API: Account

Profile, password, notification preferences, auto-renew, two-factor authentication and API keys.

These endpoints act on the account that owns the key or token used to call them.

Update your profile

PATCH /account/profile

Changes name, phone or avatar. The email cannot be changed here.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
name string No
phone string No
avatar_url string No

Responses

  • 200 OK. Returns User.
  • 422 Validation error, or not allowed in the current state

Example

curl -X PATCH https://veneshcloud.ir/api/account/profile \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Change your password

POST /account/password

Checks the current password and sets a new one.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
current_password string Yes
new_password string Yes
new_password_confirmation string Yes

Responses

  • 200 OK
  • 422 Validation error, or not allowed in the current state

Example

curl -X POST https://veneshcloud.ir/api/account/password \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"current_password":"your-password","new_password":"your-new-password","new_password_confirmation":"your-new-password"}'

Read notification preferences

GET /account/notification-preferences

Returns the email and SMS switches for each category.

Authentication: Send your API key or token as a bearer token.

Responses

  • 200 OK. Returns: data (NotificationPreferences).

Example

curl -X GET https://veneshcloud.ir/api/account/notification-preferences \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Update notification preferences

PATCH /account/notification-preferences

Changes some switches; the ones you leave out stay as they are.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
preferences object Yes

Responses

  • 200 OK. Returns: data (NotificationPreferences).
  • 422 Validation error, or not allowed in the current state

Example

curl -X PATCH https://veneshcloud.ir/api/account/notification-preferences \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"preferences":{}}'

Read auto-renew

GET /account/auto-renew

Returns whether automatic renewal is on for the account.

Authentication: Send your API key or token as a bearer token.

Responses

  • 200 OK. Returns: auto_renew (boolean).

Example

curl -X GET https://veneshcloud.ir/api/account/auto-renew \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Update auto-renew

PATCH /account/auto-renew

Turns automatic renewal on or off for the whole account.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
auto_renew boolean Yes

Responses

  • 200 OK. Returns: auto_renew (boolean).
  • 422 Validation error, or not allowed in the current state

Example

curl -X PATCH https://veneshcloud.ir/api/account/auto-renew \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"auto_renew":true}'

Start two-factor setup

POST /account/2fa/setup

Begins enabling two-factor authentication with the chosen method. For an authenticator app it returns the secret, an otpauth_url for a QR code and one-time recovery codes, shown only once. Nothing is enabled until you confirm.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
method string No totp, email, sms

Responses

  • 200 OK. Returns: method (string), secret (string), otpauth_url (string), destination_masked (string), expires_in_minutes (integer), recovery_codes (list of string).
  • 422 Validation error, or not allowed in the current state

Example

curl -X POST https://veneshcloud.ir/api/account/2fa/setup \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Resend the setup code

POST /account/2fa/resend

Sends the confirmation code again for an email or SMS setup that is pending.

Authentication: Send your API key or token as a bearer token.

Responses

  • 200 OK. Returns: message (string), expires_in_minutes (integer).
  • 422 Validation error, or not allowed in the current state
  • 429 Too many requests

Example

curl -X POST https://veneshcloud.ir/api/account/2fa/resend \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Confirm and enable two-factor

POST /account/2fa/confirm

Checks the first code and switches two-factor authentication on.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
code string Yes

Responses

  • 200 OK. Returns: message (string), two_factor_enabled (boolean), method (string).
  • 422 Validation error, or not allowed in the current state

Example

curl -X POST https://veneshcloud.ir/api/account/2fa/confirm \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"code":"123456"}'

Send a code to disable two-factor

POST /account/2fa/disable-code

For email or SMS accounts, sends the code needed to switch two-factor off.

Authentication: Send your API key or token as a bearer token.

Responses

  • 200 OK. Returns: message (string), expires_in_minutes (integer).
  • 422 Validation error, or not allowed in the current state
  • 429 Too many requests

Example

curl -X POST https://veneshcloud.ir/api/account/2fa/disable-code \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Disable two-factor

POST /account/2fa/disable

Needs your current password and a valid code.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
current_password string Yes
code string Yes

Responses

  • 200 OK. Returns: message (string), two_factor_enabled (boolean).
  • 422 Validation error, or not allowed in the current state

Example

curl -X POST https://veneshcloud.ir/api/account/2fa/disable \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"current_password":"your-password","code":"123456"}'

Send a phone verification code

POST /account/phone/send-code

Texts a verification code to the phone number on your account.

Authentication: Send your API key or token as a bearer token.

Responses

  • 200 OK. Returns: message (string), destination_masked (string), expires_in_minutes (integer).
  • 422 Validation error, or not allowed in the current state
  • 429 Too many requests

Example

curl -X POST https://veneshcloud.ir/api/account/phone/send-code \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Verify your phone number

POST /account/phone/verify

Checks the texted code and marks the phone number as verified. Changing the number resets verification.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
code string Yes

Responses

  • 200 OK. Returns: data (User).
  • 422 Validation error, or not allowed in the current state

Example

curl -X POST https://veneshcloud.ir/api/account/phone/verify \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"code":"123456"}'

List API keys

GET /account/api-keys

Returns your keys without their secret values.

Authentication: Send your API key or token as a bearer token.

Responses

  • 200 OK. Returns: data (list of ApiKey).

Example

curl -X GET https://veneshcloud.ir/api/account/api-keys \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Create an API key

POST /account/api-keys

Creates a key and returns its secret in token exactly once. It cannot be shown again.

Authentication: Send your API key or token as a bearer token.

Request body (application/json)

Field Type Required Values
name string Yes

Responses

  • 201 Created. Returns: data (ApiKey), token (string).
  • 422 Validation error, or not allowed in the current state

Example

curl -X POST https://veneshcloud.ir/api/account/api-keys \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"name":"my-name"}'

Revoke an API key

DELETE /account/api-keys/{id}

Deletes the key. Anything using it stops working immediately.

Authentication: Send your API key or token as a bearer token.

Path parameters

Field Type
id integer

Responses

  • 204 Done, no content returned
  • 404 Not found

Example

curl -X DELETE https://veneshcloud.ir/api/account/api-keys/KEY_ID \
  -H "Authorization: Bearer $VENESH_API_KEY" \
  -H "Accept: application/json"

Objects

Field lists for the objects returned above.

ApiKey

Field Type Values
id integer
name string
abilities list of string
last_used_at string
created_at string

NotificationChannelPair

Field Type Values
email boolean
sms boolean

NotificationPreferences

Field Type Values
order_updates NotificationChannelPair
billing NotificationChannelPair
support NotificationChannelPair
security NotificationChannelPair

User

Field Type Values
id integer
name string
email string
phone string
avatar_url string
role string admin, support_tech, support_finance, support_sales, customer
email_verified boolean
phone_verified boolean
two_factor_enabled boolean
two_factor_method string totp, email, sms
created_at string