Skip to main content
POST
Start user impersonation

Authorizations

Authorization
string
header
required

JWT token authentication

Headers

NexSpace-Version
string

Pin the request to a dated API version (e.g. 2026-05-10). Applied by app-level middleware to every /api route (server/routes/index.ts → apiVersionMiddleware), which echoes the resolved value back in the NexSpace-Version response header. Omit to get the latest version. Discover the catalog at GET /.well-known/api-versions.

Pattern: ^\d{4}-\d{2}-\d{2}$
Idempotency-Key
string

Replay guard for write requests. Applied by app-level middleware to every /api route (server/routes/index.ts → idempotencyMiddleware), which only acts on POST/PUT/PATCH — GET, DELETE and OPTIONS ignore the header. Re-sending the same key with an identical body within 24 hours replays the original response; the same key with a different body returns 409.

Maximum string length: 255

Body

application/json
targetUserId
integer
required

ID of the record to impersonate — a users.id, facility_users.id, or staff.id depending on userType.

userType
enum<string>
default:user

Which table targetUserId points at. Optional — the handler defaults to user.

Available options:
user,
facility_user,
staff

Response

Impersonation started successfully

success
boolean
message
string
user
object
Example:
impersonationAccessToken
string

Present ONLY for bearer (native/mobile) sessions whose target resolves to a login identity: a short-lived access token that acts as the target and carries the original operator in its impersonation claim. Cookie sessions and staff targets with no linked users row omit this field — those callers rely on the server session instead.