HomeDocsSupport
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Article Navigation
OverviewWhat is AliasFleet?Creating an AliasEmails Not ArrivingContact Support

Getting Started

Getting Started
  • What is AliasFleet?
  • Your First Alias
  • Understanding Forwarding
  • Your Dashboard at a Glance

Account & Billing

Account & Billing
  • Your Plan and Usage Limits
  • Upgrading to Pro
  • Managing Your Subscription
  • Downloading Invoices
  • Support Ticket Limits
  • Membership Tier
  • Billing Cycle and Renewal
  • API Rate Limits by Plan

Billing Support

Account & Billing
  • Cancelling Your Subscription
  • Downgrading Your AliasFleet Plan
  • Understanding Proration and Plan Changes
  • Updating Your Payment Method
  • Handling Failed Payments and Account Suspension
  • AliasFleet Refund Policy

Email Aliases

Email Aliases
  • Creating and Managing Aliases
  • Activating and Deactivating an Alias
  • Deleting an Alias
  • Sorting, Filtering and Searching Aliases
  • Grid View vs List View
  • Grouping Aliases
  • Alias Categories
  • Copying an Alias Address
  • Per-Alias Email Banner Settings
  • Alias Permission Mode
  • Sending Outbound Emails (Quick Send)

Custom Domains

Custom Domains
  • Adding a Custom Domain
  • DNS Verification
  • Domain Status and Health Indicators
  • Subdomains
  • Removing a Domain
  • Using Your Domain on Aliases

Destinations

Destinations
  • What Is a Destination?
  • Adding a Destination
  • Verifying a Destination
  • Setting a Default Destination
  • Reply from Aliases
  • Send New Emails from Aliases
  • Understanding Email Threading & Replies
  • One-Click Enable from Bounce Email
  • Removing a Destination
  • PGP Encryption for Destinations
  • WKD Auto-Encryption for Replies & Sends

Security & Privacy

Security & Privacy
  • Security Best Practices
  • Two-Factor Authentication (2FA)
  • Active Sessions
  • Changing Your Password
  • What Data AliasFleet Stores
  • Reporting a Security Issue
  • Browser Extension Sessions
  • How to Use Vault Lock in the Extension

Rate Limiting

Security & Privacy
  • Rate Limiting & Account Protection

Settings

Settings
  • General Settings
  • Profile Settings
  • Alias Settings
  • Destinations in Settings
  • Notification Settings
  • Security Settings
  • Deleting Your Account

Analytics

Analytics
  • Analytics Overview
  • Alias Performance
  • Top Senders
  • Trends
  • Bounces
  • Bandwidth Usage
  • Category Breakdown
  • Exporting Analytics Data
  • Understanding Your Alias Statistics
  • How Monthly Trends Work

Sender Rules

Sender Rules
  • Using Sender Rules
  • Blacklist vs Deactivating an Alias
  • Using Sender Rules to Allow Senders (Whitelist)
  • Blocked Emails Explained

Troubleshooting

Troubleshooting
  • Emails Not Arriving
  • Can't Verify a Destination
  • DNS Not Verifying
  • Can't Log In
  • Replies Not Going Through Alias
  • Alias Not Forwarding
  • Payment Failed
  • Browser Extension Issues
  • Too Many Requests Error
  • Page Not Loading or Showing an Error

Developers

Developer API
  • Identity & Token Introspection API
  • Aliases API
  • Alias Destinations & Batch Operations API
  • Domains API
  • Destinations API
  • Quick-Send API
  • Sender Rules API
  • Activity & Audit Logs API
  • Fleet Analytics API
  • Rules Engine API
  • Security & Threat Intelligence API
  • Webhooks API
PrivacyTermsCookies
Developer API
Docs
Developer API
Identity & Token Introspection API

Identity & Token Introspection API

Verify token validity, inspect active permission scopes, and retrieve account metadata using the Identity API.

2 min read
Updated September 4, 2026

Introspect active API credentials, verify permission scopes, and check workspace quota limits.


GET /v1/me — Introspect Caller Identity

Scope: None (Any active key) · Rate Limit: 60/min · Idempotent: Yes

Retrieves the authenticated principal's user account details, active subscription plan, assigned permission scopes, and current resource usage. Useful for startup health checks, CLI handshakes, and credential verification.

Headers

HeaderTypeRequiredDescription
AuthorizationstringYes*Bearer token format: Bearer afp_....
x-api-keystringYes*Alternative API key header.

* Exactly one authentication header must be supplied.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/me" \
  -H "Authorization: Bearer afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "user": {
    "id": "usr_9f83a2c1b4d5e6f7",
    "email": "alex.mercer@company.com",
    "username": "alexm",
    "plan": "pro",
    "is_active": true
  },
  "auth": {
    "type": "api_key",
    "key_id": "key_1a2b3c4d5e6f7g8h",
    "name": "Production Deploy Bot",
    "masked_key": "afp_••••••••••••••••0d1e",
    "scopes": [
      "aliases:read",
      "aliases:write",
      "domains:read",
      "destinations:read"
    ],
    "expires_at": null,
    "last_used_at": "2026-09-04T12:00:00.000Z"
  },
  "quotas": {
    "aliases_used": 24,
    "aliases_limit": 500,
    "domains_used": 3,
    "domains_limit": 10,
    "destinations_used": 2,
    "destinations_limit": 5
  }
}

Errors

StatusCodeCause & Resolution
401 UnauthorizedUNAUTHORIZEDMissing, expired, or invalid API key. Verify token prefix (afp_).
429 Too Many RequestsRATE_LIMIT_EXCEEDEDRequest rate limit exceeded. Check Retry-After header.

GET /v1/auth/whoami — Gateway Introspection Alias

Scope: None (Any active key) · Rate Limit: 60/min · Idempotent: Yes

Standard RFC 7662 token introspection endpoint. Operates identically to GET /v1/me, provided for API gateway plugins (Kong, Envoy, Cloudflare Workers) and OAuth2 reverse proxies that require a standard whoami URL.

Example Request

curl -X GET "https://api.aliasfleet.com/v1/auth/whoami" \
  -H "x-api-key: afp_4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e" \
  -H "Accept: application/json"

Response (200 OK)

{
  "user": {
    "id": "usr_9f83a2c1b4d5e6f7",
    "email": "alex.mercer@company.com",
    "username": "alexm",
    "plan": "pro",
    "is_active": true
  },
  "auth": {
    "type": "api_key",
    "key_id": "key_1a2b3c4d5e6f7g8h",
    "name": "Production Deploy Bot",
    "masked_key": "afp_••••••••••••••••0d1e",
    "scopes": [
      "aliases:read",
      "aliases:write"
    ]
  }
}

Errors

StatusCodeCause & Resolution
401 UnauthorizedUNAUTHORIZEDMissing, expired, or invalid token.
429 Too Many RequestsRATE_LIMIT_EXCEEDEDRequest threshold reached. Back off for the duration in Retry-After.

Frequently Asked Questions

What is the difference between /v1/me and /v1/auth/whoami?

Both endpoints execute the same internal handler and return the identical identity payload. /v1/auth/whoami is provided as a standard introspection alias for OAuth2 and API gateway middleware.

Are identity requests cached?

Yes. Identity responses are cached at the edge for up to 10 minutes per credential, providing fast validation during microservice startup.

What permissions do I need to call /v1/me?

No specific scope is required. Any active, unrevoked developer key (afp_...), dashboard session, or extension token can call this endpoint.

Was this article helpful?

Related articles

Aliases API

Create, list, inspect, update, and soft-delete email aliases programmatically using the AliasFleet REST API.

Alias Destinations & Batch Operations API

Configure multi-destination forwarding fanout, execute atomic batch updates across up to 100 aliases, and fine-tune per-alias privacy settings.

Domains API

Query shared platform domains, register custom brand domains, verify DNS records, and inspect catch-all forwarding rules.

Destinations API

Register destination inboxes, execute 6-digit OTP verification challenges, configure per-channel sender identities, and manage routing fallbacks.

Quick-Send API

Dispatch outbound emails through your aliases, stage attachments via presigned URLs, inspect delivery logs, and manage sender signatures.

Content

GET /v1/me — Introspect Caller IdentityHeadersExample RequestResponse (`200 OK`)ErrorsGET /v1/auth/whoami — Gateway Introspection AliasExample RequestResponse (`200 OK`)Errors

Still need help?

Can't find the answer you're looking for? Our support team is here to help.

Create Support Ticket