Get session context
Returns the bounded context of the authenticated local session: only the server-derived local organization, authentication class, canonical granted scopes and local mode. It never returns tokens, token hashes, principal identifiers, vault references or session identifiers.
/v1/session-contextAuthorizationBearer token · headerrequiredincludestringexpiresAt adds the token's own expiry to the response; organizationName adds the organization's display name. Comma-separated or repeated.
Authenticated local session context
modeanyrequiredauthenticationClassanyrequiredlocal_static_tokenmachine_sessionorganizationIdstringrequiredShow propertiesHide properties
stringstringscopesstring[]requireddeploymentModeanyrequiredOperator-facing deployment mode: fixture_demo/authenticated_sandbox in local_alpha, approved_production in production, degraded whenever live readiness fails regardless of mode.
fixture_demoauthenticated_sandboxapproved_productiondegradedroleanyrequiredThe resolved principal's organization role; null for a resolver that never set one.
owneradminmemberviewernullexpiresAtstring<date-time> | nullPresent only for ?include=expiresAt: the presenting token's own expiry (ISO 8601 UTC), or null when it has none.
organizationNamestring | nullPresent only for ?include=organizationName: the organization's display name, or null when the gateway could not read one.
Authentication required
local-product:read scope required
Method not allowed
Session context unavailable