Zum Inhalt springen
Web APIAuth

Auth

Introspection of the credential a request is made with — the organisation it is bound to, its tier, and the permissions it holds.

1 operationBase https://api.staging.locantra.de

Introspect the calling credential

GEThttps://api.staging.locantra.de/auth/key

Reports what the credential this request was made with can do: the organisation it is bound to, that organisation's tier, and every permission it holds. Any valid credential may call it — no permission of its own is required — which makes it the one cheap call to make once after a key is pasted, to find out what the rest of the API will allow. The key is never echoed back in the answer. Permissions are the same names operations publish as x-locantra-permission, so an operation whose permission is missing from the list is answered 403.