Skip to content

RBAC​

The signed-in caller's own roles and permissions


Get current user capabilities​

GET
/me/capabilities

Scope-aware permissions and roles for the authenticated user. Requires a bearer session and nothing else — this is the endpoint a client should use to decide what to show. The answer always includes the caller's global roles; with an organization or fundraiser scope it adds the roles held in that scope. A bare object, not wrapped in data.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Query Parameters

scopeType

Defaults to global. scopeId is required for the other two.

Type
string
Valid values
"global""organization""fundraiser"
Default
"global"
scopeId

The organization or fundraiser id. Required unless scopeType is global.

Type
string
Format
"uuid"

Responses​

User capabilities

application/json
JSON
{
"permissions": [
"string"
],
"roles": [
"string"
],
"scope": {
"type": "string",
"id": "string"
},
"fetchedAt": "string",
"expiresAt": "string"
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​


Powered by VitePress OpenAPI

Built with VitePress