Account

Describe the calling token

GET
/api/v1/me

Introspect the token you authenticated with: which org it acts on, what scope it carries, and when it expires. Side-effect free — the first call to make when wiring up an integration.

Authorization

bearerAuth
AuthorizationBearer <token>

An API key from Settings → Integrations → Webhook (org admins only), sent as Authorization: Bearer rf_org_….

The scope is ranked — a key satisfies any requirement at or below its own tier:

  • read — see leads, conversations, transcripts and handoffs. Never changes anything.
  • write — create and update leads, claim and resolve handoffs.
  • admin — mint and revoke tokens, and change org-wide integration settings.

There is no approve scope. It was a rung once; it is not one now, and a key requested with it is rejected.

Tokens are org-scoped: one sees every agent's leads in its org. There is no project dimension. The token is shown once at creation and stored only as a hash.

In: header

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/v1/me"
{  "object": "api_token",  "id": "c40f9a13-7b62-4e05-8f1a-2d3c6e9b7451",  "name": "Acme CRM",  "scope": "write",  "token_prefix": "rf_org_a1b2c3",  "created_at": "2026-07-01T08:00:00.000Z",  "last_used_at": "2026-07-26T11:04:22.000Z",  "expires_at": null,  "org": {    "id": "0a7d3c19-5f28-4b61-9e30-8c1a2f6d4b73",    "name": "Just Move Dubai",    "vertical": "real-estate"  }}