# Get the current user

> Who the access token acts as, and the workspaces it can work in.

<div class="g1t-endpoint"><span class="g1t-method" data-method="get">GET</span><code>/user</code></div>

`kind` is `user` for a person's token, `workspace` for a token that belongs to a workspace, and `agent` for the token a g1t agent works with.

`token` is what the access token you called with may do: its `scopes` (left out for full access) and `legacy` when it was made before tokens had scopes. A token reaches every workspace and repository whoever it acts as can; its scopes say what it may do there. See [Scopes](/guides/authentication/#scopes). `kind` is `user`, `workspace` for a [workspace access token](/guides/workspaces/#workspace-access-tokens), or `agent` for the token a g1t agent works with. For a workspace token, `username` is the workspace's slug and `workspaces` holds only that workspace. Each workspace carries its `base_permission`: what a member gets on each of its repositories (owners have Admin). Roles given on single repositories are in `grants`, each with `repo_id`, `workspace` and `role`; it is left out when there are none. See [Access and roles](/guides/access-and-roles/).

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`account`](/reference/mcp/#account) with `action` `whoami`, and the same inputs
- **Scope:** None. Any access token may use it.

## Example request

```sh
curl https://api.g1t.sh/user \
  -H "Authorization: Bearer $G1T_TOKEN"
```

## Example response

A successful request answers `200` with:

```json
{
  "id": "usr_01kkntcg1eeb98j62xjm7eh09p",
  "username": "syntaqx",
  "kind": "user",
  "verified": true,
  "workspaces": [
    {
      "slug": "acme",
      "role": "member",
      "base_permission": "write"
    },
    {
      "slug": "flagon-io",
      "role": "owner",
      "base_permission": "write"
    }
  ],
  "token": {
    "token_id": "tok_01kkntd3p2v8x6ym5r0c1q7a9e",
    "scopes": [
      "repo:read",
      "issues:read",
      "issues:write",
      "pull_requests:read",
      "pull_requests:write"
    ]
  }
}
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
