Skip to content

Entitlements API

Base: /org/subscribers/{subscriber_id}/entitlements

Auth: a member API key with scope check (X-API-Key). POST check and GET entitlements are the same resolution, different shape. How the value is decided: Resolution order. How to use them: Check access.

Check feature

POST /org/subscribers/{subscriber_id}/entitlements/check
{
  "feature": "sso"
}
Field Required Rules
feature yes Feature key string

200 — always when subscriber exists (even if not entitled)

Flag

{
  "feature": "sso",
  "kind": "flag",
  "allowed": true,
  "source": "plan"
}

Limit

{
  "feature": "seats",
  "kind": "limit",
  "limit": 10,
  "source": "plan"
}

Unlimited:

{
  "feature": "seats",
  "kind": "limit",
  "limit": null,
  "source": "override"
}

Not entitled (no grant):

{
  "feature": "seats",
  "kind": "limit",
  "limit": 0,
  "source": "none"
}
Field Meaning
kind flag or limit (from catalog)
allowed Flag only
limit Limit only: integer ≥ 0, or null = unlimited
source override | plan | none

Note

For flags: deny via override → allowed: false, source: override.
Deny with no override/plan → allowed: false, source: none.
For limits: missing grant → limit: 0, source: none. Explicit plan limit: 0 → source: plan.

404 — subscriber not found

422 — missing/invalid body, or feature is not a key in your catalog

429 — GET entitlements and POST check share 100 requests per second per organization.

List entitlements

GET /org/subscribers/{subscriber_id}/entitlements

Same check scope as POST check.

By default, returns only features that are entitled:

  • flag with allowed: true
  • limit with limit === null or limit > 0

Pass ?all=true to include every catalog feature with full effective values.

200 (default)

{
  "features": [
    {
      "feature": "sso",
      "kind": "flag",
      "allowed": true,
      "source": "plan"
    },
    {
      "feature": "seats",
      "kind": "limit",
      "limit": 10,
      "source": "plan"
    }
  ]
}

404 — subscriber not found

429 — same 100/sec per organization bucket as POST check.