/api/v1/auth/shared-browser-clusters
GET
Accounts that logged in from the same browser, grouped by the person they most likely belong to. A browser is recognised by a cookie the server sets on the first visit. Two accounts join the same cluster when they share a browser, and transitively: if Alice shares one browser with Bob and Bob shares another with Carol, all three are one cluster.
Administrators only. Anyone else gets 403.
This is a signal to review, not a verdict: a family computer shares its browser too.
Clusters are sorted by number of accounts, then by most recent shared session.
Inside a cluster, accounts are sorted by last_session_at, most recent first.
An account's last_session_at is its latest activity on any browser, not only
the shared ones, and is null when the account has no session left.
Query parameters
| Name | Type | Required | Meaning |
|---|---|---|---|
offset | integer | no | Number of clusters to skip. Defaults to 0. |
limit | integer | yes | Maximum number of clusters to return. |
count is the total number of clusters, for laying out pages.
Example
GET /api/v1/auth/shared-browser-clusters?offset=0&limit=1 Cookie: sid=b8be19ef-2d61-44de-b7d2-9c34ccb8a763
{
"offset": 0,
"limit": 1,
"count": 12,
"items": [
{
"accounts": [
{
"user": {
"type": "User",
"id": "28dbb0bf-0fdc-40fe-ae5a-dde193f9fea8",
"display_name": {"current": {"value": "Alice"}},
"username": "alice",
"is_banned": false
},
"last_session_at": "2026-09-14T08:21:03.114Z"
},
{
"user": {
"type": "User",
"id": "a2c4e4b6-9d1f-4b1e-8a55-2f6b0c3d7e19",
"display_name": {"current": {"value": "Bob"}},
"username": "bob",
"is_banned": true
},
"last_session_at": null
}
],
"browsers": [
{
"browser_id": "0f3c1a52-6e7d-4c8b-9a1e-5d2b7f4e8c60",
"user_count": 2,
"last_session_at": "2026-09-14T08:21:03.114Z"
}
],
"last_session_at": "2026-09-14T08:21:03.114Z"
}
]
}