> ## Documentation Index
> Fetch the complete documentation index at: https://docs.1club.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Describe the API key's organization and granted scopes

> Returns the organization the API key belongs to, the scopes granted to the key, and the catalog of resources/actions the platform API exposes. Requires a valid API key but no specific scope - use it to verify a key and discover what it can access.

A full-access key holds the single wildcard scope `*`. Test a capability against `effectiveScopes`, which expands the wildcard, rather than against `scopes`, which reports the grant verbatim.




## OpenAPI

````yaml /openapi-platform.json get /v1/platform/me
openapi: 3.0.0
info:
  title: 1club Platform API
  version: 1.0.0
  description: >-
    The 1club Platform API lets you programmatically access and manage your
    organization's data.


    ## Official API Contract


    This documentation is the official source of truth for the 1club Platform
    API.

    If an integration relies on undocumented endpoints, fields, response shapes,
    or internal behavior outside this spec, we can't guarantee backward
    compatibility.

    Build against what's documented here to stay stable as the platform evolves.


    ## Authentication


    All requests require a customer API key passed as a Bearer token:


    ```

    Authorization: Bearer 1club_sk_live_...

    ```


    Generate API keys from the admin portal under **Settings > API Tokens**.

    The key is tied to your organization - all responses are scoped to your
    org's data.


    ## Rate Limiting


    - **100 requests per minute** per API key

    - When exceeded, the API returns `429 Too Many Requests` with a
    `Retry-After` header

    - Rate limit headers are included in every response:
      - `X-RateLimit-Limit` - max requests per window
      - `X-RateLimit-Remaining` - requests remaining
      - `X-RateLimit-Reset` - seconds until the window resets

    ## Errors


    | Status | Meaning |

    |--------|---------|

    | `400` | Invalid request parameters |

    | `401` | Missing or invalid API key |

    | `404` | Resource not found (or doesn't belong to your organization) |

    | `429` | Rate limit exceeded |

    | `500` | Internal server error |
  contact:
    name: 1club API Support
    email: support@1club.ai
servers:
  - url: https://api.1club.ai
    description: Production API
security:
  - customerApiAuth: []
tags: []
paths:
  /v1/platform/me:
    get:
      tags:
        - Account
      summary: Describe the API key's organization and granted scopes
      description: >
        Returns the organization the API key belongs to, the scopes granted to
        the key, and the catalog of resources/actions the platform API exposes.
        Requires a valid API key but no specific scope - use it to verify a key
        and discover what it can access.


        A full-access key holds the single wildcard scope `*`. Test a capability
        against `effectiveScopes`, which expands the wildcard, rather than
        against `scopes`, which reports the grant verbatim.
      responses:
        '200':
          description: API key identity and granted scopes
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformIdentity'
        '401':
          description: Invalid or missing API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformError'
        '404':
          description: Organization not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformError'
        '429':
          description: Rate limit exceeded
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformError'
      security:
        - customerApiAuth: []
components:
  schemas:
    PlatformIdentity:
      type: object
      description: >-
        Describes the authorized organization, the scopes granted to the bearer
        credential, and the catalog of available platform resources.
      properties:
        organization:
          type: object
          properties:
            id:
              type: integer
            name:
              type: string
            slug:
              type: string
            currency:
              type: string
              description: >-
                ISO 4217 code the organization trades in (e.g. "EUR"). Every
                monetary amount on this API - booking `payment.amount`, plan and
                product prices, transaction totals - is expressed in it, and no
                other endpoint repeats it. Read it once when you connect.
        scopes:
          type: array
          items:
            type: string
          description: >-
            Scopes granted to the bearer credential - an API key or an MCP OAuth
            grant - exactly as held (e.g. "classes:read"). A full-access key
            holds the single wildcard scope "*"; read `effectiveScopes` to see
            what that resolves to. An MCP grant never holds "*": the wildcard is
            expanded at consent so each capability can be shown and approved.
        fullAccess:
          type: boolean
          description: >-
            True when the credential holds the wildcard scope "*", granting
            every scope including ones added after it was issued.
        effectiveScopes:
          type: array
          items:
            type: string
          description: >-
            The scopes this credential can actually use - identical to `scopes`
            for a narrow grant, and the full expansion of "*" for a full-access
            key. Check a capability against this list, not `scopes`.
        resources:
          type: array
          description: Catalog of resources and the actions each supports.
          items:
            type: object
            properties:
              resource:
                type: string
              label:
                type: string
              actions:
                type: array
                items:
                  type: string
    PlatformError:
      type: object
      properties:
        error:
          type: string
  securitySchemes:
    customerApiAuth:
      type: http
      scheme: bearer
      description: >-
        Organization-scoped bearer credential: a customer API key
        (1club_sk_live_...) or an MCP OAuth access token.

````