MobiariDocs

Get my stores and permissions

GET
/me/access

Every store the caller can reach (as owner of the store or its tenant, or through a role), with the tenant it belongs to, the caller's roles there and the effective permission codes. Load it once per session to build a store switcher and to hide what the user cannot do; the server enforces the same permissions on every call.

Authorization

bearer_auth
AuthorizationBearer <token>

Authorization: Bearer <token>. Either a session access token from POST /auth/login (refresh it with POST /auth/refresh) or a store API token (mobi_st_…). A store API token works only for the store it was issued in, and can do at most what its issuing user can there, narrowed to the scopes it was issued with.

In: header

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/me/access"
{
  "stores": [
    {
      "currency": "BRL",
      "is_owner": true,
      "logo_url": "string",
      "permissions": [
        "string"
      ],
      "roles": [
        {
          "color": "string",
          "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
          "is_system": true,
          "name": "string"
        }
      ],
      "store_id": "7fe87115-950c-4ae8-bd7e-970406bc9ac0",
      "store_name": "string",
      "store_slug": "string",
      "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
      "tenant_name": "string",
      "timezone": "America/Sao_Paulo"
    }
  ],
  "user_id": "a169451c-8525-4352-b8ca-070dd449a1a5"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}