# Me

Base URL: `https://api.brixsignage.com`. Send `Authorization: Bearer $BRIX_API_KEY` unless an operation says Auth: none.

## GET /v1/me

Describe the calling credential

Returns who is calling and what they are allowed to do: whether the caller is a signed-in person, an API key, or Brix support; the location an API key is pinned to, if any; the workspace; and the caller's full set of permissions.

Who is calling (API key, user, or Brix support), which workspace the call resolves to, and the permissions held. Call it first when a request is refused: `actor.nodeId` shows a key pinned to one location.

Auth: Bearer token. Permission: `screen.view`.

```bash
curl "https://api.brixsignage.com/v1/me" \
  -H "Authorization: Bearer $BRIX_API_KEY"
```

Response 200: Success.

| Field | Type | Description |
| --- | --- | --- |
| `data` | object |  |
| `data.actor` | object \| object \| object | The credential making the call: an API key, a user session, or Brix support. |
| `data.workspace` | WorkspaceRef |  |
| `data.workspace.id` | string | Workspace id. |
| `data.workspace.name` | string \| null | Workspace name; null only if the workspace row is missing. |
| `data.permissions` | "all" \| array of string | `all` for an owner-style credential, else every `resource.verb` held anywhere in the workspace. A planning hint: node-scoped checks still run on each call. |

```json
{
  "data": {
    "actor": {
      "kind": "key",
      "id": "key_6f7a8b9c0d1e2f3a",
      "name": "Menu board sync",
      "nodeId": null
    },
    "workspace": {
      "id": "space_1a2b3c4d5e6f7a8b",
      "name": "Riverside Coffee"
    },
    "permissions": [
      "screen.view",
      "screen.cast",
      "media.view",
      "media.create"
    ]
  }
}
```

Response 401: Missing, expired or revoked bearer token.

| Field | Type | Description |
| --- | --- | --- |
| `error` | string | Machine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, … |
| `message` | string | Human-readable explanation. Safe to show an operator. |
| `requestId` | string | Present on 5xx: quote it to support. |

Response 403: The token lacks the permission this operation needs (see `x-brix-permission`).

| Field | Type | Description |
| --- | --- | --- |
| `error` | string | Machine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, … |
| `message` | string | Human-readable explanation. Safe to show an operator. |
| `requestId` | string | Present on 5xx: quote it to support. |

Response 5XX: Server error. The body carries a `requestId` to quote to support.

| Field | Type | Description |
| --- | --- | --- |
| `error` | string | Machine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, … |
| `message` | string | Human-readable explanation. Safe to show an operator. |
| `requestId` | string | Present on 5xx: quote it to support. |
