Inspect the current credential
Returns only the caller’s own credential: its type, API key id (API keys only), workspace and environment, effective scopes and expiry. Needs no scope beyond being authenticated. Use it at startup to check the application holds the scopes it needs and none it should not. Holding a scope is not proof a call will run: policies, budgets, environment halt and quotas still apply at request time. Never cached.
/api/v2/auth/identityAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
The credential making this request, returned. Not cacheable.
successbooleanrequiredtruedataCredentialIdentityrequiredThe caller's own credential. Never contains a secret, a hash, another key or an account detail.
Show propertiesHide properties
credentialTypestringrequiredapi_keyoauthsessionapiKeyIdstring | nullrequiredOnly an API key has one. Null for OAuth and sessions; none is invented.
workspaceIdstring<uuid>requiredenvironmentIdstring<uuid>requiredscopesstring[] | nullrequiredEffective granted scopes, sorted. Null for a session, whose authority comes from the user's workspace role. Holding a scope does not prove a call will succeed; policies, budgets, environment state and quotas still apply.
expiresAtstring<date-time> | nullrequiredUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
