Identity & User Objects

YS Desk distinguishes between authenticated Workspace Team Members, external Visitors, and Visitor Sessions.

Identity Architecture

There are three primary identity contexts:

IdentityPurposeAuthentication Context
Team MemberInternal Workspace user such as Owner, Admin, or AgentAuthenticated dashboard identity
VisitorExternal user interacting through Web ChatVisitor identity associated with Workspace and Channel
Visitor SessionTime-bound Web Chat authentication contextHMAC-SHA256 signed session

A Visitor can be represented by a User record with role: GUEST.

User Object

A User represents a Workspace member or Visitor. For Team Members, relevant roles include Owner, Admin, and Agent.

Team Member Fields

FieldTypeDescription
idstringUnique User identifier.
uuidstringPublic external identifier where available.
namestringDisplay name.
emailstringUser email address.
picturestringProfile image URL.
roleRoleWorkspace role.
isOnlinebooleanCurrent online presence state.
workspaceIdstringWorkspace association.
createdAtISO-8601 timestampCreation timestamp.
updatedAtISO-8601 timestampLast update timestamp.

Authentication-provider identifiers and authentication secrets are not part of the public Reference specification.

Guest Object

A Guest represents an external Web Chat Visitor.

Relevant identity fields include:

FieldDescription
idGuest User identifier.
uuidPublic external identifier where available.
nameVisitor display name.
emailVisitor email when provided.
roleGUEST.
channelIdChannel associated with the Visitor.
workspaceIdWorkspace associated with the Visitor.
isOnlineCurrent Visitor presence state.

Visitor records are workspace- and channel-scoped.

Visitor Session Token

Visitor sessions use an HMAC-SHA256 signed session token.

Claims

{

  “workspaceId”: “<WORKSPACE_ID>”,

  “channelId”: “<CHANNEL_ID>”,

  “guestId”: “<GUEST_ID>”,

  “conversationId”: “<CONVERSATION_ID>”,

  “iat”: 0,

  “exp”: 0

}

Claim Definitions

ClaimTypeDescription
workspaceIdstringWorkspace to which the session belongs.
channelIdstringChannel through which the session was established.
guestIdstringVisitor identity when available.
conversationIdstringAssociated Conversation when available.
iatnumberToken issuance timestamp.
expnumberToken expiration timestamp.

The session token binds the Visitor session to the expected Workspace and Channel context. Invalid or expired sessions produce INVALID_VISITOR_SESSION.

User Presence & History

Presence and login-history data can contain device and connection context such as:

  • IP address representation
  • Browser
  • Operating system
  • Browser name
  • Device type
  • Session identifier
  • Origin URL
  • Login timestamp
  • Geolocation information

Geolocation data may include:

city, region, country, latitude, longitude, timezone

Raw socket identifiers and session secrets are excluded from the public Reference specification.

Invitation Object

Invitations represent pending Workspace membership invitations.

Relevant fields include:

FieldTypeDescription
idstringInvitation identifier.
emailstringInvitee email address.
roleRoleRole assigned when the invitation is accepted.
permissionsobjectPermission configuration associated with the invitation.
expiresAtISO-8601 timestampInvitation expiration time.
usedAtISO-8601 timestampAcceptance timestamp when used.
workspaceIdstringTarget Workspace identifier.

The invitation token itself must not be published as a real credential. Use <INVITATION_TOKEN> in examples.

Need Help?

Email: support@ysdesk.com

Documentation: https://docs.ysplugins.com/ys-desk

Next