Get user profile
Public profile by UUID or profile_slug. Authentication is optional: the caller's own profile may include their email, and a profile marked private is redacted for every other viewer.
WHAT SURVIVES THE REDACTION (#1696): id, name, avatar, profile_slug, created_at and the four counters — campaign_count, total_funds_raised, follower_count and following_count — with their REAL values. The leaderboard has always published a private person's rank and impact, so a profile reporting zeroes beside a board reporting real figures would be two surfaces disagreeing about one person rather than privacy.
Dropped: bio, location, website, social_links, email, phone, private_contact_email, display_name, account_status, kyc_verified_at and account_kind. The last three are more than a name — a Team chip and a verification tick say something about the person, which is exactly what a private profile withholds.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Path Parameters
User UUID or profile_slug.
Responses
User profile — a bare object, not wrapped in data. The fields marked own profile only are present only when the caller is the profile's owner.