# Client — Profile

<a id="get-api-v1-client-profile"></a>
#### `GET /api/v1/client/profile`

*Get client profile*

Return the authenticated client account profile (username, domain, email, status, 2FA, reseller info).

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/profile
```

---

<a id="put-api-v1-client-profile"></a>
#### `PUT /api/v1/client/profile`

*Update client profile*

Update profile fields (email, sidebar choice) for the authenticated client account. A session opened by impersonation does not change the sidebar choice.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `email` | string | no | — |
| `sidebar_collapsed` | boolean | no | The sidebar choice to keep: true collapsed, false expanded. A session opened by impersonation leaves the account's choice as it is. |

**Request body example:**

```json
{
  "email": "string",
  "sidebar_collapsed": false
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/profile
```

---

<a id="post-api-v1-client-profile-2fa-backup-codes-regenerate"></a>
#### `POST /api/v1/client/profile/2fa/backup-codes/regenerate`

*Regenerate backup codes (client)*

Generate a fresh set of one-time backup codes for the authenticated client; old codes are invalidated.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/profile/2fa/backup-codes/regenerate
```

---

<a id="post-api-v1-client-profile-2fa-disable"></a>
#### `POST /api/v1/client/profile/2fa/disable`

*Disable 2FA (client)*

Disable 2FA for the authenticated client after verifying the account password.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `password` | string | yes | minLength=1 |

**Request body example:**

```json
{
  "password": "REPLACE_ME"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/profile/2fa/disable
```

---

<a id="post-api-v1-client-profile-2fa-enable"></a>
#### `POST /api/v1/client/profile/2fa/enable`

*Enable 2FA (client)*

Verify the OTP code and activate 2FA for the authenticated client; returns one-time backup codes.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `code` | string | yes | minLength=6; maxLength=6; pattern=`^\d{6}$` |

**Request body example:**

```json
{
  "code": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/profile/2fa/enable
```

---

<a id="post-api-v1-client-profile-2fa-resend-code"></a>
#### `POST /api/v1/client/profile/2fa/resend-code`

*Resend email 2FA code (client)*

Resend the email OTP code during client 2FA email setup.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/profile/2fa/resend-code
```

---

<a id="post-api-v1-client-profile-2fa-setup"></a>
#### `POST /api/v1/client/profile/2fa/setup`

*Initiate 2FA setup (client)*

Initiate two-factor authentication setup for the authenticated client (totp or email method).

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `method` | string | no | default `totp`; pattern=`^(totp\|email)$` |

**Request body example:**

```json
{
  "method": "totp"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/profile/2fa/setup
```

---

<a id="patch-api-v1-client-profile-password"></a>
#### `PATCH /api/v1/client/profile/password`

*Change client password*

Change the authenticated client's password (requires current password). Invalidates all existing sessions.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `current_password` | string | yes | minLength=1 |
| `new_password` | string | yes | At least 8 characters and at most 72 bytes when UTF-8 encoded.; minLength=8; maxLength=128 |

**Request body example:**

```json
{
  "current_password": "REPLACE_ME",
  "new_password": "REPLACE_ME"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_dict_str__Any__` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {},
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PATCH \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/profile/password
```

---
