/v1/meCheck a credential, and see everything it reaches.
The first call to make with a new credential, and the one that answers both questions its holder has: does this work, and what does it unlock. It answers for either kind — an API key or an OAuth access token — and `kind` says which one you are holding. It needs no scope, which is the point: a credential that has run out of permission still has to be able to find out what it is.
Try it
Needs a key — add one aboveGET https://3fi4pdbpzj.execute-api.us-east-1.amazonaws.com/test/v1/me
Request body
None. The endpoint is addressed entirely by its path.
Request
curl "https://3fi4pdbpzj.execute-api.us-east-1.amazonaws.com/test/v1/me" \
-H "x-api-key: $PLAY_API_KEY"Response
{
"kind": "oauth",
"oauth": {
"app": {
"appId": "01JQ9B7M5N8P1Q4R7T0V3W6X9Y",
"clientId": "play_app_7c1d9e2f4a6b8c0d",
"name": "Team dashboard",
"description": "Shows your team's courses and progress in one place."
},
"scopes": ["profile:read", "courses:read", "lessons:read"],
"scope": "profile:read courses:read lessons:read"
},
"owner": {
"userId": "8f14e45f-ea6c-4f2b-9d3a-1c2b3a4d5e6f"
},
"scopes": ["profile:read", "courses:read", "lessons:read"]
}kind"key" | "oauth"- Which credential authenticated the call.
keyobject?- The key, when `kind` is `key`. Absent otherwise. It has the fields of any other key: `keyId`, `name`, `prefix`, `createdAt`, `lastUsedAt`, and the organization it was made for.
oauth.appobject?- The app the token was issued to, when `kind` is `oauth`: its `appId`, `clientId`, `name` and `description`.
oauth.scopesarray?- What the token was issued with — the permissions a person agreed to on a consent screen.
oauth.scopestring?- The same list, space-delimited, spelled the way OAuth spells it.
owner.userIdstring- Cognito `sub` of the person the credential acts as. Every read is attributed to them.
scopesarray- Every scope the credential holds. Empty for an API key unless its owner named an organization.