GET /user
Identify the user an API key authenticates as. The simplest way to verify a key works.
curl https://serpon.ai/user \
-H "Authorization: Bearer $SERPON_TOKEN" \
-H "Accept: application/json"
const res = await fetch('https://serpon.ai/user', {
headers: {
Authorization: `Bearer ${process.env.SERPON_TOKEN}`,
Accept: 'application/json',
},
});
const user = await res.json();
import os, requests
r = requests.get(
"https://serpon.ai/user",
headers={
"Authorization": f"Bearer {os.environ['SERPON_TOKEN']}",
"Accept": "application/json",
},
)
user = r.json()
{
"id": 7,
"name": "Ada Lovelace",
"email": "ada@example.com",
"email_verified_at": "2026-01-04T09:20:00.000000Z",
"current_account_id": 3,
"current_project_id": 1,
"created_at": "2026-01-04T09:12:00.000000Z",
"updated_at": "2026-07-30T14:02:11.000000Z"
}
{
"message": "Unauthenticated."
}
Return the authenticated user.
GET https://serpon.ai/user
Note the path: this endpoint sits outside the /v1 prefix, and outside the subscription gate. It answers 200 even for an account with no plan, which makes it the right probe for checking that a key is valid.
Authentication
Bearer token in the Authorization header. See Authentication.
Parameters
None.
Example
The response is the user record itself, not wrapped in a data envelope. Credentials — password hash, remember token, two-factor secrets — are never included.
Response fields
User ID.
Display name.
Email address.
The account currently selected in the dashboard. Not the account the key belongs to — an API key is bound to the account it was created under, whatever the user later switches to.
The project currently selected in the dashboard.
ISO 8601 timestamp.
Errors
| Status | When |
|---|---|
401 | Missing, invalid, or expired token |
403 | {"message": "This account is unavailable."} — the user account has been disabled |
Because this route skips the subscription check, a 200 here alongside a 402 on /v1/articles is the clearest signal that the key is fine and the account has no plan.