Skip to content

Self — the caller's user + tenant + session context

GET
/v1/identity/whoami
curl --request GET \
--url https://example.com/v1/identity/whoami \
--header 'Authorization: Bearer <token>'

Reflects the auth middleware’s attached context: tenantId + scopes always; userId / sessionId / providerId / expiresAt when the caller is on a session token; the fuller UserRecord under user when a userId is present and the IdentityDirectoryBinding resolves it. Always mounted — the /users/* routes only mount when the directory binding is wired.

Auth + user context.

Media typeapplication/json

Introspection of the caller’s current authentication context. Always carries tenantId and scopes (empty for static bearer tokens), plus userId when the token carries one; session-token callers additionally see sessionId, providerId, and expiresAt. user is the caller’s directory record, present when the deployment wires an identity directory and it knows the userId. reviewerRole is set when the token carries a reviewer role — clients can use it to gate reviewer-only UI (the approvals surface) without a second round trip.

object
tenantId
required
string format: uuid
userId
string
sessionId
string
providerId
string
scopes
required
Array<string>
expiresAt
string format: date-time
reviewerRole

Reviewer role class. Hierarchy: standard < senior < admin.

string
Allowed values: standard senior admin
user

Tenant-scoped user record (admin plane). primaryEmail may be redacted on the wire based on tenant policy (the routes treat it as opaque). metadata is free-form JSON — deployments carry IdP claims / provisioning source / roles here.

object
userId
required
string
tenantId
required
string format: uuid
primaryEmail
string
displayName
string
createdAt
required
string format: date-time
lastActiveAt
string format: date-time
metadata
object
key
additional properties
any
Example
{
"reviewerRole": "standard"
}

Missing / malformed / expired / revoked bearer token.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}