# Principal

object type

A resolved session principal — what an authenticated call acts as.

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `sessionId` | [ID](/types/#scalars) `ID!` | No further notes. |
| `kind` | [String](/types/#scalars) `String!` | The principal class — user \| api \| device. |
| `userId` | [ID](/types/#scalars) | The User construct the session is a principal of — user kind only (null on api/device). |
| `accountId` | [ID](/types/#scalars) | The acting Account — user + api kinds (the api kind's = the MINTER's Account); null on device. |
| `apiKeyId` | [ID](/types/#scalars) | The ApiKey the session was exchanged from — api kind only. |
| `deviceId` | [ID](/types/#scalars) | The Device the session belongs to — the device kind, AND the user kind on a COMPOSITE POS session (the x-at-device-session facet); null otherwise. |
| `deviceType` | [String](/types/#scalars) | The device's canned hardware class — the device kind + the composite POS session's user kind; null otherwise. |
| `registerId` | [ID](/types/#scalars) | The device's LIVE 0..1 Register binding — the device kind + the composite POS session's user kind (null while unpaired / on pi_bridge / without a device facet). The register derives its till + selling location from THIS, never from a device(id) read (a cashier tier cannot make one). |
| `logicalFacilityId` | [ID](/types/#scalars) | The device's parent LogicalFacility (the selling location) — the device kind + the composite POS session's user kind; null otherwise. |
| `orgId` | [ID](/types/#scalars) `ID!` | The organization the session acts in (the attribution org). |
| `rootId` | [ID](/types/#scalars) `ID!` | The org-group family root. |
| `capability` | [String](/types/#scalars) | The LIVE effective capability, re-derived from the account status every call — user/api kinds; null on device (a device carries trust, never authority — E). |
| `groupCaption` | [String](/types/#scalars) | The session’s organization GROUP caption; read from the group record on every me — null only when the session names no group (never for a live session). |
| `roleCaptions` | [String](/types/#scalars) `[String!]` | The captions of the roles the session ACTS with in its organization — user kind only; null on the api/device kinds (their authority is the key’s / the device’s, not a role’s). |

## Used by

- [me](/reference/your-own-session/me/)
