List the entries in the caller's profile tray
Reads profiles.v_userlinks filtered to the signed-in user. Returns a BARE ARRAY — there is no envelope, no total and no pagination, and no query parameter is read. Two fields are rewritten on the way out: a blank name becomes a label built from profile_m.new_company_text, and the type kyb_flow becomes profile_m.kyb_flow_text. Both are resolved for the request's Accept-Language, and in every shipped bundle both resolve to a frontend translation token rather than to end-user text — see the field descriptions. Always an array; [] when the user is linked to nothing.
Authorization
bearerAuth In: header
Header Parameters
Chooses the language of the two rewritten fields. It does not filter or reorder rows — only name and type change.
Parsing is not RFC 7231: config.GetLanguage takes the FIRST member of the list and keeps the part before the region subtag, so "de-CH,de" is read as "de" and q-values are never weighed. A q-value on that first member is NOT stripped either — "de;q=0.9" is read as the language "de;q=0.9", which matches nothing.
An absent or empty header falls back to the configured default language (app-config, "en" when unset). Anything else that is not one of the seeded languages — cz, de, en, fr, it in every shipped bundle — resolves to no template at all and leaves the rewritten fields empty.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/profile/tray"[
{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"name": "string",
"type": "string",
"status": "string",
"route": "/company"
}
]{
"status": 401,
"message": "Unauthorized",
"code": "common.unauthorized",
"class": "business"
}{
"status": 403,
"message": "No access to the record",
"code": "common.rbac_no_rec_access",
"class": "business"
}{
"status": 429,
"message": "Rate limit for 203.0.113.7 to 6f1c9a52-3a5e-4f2d-9d61-7c0b0a4e5f88 exceeded.",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Failed to run query",
"code": "db_m.failed_to_run_query",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Counts users, accounts and payments for each requested company. customer_ids IS EFFECTIVELY REQUIRED. It reads like an optional filter, but omitting it does NOT mean "every company in my tray": the authorisation step returns an empty set for an empty request, so the answer is 200 {"data": []}. Send the ids you want. IDS YOU MAY NOT SEE ARE DROPPED SILENTLY. The requested ids are intersected with the companies in the caller's own tray — entries whose type is exactly "company" — and anything not in that set is removed with no error and no marker. A response can therefore be shorter than the request, and the only way to tell which ids survived is to compare customer_id values. A per-company failure does NOT fail the request: that row comes back with status "error" and an opaque code while the others still carry metrics. Companies are counted concurrently, at most six at a time.
Description
Next Page