Get the authenticated user
Serves your own row joined to your organisation: identity, kind, status, capabilities as scope strings, and the organisation’s name, requiredApprovals and isInternalPlatform. It is the one read a discovered member may make, so a client can say “awaiting admission”; configure a client from it, and from nothing in the token.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Response
The caller's row; the projection position rides the body and the header.
Membership — stamped by the owner from the actor's org, or from the discovery's parent ref.
Natural key — unique among live orgs.
Platform name — per-org unique among live users with a non-empty name; empty until admission.
What the IdP stated at discovery (the name, else email, else nickname claim); informational, never a key.
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
The user's capabilities — what they may do; empty on a discovered row. a set (SBE bit-set) served as the array of its scope strings — each choice spelled <route family>:<verb> (the schema's camel-cased choice name de-camelled: accountAddressesApprove is account-addresses:approve) — in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict
Approvals a maker-checker mutation in this organisation needs: 1 = a second user's approval (dual control); 0 = the maker's own write is the concluded record; 2+ reserved (refused INVALID_FIELD). Set at bootstrap or activation; no command changes it on a live organisation. uint8: an integer 0..255
TRUE on exactly one org — the org that runs the platform. Set by BootstrapInternalPlatformOrg, never client-supplied. a boolean; absent reads false
The position as a decimal string — the last change this member had applied, orders and balance readings included.