Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Inspect the current credential

Returns only the caller’s own credential: its type, API key id (API keys only), workspace and environment, effective scopes and expiry. Needs no scope beyond being authenticated. Use it at startup to check the application holds the scopes it needs and none it should not. Holding a scope is not proof a call will run: policies, budgets, environment halt and quotas still apply at request time. Never cached.

GET/api/v2/auth/identity
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Responses
200

The credential making this request, returned. Not cacheable.

successbooleanrequired
Allowed:true
dataCredentialIdentityrequired

The caller's own credential. Never contains a secret, a hash, another key or an account detail.

Show properties
credentialTypestringrequired
Allowed:api_keyoauthsession
apiKeyIdstring | nullrequired

Only an API key has one. Null for OAuth and sessions; none is invented.

workspaceIdstring<uuid>required
environmentIdstring<uuid>required
scopesstring[] | nullrequired

Effective granted scopes, sorted. Null for a session, whose authority comes from the user's workspace role. Holding a scope does not prove a call will succeed; policies, budgets, environment state and quotas still apply.

expiresAtstring<date-time> | nullrequired
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Request
curl -X GET 'https://api.anlyon.com/api/v2/auth/identity' \
  -H 'Authorization: Bearer YOUR_TOKEN'
Response
{
  "success": true,
  "data": {
    "credentialType": "api_key",
    "apiKeyId": "string",
    "workspaceId": "ef0efa32-d1c1-43d4-a5e2-fe7b4f00403c",
    "environmentId": "19f5cc2e-7657-437a-9268-83cd3d563563",
    "scopes": [
      "string"
    ],
    "expiresAt": "2019-08-24T14:15:22Z"
  }
}