Skip to main content
Version: Next

lhc whoami

Show which user the configured API key belongs to, and which role it has.

lhc whoami [--profile <name>]

Every other lhc command acts as this user. When a command fails with 403, whoami is the fastest way to tell an insufficient role apart from a genuine error.

Output​

lhc whoami
EMAIL                    ID                                    NAME     ROLE
----- -- ---- ----
admin@acme.example.com 5ca29f9f-2cb8-447b-a714-0402d68c7c4c Dimitri admin
lhc whoami --json
{
"email": "admin@acme.example.com",
"id": "5ca29f9f-2cb8-447b-a714-0402d68c7c4c",
"name": "Dimitri",
"role": "admin"
}
FieldDescription
idUser ID
emailEmail address the key belongs to
nameDisplay name
roleOne of user, builder, admin

Roles​

RoleWhat it can do
userConsume existing assets: run analyses, read charts and dashboards
builderEverything a user can, plus build and manage datasources, models, the semantic layer, charts and dashboards
adminFull administrative control, including users, groups and instance settings

Checking which instance you are on​

whoami answers who, not where. To confirm the target instance, combine it with the profile list and instance info:

lhc configure list          # which profiles exist, and their endpoints
lhc whoami --profile prod # who you are on that instance
lhc instance info --profile prod

This matters when several profiles are configured: a command without --profile uses LHC_PROFILE, or default if that is unset.

note

whoami reads the identity behind the key. It does not reveal the key itself, and the key is never printed in any output.

Errors​

StatusMeaning
401The API key is invalid, was revoked, or the account is disabled
403Authentication reached the instance but was rejected — typically the seat gate on a cancelled or over-allocated subscription

See Authentication & Setup for creating and rotating keys.