Skip to main content
GET
Validates the provided API key and returns its metadata, including the scopes it was granted and the user and organization it belongs to. Any valid key can call this endpoint - no specific scope is required.

Headers

string
required
Bearer token. Example: Bearer runtm_sk_live_abc123...

Response

boolean
Whether the key is valid.
string
Unique identifier of the API key.
string
Display name given to the key at creation.
string
The user ID the key belongs to.
string | null
Organization the key is scoped to, or null for personal keys.
string | null
Tenant ID used for deployment and telemetry scoping. Matches organization_id for org keys, or user_id for personal keys.
string | null
Current role of the key owner in the organization (owner, admin, member), or null for personal keys.
string[]
Scopes stored on the key at creation time (e.g. ["sessions:read", "sessions:write"]).
string[]
Scopes actually enforced at request time. This is the intersection of stored scopes (expanded from any legacy names) and the current role ceiling. If the key owner has been demoted, effective_scopes will be narrower than scopes.
string | null
ISO 8601 expiration timestamp, or null for non-expiring keys.