Who is calling
const url = 'https://example.com/api/v1/me';const options = { method: 'GET', headers: {cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/me \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3EThe caller as the service knows it: name, roles and how it authenticated.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK.
Who is calling: a user of the identity provider, an API key, or the break-glass token.
object
The subject at the identity provider, or the id of the API key.
viewer, operator and/or admin.
How the caller authenticated: oidc, api_key, token or setup.
What the credential may be used for: management, gateway, setup.
cli for a user working through bl (decisions #62); the audit log
says so. The same person in the UI has None.
Example generated
{ "subject": "example", "name": "example", "email": "example", "roles": [ "example" ], "auth": "example", "scopes": [ "example" ], "via": "example"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}