Self — the caller's user + tenant + session context
const url = 'https://example.com/v1/identity/whoami';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/v1/identity/whoami \ --header 'Authorization: Bearer <token>'Reflects the auth middleware’s attached context: tenantId + scopes always; userId / sessionId / providerId / expiresAt when the caller is on a session token; the fuller UserRecord under user when a userId is present and the IdentityDirectoryBinding resolves it. Always mounted — the /users/* routes only mount when the directory binding is wired.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”Auth + user context.
Introspection of the caller’s current authentication context. Always carries tenantId and scopes (empty for static bearer tokens), plus userId when the token carries one; session-token callers additionally see sessionId, providerId, and expiresAt. user is the caller’s directory record, present when the deployment wires an identity directory and it knows the userId. reviewerRole is set when the token carries a reviewer role — clients can use it to gate reviewer-only UI (the approvals surface) without a second round trip.
object
Reviewer role class. Hierarchy: standard < senior < admin.
Tenant-scoped user record (admin plane). primaryEmail may be redacted on the wire based on tenant policy (the routes treat it as opaque). metadata is free-form JSON — deployments carry IdP claims / provisioning source / roles here.
object
object
Example
{ "reviewerRole": "standard"}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}