Account
Describe the calling token
Introspect the token you authenticated with: which org it acts on, what scope it carries, and when it expires. Side-effect free — the first call to make when wiring up an integration.
Authorization
bearerAuth AuthorizationBearer <token>
An API key from Settings → Integrations → Webhook (org admins only), sent as Authorization: Bearer rf_org_….
The scope is ranked — a key satisfies any requirement at or below its own tier:
read— see leads, conversations, transcripts and handoffs. Never changes anything.write— create and update leads, claim and resolve handoffs.admin— mint and revoke tokens, and change org-wide integration settings.
There is no approve scope. It was a rung once; it is not one now, and a key requested with it is rejected.
Tokens are org-scoped: one sees every agent's leads in its org. There is no project dimension. The token is shown once at creation and stored only as a hash.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/api/v1/me"{ "object": "api_token", "id": "c40f9a13-7b62-4e05-8f1a-2d3c6e9b7451", "name": "Acme CRM", "scope": "write", "token_prefix": "rf_org_a1b2c3", "created_at": "2026-07-01T08:00:00.000Z", "last_used_at": "2026-07-26T11:04:22.000Z", "expires_at": null, "org": { "id": "0a7d3c19-5f28-4b61-9e30-8c1a2f6d4b73", "name": "Just Move Dubai", "vertical": "real-estate" }}