> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Refresh user profile data

> Retrieves the current user's full profile including populated institution, account, and Google OAuth status. Proactively refreshes expired Google tokens when a refresh_token is available. Returns a fresh JWT token (sliding session) — store this token to extend the session without re-authentication.



## OpenAPI

````yaml /mdx/api-reference/runtime/runtime-api.json post /api/user/refresh/profile
openapi: 3.0.0
info:
  title: Pria Runtime API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Audio Notes
    description: Capture and ingest spoken notes into the personal vault
  - name: Memory
    description: User-facing memory parameters (personal + shared instance memory).
  - name: My Data
    description: >-
      GDPR controls — personal-scope counts, async ZIP-by-email export, and
      scoped soft-delete. Every endpoint pins `user = req.user._id` AND
      `institution: null`; institution-scoped data is governed by the
      institution's own retention policy and never reached from here.
  - name: Questions
    description: >-
      User-facing read of the onboarding question bank used by the "create a
      digital twin" wizard.
  - name: Transcription
    description: >-
      One-shot speech-to-text for in-place dictation. Audio blob in, transcript
      out — no Upload / History / RAG embeddings are persisted. Use
      `/audio-notes` for anything durable.
paths:
  /api/user/refresh/profile:
    post:
      tags:
        - User
      summary: Refresh user profile data
      description: >-
        Retrieves the current user's full profile including populated
        institution, account, and Google OAuth status. Proactively refreshes
        expired Google tokens when a refresh_token is available. Returns a fresh
        JWT token (sliding session) — store this token to extend the session
        without re-authentication.
      responses:
        '200':
          description: Profile refreshed successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RefreshProfileResponse'
        '400':
          description: General error during profile retrieval
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
        '401':
          description: 'User not found or deleted: authentication required'
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Authentication required
      security:
        - apiKeyAuth: []
components:
  schemas:
    RefreshProfileResponse:
      type: object
      properties:
        success:
          type: boolean
          description: Whether the operation was successful
        token:
          type: string
          description: >-
            Fresh JWT token (sliding session). Each profile refresh extends the
            session by the configured expiration period (default 6 hours). Store
            this token and use it for subsequent API requests.
        profile:
          type: object
          description: >-
            Full user profile object (User model fields merged with populated
            institution, plus Google OAuth flags). Sensitive fields (password,
            permissions, __v, created) are stripped.
          properties:
            _id:
              type: string
              description: User unique identifier
            email:
              type: string
              description: User email address
            fname:
              type: string
              description: First name
            lname:
              type: string
              description: Last name
            picture:
              type: string
              description: URL to user profile picture
            accountType:
              type: string
              enum:
                - user
                - admin
                - super
              description: 'Account type: user, admin, or super'
            credits:
              type: integer
              description: User credit balance
            creditsUsed:
              type: integer
              description: Total credits consumed
            plan:
              type: string
              description: Subscription plan (e.g. free, sdk, entry, premium, pro, monthly)
            status:
              type: string
              description: User account status (e.g. active, inactive, trialing, deleted)
            customerId:
              type: string
              description: Stripe customer ID
            institution:
              type: object
              description: >-
                Populated institution object with nested account. Contains
                public fields (name, ainame, status, credits, poolCredits,
                rtEnabled, rtVoice, picture, css, about, etc.) returned by
                instancePublicFields(). The nested `account` object includes:
                name, managerEmail, domainUrls, status, credits,
                kagFusionEnabledAllInstances, kagFusionAllowInstanceOverride,
                and **privacyPolicyHTML** (consent gate for the active session —
                kept here rather than in /api/user/refresh/entitlements
                account_data to avoid duplicating multi-KB HTML across rows that
                share the same account).
            remember_history_count:
              type: integer
              description: Number of history entries to remember
            browser_voice:
              type: string
              description: Selected browser TTS voice
            browser_voices:
              type: object
              description: Browser voice configuration per language
            rt_voice:
              type: string
              description: Selected real-time voice
            use_location:
              type: boolean
              description: Whether location services are enabled
            use_stt:
              type: boolean
              description: Whether speech-to-text is enabled
            pin_ui:
              type: boolean
              description: Whether UI sidebar is pinned
            showSideBar:
              type: boolean
              description: Whether sidebar is visible
            galleryAsGrid:
              type: boolean
              description: Whether gallery displays as grid
            ragOnlySearch:
              type: boolean
              description: >
                Knowledge — "Search Only" output toggle (axis 2 of 2). When
                `true`

                with retrieval on, Pria returns the raw vault chunks instead of
                an

                LLM-rewritten answer. Orthogonal to `ragIgnore` / `ragKagMode`.

                See PUT /user/me for the full combination matrix.
            ragIgnore:
              type: boolean
              description: >
                Knowledge — "Disabled" retrieval toggle (axis 1 of 2). When
                `true`,

                retrieval is skipped entirely and the LLM answers from its
                training

                only. Takes precedence over `ragKagMode` and `ragOnlySearch`.
            ragKagMode:
              type: boolean
              description: >
                Knowledge — "RAG + KAG Fusion" retrieval toggle (axis 1 of 2).
                When

                `true` with `ragIgnore=false` AND the user/institution is
                KAG-eligible,

                the knowledge-graph leg runs alongside the dense vector leg and
                the

                two are merged via Reciprocal Rank Fusion. KAG is always an

                augmentation on top of RAG — there is no "KAG without RAG" mode.
            dark_mode:
              type: boolean
              description: Whether dark mode is enabled
            mustChangePassword:
              type: boolean
              description: Whether user must change password on next login
            updatePasswordOnSSO:
              type: boolean
              description: Whether to update password on SSO login
            resetCodeId:
              type: string
              description: Password reset code identifier
            referralId:
              type: string
              description: User referral ID
            trial_end:
              type: string
              format: date-time
              description: Trial period end date
            trial_used:
              type: boolean
              description: Whether trial has been used
            current_period_end:
              type: string
              format: date-time
              description: Current billing period end date
            cancel_at_period_end:
              type: boolean
              description: Whether subscription cancels at period end
            lxp_user_id:
              type: string
              description: LXP platform user ID
            lxp_partner_name:
              type: string
              description: LXP partner name
            lxp_role_name:
              type: string
              description: LXP role name
            googleLoginToken:
              type: object
              description: >-
                Google OAuth token object (conditionally included). Omitted when
                institution uses institution-level Google account.
            googleOAuthScopes:
              type: array
              items:
                type: string
              description: >-
                Google OAuth scopes the user has authorized. Omitted when
                institution uses institution-level Google account.
            institutionGoogleOAuthEnabled:
              type: boolean
              description: Whether the current institution has Google OAuth enabled
            institutionGoogleOAuthScopes:
              type: array
              items:
                type: string
              description: Google OAuth scopes configured at institution level
            institutionGoogleWorkspaceEnabled:
              type: boolean
              description: Whether Google Workspace is enabled for users at the institution
            institutionGoogleUseInstitutionAccount:
              type: boolean
              description: >-
                Whether the institution uses a shared Google account (hides
                user-level tokens when true)
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-access-token
      description: JWT token passed in x-access-token header

````