Get user preferences
Returns the caller's own preferences. Callers may only access their own — any other path id answers 403.
Accounts with no stored row get a default object rather than a 404, so the returned key set differs slightly between the two cases. suppressed_scopes is always present: it lists the notification scopes this account's email address has been unsubscribed from via an emailed link. Those suppressions are keyed by address, not by account, so they stop mail even while the matching toggle reads true — which is exactly why they are reported separately rather than folded into the toggles.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Path Parameters
Responses
User preferences