Fac-360
Companies

The companies this session can operate

A listing, not an authorisation: it resolves membership across organizations and binds nothing. Selecting one is GET /console/v1/companies/{companyId}, which is where the membership check and the assignment of app.tenant_id happen as one act.

GET
/console/v1/companies

A listing, not an authorisation: it resolves membership across organizations and binds nothing. Selecting one is GET /console/v1/companies/{companyId}, which is where the membership check and the assignment of app.tenant_id happen as one act.

Authorization

consoleSession
__Host-apf_console<token>

Set by POST /console/v1/sessions. HttpOnly, Secure, SameSite=Strict, Path=/, __Host- prefixed. It is never readable by JavaScript and there is no header alternative: accepting both carriers would let an attacker choose the weaker one.

In: cookie

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/console/v1/companies" \  -H "Authorization: Bearer apf_v2_tu_credencial"
{  "schemaVersion": "console.1",  "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",  "companies": [    {      "companyId": "8bb73d03-06b4-47c7-80c7-59301f770eda",      "ruc": "string",      "legalName": "string",      "status": "ACTIVE",      "environment": "BETA",      "organizationId": "7bc05553-4b68-44e8-b7bc-37be63c6d9e9",      "memberRole": "OWNER"    }  ]}