Read account emails from a website backend
The verified Token/PHP 0.1.4 ZIP provides accountEmails(bundle, options).
Follow the package installation.
Use a consumer API User access bundle with the accepted audience and
account.me.email.list, expected subject from validated identity, and required
proof/fingerprint/certificate state. This calls the existing
/api/v2/account/me/email/list; it is not authorized by the SSO email scope.
use M7\Identity\M7IdentitySDK;
$emails = (new M7IdentitySDK())->accountEmails($apiUserBundle, [
'expected_sub' => $verifiedSubject,
]);
if (!$emails->ok()) {
throw new RuntimeException($emails->reason() ?? 'Email lookup failed');
}
The report exposes only safe id, email, verified, primary rows after
exact owner binding and malformed/duplicate/multiple-primary checks. Empty
results are valid and do not invent sub; failures expose no partial emails.
Token acquisition, session ownership, refresh, proof creation, explicit nonce
recovery and persistence remain the host's responsibility. See the
complete PHP operation contract.
For login/profile display, ordinary SSO UserInfo with openid email supplies
the primary email/email_verified when one exists. SSO has no advertised
email-list endpoint or /userinfo/emails. This account operation is separate
from consumer organization acquisition.