One route family for every provider whose credential lives in this daemon's own auth tree — sign in, finish or abandon a sign-in, list what is connected with how full each account's limits were, rename one, disconnect one. The provider is a parameter rather than a group of its own because the operations are the same six for all of them; what differs is each provider's mechanism, which its own module declares. The translator group next door is the other shape of the same idea, for subscriptions a proxy holds and re-serves. No answer here can carry a credential: the account rows have no field one could ride in, and a sign-in's proof never leaves the sandbox.
7 calls. Pick one to open it, or use the list on the right.
POST/accounts/{provider}/login/startBegin connecting an account
Hands back the page to sign in on, and the code it will ask for where there is one. The sandbox holds the proof and finishes what it can itself: a device sign-in lands in the account list on its own, a paste or a redirect needs one thing brought back to the finishing call.
What you send
Field
Type
Where
providerrequired
"claude" | "codex" | "grok" | "kimi" … (8)
address
variantWhich estate to sign in to
string
body
What comes back
Field
Type
urlThe page to open and sign…
string
codeThe one-time code the page will…
string
stateFor a redirect sign-in, the marker…
string
flowHow this attempt ends
"device" | "redirect" | "paste"
variantWhich of the provider's estates this…
string
handshakeThis attempt's id, for finishing or…
string
expiresAtWhen this attempt stops being answerable,…
import { sandbox } from "@intentic/sandbox-client";const result = await sandbox.accounts.start({ "provider": "claude", "variant": "…"});
POST/accounts/{provider}/login/completeFinish a sign-in with what the page handed back
Takes the code the page showed, or the address a redirect landed on, and finishes the attempt. Answers with the account where the exchange ends here; otherwise the sandbox still has a mint to do and the row appears in the account list.
What you send
Field
Type
Where
providerrequired
"claude" | "codex" | "grok" | "kimi" … (8)
address
handshakerequiredWhich attempt this belongs to
string
body
codeThe code the sign-in page showed,…
string
body
redirectUrlThe address the browser was sent…
string
body
labelWhat to call the account
string
body
What comes back
Field
Type
accountThe account it connected, where the…
object
idThe account's id, which is what…
string
labelWhat it is called here, which…
string
emailWho it signs in as, in…
string
organizationWhich organisation it belongs to, where…
string
variantWhich of the provider's estates it…
string
scopeWhat the credential is permitted to…
string
connectedAtWhen it was connected, in milliseconds
number
needsReauthIts stored credential can no longer…
boolean
detailWhy, in words a person can…
string
seatRefusalIts organisation has switched it off…
string
usageHow full its plan limits were…
object
windows
object[]
kind
string
label
string
utilization
number
resetsAt
number
gates
"all" | "none" | object
measuredAt
number
unreadPresent while re-reading this account keeps…
GET/accounts/{provider}/login/statusRead a sign-in attempt
Whether this exact attempt is still waiting, has connected an account, or failed. Tied to the attempt, not to the account list, so adding a second account is told apart from the first already being there. An attempt that finishes by itself on a device or browser of yours ends here.
What you send
Field
Type
Where
providerrequired
"claude" | "codex" | "grok" | "kimi" … (8)
address
handshakerequiredWhich attempt
string
query
What comes back
Field
Type
when status is "wait"
shape
when status is "ok"
shape
accountThe account it connected
object
idThe account's id, which is what…
string
labelWhat it is called here, which…
string
emailWho it signs in as, in…
string
organizationWhich organisation it belongs to, where…
string
variantWhich of the provider's estates it…
string
scopeWhat the credential is permitted to…
string
connectedAtWhen it was connected, in milliseconds
number
needsReauthIts stored credential can no longer…
boolean
detailWhy, in words a person can…
string
seatRefusalIts organisation has switched it off…
string
usageHow full its plan limits were…
object
windows
object[]
measuredAt
number
unreadPresent while re-reading this account keeps…
import { sandbox } from "@intentic/sandbox-client";const result = await sandbox.accounts.cancel({ "provider": "claude", "handshake": "…"});
GET/accounts/{provider}Connected accounts of a provider
Each connected account with how full its plan limits were when last measured, where the provider publishes any. Ask for a fresh measurement and it takes one before answering, which is slower. The credentials themselves never travel: being in this list is what connected means.
What you send
Field
Type
Where
providerrequired
"claude" | "codex" | "grok" | "kimi" … (8)
address
forceMeasure the plan limits again before…
string
query
What comes back
Field
Type
accountsThe connected accounts
object[]
idThe account's id, which is what…
string
labelWhat it is called here, which…
string
emailWho it signs in as, in…
string
organizationWhich organisation it belongs to, where…
string
variantWhich of the provider's estates it…
string
scopeWhat the credential is permitted to…
string
connectedAtWhen it was connected, in milliseconds
number
needsReauthIts stored credential can no longer…
boolean
detailWhy, in words a person can…
string
seatRefusalIts organisation has switched it off…
string
usageHow full its plan limits were…
object
windows
object[]
kind
string
label
string
utilization
number
resetsAt
number
gates
"all" | "none" | object
measuredAt
number
unreadPresent while re-reading this account keeps…