Skip to content
Helicarrier Developers

Identify the current key

Identify the authenticated caller and discover the resources and permissions available to a scoped key.

GET /api/auth/me HTTPS
Request & response examples
Request example Server-side
curl --fail-with-body --request GET \
'https://app.helicarrier.xyz/api/auth/me' \
-H "Authorization: Bearer $HELI_API_KEY"
Response example 200
{
"id": "usr_example",
"name": "Alex",
"email": "[email protected]",
"keyScope": {
"kind": "service",
"serviceId": "svc_example",
"serviceName": "my-app",
"permissions": {
"deployments": "write",
"logs": "read"
}
}
}

Illustrative values · selected fields

Authorization

Any valid API key. Catalog and identity reads do not require a capability category.

Authorization: Bearer <key> Key setup ↗

Parameters

This request does not require path, query, or body parameters.

Response 200

The identity response describes the authenticated user and, when present, the service or project key scope, permissions, and environment restrictions. Start here when using a scoped key.

Examples show selected response fields with illustrative values. Your response can contain additional fields.

id string

Unique identifier of this resource.

name string

Human-readable resource name.

email string
keyScope object

Present for a service or project key; describes its resource and capability restrictions.

Child fields
  • kind string
  • serviceId string
  • serviceName string
  • permissions object

    Capability categories granted to the key, at read or write level.

Errors

401

The API key is missing, invalid, or revoked.

403

The caller or key scope does not permit this operation.

Error handling and safe retries
ALSO AVAILABLE VIA MCP

whoami

Required MCP arguments: none. Send path, query, and body fields together as tool arguments.

Connect your agent ↗