API overview¶
The e10s API is JSON over HTTPS. Every vendor resource lives under your organization.
Base path¶
The member key is the organization. The path does not name it.
Resource map¶
| Resource | Path prefix | Purpose |
|---|---|---|
| Features | …/features |
Catalog keys (flag | limit) |
| Plans | …/plans |
Catalog + custom bundles (grants) |
| Subscribers | …/subscribers |
Your customers |
| Subscriptions | …/subscribers/{subscriber_id}/subscriptions |
Plan assignment |
| Overrides | …/subscribers/{subscriber_id}/overrides |
Per-feature exceptions |
| Entitlements | …/subscribers/{subscriber_id}/entitlements |
Check + list effective access |
Organizations, members, service accounts, API keys, invites, and the webhook URL are managed at e10s.io. See Console. Outbound events: Webhooks.
Conventions¶
- JSON request and response bodies
- You address features and plans by
key, subscribers by the id you chose - Timestamps in ISO-8601 UTC
- Snake_case field names
- Shared error shape — see Errors
- Paginated lists — see Lists
Auth summary¶
| Operations | Credential | Header | Scope |
|---|---|---|---|
| POST check, GET entitlements | Service account member API key | X-API-Key |
check (default mint) |
| Features, plans | Same | X-API-Key |
catalog:read / catalog:write |
| Subscribers, subscriptions, overrides | Same | X-API-Key |
subscribers:read / subscribers:write |
| Webhook URL | Console session | — | org:read / org:write |
Incoming webhook POSTs use HMAC, not X-API-Key. Details: Authentication, Webhooks.