<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Netlify Changelog - Edge-functions</title><description>Resources for developers building with and expanding the Netlify platform</description><link>https://www.netlify.com/</link><item><title>Know who is visiting your protected site, right from your functions</title><link>https://www.netlify.com/changelog/2026-10-07-context-user-in-functions/</link><guid isPermaLink="true">https://www.netlify.com/changelog/2026-10-07-context-user-in-functions/</guid><description>On private projects and sites protected with Netlify team login, your Netlify Functions and Edge Functions can now see who is making the request. The signed-in Netlify user is available as context.user, with their user ID, email address, and when their access expires.

This function returns the signed-in user&apos;s ID, email address, and access expiry as JSON at /whoami, and responds with a 401 when context.user isn&apos;t set:

// netlify/functions/whoami.ts
import type { Config, Context } from &amp;#39;@netlify/functions&amp;#39;

export default async (req: Request, context: Context) =&amp;gt; {
  if (!context.user) {
    return new Response(&amp;#39;Unauthorized&amp;#39;, { status: 401 })
  }

  return Response.json({
    id: context.user.id,
    email: context.user.email,
    expiresAt: context.user.expiresAt.toISOString(),
  })
}

export const config: Config = { path: &amp;#39;/whoami&amp;#39; }

Previously, protecting a site meant Netlify checked who could visit, but your code couldn&apos;t tell who they were. Knowing who&apos;s on the other end meant adding a second login of your own on top.

Now Netlify verifies the visitor at the edge and passes their identity to your code. Because context.user comes from Netlify and not from the request, a visitor can&apos;t impersonate someone else by sending their own headers.

With context.user, you can build on the login your team already uses. Examples like:

&lt;ul&gt;
&lt;li&gt;Internal dashboards and admin tools that show each person their own data&lt;/li&gt;
&lt;li&gt;Audit logs that record who made a change or triggered an action&lt;/li&gt;
&lt;li&gt;Approval and review workflows that know who approved what&lt;/li&gt;
&lt;li&gt;Per-person settings, permissions, or feature access inside an internal app&lt;/li&gt;
&lt;/ul&gt;
Learn more in the Netlify documentation:

&lt;ul&gt;
&lt;li&gt;context.user in Netlify Functions

&lt;/li&gt;
&lt;li&gt;context.user in Edge Functions

&lt;/li&gt;
&lt;li&gt;Private projects

&lt;/li&gt;
&lt;li&gt;Team login protection

&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate></item></channel></rss>