Read account emails from a website backend

The verified Token/PHP 0.1.4 ZIP provides accountEmails(bundle, options). Follow the package installation.

Use a consumer API User access bundle with the accepted audience and account.me.email.list, expected subject from validated identity, and required proof/fingerprint/certificate state. This calls the existing /api/v2/account/me/email/list; it is not authorized by the SSO email scope.

use M7\Identity\M7IdentitySDK;

$emails = (new M7IdentitySDK())->accountEmails($apiUserBundle, [
    'expected_sub' => $verifiedSubject,
]);
if (!$emails->ok()) {
    throw new RuntimeException($emails->reason() ?? 'Email lookup failed');
}

The report exposes only safe id, email, verified, primary rows after exact owner binding and malformed/duplicate/multiple-primary checks. Empty results are valid and do not invent sub; failures expose no partial emails. Token acquisition, session ownership, refresh, proof creation, explicit nonce recovery and persistence remain the host's responsibility. See the complete PHP operation contract.

For login/profile display, ordinary SSO UserInfo with openid email supplies the primary email/email_verified when one exists. SSO has no advertised email-list endpoint or /userinfo/emails. This account operation is separate from consumer organization acquisition.