> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lmrp.uk/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the current user

> **Permission:** None beyond being signed in.

**Access:** Browser session only.

The signed-in account, its linked identities, staff membership, and the permissions in effect for this request. Use it to decide what to show; every endpoint still enforces its own permission.



## OpenAPI

````yaml /api-reference/openapi.json get /me
openapi: 3.1.0
info:
  title: Argus API
  version: 0.1.0
  summary: The HTTP API behind the Argus web application.
  description: >-
    Argus is the operations platform for the UK London Mayfair ER:LC community.
    This document describes the API its own web application uses.


    **This is an internal application API.** It is not a stable public API:
    paths, fields and behaviour can change with any release, there is no
    versioning, and browser requests are tied to the application's own origin.
    Scoped service credentials exist for the community's own integrations.


    All paths are relative to `/api` on the deployment's origin. Responses are
    JSON, never cacheable, and carry an `X-Request-Id` header.
servers:
  - url: http://localhost:3000/api
    description: Local development
  - url: '{origin}/api'
    description: A deployment. `origin` is that deployment's `APP_URL`.
    variables:
      origin:
        default: https://argus.example.org
        description: The application's public origin, with no trailing slash.
security: []
tags:
  - name: Authentication
    description: >-
      Discord sign-in, Roblox account linking, the current user, and temporary
      Developer Access.
  - name: CAD Incidents
    description: >-
      Control's incidents: creation, editing, closure, and dispatching units to
      them.
  - name: CAD Units
    description: Control's view of operational units and their crew.
  - name: CAD Calls
    description: Incoming calls and how they become, or join, incidents.
  - name: CAD Events
    description: The append-only operational history.
  - name: MDT
    description: >-
      Self-service for the people crewing a unit: booking on and off, joining a
      unit, and changing its status.
  - name: Civilians
    description: 'The civilian portal: a member''s own characters, licences and vehicles.'
  - name: PNC Lookup
    description: >-
      Searching people and vehicles, full records, record history and official
      vehicle status.
  - name: PNC Licences
    description: Official changes to driving licences.
  - name: PNC Records
    description: Official records attached to people.
  - name: PNC Warrants
    description: Warrants and their lifecycle.
  - name: PNC Markers
    description: Markers and BOLOs on people and vehicles.
  - name: Staff
    description: Staff profiles and role membership.
  - name: Shifts
    description: Staff shifts.
  - name: Sessions
    description: Operational roleplay sessions.
  - name: Moderation
    description: Warnings, kicks and bans, with their delivery state.
  - name: Audit
    description: The append-only audit log.
  - name: Administration
    description: Accounts, roles and service credentials.
  - name: ERLC
    x-displayName: ER:LC
    description: Live data from the ER:LC private server.
paths:
  /me:
    get:
      tags:
        - Authentication
      summary: Get the current user
      description: >-
        **Permission:** None beyond being signed in.


        **Access:** Browser session only.


        The signed-in account, its linked identities, staff membership, and the
        permissions in effect for this request. Use it to decide what to show;
        every endpoint still enforces its own permission.
      operationId: getCurrentUser
      responses:
        '200':
          description: Success.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/CurrentUser'
                required:
                  - data
              example:
                data:
                  id: cmg5x1k2a0000l508a1b2c3d4
                  displayName: Olivia Officer
                  status: ACTIVE
                  discord:
                    id: '254781093445672960'
                    username: olivia.officer
                    avatar: null
                    userId: cmg5x1k2a0000l508a1b2c3d4
                  roblox:
                    id: '4821093375'
                    userId: cmg5x1k2a0000l508a1b2c3d4
                    username: OliviaOfficer
                    status: VERIFIED
                    method: roblox-oauth
                    linkedAt: '2026-10-06T19:30:00.000Z'
                  staff:
                    id: cmg5x1k2a0001l5089f8e7d6c
                    userId: cmg5x1k2a0000l508a1b2c3d4
                    active: true
                    createdAt: '2026-10-06T19:30:00.000Z'
                    updatedAt: '2026-10-06T19:30:00.000Z'
                    roles:
                      - staffId: cmg5x1k2a0001l5089f8e7d6c
                        roleId: cmg5x0aaa0003l508role0001
                        role:
                          id: cmg5x0aaa0003l508role0001
                          name: Police officer
                  developerAccess: false
                  permissions:
                    - cad.unit.self
                    - civilians.create
                    - civilians.manage_own
                    - pnc.licences.manage
                    - pnc.markers.manage
                    - pnc.records.manage
                    - pnc.vehicles.manage
                    - pnc.view
                    - pnc.warrants.manage
        '401':
          $ref: '#/components/responses/Unauthenticated'
        '403':
          description: |-
            `USER_REQUIRED`: the caller is a service credential.

            `ACCOUNT_DISABLED`: the account is suspended or disabled.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error:
                  code: USER_REQUIRED
                  message: A signed-in user is required.
                requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
        '429':
          $ref: '#/components/responses/RateLimited'
        default:
          $ref: '#/components/responses/UnexpectedError'
      security:
        - sessionCookie: []
components:
  headers:
    RequestId:
      schema:
        type: string
        format: uuid
      description: Identifies this request in server logs.
    RetryAfter:
      schema:
        type: integer
        minimum: 1
      description: Seconds to wait before trying again.
  schemas:
    CurrentUser:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/Id'
        displayName:
          type: string
        status:
          $ref: '#/components/schemas/AccountStatus'
        discord:
          anyOf:
            - $ref: '#/components/schemas/DiscordAccount'
            - type: 'null'
        roblox:
          anyOf:
            - $ref: '#/components/schemas/RobloxAccount'
            - type: 'null'
        staff:
          anyOf:
            - allOf:
                - $ref: '#/components/schemas/StaffProfile'
                - type: object
                  properties:
                    roles:
                      type: array
                      items:
                        $ref: '#/components/schemas/RoleAssignment'
                  required:
                    - roles
            - type: 'null'
        developerAccess:
          type: boolean
          description: Whether temporary Developer Access is in effect for this session.
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/Permission'
          description: Effective permissions, sorted.
      required:
        - id
        - displayName
        - status
        - discord
        - roblox
        - staff
        - developerAccess
        - permissions
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable machine-readable code.
            message:
              type: string
            details:
              description: >-
                Present on some errors. Validation failures carry an array of
                `{path, message}`; ER:LC failures carry `{availability:
                "unavailable"}`.
          required:
            - code
            - message
        requestId:
          type: string
          format: uuid
          description: >-
            Also sent as the `X-Request-Id` header. Quote it when reporting a
            problem.
      required:
        - error
        - requestId
    Id:
      type: string
      minLength: 1
      maxLength: 64
      pattern: ^[a-zA-Z0-9_-]+$
      description: Argus record identifier.
    AccountStatus:
      type: string
      enum:
        - ACTIVE
        - SUSPENDED
        - DISABLED
    DiscordAccount:
      type: object
      properties:
        id:
          type: string
          description: Discord user ID.
        userId:
          $ref: '#/components/schemas/Id'
        username:
          type: string
        avatar:
          type:
            - string
            - 'null'
      required:
        - id
        - userId
        - username
        - avatar
    RobloxAccount:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/RobloxId'
        userId:
          $ref: '#/components/schemas/Id'
        username:
          type: string
        status:
          type: string
        method:
          type: string
        linkedAt:
          type: string
          format: date-time
      required:
        - id
        - userId
        - username
        - status
        - method
        - linkedAt
    StaffProfile:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/Id'
        userId:
          $ref: '#/components/schemas/Id'
        active:
          type: boolean
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
      required:
        - id
        - userId
        - active
        - createdAt
        - updatedAt
    RoleAssignment:
      type: object
      properties:
        staffId:
          $ref: '#/components/schemas/Id'
        roleId:
          $ref: '#/components/schemas/Id'
        role:
          type: object
          properties:
            id:
              $ref: '#/components/schemas/Id'
            name:
              type: string
          required:
            - id
            - name
      required:
        - staffId
        - roleId
        - role
    Permission:
      type: string
      enum:
        - cad.unit.self
        - cad.view
        - cad.dispatch
        - cad.incidents.create
        - cad.incidents.manage
        - cad.units.manage
        - cad.calls.manage
        - server.view
        - players.view
        - players.lookup
        - sessions.view
        - sessions.manage
        - shifts.view
        - shifts.manage
        - staff.view
        - staff.manage
        - moderation.view
        - moderation.warn
        - moderation.kick
        - moderation.ban
        - moderation.history
        - audit.view
        - admin.manage
        - civilians.create
        - civilians.manage_own
        - civilians.manage
        - pnc.view
        - pnc.records.manage
        - pnc.licences.manage
        - pnc.warrants.manage
        - pnc.markers.manage
        - pnc.vehicles.manage
      description: An Argus permission key.
    RobloxId:
      type: string
      pattern: ^[1-9][0-9]{0,19}$
      description: Roblox user ID, as a string.
  responses:
    Unauthenticated:
      description: >-
        `UNAUTHENTICATED`: no session cookie, or an invalid, expired or revoked
        service credential.


        `SESSION_EXPIRED`: the session has ended.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHENTICATED
              message: Sign in to continue.
            requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
    RateLimited:
      description: >-
        `RATE_LIMITED`: more than 180 reads or 60 writes in a minute for this
        caller.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: RATE_LIMITED
              message: Too many requests.
            requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
    UnexpectedError:
      description: >-
        Any other failure, in the same error envelope: `INTERNAL_ERROR` (500),
        `METHOD_NOT_ALLOWED` (405), `BODY_TOO_LARGE` (413, over 16 KiB) or
        `UNSUPPORTED_MEDIA_TYPE` (415, body not sent as `application/json`).
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INTERNAL_ERROR
              message: The request could not be completed.
            requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
  securitySchemes:
    sessionCookie:
      type: apiKey
      in: cookie
      name: __Host-argus-session
      description: >-
        The opaque session cookie set by Discord sign-in. Named `argus-session`
        outside production. HttpOnly, so scripts cannot read it; same-origin
        requests send it automatically. Requests other than GET must also carry
        an `Origin` header equal to the application's own origin.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.