> ## Documentation Index
> Fetch the complete documentation index at: https://docs.01advertising.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Read the current session

> The user, the session, and the caller's standing in the organization and workspace named by `orgSlug` / `workspaceSlug` (the Portal URL, ADR-0043), from the session cookie or the bearer token. A slug the caller cannot see answers `null` for that part; without `orgSlug` both are `null`. Answers `null` when nobody is signed in — being signed out is not an error. API keys are refused (401): sessions belong to people.



## OpenAPI

````yaml /api/openapi.json get /v1/auth/session
openapi: 3.1.0
info:
  title: 01Advertising Platform API
  version: 0.1.0
  description: >-
    HTTP API of the 01Advertising Platform: organizations, workspaces, API keys,
    audit logs, and the integrations that connect workspaces to advertising
    systems.


    ## Base URL and versions


    Production is `https://api.01ads.com`. Business endpoints live under `/v1`;
    `/health`, `/version`, and `/openapi.json` are unversioned. Before 1.0,
    breaking changes are made in place under `/v1` and shipped together with the
    Portal and CLI; from 1.0 on, a breaking change becomes a `/v2` sibling.
    Operation ids and schema names are stable identifiers. Local development
    runs at `http://127.0.0.1:3000` (`make api`).


    ## Authentication


    Three ways in, declared as security schemes and on every operation: a
    **session cookie** (browsers, set by the sign-in routes), the same session
    as **`Authorization: Bearer`** (the CLI and scripts), or an
    organization-bound **API key** as `x-api-key` (integrations and automation).
    Operations that declare no security requirement are public; operations that
    list only the two session schemes refuse API keys — administrative and
    account changes stay with people.


    ## Errors


    Every non-2xx answer is `application/problem+json` (RFC 9457): `type`,
    `title`, `status`, `detail`, `instance`, and `requestId`; validation
    failures add `errors: [{ path, message }]`. Browser flows answer 302 with no
    body.


    ## Collections, rate limits, and system administration


    Collections are returned whole; `GET /v1/organizations/{orgSlug}/audit-logs`
    is cursor-paginated (`cursor`, `limit`, `nextCursor`). Sign-in emails and
    sign-ups are limited per client address and per email, invitations created
    through an API key per key, and the public connect flow per address and per
    token: a limited request answers 429 with `Retry-After` in seconds.


    Guides, playbooks, and the embedding walkthrough:
    https://docs.01advertising.com.
  termsOfService: https://www.01advertising.com/legal/terms/
  contact:
    name: 01Advertising API support
    email: support@01advertising.com
    url: https://docs.01advertising.com
  license:
    name: Proprietary
    url: https://www.01advertising.com/legal/terms/
servers:
  - url: https://api.01ads.com
    description: Production
security:
  - bearerAuth: []
  - apiKey: []
tags:
  - name: account
    description: The caller's own profile, sign-up, and the invitations addressed to them
    externalDocs:
      url: https://docs.01advertising.com/guides/account
      description: Account guide
  - name: auth
    description: Sign-in methods, magic links, provider sign-in, sessions, and sign-out
    externalDocs:
      url: https://docs.01advertising.com/guides/auth
      description: Authentication guide
  - name: organizations
    description: Organization membership and invitation management
    externalDocs:
      url: https://docs.01advertising.com/guides/organizations
      description: Organizations guide
  - name: workspaces
    description: 'Workspaces: isolated partitions within an organization'
    externalDocs:
      url: https://docs.01advertising.com/guides/workspaces
      description: Workspaces guide
  - name: api-keys
    description: Programmatic access credentials
    externalDocs:
      url: https://docs.01advertising.com/guides/api-keys
      description: API keys guide
  - name: audit
    description: Organization audit trail (cursor-paginated)
    externalDocs:
      url: https://docs.01advertising.com/guides/audit-logs
      description: Audit log guide
  - name: integrations
    description: Workspace integrations with external advertising systems
    externalDocs:
      url: https://docs.01advertising.com/guides/integrations
      description: Integrations guide
  - name: connect
    description: >-
      The public connect flow a client uses to authorize an integration (no
      session)
    externalDocs:
      url: https://docs.01advertising.com/guides/integrations-embedding
      description: Embedding the connect flow
  - name: infra
    description: Health, build information, and this document
    externalDocs:
      url: https://docs.01advertising.com/guides/api-conventions
      description: API conventions
externalDocs:
  url: https://docs.01advertising.com
  description: Developer documentation
paths:
  /v1/auth/session:
    get:
      tags:
        - auth
      summary: Read the current session
      description: >-
        The user, the session, and the caller's standing in the organization and
        workspace named by `orgSlug` / `workspaceSlug` (the Portal URL,
        ADR-0043), from the session cookie or the bearer token. A slug the
        caller cannot see answers `null` for that part; without `orgSlug` both
        are `null`. Answers `null` when nobody is signed in — being signed out
        is not an error. API keys are refused (401): sessions belong to people.
      operationId: getSession
      parameters:
        - schema:
            type: string
            minLength: 1
            description: >-
              Scope the answer to this organization (the one the Portal URL
              names). Omitted: the session's active organization
            examples:
              - acme-corp
          required: false
          description: >-
            Scope the answer to this organization (the one the Portal URL
            names). Omitted: the session's active organization
          name: orgSlug
          in: query
        - schema:
            type: string
            minLength: 1
            description: >-
              With `orgSlug`: also resolve this workspace and the caller's
              effective role in it
            examples:
              - eu-clients
          required: false
          description: >-
            With `orgSlug`: also resolve this workspace and the caller's
            effective role in it
          name: workspaceSlug
          in: query
      responses:
        '200':
          description: The session, or null when anonymous
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Session'
        '401':
          description: API keys do not authenticate the auth routes
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                unauthorized:
                  summary: No usable credential
                  value:
                    type: about:blank
                    title: Unauthorized
                    status: 401
                    detail: Authentication required. Sign in and try again.
                    instance: /v1/organizations
                    requestId: 2f6a9c3d-1e4b-4a8c-b7d2-5e0f1a2b3c4d
      security:
        - bearerAuth: []
        - {}
components:
  schemas:
    Session:
      type:
        - object
        - 'null'
      properties:
        user:
          type: object
          properties:
            id:
              type: string
            email:
              type: string
              format: email
            name:
              type: string
            emailVerified:
              type: boolean
            image:
              type:
                - string
                - 'null'
            role:
              type:
                - string
                - 'null'
              description: Platform role; `user` for every regular account
          required:
            - id
            - email
            - name
            - emailVerified
            - image
            - role
        session:
          type: object
          properties:
            expiresAt:
              type: string
              description: ISO timestamp
          required:
            - expiresAt
        organization:
          type:
            - object
            - 'null'
          properties:
            id:
              type: string
            slug:
              type: string
            name:
              type: string
            role:
              type: string
              enum:
                - admin
                - member
                - viewer
                - guest
              description: The caller's role in it
          required:
            - id
            - slug
            - name
            - role
          description: >-
            The organization named by `orgSlug` (null when no slug was given or
            the caller is not a member of it)
        workspace:
          type:
            - object
            - 'null'
          properties:
            id:
              type: string
            slug:
              type: string
            name:
              type: string
            region:
              type: string
              enum:
                - gcp-us-central1
            role:
              type: string
              enum:
                - admin
                - member
                - viewer
              description: The caller's effective role in it
          required:
            - id
            - slug
            - name
            - region
            - role
          description: >-
            The workspace named by `workspaceSlug` inside that organization, or
            null when no slug was given or the caller cannot view it
      required:
        - user
        - session
        - organization
        - workspace
      description: The session, or null when the caller is not signed in
    Problem:
      type: object
      properties:
        type:
          type: string
          examples:
            - about:blank
        title:
          type: string
          examples:
            - Unauthorized
        status:
          type: integer
          examples:
            - 401
        detail:
          type: string
        instance:
          type: string
          examples:
            - /v1/me
        requestId:
          type: string
        errors:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              message:
                type: string
            required:
              - path
              - message
          description: Field-level problems of a validation failure
      required:
        - type
        - title
        - status
        - instance
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Session token as `Authorization: Bearer` (the CLI and scripts).'
    apiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization-bound API key; accepted on /v1 routes other than
        /v1/auth/*.

````