メインコンテンツへスキップ

validate

dci validate

Returns the domain, email, and effective permissions of the current API user. Callable by any authenticated token, regardless of its own permissions.

Authentication vs. access

dci login proves authentication; dci validate confirms both identity and access under the active customer context, so run it after switching contexts or when a command fails with PERMISSION_DENIED. dci status shows the local session state without calling the API.

Examples

# Who am I — the domain and email the API resolves your credentials to.
dci validate
A one-row table with `domain` and `email`. An authentication or permission error means the cached login or `DCI_API_KEY` is not accepted for the active customer context.
# Check access under another customer context before switching to it.
dci validate --customer-context acme.com
# As JSON, for a CI preflight step.
dci validate --output json

Output

OK - The domain and email of the API user returned.

By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.

FieldTypeDescription
domainstring
emailstring
permissionsarray of stringThe caller's own effective permission names (e.g. "CloudAnalyticsReadOnly"), not opaque permission IDs. Empty for a DoiT employee token, which is not scoped to a fixed permission set.
Raw JSON schema
{
"type": "object",
"description": "A response confirming caller's domain and email.",
"properties": {
"domain": {
"type": "string"
},
"email": {
"type": "string"
},
"permissions": {
"type": "array",
"description": "The caller's own effective permission names (e.g. \"CloudAnalyticsReadOnly\"), not opaque permission IDs. Empty for a DoiT employee token, which is not scoped to a fixed permission set.",
"items": {
"type": "string"
}
}
}
}

Errors

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP status to exit code mapping
HTTP statusExit codeError codeMeaning
40030VALIDATION_ERRORThe arguments or request body were rejected. Review the command's flags and payload.
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.