Get the current authenticated user
Returns identity, membership, tenant, and role claims after signature and host-to-tenant validation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
OK
*/*- response
company?globalUserId?stringmembershipId?stringroles?array<string>tenantId?stringuserId?stringcurl -X GET 'https://api.monetaryai.uz/api/v1/me'{ "company": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "name": "string", "onboardingComplete": true, "taxId": "string" }, "globalUserId": "string", "membershipId": "string", "roles": [ "string" ], "tenantId": "string", "userId": "string"}Revoke one own refresh session DELETE
Stops future refresh for this family only. Already issued access JWTs remain valid until their configured expiry; this is not immediate access-token invalidation. Only the authenticated active membership's family in this tenant can be changed.
List own active refresh sessions GET
Returns family identifiers, creation, refresh-expiry, User-Agent, IP and last login/refresh activity for the authenticated active membership in this tenant. No tokens or hashes. User-Agent is untrusted client metadata; IP is the container remote address. Current is determined by the signed session_id claim (legacy tokens have no current marker). Stable newest-first pagination.