Get current user capabilities
Scope-aware permissions and roles for the authenticated user. Requires a bearer session and nothing else — this is the endpoint a client should use to decide what to show. The answer always includes the caller's global roles; with an organization or fundraiser scope it adds the roles held in that scope. A bare object, not wrapped in data.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Query Parameters
Defaults to global. scopeId is required for the other two.
"global""organization""fundraiser""global"The organization or fundraiser id. Required unless scopeType is global.
"uuid"Responses
User capabilities