Account: the /me Endpoints
Everything that reads or changes the signed-in account — its profile, roles and permissions, preferences, API keys, and the lists that belong to it. These endpoints all take authenticateToken and act on the caller; most take no id at all, so there is nothing to point at somebody else.
Two spellings of "me"
The newer endpoints live under /me/* and never take an id. Some older account endpoints live under /users/:id/* and compare :id with the session's own profile id — pass your profile UUID there, not your slug (a slug fails the ownership check with 403). A few live under /users/me/*. All three are listed below.
| Reference section | Operations | About |
|---|---|---|
| Users | 24 | User profiles and preferences |
| RBAC | 1 | The signed-in caller's own roles and permissions |
| Achievements | 17 | The public badge catalogue, single badges, the "just earned" feed, and individual earned cards with their share pictures and verify QR codes. |
| API Keys | 3 | Long-lived `fh_live_…` keys for CLI and agent access. A key is sent as `Authorization: Bearer fh_live_…` and authenticates as the user who created it, on every endpoint that accepts a bearer session. |
| Creator Subscriptions | 10 | Creator monetisation tiers (each mirrored to a Stripe Product and Prices) and the fan-side recurring subscriptions to them. |
| Email Preferences | 4 | Public, token-authorised unsubscribe and resubscribe for any address FundlyHub mails, including guest donors with no account. |
Who am I
| Endpoint | Returns |
|---|---|
GET /me/capabilities | Your effective permissions and roles for a scope (?scopeType=global|organization|fundraiser&scopeId=…), with fetchedAt / expiresAt cache hints. Needs no permission. The bearer-friendly identity probe. |
GET /cognito/me | The session's profile, wrapped in user. Cookie sessions only — it ignores the Authorization header. |
GET /users/:id | Your public profile; when :id is you, it also carries email, phone and private_contact_email. |
GET /me/capabilities is what clients should use to decide what to show.
curl -H "Authorization: Bearer $FUNDLYHUB_API_KEY" \
"https://api.fundlyhub.org/api/v1/me/capabilities?scopeType=global"{
"permissions": ["view_own_referral_portal", "endorse_campaigns"],
"roles": ["ambassador"],
"scope": { "type": "global", "id": null },
"fetchedAt": "2026-10-02T12:00:00.000Z",
"expiresAt": "2026-10-02T12:05:00.000Z"
}A role granted or revoked takes effect on the next request: the RBAC cache is invalidated when an assignment changes, and expiresAt is only an upper bound on how stale a client's own copy can be.
Profile and settings
| Endpoint | Purpose |
|---|---|
PATCH /users/:id | Name, profile_slug, social_links, location. |
POST /users/:id/avatar · DELETE | Avatar as base64 JSON; stored as a 256×256 WebP. |
PUT /users/me/private-contact | The contact address only FundlyHub staff see; sends a verification email. |
POST /users/me/private-contact/resend | Re-send that verification (5 a minute, per user). |
PUT /users/me/phone | Stored, not SMS-verified. |
GET /users/me/publish-readiness | The checklist behind the campaign publish gate. |
POST /users/:id/deactivate | Self-service deactivation; clears the session cookies. |
Field rules and response shapes are on User Profiles.
Preferences
GET /users/:id/preferences · PUT /users/:id/preferences
Own account only. PUT is a partial write — send the keys you want to change. The notification switches are notify_donations, notify_comments, notify_updates, notify_milestones, notify_campaign_status, notify_followers, notify_org_status, notify_payouts, notify_digest, notify_donation_reminders and notify_endorsement_requests.
The response also carries suppressed_scopes: the notification scopes blocked for the account's email address by unsubscribe links. Those are address-keyed and cannot write the preferences row, so a switch can read "on" while mail is suppressed. Check it before telling a user their mail is on. Writing a switch back to true with PUT clears the matching suppression, which is how a user resubscribes.
API keys
| Endpoint | Purpose |
|---|---|
POST /api-keys | Create a key: { "name": "…", "expires_at": "…" }. The full fh_live_… value is in the 201 body once. |
GET /api-keys | Your keys (?include_revoked=true for revoked ones too), with prefix, last_used_at, expires_at. |
DELETE /api-keys/:id | Revoke immediately. |
An API key acts as its owner with the owner's full permissions; key scopes are reserved for future use. Details and the security guidance are on Authentication.
Lists that belong to you
| Endpoint | What it lists | Page |
|---|---|---|
GET /notifications | Your notifications, plus unreadCount and updatesUnreadCount | Notifications & Campaign Updates |
GET /me/campaign-updates | Updates on campaigns you follow or gave to, with read state | Notifications & Campaign Updates |
GET /donor/me/summary, /donations, /annual-statement | Your giving | Donations |
GET /organizations/me | Organizations you hold an active role on | Organizations |
GET /payouts/earnings | What your campaigns have raised and where it is | Payouts |
GET /me/tiers · POST · PATCH /me/tiers/:tier_id · DELETE | Your creator support tiers (DELETE archives; DELETE …/permanent deletes) | — |
GET /me/subscriptions · POST · POST /me/subscriptions/:id/cancel · /resume | Creator subscriptions you pay for | — |
GET /me/achievements · PATCH /me/achievements/:slug · PUT/DELETE /me/achievements/pin | Your achievements, their visibility, and the one pinned to your profile | — |
GET /me/achievements/reveals · POST /me/achievements/reveals/ack | Cards earned but not yet opened, and marking them opened | — |
GET /me/referrals/* · GET /me/campaigns | The ambassador portal (needs view_own_referral_portal) | Ambassador Program |
Related
- Authentication — sessions, API keys, sign-out
- Roles & Permissions — what
/me/capabilitiesreports - User Profiles — the full profile contract