---
title: "Check the credential"
description: "Call this first. It shows the workspace the credential works in, its type (API key, MCP sign-in token or dashboard session), whether it can write, and for keys the id and expiry. A read key gets 403 read_only_key on any write, and scripts often aim at the wrong workspace."
canonical: https://docs.rumoro.dev/api/auth/whoami
markdown: https://docs.rumoro.dev/api/auth/whoami.mdx
---

# Check the credential

`GET /v1/whoami`

Call this first. It shows the workspace the credential works in, its type (API key, MCP sign-in token or dashboard session), whether it can write, and for keys the id and expiry. A read key gets 403 read_only_key on any write, and scripts often aim at the wrong workspace.

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Details of the credential |
| 401 | The API key is missing or not valid |

The [OpenAPI document](https://api.rumoro.dev/v1/openapi.json) has every schema. Rules shared by all endpoints are in [Conventions](https://docs.rumoro.dev/conventions.mdx).
