List CLI sessions for org members (admin)
Admin oversight of every active CLI session belonging to a member of orgId. Returns the same per-device shape as the personal /api/auth/cli/sessions endpoint, plus the owning member's id/email/name. Visibility scoped to the org's CURRENT roster — a member who left no longer surfaces here. Owner/admin only.
CLI sessions are user-scoped, NOT space-scoped: a session is created by appstrate login against a user account, and is reusable across every space the user can reach. This endpoint therefore returns every active session held by a member of the org, regardless of which space(s) that member operates in — an admin auditing one space surface still sees CLI sessions that the same human is using to drive a different space in the same org.
/api/orgs/{orgId}/cli-sessionsCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Path Parameters
curl -X GET "https://your-instance/api/orgs/string/cli-sessions"{
"object": "list",
"data": [
{
"familyId": "string",
"userId": "string",
"userEmail": "string",
"userName": "string",
"deviceName": "string",
"userAgent": "string",
"createdIp": "string",
"lastUsedIp": "string",
"lastUsedAt": "2019-08-24T14:15:22Z",
"createdAt": "2019-08-24T14:15:22Z",
"expiresAt": "2019-08-24T14:15:22Z",
"current": true
}
],
"hasMore": true
}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/rate-limited",
"title": "Rate Limited",
"status": 429,
"detail": "Too many requests. Please try again shortly.",
"code": "rate_limited",
"request_id": "req_abc123",
"retry_after": 30
}