many">; Permissions: z.ZodArray, "many">; RoleId: z.ZodString; RoleName: z.ZodString; }, "strip", z.ZodTypeAny, { Permissions: { action: number; resource: string; }[]; IsWildcard: boolean; Managers: { Namespace: string; UserId: string; DisplayName: string; }[]; RoleId: string; RoleName: string; }, { Permissions: { action: number; resource: string; }[]; IsWildcard: boolean; Managers: { Namespace: string; UserId: string; DisplayName: string; }[]; RoleId: string; RoleName: string; }>; interface RoleResponseWithManagers extends z.TypeOf { } declare const RoleResponseWithManagersV3: z.ZodObject<{ adminRole: z.ZodBoolean; isWildcard: z.ZodBoolean; managers: z.ZodArray, "many">; permissions: z.ZodArray>; schedCron: z.ZodOptional>; schedRange: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }>, "many">; roleId: z.ZodString; roleName: z.ZodString; }, "strip", z.ZodTypeAny, { roleId: string; permissions: { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }[]; adminRole: boolean; isWildcard: boolean; roleName: string; managers: { namespace: string; userId: string; displayName: string; }[]; }, { roleId: string; permissions: { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }[]; adminRole: boolean; isWildcard: boolean; roleName: string; managers: { namespace: string; userId: string; displayName: string; }[]; }>; interface RoleResponseWithManagersV3 extends z.TypeOf { } declare const SimpleUserBan: z.ZodObject<{ ban: z.ZodString; endDate: z.ZodNumber; }, "strip", z.ZodTypeAny, { ban: string; endDate: number; }, { ban: string; endDate: number; }>; interface SimpleUserBan extends z.TypeOf { } declare const SimpleUserPlatformInfoV3: z.ZodObject<{ displayName: z.ZodOptional>; linkedAt: z.ZodString; namespace: z.ZodString; originNamespace: z.ZodString; platformId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { namespace: string; linkedAt: string; originNamespace: string; displayName?: string | null | undefined; platformId?: string | null | undefined; }, { namespace: string; linkedAt: string; originNamespace: string; displayName?: string | null | undefined; platformId?: string | null | undefined; }>; interface SimpleUserPlatformInfoV3 extends z.TypeOf { } declare const SsoConfig: z.ZodObject<{ googleKey: z.ZodRecord; groupConfigs: z.ZodArray>>; group: z.ZodString; roleId: z.ZodString; }, "strip", z.ZodTypeAny, { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }, { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }>, "many">; }, "strip", z.ZodTypeAny, { googleKey: Record; groupConfigs: { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }[]; }, { googleKey: Record; groupConfigs: { roleId: string; group: string; assignNamespaces?: string[] | null | undefined; }[]; }>; interface SsoConfig extends z.TypeOf { } declare const SsoConfigPatchReq: z.ZodObject<{ googleKey: z.ZodOptional>>; groupConfigs: z.ZodOptional>>; group: z.ZodString; roleId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { group: string; roleId?: string | null | undefined; assignNamespaces?: string[] | null | undefined; }, { group: string; roleId?: string | null | undefined; assignNamespaces?: string[] | null | undefined; }>, "many">>>; }, "strip", z.ZodTypeAny, { googleKey?: Record | null | undefined; groupConfigs?: { group: string; roleId?: string | null | undefined; assignNamespaces?: string[] | null | undefined; }[] | null | undefined; }, { googleKey?: Record | null | undefined; groupConfigs?: { group: string; roleId?: string | null | undefined; assignNamespaces?: string[] | null | undefined; }[] | null | undefined; }>; interface SsoConfigPatchReq extends z.TypeOf { } declare const TagDetail: z.ZodObject<{ id: z.ZodString; tagName: z.ZodOptional>; }, "strip", z.ZodTypeAny, { id: string; tagName?: string | null | undefined; }, { id: string; tagName?: string | null | undefined; }>; interface TagDetail extends z.TypeOf { } declare const TicketEndpointAction: z.ZodObject<{ action: z.ZodString; href: z.ZodString; }, "strip", z.ZodTypeAny, { action: string; href: string; }, { action: string; href: string; }>; interface TicketEndpointAction extends z.TypeOf { } declare const UserActiveBanResponse: z.ZodObject<{ Ban: z.ZodString; BanId: z.ZodString; EndDate: z.ZodString; }, "strip", z.ZodTypeAny, { Ban: string; BanId: string; EndDate: string; }, { Ban: string; BanId: string; EndDate: string; }>; interface UserActiveBanResponse extends z.TypeOf { } declare const UserActiveBanResponseV3: z.ZodObject<{ ban: z.ZodString; banId: z.ZodString; endDate: z.ZodString; targetedNamespace: z.ZodString; }, "strip", z.ZodTypeAny, { ban: string; endDate: string; targetedNamespace: string; banId: string; }, { ban: string; endDate: string; targetedNamespace: string; banId: string; }>; interface UserActiveBanResponseV3 extends z.TypeOf { } declare const UserActiveBanResponseV4: z.ZodObject<{ ban: z.ZodString; banId: z.ZodString; endDate: z.ZodString; }, "strip", z.ZodTypeAny, { ban: string; endDate: string; banId: string; }, { ban: string; endDate: string; banId: string; }>; interface UserActiveBanResponseV4 extends z.TypeOf { } declare const UserBan: z.ZodObject<{ comment: z.ZodString; endDate: z.ZodNumber; reason: z.ZodString; }, "strip", z.ZodTypeAny, { endDate: number; reason: string; comment: string; }, { endDate: number; reason: string; comment: string; }>; interface UserBan extends z.TypeOf { } declare const UserBanWithStatus: z.ZodObject<{ active: z.ZodBoolean; ban: z.ZodString; banId: z.ZodString; bannedBy: z.ZodObject<{ displayName: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { userId: string; displayName: string; }, { userId: string; displayName: string; }>; comment: z.ZodString; createdAt: z.ZodString; disabledDate: z.ZodString; enabled: z.ZodBoolean; endDate: z.ZodString; namespace: z.ZodString; reason: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; ban: string; disabledDate: string; enabled: boolean; endDate: string; createdAt: string; reason: string; comment: string; banId: string; userId: string; bannedBy: { userId: string; displayName: string; }; active: boolean; }, { namespace: string; ban: string; disabledDate: string; enabled: boolean; endDate: string; createdAt: string; reason: string; comment: string; banId: string; userId: string; bannedBy: { userId: string; displayName: string; }; active: boolean; }>; interface UserBanWithStatus extends z.TypeOf { } declare const UserBaseInfo: z.ZodObject<{ avatarUrl: z.ZodString; displayName: z.ZodString; platformUserIds: z.ZodRecord; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; username: z.ZodOptional>; }, "strip", z.ZodTypeAny, { userId: string; displayName: string; avatarUrl: string; platformUserIds: Record; username?: string | null | undefined; uniqueDisplayName?: string | null | undefined; }, { userId: string; displayName: string; avatarUrl: string; platformUserIds: Record; username?: string | null | undefined; uniqueDisplayName?: string | null | undefined; }>; interface UserBaseInfo extends z.TypeOf { } declare const UserBulkUpdateRequestV3: z.ZodObject<{ skipLoginQueue: z.ZodBoolean; }, "strip", z.ZodTypeAny, { skipLoginQueue: boolean; }, { skipLoginQueue: boolean; }>; interface UserBulkUpdateRequestV3 extends z.TypeOf { } declare const UserInfo: z.ZodObject<{ country: z.ZodOptional>; }, "strip", z.ZodTypeAny, { country?: string | null | undefined; }, { country?: string | null | undefined; }>; interface UserInfo extends z.TypeOf { } declare const UserInfoResponse: z.ZodObject<{ displayName: z.ZodString; emailAddress: z.ZodString; namespace: z.ZodString; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName?: string | null | undefined; }, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName?: string | null | undefined; }>; interface UserInfoResponse extends z.TypeOf { } declare const UserInvitationHistory: z.ZodObject<{ accepted: z.ZodBoolean; invitee: z.ZodString; updatedAt: z.ZodString; }, "strip", z.ZodTypeAny, { updatedAt: string; accepted: boolean; invitee: string; }, { updatedAt: string; accepted: boolean; invitee: string; }>; interface UserInvitationHistory extends z.TypeOf { } declare const UserLinkedPlatform: z.ZodObject<{ DisplayName: z.ZodOptional>; EmailAddress: z.ZodOptional>; LinkedAt: z.ZodString; Namespace: z.ZodString; OriginNamespace: z.ZodString; PlatformId: z.ZodOptional>; PlatformUserId: z.ZodOptional>; UserId: z.ZodString; XUID: z.ZodOptional>; }, "strip", z.ZodTypeAny, { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }, { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }>; interface UserLinkedPlatform extends z.TypeOf { } declare const UserLinkedPlatformV3: z.ZodObject<{ accountGroup: z.ZodString; displayName: z.ZodOptional>; emailAddress: z.ZodOptional>; linkedAt: z.ZodString; namespace: z.ZodString; originNamespace: z.ZodString; platformId: z.ZodOptional>; platformUserId: z.ZodOptional>; userId: z.ZodString; xuid: z.ZodOptional>; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; linkedAt: string; originNamespace: string; accountGroup: string; xuid?: string | null | undefined; displayName?: string | null | undefined; platformUserId?: string | null | undefined; platformId?: string | null | undefined; emailAddress?: string | null | undefined; }, { namespace: string; userId: string; linkedAt: string; originNamespace: string; accountGroup: string; xuid?: string | null | undefined; displayName?: string | null | undefined; platformUserId?: string | null | undefined; platformId?: string | null | undefined; emailAddress?: string | null | undefined; }>; interface UserLinkedPlatformV3 extends z.TypeOf { } declare const UserLoginHistoryResponse: z.ZodObject<{ ApplicationName: z.ZodString; City: z.ZodString; Country: z.ZodString; DeviceId: z.ZodString; State: z.ZodString; Timestamp: z.ZodNumber; deviceName: z.ZodString; }, "strip", z.ZodTypeAny, { ApplicationName: string; City: string; Country: string; DeviceId: string; State: string; Timestamp: number; deviceName: string; }, { ApplicationName: string; City: string; Country: string; DeviceId: string; State: string; Timestamp: number; deviceName: string; }>; interface UserLoginHistoryResponse extends z.TypeOf { } declare const UserPermissionsResponseV3: z.ZodObject<{ action: z.ZodNumber; resource: z.ZodString; schedAction: z.ZodOptional>; schedCron: z.ZodOptional>; schedRange: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }>; interface UserPermissionsResponseV3 extends z.TypeOf { } declare const UserPermissionsResponseV4: z.ZodObject<{ action: z.ZodNumber; resource: z.ZodString; schedAction: z.ZodOptional>; schedCron: z.ZodOptional>; schedRange: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }>; interface UserPermissionsResponseV4 extends z.TypeOf { } declare const UserPlatformInfo: z.ZodObject<{ platformAvatarUrl: z.ZodOptional>; platformDisplayName: z.ZodOptional>; platformGroup: z.ZodOptional>; platformId: z.ZodString; platformUserId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }>; interface UserPlatformInfo extends z.TypeOf { } declare const UserPlatformInfos: z.ZodObject<{ avatarUrl: z.ZodOptional>; displayName: z.ZodOptional>; platformInfos: z.ZodArray>; platformDisplayName: z.ZodOptional>; platformGroup: z.ZodOptional>; platformId: z.ZodString; platformUserId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }>, "many">; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; }, "strip", z.ZodTypeAny, { userId: string; platformInfos: { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }[]; displayName?: string | null | undefined; avatarUrl?: string | null | undefined; uniqueDisplayName?: string | null | undefined; }, { userId: string; platformInfos: { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }[]; displayName?: string | null | undefined; avatarUrl?: string | null | undefined; uniqueDisplayName?: string | null | undefined; }>; interface UserPlatformInfos extends z.TypeOf { } declare const UserPlatformLinkHistory: z.ZodObject<{ action: z.ZodString; actor: z.ZodString; actorType: z.ZodString; createdAt: z.ZodNumber; namespace: z.ZodString; platform: z.ZodString; platformDisplayName: z.ZodString; platformId: z.ZodString; platformUserId: z.ZodString; publisherUserId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; action: string; createdAt: number; platformUserId: string; platformId: string; platformDisplayName: string; actor: string; actorType: string; platform: string; publisherUserId: string; }, { namespace: string; action: string; createdAt: number; platformUserId: string; platformId: string; platformDisplayName: string; actor: string; actorType: string; platform: string; publisherUserId: string; }>; interface UserPlatformLinkHistory extends z.TypeOf { } declare const UserRevocationListRecord: z.ZodObject<{ id: z.ZodString; revoked_at: z.ZodString; }, "strip", z.ZodTypeAny, { id: string; revoked_at: string; }, { id: string; revoked_at: string; }>; interface UserRevocationListRecord extends z.TypeOf { } declare const UserRolesV4Response: z.ZodObject<{ assignedNamespaces: z.ZodArray; roleId: z.ZodString; roleName: z.ZodString; }, "strip", z.ZodTypeAny, { roleId: string; assignedNamespaces: string[]; roleName: string; }, { roleId: string; assignedNamespaces: string[]; roleName: string; }>; interface UserRolesV4Response extends z.TypeOf { } declare const UserSearchByPlatformIdResult: z.ZodObject<{ DisplayName: z.ZodString; EmailAddress: z.ZodString; LinkedPlatforms: z.ZodArray>; EmailAddress: z.ZodOptional>; LinkedAt: z.ZodString; Namespace: z.ZodString; OriginNamespace: z.ZodString; PlatformId: z.ZodOptional>; PlatformUserId: z.ZodOptional>; UserId: z.ZodString; XUID: z.ZodOptional>; }, "strip", z.ZodTypeAny, { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }, { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }>, "many">; PhoneNumber: z.ZodString; UserId: z.ZodString; }, "strip", z.ZodTypeAny, { UserId: string; DisplayName: string; EmailAddress: string; LinkedPlatforms: { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }[]; PhoneNumber: string; }, { UserId: string; DisplayName: string; EmailAddress: string; LinkedPlatforms: { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }[]; PhoneNumber: string; }>; interface UserSearchByPlatformIdResult extends z.TypeOf { } declare const UserSearchResult: z.ZodObject<{ DisplayName: z.ZodString; EmailAddress: z.ZodString; LinkedPlatforms: z.ZodArray>; EmailAddress: z.ZodOptional>; LinkedAt: z.ZodString; Namespace: z.ZodString; OriginNamespace: z.ZodString; PlatformId: z.ZodOptional>; PlatformUserId: z.ZodOptional>; UserId: z.ZodString; XUID: z.ZodOptional>; }, "strip", z.ZodTypeAny, { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }, { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }>, "many">; PhoneNumber: z.ZodString; UserId: z.ZodString; }, "strip", z.ZodTypeAny, { UserId: string; DisplayName: string; EmailAddress: string; LinkedPlatforms: { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }[]; PhoneNumber: string; }, { UserId: string; DisplayName: string; EmailAddress: string; LinkedPlatforms: { Namespace: string; UserId: string; LinkedAt: string; OriginNamespace: string; PlatformId?: string | null | undefined; DisplayName?: string | null | undefined; EmailAddress?: string | null | undefined; PlatformUserId?: string | null | undefined; XUID?: string | null | undefined; }[]; PhoneNumber: string; }>; interface UserSearchResult extends z.TypeOf { } declare const UserUnbanCreateRequestV3: z.ZodObject<{ banId: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { banId: string; userId: string; }, { banId: string; userId: string; }>; interface UserUnbanCreateRequestV3 extends z.TypeOf { } declare const UserWithLinkedPlatformAccounts: z.ZodObject<{ displayName: z.ZodString; emailAddress: z.ZodString; linkedPlatforms: z.ZodArray>; platformUserId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }>, "many">; namespace: z.ZodString; uniqueDisplayName: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }, { namespace: string; userId: string; displayName: string; emailAddress: string; uniqueDisplayName: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }>; interface UserWithLinkedPlatformAccounts extends z.TypeOf { } declare const UserWithPlatformAccounts: z.ZodObject<{ linkedPlatforms: z.ZodArray>; platformUserId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }, { namespace: string; platformUserId: string; platformId?: string | null | undefined; }>, "many">; namespace: z.ZodString; userId: z.ZodString; }, "strip", z.ZodTypeAny, { namespace: string; userId: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }, { namespace: string; userId: string; linkedPlatforms: { namespace: string; platformUserId: string; platformId?: string | null | undefined; }[]; }>; interface UserWithPlatformAccounts extends z.TypeOf { } declare const UserWithPlatformInfo: z.ZodObject<{ avatarUrl: z.ZodOptional>; displayName: z.ZodOptional>; platformInfos: z.ZodArray>; platformDisplayName: z.ZodOptional>; platformGroup: z.ZodOptional>; platformId: z.ZodString; platformUserId: z.ZodOptional>; }, "strip", z.ZodTypeAny, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }, { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }>, "many">; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; username: z.ZodOptional>; xuid: z.ZodOptional>; }, "strip", z.ZodTypeAny, { userId: string; platformInfos: { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }[]; xuid?: string | null | undefined; displayName?: string | null | undefined; username?: string | null | undefined; avatarUrl?: string | null | undefined; uniqueDisplayName?: string | null | undefined; }, { userId: string; platformInfos: { platformId: string; platformUserId?: string | null | undefined; platformDisplayName?: string | null | undefined; platformGroup?: string | null | undefined; platformAvatarUrl?: string | null | undefined; }[]; xuid?: string | null | undefined; displayName?: string | null | undefined; username?: string | null | undefined; avatarUrl?: string | null | undefined; uniqueDisplayName?: string | null | undefined; }>; interface UserWithPlatformInfo extends z.TypeOf { } declare const Validation: z.ZodObject<{ allowAllSpecialCharacters: z.ZodBoolean; allowDigit: z.ZodBoolean; allowLetter: z.ZodBoolean; allowSpace: z.ZodBoolean; allowUnicode: z.ZodBoolean; avatarConfig: z.ZodOptional; preferRegex: z.ZodBoolean; regex: z.ZodString; }, "strip", z.ZodTypeAny, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }>>>; blockedWord: z.ZodArray; description: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>, "many">; isCustomRegex: z.ZodBoolean; letterCase: z.ZodString; maxLength: z.ZodNumber; maxRepeatingAlphaNum: z.ZodNumber; maxRepeatingSpecialCharacter: z.ZodNumber; minCharType: z.ZodNumber; minLength: z.ZodNumber; profanityFilter: z.ZodString; regex: z.ZodString; specialCharacterLocation: z.ZodString; specialCharacters: z.ZodArray; }, "strip", z.ZodTypeAny, { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; profanityFilter: string; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; }, { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; profanityFilter: string; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; }>; interface Validation extends z.TypeOf { } declare const ValidationDescription: z.ZodObject<{ language: z.ZodString; message: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>; interface ValidationDescription extends z.TypeOf { } declare const ValidationDetail: z.ZodObject<{ allowAllSpecialCharacters: z.ZodBoolean; allowDigit: z.ZodBoolean; allowLetter: z.ZodBoolean; allowSpace: z.ZodBoolean; allowUnicode: z.ZodBoolean; avatarConfig: z.ZodOptional; preferRegex: z.ZodBoolean; regex: z.ZodString; }, "strip", z.ZodTypeAny, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }>>>; blockedWord: z.ZodArray; description: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>, "many">; isCustomRegex: z.ZodBoolean; letterCase: z.ZodString; maxLength: z.ZodNumber; maxRepeatingAlphaNum: z.ZodNumber; maxRepeatingSpecialCharacter: z.ZodNumber; minCharType: z.ZodNumber; minLength: z.ZodNumber; profanityFilter: z.ZodOptional>; regex: z.ZodString; specialCharacterLocation: z.ZodString; specialCharacters: z.ZodArray; }, "strip", z.ZodTypeAny, { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }, { description: { message: string[]; language: string; }[]; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }>; interface ValidationDetail extends z.TypeOf { } declare const ValidationDetailPublic: z.ZodObject<{ allowAllSpecialCharacters: z.ZodBoolean; allowDigit: z.ZodBoolean; allowLetter: z.ZodBoolean; allowSpace: z.ZodBoolean; allowUnicode: z.ZodBoolean; avatarConfig: z.ZodOptional; preferRegex: z.ZodBoolean; regex: z.ZodString; }, "strip", z.ZodTypeAny, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }, { allowedPrefixes: string[]; preferRegex: boolean; regex: string; }>>>; blockedWord: z.ZodArray; description: z.ZodObject<{ language: z.ZodString; message: z.ZodArray; }, "strip", z.ZodTypeAny, { message: string[]; language: string; }, { message: string[]; language: string; }>; isCustomRegex: z.ZodBoolean; letterCase: z.ZodString; maxLength: z.ZodNumber; maxRepeatingAlphaNum: z.ZodNumber; maxRepeatingSpecialCharacter: z.ZodNumber; minCharType: z.ZodNumber; minLength: z.ZodNumber; profanityFilter: z.ZodOptional>; regex: z.ZodString; specialCharacterLocation: z.ZodString; specialCharacters: z.ZodArray; }, "strip", z.ZodTypeAny, { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }, { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; }>; interface ValidationDetailPublic extends z.TypeOf { } declare const ValidUserIdResponseV4: z.ZodObject<{ exists: z.ZodBoolean; userId: z.ZodString; }, "strip", z.ZodTypeAny, { userId: string; exists: boolean; }, { userId: string; exists: boolean; }>; interface ValidUserIdResponseV4 extends z.TypeOf { } declare const WalletAggResponse: z.ZodObject<{ balance: z.ZodNumber; currencyCode: z.ZodString; currencySymbol: z.ZodString; }, "strip", z.ZodTypeAny, { balance: number; currencyCode: string; currencySymbol: string; }, { balance: number; currencyCode: string; currencySymbol: string; }>; interface WalletAggResponse extends z.TypeOf { } /** * AUTO GENERATED */ declare function BansApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/bans [GET]_** */ getBans: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/bans/reasons [GET]_** */ getBansReasons: () => Promise>; }; /** * AUTO GENERATED */ declare function ClientsApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients [GET]_** */ getClients: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients [POST]_** */ createClient: (data: ClientCreateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [DELETE]_** */ deleteClient_ByClientId: (clientId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [GET]_** */ getClient_ByClientId: (clientId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [PATCH]_** */ updateClient_ByClientId: (clientId: string, data: ClientUpdateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/{clientId}/secret [PUT]_** */ updateSecret_ByClientId: (clientId: string, data: ClientUpdateSecretRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients [GET]_** */ getClients_ByNS: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/v3/admin/namespaces/{namespace}/clients [POST]_** */ createClient_ByNS: (data: ClientCreateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _iam/v3/admin/namespaces/{namespace}/clients/{clientId}/permissions [PUT]_** */ updateClientpermission_ByClientId: (clientId: string, data: ClientPermissions) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [DELETE]_** */ deleteClient_ByClientId_ByNS: (clientId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId}/permissions/{resource}/{action} [DELETE]_** */ deleteClientpermission_ByClientId_ByResource_ByAction: (clientId: string, resource: string, action: number) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId}/permissions [POST]_** */ updateClientpermission_ByClientId_ByResource_ByAction: (clientId: string, resource: string, action: number) => Promise>; }; /** * AUTO GENERATED */ declare function ConfigApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { getConfigPublic_v3: () => Promise>; /** * This endpoint return the value of config key. The namespace should be publisher namespace or studio namespace. Note: this endpoint does not need any authorization. **Supported config key:** * uniqueDisplayNameEnabled * usernameDisabled * mandatoryEmailVerificationEnabled * verificationCodeType If the key is verificationCodeType, then possible value format will be '{collection}:{N}'; example: 'ABCDEFGHI:6', 'ABCDEFGHI1234:8','01234567894:7' */ getConfig_ByConfigKey_v3: (configKey: string) => Promise>; }; /** * AUTO GENERATED */ declare function CountryApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Public get country list, will filter out countries in black list */ getCountries_v3: () => Promise>; }; /** * AUTO GENERATED */ declare class Bans$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/bans [GET]_** */ getBans(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/bans/reasons [GET]_** */ getBansReasons(): Promise>; } /** * AUTO GENERATED */ declare class Clients$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients [GET]_** */ getClients(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients [POST]_** */ createClient(data: ClientCreateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [DELETE]_** */ deleteClient_ByClientId(clientId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [GET]_** */ getClient_ByClientId(clientId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [PATCH]_** */ updateClient_ByClientId(clientId: string, data: ClientUpdateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/{clientId}/secret [PUT]_** */ updateSecret_ByClientId(clientId: string, data: ClientUpdateSecretRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients [GET]_** */ getClients_ByNS(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/v3/admin/namespaces/{namespace}/clients [POST]_** */ createClient_ByNS(data: ClientCreateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _iam/v3/admin/namespaces/{namespace}/clients/{clientId}/permissions [PUT]_** */ updateClientpermission_ByClientId(clientId: string, data: ClientPermissions): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId} [DELETE]_** */ deleteClient_ByClientId_ByNS(clientId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId}/permissions/{resource}/{action} [DELETE]_** */ deleteClientpermission_ByClientId_ByResource_ByAction(clientId: string, resource: string, action: number): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/clients/{clientId}/permissions [POST]_** */ updateClientpermission_ByClientId_ByResource_ByAction(clientId: string, resource: string, action: number): Promise>; } /** * AUTO GENERATED */ declare class Config$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); getConfigPublic_v3(): Promise>; /** * This endpoint return the value of config key. The namespace should be publisher namespace or studio namespace. Note: this endpoint does not need any authorization. **Supported config key:** * uniqueDisplayNameEnabled * usernameDisabled * mandatoryEmailVerificationEnabled * verificationCodeType If the key is verificationCodeType, then possible value format will be '{collection}:{N}'; example: 'ABCDEFGHI:6', 'ABCDEFGHI1234:8','01234567894:7' */ getConfig_ByConfigKey_v3(configKey: string): Promise>; } /** * AUTO GENERATED */ declare class Country$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Public get country list, will filter out countries in black list */ getCountries_v3(): Promise>; } /** * AUTO GENERATED */ declare class InputValidations$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * No role required This endpoint is to get list of input validation configuration. <code>regex</code> parameter will be returned if <code>isCustomRegex</code> is true. Otherwise, it will be empty. */ getInputValidations_v3(queryParams?: { defaultOnEmpty?: boolean | null; languageCode?: string | null; }): Promise>; /** * This endpoint is to get input validation configuration by field. */ getInputValidation_ByField_v3(field: string): Promise>; } /** * AUTO GENERATED */ declare class OAuth$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * @deprecated * ## The endpoint is going to be deprecated This endpoint serves public keys for verifying JWT access tokens generated by this service. When a client application wants to verify a JWT token, it needs to get the 'kid' value found in the JWT token header and use it to look up the corresponding public key from a set returned by this endpoint. The client application can then use that public key to verify the JWT. A client application might cache the keys so it doesn't need to do request every time it needs to verify a JWT token. If a client application caches the keys and a key with the same 'kid' cannot be found in the cache, it should then try to refresh the keys by making a request to this endpoint again. Please refer to the RFC for more information about JWK (JSON Web Key): https://tools.ietf.org/html/rfc7517 ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/jwks [GET]_** */ getOauthJwks(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: /iam/v3/oauth/token [POST]** - **Note: difference in V3 response:** format difference(Pascal case => Camel case): permissions field from Action => action, Resource => resource This endpoint requires all requests to have <code>Authorization</code> header set with <code>Basic</code> access authentication constructed from client id and client secret. This endpoint supports different **grant types**: 1. Grant Type == <code>client_credentials</code>: This endpoint will check the client credentials provided through Authorization header. 2. Grant Type == <code>password</code>: The grant type to use for authenticating a user, whether it's by email / username and password combination or through platform. 3. Grant Type == <code>refresh_token</code>: Used to get a new access token for a valid refresh token. 4. Grant Type == <code>authorization_code</code>: It generates the user token by given the authorization code which generated in "/authorize" API response. It should also pass in the redirect_uri, which should be the same as generating the authorization code request. For platform authentication, use grant type <code>password</code>. The <code>username</code> field would be in form of <code>platform:<platform type></code>, for example <code>platform:steam</code> for Steam. For the <code>password</code> field, set it to the authentication/authorization ticket or token obtainable through the respective platform SDK after authenticated the user to the platform. Supported platforms: - **steam** - use <code>platform:steam</code> as the username and use the authentication ticket obtained from Steam through the Steam SDK as the password. - **ps4** - use <code>platform:ps4</code> as the username and use the authorization code obtained from the PlayStation Network through a player PS4 unit as the password. - **live** - use <code>platform:live</code> as the username and use token obtained from Xbox Secure Token Service (XSTS) as the password. - **oculus** - use <code>platform:oculus</code> as the username and use the <code>user_id:nonce</code> as password obtained from Oculus through the Oculus SDK. The access token and refresh token are in form of JWT token. An access token JWT contains data which structure is similar to the Response Class below, but without OAuth-related data. To verify a token, use the public keys obtained from the <code>/jwks</code> endpoint below. ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - **aud**. The aud is the client ID. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **sub**. The UserID. The sub is omitted if the token is generated from client credential ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. ## Track Login History This endpoint will track login history to detect suspicious login activity, please provide "device_id" (alphanumeric) in request header parameter otherwise we will set to "unknown". Align with General Data Protection Regulation in Europe, user login history will be kept within 28 days by default" */ postOauthToken(data: { grant_type: 'authorization_code' | 'client_credentials' | 'password' | 'refresh_token'; code?: string | null; extend_exp?: boolean | null; namespace?: string | null; password?: string | null; redirect_uri?: string | null; refresh_token?: string | null; username?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/verify [POST]_** - **Note: difference in V3 response:** 1. format difference(Pascal case => Camel case): permissions field from Action => action, Resource => resource */ postOauthVerify(data: { token: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated The endpoint supports two response types: ### 1. Response Type == "code": The endpoint returns an authorization code that will be used by the IAM client to exchange for an access token. It supports two different headers, the basic and the bearer header. Each behaves differently. - **The basic header** The basic header’s value is the base64 of the client ID and client secret. It is used by the developer whenever the developer authorizes a user on a same namespace. - **The bearer header** The bearer header’s value is an access token. It is used by the developer whenever the developer authorizes a user on a different namespace. The endpoint validates user’s entitlement on the designated namespace for making sure the user is authorized for a designated namespace. Following are the responses returned by the endpoint: - **Authorize success**: redirects to the given URL with the following information: ?code={authorization code}&state={state} - **Authorize failure**: redirects to the given URL with the following information:?error=access_denied&error_description=... ### 2. Response Type == "token" (Implicit) is deprecated. ### Endpoint migration guide - **Substitute endpoint (for: basic header style)**: _/iam/v3/oauth/authorize [GET]_ - **Substitute endpoint (for: bearer header style)**: step1: /iam/v3/namespace/{namespace}/token/request [POST] => get code step2: /iam/v3/token/exchange [POST] => get token by step1's code - **Note:** 1. V3 is standard OAuth2 flow and support PKCE 2. Will not support implicit flow in v3. */ postOauthAuthorize(data: { client_id: string | null; redirect_uri: string | null; response_type: 'code' | 'token'; login?: string | null; password?: string | null; scope?: string | null; state?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint revokes a user. This endpoint requires all requests to have Authorization header set with Bearer access authentication with valid access token. When other clients know that the userID has been revoked and the token is issued before the revocation, forcing a new token will contain banned permissions. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/admin/namespaces/{namespace}/users/{userId}/revoke [POST]_** */ postOauthRevokeUser(data: { userID: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Revokes a token. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret or Bearer access authentication with valid access token. ### Endpoint migration guide - **Substitute endpoint: _/v3/oauth/revoke [POST]_** */ postOauthRevokeToken(data: { token: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint will return a list of revoked users and revoked tokens. List of revoked tokens in bloom filter format. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. The bloom filter uses MurmurHash3 algorithm for hashing the values ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/revocationlist [GET]_** */ getOauthRevocationlist(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint requires all requests to have authorization header set with bearer token. The endpoint revokes all access tokens and refresh tokens a user has prior the revocation time. It is a convenient feature for the developer (or admin) who wanted to revokes all user's access tokens and refresh tokens generated before some period of time. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/admin/namespaces/{namespace}/users/{userId}/revoke [POST]_** */ updateRevokeOauth_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. For publisher-game namespace schema : Specify only either platform_token or device_id. Device token grant should be requested along with device_id parameter against game namespace. Another 3rd party platform token grant should be requested along with platform_token parameter against publisher namespace. Supported platforms: - **steamopenid**: Steam's user authentication method using OpenID 2.0. The expected value of the platform token is the URL generated by Steam on web authentication The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /iam/bans.. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/platforms/{platformId}/token [POST]_** */ postTokenOauth_ByPlatformId(platformId: string, data: { device_id?: string | null; macAddress?: string | null; platform_token?: string | null; }): Promise>; } /** * AUTO GENERATED */ declare class OAuth20$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint serves public keys for verifying JWT access tokens generated by this service. When a client application wants to verify a JWT token, it needs to get the 'kid' value found in the JWT token header and use it to look up the corresponding public key from a set returned by this endpoint. The client application can then use that public key to verify the JWT. A client application might cache the keys so it doesn't need to do request every time it needs to verify a JWT token. If a client application caches the keys and a key with the same 'kid' cannot be found in the cache, it should then try to refresh the keys by making a request to this endpoint again. Please refer to the RFC for more information about JWK (JSON Web Key): https://tools.ietf.org/html/rfc7517 action code : 10709 */ getOauthJwks_v3(): Promise>; /** * This endpoint supports grant type: 1. Grant Type == <code>authorization_code</code>: It generates the user token by given the authorization code which generated in "/iam/v3/authenticate" API response. It should also pass in the redirect_uri, which should be the same as generating the authorization code request. 2. Grant Type == <code>password</code>: The grant type to use for authenticating a user, whether it's by email / username and password combination or through platform. 3. Grant Type == <code>refresh_token</code>: Used to get a new access token for a valid refresh token. 4. Grant Type == <code>client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. 5. Grant Type == <code>urn:ietf:params:oauth:grant-type:extend_client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. It only allows publisher/studio namespace client. In generated token: 1. There wil be no roles, namespace_roles & permission. 2. The scope will be fixed as 'extend'. 3. There will have a new field 'extend_namespace', the value is from token request body. ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the targeted resource server. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **client_id**. The UserID. The sub is omitted if the token is generated from client credential - **scope**. The scope of the access request, expressed as a list of space-delimited, case-sensitive strings ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. ## Device Cookie Validation _**For grant type "password" only**_ Device Cookie is used to protect the user account from brute force login attack, <a target="_blank" href="https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies">more detail from OWASP<a>. This endpoint will read device cookie from request header **Auth-Trust-Id**. If device cookie not found, it will generate a new one and set it into response body **auth_trust_id** when successfully login. ## Track Login History This endpoint will track login history to detect suspicious login activity, please provide **Device-Id** (alphanumeric) in request header parameter otherwise it will set to "unknown". Align with General Data Protection Regulation in Europe, user login history will be kept within 28 days by default" ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Response note If it is a user token request and user hasn't accepted required legal policy, the field <code>is_comply</code> will be false in response and responsed token will have no permission. action code: 10703 */ postOauthToken_v3(data: { grant_type: 'authorization_code' | 'client_credentials' | 'password' | 'refresh_token' | 'urn:ietf:params:oauth:grant-type:extend_client_credentials'; additionalData?: string | null; client_id?: string | null; client_secret?: string | null; code?: string | null; code_verifier?: string | null; extendNamespace?: string | null; extend_exp?: boolean | null; password?: string | null; redirect_uri?: string | null; refresh_token?: string | null; scope?: string | null; username?: string | null; }): Promise>; /** * This endpoint revokes a token. This endpoint requires authorized requests header with Basic Authentication from client that establish the token. action code: 10706 */ postOauthRevoke_v3(data: { token: string | null; }): Promise>; /** * This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. */ postOauthVerify_v3(data: { token: string | null; }): Promise>; /** * Send 2FA code This endpoint is used for sending 2FA code. */ postOauthMfaCode_v3(data: { clientId: string | null; factor: string | null; mfaToken: string | null; }): Promise>; /** * Initializes OAuth2.0 authorization code flow The endpoint stores authorization request and redirects to login page with the authorization request id. The user can then do the authentication on the login page. The user will be redirected back to the requesting client with authorization code if successfully authenticated. Only authorization code flow supported by this endpoint, implicit flow is not supported. - **Authorize success**: redirects to login page with the following information: ?request_id={authorization_request_id} - **Authorize failure**: redirects to the given redirect uri with the following information: ?error={error_code}&error_description={error description} For Public Client case, it's mandatory to fill **code_challenge** to avoid authorization code interception attack. Please refer to the RFC for more information about Proof Key for Code Exchange(PKCE): https://datatracker.ietf.org/doc/html/rfc7636 Following are the error code based on the specification: - invalid_request: The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than once, or is otherwise malformed. - server_error: The authorization server encountered an unexpected condition that prevented it from fulfilling the request. - unauthorized_client: The client is not authorized to request a token using this method. - access_denied: The resource owner or authorization server denied the request. - invalid_scope: The requested scope is invalid, unknown, or malformed. - unsupported_response_type: The authorization server does not support obtaining a token using this method. - temporarily_unavailable: The authorization server is currently unable to handle the request due to a temporary overloading or maintenance of the server. Please refer to the RFC for more information about authorization code flow: https://tools.ietf.org/html/rfc6749#section-4.1 action code: 10701 */ getOauthAuthorize_v3(queryParams: { client_id: string | null; response_type: 'code'; blockedPlatformId?: string | null; code_challenge?: string | null; code_challenge_method?: 'S256' | 'plain'; createHeadless?: boolean | null; loginWebBased?: boolean | null; nonce?: string | null; oneTimeLinkCode?: string | null; redirect_uri?: string | null; scope?: string | null; state?: string | null; target_auth_page?: string | null; useRedirectUriAsLoginUrlWhenLocked?: boolean | null; }): Promise>; /** * This endpoint returns information about an access token intended to be used by resource servers or other internal servers. This endpoint requires authorized requests header with valid basic or bearer token. action code : 10705 */ postOauthIntrospect_v3(data: { token: string | null; }): Promise>; /** * Verify 2FA code This endpoint is used for verifying 2FA code. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token */ postOauthMfaVerify_v3(data: { code: string | null; factor: string | null; mfaToken: string | null; rememberDevice: boolean | null; }): Promise>; /** * This endpoint will return a list of revoked users and revoked tokens. List of revoked tokens in bloom filter format. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. The bloom filter uses MurmurHash3 algorithm for hashing the values action code : 10708 */ getOauthRevocationlist_v3(): Promise>; /** * Change 2FA method This endpoint is used for change 2FA method. Only enabled methods are accepted. Supported methods: - authenticator - backupCode - email */ postOauthMfaFactorChange_v3(data: { factor: string | null; mfaToken: string | null; }): Promise>; /** * # This endpoint is in ALPHA, avoid using this endpoint fow now, reach out to AB support for inquiries Simultaneous login flow. The primary goals of this project are to entitle players to authenticate on a native PC platform(Steam/Epic) and the PlayStation platform, link their accounts, and provide support for platform sync with a valid 3rd platform access token. ## Given a valid native ticket and empty simultaneous ticket, these cases will be failed - Native ticket's account is not linked AGS account yet - Native ticket's account is linked AGS account, but AGS account is not linked simultaneous platform yet - Native ticket's account is linked AGS account, AGS account is linked simultaneous platform but there is no available simultaneous token.(only if this platform is expected to store the platform token) ## Given a valid native ticket and empty simultaneous ticket, this case will be success - Native ticket's account already linked AGS account, this AGS account already linked simultaneous platform. There is valid simultaneous token.(this is required only when this simultaneous is expected to cache platform token) ## Given a valid native ticket token and valid simultaneous ticket, these cases will be failed #### Native ticket's account is already linked with AGS account - Native linked AGS account is linked this simultaneous platform but is different with simultaneous ticket's account - Native linked AGS account is not linked with simultaneous but has a linking history with simultaneous platform and it is different with simultaneous ticket's account #### Native ticket's account is not linked with AGS account and Simultaneous ticket's account is already linked wth AGS account - Simultaneous linked AGS account is linked this native platform but is different with native ticket's account - Simultaneous linked AGS account is not linked with native but has a linking history with native platform and it is different with native ticket's account ## Given a valid native ticket and valid simultaneous ticket, these cases will be success - Native ticket's account & Simultaneous ticket's account are both not linked to AGS account yet - Native ticket's account & Simultaneous ticket's account are already linked to same AGS account */ postOauthSimultaneousLogin_v3(data: { nativePlatform: 'epicgames' | 'steam'; nativePlatformTicket: string | null; simultaneousPlatform?: string | null; simultaneousTicket?: string | null; }): Promise>; /** * This is a forward version for '/mfa/verify'. If there is any error, it will redirect to login website with error details. If success, it will forward to auth request redirect url If got error, it will forward to login website Verify 2FA code This endpoint is used for verifying 2FA code. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token */ postOauthMfaVerifyForward_v3(data: { clientId: string | null; code: string | null; factor: string | null; mfaToken: string | null; defaultFactor?: string | null; factors?: string | null; rememberDevice?: boolean | null; }): Promise>; /** * Platform token grant specifically used for performing token grant using platform, e.g. Steam, Justice, etc. The endpoint automatically create an account if the account associated with the platform is not exists yet. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. For publisher-game namespace schema : Specify only either platform_token or device_id. Device token grant should be requested along with device_id parameter against game namespace. Another 3rd party platform token grant should be requested along with platform_token parameter against publisher namespace. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Supported platforms: - **steam**: The platform_token’s value is the binary ticket returned by Steam. If this ticket was generated by Steam GetAuthTicketForWebApi with version >= 1.57, then platform token should use this style: <code>{identity}:{ticket}</code>, the <code>{identity}</code> was the parameter to call GetAuthTicketForWebApi when the ticket was created. Note: Do not contain <code>:</code> in this <code>{identity}</code>. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code or idToken returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code or idToken returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code or idToken returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the id_token returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. ## Account Group Several platforms are grouped under account groups. The accounts on these platforms have the same platform user id. Login using one of these platform will returns the same IAM user. Following is the current registered account grouping: - Steam group(steamnetwork): - steam - steamopenid - PSN group(psn) - ps4web - ps4 - ps5 - XBOX group(xbox) - live - xblweb - Oculus group(oculusgroup) - oculus - oculusweb ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the client ID. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **sub**. The UserID. The sub is omitted if the token is generated from client credential ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. action code : 10704 */ postTokenOauth_ByPlatformId_v3(platformId: string, data: { additionalData?: string | null; client_id?: string | null; createHeadless?: boolean | null; device_id?: string | null; macAddress?: string | null; platform_token?: string | null; serviceLabel?: number; skipSetCookie?: boolean | null; }): Promise>; /** * Generate url to request auth code from third party platform ## Supported platforms: - **steamopenid**This endpoint redirects to steam login page, then redirect back to platform authenticate endpoint after successfully authenticating user steam. - **xblweb**This endpoint redirects to xbox login page, then redirect back to platform authenticate endpoint after successfully authenticating xbox user. - **ps4web**This endpoint redirects to psn login page, then redirect back to platform authenticate endpoint after successfully authenticating psn user. - **epicgames**This endpoint redirects to Epicgames OAuth login page. then redirect to platform authenticate endpoint after successfully authenticating an Epicgames credential - **twitch**This endpoint redirects to twitch login page, then redirect back to platform authenticate endpoint after successfully authenticating twitch user. - **azure**This endpoint redirects to azure login page, then redirect back to platform authenticate(saml) endpoint after successfully authenticating azure user. - **facebook**This endpoint redirects to facebook login page, then redirect back to platform authenticate endpoint after successfully authenticating facebook user. - **google**This endpoint redirects to google login page, then redirect back to platform authenticate endpoint after successfully authenticating google user. - **snapchat**This endpoint redirects to snapchat login page, then redirect back to platform authenticate endpoint after successfully authenticating snapchat user. - **discord**This endpoint redirects to discord login page, then redirect back to platform authenticate endpoint after successfully authenticating discord user. - **amazon**This endpoint redirects to amazon login page, then redirect back to platform authenticate endpoint after successfully authenticating amazon user. - **oculusweb**This endpoint redirects to oculus login page, then redirect back to Login Website page after successfully authenticating oculus user. action code : 10702' */ getAuthorizeOauth_ByPlatformId_v3(platformId: string, queryParams: { request_id: string | null; client_id?: string | null; redirect_uri?: string | null; }): Promise>; /** * Retrieve User Third Party Platform Token This endpoint used for retrieving third party platform token for user that login using third party, if user have not link requested platform in game namespace, will try to retrieving third party platform token from publisher namespace. Passing platform group name or it's member will return same access token that can be used across the platform members. The third party platform and platform group covered for this is: - (psn) ps4web - (psn) ps4 - (psn) ps5 - epicgames - twitch - awscognito - <amazon/li> - eaorigin - snapchat - twitch - live **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getPlatformTokenOauth_ByUserId_ByPlatformId_v3(userId: string, platformId: string): Promise>; } /** * AUTO GENERATED */ declare class OAuth20Extension$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint is used to remove **access_token**, **refresh_token** from cookie. */ createLogout_v3(): Promise>; /** * This endpoint is being used to authenticate a user account. It validates user's email / username and password. Deactivated or login-banned users are unable to login. Redirect URI and Client ID must be specified as a pair and only used to redirect to the specified redirect URI in case the requestId is no longer valid. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. Action code: 10801 */ postAuthenticate_v3(data: { password: string | null; request_id: string | null; user_name: string | null; client_id?: string | null; extend_exp?: boolean | null; redirect_uri?: string | null; }): Promise>; /** * This endpoint is being used to create headless account after 3rd platform authenticated, and response token . The 'linkingToken' in request body is received from "/platforms/{platformId}/token" when 3rd platform account is not linked to justice account yet. */ postHeadlesToken_v3(data: { linkingToken: string | null; additionalData?: string | null; extend_exp?: boolean | null; }): Promise>; /** * This endpoint is being used to generate target token. It requires basic header with ClientID and Secret, it should match the ClientID when call <code>/iam/v3/namespace/{namespace}/token/request</code> The code should be generated from <code>/iam/v3/namespace/{namespace}/token/request</code>. */ postTokenExchange_v3(data: { code: string | null; additionalData?: string | null; }): Promise>; /** * In login website based flow, after account upgraded, we need this API to handle the forward */ postUpgradeForward_v3(data: { client_id: string | null; upgrade_success_token: string | null; }): Promise>; /** * This endpoint get country location based on the request. */ getLocationCountry_v3(): Promise>; /** * This endpoint is being used to request the one time code [8 length] for headless account to link or upgrade to a full account. Should specify the target platform id and current user should already linked to this platform. Current user should be a headless account. ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **googleplaygames** - **oculus** - **twitch** - **discord** - **android** - **ios** - **apple** - **device** - **justice** - **epicgames** - **ps4** - **ps5** - **nintendo** - **awscognito** - **live** - **xblweb** - **netflix** - **snapchat** */ postLinkCodeRequest_v3(data: { platformId: string | null; redirectUri?: string | null; state?: string | null; }): Promise>; /** * This endpoint is being used to validate one time link code. */ postLinkCodeValidate_v3(data: { oneTimeLinkCode: string | null; }): Promise>; /** * This endpoint is being used to generate user's token by one time link code. It requires a code which can be generated from <code>/iam/v3/link/code/request</code> or <code>/iam/v3/public/users/me/link/forward</code>. This endpoint support creating transient token by utilizing **isTransient** param: **isTransient=true** will generate a transient token with a short Time Expiration and without a refresh token **isTransient=false** will consume the one-time code and generate the access token with a refresh token. */ postLinkTokenExchange_v3(data: { client_id: string | null; oneTimeLinkCode: string | null; additionalData?: string | null; isTransient?: boolean | null; }): Promise>; /** * This endpoint is being used to authenticate a user account and perform platform link. It validates user's email / username and password. If user already enable 2FA, then invoke _/mfa/verify_ using **mfa_token** from this endpoint response. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. */ postAuthenticateWithLink_v3(data: { client_id: string | null; linkingToken: string | null; password: string | null; username: string | null; extend_exp?: boolean | null; }): Promise>; /** * This endpoint is being used to authenticate a user account and perform platform link. It validates user's email / username and password. If user already enable 2FA, then invoke _/mfa/verify_ using **mfa_token** from this endpoint response. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. */ postAuthenticateWithLinkForward_v3(data: { client_id: string | null; linkingToken: string | null; password: string | null; username: string | null; extend_exp?: boolean | null; }): Promise>; /** * This endpoint is being used to request the code to exchange a new token. The target new token's clientId should NOT be same with current using one. Path namespace should be target namespace. Client ID should match the target namespace. The code in response can be consumed by <code>/iam/v3/token/exchange</code> */ postTokenRequest_v3(data: { client_id: string | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: 'S256' | 'plain'; }): Promise>; /** * This endpoint authenticates user platform. It validates user to its respective platforms. Deactivated or login-banned users are unable to login. If already linked with justice account or match SSO condition, will redirect to client's redirect url with code. then invoke '/iam/v3/oauth/token' with grant_type=authorization_code If already not linked with justice account and not match SSO condition, will redirect to client's account linking page ## Supported platforms: - **steamopenid**Steam login page will redirects to this endpoint after login success as previously defined on openID request parameter <code>openid.return_to</code> when request login to steam https://openid.net/specs/openid-authentication-2_0.html#anchor27 - **ps4web**PS4 login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> https://ps4.siedev.net/resources/documents/WebAPI/1/Auth_WebAPI-Reference/0002.html#0GetAccessTokenUsingAuthorizationCode - **xblweb**XBL login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **epicgames**Epicgames login page will redirects to this endpoint after login success or an error occurred. If error, it redirects to the login page. - **twitch**Twitch login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **facebook**Facebook login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **google**Google login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **snapchat**Snapchat login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **discord**Discord login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> action code : 10709 */ getAuthenticate_ByPlatformId_v3(platformId: string, queryParams: { state: string | null; code?: string | null; error?: string | null; assoc_handle?: string | null; claimed_id?: string | null; identity?: string | null; mode?: string | null; ns?: string | null; op_endpoint?: string | null; response_nonce?: string | null; return_to?: string | null; sig?: string | null; signed?: string | null; }): Promise>; /** * This endpoint will validate the third party platform token, for some platforms will also refresh the token stored in IAM, it will not generate any event or AB access/refresh token. This endpoint can be used by game client to refresh third party token if game client got platform token not found error, for example got 404 platform token not found from IAP/DLC. ## Platforms will refresh stored token: - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **epicgames**: The platform_token’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **amazon**: The platform_token’s value is authorization code. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. */ postTokenVerify_ByPlatformId_v3(platformId: string, data: { platform_token: string | null; }): Promise>; } /** * AUTO GENERATED */ declare class OAuth20V4$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint supports grant type: 1. Grant Type == <code>authorization_code</code>: It generates the user token by given the authorization code which generated in "/iam/v3/authenticate" API response. It should also pass in the redirect_uri, which should be the same as generating the authorization code request. 2. Grant Type == <code>password</code>: The grant type to use for authenticating a user, whether it's by email / username and password combination or through platform. 3. Grant Type == <code>refresh_token</code>: Used to get a new access token for a valid refresh token. 4. Grant Type == <code>client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. 5. Grant Type == <code>urn:ietf:params:oauth:grant-type:extend_client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. It only allows publisher/studio namespace client. In generated token: 1. There wil be no roles, namespace_roles & permission. 2. The scope will be fixed as 'extend'. 3. There will have a new field 'extend_namespace', the value is from token request body. 6. Grant Type == <code>urn:ietf:params:oauth:grant-type:login_queue_ticket</code>: It generates a token by validating the login queue ticket against login queue service. ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the targeted resource server. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **client_id**. The UserID. The sub is omitted if the token is generated from client credential - **scope**. The scope of the access request, expressed as a list of space-delimited, case-sensitive strings ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. ## Device Cookie Validation _**For grant type "password" only**_ Device Cookie is used to protect the user account from brute force login attack, <a target="_blank" href="https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies">more detail from OWASP<a>. This endpoint will read device cookie from request header **Auth-Trust-Id**. If device cookie not found, it will generate a new one and set it into response body **auth_trust_id** when successfully login. ## Track Login History This endpoint will track login history to detect suspicious login activity, please provide **Device-Id** (alphanumeric) in request header parameter otherwise it will set to "unknown". Align with General Data Protection Regulation in Europe, user login history will be kept within 28 days by default" ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Response note If it is a user token request and user hasn't accepted required legal policy, the field <code>is_comply</code> will be false in response and responsed token will have no permission. action code: 10703 * * #### Response type: * - `TokenWithDeviceCookieResponseV3` * - `LoginQueueTicketResponse` */ postOauthToken_v4(data: { grant_type: 'authorization_code' | 'client_credentials' | 'password' | 'refresh_token' | 'urn:ietf:params:oauth:grant-type:extend_client_credentials' | 'urn:ietf:params:oauth:grant-type:login_queue_ticket'; additionalData?: string | null; client_id?: string | null; client_secret?: string | null; code?: string | null; code_verifier?: string | null; extendNamespace?: string | null; extend_exp?: boolean | null; login_queue_ticket?: string | null; password?: string | null; redirect_uri?: string | null; refresh_token?: string | null; scope?: string | null; username?: string | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: 'S256' | 'plain'; }): Promise>; /** * Verify 2FA code This endpoint is used for verifying 2FA code. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthMfaVerify_v4(data: { code: string | null; factor: string | null; mfaToken: string | null; rememberDevice: boolean | null; }): Promise>; /** * This endpoint is being used to create headless account after 3rd platform authenticated, and response token . The 'linkingToken' in request body is received from "/platforms/{platformId}/token" when 3rd platform account is not linked to justice account yet. * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthHeadlesToken_v4(data: { linkingToken: string | null; additionalData?: string | null; extend_exp?: boolean | null; }): Promise>; /** * This endpoint is being used to generate target token. It requires basic header with ClientID and Secret, it should match the ClientID when call <code>/iam/v3/namespace/{namespace}/token/request</code> The code should be generated from <code>/iam/v3/namespace/{namespace}/token/request</code>. * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthTokenExchange_v4(data: { code: string | null; additionalData?: string | null; }): Promise>; /** * # This endpoint is in ALPHA, avoid using this endpoint fow now, reach out to AB support for inquiries Simultaneous login flow. The primary goals of this project are to entitle players to authenticate on a native PC platform(Steam/Epic) and the PlayStation platform, link their accounts, and provide support for platform sync with a valid 3rd platform access token. ## Given a valid native ticket and empty simultaneous ticket, these cases will be failed - Native ticket's account is not linked AGS account yet - Native ticket's account is linked AGS account, but AGS account is not linked simultaneous platform yet - Native ticket's account is linked AGS account, AGS account is linked simultaneous platform but there is no available simultaneous token.(only if this platform is expected to store the platform token) ## Given a valid native ticket and empty simultaneous ticket, this case will be success - Native ticket's account already linked AGS account, this AGS account already linked simultaneous platform. There is valid simultaneous token.(this is required only when this simultaneous is expected to cache platform token) ## Given a valid native ticket token and valid simultaneous ticket, these cases will be failed #### Native ticket's account is already linked with AGS account - Native linked AGS account is linked this simultaneous platform but is different with simultaneous ticket's account - Native linked AGS account is not linked with simultaneous but has a linking history with simultaneous platform and it is different with simultaneous ticket's account #### Native ticket's account is not linked with AGS account and Simultaneous ticket's account is already linked wth AGS account - Simultaneous linked AGS account is linked this native platform but is different with native ticket's account - Simultaneous linked AGS account is not linked with native but has a linking history with native platform and it is different with native ticket's account ## Given a valid native ticket and valid simultaneous ticket, these cases will be success - Native ticket's account & Simultaneous ticket's account are both not linked to AGS account yet - Native ticket's account & Simultaneous ticket's account are already linked to same AGS account * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthSimultaneousLogin_v4(data: { nativePlatform: 'epicgames' | 'steam'; nativePlatformTicket: string | null; simultaneousPlatform?: string | null; simultaneousTicket?: string | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: 'S256' | 'plain'; }): Promise>; /** * This endpoint is being used to authenticate a user account and perform platform link. It validates user's email / username and password. If user already enable 2FA, then invoke _/mfa/verify_ using **mfa_token** from this endpoint response. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthAuthenticateWithLink_v4(data: { client_id: string | null; linkingToken: string | null; password: string | null; username: string | null; extend_exp?: boolean | null; }): Promise>; /** * Platform token grant specifically used for performing token grant using platform, e.g. Steam, Justice, etc. The endpoint automatically create an account if the account associated with the platform is not exists yet. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. For publisher-game namespace schema : Specify only either platform_token or device_id. Device token grant should be requested along with device_id parameter against game namespace. Another 3rd party platform token grant should be requested along with platform_token parameter against publisher namespace. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Supported platforms: - **steam**: The platform_token’s value is the binary ticket returned by Steam. If this ticket was generated by Steam GetAuthTicketForWebApi with version >= 1.57, then platform token should use this style: <code>{identity}:{ticket}</code>, the <code>{identity}</code> was the parameter to call GetAuthTicketForWebApi when the ticket was created. Note: Do not contain <code>:</code> in this <code>{identity}</code>. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code or idToken returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code or idToken returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code or idToken returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the id_token returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. ## Account Group Several platforms are grouped under account groups. The accounts on these platforms have the same platform user id. Login using one of these platform will returns the same IAM user. Following is the current registered account grouping: - Steam group(steamnetwork): - steam - steamopenid - PSN group(psn) - ps4web - ps4 - ps5 - XBOX group(xbox) - live - xblweb - Oculus group(oculusgroup) - oculus - oculusweb ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the client ID. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **sub**. The UserID. The sub is omitted if the token is generated from client credential ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. action code : 10704 * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postTokenOauth_ByPlatformId_v4(platformId: string, data: { additionalData?: string | null; client_id?: string | null; createHeadless?: boolean | null; device_id?: string | null; macAddress?: string | null; platform_token?: string | null; serviceLabel?: number; skipSetCookie?: boolean | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: 'S256' | 'plain'; }): Promise>; } /** * AUTO GENERATED */ declare class ProfileUpdateStrategy$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This API is for public user to get profile update strategy by namespace and field. Note: If the config is not found, this API will return a config with unlimited. */ getProfileUpdateStrategies_v3(queryParams?: { field?: 'country' | 'display_name' | 'dob' | 'username'; }): Promise>; } /** * AUTO GENERATED */ declare class Roles$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles [GET]_** */ getRoles(queryParams?: { isWildcard?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Role can only be assigned to other users by the role's manager. If role is an administrator role (i.e. AdminRole == true), it will list out the role's members. Administrator role can be created only when at least 1 manager is specified. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles [POST]_** */ createRole(data: RoleCreateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId} [DELETE]_** */ deleteRole_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId} [GET]_** */ getRole_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId} [PATCH]_** */ updateRole_ByRoleId(roleId: string, data: RoleUpdateRequest): Promise>; /** * This endpoint is used to get all non-admin role. action code: 10418 */ getRoles_v3(queryParams?: { after?: string | null; before?: string | null; isWildcard?: boolean | null; limit?: number; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/admin [DELETE]_** */ deleteAdmin_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Admin roles has its members listed in the role. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/admin [GET]_** */ getAdmin_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Admin roles has its members listed in the role. Role can be set as admin role only when it has at least 1 manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/admin [POST]_** */ updateAdmin_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/members [DELETE]_** */ deleteMember_ByRoleId(roleId: string, data: RoleMembersRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/members [GET]_** */ getMembers_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Admin roles has its members listed in the role. Role can only be assigned to other users by the role's manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/members [POST]_** */ updateMember_ByRoleId(roleId: string, data: RoleMembersRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/managers [DELETE]_** */ deleteManager_ByRoleId(roleId: string, data: RoleManagersRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Role can only be assigned to other users by the role's manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/managers [GET]_** */ getManagers_ByRoleId(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Role can only be assigned to other users by the role's manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/managers [POST]_** */ updateManager_ByRoleId(roleId: string, data: RoleManagersRequest): Promise>; /** * This endpoint is used to get non-admin role based on specify roleId. action code : 10417 */ getRole_ByRoleId_v3(roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint will REPLACE role's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. \*: all values in the fields, e.g. \* in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/permissions [POST]_** */ updatePermission_ByRoleId(roleId: string, data: Permissions): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/permissions/{resource}/{action} [DELETE]_** - **Substitute endpoint: _/iam/v4/admin/roles/{roleId}/permissions [DELETE]_** */ deletePermission_ByRoleId_ByResource_ByAction(roleId: string, resource: string, action: number): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint will update existing permission (bitwise OR the action) if found one with same resource, otherwise it will append a new permission Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: - Seconds: 0-59 * / , - - Minutes: 0-59 * / , - - Hours: 0-23 * / , - - Day of month: 1-31 * / , - L W - Month: 1-12 JAN-DEC * / , - - Day of week: 0-6 SUN-SAT * / , - L # - Year: 1970-2099 * / , - Special characters: - \**: all values in the fields, e.g. \* in seconds fields indicates every second - /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter - ,: separate items of a list, e.g. MON,WED,FRI in day of week - -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive - L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. - W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." - #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. ### Endpoint migration guide - **Substitute endpoint(update): _/iam/v3/admin/roles/{roleId}/permissions [PUT]_** - **Substitute endpoint(create): _/iam/v3/admin/roles/{roleId}/permissions [POST]_** */ updatePermission_ByRoleId_ByResource_ByAction(roleId: string, resource: string, action: number, data: UpdatePermissionScheduleRequest): Promise>; } /** * AUTO GENERATED */ declare class Sso$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); getSso_ByPlatformId_v3(platformId: string, queryParams?: { payload?: string | null; }): Promise>; /** * Logout user's session on platform that logged in using SSO. Supported platforms: - discourse */ createLogout_ByPlatformId_v3(platformId: string): Promise>; } /** * AUTO GENERATED */ declare class SsoSaml20$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint authenticates user platform for SAML protocol. It validates user to its respective platforms. Deactivated or login-banned users are unable to login. ## Supported platforms: - **azure** Microsoft login page will redirects to this endpoint after login success as previously defined on authentication request SAML */ postAuthenticateSamlSso_ByPlatformId_v3(platformId: string, queryParams: { state: string | null; code?: string | null; error?: string | null; }): Promise>; } /** * AUTO GENERATED */ declare class ThirdPartyCredential$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This is the Public API to Get All Active OIDC Platform Credential By Client ID */ getPlatformsClientsOidc_v3(queryParams: { clientId: string | null; }): Promise>; /** * This is the Public API to Get All Active 3rd Platform Credential. */ getPlatformsClientsActive_v3(): Promise>; } /** * AUTO GENERATED */ declare class Users$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * Get my user data __Supported 3rd platforms:__ * __PSN(ps4web, ps4, ps5)__ * account id * display name * avatar * __Xbox(live, xblweb)__ * xuid or pxuid * display name * __Steam(steam, steamopenid)__ * steam id * display name * avatar * __EpicGames(epicgames)__ * epic account id * display name action code : 10147 */ getUsersMe_v3(queryParams?: { includeAllPlatforms?: boolean | null; }): Promise>; /** * This endpoint does not need a namespace in the path, we will find the namespace based on: - If this is premium environment, the namespace will be the publisher namespace. - If this is shared cloud: - If this is from Admin Portal, we will find the user by the email. - If this is not from Admin Portal, we will find the namespace based on the client id. **Note**: - The param **clientId** is required in Shared Cloud - The namespace in the response is publisher/studio namespace */ createUserForgot_v3(data: ForgotPasswordWithoutNamespaceRequestV3): Promise>; /** * This API is created to match openid userinfo standard => https://openid.net/specs/openid-connect-core-1_0.html#UserInfo */ getUsersUserinfo_v3(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users [POST]_** - **Substitute endpoint: _/iam/v4/public/namespaces/{namespace}/users [POST]_** - **Note:** 1. v3 & v4 introduce optional verification code 2. format difference(Pascal case => Camel case) Available Authentication Types: 1. **EMAILPASSWD**: an authentication type used for new user registration through email. 2. **PHONEPASSWD**: an authentication type used for new user registration through phone number. Country use ISO3166-1 alpha-2 two letter, e.g. US. */ createUser(data: UserCreateRequest): Promise>; /** * This API is for user to get self profile update allow status. Note: If the config is not found, this API will return a config with unlimited. */ getUsersMeProfileStatus_v3(): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(Public): _/iam/v3/admin/namespaces/{namespace}/roles/{roleId}/users [GET]_** - **Note:** difference in V3 response, format difference: Pascal case => Camel case This endpoint search admin users which have the roleId Notes : this endpoint only accept admin role. Admin Role is role which have admin status and members. Use endpoint [GET] /roles/{roleId}/admin to check the role status */ getUsersAdmin(queryParams?: { after?: number; before?: number; limit?: number; roleId?: string | null; }): Promise>; getUsersVerifyLinkVerify_v3(queryParams?: { code?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/search [GET]_** Search all users that match the query on these fields: all login IDs (email address, phone number, and platform user id), userID, display name, and on the specified namespace. If the query is not defined, then it searches all users on the specified namespace. */ getUsersSearch(queryParams?: { query?: string | null; }): Promise>; /** * Get my redirect uri after link, this endpoint will return NotFound(404) if redirect uri is not found */ getUsersMeLinkRedirection_v3(queryParams: { oneTimeLinkCode: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/information [DELETE]_** */ deleteUser_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(Public): _/iam/v3/public/namespaces/{namespace}/users/{userId} [GET]_** - **Substitute endpoint(Admin): _/iam/v3/admin/namespaces/{namespace}/users/{userId} [GET]_** - **Note:** format difference in response: Pascal case => Camel case */ getUser_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint([PUT]): _/iam/v3/public/namespaces/{namespace}/users/me [PUT]_** - **Substitute endpoint([PATCH]): _/iam/v3/public/namespaces/{namespace}/users/me [PATCH]_** - **Substitute endpoint([PATCH]): _/iam/v4/public/namespaces/{namespace}/users/me [PATCH]_** - **Note:** 1. Prefer [PATCH] if client support PATCH method 2. Difference in V3/v4 request body, format difference: Pascal case => Camel case This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {Country, DisplayName, LanguageTag} Country use ISO3166-1 alpha-2 two letter, e.g. US. **Several case of updating email address** - User want to update email address of which have been verified, NewEmailAddress response field will be filled with new email address - User want to update email address of which have not been verified, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with verified email before. NewEmailAddress response field will be filled with newest email address. */ updateUser_ByUserId(userId: string, data: UserUpdateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users [GET]_** */ getUsersByLoginId(queryParams?: { loginId?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users [POST]_** - **Substitute endpoint: _/iam/v4/public/namespaces/{namespace}/users [POST]_** - **Note:** 1. v3 & v4 introduce optional verification code 2. format difference(Pascal case => Camel case) Available Authentication Types: 1. *EMAILPASSWD*: an authentication type used for new user registration through email. Country use ISO3166-1 alpha-2 two letter, e.g. US. */ createUser_v2(data: UserCreateRequest): Promise>; /** * This endpoint search all users on the specified namespace that match the query on these fields: display name, unique display name, username or by 3rd party display name. The query length must be between 3 and 30 characters. For email address queries (i.e. contains '@'), the allowed length is 3 to 40 characters. Otherwise, the database will not be queried. The default limit value is 20. ## Searching by 3rd party platform **Note: searching by 3rd party platform display name will use exact query, not fuzzy query.** Step when searching by 3rd party platform display name: 1. set __by__ to __thirdPartyPlatform__ 2. set __platformId__ to the _supported platform id_ 3. set __platformBy__ to __platformDisplayName__ **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 ## IP Rate Limit validation This API have IP Rate Limit validation, which activates when triggered excessively from the same IP address (throw 429 http error). The default rule: 10 max request per 30 seconds (per unique IP address). To mitigate potential unexpected issues in your implementation, consider adhering to these best practices as illustrated in the following examples: * Delay invoking the Search API if the player continues typing in the search box, and only utilize the latest input provided. * Prevent players from double-clicking or making multiple clicks within a short time frame. */ getUsers_v3(queryParams?: { by?: string | null; limit?: number; offset?: number; platformBy?: string | null; platformId?: string | null; query?: string | null; }): Promise>; /** * Available Authentication Types: 1. **EMAILPASSWD**: an authentication type used for new user registration through email. **Note**: * **uniqueDisplayName**: this is required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true. * **code**: this is required when mandatoryEmailVerificationEnabled config is true. please refer to the config from /iam/v3/public/namespaces/{namespace}/config/{configKey} [GET] API. Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createUser_v3(data: UserCreateRequestV3): Promise>; /** * The verification link is sent to email address It will not send request if user email is already verified */ createUserMeVerifyLinkRequest_v3(data: SendVerificationLinkRequest): Promise>; /** * This API need the upgradeToken in request body. Available contexts for use : 1. **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the email address is already used by others by returning HTTP Status Code 409. */ createUserMeCodeRequestForward_v3(data: SendVerificationCodeRequestV3): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [POST]_** */ createBan_ByUserId(userId: string, data: BanCreateRequest): Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. action code : 10103 */ patchUserMe_v3(data: PublicUserUpdateRequestV3): Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. **Important notes:** This endpoint provides support for client that doesn't have PATCH support, i.e. UE4 before v4.23 released. If the client support PATCH method, use [PATCH] /iam/v3/public/namespaces/{namespace}/users/me instead action code : 10103 */ updateUserMe_v3(data: PublicUserUpdateRequestV3): Promise>; /** * Note: 1. My account should be full account 2. My account not linked to request headless account's third platform. After client resolving the conflict, it will call endpoint <code>/iam/v3/public/users/me/headless/linkWithProgression [POST]</code> */ getUsersMeHeadlessLinkConflict_v3(queryParams: { oneTimeLinkCode: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [GET]_** */ getBans_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/reset [POST]_** */ createUserResetPassword(data: ResetPasswordRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles [PATCH]_** */ updateRole_ByUserId(userId: string, data: string[]): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/forgot [POST]_** **Special note for publisher-game scenario:** Game Client should provide game namespace path parameter and Publisher Client should provide publisher namespace path parameter. The password reset code will be sent to the publisher account's email address. */ createUserForgotPassword(data: SendVerificationCodeRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(query by email list): _/iam/v3/public/namespaces/{namespace}/users/bulk/basic [POST]_** - **Substitute endpoint(query by user id list): _/iam/v3/admin/namespaces/{namespace}/users/search/bulk [POST]_** */ getUsersListByLoginIds(queryParams?: { loginIds?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** */ updateEnable_ByUserId(userId: string): Promise>; /** * action code: 10105 */ createUserReset_v3(data: ResetPasswordRequestV3): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** For **Deletion Account** purpose fill the reason with: - **DeactivateAccount** : if your deletion request comes from user - **AdminDeactivateAccount** : if your deletion request comes from admin */ updateDisable_ByUserId(userId: string, data: DisableUserRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(Public): _/iam/v3/public/namespaces/{namespace}/platforms/{platformId}/users/{platformUserId} [GET]_** - **Substitute endpoint(Admin): _/iam/v3/admin/namespaces/{namespace}/platforms/{platformId}/users/{platformUserId} [GET]_** - **Note:** 1. difference in V3 response, format difference: Pascal case => Camel case */ getUsersByPlatformUserId(queryParams: { platformID: string | null; platformUserID: string | null; }): Promise>; /** * **Special note for publisher-game scenario:** Game Client should provide game namespace path parameter and Publisher Client should provide publisher namespace path parameter. The password reset code will be sent to the publisher account's email address. action code : 10104 */ createUserForgot_ByNS_v3(data: ForgotPasswordRequestV3): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/password [PUT]_** */ updatePassword_ByUserId(userId: string, data: UserPasswordUpdateRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [POST]_** Access token from original namespace is needed as authorization header. Access token from designated account needed as form parameter to verify the ownership of that account. When platformID (device platfom ID) is specified, platform login method for that specific platform ID is removed. This means to protect account from second hand device usage. */ postCrosslink_ByUserId(userId: string, data: { linkingToken: string | null; platformId?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/platforms [GET]_** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms [GET]_** ## Justice Platform Account The permission ’ADMIN:NAMESPACE:{namespace}:JUSTICE:USER:{userId}’ [READ] is required in order to read the UserID who linked with the user. */ getPlatforms_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/publisher [GET]_** **Restriction:** Path Parameter *namespace* can be provided only with game namespace */ getPublisher_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint(Public): _/iam/v3/public/namespaces/{namespace}/users/{userId} [GET]_** - **Substitute endpoint(Admin): _/iam/v3/admin/namespaces/{namespace}/users/{userId} [GET]_** - **Note:** format difference in response: Pascal case => Camel case */ getUser_ByUserId_v2(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint([PUT]): _/iam/v3/public/namespaces/{namespace}/users/me [PUT]_** - **Substitute endpoint([PATCH]): _/iam/v3/public/namespaces/{namespace}/users/me [PATCH]_** - **Substitute endpoint([PATCH]): _/iam/v4/public/namespaces/{namespace}/users/me [PATCH]_** - **Note:** 1. Prefer [PATCH] if client support PATCH method 2. Difference in V3/v4 request body, format difference: Pascal case => Camel case This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {Country, DisplayName, LanguageTag} */ patchUser_ByUserId_v2(userId: string, data: UserUpdateRequest): Promise>; /** * @deprecated * This endpoint retrieve user attributes. action code: 10129 **Substitute endpoint:** /v4/public/namespaces/{namespace}/users/{userId} [GET] */ getUser_ByUserId_v3(userId: string): Promise>; /** * Note: 1. My account should be full account 2. My account not linked to headless account's third platform. */ createUserMeHeadlesLinkWithProgression_v3(data: LinkHeadlessAccountRequest): Promise>; /** * Note: 1. the max count of user ids in the request is 100 2. if platform id is not empty, the result will only contain the corresponding platform infos 3. if platform id is empty, the result will contain all the supported platform infos __Supported 3rd platforms:__ * __PSN(ps4web, ps4, ps5)__ * account id * display name * avatar * __Xbox(live, xblweb)__ * xuid or pxuid * display name * __Steam(steam, steamopenid)__ * steam id * display name * avatar * __EpicGames(epicgames)__ * epic account id * display name */ createUserPlatform_v3(data: UsersPlatformInfosRequestV3): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/information [DELETE]_** */ deleteInformation_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/information [GET]_** */ getInformation_ByUserId(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/permissions [POST]_** This endpoint will REPLACE user's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByUserId(userId: string, data: Permissions): Promise>; /** * @deprecated * Notes: - This endpoint bulk get users' basic info by userId, max allowed 100 at a time - If namespace is game, will search by game user Id, other wise will search by publisher namespace - **Result will include displayName(if it exists)** - **Substitute endpoint:** /iam/v3/public/namespaces/{namespace}/users/platforms [POST] */ createUserBulkBasic_v3(data: UserIDsRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/code/verify [POST]_** Redeems a verification code sent to a user to verify the user's contact address is correct Available ContactType : *email* or *phone* */ updateVerification_ByUserId(userId: string, data: UserVerificationRequest): Promise>; /** * Verify the registration code */ createUserCodeVerify_v3(data: VerifyRegistrationCode): Promise>; /** * action code: 10107 */ updateUserMePassword_v3(data: UserPasswordUpdateV3Request): Promise>; /** * Check user's account availability. Available field : - displayName - uniqueDisplayName - username If request include access token with user ID data, that user ID will be excluded from availability check. For example, in case user update his emailAddress, he can use his own emailAddress to update his account. Response Code : - Account Available : 404 (not found) - Account Not Available : 204 (no content) */ getUsersAvailability_v3(queryParams: { field: string | null; query: string | null; }): Promise>; /** * This endpoint will validate the request's email address. If it already been used, will response 409. If it is available, we will send a verification code to this email address. This code can be verified by this [endpoint](#operations-Users-PublicVerifyRegistrationCode). */ createUserCodeRequest_v3(data: SendRegisterVerificationCodeRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles/{roleId} [DELETE]_** */ deleteRole_ByUserId_ByRoleId(userId: string, roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles/{roleId} [POST]_** */ updateRole_ByUserId_ByRoleId(userId: string, roleId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/bans [GET]_** */ getBans_ByUserId_v2(userId: string, queryParams?: { activeOnly?: boolean | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/reset [POST]_** */ createUserResetPassword_v2(data: ResetPasswordRequest): Promise>; /** * Notes: - This endpoint retrieve the first page of the data if after and before parameters is empty - **The pagination is not working yet** **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getBans_ByUserId_v3(userId: string, queryParams?: { activeOnly?: boolean | null; after?: string | null; before?: string | null; limit?: number; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/forgot [POST]_** **Special note for publisher-game scenario:** Game Client should provide game namespace path parameter and Publisher Client should provide publisher namespace path parameter. The password reset code will be sent to the publisher account's email address. */ createUserForgotPassword_v2(data: SendVerificationCodeRequest): Promise>; /** * Will consume code if validateOnly is set false Redeems a verification code sent to a user to verify the user's contact address is correct Available ContactType : **email** action code: 10107 */ createUserMeCodeVerify_v3(data: UserVerificationRequestV3): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/logins/histories [GET]_** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/logins/histories [GET]_** Notes for this endpoint: - This endpoint retrieve the first page of the data if 'after' and 'before' parameters is empty. - The maximum value of the limit is 100 and the minimum value of the limit is 1. - This endpoint retrieve the next page of the data if we provide 'after' parameters with valid Unix timestamp. - This endpoint retrieve the previous page of the data if we provide 'before' parameter with valid data Unix timestamp. */ getLoginsHistories_ByUserId(userId: string, queryParams?: { after?: number; before?: number; limit?: number; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/code/request [POST]_** The verification code is sent to either the phone number or email address. It depends on the LoginID's value. Available contexts for use : 1. **UserAccountRegistration** a context type used for verifying email address in user account registration. It returns 409 if the email address already verified. **_It is the default context if the Context field is empty_** 2. **UpdateEmailAddress** a context type used for verify user before updating email address.(Without email address verified checking) 3. **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the loginId field's value is already used by others by returning HTTP Status Code 409. */ updateVerificationcode_ByUserId(userId: string, data: SendVerificationCodeRequest): Promise>; /** * The verification code is sent to email address Available contexts for use : 1. **UserAccountRegistration** a context type used for verifying email address in user account registration. It returns 409 if the email address already verified. **_It is the default context if the Context field is empty_** 2. **UpdateEmailAddress** a context type used for verify user before updating email address.(Without email address verified checking) 3. **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the email address is already used by others by returning HTTP Status Code 409. action code: 10116 */ createUserMeCodeRequest_v3(data: SendVerificationCodeRequestV3): Promise>; /** * Validate user's input. -------- **note:** - this endpoint will check the input validation and profanity filter service(if this is enabled) - the namespace should be publisher namespace */ createUserInputValidation_v3(data: UserInputValidationRequest): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/password [PUT]_** */ updatePassword_ByUserId_v2(userId: string, data: UserPasswordUpdateRequest): Promise>; /** * This endpoint is used to validate the user password. This endpoint validate the user password by specifying the userId and password. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ postValidate_ByUserId_v3(userId: string, data: { password: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans/{banId} [PATCH]_** */ updateEnable_ByUserId_ByBanId(userId: string, banId: string): Promise>; /** * This endpoint retrieves platform accounts linked to user. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 **Authentication:** The _**userId**_ parameter should match the one in the access token. action code: 10128 */ getPlatforms_ByUserId_v3(userId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; platformId?: string | null; }): Promise>; /** * **Restriction:** Path Parameter **namespace** can be provided only with game namespace */ getPublisher_ByUserId_v3(userId: string): Promise>; /** * action code : 10124 if set NeedVerificationCode = true, IAM will send verification code into email user can use that verification code to verify user through /iam/v3/public/namespaces/{namespace}/users/me/code/verify */ createUserMeHeadlesVerify_v3(data: UpgradeHeadlessAccountV3Request, queryParams?: { needVerificationCode?: boolean | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans/{banId} [PATCH]_** **Notes for using IAM in publisher - game studio scenarios** The endpoint allows: - The admin user in publisher namespace disables user’s ban in publisher namespace. - The admin user in game namespace disables user’s ban in game namespace. - The admin user in publisher namespace disables user’s ban in publisher namespace. Other scenarios are not supported and will return 403: Forbidden. */ updateDisable_ByUserId_ByBanId(userId: string, banId: string): Promise>; /** * This endpoint retrieves user info and linked platform accounts. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getInformation_ByUserId_v3(userId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/headless/verify [POST]_** */ updateUpgradeHeadlessAccount_ByUserId(userId: string, data: UpgradeHeadlessAccountRequest): Promise>; /** * Endpoint to validate user invitation. When not found, it could also means the invitation has expired. */ getUserInvite_ByInvitationId_v3(invitationId: string): Promise>; /** * This endpoint create user from saved roles when creating invitation and submitted data. User will be able to login after completing submitting the data through this endpoint. Available Authentication Types: EMAILPASSWD: an authentication type used for new user registration through email. **Note**: * **uniqueDisplayName**: this is required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true. Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. */ createUserInvite_ByInvitationId_v3(invitationId: string, data: UserCreateRequestV3): Promise>; /** * @deprecated * List User ID By Platform User ID This endpoint intended to list game user ID from the given namespace This endpoint return list of user ID by given platform ID and list of platform user ID Supported platform: - steam - steamopenid - ps4web - ps4 - ps5 - live - xblweb - oculus - oculusweb - facebook - google - googleplaygames - twitch - discord - apple - device - justice - epicgames - nintendo - awscognito - netflix - snapchat - oidc platform id Note: **nintendo platform user ID**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ createUser_ByPlatformId_v3(platformId: string, data: PlatformUserIdRequest, queryParams?: { rawPID?: boolean | null; rawPUID?: boolean | null; }): Promise>; /** * It is going to be **DEPRECATED**. Update Platform Account relation to current User Account. Note: Game progression data (statistics, reward, etc) associated with previous User Account will not be transferred. If the data is tight to game user ID, the user will have the game progression data. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ createPlatformLink_ByUserId_v3(userId: string, data: LinkPlatformAccountRequest): Promise>; /** * If validateOnly is set false, consume code and upgrade headless account and automatically verified the email address if it is succeeded The endpoint upgrades a headless account by linking the headless account with the email address and the password. By upgrading the headless account into a full account, the user could use the email address and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the send verification code endpoint. This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. Supported user data fields : - displayName - dateOfBirth : format YYYY-MM-DD, e.g. 2019-04-29 - country : format ISO3166-1 alpha-2 two letter, e.g. US action code : 10124 */ createUserMeHeadlesCodeVerify_v3(data: UpgradeHeadlessAccountWithVerificationCodeRequestV3): Promise>; /** * Notes for this endpoint: - This endpoint retrieve the first page of the data if <code>after</code> and <code>before</code> parameters is empty. - The maximum value of the limit is 100 and the minimum value of the limit is 1. - This endpoint retrieve the next page of the data if we provide <code>after</code> parameters with valid Unix timestamp. - This endpoint retrieve the previous page of the data if we provide <code>before</code> parameter with valid data Unix timestamp. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getLoginsHistories_ByUserId_v3(userId: string, queryParams?: { after?: number; before?: number; limit?: number; }): Promise>; /** * @deprecated * ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **googleplaygames** - **oculus** - **twitch** - **android** - **ios** - **apple** - **device** - **discord** - **awscognito** - **epicgames** - **nintendo** Unlink user's account from a specific platform. 'justice' platform might have multiple accounts from different namespaces linked. _platformNamespace_ need to be specified when the platform ID is 'justice'. Unlink user's account from justice platform will enable password token grant and password update. If you want to unlink user's account in a game namespace, you have to specify _platformNamespace_ to that game namespace. action code : 10121 */ deleteUserMePlatform_ByPlatformId_v3(platformId: string, data: UnlinkUserPlatformRequest): Promise>; /** * **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the binary ticket returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **googleplaygames**: The ticket’s value is the authorization code returned by Google play games OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **apple**: The ticket’s value is the authorization code returned by Apple OAuth. - **device**: Every device that doesn't run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. - **ps4web**: The ticket’s value is the authorization code returned by PSN OAuth. - **ps4**: The ticket’s value is the authorization code returned by PSN OAuth. - **ps5**: The ticket’s value is the authorization code returned by PSN OAuth. - **xblweb**: The ticket’s value is the authorization code returned by XBox Live OAuth. - **live**: The ticket’s value is the XSTS token. - **awscognito**: The ticket’s value is the aws cognito access token (JWT). - **epicgames**: The ticket’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **nintendo**: The ticket’s value is the id_token returned by Nintendo OAuth. - **netflix**: The ticket’s value is GAT (Gamer Access Token) returned by Netflix backend. - **snapchat**: The ticket’s value is authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. action code : 10144 */ postUserMePlatform_ByPlatformId_v3(platformId: string, data: { ticket: string | null; redirectUri?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [POST]_** **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **apple**: The ticket’s value is the authorization code returned by Apple OAuth. - **device**: Every device that does’nt run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. */ postLink_ByUserId_ByPlatformId(userId: string, platformId: string, data: { ticket: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/platforms/justice [GET]_** This endpoint gets list justice platform account by providing publisher namespace and publisher userID. */ getPlatformsJustice_ByUserId_v2(userId: string): Promise>; /** * This endpoint retrieves platform accounts linked to user. It will query all linked platform accounts. The results will be distinct and grouped by platform, and for each platform, we will select the oldest linked one. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getDistinctPlatforms_ByUserId_v3(userId: string): Promise>; /** * This endpoint gets list justice platform account by providing publisher namespace and publisher userID. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getPlatformsJustice_ByUserId_v3(userId: string): Promise>; /** * This endpoint is used to get linking status. This API need logged user and user can only request its own linking status. */ getAsyncStatus_ByRequestId_v3(requestId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [DELETE]_** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId}/all [DELETE]_** ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **oculus** - **twitch** - **android** - **ios** - **device** - **justice**: A user might have several 'justice’ platform on different namespaces. That’s why the platform_namespace need to be specified when the platform ID is ‘justice’. The platform_namespace is the designated user’s namespace. Unlink user's account with platform. 'justice' platform might have multiple accounts from different namespaces linked. platform_namespace need to be specified when the platform ID is 'justice'. Unlinking justice platform will enable password token grant and password update. */ postUnlink_ByUserId_ByPlatformId(userId: string, platformId: string, data: { platform_namespace?: string | null; }): Promise>; /** * Unlink user's account from third platform in all namespaces. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: to unlink steam third party account, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 Unlink platform account associated with a group: If user unlink platform account associated with a group, the API logic will unlink all of platform account under that group as well. example: if user unlink from ps4, the API logic will unlink ps5 and ps4web as well */ deleteAllMeUser_ByPlatformId_v3(platformId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/permissions/{resource}/{action} [DELETE]_** */ deletePermission_ByUserId_ByResource_ByAction(userId: string, resource: string, action: number): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/permissions [POST]_** This endpoint will update existing permission (bitwise OR the action) if found one with same resource, otherwise it will append a new permission Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByUserId_ByResource_ByAction(userId: string, resource: string, action: number, data: UpdatePermissionScheduleRequest): Promise>; /** * Force linking user account with platform. If this platform account was already linked to another user account, this endpoint will perform force linking and remove platform from that conflict user, not only from the current request namespace but also include all the enrolled namespaces. If current user have linked to this platform with another platform account (include once linked but it is unlinked now), it will not allow user to perform linking. ## Supported platforms: - **steam**: The platform_token’s value is the binary ticket returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the id_token returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. */ postForceMeUser_ByPlatformId_v3(platformId: string, data: { ticket: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/agerestrictions/countries/{countryCode} [GET]_** */ getAgerestrictions_ByCountryCode_v2(countryCode: string): Promise>; /** * Get age restriction by country code. It will always get by publisher namespace */ getAgerestrictionCountry_ByCountryCode_v3(countryCode: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms/justice/{targetNamespace} [GET]_** This endpoint requires the client access token as the bearer token This endpoint will support publisher access to game and game access to publisher If targetNamespace filled with publisher namespace then this endpoint will return its publisher user id and publisher namespace. If targetNamespace filled with game namespace then this endpoint will return its game user id and game namespace. **Will create game user id if not exists.** */ getPlatformJustice_ByUserId_ByTargetNamespace(userId: string, targetNamespace: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms/justice/{targetNamespace} [GET]_** This endpoint requires the client access token as the bearer token The endpoint returns user Justice platform account linked with the given user. If the user Justice platform account doesn't exist in the designated namespace, the endpoint is going to *create and return the new Justice platform account.* The newly user Justice platform account is going to be forced to perform token grant through the given user and can't perform password update ### Read Justice Platform Account UserID Without permission the UserID is going to be censored and replaced with “Redacted” text. */ updatePlatformJustice_ByUserId_ByTargetNamespace(userId: string, targetNamespace: string): Promise>; /** * This endpoint is used to generate third party login page which will redirected to establish endpoint. Supported platforms: - ps4web - xblweb - steamopenid - epicgames - facebook - twitch - google - apple - snapchat - discord - amazon - oculusweb */ getWebLinkMeUsers_ByPlatformId_v3(platformId: string, queryParams?: { clientId?: string | null; redirectUri?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [DELETE]_** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId}/all [DELETE]_** ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **oculus** - **twitch** - **android** - **ios** - **device** - **discord** Delete link of user's account with platform. 'justice' platform might have multiple accounts from different namespaces linked. platform_namespace need to be specified when the platform ID is 'justice'. Delete link of justice platform will enable password token grant and password update. */ deleteLink_ByUserId_ByPlatformId_v2(userId: string, platformId: string, data: { platform_namespace?: string | null; }): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [POST]_** **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **device**: Every device that doesn't run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. */ postLink_ByUserId_ByPlatformId_v2(userId: string, platformId: string, data: { ticket: string | null; }): Promise>; /** * Force update other account's Platform Account relation to current User Account. This endpoint can transfer progression from 3rd platform binding account's to current account. This endpoint need the same requestID which also used in [Get link status](#operations-Users-PublicGetAsyncStatus). **Authentication:** The _**userId**_ parameter should match the one in the access token. */ createPlatformLinkWithProgression_ByUserId_v3(userId: string, data: LinkPlatformAccountWithProgressionRequest): Promise>; /** * Create Justice User from Publisher User information. It will check first if Justice User on target namespace already exist. */ createUserMePlatformJustice_ByTargetNamespace_v3(targetNamespace: string): Promise>; /** * @deprecated * Get User By Platform User ID. This endpoint return user information by given platform ID and platform user ID. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: for steam network platform, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Note**: this is deprecated, substitute endpoint: /iam/v4/public/namespaces/{namespace}/platforms/{platformId}/users/{platformUserId} [GET] **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getUser_ByPlatformId_ByPlatformUserId_v3(platformId: string, platformUserId: string): Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/headless/code/verify [POST]_** The endpoint upgrades a headless account by linking the headless account with the email address and the password. By upgrading the headless account into a full account, the user could use the email address and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the send verification code endpoint. */ updateUpgradeHeadlessAccountWithVerificationCode_ByUserId(userId: string, data: UpgradeHeadlessAccountWithVerificationCodeRequest): Promise>; /** * This endpoint is used to process third party account link, this endpoint will return the link status directly instead of redirecting to the original page. The param **state** comes from the response of <code>/users/me/platforms/{platformId}/web/link</code> Supported platforms: - ps4web - xblweb - steamopenid - epicgames - facebook - twitch - google - apple - snapchat - discord - amazon - oculusweb */ postWebLinkProcesMeUser_ByPlatformId_v3(platformId: string, data: { state: string | null; code?: string | null; }): Promise>; /** * This endpoint is used by third party to redirect the code for the purpose of linking the account third party to IAM account. Supported platforms: - ps4web - xblweb - steamopenid - epicgames - facebook - twitch - google - apple - snapchat - discord - amazon - oculusweb */ getWebLinkEstablishMeUsers_ByPlatformId_v3(platformId: string, queryParams: { state: string | null; code?: string | null; }): Promise>; } /** * AUTO GENERATED */ declare class UsersV4$ { private axiosInstance; private namespace; private useSchemaValidation; constructor(axiosInstance: AxiosInstance, namespace: string, useSchemaValidation?: boolean); /** * This endpoint is used to invite a game studio admin user with new namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. Request body details: - emailAddress: email address of the user to be invited - namespace: new namespace of the user to be created - namespaceDisplayName: display name of the new namespace - additionalData(optional): for utm parameter data The invited users will also be assigned with "User" role by default. */ createUserInvite_v4(data: PublicInviteUserRequestV4): Promise>; /** * Create a new user with unique email address and username. **Required attributes:** - authType: possible value is EMAILPASSWD - emailAddress: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. - uniqueDisplayName: required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true, please refer to the rule from /v3/public/inputValidations API. - code: required when mandatoryEmailVerificationEnabled config is true, please refer to the config from /iam/v3/public/namespaces/{namespace}/config/{configKey} [GET] API. **Not required attributes:** - displayName: Please refer to the rule from /v3/public/inputValidations API. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createUser_v4(data: CreateUserRequestV4): Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. action code : 10103 */ patchUserMe_v4(data: PublicUserUpdateRequestV3): Promise>; /** * Create a test user and not send verification code email **Required attributes:** - verified: this new user is verified or not - authType: possible value is EMAILPASSWD - emailAddress: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. **Not required attributes:** - displayName: Please refer to the rule from /v3/public/inputValidations API. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createTestUser_v4(data: CreateTestUserRequestV4): Promise>; /** * This endpoint only returns user's public information. action code: 10129 */ getUser_ByUserId_v4(userId: string): Promise>; /** * The endpoint to update my email address. It requires a verification code from <code>/users/me/code/request</code> with **UpdateEmailAddress** context. */ updateUserMeEmail_v4(data: EmailUpdateRequestV4): Promise>; /** * This is a forward version for code verify. The endpoint upgrades a headless account by linking the headless account with the email address, username, and password. By upgrading the headless account into a full account, the user could use the email address, username, and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the [send verification code endpoint](#operations-Users-PublicSendCodeForwardV3). This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. */ createUserMeHeadlesCodeVerifyForward_v4(data: UpgradeHeadlessAccountWithVerificationCodeForwardRequestV4): Promise>; /** * (Only for test)This endpoint is used to remove trusted device. This endpoint Requires device_token in cookie */ deleteUserMeMfaDevice_v4(): Promise>; /** * This endpoint is used to get user enabled factors. */ getUsersMeMfaFactor_v4(): Promise>; /** * This endpoint is used to make 2FA factor default. */ postUserMeMfaFactor_v4(data: { factor: string | null; }): Promise>; /** * This endpoint will get user's' MFA status. */ getUsersMeMfaStatus_v4(): Promise>; /** * @deprecated * This endpoint will get user's' MFA status. --------- **Substitute endpoint**: /iam/v4/public/namespaces/{namespace}/users/me/mfa/status [GET] */ createUserMeMfaStatus_v4(): Promise>; /** * @deprecated * This endpoint is used to get 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ getUsersMeMfaBackupCode_v4(): Promise>; /** * @deprecated * This endpoint is used to generate 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ createUserMeMfaBackupCode_v4(): Promise>; /** * This endpoint is used to send email code. ---------------- Supported values of action: * ChangePassword * DisableMFAEmail */ postUserMeMfaEmailCode_v4(data: { action?: string | null; languageTag?: string | null; }): Promise>; /** * Upgrade headless account to full account without verifying email address. Client does not need to provide verification code which sent to email address. action code : 10124 */ createUserMeHeadlesVerify_v4(data: UpgradeHeadlessAccountRequestV4): Promise>; /** * This endpoint is used to get existing 8-digits backup codes. Each codes is a one-time code and will be deleted once used. The codes will be sent through linked email. */ getUsersMeMfaBackupCodes_v4(queryParams?: { languageTag?: string | null; }): Promise>; /** * This endpoint is used to generate 8-digits backup codes. Each codes is a one-time code and will be deleted once used. The codes will be sent through linked email. */ createUserMeMfaBackupCode_ByNS_v4(queryParams?: { languageTag?: string | null; }): Promise>; /** * This endpoint is used to enable 2FA email. */ postUserMeMfaEmailEnable_v4(data: { code: string | null; }): Promise>; /** * This endpoint is used to disable 2FA email. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ createUserMeMfaEmailDisable_v4(data: DisableMfaRequest): Promise>; /** * This endpoint create user from saved roles when creating invitation and submitted data. User will be able to login after completing submitting the data through this endpoint. Available Authentication Types: EMAILPASSWD: an authentication type used for new user registration through email. **Note**: * **uniqueDisplayName**: this is required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true. Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. Required attributes: - authType: possible value is EMAILPASSWD (see above) - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. - displayName: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. */ createUserInvite_ByInvitationId_v4(invitationId: string, data: CreateUserRequestV4): Promise>; /** * List User ID By Platform User ID This endpoint intended to list game user ID from the given namespace This endpoint return list of user ID by given platform ID and list of platform user ID, the max count is 100. Supported platform: - steam - steamopenid - ps4web - ps4 - ps5 - live - xblweb - oculus - if query by app user id, please set the param **pidType** to **OCULUS_APP_USER_ID** - oculusweb - facebook - google - googleplaygames - twitch - discord - apple - device - justice - epicgames - nintendo - awscognito - netflix - snapchat - oidc platform id Note: **nintendo platform user ID**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 <br> If the request body exceed the max limitation, the max count will be in response body's messageVariables: "messageVariables": {"maxCount": "100"} */ createUser_ByPlatformId_v4(platformId: string, data: PlatformUserIdRequestV4, queryParams?: { rawPUID?: boolean | null; }): Promise>; /** * The endpoint upgrades a headless account by linking the headless account with the email address, username, and password. By upgrading the headless account into a full account, the user could use the email address, username, and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the [send verification code endpoint](#operations-Users-PublicSendVerificationCodeV3). This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. Supported user data fields: - displayName - dateOfBirth : format YYYY-MM-DD, e.g. 2019-04-29 - country : format ISO3166-1 alpha-2 two letter, e.g. US action code : 10124 */ createUserMeHeadlesCodeVerify_v4(data: UpgradeHeadlessAccountWithVerificationCodeRequestV4): Promise>; /** * This endpoint will verify user's' MFA code and generate a MFA token for the action. */ postUserMeMfaChallengeVerify_v4(data: { code?: string | null; factor?: string | null; }): Promise>; /** * This endpoint is used to generate a secret key for 3rd-party authenticator app. A QR code URI is also returned so that frontend can generate QR code image. */ createUserMeMfaAuthenticatorKey_v4(): Promise>; /** * @deprecated * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_v4(): Promise>; /** * This endpoint is used to disable 2FA backup codes. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaBackupCodeDisable_v4(data: DisableMfaRequest): Promise>; /** * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_ByNS_v4(queryParams?: { languageTag?: string | null; }): Promise>; /** * @deprecated * This endpoint is used to download backup codes. */ getUsersMeMfaBackupCodeDownload_v4(): Promise>; /** * This endpoint is used to enable 2FA authenticator. ---------- Prerequisites: - Generate the secret key/QR code uri by **_/iam/v4/public/namespaces/{namespace}/users/me/mfa/authenticator/key_** - Consume the secret key/QR code by an authenticator app - Get the code from the authenticator app */ postUserMeMfaAuthenticatorEnable_v4(data: { code: string | null; }): Promise>; /** * This endpoint is used to disable 2FA authenticator. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaAuthenticatorDisable_v4(data: DisableMfaRequest): Promise>; /** * Get User By Platform User ID. This endpoint return user information by given platform ID and platform user ID. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: for steam network platform, you can use steamnetwork / steam / steamopenid as platformId path parameter. If the target platform is not linked to the current user, will only return public information. ---------- **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getUser_ByPlatformId_ByPlatformUserId_v4(platformId: string, platformUserId: string): Promise>; } /** * AUTO GENERATED */ declare function InputValidationsApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * No role required This endpoint is to get list of input validation configuration. <code>regex</code> parameter will be returned if <code>isCustomRegex</code> is true. Otherwise, it will be empty. */ getInputValidations_v3: (queryParams?: { defaultOnEmpty?: boolean | null; languageCode?: string | null; }) => Promise>; /** * This endpoint is to get input validation configuration by field. */ getInputValidation_ByField_v3: (field: string) => Promise>; }; /** * AUTO GENERATED */ declare function OAuth20Api(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint serves public keys for verifying JWT access tokens generated by this service. When a client application wants to verify a JWT token, it needs to get the 'kid' value found in the JWT token header and use it to look up the corresponding public key from a set returned by this endpoint. The client application can then use that public key to verify the JWT. A client application might cache the keys so it doesn't need to do request every time it needs to verify a JWT token. If a client application caches the keys and a key with the same 'kid' cannot be found in the cache, it should then try to refresh the keys by making a request to this endpoint again. Please refer to the RFC for more information about JWK (JSON Web Key): https://tools.ietf.org/html/rfc7517 action code : 10709 */ getOauthJwks_v3: () => Promise>; /** * This endpoint supports grant type: 1. Grant Type == <code>authorization_code</code>: It generates the user token by given the authorization code which generated in "/iam/v3/authenticate" API response. It should also pass in the redirect_uri, which should be the same as generating the authorization code request. 2. Grant Type == <code>password</code>: The grant type to use for authenticating a user, whether it's by email / username and password combination or through platform. 3. Grant Type == <code>refresh_token</code>: Used to get a new access token for a valid refresh token. 4. Grant Type == <code>client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. 5. Grant Type == <code>urn:ietf:params:oauth:grant-type:extend_client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. It only allows publisher/studio namespace client. In generated token: 1. There wil be no roles, namespace_roles & permission. 2. The scope will be fixed as 'extend'. 3. There will have a new field 'extend_namespace', the value is from token request body. ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the targeted resource server. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **client_id**. The UserID. The sub is omitted if the token is generated from client credential - **scope**. The scope of the access request, expressed as a list of space-delimited, case-sensitive strings ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. ## Device Cookie Validation _**For grant type "password" only**_ Device Cookie is used to protect the user account from brute force login attack, <a target="_blank" href="https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies">more detail from OWASP<a>. This endpoint will read device cookie from request header **Auth-Trust-Id**. If device cookie not found, it will generate a new one and set it into response body **auth_trust_id** when successfully login. ## Track Login History This endpoint will track login history to detect suspicious login activity, please provide **Device-Id** (alphanumeric) in request header parameter otherwise it will set to "unknown". Align with General Data Protection Regulation in Europe, user login history will be kept within 28 days by default" ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Response note If it is a user token request and user hasn't accepted required legal policy, the field <code>is_comply</code> will be false in response and responsed token will have no permission. action code: 10703 */ postOauthToken_v3: (data: { grant_type: "authorization_code" | "client_credentials" | "password" | "refresh_token" | "urn:ietf:params:oauth:grant-type:extend_client_credentials"; additionalData?: string | null; client_id?: string | null; client_secret?: string | null; code?: string | null; code_verifier?: string | null; extendNamespace?: string | null; extend_exp?: boolean | null; password?: string | null; redirect_uri?: string | null; refresh_token?: string | null; scope?: string | null; username?: string | null; }) => Promise>; /** * This endpoint revokes a token. This endpoint requires authorized requests header with Basic Authentication from client that establish the token. action code: 10706 */ postOauthRevoke_v3: (data: { token: string | null; }) => Promise>; /** * This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. */ postOauthVerify_v3: (data: { token: string | null; }) => Promise>; /** * Send 2FA code This endpoint is used for sending 2FA code. */ postOauthMfaCode_v3: (data: { clientId: string | null; factor: string | null; mfaToken: string | null; }) => Promise>; /** * Initializes OAuth2.0 authorization code flow The endpoint stores authorization request and redirects to login page with the authorization request id. The user can then do the authentication on the login page. The user will be redirected back to the requesting client with authorization code if successfully authenticated. Only authorization code flow supported by this endpoint, implicit flow is not supported. - **Authorize success**: redirects to login page with the following information: ?request_id={authorization_request_id} - **Authorize failure**: redirects to the given redirect uri with the following information: ?error={error_code}&error_description={error description} For Public Client case, it's mandatory to fill **code_challenge** to avoid authorization code interception attack. Please refer to the RFC for more information about Proof Key for Code Exchange(PKCE): https://datatracker.ietf.org/doc/html/rfc7636 Following are the error code based on the specification: - invalid_request: The request is missing a required parameter, includes an invalid parameter value, includes a parameter more than once, or is otherwise malformed. - server_error: The authorization server encountered an unexpected condition that prevented it from fulfilling the request. - unauthorized_client: The client is not authorized to request a token using this method. - access_denied: The resource owner or authorization server denied the request. - invalid_scope: The requested scope is invalid, unknown, or malformed. - unsupported_response_type: The authorization server does not support obtaining a token using this method. - temporarily_unavailable: The authorization server is currently unable to handle the request due to a temporary overloading or maintenance of the server. Please refer to the RFC for more information about authorization code flow: https://tools.ietf.org/html/rfc6749#section-4.1 action code: 10701 */ getOauthAuthorize_v3: (queryParams: { client_id: string | null; response_type: "code"; blockedPlatformId?: string | null; code_challenge?: string | null; code_challenge_method?: "S256" | "plain"; createHeadless?: boolean | null; loginWebBased?: boolean | null; nonce?: string | null; oneTimeLinkCode?: string | null; redirect_uri?: string | null; scope?: string | null; state?: string | null; target_auth_page?: string | null; useRedirectUriAsLoginUrlWhenLocked?: boolean | null; }) => Promise>; /** * This endpoint returns information about an access token intended to be used by resource servers or other internal servers. This endpoint requires authorized requests header with valid basic or bearer token. action code : 10705 */ postOauthIntrospect_v3: (data: { token: string | null; }) => Promise>; /** * Verify 2FA code This endpoint is used for verifying 2FA code. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token */ postOauthMfaVerify_v3: (data: { code: string | null; factor: string | null; mfaToken: string | null; rememberDevice: boolean | null; }) => Promise>; /** * This endpoint will return a list of revoked users and revoked tokens. List of revoked tokens in bloom filter format. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. The bloom filter uses MurmurHash3 algorithm for hashing the values action code : 10708 */ getOauthRevocationlist_v3: () => Promise>; /** * Change 2FA method This endpoint is used for change 2FA method. Only enabled methods are accepted. Supported methods: - authenticator - backupCode - email */ postOauthMfaFactorChange_v3: (data: { factor: string | null; mfaToken: string | null; }) => Promise>; /** * # This endpoint is in ALPHA, avoid using this endpoint fow now, reach out to AB support for inquiries Simultaneous login flow. The primary goals of this project are to entitle players to authenticate on a native PC platform(Steam/Epic) and the PlayStation platform, link their accounts, and provide support for platform sync with a valid 3rd platform access token. ## Given a valid native ticket and empty simultaneous ticket, these cases will be failed - Native ticket's account is not linked AGS account yet - Native ticket's account is linked AGS account, but AGS account is not linked simultaneous platform yet - Native ticket's account is linked AGS account, AGS account is linked simultaneous platform but there is no available simultaneous token.(only if this platform is expected to store the platform token) ## Given a valid native ticket and empty simultaneous ticket, this case will be success - Native ticket's account already linked AGS account, this AGS account already linked simultaneous platform. There is valid simultaneous token.(this is required only when this simultaneous is expected to cache platform token) ## Given a valid native ticket token and valid simultaneous ticket, these cases will be failed #### Native ticket's account is already linked with AGS account - Native linked AGS account is linked this simultaneous platform but is different with simultaneous ticket's account - Native linked AGS account is not linked with simultaneous but has a linking history with simultaneous platform and it is different with simultaneous ticket's account #### Native ticket's account is not linked with AGS account and Simultaneous ticket's account is already linked wth AGS account - Simultaneous linked AGS account is linked this native platform but is different with native ticket's account - Simultaneous linked AGS account is not linked with native but has a linking history with native platform and it is different with native ticket's account ## Given a valid native ticket and valid simultaneous ticket, these cases will be success - Native ticket's account & Simultaneous ticket's account are both not linked to AGS account yet - Native ticket's account & Simultaneous ticket's account are already linked to same AGS account */ postOauthSimultaneousLogin_v3: (data: { nativePlatform: "epicgames" | "steam"; nativePlatformTicket: string | null; simultaneousPlatform?: string | null; simultaneousTicket?: string | null; }) => Promise>; /** * This is a forward version for '/mfa/verify'. If there is any error, it will redirect to login website with error details. If success, it will forward to auth request redirect url If got error, it will forward to login website Verify 2FA code This endpoint is used for verifying 2FA code. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token */ postOauthMfaVerifyForward_v3: (data: { clientId: string | null; code: string | null; factor: string | null; mfaToken: string | null; defaultFactor?: string | null; factors?: string | null; rememberDevice?: boolean | null; }) => Promise>; /** * Platform token grant specifically used for performing token grant using platform, e.g. Steam, Justice, etc. The endpoint automatically create an account if the account associated with the platform is not exists yet. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. For publisher-game namespace schema : Specify only either platform_token or device_id. Device token grant should be requested along with device_id parameter against game namespace. Another 3rd party platform token grant should be requested along with platform_token parameter against publisher namespace. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Supported platforms: - **steam**: The platform_token’s value is the binary ticket returned by Steam. If this ticket was generated by Steam GetAuthTicketForWebApi with version >= 1.57, then platform token should use this style: <code>{identity}:{ticket}</code>, the <code>{identity}</code> was the parameter to call GetAuthTicketForWebApi when the ticket was created. Note: Do not contain <code>:</code> in this <code>{identity}</code>. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code or idToken returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code or idToken returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code or idToken returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the id_token returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. ## Account Group Several platforms are grouped under account groups. The accounts on these platforms have the same platform user id. Login using one of these platform will returns the same IAM user. Following is the current registered account grouping: - Steam group(steamnetwork): - steam - steamopenid - PSN group(psn) - ps4web - ps4 - ps5 - XBOX group(xbox) - live - xblweb - Oculus group(oculusgroup) - oculus - oculusweb ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the client ID. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **sub**. The UserID. The sub is omitted if the token is generated from client credential ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. action code : 10704 */ postTokenOauth_ByPlatformId_v3: (platformId: string, data: { additionalData?: string | null; client_id?: string | null; createHeadless?: boolean | null; device_id?: string | null; macAddress?: string | null; platform_token?: string | null; serviceLabel?: number; skipSetCookie?: boolean | null; }) => Promise>; /** * Generate url to request auth code from third party platform ## Supported platforms: - **steamopenid**This endpoint redirects to steam login page, then redirect back to platform authenticate endpoint after successfully authenticating user steam. - **xblweb**This endpoint redirects to xbox login page, then redirect back to platform authenticate endpoint after successfully authenticating xbox user. - **ps4web**This endpoint redirects to psn login page, then redirect back to platform authenticate endpoint after successfully authenticating psn user. - **epicgames**This endpoint redirects to Epicgames OAuth login page. then redirect to platform authenticate endpoint after successfully authenticating an Epicgames credential - **twitch**This endpoint redirects to twitch login page, then redirect back to platform authenticate endpoint after successfully authenticating twitch user. - **azure**This endpoint redirects to azure login page, then redirect back to platform authenticate(saml) endpoint after successfully authenticating azure user. - **facebook**This endpoint redirects to facebook login page, then redirect back to platform authenticate endpoint after successfully authenticating facebook user. - **google**This endpoint redirects to google login page, then redirect back to platform authenticate endpoint after successfully authenticating google user. - **snapchat**This endpoint redirects to snapchat login page, then redirect back to platform authenticate endpoint after successfully authenticating snapchat user. - **discord**This endpoint redirects to discord login page, then redirect back to platform authenticate endpoint after successfully authenticating discord user. - **amazon**This endpoint redirects to amazon login page, then redirect back to platform authenticate endpoint after successfully authenticating amazon user. - **oculusweb**This endpoint redirects to oculus login page, then redirect back to Login Website page after successfully authenticating oculus user. action code : 10702' */ getAuthorizeOauth_ByPlatformId_v3: (platformId: string, queryParams: { request_id: string | null; client_id?: string | null; redirect_uri?: string | null; }) => Promise>; /** * Retrieve User Third Party Platform Token This endpoint used for retrieving third party platform token for user that login using third party, if user have not link requested platform in game namespace, will try to retrieving third party platform token from publisher namespace. Passing platform group name or it's member will return same access token that can be used across the platform members. The third party platform and platform group covered for this is: - (psn) ps4web - (psn) ps4 - (psn) ps5 - epicgames - twitch - awscognito - <amazon/li> - eaorigin - snapchat - twitch - live **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getPlatformTokenOauth_ByUserId_ByPlatformId_v3: (userId: string, platformId: string) => Promise>; }; /** * AUTO GENERATED */ declare function OAuth20ExtensionApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint is used to remove **access_token**, **refresh_token** from cookie. */ createLogout_v3: () => Promise>; /** * This endpoint is being used to authenticate a user account. It validates user's email / username and password. Deactivated or login-banned users are unable to login. Redirect URI and Client ID must be specified as a pair and only used to redirect to the specified redirect URI in case the requestId is no longer valid. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. Action code: 10801 */ postAuthenticate_v3: (data: { password: string | null; request_id: string | null; user_name: string | null; client_id?: string | null; extend_exp?: boolean | null; redirect_uri?: string | null; }) => Promise>; /** * This endpoint is being used to create headless account after 3rd platform authenticated, and response token . The 'linkingToken' in request body is received from "/platforms/{platformId}/token" when 3rd platform account is not linked to justice account yet. */ postHeadlesToken_v3: (data: { linkingToken: string | null; additionalData?: string | null; extend_exp?: boolean | null; }) => Promise>; /** * This endpoint is being used to generate target token. It requires basic header with ClientID and Secret, it should match the ClientID when call <code>/iam/v3/namespace/{namespace}/token/request</code> The code should be generated from <code>/iam/v3/namespace/{namespace}/token/request</code>. */ postTokenExchange_v3: (data: { code: string | null; additionalData?: string | null; }) => Promise>; /** * In login website based flow, after account upgraded, we need this API to handle the forward */ postUpgradeForward_v3: (data: { client_id: string | null; upgrade_success_token: string | null; }) => Promise>; /** * This endpoint get country location based on the request. */ getLocationCountry_v3: () => Promise>; /** * This endpoint is being used to request the one time code [8 length] for headless account to link or upgrade to a full account. Should specify the target platform id and current user should already linked to this platform. Current user should be a headless account. ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **googleplaygames** - **oculus** - **twitch** - **discord** - **android** - **ios** - **apple** - **device** - **justice** - **epicgames** - **ps4** - **ps5** - **nintendo** - **awscognito** - **live** - **xblweb** - **netflix** - **snapchat** */ postLinkCodeRequest_v3: (data: { platformId: string | null; redirectUri?: string | null; state?: string | null; }) => Promise>; /** * This endpoint is being used to validate one time link code. */ postLinkCodeValidate_v3: (data: { oneTimeLinkCode: string | null; }) => Promise>; /** * This endpoint is being used to generate user's token by one time link code. It requires a code which can be generated from <code>/iam/v3/link/code/request</code> or <code>/iam/v3/public/users/me/link/forward</code>. This endpoint support creating transient token by utilizing **isTransient** param: **isTransient=true** will generate a transient token with a short Time Expiration and without a refresh token **isTransient=false** will consume the one-time code and generate the access token with a refresh token. */ postLinkTokenExchange_v3: (data: { client_id: string | null; oneTimeLinkCode: string | null; additionalData?: string | null; isTransient?: boolean | null; }) => Promise>; /** * This endpoint is being used to authenticate a user account and perform platform link. It validates user's email / username and password. If user already enable 2FA, then invoke _/mfa/verify_ using **mfa_token** from this endpoint response. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. */ postAuthenticateWithLink_v3: (data: { client_id: string | null; linkingToken: string | null; password: string | null; username: string | null; extend_exp?: boolean | null; }) => Promise>; /** * This endpoint is being used to authenticate a user account and perform platform link. It validates user's email / username and password. If user already enable 2FA, then invoke _/mfa/verify_ using **mfa_token** from this endpoint response. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. */ postAuthenticateWithLinkForward_v3: (data: { client_id: string | null; linkingToken: string | null; password: string | null; username: string | null; extend_exp?: boolean | null; }) => Promise>; /** * This endpoint is being used to request the code to exchange a new token. The target new token's clientId should NOT be same with current using one. Path namespace should be target namespace. Client ID should match the target namespace. The code in response can be consumed by <code>/iam/v3/token/exchange</code> */ postTokenRequest_v3: (data: { client_id: string | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: "S256" | "plain"; }) => Promise>; /** * This endpoint authenticates user platform. It validates user to its respective platforms. Deactivated or login-banned users are unable to login. If already linked with justice account or match SSO condition, will redirect to client's redirect url with code. then invoke '/iam/v3/oauth/token' with grant_type=authorization_code If already not linked with justice account and not match SSO condition, will redirect to client's account linking page ## Supported platforms: - **steamopenid**Steam login page will redirects to this endpoint after login success as previously defined on openID request parameter <code>openid.return_to</code> when request login to steam https://openid.net/specs/openid-authentication-2_0.html#anchor27 - **ps4web**PS4 login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> https://ps4.siedev.net/resources/documents/WebAPI/1/Auth_WebAPI-Reference/0002.html#0GetAccessTokenUsingAuthorizationCode - **xblweb**XBL login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **epicgames**Epicgames login page will redirects to this endpoint after login success or an error occurred. If error, it redirects to the login page. - **twitch**Twitch login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **facebook**Facebook login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **google**Google login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **snapchat**Snapchat login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> - **discord**Discord login page will redirects to this endpoint after login success as previously defined on authorize request parameter <code>redirect_uri</code> action code : 10709 */ getAuthenticate_ByPlatformId_v3: (platformId: string, queryParams: { state: string | null; code?: string | null; error?: string | null; assoc_handle?: string | null; claimed_id?: string | null; identity?: string | null; mode?: string | null; ns?: string | null; op_endpoint?: string | null; response_nonce?: string | null; return_to?: string | null; sig?: string | null; signed?: string | null; }) => Promise>; /** * This endpoint will validate the third party platform token, for some platforms will also refresh the token stored in IAM, it will not generate any event or AB access/refresh token. This endpoint can be used by game client to refresh third party token if game client got platform token not found error, for example got 404 platform token not found from IAP/DLC. ## Platforms will refresh stored token: - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **epicgames**: The platform_token’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **amazon**: The platform_token’s value is authorization code. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. */ postTokenVerify_ByPlatformId_v3: (platformId: string, data: { platform_token: string | null; }) => Promise>; }; /** * AUTO GENERATED */ declare function OAuth20V4Api(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint supports grant type: 1. Grant Type == <code>authorization_code</code>: It generates the user token by given the authorization code which generated in "/iam/v3/authenticate" API response. It should also pass in the redirect_uri, which should be the same as generating the authorization code request. 2. Grant Type == <code>password</code>: The grant type to use for authenticating a user, whether it's by email / username and password combination or through platform. 3. Grant Type == <code>refresh_token</code>: Used to get a new access token for a valid refresh token. 4. Grant Type == <code>client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. 5. Grant Type == <code>urn:ietf:params:oauth:grant-type:extend_client_credentials</code>: It generates a token by checking the client credentials provided through Authorization header. It only allows publisher/studio namespace client. In generated token: 1. There wil be no roles, namespace_roles & permission. 2. The scope will be fixed as 'extend'. 3. There will have a new field 'extend_namespace', the value is from token request body. 6. Grant Type == <code>urn:ietf:params:oauth:grant-type:login_queue_ticket</code>: It generates a token by validating the login queue ticket against login queue service. ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the targeted resource server. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **client_id**. The UserID. The sub is omitted if the token is generated from client credential - **scope**. The scope of the access request, expressed as a list of space-delimited, case-sensitive strings ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. ## Device Cookie Validation _**For grant type "password" only**_ Device Cookie is used to protect the user account from brute force login attack, <a target="_blank" href="https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies">more detail from OWASP<a>. This endpoint will read device cookie from request header **Auth-Trust-Id**. If device cookie not found, it will generate a new one and set it into response body **auth_trust_id** when successfully login. ## Track Login History This endpoint will track login history to detect suspicious login activity, please provide **Device-Id** (alphanumeric) in request header parameter otherwise it will set to "unknown". Align with General Data Protection Regulation in Europe, user login history will be kept within 28 days by default" ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Response note If it is a user token request and user hasn't accepted required legal policy, the field <code>is_comply</code> will be false in response and responsed token will have no permission. action code: 10703 * * #### Response type: * - `TokenWithDeviceCookieResponseV3` * - `LoginQueueTicketResponse` */ postOauthToken_v4: (data: { grant_type: "authorization_code" | "client_credentials" | "password" | "refresh_token" | "urn:ietf:params:oauth:grant-type:extend_client_credentials" | "urn:ietf:params:oauth:grant-type:login_queue_ticket"; additionalData?: string | null; client_id?: string | null; client_secret?: string | null; code?: string | null; code_verifier?: string | null; extendNamespace?: string | null; extend_exp?: boolean | null; login_queue_ticket?: string | null; password?: string | null; redirect_uri?: string | null; refresh_token?: string | null; scope?: string | null; username?: string | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: "S256" | "plain"; }) => Promise>; /** * Verify 2FA code This endpoint is used for verifying 2FA code. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthMfaVerify_v4: (data: { code: string | null; factor: string | null; mfaToken: string | null; rememberDevice: boolean | null; }) => Promise>; /** * This endpoint is being used to create headless account after 3rd platform authenticated, and response token . The 'linkingToken' in request body is received from "/platforms/{platformId}/token" when 3rd platform account is not linked to justice account yet. * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthHeadlesToken_v4: (data: { linkingToken: string | null; additionalData?: string | null; extend_exp?: boolean | null; }) => Promise>; /** * This endpoint is being used to generate target token. It requires basic header with ClientID and Secret, it should match the ClientID when call <code>/iam/v3/namespace/{namespace}/token/request</code> The code should be generated from <code>/iam/v3/namespace/{namespace}/token/request</code>. * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthTokenExchange_v4: (data: { code: string | null; additionalData?: string | null; }) => Promise>; /** * # This endpoint is in ALPHA, avoid using this endpoint fow now, reach out to AB support for inquiries Simultaneous login flow. The primary goals of this project are to entitle players to authenticate on a native PC platform(Steam/Epic) and the PlayStation platform, link their accounts, and provide support for platform sync with a valid 3rd platform access token. ## Given a valid native ticket and empty simultaneous ticket, these cases will be failed - Native ticket's account is not linked AGS account yet - Native ticket's account is linked AGS account, but AGS account is not linked simultaneous platform yet - Native ticket's account is linked AGS account, AGS account is linked simultaneous platform but there is no available simultaneous token.(only if this platform is expected to store the platform token) ## Given a valid native ticket and empty simultaneous ticket, this case will be success - Native ticket's account already linked AGS account, this AGS account already linked simultaneous platform. There is valid simultaneous token.(this is required only when this simultaneous is expected to cache platform token) ## Given a valid native ticket token and valid simultaneous ticket, these cases will be failed #### Native ticket's account is already linked with AGS account - Native linked AGS account is linked this simultaneous platform but is different with simultaneous ticket's account - Native linked AGS account is not linked with simultaneous but has a linking history with simultaneous platform and it is different with simultaneous ticket's account #### Native ticket's account is not linked with AGS account and Simultaneous ticket's account is already linked wth AGS account - Simultaneous linked AGS account is linked this native platform but is different with native ticket's account - Simultaneous linked AGS account is not linked with native but has a linking history with native platform and it is different with native ticket's account ## Given a valid native ticket and valid simultaneous ticket, these cases will be success - Native ticket's account & Simultaneous ticket's account are both not linked to AGS account yet - Native ticket's account & Simultaneous ticket's account are already linked to same AGS account * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthSimultaneousLogin_v4: (data: { nativePlatform: "epicgames" | "steam"; nativePlatformTicket: string | null; simultaneousPlatform?: string | null; simultaneousTicket?: string | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: "S256" | "plain"; }) => Promise>; /** * This endpoint is being used to authenticate a user account and perform platform link. It validates user's email / username and password. If user already enable 2FA, then invoke _/mfa/verify_ using **mfa_token** from this endpoint response. ## Device Cookie Validation Device Cookie is used to protect the user account from brute force login attack, [more detail from OWASP](https://owasp.org/www-community/Slow_Down_Online_Guessing_Attacks_with_Device_Cookies). This endpoint will read device cookie from cookie **auth-trust-id**. If device cookie not found, it will generate a new one and set it into cookie when successfully authenticate. * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postOauthAuthenticateWithLink_v4: (data: { client_id: string | null; linkingToken: string | null; password: string | null; username: string | null; extend_exp?: boolean | null; }) => Promise>; /** * Platform token grant specifically used for performing token grant using platform, e.g. Steam, Justice, etc. The endpoint automatically create an account if the account associated with the platform is not exists yet. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. For publisher-game namespace schema : Specify only either platform_token or device_id. Device token grant should be requested along with device_id parameter against game namespace. Another 3rd party platform token grant should be requested along with platform_token parameter against publisher namespace. ## 2FA remember device To remember device for 2FA, should provide cookie: device_token or header: Device-Token ## Supported platforms: - **steam**: The platform_token’s value is the binary ticket returned by Steam. If this ticket was generated by Steam GetAuthTicketForWebApi with version >= 1.57, then platform token should use this style: <code>{identity}:{ticket}</code>, the <code>{identity}</code> was the parameter to call GetAuthTicketForWebApi when the ticket was created. Note: Do not contain <code>:</code> in this <code>{identity}</code>. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code or idToken returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code or idToken returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code or idToken returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the id_token returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. ## Account Group Several platforms are grouped under account groups. The accounts on these platforms have the same platform user id. Login using one of these platform will returns the same IAM user. Following is the current registered account grouping: - Steam group(steamnetwork): - steam - steamopenid - PSN group(psn) - ps4web - ps4 - ps5 - XBOX group(xbox) - live - xblweb - Oculus group(oculusgroup) - oculus - oculusweb ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - 8: Suspicious Login - **aud**. The aud is the client ID. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **sub**. The UserID. The sub is omitted if the token is generated from client credential ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. action code : 10704 * * #### Response type: * - `TokenResponseV3` * - `LoginQueueTicketResponse` */ postTokenOauth_ByPlatformId_v4: (platformId: string, data: { additionalData?: string | null; client_id?: string | null; createHeadless?: boolean | null; device_id?: string | null; macAddress?: string | null; platform_token?: string | null; serviceLabel?: number; skipSetCookie?: boolean | null; }, queryParams?: { code_challenge?: string | null; code_challenge_method?: "S256" | "plain"; }) => Promise>; }; /** * AUTO GENERATED */ declare function OAuthApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * @deprecated * ## The endpoint is going to be deprecated This endpoint serves public keys for verifying JWT access tokens generated by this service. When a client application wants to verify a JWT token, it needs to get the 'kid' value found in the JWT token header and use it to look up the corresponding public key from a set returned by this endpoint. The client application can then use that public key to verify the JWT. A client application might cache the keys so it doesn't need to do request every time it needs to verify a JWT token. If a client application caches the keys and a key with the same 'kid' cannot be found in the cache, it should then try to refresh the keys by making a request to this endpoint again. Please refer to the RFC for more information about JWK (JSON Web Key): https://tools.ietf.org/html/rfc7517 ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/jwks [GET]_** */ getOauthJwks: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: /iam/v3/oauth/token [POST]** - **Note: difference in V3 response:** format difference(Pascal case => Camel case): permissions field from Action => action, Resource => resource This endpoint requires all requests to have <code>Authorization</code> header set with <code>Basic</code> access authentication constructed from client id and client secret. This endpoint supports different **grant types**: 1. Grant Type == <code>client_credentials</code>: This endpoint will check the client credentials provided through Authorization header. 2. Grant Type == <code>password</code>: The grant type to use for authenticating a user, whether it's by email / username and password combination or through platform. 3. Grant Type == <code>refresh_token</code>: Used to get a new access token for a valid refresh token. 4. Grant Type == <code>authorization_code</code>: It generates the user token by given the authorization code which generated in "/authorize" API response. It should also pass in the redirect_uri, which should be the same as generating the authorization code request. For platform authentication, use grant type <code>password</code>. The <code>username</code> field would be in form of <code>platform:<platform type></code>, for example <code>platform:steam</code> for Steam. For the <code>password</code> field, set it to the authentication/authorization ticket or token obtainable through the respective platform SDK after authenticated the user to the platform. Supported platforms: - **steam** - use <code>platform:steam</code> as the username and use the authentication ticket obtained from Steam through the Steam SDK as the password. - **ps4** - use <code>platform:ps4</code> as the username and use the authorization code obtained from the PlayStation Network through a player PS4 unit as the password. - **live** - use <code>platform:live</code> as the username and use token obtained from Xbox Secure Token Service (XSTS) as the password. - **oculus** - use <code>platform:oculus</code> as the username and use the <code>user_id:nonce</code> as password obtained from Oculus through the Oculus SDK. The access token and refresh token are in form of JWT token. An access token JWT contains data which structure is similar to the Response Class below, but without OAuth-related data. To verify a token, use the public keys obtained from the <code>/jwks</code> endpoint below. ## Access Token Content Following is the access token’s content: - **namespace**. It is the namespace the token was generated from. - **display_name**. The display name of the sub. It is empty if the token is generated from the client credential - **roles**. The sub’s roles. It is empty if the token is generated from the client credential - **namespace_roles**. The sub’s roles scoped to namespace. Improvement from roles, which make the role scoped to specific namespace instead of global to publisher namespace - **permissions**. The sub or aud’ permissions - **bans**. The sub’s list of bans. It is used by the IAM client for validating the token. - **jflgs**. It stands for Justice Flags. It is a special flag used for storing additional status information regarding the sub. It is implemented as a bit mask. Following explains what each bit represents: - 1: Email Address Verified - 2: Phone Number Verified - 4: Anonymous - **aud**. The aud is the client ID. - **iat**. The time the token issues at. It is in Epoch time format - **exp**. The time the token expires. It is in Epoch time format - **sub**. The UserID. The sub is omitted if the token is generated from client credential ## Bans The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /bans. ## Track Login History This endpoint will track login history to detect suspicious login activity, please provide "device_id" (alphanumeric) in request header parameter otherwise we will set to "unknown". Align with General Data Protection Regulation in Europe, user login history will be kept within 28 days by default" */ postOauthToken: (data: { grant_type: "authorization_code" | "client_credentials" | "password" | "refresh_token"; code?: string | null; extend_exp?: boolean | null; namespace?: string | null; password?: string | null; redirect_uri?: string | null; refresh_token?: string | null; username?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/verify [POST]_** - **Note: difference in V3 response:** 1. format difference(Pascal case => Camel case): permissions field from Action => action, Resource => resource */ postOauthVerify: (data: { token: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated The endpoint supports two response types: ### 1. Response Type == "code": The endpoint returns an authorization code that will be used by the IAM client to exchange for an access token. It supports two different headers, the basic and the bearer header. Each behaves differently. - **The basic header** The basic header’s value is the base64 of the client ID and client secret. It is used by the developer whenever the developer authorizes a user on a same namespace. - **The bearer header** The bearer header’s value is an access token. It is used by the developer whenever the developer authorizes a user on a different namespace. The endpoint validates user’s entitlement on the designated namespace for making sure the user is authorized for a designated namespace. Following are the responses returned by the endpoint: - **Authorize success**: redirects to the given URL with the following information: ?code={authorization code}&state={state} - **Authorize failure**: redirects to the given URL with the following information:?error=access_denied&error_description=... ### 2. Response Type == "token" (Implicit) is deprecated. ### Endpoint migration guide - **Substitute endpoint (for: basic header style)**: _/iam/v3/oauth/authorize [GET]_ - **Substitute endpoint (for: bearer header style)**: step1: /iam/v3/namespace/{namespace}/token/request [POST] => get code step2: /iam/v3/token/exchange [POST] => get token by step1's code - **Note:** 1. V3 is standard OAuth2 flow and support PKCE 2. Will not support implicit flow in v3. */ postOauthAuthorize: (data: { client_id: string | null; redirect_uri: string | null; response_type: "code" | "token"; login?: string | null; password?: string | null; scope?: string | null; state?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint revokes a user. This endpoint requires all requests to have Authorization header set with Bearer access authentication with valid access token. When other clients know that the userID has been revoked and the token is issued before the revocation, forcing a new token will contain banned permissions. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/admin/namespaces/{namespace}/users/{userId}/revoke [POST]_** */ postOauthRevokeUser: (data: { userID: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Revokes a token. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret or Bearer access authentication with valid access token. ### Endpoint migration guide - **Substitute endpoint: _/v3/oauth/revoke [POST]_** */ postOauthRevokeToken: (data: { token: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint will return a list of revoked users and revoked tokens. List of revoked tokens in bloom filter format. This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. The bloom filter uses MurmurHash3 algorithm for hashing the values ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/revocationlist [GET]_** */ getOauthRevocationlist: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint requires all requests to have authorization header set with bearer token. The endpoint revokes all access tokens and refresh tokens a user has prior the revocation time. It is a convenient feature for the developer (or admin) who wanted to revokes all user's access tokens and refresh tokens generated before some period of time. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/admin/namespaces/{namespace}/users/{userId}/revoke [POST]_** */ updateRevokeOauth_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint requires all requests to have Authorization header set with Basic access authentication constructed from client id and client secret. For publisher-game namespace schema : Specify only either platform_token or device_id. Device token grant should be requested along with device_id parameter against game namespace. Another 3rd party platform token grant should be requested along with platform_token parameter against publisher namespace. Supported platforms: - **steamopenid**: Steam's user authentication method using OpenID 2.0. The expected value of the platform token is the URL generated by Steam on web authentication The JWT contains user's active bans with its expiry date. List of ban types can be obtained from /iam/bans.. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/oauth/platforms/{platformId}/token [POST]_** */ postTokenOauth_ByPlatformId: (platformId: string, data: { device_id?: string | null; macAddress?: string | null; platform_token?: string | null; }) => Promise>; }; /** * AUTO GENERATED */ declare function ProfileUpdateStrategyApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This API is for public user to get profile update strategy by namespace and field. Note: If the config is not found, this API will return a config with unlimited. */ getProfileUpdateStrategies_v3: (queryParams?: { field?: "country" | "display_name" | "dob" | "username"; }) => Promise>; }; /** * AUTO GENERATED */ declare function RolesApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles [GET]_** */ getRoles: (queryParams?: { isWildcard?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Role can only be assigned to other users by the role's manager. If role is an administrator role (i.e. AdminRole == true), it will list out the role's members. Administrator role can be created only when at least 1 manager is specified. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles [POST]_** */ createRole: (data: RoleCreateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId} [DELETE]_** */ deleteRole_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId} [GET]_** */ getRole_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId} [PATCH]_** */ updateRole_ByRoleId: (roleId: string, data: RoleUpdateRequest) => Promise>; /** * This endpoint is used to get all non-admin role. action code: 10418 */ getRoles_v3: (queryParams?: { after?: string | null; before?: string | null; isWildcard?: boolean | null; limit?: number; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/admin [DELETE]_** */ deleteAdmin_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Admin roles has its members listed in the role. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/admin [GET]_** */ getAdmin_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Admin roles has its members listed in the role. Role can be set as admin role only when it has at least 1 manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/admin [POST]_** */ updateAdmin_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/members [DELETE]_** */ deleteMember_ByRoleId: (roleId: string, data: RoleMembersRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/members [GET]_** */ getMembers_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Admin roles has its members listed in the role. Role can only be assigned to other users by the role's manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/members [POST]_** */ updateMember_ByRoleId: (roleId: string, data: RoleMembersRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/managers [DELETE]_** */ deleteManager_ByRoleId: (roleId: string, data: RoleManagersRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Role can only be assigned to other users by the role's manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/managers [GET]_** */ getManagers_ByRoleId: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated Role can only be assigned to other users by the role's manager. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/managers [POST]_** */ updateManager_ByRoleId: (roleId: string, data: RoleManagersRequest) => Promise>; /** * This endpoint is used to get non-admin role based on specify roleId. action code : 10417 */ getRole_ByRoleId_v3: (roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint will REPLACE role's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. \*: all values in the fields, e.g. \* in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/permissions [POST]_** */ updatePermission_ByRoleId: (roleId: string, data: Permissions) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/roles/{roleId}/permissions/{resource}/{action} [DELETE]_** - **Substitute endpoint: _/iam/v4/admin/roles/{roleId}/permissions [DELETE]_** */ deletePermission_ByRoleId_ByResource_ByAction: (roleId: string, resource: string, action: number) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated This endpoint will update existing permission (bitwise OR the action) if found one with same resource, otherwise it will append a new permission Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: - Seconds: 0-59 * / , - - Minutes: 0-59 * / , - - Hours: 0-23 * / , - - Day of month: 1-31 * / , - L W - Month: 1-12 JAN-DEC * / , - - Day of week: 0-6 SUN-SAT * / , - L # - Year: 1970-2099 * / , - Special characters: - \**: all values in the fields, e.g. \* in seconds fields indicates every second - /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter - ,: separate items of a list, e.g. MON,WED,FRI in day of week - -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive - L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. - W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." - #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. ### Endpoint migration guide - **Substitute endpoint(update): _/iam/v3/admin/roles/{roleId}/permissions [PUT]_** - **Substitute endpoint(create): _/iam/v3/admin/roles/{roleId}/permissions [POST]_** */ updatePermission_ByRoleId_ByResource_ByAction: (roleId: string, resource: string, action: number, data: UpdatePermissionScheduleRequest) => Promise>; }; /** * AUTO GENERATED */ declare function SsoApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { getSso_ByPlatformId_v3: (platformId: string, queryParams?: { payload?: string | null; }) => Promise>; /** * Logout user's session on platform that logged in using SSO. Supported platforms: - discourse */ createLogout_ByPlatformId_v3: (platformId: string) => Promise>; }; /** * AUTO GENERATED */ declare function SsoSaml20Api(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint authenticates user platform for SAML protocol. It validates user to its respective platforms. Deactivated or login-banned users are unable to login. ## Supported platforms: - **azure** Microsoft login page will redirects to this endpoint after login success as previously defined on authentication request SAML */ postAuthenticateSamlSso_ByPlatformId_v3: (platformId: string, queryParams: { state: string | null; code?: string | null; error?: string | null; }) => Promise>; }; /** * AUTO GENERATED */ declare function ThirdPartyCredentialApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This is the Public API to Get All Active OIDC Platform Credential By Client ID */ getPlatformsClientsOidc_v3: (queryParams: { clientId: string | null; }) => Promise>; /** * This is the Public API to Get All Active 3rd Platform Credential. */ getPlatformsClientsActive_v3: () => Promise>; }; /** * AUTO GENERATED */ declare function UsersApi(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * Get my user data __Supported 3rd platforms:__ * __PSN(ps4web, ps4, ps5)__ * account id * display name * avatar * __Xbox(live, xblweb)__ * xuid or pxuid * display name * __Steam(steam, steamopenid)__ * steam id * display name * avatar * __EpicGames(epicgames)__ * epic account id * display name action code : 10147 */ getUsersMe_v3: (queryParams?: { includeAllPlatforms?: boolean | null; }) => Promise>; /** * This endpoint does not need a namespace in the path, we will find the namespace based on: - If this is premium environment, the namespace will be the publisher namespace. - If this is shared cloud: - If this is from Admin Portal, we will find the user by the email. - If this is not from Admin Portal, we will find the namespace based on the client id. **Note**: - The param **clientId** is required in Shared Cloud - The namespace in the response is publisher/studio namespace */ createUserForgot_v3: (data: ForgotPasswordWithoutNamespaceRequestV3) => Promise>; /** * This API is created to match openid userinfo standard => https://openid.net/specs/openid-connect-core-1_0.html#UserInfo */ getUsersUserinfo_v3: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users [POST]_** - **Substitute endpoint: _/iam/v4/public/namespaces/{namespace}/users [POST]_** - **Note:** 1. v3 & v4 introduce optional verification code 2. format difference(Pascal case => Camel case) Available Authentication Types: 1. **EMAILPASSWD**: an authentication type used for new user registration through email. 2. **PHONEPASSWD**: an authentication type used for new user registration through phone number. Country use ISO3166-1 alpha-2 two letter, e.g. US. */ createUser: (data: UserCreateRequest) => Promise>; /** * This API is for user to get self profile update allow status. Note: If the config is not found, this API will return a config with unlimited. */ getUsersMeProfileStatus_v3: () => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(Public): _/iam/v3/admin/namespaces/{namespace}/roles/{roleId}/users [GET]_** - **Note:** difference in V3 response, format difference: Pascal case => Camel case This endpoint search admin users which have the roleId Notes : this endpoint only accept admin role. Admin Role is role which have admin status and members. Use endpoint [GET] /roles/{roleId}/admin to check the role status */ getUsersAdmin: (queryParams?: { after?: number; before?: number; limit?: number; roleId?: string | null; }) => Promise>; getUsersVerifyLinkVerify_v3: (queryParams?: { code?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/search [GET]_** Search all users that match the query on these fields: all login IDs (email address, phone number, and platform user id), userID, display name, and on the specified namespace. If the query is not defined, then it searches all users on the specified namespace. */ getUsersSearch: (queryParams?: { query?: string | null; }) => Promise>; /** * Get my redirect uri after link, this endpoint will return NotFound(404) if redirect uri is not found */ getUsersMeLinkRedirection_v3: (queryParams: { oneTimeLinkCode: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/information [DELETE]_** */ deleteUser_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(Public): _/iam/v3/public/namespaces/{namespace}/users/{userId} [GET]_** - **Substitute endpoint(Admin): _/iam/v3/admin/namespaces/{namespace}/users/{userId} [GET]_** - **Note:** format difference in response: Pascal case => Camel case */ getUser_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint([PUT]): _/iam/v3/public/namespaces/{namespace}/users/me [PUT]_** - **Substitute endpoint([PATCH]): _/iam/v3/public/namespaces/{namespace}/users/me [PATCH]_** - **Substitute endpoint([PATCH]): _/iam/v4/public/namespaces/{namespace}/users/me [PATCH]_** - **Note:** 1. Prefer [PATCH] if client support PATCH method 2. Difference in V3/v4 request body, format difference: Pascal case => Camel case This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {Country, DisplayName, LanguageTag} Country use ISO3166-1 alpha-2 two letter, e.g. US. **Several case of updating email address** - User want to update email address of which have been verified, NewEmailAddress response field will be filled with new email address - User want to update email address of which have not been verified, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, {LoginId, OldEmailAddress, EmailAddress} response field will be filled with verified email before. NewEmailAddress response field will be filled with newest email address. */ updateUser_ByUserId: (userId: string, data: UserUpdateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users [GET]_** */ getUsersByLoginId: (queryParams?: { loginId?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users [POST]_** - **Substitute endpoint: _/iam/v4/public/namespaces/{namespace}/users [POST]_** - **Note:** 1. v3 & v4 introduce optional verification code 2. format difference(Pascal case => Camel case) Available Authentication Types: 1. *EMAILPASSWD*: an authentication type used for new user registration through email. Country use ISO3166-1 alpha-2 two letter, e.g. US. */ createUser_v2: (data: UserCreateRequest) => Promise>; /** * This endpoint search all users on the specified namespace that match the query on these fields: display name, unique display name, username or by 3rd party display name. The query length must be between 3 and 30 characters. For email address queries (i.e. contains '@'), the allowed length is 3 to 40 characters. Otherwise, the database will not be queried. The default limit value is 20. ## Searching by 3rd party platform **Note: searching by 3rd party platform display name will use exact query, not fuzzy query.** Step when searching by 3rd party platform display name: 1. set __by__ to __thirdPartyPlatform__ 2. set __platformId__ to the _supported platform id_ 3. set __platformBy__ to __platformDisplayName__ **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 ## IP Rate Limit validation This API have IP Rate Limit validation, which activates when triggered excessively from the same IP address (throw 429 http error). The default rule: 10 max request per 30 seconds (per unique IP address). To mitigate potential unexpected issues in your implementation, consider adhering to these best practices as illustrated in the following examples: * Delay invoking the Search API if the player continues typing in the search box, and only utilize the latest input provided. * Prevent players from double-clicking or making multiple clicks within a short time frame. */ getUsers_v3: (queryParams?: { by?: string | null; limit?: number; offset?: number; platformBy?: string | null; platformId?: string | null; query?: string | null; }) => Promise>; /** * Available Authentication Types: 1. **EMAILPASSWD**: an authentication type used for new user registration through email. **Note**: * **uniqueDisplayName**: this is required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true. * **code**: this is required when mandatoryEmailVerificationEnabled config is true. please refer to the config from /iam/v3/public/namespaces/{namespace}/config/{configKey} [GET] API. Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createUser_v3: (data: UserCreateRequestV3) => Promise>; /** * The verification link is sent to email address It will not send request if user email is already verified */ createUserMeVerifyLinkRequest_v3: (data: SendVerificationLinkRequest) => Promise>; /** * This API need the upgradeToken in request body. Available contexts for use : 1. **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the email address is already used by others by returning HTTP Status Code 409. */ createUserMeCodeRequestForward_v3: (data: SendVerificationCodeRequestV3) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [POST]_** */ createBan_ByUserId: (userId: string, data: BanCreateRequest) => Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. action code : 10103 */ patchUserMe_v3: (data: PublicUserUpdateRequestV3) => Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. **Important notes:** This endpoint provides support for client that doesn't have PATCH support, i.e. UE4 before v4.23 released. If the client support PATCH method, use [PATCH] /iam/v3/public/namespaces/{namespace}/users/me instead action code : 10103 */ updateUserMe_v3: (data: PublicUserUpdateRequestV3) => Promise>; /** * Note: 1. My account should be full account 2. My account not linked to request headless account's third platform. After client resolving the conflict, it will call endpoint <code>/iam/v3/public/users/me/headless/linkWithProgression [POST]</code> */ getUsersMeHeadlessLinkConflict_v3: (queryParams: { oneTimeLinkCode: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans [GET]_** */ getBans_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/reset [POST]_** */ createUserResetPassword: (data: ResetPasswordRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles [PATCH]_** */ updateRole_ByUserId: (userId: string, data: string[]) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/forgot [POST]_** **Special note for publisher-game scenario:** Game Client should provide game namespace path parameter and Publisher Client should provide publisher namespace path parameter. The password reset code will be sent to the publisher account's email address. */ createUserForgotPassword: (data: SendVerificationCodeRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(query by email list): _/iam/v3/public/namespaces/{namespace}/users/bulk/basic [POST]_** - **Substitute endpoint(query by user id list): _/iam/v3/admin/namespaces/{namespace}/users/search/bulk [POST]_** */ getUsersListByLoginIds: (queryParams?: { loginIds?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** */ updateEnable_ByUserId: (userId: string) => Promise>; /** * action code: 10105 */ createUserReset_v3: (data: ResetPasswordRequestV3) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/status [PATCH]_** For **Deletion Account** purpose fill the reason with: - **DeactivateAccount** : if your deletion request comes from user - **AdminDeactivateAccount** : if your deletion request comes from admin */ updateDisable_ByUserId: (userId: string, data: DisableUserRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint(Public): _/iam/v3/public/namespaces/{namespace}/platforms/{platformId}/users/{platformUserId} [GET]_** - **Substitute endpoint(Admin): _/iam/v3/admin/namespaces/{namespace}/platforms/{platformId}/users/{platformUserId} [GET]_** - **Note:** 1. difference in V3 response, format difference: Pascal case => Camel case */ getUsersByPlatformUserId: (queryParams: { platformID: string | null; platformUserID: string | null; }) => Promise>; /** * **Special note for publisher-game scenario:** Game Client should provide game namespace path parameter and Publisher Client should provide publisher namespace path parameter. The password reset code will be sent to the publisher account's email address. action code : 10104 */ createUserForgot_ByNS_v3: (data: ForgotPasswordRequestV3) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/password [PUT]_** */ updatePassword_ByUserId: (userId: string, data: UserPasswordUpdateRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [POST]_** Access token from original namespace is needed as authorization header. Access token from designated account needed as form parameter to verify the ownership of that account. When platformID (device platfom ID) is specified, platform login method for that specific platform ID is removed. This means to protect account from second hand device usage. */ postCrosslink_ByUserId: (userId: string, data: { linkingToken: string | null; platformId?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/platforms [GET]_** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms [GET]_** ## Justice Platform Account The permission ’ADMIN:NAMESPACE:{namespace}:JUSTICE:USER:{userId}’ [READ] is required in order to read the UserID who linked with the user. */ getPlatforms_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/publisher [GET]_** **Restriction:** Path Parameter *namespace* can be provided only with game namespace */ getPublisher_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint(Public): _/iam/v3/public/namespaces/{namespace}/users/{userId} [GET]_** - **Substitute endpoint(Admin): _/iam/v3/admin/namespaces/{namespace}/users/{userId} [GET]_** - **Note:** format difference in response: Pascal case => Camel case */ getUser_ByUserId_v2: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint([PUT]): _/iam/v3/public/namespaces/{namespace}/users/me [PUT]_** - **Substitute endpoint([PATCH]): _/iam/v3/public/namespaces/{namespace}/users/me [PATCH]_** - **Substitute endpoint([PATCH]): _/iam/v4/public/namespaces/{namespace}/users/me [PATCH]_** - **Note:** 1. Prefer [PATCH] if client support PATCH method 2. Difference in V3/v4 request body, format difference: Pascal case => Camel case This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {Country, DisplayName, LanguageTag} */ patchUser_ByUserId_v2: (userId: string, data: UserUpdateRequest) => Promise>; /** * @deprecated * This endpoint retrieve user attributes. action code: 10129 **Substitute endpoint:** /v4/public/namespaces/{namespace}/users/{userId} [GET] */ getUser_ByUserId_v3: (userId: string) => Promise>; /** * Note: 1. My account should be full account 2. My account not linked to headless account's third platform. */ createUserMeHeadlesLinkWithProgression_v3: (data: LinkHeadlessAccountRequest) => Promise>; /** * Note: 1. the max count of user ids in the request is 100 2. if platform id is not empty, the result will only contain the corresponding platform infos 3. if platform id is empty, the result will contain all the supported platform infos __Supported 3rd platforms:__ * __PSN(ps4web, ps4, ps5)__ * account id * display name * avatar * __Xbox(live, xblweb)__ * xuid or pxuid * display name * __Steam(steam, steamopenid)__ * steam id * display name * avatar * __EpicGames(epicgames)__ * epic account id * display name */ createUserPlatform_v3: (data: UsersPlatformInfosRequestV3) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/information [DELETE]_** */ deleteInformation_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/information [GET]_** */ getInformation_ByUserId: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/permissions [POST]_** This endpoint will REPLACE user's permissions with the ones defined in body Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByUserId: (userId: string, data: Permissions) => Promise>; /** * @deprecated * Notes: - This endpoint bulk get users' basic info by userId, max allowed 100 at a time - If namespace is game, will search by game user Id, other wise will search by publisher namespace - **Result will include displayName(if it exists)** - **Substitute endpoint:** /iam/v3/public/namespaces/{namespace}/users/platforms [POST] */ createUserBulkBasic_v3: (data: UserIDsRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/code/verify [POST]_** Redeems a verification code sent to a user to verify the user's contact address is correct Available ContactType : *email* or *phone* */ updateVerification_ByUserId: (userId: string, data: UserVerificationRequest) => Promise>; /** * Verify the registration code */ createUserCodeVerify_v3: (data: VerifyRegistrationCode) => Promise>; /** * action code: 10107 */ updateUserMePassword_v3: (data: UserPasswordUpdateV3Request) => Promise>; /** * Check user's account availability. Available field : - displayName - uniqueDisplayName - username If request include access token with user ID data, that user ID will be excluded from availability check. For example, in case user update his emailAddress, he can use his own emailAddress to update his account. Response Code : - Account Available : 404 (not found) - Account Not Available : 204 (no content) */ getUsersAvailability_v3: (queryParams: { field: string | null; query: string | null; }) => Promise>; /** * This endpoint will validate the request's email address. If it already been used, will response 409. If it is available, we will send a verification code to this email address. This code can be verified by this [endpoint](#operations-Users-PublicVerifyRegistrationCode). */ createUserCodeRequest_v3: (data: SendRegisterVerificationCodeRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles/{roleId} [DELETE]_** */ deleteRole_ByUserId_ByRoleId: (userId: string, roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/roles/{roleId} [POST]_** */ updateRole_ByUserId_ByRoleId: (userId: string, roleId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/bans [GET]_** */ getBans_ByUserId_v2: (userId: string, queryParams?: { activeOnly?: boolean | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/reset [POST]_** */ createUserResetPassword_v2: (data: ResetPasswordRequest) => Promise>; /** * Notes: - This endpoint retrieve the first page of the data if after and before parameters is empty - **The pagination is not working yet** **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getBans_ByUserId_v3: (userId: string, queryParams?: { activeOnly?: boolean | null; after?: string | null; before?: string | null; limit?: number; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/forgot [POST]_** **Special note for publisher-game scenario:** Game Client should provide game namespace path parameter and Publisher Client should provide publisher namespace path parameter. The password reset code will be sent to the publisher account's email address. */ createUserForgotPassword_v2: (data: SendVerificationCodeRequest) => Promise>; /** * Will consume code if validateOnly is set false Redeems a verification code sent to a user to verify the user's contact address is correct Available ContactType : **email** action code: 10107 */ createUserMeCodeVerify_v3: (data: UserVerificationRequestV3) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/logins/histories [GET]_** - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/logins/histories [GET]_** Notes for this endpoint: - This endpoint retrieve the first page of the data if 'after' and 'before' parameters is empty. - The maximum value of the limit is 100 and the minimum value of the limit is 1. - This endpoint retrieve the next page of the data if we provide 'after' parameters with valid Unix timestamp. - This endpoint retrieve the previous page of the data if we provide 'before' parameter with valid data Unix timestamp. */ getLoginsHistories_ByUserId: (userId: string, queryParams?: { after?: number; before?: number; limit?: number; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/code/request [POST]_** The verification code is sent to either the phone number or email address. It depends on the LoginID's value. Available contexts for use : 1. **UserAccountRegistration** a context type used for verifying email address in user account registration. It returns 409 if the email address already verified. **_It is the default context if the Context field is empty_** 2. **UpdateEmailAddress** a context type used for verify user before updating email address.(Without email address verified checking) 3. **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the loginId field's value is already used by others by returning HTTP Status Code 409. */ updateVerificationcode_ByUserId: (userId: string, data: SendVerificationCodeRequest) => Promise>; /** * The verification code is sent to email address Available contexts for use : 1. **UserAccountRegistration** a context type used for verifying email address in user account registration. It returns 409 if the email address already verified. **_It is the default context if the Context field is empty_** 2. **UpdateEmailAddress** a context type used for verify user before updating email address.(Without email address verified checking) 3. **upgradeHeadlessAccount** The context is intended to be used whenever the email address wanted to be automatically verified on upgrading a headless account. If this context used, IAM rejects the request if the email address is already used by others by returning HTTP Status Code 409. action code: 10116 */ createUserMeCodeRequest_v3: (data: SendVerificationCodeRequestV3) => Promise>; /** * Validate user's input. -------- **note:** - this endpoint will check the input validation and profanity filter service(if this is enabled) - the namespace should be publisher namespace */ createUserInputValidation_v3: (data: UserInputValidationRequest) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/password [PUT]_** */ updatePassword_ByUserId_v2: (userId: string, data: UserPasswordUpdateRequest) => Promise>; /** * This endpoint is used to validate the user password. This endpoint validate the user password by specifying the userId and password. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ postValidate_ByUserId_v3: (userId: string, data: { password: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans/{banId} [PATCH]_** */ updateEnable_ByUserId_ByBanId: (userId: string, banId: string) => Promise>; /** * This endpoint retrieves platform accounts linked to user. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 **Authentication:** The _**userId**_ parameter should match the one in the access token. action code: 10128 */ getPlatforms_ByUserId_v3: (userId: string, queryParams?: { after?: string | null; before?: string | null; limit?: number; platformId?: string | null; }) => Promise>; /** * **Restriction:** Path Parameter **namespace** can be provided only with game namespace */ getPublisher_ByUserId_v3: (userId: string) => Promise>; /** * action code : 10124 if set NeedVerificationCode = true, IAM will send verification code into email user can use that verification code to verify user through /iam/v3/public/namespaces/{namespace}/users/me/code/verify */ createUserMeHeadlesVerify_v3: (data: UpgradeHeadlessAccountV3Request, queryParams?: { needVerificationCode?: boolean | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/bans/{banId} [PATCH]_** **Notes for using IAM in publisher - game studio scenarios** The endpoint allows: - The admin user in publisher namespace disables user’s ban in publisher namespace. - The admin user in game namespace disables user’s ban in game namespace. - The admin user in publisher namespace disables user’s ban in publisher namespace. Other scenarios are not supported and will return 403: Forbidden. */ updateDisable_ByUserId_ByBanId: (userId: string, banId: string) => Promise>; /** * This endpoint retrieves user info and linked platform accounts. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getInformation_ByUserId_v3: (userId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/headless/verify [POST]_** */ updateUpgradeHeadlessAccount_ByUserId: (userId: string, data: UpgradeHeadlessAccountRequest) => Promise>; /** * Endpoint to validate user invitation. When not found, it could also means the invitation has expired. */ getUserInvite_ByInvitationId_v3: (invitationId: string) => Promise>; /** * This endpoint create user from saved roles when creating invitation and submitted data. User will be able to login after completing submitting the data through this endpoint. Available Authentication Types: EMAILPASSWD: an authentication type used for new user registration through email. **Note**: * **uniqueDisplayName**: this is required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true. Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. */ createUserInvite_ByInvitationId_v3: (invitationId: string, data: UserCreateRequestV3) => Promise>; /** * @deprecated * List User ID By Platform User ID This endpoint intended to list game user ID from the given namespace This endpoint return list of user ID by given platform ID and list of platform user ID Supported platform: - steam - steamopenid - ps4web - ps4 - ps5 - live - xblweb - oculus - oculusweb - facebook - google - googleplaygames - twitch - discord - apple - device - justice - epicgames - nintendo - awscognito - netflix - snapchat - oidc platform id Note: **nintendo platform user ID**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ createUser_ByPlatformId_v3: (platformId: string, data: PlatformUserIdRequest, queryParams?: { rawPID?: boolean | null; rawPUID?: boolean | null; }) => Promise>; /** * It is going to be **DEPRECATED**. Update Platform Account relation to current User Account. Note: Game progression data (statistics, reward, etc) associated with previous User Account will not be transferred. If the data is tight to game user ID, the user will have the game progression data. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ createPlatformLink_ByUserId_v3: (userId: string, data: LinkPlatformAccountRequest) => Promise>; /** * If validateOnly is set false, consume code and upgrade headless account and automatically verified the email address if it is succeeded The endpoint upgrades a headless account by linking the headless account with the email address and the password. By upgrading the headless account into a full account, the user could use the email address and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the send verification code endpoint. This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. Supported user data fields : - displayName - dateOfBirth : format YYYY-MM-DD, e.g. 2019-04-29 - country : format ISO3166-1 alpha-2 two letter, e.g. US action code : 10124 */ createUserMeHeadlesCodeVerify_v3: (data: UpgradeHeadlessAccountWithVerificationCodeRequestV3) => Promise>; /** * Notes for this endpoint: - This endpoint retrieve the first page of the data if <code>after</code> and <code>before</code> parameters is empty. - The maximum value of the limit is 100 and the minimum value of the limit is 1. - This endpoint retrieve the next page of the data if we provide <code>after</code> parameters with valid Unix timestamp. - This endpoint retrieve the previous page of the data if we provide <code>before</code> parameter with valid data Unix timestamp. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getLoginsHistories_ByUserId_v3: (userId: string, queryParams?: { after?: number; before?: number; limit?: number; }) => Promise>; /** * @deprecated * ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **googleplaygames** - **oculus** - **twitch** - **android** - **ios** - **apple** - **device** - **discord** - **awscognito** - **epicgames** - **nintendo** Unlink user's account from a specific platform. 'justice' platform might have multiple accounts from different namespaces linked. _platformNamespace_ need to be specified when the platform ID is 'justice'. Unlink user's account from justice platform will enable password token grant and password update. If you want to unlink user's account in a game namespace, you have to specify _platformNamespace_ to that game namespace. action code : 10121 */ deleteUserMePlatform_ByPlatformId_v3: (platformId: string, data: UnlinkUserPlatformRequest) => Promise>; /** * **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the binary ticket returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **googleplaygames**: The ticket’s value is the authorization code returned by Google play games OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **apple**: The ticket’s value is the authorization code returned by Apple OAuth. - **device**: Every device that doesn't run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. - **ps4web**: The ticket’s value is the authorization code returned by PSN OAuth. - **ps4**: The ticket’s value is the authorization code returned by PSN OAuth. - **ps5**: The ticket’s value is the authorization code returned by PSN OAuth. - **xblweb**: The ticket’s value is the authorization code returned by XBox Live OAuth. - **live**: The ticket’s value is the XSTS token. - **awscognito**: The ticket’s value is the aws cognito access token (JWT). - **epicgames**: The ticket’s value is an access-token or authorization code obtained from Epicgames EOS Account Service. - **nintendo**: The ticket’s value is the id_token returned by Nintendo OAuth. - **netflix**: The ticket’s value is GAT (Gamer Access Token) returned by Netflix backend. - **snapchat**: The ticket’s value is authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. action code : 10144 */ postUserMePlatform_ByPlatformId_v3: (platformId: string, data: { ticket: string | null; redirectUri?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [POST]_** **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **apple**: The ticket’s value is the authorization code returned by Apple OAuth. - **device**: Every device that does’nt run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. */ postLink_ByUserId_ByPlatformId: (userId: string, platformId: string, data: { ticket: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/{userId}/platforms/justice [GET]_** This endpoint gets list justice platform account by providing publisher namespace and publisher userID. */ getPlatformsJustice_ByUserId_v2: (userId: string) => Promise>; /** * This endpoint retrieves platform accounts linked to user. It will query all linked platform accounts. The results will be distinct and grouped by platform, and for each platform, we will select the oldest linked one. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getDistinctPlatforms_ByUserId_v3: (userId: string) => Promise>; /** * This endpoint gets list justice platform account by providing publisher namespace and publisher userID. **Authentication:** The _**userId**_ parameter should match the one in the access token. */ getPlatformsJustice_ByUserId_v3: (userId: string) => Promise>; /** * This endpoint is used to get linking status. This API need logged user and user can only request its own linking status. */ getAsyncStatus_ByRequestId_v3: (requestId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [DELETE]_** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId}/all [DELETE]_** ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **oculus** - **twitch** - **android** - **ios** - **device** - **justice**: A user might have several 'justice’ platform on different namespaces. That’s why the platform_namespace need to be specified when the platform ID is ‘justice’. The platform_namespace is the designated user’s namespace. Unlink user's account with platform. 'justice' platform might have multiple accounts from different namespaces linked. platform_namespace need to be specified when the platform ID is 'justice'. Unlinking justice platform will enable password token grant and password update. */ postUnlink_ByUserId_ByPlatformId: (userId: string, platformId: string, data: { platform_namespace?: string | null; }) => Promise>; /** * Unlink user's account from third platform in all namespaces. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: to unlink steam third party account, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 Unlink platform account associated with a group: If user unlink platform account associated with a group, the API logic will unlink all of platform account under that group as well. example: if user unlink from ps4, the API logic will unlink ps5 and ps4web as well */ deleteAllMeUser_ByPlatformId_v3: (platformId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/permissions/{resource}/{action} [DELETE]_** */ deletePermission_ByUserId_ByResource_ByAction: (userId: string, resource: string, action: number) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/permissions [POST]_** This endpoint will update existing permission (bitwise OR the action) if found one with same resource, otherwise it will append a new permission Schedule contains cron string or date range (both are UTC, also in cron syntax) to indicate when a permission and action are in effect. Both schedule types accepts quartz compatible cron syntax e.g. * * * * * * *. In ranged schedule, first element will be start date, and second one will be end date If schedule is set, the scheduled action must be valid too, that is between 1 to 15, inclusive Syntax reference Fields: 1. Seconds: 0-59 * / , - 2. Minutes: 0-59 * / , - 3. Hours: 0-23 * / , - 4. Day of month: 1-31 * / , - L W 5. Month: 1-12 JAN-DEC * / , - 6. Day of week: 0-6 SUN-SAT * / , - L # 7. Year: 1970-2099 * / , - Special characters: 1. *: all values in the fields, e.g. * in seconds fields indicates every second 2. /: increments of ranges, e.g. 3-59/15 in the minute field indicate the third minute of the hour and every 15 minutes thereafter 3. ,: separate items of a list, e.g. MON,WED,FRI in day of week 4. -: range, e.g. 2010-2018 indicates every year between 2010 and 2018, inclusive 5. L: last, e.g. When used in the day-of-week field, it allows you to specify constructs such as "the last Friday" (5L) of a given month. In the day-of-month field, it specifies the last day of the month. 6. W: business day, e.g. if you were to specify 15W as the value for the day-of-month field, the meaning is: "the nearest business day to the 15th of the month." 7. #: must be followed by a number between one and five. It allows you to specify constructs such as "the second Friday" of a given month. */ updatePermission_ByUserId_ByResource_ByAction: (userId: string, resource: string, action: number, data: UpdatePermissionScheduleRequest) => Promise>; /** * Force linking user account with platform. If this platform account was already linked to another user account, this endpoint will perform force linking and remove platform from that conflict user, not only from the current request namespace but also include all the enrolled namespaces. If current user have linked to this platform with another platform account (include once linked but it is unlinked now), it will not allow user to perform linking. ## Supported platforms: - **steam**: The platform_token’s value is the binary ticket returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The platform_token's value is URL generated by Steam on web authentication - **facebook**: The platform_token’s value is the authorization code returned by Facebook OAuth - **google**: The platform_token’s value is the authorization code returned by Google OAuth - **googleplaygames**: The platform_token’s value is the authorization code returned by Google play games OAuth - **oculus**: The platform_token’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The platform_token’s value is the authorization code returned by Twitch OAuth. - **discord**: The platform_token’s value is the authorization code returned by Discord OAuth - **android**: The device_id is the Android’s device ID - **ios**: The device_id is the iOS’s device ID. - **apple**: The platform_token’s value is the authorization code returned by Apple OAuth.(We will use this code to generate APP token) - **device**: Every device that does’nt run Android and iOS is categorized as a device. The device_id is the device’s ID. - **justice**: The platform_token’s value is the designated user’s access token. - **epicgames**: The platform_token’s value is an access-token obtained from Epicgames EOS Account Service. - **ps4**: The platform_token’s value is the authorization code returned by Sony OAuth. - **ps5**: The platform_token’s value is the authorization code returned by Sony OAuth. - **nintendo**: The platform_token’s value is the id_token returned by Nintendo OAuth. - **awscognito**: The platform_token’s value is the aws cognito access token or id token (JWT). - **live**: The platform_token’s value is xbox XSTS token - **xblweb**: The platform_token’s value is code returned by xbox after login - **netflix**: The platform_token’s value is GAT (Gamer Access Token) returned by Netflix backend - **snapchat**: The platform_token’s value is the authorization code returned by Snapchat OAuth. - **for specific generic oauth (OIDC)**: The platform_token’s value should be the same type as created OIDC auth type whether it is auth code, idToken or bearerToken. */ postForceMeUser_ByPlatformId_v3: (platformId: string, data: { ticket: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/agerestrictions/countries/{countryCode} [GET]_** */ getAgerestrictions_ByCountryCode_v2: (countryCode: string) => Promise>; /** * Get age restriction by country code. It will always get by publisher namespace */ getAgerestrictionCountry_ByCountryCode_v3: (countryCode: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms/justice/{targetNamespace} [GET]_** This endpoint requires the client access token as the bearer token This endpoint will support publisher access to game and game access to publisher If targetNamespace filled with publisher namespace then this endpoint will return its publisher user id and publisher namespace. If targetNamespace filled with game namespace then this endpoint will return its game user id and game namespace. **Will create game user id if not exists.** */ getPlatformJustice_ByUserId_ByTargetNamespace: (userId: string, targetNamespace: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/admin/namespaces/{namespace}/users/{userId}/platforms/justice/{targetNamespace} [GET]_** This endpoint requires the client access token as the bearer token The endpoint returns user Justice platform account linked with the given user. If the user Justice platform account doesn't exist in the designated namespace, the endpoint is going to *create and return the new Justice platform account.* The newly user Justice platform account is going to be forced to perform token grant through the given user and can't perform password update ### Read Justice Platform Account UserID Without permission the UserID is going to be censored and replaced with “Redacted” text. */ updatePlatformJustice_ByUserId_ByTargetNamespace: (userId: string, targetNamespace: string) => Promise>; /** * This endpoint is used to generate third party login page which will redirected to establish endpoint. Supported platforms: - ps4web - xblweb - steamopenid - epicgames - facebook - twitch - google - apple - snapchat - discord - amazon - oculusweb */ getWebLinkMeUsers_ByPlatformId_v3: (platformId: string, queryParams?: { clientId?: string | null; redirectUri?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [DELETE]_** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId}/all [DELETE]_** ## Supported platforms: - **steam** - **steamopenid** - **facebook** - **google** - **oculus** - **twitch** - **android** - **ios** - **device** - **discord** Delete link of user's account with platform. 'justice' platform might have multiple accounts from different namespaces linked. platform_namespace need to be specified when the platform ID is 'justice'. Delete link of justice platform will enable password token grant and password update. */ deleteLink_ByUserId_ByPlatformId_v2: (userId: string, platformId: string, data: { platform_namespace?: string | null; }) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated **Endpoint migration guide** - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/platforms/{platformId} [POST]_** **Prerequisite:** Platform client configuration need to be added to database for specific platformId. Namespace service URL need to be specified (refer to required environment variables). ## Supported platforms: - **steam**: The ticket’s value is the authentication code returned by Steam. - **steamopenid**: Steam's user authentication method using OpenID 2.0. The ticket's value is URL generated by Steam on web authentication - **facebook**: The ticket’s value is the authorization code returned by Facebook OAuth - **google**: The ticket’s value is the authorization code returned by Google OAuth - **oculus**: The ticket’s value is a string composed of Oculus's user ID and the nonce separated by a colon (:). - **twitch**: The ticket’s value is the authorization code returned by Twitch OAuth. - **android**: The ticket's value is the Android’s device ID - **ios**: The ticket's value is the iOS’s device ID. - **device**: Every device that doesn't run Android and iOS is categorized as a device platform. The ticket's value is the device’s ID. - **discord**: The ticket’s value is the authorization code returned by Discord OAuth. */ postLink_ByUserId_ByPlatformId_v2: (userId: string, platformId: string, data: { ticket: string | null; }) => Promise>; /** * Force update other account's Platform Account relation to current User Account. This endpoint can transfer progression from 3rd platform binding account's to current account. This endpoint need the same requestID which also used in [Get link status](#operations-Users-PublicGetAsyncStatus). **Authentication:** The _**userId**_ parameter should match the one in the access token. */ createPlatformLinkWithProgression_ByUserId_v3: (userId: string, data: LinkPlatformAccountWithProgressionRequest) => Promise>; /** * Create Justice User from Publisher User information. It will check first if Justice User on target namespace already exist. */ createUserMePlatformJustice_ByTargetNamespace_v3: (targetNamespace: string) => Promise>; /** * @deprecated * Get User By Platform User ID. This endpoint return user information by given platform ID and platform user ID. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: for steam network platform, you can use steamnetwork / steam / steamopenid as platformId path parameter. **Note**: this is deprecated, substitute endpoint: /iam/v4/public/namespaces/{namespace}/platforms/{platformId}/users/{platformUserId} [GET] **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getUser_ByPlatformId_ByPlatformUserId_v3: (platformId: string, platformUserId: string) => Promise>; /** * @deprecated * ## The endpoint is going to be deprecated ### Endpoint migration guide - **Substitute endpoint: _/iam/v3/public/namespaces/{namespace}/users/me/headless/code/verify [POST]_** The endpoint upgrades a headless account by linking the headless account with the email address and the password. By upgrading the headless account into a full account, the user could use the email address and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the send verification code endpoint. */ updateUpgradeHeadlessAccountWithVerificationCode_ByUserId: (userId: string, data: UpgradeHeadlessAccountWithVerificationCodeRequest) => Promise>; /** * This endpoint is used to process third party account link, this endpoint will return the link status directly instead of redirecting to the original page. The param **state** comes from the response of <code>/users/me/platforms/{platformId}/web/link</code> Supported platforms: - ps4web - xblweb - steamopenid - epicgames - facebook - twitch - google - apple - snapchat - discord - amazon - oculusweb */ postWebLinkProcesMeUser_ByPlatformId_v3: (platformId: string, data: { state: string | null; code?: string | null; }) => Promise>; /** * This endpoint is used by third party to redirect the code for the purpose of linking the account third party to IAM account. Supported platforms: - ps4web - xblweb - steamopenid - epicgames - facebook - twitch - google - apple - snapchat - discord - amazon - oculusweb */ getWebLinkEstablishMeUsers_ByPlatformId_v3: (platformId: string, queryParams: { state: string | null; code?: string | null; }) => Promise>; }; /** * AUTO GENERATED */ declare function UsersV4Api(sdk: AccelByteSDK, args?: SdkSetConfigParam): { /** * This endpoint is used to invite a game studio admin user with new namespace in multi tenant mode. It will return error if the service multi tenant mode is set to false. Request body details: - emailAddress: email address of the user to be invited - namespace: new namespace of the user to be created - namespaceDisplayName: display name of the new namespace - additionalData(optional): for utm parameter data The invited users will also be assigned with "User" role by default. */ createUserInvite_v4: (data: PublicInviteUserRequestV4) => Promise>; /** * Create a new user with unique email address and username. **Required attributes:** - authType: possible value is EMAILPASSWD - emailAddress: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. - uniqueDisplayName: required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true, please refer to the rule from /v3/public/inputValidations API. - code: required when mandatoryEmailVerificationEnabled config is true, please refer to the config from /iam/v3/public/namespaces/{namespace}/config/{configKey} [GET] API. **Not required attributes:** - displayName: Please refer to the rule from /v3/public/inputValidations API. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createUser_v4: (data: CreateUserRequestV4) => Promise>; /** * This Endpoint support update user based on given data. **Single request can update single field or multi fields.** Supported field {country, displayName, languageTag, dateOfBirth, avatarUrl, userName} Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. **Response body logic when user updating email address:** - User want to update email address of which have been verified, newEmailAddress response field will be filled with new email address. - User want to update email address of which have not been verified, { oldEmailAddress, emailAddress} response field will be filled with new email address. - User want to update email address of which have been verified and updated before, { oldEmailAddress, emailAddress} response field will be filled with verified email before. newEmailAddress response field will be filled with newest email address. action code : 10103 */ patchUserMe_v4: (data: PublicUserUpdateRequestV3) => Promise>; /** * Create a test user and not send verification code email **Required attributes:** - verified: this new user is verified or not - authType: possible value is EMAILPASSWD - emailAddress: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. **Not required attributes:** - displayName: Please refer to the rule from /v3/public/inputValidations API. This endpoint support accepting agreements for the created user. Supply the accepted agreements in acceptedPolicies attribute. */ createTestUser_v4: (data: CreateTestUserRequestV4) => Promise>; /** * This endpoint only returns user's public information. action code: 10129 */ getUser_ByUserId_v4: (userId: string) => Promise>; /** * The endpoint to update my email address. It requires a verification code from <code>/users/me/code/request</code> with **UpdateEmailAddress** context. */ updateUserMeEmail_v4: (data: EmailUpdateRequestV4) => Promise>; /** * This is a forward version for code verify. The endpoint upgrades a headless account by linking the headless account with the email address, username, and password. By upgrading the headless account into a full account, the user could use the email address, username, and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the [send verification code endpoint](#operations-Users-PublicSendCodeForwardV3). This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. */ createUserMeHeadlesCodeVerifyForward_v4: (data: UpgradeHeadlessAccountWithVerificationCodeForwardRequestV4) => Promise>; /** * (Only for test)This endpoint is used to remove trusted device. This endpoint Requires device_token in cookie */ deleteUserMeMfaDevice_v4: () => Promise>; /** * This endpoint is used to get user enabled factors. */ getUsersMeMfaFactor_v4: () => Promise>; /** * This endpoint is used to make 2FA factor default. */ postUserMeMfaFactor_v4: (data: { factor: string | null; }) => Promise>; /** * This endpoint will get user's' MFA status. */ getUsersMeMfaStatus_v4: () => Promise>; /** * @deprecated * This endpoint will get user's' MFA status. --------- **Substitute endpoint**: /iam/v4/public/namespaces/{namespace}/users/me/mfa/status [GET] */ createUserMeMfaStatus_v4: () => Promise>; /** * @deprecated * This endpoint is used to get 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ getUsersMeMfaBackupCode_v4: () => Promise>; /** * @deprecated * This endpoint is used to generate 8-digits backup codes. Each code is a one-time code and will be deleted once used. */ createUserMeMfaBackupCode_v4: () => Promise>; /** * This endpoint is used to send email code. ---------------- Supported values of action: * ChangePassword * DisableMFAEmail */ postUserMeMfaEmailCode_v4: (data: { action?: string | null; languageTag?: string | null; }) => Promise>; /** * Upgrade headless account to full account without verifying email address. Client does not need to provide verification code which sent to email address. action code : 10124 */ createUserMeHeadlesVerify_v4: (data: UpgradeHeadlessAccountRequestV4) => Promise>; /** * This endpoint is used to get existing 8-digits backup codes. Each codes is a one-time code and will be deleted once used. The codes will be sent through linked email. */ getUsersMeMfaBackupCodes_v4: (queryParams?: { languageTag?: string | null; }) => Promise>; /** * This endpoint is used to generate 8-digits backup codes. Each codes is a one-time code and will be deleted once used. The codes will be sent through linked email. */ createUserMeMfaBackupCode_ByNS_v4: (queryParams?: { languageTag?: string | null; }) => Promise>; /** * This endpoint is used to enable 2FA email. */ postUserMeMfaEmailEnable_v4: (data: { code: string | null; }) => Promise>; /** * This endpoint is used to disable 2FA email. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ createUserMeMfaEmailDisable_v4: (data: DisableMfaRequest) => Promise>; /** * This endpoint create user from saved roles when creating invitation and submitted data. User will be able to login after completing submitting the data through this endpoint. Available Authentication Types: EMAILPASSWD: an authentication type used for new user registration through email. **Note**: * **uniqueDisplayName**: this is required when uniqueDisplayNameEnabled/UNIQUE_DISPLAY_NAME_ENABLED is true. Country use ISO3166-1 alpha-2 two letter, e.g. US. Date of Birth format : YYYY-MM-DD, e.g. 2019-04-29. Required attributes: - authType: possible value is EMAILPASSWD (see above) - country: ISO3166-1 alpha-2 two letter, e.g. US. - dateOfBirth: YYYY-MM-DD, e.g. 1990-01-01. valid values are between 1905-01-01 until current date. - displayName: Please refer to the rule from /v3/public/inputValidations API. - password: Please refer to the rule from /v3/public/inputValidations API. - username: Please refer to the rule from /v3/public/inputValidations API. */ createUserInvite_ByInvitationId_v4: (invitationId: string, data: CreateUserRequestV4) => Promise>; /** * List User ID By Platform User ID This endpoint intended to list game user ID from the given namespace This endpoint return list of user ID by given platform ID and list of platform user ID, the max count is 100. Supported platform: - steam - steamopenid - ps4web - ps4 - ps5 - live - xblweb - oculus - if query by app user id, please set the param **pidType** to **OCULUS_APP_USER_ID** - oculusweb - facebook - google - googleplaygames - twitch - discord - apple - device - justice - epicgames - nintendo - awscognito - netflix - snapchat - oidc platform id Note: **nintendo platform user ID**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 <br> If the request body exceed the max limitation, the max count will be in response body's messageVariables: "messageVariables": {"maxCount": "100"} */ createUser_ByPlatformId_v4: (platformId: string, data: PlatformUserIdRequestV4, queryParams?: { rawPUID?: boolean | null; }) => Promise>; /** * The endpoint upgrades a headless account by linking the headless account with the email address, username, and password. By upgrading the headless account into a full account, the user could use the email address, username, and password for using Justice IAM. The endpoint is a shortcut for upgrading a headless account and verifying the email address in one call. In order to get a verification code for the endpoint, please check the [send verification code endpoint](#operations-Users-PublicSendVerificationCodeV3). This endpoint also have an ability to update user data (if the user data field is specified) right after the upgrade account process is done. Supported user data fields: - displayName - dateOfBirth : format YYYY-MM-DD, e.g. 2019-04-29 - country : format ISO3166-1 alpha-2 two letter, e.g. US action code : 10124 */ createUserMeHeadlesCodeVerify_v4: (data: UpgradeHeadlessAccountWithVerificationCodeRequestV4) => Promise>; /** * This endpoint will verify user's' MFA code and generate a MFA token for the action. */ postUserMeMfaChallengeVerify_v4: (data: { code?: string | null; factor?: string | null; }) => Promise>; /** * This endpoint is used to generate a secret key for 3rd-party authenticator app. A QR code URI is also returned so that frontend can generate QR code image. */ createUserMeMfaAuthenticatorKey_v4: () => Promise>; /** * @deprecated * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_v4: () => Promise>; /** * This endpoint is used to disable 2FA backup codes. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaBackupCodeDisable_v4: (data: DisableMfaRequest) => Promise>; /** * This endpoint is used to enable 2FA backup codes. */ createUserMeMfaBackupCodeEnable_ByNS_v4: (queryParams?: { languageTag?: string | null; }) => Promise>; /** * @deprecated * This endpoint is used to download backup codes. */ getUsersMeMfaBackupCodeDownload_v4: () => Promise>; /** * This endpoint is used to enable 2FA authenticator. ---------- Prerequisites: - Generate the secret key/QR code uri by **_/iam/v4/public/namespaces/{namespace}/users/me/mfa/authenticator/key_** - Consume the secret key/QR code by an authenticator app - Get the code from the authenticator app */ postUserMeMfaAuthenticatorEnable_v4: (data: { code: string | null; }) => Promise>; /** * This endpoint is used to disable 2FA authenticator. ------ **Note**: **mfaToken** is required when all the following are enabled: - The environment variable **SENSITIVE_MFA_AUTH_ENABLED** is true - The **Two-Factor Authentication** is enabled in the IAM client where user logs in - Users already enabled the MFA */ deleteUserMeMfaAuthenticatorDisable_v4: (data: DisableMfaRequest) => Promise>; /** * Get User By Platform User ID. This endpoint return user information by given platform ID and platform user ID. Several platforms are grouped under account groups, you can use either platform ID or platform group as platformId path parameter. example: for steam network platform, you can use steamnetwork / steam / steamopenid as platformId path parameter. If the target platform is not linked to the current user, will only return public information. ---------- **Supported Platforms:** - Steam group (steamnetwork): - steam - steamopenid - PSN group (psn): - ps4web - ps4 - ps5 - XBOX group(xbox): - live - xblweb - Oculus group (oculusgroup): - oculus - oculusweb - Google group (google): - google - googleplaygames: - epicgames - facebook - twitch - discord - android - ios - apple - device - nintendo - awscognito - amazon - netflix - snapchat - _oidc platform id_ Note: - You can use either platform id or platform group as **platformId** parameter. - **Nintendo platform user id**: NSA ID need to be appended with Environment ID using colon as separator. e.g kmzwa8awaa:dd1 */ getUser_ByPlatformId_ByPlatformUserId_v4: (platformId: string, platformUserId: string) => Promise>; }; /** * AUTO GENERATED */ declare const Iam: { BansAdminApi: typeof BansAdminApi; RolesAdminApi: typeof RolesAdminApi; UsersAdminApi: typeof UsersAdminApi; UsersV4AdminApi: typeof UsersV4AdminApi; InputValidationsAdminApi: typeof InputValidationsAdminApi; ClientsConfigV3AdminApi: typeof ClientsConfigV3AdminApi; AccountIdentifierTagAdminApi: typeof AccountIdentifierTagAdminApi; ClientsAdminApi: typeof ClientsAdminApi; DevicesV4AdminApi: typeof DevicesV4AdminApi; CountryAdminApi: typeof CountryAdminApi; OverrideRoleConfigV3AdminApi: typeof OverrideRoleConfigV3AdminApi; ThirdPartyCredentialAdminApi: typeof ThirdPartyCredentialAdminApi; SsoCredentialAdminApi: typeof SsoCredentialAdminApi; LoginAllowlistAdminApi: typeof LoginAllowlistAdminApi; ConfigAdminApi: typeof ConfigAdminApi; ProfileUpdateStrategyAdminApi: typeof ProfileUpdateStrategyAdminApi; OAuth20AdminApi: typeof OAuth20AdminApi; BansApi: typeof BansApi; RolesApi: typeof RolesApi; ClientsApi: typeof ClientsApi; OAuth20ExtensionApi: typeof OAuth20ExtensionApi; OAuthApi: typeof OAuthApi; OAuth20Api: typeof OAuth20Api; OAuth20V4Api: typeof OAuth20V4Api; ConfigApi: typeof ConfigApi; UsersApi: typeof UsersApi; SsoApi: typeof SsoApi; UsersV4Api: typeof UsersV4Api; InputValidationsApi: typeof InputValidationsApi; CountryApi: typeof CountryApi; SsoSaml20Api: typeof SsoSaml20Api; ThirdPartyCredentialApi: typeof ThirdPartyCredentialApi; ProfileUpdateStrategyApi: typeof ProfileUpdateStrategyApi; version: () => void; }; declare class CodeChallenge { static load: () => any; static save: (codeVerifier: any) => void; static clear: () => void; static generateChallenge(): { verifier: string; challenge: string; }; static generateCsrf(): string; static stringifySentState(sentState: CodeChallengeSentState): string; static parseSentState(stringifiedSentState: string): { sentState: any; error: null; } | { sentState: null; error: unknown; }; } declare const CodeChallengeSentState: z.ZodObject<{ csrf: z.ZodString; payload: z.ZodNullable; }, "strip", z.ZodTypeAny, { payload: string | null; csrf: string; }, { payload: string | null; csrf: string; }>; interface CodeChallengeSentState extends z.infer { } declare class IamHelper { static getAuthorizationCodeParams(urlSearchParams: string): { code: string | null; error: string | null; state: string; }; static currentUserIsHeadlessAccount(user: UserResponseV3 | null): boolean; static currentUserNeedsVerification(user: UserResponseV3 | null): boolean; static currentUserIsUpdatingEmail(user: UserResponseV3 | null): boolean; static currentUserIsEligible(user: UserResponseV3 | null): boolean; static isUserBanned(user: UserResponseV3 | UserResponseV4 | null): boolean; static currentUserDisplayNameIsEmpty(user: UserResponseV3 | UserResponseV4 | null, checkUniqueDisplayName?: boolean): boolean; } declare const MFADataResponse: z.ZodObject<{ mfa_token: z.ZodString; factors: z.ZodArray; default_factor: z.ZodString; }, "strip", z.ZodTypeAny, { mfa_token: string; factors: string[]; default_factor: string; }, { mfa_token: string; factors: string[]; default_factor: string; }>; interface MFADataResponse extends z.infer { } interface Verify2FAParam { factor: string | null; code: string | null; rememberDevice: boolean | null; mfaToken?: string | null; } interface Request2FAEmailCode { factor: string; mfaToken?: string | null; clientId?: string; } declare const AuthenticatorSecretKey: z.ZodObject<{ secretKey: z.ZodString; uri: z.ZodString; }, "strip", z.ZodTypeAny, { secretKey: string; uri: string; }, { secretKey: string; uri: string; }>; interface AuthenticatorSecretKey extends z.infer { } interface OAuthApiOptions { clientId: string; } /** * Oauth client functions */ declare class IamOAuthClient { conf: AxiosRequestConfig; namespace: string; options: OAuthApiOptions; sdk: AccelByteSDK; constructor(sdk: AccelByteSDK, args?: SdkConstructorParam); private newInstance; /** * POST [/iam/v3/logout](api) * * This method is used to remove __access_token__, __refresh_token__ from cookie and revoke token from usage. * Supported methods: * - VerifyToken to verify token from header * - AddTokenToRevocationList to revoke token with TTL */ logout: () => Promise<{ response: null; error: _accelbyte_sdk.ResponseError; } | { response: axios.AxiosResponse; error: null; }>; /** * POST [/iam/v3/oauth/revoke](api) * * This method revokes a token. * This method requires authorized requests header with Basic Authentication from client that establish the token.action code: 10706 */ revoke: ({ token }: { token: string; }) => Promise<_accelbyte_sdk.Response>; /** * POST [/iam/v3/oauth/mfa/verify](api) * * Verify 2FA code * This method is used for verifying 2FA code. * ##2FA remember device * To remember device for 2FA, should provide cookie: device_token or header: Device-Token * */ verify2FA: ({ factor, code, mfaToken, rememberDevice }: Verify2FAParam) => Promise>; /** * POST [/iam/v3/oauth/mfa/code](api) */ request2FAEmailCode: ({ mfaToken, factor }: Request2FAEmailCode) => Promise>; static exchangeTokenOauthByPlatformId: (platformId: string, client_id: string, data: { platform_token?: string | null; client_id?: string | null; device_id?: string | null; createHeadless?: boolean | null; macAddress?: string | null; skipSetCookie?: boolean | null; }, sdkAssemblyConfig: any) => Promise<_accelbyte_sdk.Response>; } declare const MFA_DATA_STORAGE_KEY = "mfaData"; interface MatchReceivedStateResult { error: unknown | null; result: { payload: string; codeVerifier: string; } | null; } declare const TWOFA_PAGE: z.ZodEnum<["authenticator", "backupCode", "email", "options", "verify"]>; type TWOFA_PAGE = z.TypeOf; interface MFAData { mfaToken: string; factors: string[]; defaultFactor: TWOFA_PAGE; email: string; } interface UserAuthorizationOptions { clientId: string; redirectURI: string; baseURL: string; } declare const LoginErrorParam: z.ZodEnum<["cancelled", "login_session_expired"]>; type LoginErrorParam = z.TypeOf; declare class LoginErrorCancelled extends Error { } declare class LoginErrorExpired extends Error { } declare class LoginErrorUnknown extends Error { } declare class LoginErrorUnmatchedState extends Error { } declare class IamUserAuthorizationClient { private sdk; conf: AxiosRequestConfig; namespace: string; options: UserAuthorizationOptions; constructor(sdk: AccelByteSDK, args?: SdkSetConfigParam); loginWithAuthorizationCode: ({ code, codeVerifier, deviceId }: { code: string; codeVerifier: string; deviceId?: string; }) => Promise<{ mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; response: null; error: _accelbyte_sdk.ResponseError; } | { mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; response: AxiosResponse; error: null; }>; loginWithPasswordAuthorization: ({ username, password, deviceId }: { username: string; password: string; deviceId?: string; }) => Promise<{ mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; response: null; error: _accelbyte_sdk.ResponseError; } | { mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; response: AxiosResponse; error: null; }>; static getMfaDataFromError: (errorResponse: AxiosResponse) => { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; static getMfaDataFromStorage: () => any; static removeMfaDataFromStorage: () => void; static matchReceivedState: (maybeSentState: string) => MatchReceivedStateResult; static deduceLoginError: (error: string) => LoginErrorCancelled | LoginErrorExpired | LoginErrorUnknown; loginWithCodeAuthorization: ({ code }: { code: string; }) => Promise<{ mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; response: AxiosResponse; error: null; }>; exchangeSSOAuthorizationCode: ({ code, error }: { code?: string | null; error?: string | null; }) => Promise<{ response: AxiosResponse; mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; returnPath: null; } | null>; exchangeAuthorizationCode: ({ code, error, state }: { code?: string | null; error?: string | null; state?: string | null; }) => Promise<{ response: AxiosResponse | null; mfaData: { mfaToken: any; factors: any; defaultFactor: any; email: any; } | undefined; returnPath: any; } | null>; createLoginURL: (returnPath?: string | null, targetAuthPage?: string, oneTimeLinkCode?: string) => string; createForgotPasswordURL: () => string; /** * @internal */ refreshToken: (_refreshToken?: string) => Promise | false>; private getSearchParams; } /** * @deprecated, this is original *Api class */ declare class IamUserClient { conf: AxiosRequestConfig; namespace: string; /** * @internal */ constructor(sdk: AccelByteSDK, args?: SdkSetConfigParam); /** * GET [/iam/v3/public/users/me](api) * * get currently logged-in user */ getCurrentUser: () => Promise<_accelbyte_sdk.Response>; /** * Render 2D Avatar via readyplayer.me POST [](https://docs.readyplayer.me/ready-player-me/avatars/2d-avatars/render-api) * @internal */ renderImageFromGlbModel: (data: { model: string; scene: string; }) => Promise<_accelbyte_sdk.Response>; /** * @internal */ newInstance(namespace?: string): Users$; } declare const ValidateableInputField: z.ZodEnum<["username", "displayName", "password", "email", "dateOfBirth"]>; type ValidateableInputField = z.infer; declare class InputValidationHelper { static validateDisplayName: (value: string, isRequired: boolean | undefined, validations: InputValidationDataPublic[], validateBadWord?: boolean) => "empty" | "lessThanLengthLimit" | "exceedLengthLimit" | "invalidFormat" | "containsBadWords" | "containsForbiddenWords" | null; static validateUserName: (value: string, validations: InputValidationDataPublic[], validateBadWord?: boolean) => "empty" | "lessThanLengthLimit" | "exceedLengthLimit" | "invalidFormat" | "containsBadWords" | null; static validateDateOfBirth: (value: string, validations: InputValidationDataPublic[]) => "empty" | null; static validatePassword: (value: string, validations: InputValidationDataPublic[]) => "empty" | "lessThanLengthLimit" | "exceedLengthLimit" | "invalidFormat" | null; static validateEmail: (value: string, validations: InputValidationDataPublic[]) => "empty" | "lessThanLengthLimit" | "exceedLengthLimit" | "invalidFormat" | "containsForbiddenWords" | null; static validateWithRegex: (value: string, { validation, isRequired }: { validation: ValidationDetailPublic; isRequired?: boolean; }) => "empty" | "lessThanLengthLimit" | "exceedLengthLimit" | "invalidFormat" | "containsForbiddenWords" | null; static getValidationDescription(key: ValidateableInputField, validations: InputValidationDataPublic[]): string[]; static getValidationByKey: (key: ValidateableInputField, validations: InputValidationDataPublic[]) => { description: { message: string[]; language: string; }; minLength: number; maxLength: number; regex: string; allowAllSpecialCharacters: boolean; allowDigit: boolean; allowLetter: boolean; allowSpace: boolean; allowUnicode: boolean; blockedWord: string[]; isCustomRegex: boolean; letterCase: string; maxRepeatingAlphaNum: number; maxRepeatingSpecialCharacter: number; minCharType: number; specialCharacterLocation: string; specialCharacters: string[]; avatarConfig?: { allowedPrefixes: string[]; preferRegex: boolean; regex: string; } | null | undefined; profanityFilter?: string | null | undefined; } | undefined; static formatBlockedWord: (value: string, blockedWord: string[]) => string | undefined; } declare enum IamConfigKey { UNIQUE_DISPLAY_NAME_ENABLED = "uniqueDisplayNameEnabled", USERNAME_DISABLED = "usernameDisabled", MANDATORY_EMAIL_VERIFICATION_ENABLED = "mandatoryEmailVerificationEnabled" } declare const mandatoryAccountUpgradeLocalStorageName: string; declare const IamConfigData: z.ZodObject<{ usernameDisabled: z.ZodDefault; uniqueDisplayNameEnabled: z.ZodDefault; mandatoryEmailVerificationEnabled: z.ZodDefault; }, "strip", z.ZodTypeAny, { uniqueDisplayNameEnabled: boolean; usernameDisabled: boolean; mandatoryEmailVerificationEnabled: boolean; }, { uniqueDisplayNameEnabled?: boolean | undefined; usernameDisabled?: boolean | undefined; mandatoryEmailVerificationEnabled?: boolean | undefined; }>; interface IamConfigData extends z.infer { } declare const ReadyPlayerMe: z.ZodObject<{ renders: z.ZodArray; }, "strip", z.ZodTypeAny, { renders: string[]; }, { renders: string[]; }>; type ReadyPlayerMe = z.TypeOf; declare const BanType: z.ZodEnum<["ORDER_AND_PAYMENT"]>; type BanType = z.infer; declare const EligibleUser: z.ZodObject, "many">; country: z.ZodString; createdAt: z.ZodString; dateOfBirth: z.ZodString; deletionStatus: z.ZodBoolean; displayName: z.ZodString; emailAddress: z.ZodString; emailVerified: z.ZodBoolean; enabled: z.ZodBoolean; lastDateOfBirthChangedTime: z.ZodString; lastEnabledChangedTime: z.ZodString; namespace: z.ZodString; newEmailAddress: z.ZodOptional>; oldEmailAddress: z.ZodString; permissions: z.ZodArray>; schedCron: z.ZodOptional>; schedRange: z.ZodOptional>>; }, "strip", z.ZodTypeAny, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }, { action: number; resource: string; schedAction?: number | null | undefined; schedCron?: string | null | undefined; schedRange?: string[] | null | undefined; }>, "many">; phoneNumber: z.ZodOptional>; phoneVerified: z.ZodBoolean; platformId: z.ZodOptional>; platformUserId: z.ZodOptional>; roles: z.ZodArray; uniqueDisplayName: z.ZodOptional>; userId: z.ZodString; username: z.ZodOptional>; }, "bans" | "userId" | "displayName" | "country" | "username" | "deletionStatus" | "emailAddress" | "emailVerified" | "newEmailAddress" | "oldEmailAddress">, "strip", z.ZodTypeAny, { bans: { ban: string; endDate: string; banId: string; }[]; userId: string; displayName: string; country: string; deletionStatus: boolean; emailAddress: string; emailVerified: boolean; oldEmailAddress: string; username?: string | null | undefined; newEmailAddress?: string | null | undefined; }, { bans: { ban: string; endDate: string; banId: string; }[]; userId: string; displayName: string; country: string; deletionStatus: boolean; emailAddress: string; emailVerified: boolean; oldEmailAddress: string; username?: string | null | undefined; newEmailAddress?: string | null | undefined; }>; type EligibleUser = z.TypeOf; export { AcceptedPoliciesRequest, AccountIdentifierTagAdmin$, AccountIdentifierTagAdminApi, AccountProgressionInfo, AddUserRoleV4Request, AdminBulkUserRequest, AgeRestrictionRequest, AgeRestrictionRequestV3, AgeRestrictionResponse, AgeRestrictionResponseV3, AllowedPermission, AssignUserV4Request, AssignedUserV4Response, AuthenticatorKeyResponseV4, AuthenticatorSecretKey, AvatarConfig, BackupCodesResponseV4, Ban, BanCreateRequest, BanReason, BanReasonV3, BanReasons, BanReasonsV3, BanType, BanUpdateRequest, BanV3, BannedBy, BannedByV3, Bans, Bans$, BansAdmin$, BansAdminApi, BansApi, BansV3, BulkAccountTypeUpdateRequestV4, BulkBanCreateRequestV3, BulkUnbanCreateRequestV3, CheckAvailabilityResponse, CheckValidUserIdRequestV4, ClientCreateRequest, ClientCreationResponse, ClientCreationV3Request, ClientModulePermission, ClientPermission, ClientPermissionSet, ClientPermissionV3, ClientPermissions, ClientPermissionsV3, ClientResponse, ClientResponseArray, ClientSelectedGroup, ClientTemplate, ClientUpdateRequest, ClientUpdateSecretRequest, ClientUpdateV3Request, ClientV3Response, Clients$, ClientsAdmin$, ClientsAdminApi, ClientsApi, ClientsConfigV3Admin$, ClientsConfigV3AdminApi, ClientsUpdateRequestV3, ClientsV3Response, CodeChallenge, Config$, ConfigAdmin$, ConfigAdminApi, ConfigApi, ConfigValueResponseV3, ConflictedUserPlatformAccounts, Country, Country$, CountryAdmin$, CountryAdminApi, CountryAgeRestriction, CountryAgeRestrictionArray, CountryAgeRestrictionRequest, CountryAgeRestrictionV3Request, CountryApi, CountryBlacklistRequest, CountryBlacklistResponse, CountryLocationResponse, CountryResponse, CountryResponseArray, CountryV3Response, CountryV3ResponseArray, CreateJusticeUserResponse, CreateTestUserRequestV4, CreateTestUserResponseV4, CreateTestUsersRequestV4, CreateTestUsersResponseV4, CreateUserRequestV4, CreateUserResponseV4, CursorGetUserRequest, CursorGetUserResponse, CursorGetUserResponseData, DefaultFieldValue, DefaultFieldValueValue, Description, DeviceBanRequestV4, DeviceBanResponseV4, DeviceBanUpdateRequestV4, DeviceBannedResponseV4, DeviceBansResponseV4, DeviceIdDecryptResponseV4, DeviceResponseV4, DeviceTypeResponseV4, DeviceTypesResponseV4, DeviceUserResponseV4, DeviceUsersResponseV4, DevicesResponseV4, DevicesV4Admin$, DevicesV4AdminApi, DisableMfaRequest, DisableUserRequest, DistinctLinkedPlatformV3, DistinctPlatformResponseV3, DlcAggResponse, EligibleUser, EmailUpdateRequestV4, EnabledFactorsResponseV4, ErrorResponse, ErrorResponseWithConflictedUserPlatformAccounts, FailedBanUnbanUserV3, FieldUpdateAllowStatus, FilterJson, ForgotPasswordRequestV3, ForgotPasswordResponseV3, ForgotPasswordWithoutNamespaceRequestV3, GetAdminUsersResponse, GetBulkUserBansRequest, GetLinkHeadlessAccountConflictResponse, GetProfileUpdateStrategyConfigResponse, GetPublisherUserResponse, GetUserBanSummaryV3, GetUserBanV3Response, GetUserJusticePlatformAccountResponse, GetUserMapping, GetUserMappingArray, GetUserMappingV3, GetUserMappingV3Array, GetUsersResponseWithPaginationV3, GroupAndRoleMappingForPatch, GroupAndRoleMappingForUpdate, Iam, IamConfigData, IamConfigKey, IamHelper, IamOAuthClient, IamUserAuthorizationClient, IamUserClient, InputValidationConfigVersion, InputValidationData, InputValidationDataPublic, InputValidationDescription, InputValidationHelper, InputValidationUpdatePayload, InputValidations$, InputValidationsAdmin$, InputValidationsAdminApi, InputValidationsApi, InputValidationsPublicResponse, InputValidationsResponse, InternalConfigResponseV3, InvitationHistoryResponse, InviteUserRequestV3, InviteUserRequestV4, InviteUserResponseV3, JwkKey, JwkSet, JwtBanV3, LinkHeadlessAccountRequest, LinkPlatformAccountRequest, LinkPlatformAccountWithProgressionRequest, LinkRequest, LinkingHistoryResponseWithPaginationV3, ListAssignedUsersV4Response, ListBulkUserBanResponseV3, ListBulkUserPlatformsResponse, ListBulkUserResponse, ListClientPermissionSet, ListEmailAddressRequest, ListInvitationHistoriesV4Response, ListRoleV4Response, ListTemplatesResponse, ListUpsertModulesRequest, ListUserInformationResult, ListUserResponseV3, ListUserRolesV4Response, ListUsersWithPlatformAccountsResponse, ListValidUserIdResponseV4, LoginAllowlistAdmin$, LoginAllowlistAdminApi, LoginAllowlistRequest, LoginAllowlistResponse, LoginErrorCancelled, LoginErrorExpired, LoginErrorParam, LoginErrorUnknown, LoginErrorUnmatchedState, LoginHistoriesResponse, LoginQueueTicketResponse, type MFAData, MFADataResponse, MFA_DATA_STORAGE_KEY, NamespaceInvitationHistoryUserV4Response, NamespaceRole, NamespaceRoleRequest, NetflixCertificates, OAuth$, OAuth20$, OAuth20Admin$, OAuth20AdminApi, OAuth20Api, OAuth20Extension$, OAuth20ExtensionApi, OAuth20V4$, OAuth20V4Api, OAuthApi, type OAuthApiOptions, OneTimeCodeLinkRedirectionResponse, OneTimeLinkingCodeResponse, OneTimeLinkingCodeValidationResponse, OverrideRoleConfigV3Admin$, OverrideRoleConfigV3AdminApi, OverrideRolePermission, Pagination, PaginationV3, Permission, PermissionDeleteRequest, PermissionGroup, PermissionSetDeleteGroupRequest, PermissionSetUpsertRequest, PermissionV3, Permissions, PermissionsV3, PlatformAccount, PlatformDomainDeleteRequest, PlatformDomainPatchRequest, PlatformDomainResponse, PlatformDomainUpdateRequest, PlatformLinkingHistory, PlatformTokenRefreshResponseV3, PlatformUserIdRequest, PlatformUserIdRequestV4, PlatformUserInformation, PlatformUserInformationV3, ProfileUpdateConfig, ProfileUpdateStrategy$, ProfileUpdateStrategyAdmin$, ProfileUpdateStrategyAdminApi, ProfileUpdateStrategyApi, ProgressionInfo, PublicInviteUserRequestV4, PublicOpenIdUserInfoResponse, PublicThirdPartyPlatformInfo, PublicThirdPartyPlatformInfoArray, PublicUserInformationResponseV3, PublicUserInformationV3, PublicUserResponse, PublicUserResponseV3, PublicUserUpdateRequestV3, PublicUsersResponse, QueryCursor, ReadyPlayerMe, RegisteredDomain, RemoveUserRoleV4Request, ReplaceRolePermission, type Request2FAEmailCode, ResetPasswordRequest, ResetPasswordRequestV3, RevocationList, RevokeUserV4Request, Role, RoleAdminStatusResponse, RoleAdminStatusResponseV3, RoleCreateRequest, RoleCreateV3Request, RoleManager, RoleManagerV3, RoleManagersRequest, RoleManagersRequestV3, RoleManagersResponse, RoleManagersResponsesV3, RoleMember, RoleMemberV3, RoleMembersRequest, RoleMembersRequestV3, RoleMembersResponse, RoleMembersResponseV3, RoleNamesResponseV3, RoleOverrideResponse, RoleOverrideSourceResponse, RoleOverrideStatsUpdateRequest, RoleOverrideUpdateRequest, RolePermissionResponseV3, RoleResponse, RoleResponseV3, RoleResponseWithManagers, RoleResponseWithManagersAndPaginationV3, RoleResponseWithManagersArray, RoleResponseWithManagersV3, RoleUpdateRequest, RoleUpdateRequestV3, RoleV3, RoleV4Request, RoleV4Response, Roles$, RolesAdmin$, RolesAdminApi, RolesApi, SearchUsersByPlatformIdResponse, SearchUsersResponse, SearchUsersResponseWithPaginationV3, SendRegisterVerificationCodeRequest, SendVerificationCodeRequest, SendVerificationCodeRequestV3, SendVerificationLinkRequest, SimpleProfileUpdateStrategyConfigs, SimpleUserBan, SimpleUserPlatformInfoV3, Sso$, SsoApi, SsoConfig, SsoConfigPatchReq, SsoCredentialAdmin$, SsoCredentialAdminApi, SsoPlatformCredentialRequest, SsoPlatformCredentialResponse, SsoPlatformCredentialResponseArray, SsoSaml20$, SsoSaml20Api, TWOFA_PAGE, TagCreateRequestV3, TagDetail, TagResponse, TagUpdateRequestV3, TagsGetResponseV3, TargetTokenCodeResponse, ThirdPartyCredential$, ThirdPartyCredentialAdmin$, ThirdPartyCredentialAdminApi, ThirdPartyCredentialApi, ThirdPartyLoginPlatformCredentialRequest, ThirdPartyLoginPlatformCredentialResponse, ThirdPartyLoginPlatformCredentialResponseArray, TicketEndpointAction, TokenIntrospectResponse, TokenResponse, TokenResponseV3, TokenThirdPartyLinkStatusResponse, TokenThirdPartyResponse, TokenWithDeviceCookieResponseV3, UnlinkUserPlatformRequest, UpdatePermissionScheduleRequest, UpdateProfileUpdateStrategyConfigRequest, UpdateUserDeletionStatusRequest, UpdateUserStatusRequest, UpgradeHeadlessAccountRequest, UpgradeHeadlessAccountRequestV4, UpgradeHeadlessAccountV3Request, UpgradeHeadlessAccountWithVerificationCodeForwardRequestV4, UpgradeHeadlessAccountWithVerificationCodeRequest, UpgradeHeadlessAccountWithVerificationCodeRequestV3, UpgradeHeadlessAccountWithVerificationCodeRequestV4, UserActiveBanResponse, UserActiveBanResponseV3, UserActiveBanResponseV4, UserBan, UserBanResponse, UserBanResponseArray, UserBanResponseV3, UserBanWithStatus, UserBaseInfo, UserBulkUpdateRequestV3, UserCreateRequest, UserCreateRequestV3, UserCreateResponse, UserCreateResponseV3, UserDeletionStatusResponse, UserIDsRequest, UserIdentityUpdateRequestV3, UserInfo, UserInfoResponse, UserInformation, UserInformationV3, UserInputValidationRequest, UserInputValidationResponse, UserInvitationHistory, UserInvitationV3, UserLinkedPlatform, UserLinkedPlatformArray, UserLinkedPlatformV3, UserLinkedPlatformsResponseV3, UserLoginHistoryResponse, UserMfaStatusResponseV4, UserMfaTokenResponseV4, UserPasswordUpdateRequest, UserPasswordUpdateV3Request, UserPermissionsResponseV3, UserPermissionsResponseV4, UserPlatformInfo, UserPlatformInfos, UserPlatformLinkHistories, UserPlatformLinkHistory, UserPlatformMetadata, UserPlatforms, UserProfileUpdateAllowStatus, UserPublicInfoResponseV4, UserResponse, UserResponseArray, UserResponseV3, UserResponseV4, UserRevocationListRecord, UserRolesV4Response, UserSearchByPlatformIdResult, UserSearchResult, UserStateResponseV3, UserUnbanCreateRequestV3, UserUpdateRequest, UserUpdateRequestV3, UserVerificationRequest, UserVerificationRequestV3, UserWithLinkedPlatformAccounts, UserWithPlatformAccounts, UserWithPlatformInfo, Users$, UsersAdmin$, UsersAdminApi, UsersApi, UsersPlatformInfosRequestV3, UsersPlatformInfosResponse, UsersUpdateRequestV3, UsersV4$, UsersV4Admin$, UsersV4AdminApi, UsersV4Api, V3ClientUpdateSecretRequest, ValidUserIdResponseV4, ValidateableInputField, Validation, ValidationDescription, ValidationDetail, ValidationDetailPublic, VerificationCodeResponse, type Verify2FAParam, VerifyRegistrationCode, WalletAggResponse, WebLinkingResponse, mandatoryAccountUpgradeLocalStorageName };