> ## Documentation Index
> Fetch the complete documentation index at: https://trueforge.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Current session

> Returns the authenticated caller identity (`type`, `tenant_id`, `subject`, `roles`) wrapped as `{ data }`. `type` is `oidc-connected` when browser OIDC is enabled, otherwise `default`. When auth is enabled this requires a valid `id_token` cookie or `Authorization: Bearer` token (401 otherwise). When auth is disabled, returns the standalone default identity.



## OpenAPI

````yaml /openapi.json get /api/v1/auth/me
openapi: 3.1.0
info:
  description: >-
    HTTP API for the TrueForge agent server (`/api/v1`). Interactive docs are
    served at `/api/v1/docs` (OpenAPI JSON at `/api/v1/openapi.json`).


    **Authentication:** Standalone auth accepts requests without credentials —
    middleware stamps a local default user. When OIDC or TrueFoundry auth is
    configured, protected routes require a valid cookie or `Authorization:
    Bearer` token. There is no built-in API-key scheme; pass custom headers only
    if your reverse proxy or IdP layer requires them.


    Covers DB-backed sessions, the agent registry, settings catalogs, and
    model/MCP/skill/sandbox providers.
  title: TrueForge API
  version: 0.0.0
servers: []
security:
  - BearerAuth: []
tags:
  - name: Internal
  - name: Auth
  - name: Capabilities
  - name: Models
  - name: MCP Servers
  - name: Skills
  - name: Sandboxes
  - name: Web Search Providers
  - name: Agents
  - name: Schedules
  - name: Agent Sessions
paths:
  /api/v1/auth/me:
    get:
      tags:
        - Auth
      summary: Current session
      description: >-
        Returns the authenticated caller identity (`type`, `tenant_id`,
        `subject`, `roles`) wrapped as `{ data }`. `type` is `oidc-connected`
        when browser OIDC is enabled, otherwise `default`. When auth is enabled
        this requires a valid `id_token` cookie or `Authorization: Bearer` token
        (401 otherwise). When auth is disabled, returns the standalone default
        identity.
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetMeResponse'
          description: Caller identity for the current request.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RequestErrorResponse'
          description: Auth is enabled and the request has no valid cookie or Bearer token.
components:
  schemas:
    GetMeResponse:
      properties:
        data:
          $ref: '#/components/schemas/Me'
      required:
        - data
      type: object
    RequestErrorResponse:
      properties:
        error:
          properties:
            code:
              description: Optional machine-readable error code; null when not applicable.
              type:
                - string
                - 'null'
            message:
              description: Human-readable explanation of the failure.
              type: string
            param:
              description: >-
                Optional request field that caused the error; null when not
                field-specific.
              type:
                - string
                - 'null'
            type:
              description: Optional error category (e.g. validation vs conflict).
              type: string
          required:
            - message
          type: object
      required:
        - error
      type: object
    Me:
      properties:
        roles:
          description: Roles for the authenticated caller.
          items:
            type: string
          type: array
        subject:
          $ref: '#/components/schemas/GetMeSubject'
        tenant_id:
          description: Tenant scope for the authenticated caller.
          type: string
        type:
          $ref: '#/components/schemas/MeSessionType'
      required:
        - type
        - tenant_id
        - subject
        - roles
      type: object
    GetMeSubject:
      properties:
        display_name:
          description: Human-readable name for the caller.
          type: string
        id:
          description: Stable subject identifier for the caller.
          type: string
        type:
          description: Subject kind as returned by the identity provider (stored as-is).
          type: string
      required:
        - id
        - type
        - display_name
      type: object
    MeSessionType:
      description: >-
        `oidc-connected` when the process is running with browser OIDC login;
        `default` for standalone or TrueFoundry token auth.
      enum:
        - default
        - oidc-connected
      type: string
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: >-
        Caller credential (`Authorization: Bearer <token>`). Required on
        protected routes when auth is enabled. Browser sessions may use the
        HttpOnly `id_token` or `accessToken` cookie instead.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.