Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Headers

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Response

The session.

user
object
active_organization_id
string<uuid> | null

Null when the session is in no organization — an account removed from its last one. The four fields below and role are null with it, and permissions is empty. Only GET /v1/organizations, POST /v1/organizations, this endpoint and POST /v1/session/logout answer in that state; everything else is not_a_member (403).

active_organization_code
string | null
active_organization_name
string | null
active_organization_logo
string | null
onboarded
boolean
role
string | null
permissions
enum<string>[]

A fine-grained capability. The catalogue lives in Go; which role holds which lives in the database.

Available options:
organization:update,
organization:delete,
members:read,
members:write,
roles:read,
roles:manage,
api_keys:read,
api_keys:write,
customers:read,
customers:write
two_factor_available
boolean

A platform capability, not the organization's.

uploads_available
boolean

A platform capability, not the organization's.

expires_at
string<date-time>