Skip to main content
Resolved scope for the current token

Authorizations

Authorization
string
header
required

Every request sends Authorization: Bearer <token>. The token is either a panel session (a JWT from /auth/login, 12 hours) or an API key ft_<id>_<secret>. An API key is accepted only from an address on its IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required for an old key that has none), is limited to its rate per minute (429 rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on every response), and at most 60 call placements a minute.

Response

OK

The RESOLVED scope, not merely the token's claims, so the panel can render navigation without guessing at permissions.

all_organisations
boolean
required
organisation_ids
string<uuid>[]
required
team_ids
string<uuid>[]
required
user
object
required