Get Profile
GET/api/auth/profile
Returns the authenticated user's profile information along with a top-level is_production_server flag indicating whether the server is running in production (used by the SPA to gate sandbox-environment UI affordances).
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token.
Response flags:
is_production_server(boolean) — true when this pod is the production environment.features(object) — per-account feature-flag map (same asGET /api/features); each value is a boolean.
Request
Responses
- 200
- 401
- 403
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.