Skip to content

Get Executing User Node

Utils/User

Gets the user context of the current execution. Returns a typed struct containing sub (user ID), role, permissions, attributes, and details of the calling principal. Use 'Break Struct' to access individual fields.

utils_user_get_executing_userstd
Inputs0
Outputs2
Security exposure8/10
Packagestd

Ratings

Scores range from 0 to 10. Higher values mean more impact, exposure, or operational weight.

SecurityAttack surface and exposure impact.
8/10High
PrivacyPotential sensitivity of processed data.
6/10Medium
PerformanceRuntime or resource pressure.
10/10High
GovernancePolicy, audit, or compliance impact.
8/10High
ReliabilityOperational stability considerations.
10/10High
CostExternal or compute cost impact.
10/10High

Input Pins

0

No input pins.

Output Pins

2

User Context

Struct
user_context

The complete user execution context. Use 'Break Struct' to access: sub, role (with id, name, permissions, attributes), isTechnicalUser, keyId, principal, originAppId, onBehalfOf

UserExecutionContextUserExecutionContext7 fields
substringrequired

User subject identifier (e.g., OIDC sub claim) Empty for technical users (API keys, app connections)

roleanyOf (2)

Role information

variant 1RoleContextvariant

Role context containing role metadata and permissions

idstringrequired

Role ID

namestringrequired

Role name

permissionsinteger:int64required

Role permissions as a bitfield

format int64
attributesArray<string>required

Custom attributes assigned to the role

itemsstringarray item
customAttributesMap<string, string>

Custom key-value attributes that can be set by users

default {}
*stringmap value
variant 2nullvariant
isTechnicalUserboolean

Whether this is a technical user (API key, app connection) rather than a human user

default false
keyIdstring | null

For API keys, the key identifier. Never set for other principals.

default null
principalExecutionPrincipal

Which kind of principal started the run.

default "user"
variant 1constvariant

A human account: an OIDC session or a personal access token.

const "user"
variant 2constvariant

An app-scoped API key. Carries no human subject of its own.

const "apiKey"
variant 3constvariant

Another app calling through an app connection.

const "connectedApp"
originAppIdstring | null

For `ConnectedApp`, the app that made the call.

onBehalfOfstring | null

Subject the calling principal reported as the initiator: the API key's creator, or the user an app connection passed through. Attribution only — the run must never treat it as an identity it may act as.

Schema enforced

Has User

Boolean
has_user

True if user context is available

Node Info

Internal name
utils_user_get_executing_user
Category
Utils/User