Get User Avatar
Authorization
bearerAuth In: header
Path Parameters
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/users/497f6eca-6276-4993-bfeb-53cbbbba6f08/avatar"{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"owner_id": "8826ee2e-7933-4665-aef2-2393f84a0d05",
"avatar_type": "string",
"upload_id": "f2ef591b-135b-46fa-a604-3d4fda5bfbfb",
"content": "string",
"metadata": {},
"active": true
}{
"status": 400,
"message": "Invalid user input",
"code": "users_m.invalid_user_input",
"class": "validation"
}{
"status": 401,
"message": "Unauthorized",
"code": "common.unauthorized",
"class": "business"
}{
"status": 403,
"message": "No access to the record",
"code": "common.rbac_no_rec_access",
"class": "business"
}{
"status": 429,
"message": "Rate limit for 203.0.113.10 to 456e1234-e89b-12d3-a456-426614174111 exceeded.",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Internal server error",
"code": "common.server_error",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}AUTHENTICATED BY X-API-Key, not by a bearer token. auth.APIKeyMiddleware REPLACES the usual chain on this route, so there is no user context, no RBAC check and no licence check — and the refusals are common.api_key_required / common.invalid_api_key rather than common.unauthorized / common.rbac_no_rec_access. An OPTIONS request skips the key check entirely. Submit the registration code. A code checked against an address nobody registered, or one already confirmed, is refused exactly as a wrong code is — `400 otp_m.otp_invalid`, `400 otp_m.otp_expired`, or `429 otp_m.cooling_period_active` once the attempt budget is spent — so the refusal names no account state. Attempts against a credential the caller does not own never reach that credential's budget.
Next Page