Skip to content

Loading…

Retrieve key context

Return the workspace and scopes of the API key used for the request.

GET/v1/ext/me

Works with any active API key — no scope required

On this page

Use this endpoint to check a key: at deploy time, in a health check, or when a user pastes a key into your product. It works with any active key, needs no scope and does not read or change workspace data.

Compare user.scopes with the scopes your integration needs, and fail early with a clear message if one is missing — instead of waiting for the first 401 Lack of permissions.

Example request

curl "https://api.vestta.app/v1/ext/me" \
  -H "X-Api-Key: $VESTTA_API_KEY"

Authorization

  • X-Api-Keystringheaderrequired

    Your API key, AC_LIVE_<key_id>.<secret>. Authorization: ApiKey <key> is also accepted.

Response

200 Successful response.

Example response
{
  "status": "ok",
  "user": {
    "company_name": "Inmobiliaria Ejemplo",
    "scopes": [
      "properties:read",
      "leads:read"
    ],
    "auth_method": "api_key"
  }
}

Response fields

  • statusstringrequired always ok
  • userApiKeyContextrequired

Errors

StatusWhen
401 UnauthorizedThe API key is missing, malformed, unknown, revoked or expired, or lacks the required scope.
422 Unprocessable ContentA path parameter, query parameter or body field is invalid.
500 Internal Server ErrorUnexpected server error while processing the request.

Error bodies and how to handle each case: Errors.