Get the scopes this workspace may grant
curl --request GET \
--url https://app.sahlfinancial.com/api/v1/api-keys/capabilities \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.sahlfinancial.com/api/v1/api-keys/capabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/api-keys/capabilities"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"kyc_partner": false,
"allowed_scopes": [],
"identity_audience": null
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Get the scopes this workspace may grant
Who can call it: tenant_admin, tenant_api_manager or platform_admin.
kyc:* scopes are offered only to workspaces enabled for the Partner KYC API.
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
Get the scopes this workspace may grant
curl --request GET \
--url https://app.sahlfinancial.com/api/v1/api-keys/capabilities \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.sahlfinancial.com/api/v1/api-keys/capabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/api-keys/capabilities"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"kyc_partner": false,
"allowed_scopes": [],
"identity_audience": null
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Authorizations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.