Skip to navigation

Get the authenticated user

Serves your own row joined to your organisation: identity, kind, status, capabilities as scope strings, and the organisation’s name, requiredApprovals and isInternalPlatform. It is the one read a discovered member may make, so a client can say “awaiting admission”; configure a client from it, and from nothing in the token.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Response

The caller's row; the projection position rides the body and the header.

userIdinteger
Sticky entity key.
orgIdinteger

Membership — stamped by the owner from the actor's org, or from the discovery's parent ref.

orgNamestring

Natural key — unique among live orgs.

namestring

Platform name — per-org unique among live users with a non-empty name; empty until admission.

displayNamestring

What the IdP stated at discovery (the name, else email, else nickname claim); informational, never a key.

kindenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
statusenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
capabilitieslist of enums

The user's capabilities — what they may do; empty on a discovered row. a set (SBE bit-set) served as the array of its scope strings — each choice spelled <route family>:<verb> (the schema's camel-cased choice name de-camelled: accountAddressesApprove is account-addresses:approve) — in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict

requiredApprovalsinteger0-255

Approvals a maker-checker mutation in this organisation needs: 1 = a second user's approval (dual control); 0 = the maker's own write is the concluded record; 2+ reserved (refused INVALID_FIELD). Set at bootstrap or activation; no command changes it on a live organisation. uint8: an integer 0..255

isInternalPlatformboolean

TRUE on exactly one org — the org that runs the platform. Set by BootstrapInternalPlatformOrg, never client-supplied. a boolean; absent reads false

globalSequencestringformat: "^[0-9]+$"

The position as a decimal string — the last change this member had applied, orders and balance readings included.

Errors

401
Get Me Users Request Unauthorized Error
403
Get Me Users Request Forbidden Error
503
Get Me Users Request Service Unavailable Error