Active sessions and devices, and account protection. Sessions are managed by SS-01 (GET/DELETE /sessions · POST /sessions/end-others).
TOTP / passkey MFA is not yet exposed by the SS-01 identity contract, so we don't show a partial flow. When the endpoints land, you'll enrol an authenticator app or security key right here. Want early access?