Know who is visiting your protected site, right from your functions
By Steven Van ·
Functions and Edge Functions receive the signed-in user's ID, email, and access expiry on private projects and sites with team login.
Protected sites can now pass the visitor’s identity to application code without requiring a second login. On private projects and sites protected with team login, Netlify makes the signed-in user available to Functions and Edge Functions through context.user.
Read the visitor’s identity
The context.user object includes the user’s ID, email address, and access expiry. The announcement includes a /whoami function that returns those fields as JSON, or responds with a 401 Unauthorized status when context.user is absent.
Netlify verifies the visitor at the edge and passes their identity to the function. Because context.user comes from Netlify rather than the request, visitors cannot impersonate someone else by supplying their own headers.
Build on the existing team login
Functions can use that identity to show personal data in internal dashboards, record who triggered an action in audit logs, track approvals, or apply per-person settings, permissions, and feature access.