---
title: "Caller"
description: "who is calling, as the auth gateway made it"
section: concepts
address: /concepts/caller
contract: 0476e35e6e275db5
---

# Caller

who is calling, as the auth gateway made it

[figure: Caller is a view at none scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | view |
| scope | none |
| key | made for each request and never stored |
| store | none |
| family | kernel |



## Fields


| field | type | required | note |
|---|---|---|---|
| `kind` | `one of a user \| our agent \| an outside agent \| the platform's own work \| the crawler` | yes |  |
| `acts_for` | `id` | no | the user acted for |
| `came_in_through` | `one of a session \| a key \| a run` | yes |  |
| `client` | `id` | no |  |
| `access_scopes` | [AccessScope](/concepts/accessscope) | yes | on the token |
| `signed_in_strength` | `one of password \| passkey \| second factor` | no |  |
| `signed_in_at` | `time` | no |  |
| `tenant` | `id` | yes | the token is bound to one tenant |
| `grants` | [GrantRef](/concepts/grantref) | yes | after all three narrowings, for the place asked |
| `run` | `id` | no |  |



## Routes that use it
- [`/v1/session/whoami`](/reference/session/whoami) returns it
- [`/v1/session/sign_in`](/reference/session/sign_in) returns it
