Get current authenticated user
Returns the full profile of the currently authenticated user including private fields, roles, and tenant settings. Refreshes the user’s permissions on each call (unless impersonating). Auto-detects and sets the user’s timezone from the HTTP_USER_TIMEZONE header if not already set. Also logs the access event for activity tracking.
Authorizations
Server-to-server authentication. Generate a token in the admin UI at
Settings → Developers → API Access. Send the raw token in the
Api-Token header — there is no Bearer prefix.
Tokens can be marked read-only at creation time, in which case the API
rejects any non-GET request with 403 Forbidden.
Response
User resource
255255
