> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fivemesh.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Inspect an API key

> Read the authenticated key's permissions, path restrictions and server binding.

Use this read-only endpoint to check which key your integration is using. It does not return the secret.

```bash theme={null}
curl "https://api.fivemesh.io/v1/whoami" \
  -H "Authorization: Bearer $FIVEMESH_API_KEY"
```

The response includes:

| Field | Meaning |
| - | - |
| `credentialType` | `server` or `developer`. |
| `keyId` | Key record identifier. |
| `organization` | Optional organization context; its ID may be `null` for a personal key. |
| `server` | Bound server with `id` and `cfxId`, or `null` for a global key. |
| `permissions` | Allowed actions grouped by service. |
| `restrictions` | Allowed and denied CDN path prefixes. |
| `allowedMimeTypes` | MIME restrictions, or `null` when unrestricted. |

Responses are private and not cached. The SDK calls this endpoint at startup and exposes it through `whoami()`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.