Skip to main content
GET
cURL
Use this endpoint to check which account a credential belongs to and whether it still has paid data access. The CLI uses it for 0xinsider whoami. For request counts and remaining quota, use Usage.

Key response fields

Example

What it does not return

  • An email address, a token, or a credential hash. Nothing in the body identifies a person.
  • Paid data. A valid credential keeps this diagnostic after paid data access lapses, while every paid data route answers 402 subscription_required.
  • An answer for an OAuth grant without the read scope. That answers 403 insufficient_scope and names the missing scope.
  • An answer for a revoked, expired, unknown, deleted, or locked credential. Each one keeps the refusal it already had.
  • Any other account. You see only the account the credential belongs to.

Authorizations

Authorization
string
header
required

Legacy default or named integration API key, or OAuth 2.1 access token, in the Authorization header as Bearer oxi_sk_live_... or Bearer oxi_at_.... Default keys retain full access; integration keys are limited to their approved read, webhooks, export and usage scopes and expire within 90 days. All credentials share the owner's account limits. Data calls require an active Pro subscription and return live data. A 401 carries WWW-Authenticate: Bearer resource_metadata="https://api.0xinsider.com/.well-known/oauth-protected-resource" (RFC 6750 section 3, RFC 9728).

Headers

X-Query-Validation
enum<string>

Opt into strict query-name validation. The default is compatible: unknown names are ignored and reported in X-Query-Ignored. With strict, an unknown name returns 400 bad_request with error.reason unknown_query_parameter before the handler runs, including when its percent escape is incomplete.

Available options:
strict

Response

Authenticated account and credential identity.

object
enum<string>
required
Available options:
account
data
object
required
meta
object
required