> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ticktock.bet/llms.txt
> Use this file to discover all available pages before exploring further.

# whoami

> Tenant identity — granted scopes, sport allowlist, rate limit

## What it returns

Introspection on the calling tenant — who you are, what your key can do, and how often you can call. **First request you should make on any new key.**

```json theme={null}
{
  "data": {
    "tenant_id": "uuid",
    "name": "Acme Sportsbook",
    "scopes": ["cs2:matches:list", "cs2:markets:read", ...],
    "sport_allowlist": ["cs2"],
    "rate_limit_rpm": 600
  }
}
```

If `scopes` is shorter than expected, contact your account manager.

## Required scope

Any valid key. No specific scope needed.

## Example

```bash theme={null}
curl -H "X-API-Key: $TT_KEY" \
  https://ticktock.bet/v1/whoami
```


## OpenAPI

````yaml openapi/cs2-api.json GET /v1/whoami
openapi: 3.1.0
info:
  title: TickTock B2B API
  description: >-
    Unified CS2 API (``/cs2/v1/*``) plus sport-agnostic ``/v1/*`` meta
    endpoints. Tenant-authenticated via ``X-API-Key`` or ``x-access-token``
    header (REST), or ``api_key`` query parameter (WebSocket). Field visibility
    is gated by per-key scopes — see ``docs/CS2_API_REFERENCE.md`` for the
    catalog and migration.
  version: 1.0.0
servers:
  - url: https://ticktock.bet
    description: Production (same-origin proxy)
  - url: https://feed.ticktock.bet
    description: Production (B2B subdomain)
security: []
paths:
  /v1/whoami:
    get:
      tags:
        - Meta
      summary: Tenant identity introspection
      description: >-
        Returns the calling tenant's identity, the scopes attached to the API
        key on this request, the sport namespaces it can call, and its rate
        limit. Useful for clients to verify their subscription and discover what
        they're allowed to do.


        Supports both JSON (default) and XML via ``Accept: application/xml`` or
        the ``/v1/whoami.xml`` sibling URL. The XML body is byte-compatible with
        the AMQP ``<bookmaker_details>`` envelope.
      operationId: whoami_v1_whoami_get
      parameters:
        - name: accept
          in: header
          required: false
          schema:
            type: string
            default: application/json
            title: Accept
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                title: Response Whoami V1 Whoami Get
              example:
                data:
                  tenant_id: 0e1f…
                  name: Acme Sportsbook
                  scopes:
                    - cs2:matches:list
                    - cs2:matches:read
                    - cs2:markets:read
                    - cs2:markets:settlements
                    - cs2:stream:matches
                    - cs2:stream:markets
                  sport_allowlist:
                    - cs2
                  rate_limit_rpm: 600
                  allowed_games:
                    - cs2
            application/xml: {}
        '401':
          description: >-
            Missing API key. Pass either `X-API-Key: <your-key>` or
            `$x$access-token: <your-key>` on REST calls (or `?api_key=` on
            WebSocket handshakes).
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                    description: Human-readable error message.
                required:
                  - detail
              example:
                detail: Missing X-API-Key or $x$access-token header
        '403':
          description: >-
            API key authenticated but lacks the scope required for this
            endpoint, or the path's sport is not in the key's `sport_allowlist`.
            Use `GET /v1/whoami` to inspect the granted scope set.
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                    description: Human-readable error message.
                required:
                  - detail
              example:
                detail: >-
                  Required scope 'cs2:matches:detail' is not granted to this API
                  key. Contact your account manager to extend the key's scopes.
        '422':
          description: >-
            Validation error — a query/path parameter failed validation. The
            body lists the offending fields.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
              example:
                detail:
                  - type: enum
                    loc:
                      - query
                      - time_filter
                    msg: 'Input should be one of: 3m, 6m, 1y, all'
                    input: 2w
        '429':
          description: >-
            Tenant rate limit exceeded. Default is 600 req/min per tenant;
            configurable per contract. WebSocket connections are not
            rate-limited at the request layer.
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                    description: Human-readable error message.
                required:
                  - detail
              example:
                detail: Rate limit exceeded (600 req/min)
          headers:
            Retry-After:
              description: Seconds to wait before retrying.
              schema:
                type: integer
                example: 30
      security:
        - XAPIKeyHeader: []
        - XAccessTokenHeader: []
        - UOFAccessTokenHeader: []
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    XAPIKeyHeader:
      type: apiKey
      description: Tenant API key issued during onboarding
      in: header
      name: X-API-Key
    XAccessTokenHeader:
      type: apiKey
      description: UOF-standard alias for the tenant API key
      in: header
      name: x-access-token
    UOFAccessTokenHeader:
      type: apiKey
      description: Deprecated alias for x-access-token (backward compatibility)
      in: header
      name: $x$access-token

````