Get who the caller is
The subject, scopes, agents and sandbox grants of the credential that sends it: an application key (alone or acting for a subject), a management key (via: management:<principalId>, no scopes, no agents), or a trusted issuer's token (via: issuer:<name>).
AuthorizationBearer <token>An application key of the Tenant (PUT /v1/tenant/keys/{keyId}), or Studio's key, derived from the admin key. With Nylorun-Subject and Nylorun-Scopes, it acts for that person, narrowed to those scopes. Never accepted from a browser (Origin).
Nylorun-Protocol*stringThe protocol version, 8
Nylorun-Subject?stringThe person an application key acts for
Nylorun-Scopes?stringThe subject's space-separated scopes; required with a subject
The caller
application/json- response
subject?stringThe person the request acts for; absent for an application key alone
scopes*array<>agents*|array<>sandboxes?array<string>A token caller's sandbox grants (empty reaches none); absent when no grant limits the caller
via*stringHow the caller authenticated: application:<principalId>, management:<principalId>, subject or issuer:<name>
curl -X GET "https://example.com/v1/me" \ -H "Nylorun-Protocol: string"{ "subject": "string", "scopes": [ "agents:read" ], "agents": "*", "sandboxes": [ "string" ], "via": "string"}