Token introspection
Ask the API what the token you hold can do.
| Method | Path | Scope |
|---|---|---|
| GET | /api/v1/me | any valid token |
GET /api/v1/me
Returns the metadata of the token used to make the call and the tenant it belongs to — never the token plaintext. env is live or test and matches the token prefix (tk_live_ / tk_test_); it reflects the deployment the token was minted by, see Sandbox. Useful as a first call from a new integration, and for support tooling that needs to answer "what is this key allowed to do?".
Response 200
This is the one endpoint whose body is not wrapped in data — the four
members are at the top level:
{
"token": {
"id": "tok_…",
"name": "Zapier production",
"prefix": "tk_live_ab…",
"scopes": ["trips:read", "bookings:read", "webhooks:write"],
"lastUsedAt": "2026-09-05T10:12:00.000Z",
"expiresAt": null,
"createdAt": "2026-05-26T12:00:00.000Z",
"revoked": false
},
"tenant": { "id": "ten_…", "name": "Andes Trails", "slug": "andes-trails", "active": true },
"tier": "pro",
"env": "live"
}token and tenant are each null if the row behind them has gone.
Errors — 401, 403 (plan-required, if the tenant's plan has no API access — this endpoint is behind the same gate as the rest), 429.
/api/v1/meTry itConfirms the token works and shows its scopes.
Requests are proxied through this docs site so CORS doesn't block the call. Use a sandbox token if you don't want test calls hitting live data.
GET /api/v1/me
