← All action domains

Profile

4 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.

Forget all browsers

profile.forget_trusted_browserswriteconfirm

Remove every browser that was set to skip the two-factor step for this account, so the next sign-in on each one asks for a second factor again. Use this when a laptop or phone is lost or stolen. It signs nobody out and removes no sign-in method — it only withdraws the ‘don’t ask again on this browser’ permission. It cannot be undone except by ticking that box again on each device.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/profile.forget_trusted_browsers \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool profile_forget_trusted_browsers at https://app.chirply.io/api/mcp, same bearer token, same input.

View profile

profile.getread

Read the acting person's profile. For an account API key, reads the account owner's profile. Founder-only fields are included when that person is a founder.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/profile.get \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool profile_get at https://app.chirply.io/api/mcp, same bearer token, same input.

Sign-in & security

profile.security_statusread

Read how the acting person's sign-in is protected: whether they use an authenticator app, how many passkeys they have registered, how many single-use recovery codes are left in case they lose the authenticator, and how many browsers are set to skip the second step. For an account API key, reads the account owner's status. Read-only, and it never returns a passkey or a recovery code — only whether they exist. Enrolling an authenticator, adding a passkey, generating recovery codes and spending one to get back in can only be done by the person themselves, because each needs a live code, a live browser ceremony, or a sign-in session; see the note at the foot of this module.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/profile.security_status \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool profile_security_status at https://app.chirply.io/api/mcp, same bearer token, same input.

Save profile

profile.updatewrite

Update the acting person's real name, chat handle, and photo across the app. If the person is a founder, also updates their founder-wall biography, links, and public-or-anonymous visibility. For an account API key, updates the account owner's profile. This sends no messages and costs nothing.

Parameters

FieldTypeRequiredDescription
github_usernamestringoptionalOptional self-reported GitHub username, without a URL, used to look up this person's work in the account's tracked repositories. This does not verify GitHub ownership or grant repository access. Empty clears it; omission preserves it.
full_namestringrequiredThe person's real name, kept visible beside their chat handle so coworkers can identify them.
handlestringoptionalThe person's optional, globally unique chat handle without a leading @. When present, chat shows it first while keeping the real name visible; either value can be used in an @mention. Omit this field to preserve the current handle.
phonestringoptionalThe person's own mobile number, stored in E.164. This is what lets a workflow's "Alert my team" step text or call them about a new lead instead of only emailing them; it is never used to market to them and is never shown to a contact. Anything unreachable is rejected rather than saved. Empty clears it; omission preserves it.
avatar_urlstringrequiredPublic HTTPS URL for the person's profile photo; use an empty string to remove it.
is_publicbooleanoptionalFor founders, whether their details appear publicly on the founders wall instead of anonymously. Default: false
headlinestringoptionalFor founders, the role or short headline shown on the founders wall. Default: ""
biostringoptionalFor founders, a short public biography. Default: ""
companystringoptionalFor founders, the company shown on the founders wall. Default: ""
locationstringoptionalFor founders, the location shown on the founders wall. Default: ""
website_urlstringoptionalFor founders, their public website URL. Default: ""
x_urlstringoptionalFor founders, their public X profile URL. Default: ""
linkedin_urlstringoptionalFor founders, their public LinkedIn profile URL. Default: ""

Example

curl -X POST https://app.chirply.io/api/v1/actions/profile.update \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "full_name": "Example",
    "avatar_url": "https://example.com"
  }'
Test with your API key

Over MCP the same operation is the tool profile_update at https://app.chirply.io/api/mcp, same bearer token, same input.

The machine-readable version of this page is GET https://app.chirply.io/api/v1/actions?domain=profile — same operations, with full JSON Schemas. Authentication, errors and rate limits are covered in the API documentation home.