curl https://phosra-api-sandbox-production.up.railway.app/oauth/profiles \
-H "Authorization: Bearer sbxtok_9xRWtUBLsk1omBYjWWe-20KbCxTO1Noh"const BASE = "https://phosra-api-sandbox-production.up.railway.app"
const res = await fetch(`${BASE}/oauth/profiles`, { headers: { Authorization: "Bearer sbxtok_9xRWtUBLsk1omBYjWWe-20KbCxTO1Noh" } })
const profiles = await res.json() // bare array
console.log(res.status, profiles.map((p) => p.displayName)) // 200 [ 'Mia', 'Leo', 'Ava' ]
import requests
url = "https://phosra-api-sandbox-production.up.railway.app/oauth/profiles"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://phosra-api-sandbox-production.up.railway.app/oauth/profiles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://phosra-api-sandbox-production.up.railway.app/oauth/profiles"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://phosra-api-sandbox-production.up.railway.app/oauth/profiles")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://phosra-api-sandbox-production.up.railway.app/oauth/profiles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"id": "mia",
"displayName": "Mia",
"subject_ref": "a11ce0fa-0000-4000-8000-0000000000a1",
"kind": "child"
},
{
"id": "leo",
"displayName": "Leo",
"subject_ref": "a11ce0fa-0000-4000-8000-0000000000a2",
"kind": "child"
},
{
"id": "ava",
"displayName": "Ava",
"subject_ref": "a11ce0fa-0000-4000-8000-0000000000a3",
"kind": "child"
}
]{
"error": "invalid_token"
}404 page not found
{
"error": "Too Many Requests",
"message": "rate limit exceeded",
"code": 429
}{
"error": "Internal Server Error",
"message": "internal error",
"code": 500
}{
"error": "Bad Gateway",
"message": "downstream provider error",
"code": 502
}{
"error": "Service Unavailable",
"message": "downstream provider unavailable",
"code": 503
}Reference profiles leg — child list (sandbox)
SANDBOX-ONLY. Returns a BARE JSON ARRAY of the seeded sandbox child profiles (Mia/Leo/Ava) for a valid Authorization: Bearer sbxtok_… token. Gated on the Restricted band. Source: internal/ocsshttp/handler_sandbox_oauth.go Profiles().
curl https://phosra-api-sandbox-production.up.railway.app/oauth/profiles \
-H "Authorization: Bearer sbxtok_9xRWtUBLsk1omBYjWWe-20KbCxTO1Noh"const BASE = "https://phosra-api-sandbox-production.up.railway.app"
const res = await fetch(`${BASE}/oauth/profiles`, { headers: { Authorization: "Bearer sbxtok_9xRWtUBLsk1omBYjWWe-20KbCxTO1Noh" } })
const profiles = await res.json() // bare array
console.log(res.status, profiles.map((p) => p.displayName)) // 200 [ 'Mia', 'Leo', 'Ava' ]
import requests
url = "https://phosra-api-sandbox-production.up.railway.app/oauth/profiles"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://phosra-api-sandbox-production.up.railway.app/oauth/profiles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://phosra-api-sandbox-production.up.railway.app/oauth/profiles"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://phosra-api-sandbox-production.up.railway.app/oauth/profiles")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://phosra-api-sandbox-production.up.railway.app/oauth/profiles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body[
{
"id": "mia",
"displayName": "Mia",
"subject_ref": "a11ce0fa-0000-4000-8000-0000000000a1",
"kind": "child"
},
{
"id": "leo",
"displayName": "Leo",
"subject_ref": "a11ce0fa-0000-4000-8000-0000000000a2",
"kind": "child"
},
{
"id": "ava",
"displayName": "Ava",
"subject_ref": "a11ce0fa-0000-4000-8000-0000000000a3",
"kind": "child"
}
]{
"error": "invalid_token"
}404 page not found
{
"error": "Too Many Requests",
"message": "rate limit exceeded",
"code": 429
}{
"error": "Internal Server Error",
"message": "internal error",
"code": 500
}{
"error": "Bad Gateway",
"message": "downstream provider error",
"code": 502
}{
"error": "Service Unavailable",
"message": "downstream provider unavailable",
"code": 503
}/api/v1), gated on
PHOSRA_ENV==sandbox — 404 elsewhere.Authorization: Bearer sbxtok_… token from
POST /oauth/token. The response is not wrapped in
an object — it is the array itself.
Worked example
Fully runnable — supply a token from the token leg:curl https://phosra-api-sandbox-production.up.railway.app/oauth/profiles \
-H "Authorization: Bearer sbxtok_9xRWtUBLsk1omBYjWWe-20KbCxTO1Noh"
const BASE = "https://phosra-api-sandbox-production.up.railway.app"
const res = await fetch(`${BASE}/oauth/profiles`, {
headers: { Authorization: "Bearer sbxtok_9xRWtUBLsk1omBYjWWe-20KbCxTO1Noh" },
})
const profiles = await res.json() // bare array
console.log(res.status, profiles.map((p) => p.displayName)) // 200 [ 'Mia', 'Leo', 'Ava' ]
200 response (captured from the hosted sandbox):
[
{ "id": "mia", "displayName": "Mia", "subject_ref": "a11ce0fa-0000-4000-8000-0000000000a1", "kind": "child" },
{ "id": "leo", "displayName": "Leo", "subject_ref": "a11ce0fa-0000-4000-8000-0000000000a2", "kind": "child" },
{ "id": "ava", "displayName": "Ava", "subject_ref": "a11ce0fa-0000-4000-8000-0000000000a3", "kind": "child" }
]
sbxtok_ bearer token returns 401 invalid_token. The subject_ref is the
stable child id that downstream policy and enforcement legs key on.Authorizations
SANDBOX-ONLY opaque bearer ("sbxtok_…") issued by POST /oauth/token, presented to GET /oauth/profiles. Not a production credential — the sandbox reference OAuth surface is stateless and gated on PHOSRA_ENV==sandbox.
Response
Bare array of child profiles (NOT wrapped in an object).
Unique identifier for this resource.
"mia"
Human-readable child display name shown on the consent page.
"Mia"
Stable child id downstream policy/enforcement legs key on.
"a11ce0fa-0000-4000-8000-0000000000a1"
Profile kind; always child for the seeded sandbox family.
"child"