---
title: "Initialize Recovery Flow for API Clients"
method: GET
path: "/self-service/recovery/api"
tags: ["public"]
---

# Initialize Recovery Flow for API Clients

`GET /self-service/recovery/api`

This endpoint initiates a recovery flow for API clients such as mobile devices, smart TVs, and so on.

If a valid provided session cookie or session token is provided, a 400 Bad Request error.

To fetch an existing recovery flow call `/self-service/recovery/flows?flow=<flow_id>`.

:::warning

You MUST NOT use this endpoint in client-side (Single Page Apps, ReactJS, AngularJS) nor server-side (Java Server
Pages, NodeJS, PHP, Golang, ...) browser applications. Using this endpoint in these applications will make
you vulnerable to a variety of CSRF attacks.

This endpoint MUST ONLY be used in scenarios such as native mobile apps (React Native, Objective C, Swift, Java, ...).

:::

More information can be found at [Ory Kratos Account Recovery Documentation](../self-service/flows/account-recovery.mdx).

## Response `200`

recoveryFlow

- RecoveryFlow — This request is used when an identity wants to recover their account. We recommend reading the [Account Recovery Documentation](../self-service/flows/password-reset-account-recovery)
  - `active` string — Active, if set, contains the registration method that is being used. It is initially not set.
  - `expires_at` string, date-time, required — ExpiresAt is the time (UTC) when the request expires. If the user still wishes to update the setting, a new request has to be initiated.
  - `id` string, uuid4, required
  - `issued_at` string, date-time, required — IssuedAt is the time (UTC) when the request occurred.
  - `messages` UiText[]
    - `context` object — The message's context. Useful when customizing messages.
    - `id` integer, required
    - `text` string, required — The message text. Written in american english.
    - `type` string, required
  - `methods` object, required — Methods contains context for all account recovery methods. If a registration request has been processed, but for example the password is incorrect, this will contain error messages.
  - `request_url` string, required — RequestURL is the initial URL that was requested from Ory Kratos. It can be used to forward information contained in the URL's path or query for example.
  - `state` string, required
  - `type` string — The flow type can either be `api` or `browser`.

## Other responses

- `400` — genericError
- `500` — genericError

---

[API](https://skmtc.dev/ory/apis/ory-kratos-api.md) · [All operations](https://skmtc.dev/ory/apis/ory-kratos-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ory/ory-kratos-api/revisions/e77b8bae3f57/schema)
