risk_level and flags mark sign-ins that may need a second look, such as a new IP, a new device or a new country.
- Add
?flagged=trueto return only suspicious sign-ins. - Add
?status=failedto see failed attempts. Requests with a wrong API secret or a revoked API key appear here withauth_methodset toapi_key. If you see these unexpectedly, revoke the key in Developers → API Keys and create a new one. - Called with an API key, this returns the business account owner’s history. Team members see their own history in the dashboard.

