openapi: 3.2.0 info: title: Wego User API description: 'Wego''s travel API: places, flights, hotels and fares. Please see https://docs.wego.com for more details.' version: 0.19.0 servers: - url: https://api.wego.com security: - oauth2: [] - bearerAuth: [] tags: - name: User description: The authenticated caller. `getCurrentUser` returns the identity behind the bearer token (the CLI's `wego whoami`). paths: /v1/user: get: operationId: getCurrentUser tags: - User summary: Get the authenticated user description: Returns the caller's own identity, read from the verified access-token claims. Profile fields (email, name, country) appear only when the token carries them. responses: '200': description: The caller's identity claims. content: application/json: schema: type: object properties: sub: type: string description: 'The token subject (the JWT `sub`): the user''s email, which auth.wego.com uses as the stable user identifier.' scope: description: Space-separated OAuth scopes granted to the token. type: string email: description: The user's email address, when the token carries it. type: string name: description: The user's full display name, when present. type: string first_name: description: The user's given name, when present. type: string last_name: description: The user's family name, when present. type: string country_code: description: The user's market country code, when present (id_token-sourced; usually absent on the access token). type: string uid: description: 'The AS''s own numeric user id. Published as `string | number` because that is what it is: it arrives as a number today, and a `string`-only declaration would be a promise the API does not keep.' anyOf: - type: string - type: number principal_name: description: The auth server's principal name for the user, when present. type: string required: - sub '401': description: Missing or invalid bearer token. content: application/problem+json: schema: $ref: '#/components/schemas/Problem' '429': description: Rate limit exceeded; retry after the `Retry-After` seconds. content: application/problem+json: schema: $ref: '#/components/schemas/Problem' components: schemas: Problem: type: object description: RFC 9457 Problem Details, served as application/problem+json. required: - type - title - status - instance - code - trace_id properties: type: type: string format: uri description: Problem-type URI. `about:blank` for now (no semantics beyond the status); real type URIs follow once the public host is fixed. title: type: string description: Fixed human summary, the same across a `code`. status: type: integer description: The HTTP status code, repeated as a JSON number. detail: type: string description: Instance-specific human explanation of this failure. instance: type: string description: The request path this occurrence happened on. code: type: string enum: - validation_failed - invalid_token - insufficient_scope - not_found - rates_require_hotel_search - rate_limited - bad_gateway - upstream_unavailable - upstream_rate_limited - internal_error description: Stable machine token from a closed enum – the field an agent branches on. trace_id: type: string description: Correlates this response to its logs; also returned in the `x-trace-id` response header. securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Wego auth server access token, sent as `Authorization: Bearer ` (RFC 6750).' oauth2: type: oauth2 description: OAuth2 authorization-code flow (PKCE supported) against the Wego auth server. flows: authorizationCode: authorizationUrl: https://auth.wego.com/user-auth/v2/users/oauth/authorize tokenUrl: https://auth.wego.com/user-auth/v2/users/oauth/token x-scalar-client-id: 251815b9647317f4895122fd4924b7d44541d8fcc27be528435e3ad9bbf7e1ee x-usePkce: SHA-256 scopes: openid: OpenID Connect sign-in. profile: Basic profile claims. users: User identity for the API. x-default-scopes: - openid - profile - users