> ## Documentation Index
> Fetch the complete documentation index at: https://docs.skyvexsoftware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify token and return profile

> Validates the Bearer token and returns the pilot's profile. Use this on app launch to confirm the stored token is still valid and refresh cached profile fields. The response shape matches `POST /pilot/login` minus the `token` field.



## OpenAPI

````yaml /api-reference/openapi.json get /pilot/verify
openapi: 3.1.0
info:
  title: Stratos Core API
  version: 0.3.0
  summary: >-
    The Stratos VA API contract — auth, pilot identity, reference data, and the
    flight lifecycle.
  description: >-
    The contract every Stratos desktop client speaks to a virtual airline's crew
    system. The reference implementation is the open-source [stratos-core-api
    phpVMS 7 module](https://github.com/SkyvexSoftware/stratos-core-api), but
    any backend can implement these endpoints — they're framework-agnostic.


    Every endpoint in this reference is documented under `/api/stratos` — that's
    the convention the phpVMS module uses, and what we recommend for
    consistency. You're free to mount the surface anywhere you like; the desktop
    client just uses whatever base URL is set in your Stratos airline
    configuration.


    ## Authentication


    Most endpoints require a Bearer token — the pilot's API key, obtained via
    `POST /pilot/login` or your OAuth flow. Send as `Authorization: Bearer
    <api_key>` on every authenticated request.


    Public (no token): `GET /` and `POST /pilot/login`.


    ## Conventions


    - JSON, `snake_case` field names.

    - Distances in nautical miles, weights in pounds, flight times in decimal
    hours (unless suffixed `_minutes`).

    - Coordinates are decimal degrees (WGS84).

    - CORS is wide-open; the client preflights every method.
servers:
  - url: '{baseUrl}'
    description: >-
      Your VA's Stratos API base — set this to whatever URL the Stratos client
      is pointed at, including any path prefix you chose to mount the surface
      under.
    variables:
      baseUrl:
        default: https://crew.example.com/api/stratos
        description: >-
          Full base URL including the path prefix (no trailing slash). The
          phpVMS reference module mounts under `/api/stratos`; if you mounted
          yours somewhere else (e.g. `https://api.youva.com/stratos/v1`), use
          that.
security:
  - BearerAuth: []
tags:
  - name: Pilot
    description: Authentication, profile, and career statistics.
  - name: Reference Data
    description: Static lookup data the client renders in UI.
  - name: Flights
    description: >-
      Browse the schedule, manage bids, and run the active-flight lifecycle
      (start, update, complete, cancel).
paths:
  /pilot/verify:
    get:
      tags:
        - Pilot
      summary: Verify token and return profile
      description: >-
        Validates the Bearer token and returns the pilot's profile. Use this on
        app launch to confirm the stored token is still valid and refresh cached
        profile fields. The response shape matches `POST /pilot/login` minus the
        `token` field.
      operationId: pilotVerify
      responses:
        '200':
          description: Token is valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PilotSession'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    PilotSession:
      type: object
      required:
        - db_id
        - pilot_id
        - first_name
        - last_name
        - email
        - rank
        - rank_image
        - rank_level
        - avatar
      properties:
        db_id:
          type: integer
          description: Internal database ID. Stable across pilot ID changes.
        pilot_id:
          type: string
          description: >-
            Display pilot ID (airline ICAO + zero-padded number per VA setting).
            Example: `QFA0001`.
          example: QFA0001
        first_name:
          type: string
        last_name:
          type: string
        email:
          type: string
          format: email
        rank:
          type: string
          description: Human-readable rank name.
          example: First Officer
        rank_image:
          type: string
          format: uri
          nullable: true
          description: >-
            URL to the pilot's rank insignia image. The Stratos client renders
            this as a rank badge in the dashboard and pilot-centre plugins.
            Return `null` if the rank has no image. The phpVMS reference
            resolves this from the rank's `image_url` column (relative paths are
            wrapped in your phpVMS public URL automatically).
        rank_level:
          type: integer
          description: >-
            Numeric rank tier (0-based) — index into the rank ladder ordered
            ascending by required hours. Used by the Stratos client for any
            rank-gated UI behaviour. The phpVMS reference computes this as the
            count of ranks with fewer required hours than the pilot's current
            rank, matching phpVMS's own auto-promote ordering.
        avatar:
          type: string
          format: uri
          description: Absolute URL to the pilot's avatar image.
    Error:
      type: object
      properties:
        error:
          type: string
        success:
          type: boolean
        message:
          type: string
  responses:
    Unauthorized:
      description: Missing or invalid Bearer token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            error: Invalid Token
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        The pilot's API key, obtained via `POST /pilot/login` or your OAuth
        flow. Send as `Authorization: Bearer <api_key>` on every authenticated
        request.

````