Describe the authenticated caller

Returns the identity behind the token and every tenant/role assigned to it. Useful to confirm which client_id, scopes and X-Tenant-Id values a credential is allowed to use.

For an M2M (client-credentials) token, sub and clientId hold the same value.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
X-Request-TimestampstringRequired

Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).

X-Content-SHA256stringRequired

Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.

X-Request-SignaturestringRequired

Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.

Response

Caller described.
substring

Token sub claim. Equals clientId for M2M credentials.

tenantRoleslist of objects
emailstringOptional
clientIdstringOptional
scopeslist of stringsOptional

Errors

401
Unauthorized Error
500
Internal Server Error