lhc whoami
Show which user the configured API key belongs to, and which role it has.
lhc whoami [--profile <name>]
Every other lhc command acts as this user. When a command fails with 403,
whoami is the fastest way to tell an insufficient role apart from a genuine
error.
Output
lhc whoami
EMAIL ID NAME ROLE
----- -- ---- ----
admin@acme.example.com 5ca29f9f-2cb8-447b-a714-0402d68c7c4c Dimitri admin
lhc whoami --json
{
"email": "admin@acme.example.com",
"id": "5ca29f9f-2cb8-447b-a714-0402d68c7c4c",
"name": "Dimitri",
"role": "admin"
}
| Field | Description |
|---|---|
id | User ID |
email | Email address the key belongs to |
name | Display name |
role | One of user, builder, admin |
Roles
| Role | What it can do |
|---|---|
user | Consume existing assets: run analyses, read charts and dashboards |
builder | Everything a user can, plus build and manage datasources, models, the semantic layer, charts and dashboards |
admin | Full administrative control, including users, groups and instance settings |
Checking which instance you are on
whoami answers who, not where. To confirm the target instance, combine it
with the profile list and instance info:
lhc configure list # which profiles exist, and their endpoints
lhc whoami --profile prod # who you are on that instance
lhc instance info --profile prod
This matters when several profiles are configured: a command without
--profile uses LHC_PROFILE, or default if that is unset.
note
whoami reads the identity behind the key. It does not reveal the key itself,
and the key is never printed in any output.
Errors
| Status | Meaning |
|---|---|
401 | The API key is invalid, was revoked, or the account is disabled |
403 | Authentication reached the instance but was rejected — typically the seat gate on a cancelled or over-allocated subscription |
See Authentication & Setup for creating and rotating keys.