---
title: "GET /api/v1/agent-vault/sessions/{sessionId}"
method: GET
path: "/api/v1/agent-vault/sessions/{sessionId}"
tags: ["Agent Vault Sessions"]
---

# GET /api/v1/agent-vault/sessions/{sessionId}

`GET /api/v1/agent-vault/sessions/{sessionId}`

Gets an Agent Vault session.

## Path parameters

- `sessionId` string, uuid, required

## Response `200`

Default Response

- object
  - `session` object, required
    - `id` string, uuid, required — The ID of the session.
    - `actor` union, required
      - object
        - `type` 'user', required — Whether the session belongs to a user or a machine identity.
        - `id` string, uuid, nullable, required — The ID of the user or machine identity the session belongs to, or null if it was deleted.
        - `username` string, required — The username of the user. Once the user is deleted, the email recorded when the session was created.
        - `email` string, nullable, required — The email address of the user. Once the user is deleted, the email recorded when the session was created.
        - `firstName` string, nullable, required — The first name of the user. Once the user is deleted, the full name recorded when the session was created.
        - `lastName` string, nullable, required — The last name of the user, or null once the user is deleted.
      - object
        - `type` 'machineIdentity', required — Whether the session belongs to a user or a machine identity.
        - `id` string, uuid, nullable, required — The ID of the user or machine identity the session belongs to, or null if it was deleted.
        - `name` string, required — The name of the machine identity. Once the machine identity is deleted, the name recorded when the session was created.
    - `status` 'active' | 'revoked' | 'expired', required
    - `expiresAt` string, date-time, nullable, required — When the session expires, or null when it never does.
    - `revokedAt` string, date-time, nullable, required
    - `createdAt` string, date-time, required
    - `accessBundles` object[], required
      - `id` string, uuid, nullable, required
      - `name` string, required
      - `position` number, required
    - `recentSessionLogCounts` object, required — How many of the session's requests were recorded in its session log, and how many the proxy couldn't record, over the 24 hours before its most recent recorded request.
      - `recordedCount` number, required — The number of requests recorded in the session log.
      - `droppedCount` number, required — The number of requests the proxy couldn't record in the session log.

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-30** `b1861c910818` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/agent-vault/sessions/:sessionId/get.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/3f1f969fcbcb?raw)
