Endpoint categories

API version 2026-09-21

Download OpenAPI YAML

API reference

Explore every Runtime API and Management API endpoint generated from the published OpenAPI document. Each operation includes parameters, request and response schemas, and an Example Value.

Generated from OpenAPI 3.1.0 (no try-it console)

Example Values are illustrative values generated from OpenAPI types and constraints. They are not valid IDs, tokens, or secrets.

Endpoints

90

53 paths

Server URL

https://usakey.jp

Authentication

See each operation

The Management API uses API keys. Runtime API operations use device signatures when required.

Read Product app integration (Runtime API) for product authentication and External integration (Management API) for API key and webhook operations before integrating.

Runtime API

Runtime bootstrap

2 operations

Fetch signing keys and signed server time.

GET /runtime/v1/products/{product_id}/trust-bundle Fetch the signing-key trust bundle

Fetch the root-authorized signing keys used to verify signatures for a product.

Authentication
None
Required scope
—
Operation ID
runtime_v1_products_trust_bundle

Parameters

NameLocationRequiredType and description
product_id Path Required

Example Value

"product_id_aaaaaaaaaaaaaaaaaaaa"

Responses

200

Success

Trust bundle

application/json

Example Value

{
  "data": {
    "bundle": {},
    "root_signature": "example-token"
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/time Obtain signed server time

Obtain signed server time containing the client nonce for detecting local clock tampering.

Authentication
None
Required scope
—
Operation ID
runtime_v1_time_create

Request body

Required
application/json

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "sdk_version": "string"
}

Responses

200

Success

Product-key-signed response envelope

application/json

Example Value

{
  "data": "string",
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Runtime API

Runtime activation

8 operations

Register devices and continuously verify license state.

POST /runtime/v1/activations/{activation_id}/heartbeat Refresh device activation and certificate

Send a heartbeat from an activated device to refresh license state and its device certificate.

Authentication
deviceProof
Required scope
—
Operation ID
runtime_v1_activations_heartbeat

Parameters

NameLocationRequiredType and description
activation_id Path Required

Example Value

"activation_id_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Activation Header Required

Example Value

"x_usakey_activation_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Timestamp Header Required
integer

Example Value

1
X-Usakey-Nonce Header Required
string Minimum length: 22 Maximum length: 255

Example Value

"stringxxxxxxxxxxxxxxxx"
X-Usakey-Signature Header Required
string Maximum length: 1024

Example Value

"example-token"

Request body

Required
application/json

Example Value

{
  "machine_info": {
    "os": "string",
    "arch": "string"
  }
}

Responses

200

Success

Current license state and refreshed certificate

application/json

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "license_status": "active",
    "certificate": "string",
    "next_heartbeat_in": 10,
    "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The license was revoked (LICENSE_REVOKED) or has expired (LICENSE_EXPIRED), the device-risk policy blocked the activation or the license, or the named-user assignment is no longer active. License state is reported before activation state, so a device of a revoked license receives LICENSE_REVOKED rather than ACTIVATION_DEACTIVATED. An expired license keeps its activations, so the same activation_id works again after the expiry is extended and the license resumed. LICENSE_REVOKED and LICENSE_EXPIRED count toward the short burst windows but not toward the monthly Runtime API allowance. A suspended license is not an error; it returns 200 with license_status suspended.

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
410

Gone

Resource is no longer active

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

Unmanaged offline perpetual licenses do not use heartbeat, or full machine_info is required because the digest changed, no full baseline exists, or the last full baseline is older than 24 hours

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/activations/{activation_id}/sealed-file-keys Receive a sealed file's key for this device

Send a sealed file's header and, if the license may use the file, receive its per-file data key wrapped again to this device's key. The file itself is never sent.

Sends the header of a sealed file (docs/security/sealed-files.md). If the license may use the file, the per-file data key that the vendor wrapped to the product sealing key is opened on the server and wrapped again with HPKE to this activation's P-256 KEM public key. The file itself never reaches Usakey. The device caches the result, so this is called once per file and device.

Authentication
deviceProof
Required scope
—
Operation ID
runtime_v1_activations_sealed_file_keys

Parameters

NameLocationRequiredType and description
activation_id Path Required

Example Value

"activation_id_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Activation Header Required

Example Value

"x_usakey_activation_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Timestamp Header Required
integer

Example Value

1
X-Usakey-Nonce Header Required
string Minimum length: 22 Maximum length: 255

Example Value

"stringxxxxxxxxxxxxxxxx"
X-Usakey-Signature Header Required
string Maximum length: 1024

Example Value

"example-token"

Request body

Required
application/json

Example Value

{
  "header": "example_value",
  "sdk_version": "string"
}

Responses

200

Success

The data key wrapped to this device's KEM public key

application/json

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "file_id": "esNxn3TKNIsd_Dyi2XYojA",
    "header_sha256": "f7511808a1669a5481adebe399a96ad043d29ebb887207743368c3fb812717e5",
    "enc": "BC1G-oCCtQBTqm4VEolqWH6MHHbpugqlixdHLXLURww-71zLlbPAaperQqYpqsHIyF9bJ66JOqwcEaZ1yHqSNPI",
    "wrapped_key": "j4LNTalkfJFXswg_u9NXmazh7FZQHrAs4iqPQNp0hHCsdQIZWcS3AOpEkYp2mape"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The license was revoked (LICENSE_REVOKED), has expired (LICENSE_EXPIRED) or is suspended (LICENSE_SUSPENDED; unlike heartbeat, a suspended license receives no key), the named-user assignment is no longer active, the workspace plan does not include sealed files (PLAN_ENTITLEMENT_REQUIRED with details.entitlement sealed_files), or the file names an entitlement that is not true for this license (SEALED_FILE_ENTITLEMENT_REQUIRED with details.entitlement).

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
410

Gone

Resource is no longer active

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

The header is not a valid sealed-file header, was sealed for another product or with an unknown, retired-for-deletion or compromised key, or its data key cannot be opened, or the activation's KEM key is not a P-256 key (SEALED_FILE_INVALID).

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/activations Bind a license to a device key

Bind a license key to a device public key and issue a signed license certificate.

Authentication
None
Required scope
—
Operation ID
runtime_v1_activations_create

Parameters

NameLocationRequiredType and description
Idempotency-Key Header Required
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Request body

Required
application/json

Example Value

{
  "license_key": "string",
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "device_signing_public_key": "string",
  "device_kem_public_key": "string",
  "device_proof": "string",
  "machine_signals": {
    "property": "string"
  },
  "machine_info": {
    "os": "string",
    "arch": "string"
  },
  "app_version": "string",
  "sdk_version": "string",
  "request_id": "01K5QWERTY1234567890ABCDEFG",
  "client_time": 1,
  "named_user_token": "Example name",
  "nonce": "stringxxxxxxxxxxxxxxxx"
}

Responses

201

Created

Device activation and signed license certificate

application/json

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "certificate": "string",
    "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

The license requires device-bound offline package activation

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /runtime/v1/activations/{activation_id} Deactivate the current device

Use the device credentials to remove its own activation.

Authentication
deviceProof
Required scope
—
Operation ID
runtime_v1_activations_destroy

Parameters

NameLocationRequiredType and description
activation_id Path Required

Example Value

"activation_id_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Activation Header Required

Example Value

"x_usakey_activation_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Timestamp Header Required
integer

Example Value

1
X-Usakey-Nonce Header Required
string Minimum length: 22 Maximum length: 255

Example Value

"stringxxxxxxxxxxxxxxxx"
X-Usakey-Signature Header Required
string Maximum length: 1024

Example Value

"example-token"

Responses

200

Success

Product-key-signed response envelope

application/json

Example Value

{
  "data": "string",
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
410

Gone

Resource is no longer active

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/email-verifications Start email license verification

For a named-user license, sends a six-digit code to the address the vendor registered for a local-ID license user. A code is sent only when the address matches, but the response is the same 202 either way, so registered addresses cannot be discovered. The code is valid for 10 minutes and 5 attempts, and a new start for the same product, license key, and address invalidates the previous one. Not counted toward the monthly Runtime API quota.

Sends a six-digit verification code to the email address that the software vendor registered for a local-ID license user, so the app can obtain a named-user token for activation. The response has the same shape and status whether or not the address matched, and a code is sent only when it matched: the license key is active, the policy is named-user, the workspace has email license verification (Personal or higher), exactly one active local-ID license user (not linked to an OIDC connection) has this address, and that user has a current assignment on this license. A new start for the same product, license key, and address invalidates the previous one. The code expires in 10 minutes and allows 5 attempts. These requests do not count toward the monthly Runtime API quota; the activation that follows does.

Authentication
None
Required scope
—
Operation ID
runtime_v1_email_verifications_create

Request body

Required
application/json

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "license_key": "string",
  "email": "developer@example.com",
  "device_signing_public_key": "string",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "locale": "ja",
  "sdk_version": "string"
}

Responses

202

Accepted

Verification started. A code was sent only if the address matched; the response does not say whether it did

application/json

Example Value

{
  "data": {
    "verification_id": "verification_id_aaaaaaaaaaaaaaaaaaaa",
    "expires_at": "2026-09-21T00:00:00Z",
    "resend_after_sec": 1,
    "code_length": 1
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/email-verifications/{verification_id}/confirm Confirm the code and get an activation token

Checks the code with the same device signing key that started the verification and returns a token (valid for 5 minutes) to pass as named_user_token to POST /runtime/v1/activations. License users with two-factor authentication also send an authenticator app code or a recovery code (second_factor_code). Without it, the response is 401 TWO_FACTOR_REQUIRED and the emailed code stays valid. Each mistake uses one attempt; when they run out or 10 minutes pass, start again.

Checks the six-digit code with the same device signing public key that started the verification and returns a named-user token for POST /runtime/v1/activations (named_user_token). The token is valid for 5 minutes. For users with two-factor authentication, also send second_factor_code: an authenticator app code, a recovery code, or the approval code obtained by opening the link in the verification email and approving with a passkey. The passkey approval code is valid only for this verification, for up to 10 minutes, and can be used once. Without the second factor, the response is 401 TWO_FACTOR_REQUIRED and the emailed code stays valid, so send both again. Each wrong code, wrong device key, or wrong second-factor code uses one of 5 attempts; after that, or after 10 minutes, start again. An unknown or unmatched verification returns the same errors as a wrong code.

Authentication
None
Required scope
—
Operation ID
runtime_v1_email_verifications_confirm

Parameters

NameLocationRequiredType and description
verification_id Path Required

Example Value

"verification_id_aaaaaaaaaaaaaaaaaaaa"

Request body

Required
application/json

Example Value

{
  "code": "123456",
  "second_factor_code": "string",
  "device_signing_public_key": "string",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "sdk_version": "string"
}

Responses

200

Success

Named-user token for activation

application/json

Example Value

{
  "data": {
    "named_user_token": "Example name",
    "expires_at": "2026-09-21T00:00:00Z"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

EMAIL_VERIFICATION_CODE_INVALID (wrong code or device key), TWO_FACTOR_REQUIRED (the emailed code is correct and still valid; send an authenticator app code, a passkey approval code from the emailed link, or a recovery code with it), or TWO_FACTOR_INVALID. details.remaining_attempts is the number of attempts left

application/json

Example Value

{
  "error": {
    "code": "EMAIL_VERIFICATION_CODE_INVALID",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "details": {
      "remaining_attempts": 0
    }
  }
}
403

Forbidden

TWO_FACTOR_LOCKED (the vendor must unlock two-factor authentication for this user), NAMED_USER_ASSIGNMENT_UNAVAILABLE (the assignment, user, license, or plan changed after the start), or PLAN_ENTITLEMENT_REQUIRED

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
410

Gone

EMAIL_VERIFICATION_EXPIRED. The verification expired, was used, was replaced by a newer start, ran out of attempts, or is unknown. Start a new verification

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/trial-verifications Start a trial with email verification

Sends a six-digit code to the address the user entered so the app can start a trial of the product on this device. A code is sent only when the product accepts trial sign-ups (the vendor chose a trial policy and its 24-hour limit has room) and the workspace has the trial entitlement; otherwise the response is the same 202. Whether the address already had a trial is reported at confirmation. Sending to the same address is spaced by 120 seconds and limited to 3 per hour and 5 per day per product, and 10 per day across products. Not counted toward the monthly Runtime API quota.

Sends a six-digit code to the email address the user entered, so the app can start a trial of this product on this device. A code is sent only when the product accepts trial sign-ups (the vendor chose a trial policy for it and its 24-hour sign-up limit has room) and the workspace has the trial_licenses entitlement. Otherwise the response is the same 202 and nothing is sent. Whether the address or device already had a trial is not checked here; the confirmation reports it. Sending to the same address is spaced by 120 seconds and limited to 3 per hour and 5 per day per product, and 10 per day across all products. Not counted toward the monthly Runtime API quota.

Authentication
None
Required scope
—
Operation ID
runtime_v1_trial_verifications_create

Request body

Required
application/json

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "email": "developer@example.com",
  "device_signing_public_key": "string",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "locale": "ja",
  "sdk_version": "string"
}

Responses

202

Accepted

Verification started. A code was sent only if the product accepts trial sign-ups; the response does not say whether it does

application/json

Example Value

{
  "data": {
    "verification_id": "verification_id_aaaaaaaaaaaaaaaaaaaa",
    "expires_at": "2026-09-21T00:00:00Z",
    "resend_after_sec": 1,
    "code_length": 1
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/trial-verifications/{verification_id}/confirm Confirm the code, issue a trial license, and activate this device

Checks the code and the address from the start request, issues a trial license with the policy the vendor chose, and activates this device. The response is the same signed activation data plus license_id; no license key is returned. The body has the activation fields (without license_key and product_id) plus code and email, and device_proof is signed after the prefix Usakey-Trial-Proof-v1 and a newline. If the same address has an active trial, this device joins it. If the address or device key had a trial in the last 365 days, the response is 403 TRIAL_ALREADY_USED. The activation counts once toward the monthly quota.

Checks the code and the address from the start request, then issues a trial license with the policy the vendor chose and activates this device in the same request. The response is the same signed activation as POST /runtime/v1/activations plus license_id; no license key is returned. The body has the activation fields (without license_key and product_id) plus code and email, and device_proof signs it after the prefix Usakey-Trial-Proof-v1 and a newline instead of the activation prefix. If the same address already has an active trial of this product, this device joins that trial. If the address or the device key had a trial of this product in the last 365 days, the response is 403 TRIAL_ALREADY_USED. The activation counts once toward the monthly Runtime API quota.

Authentication
None
Required scope
—
Operation ID
runtime_v1_trial_verifications_confirm

Parameters

NameLocationRequiredType and description
verification_id Path Required

Example Value

"verification_id_aaaaaaaaaaaaaaaaaaaa"
Idempotency-Key Header Required
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Request body

Required
application/json

Example Value

{
  "code": "123456",
  "email": "developer@example.com",
  "device_signing_public_key": "string",
  "device_kem_public_key": "string",
  "device_proof": "string",
  "machine_signals": {
    "property": "string"
  },
  "machine_info": {
    "os": "string",
    "arch": "string"
  },
  "app_version": "string",
  "sdk_version": "string",
  "request_id": "01K5QWERTY1234567890ABCDEFG",
  "client_time": 1,
  "nonce": "stringxxxxxxxxxxxxxxxx"
}

Responses

201

Created

Trial license issued and device activated

application/json

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "certificate": "string",
    "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

EMAIL_VERIFICATION_CODE_INVALID (wrong code, address, or device key; details.remaining_attempts) or DEVICE_PROOF_INVALID

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

TRIAL_ALREADY_USED, TRIAL_ACTIVATION_INVALID (the product stopped accepting trial sign-ups or reached its 24-hour limit; details.reason), LICENSE_* or PLAN_ENTITLEMENT_REQUIRED

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

PLAN_QUOTA_EXCEEDED (the workspace trial allowance is full), MACHINE_LIMIT_REACHED, DEVICE_KEY_MISMATCH, or an idempotency conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
410

Gone

EMAIL_VERIFICATION_EXPIRED. Start a new verification

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

Full machine_info is required

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Runtime API

Runtime concurrent use

3 operations

Acquire, renew, and release concurrent-use seats.

POST /runtime/v1/leases/{lease_id}/heartbeat Renew a concurrent-use lease

Extend an acquired concurrent-use lease and retain its seat.

Authentication
deviceProof
Required scope
—
Operation ID
runtime_v1_leases_heartbeat

Parameters

NameLocationRequiredType and description
lease_id Path Required

Example Value

"lease_id_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Activation Header Required

Example Value

"x_usakey_activation_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Timestamp Header Required
integer

Example Value

1
X-Usakey-Nonce Header Required
string Minimum length: 22 Maximum length: 255

Example Value

"stringxxxxxxxxxxxxxxxx"
X-Usakey-Signature Header Required
string Maximum length: 1024

Example Value

"example-token"

Request body

Required
application/json

Example Value

{
  "instance_id": "01K5QWERTY1234567890ABCDEFG"
}

Responses

200

Success

Renewed concurrent-use lease

application/json

Example Value

{
  "data": {
    "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
    "instance_id": "01K5QWERTY1234567890ABCDEFG",
    "expires_at": 1,
    "heartbeat_in": 10
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
410

Gone

Resource is no longer active

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /runtime/v1/leases Acquire one concurrent-use seat

Acquire a single lease from the product's concurrent-use allowance.

Authentication
deviceProof
Required scope
—
Operation ID
runtime_v1_leases_create

Parameters

NameLocationRequiredType and description
X-Usakey-Activation Header Required

Example Value

"x_usakey_activation_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Timestamp Header Required
integer

Example Value

1
X-Usakey-Nonce Header Required
string Minimum length: 22 Maximum length: 255

Example Value

"stringxxxxxxxxxxxxxxxx"
X-Usakey-Signature Header Required
string Maximum length: 1024

Example Value

"example-token"

Request body

Required
application/json

Example Value

{
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "instance_id": "01K5QWERTY1234567890ABCDEFG"
}

Responses

201

Created

Acquired concurrent-use lease

application/json

Example Value

{
  "data": {
    "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
    "instance_id": "01K5QWERTY1234567890ABCDEFG",
    "expires_at": 1,
    "heartbeat_in": 10
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /runtime/v1/leases/{lease_id} Release a concurrent-use lease

Return a lease after use and free the concurrent-use seat.

Authentication
deviceProof
Required scope
—
Operation ID
runtime_v1_leases_destroy

Parameters

NameLocationRequiredType and description
lease_id Path Required

Example Value

"lease_id_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Activation Header Required

Example Value

"x_usakey_activation_aaaaaaaaaaaaaaaaaaaa"
X-Usakey-Timestamp Header Required
integer

Example Value

1
X-Usakey-Nonce Header Required
string Minimum length: 22 Maximum length: 255

Example Value

"stringxxxxxxxxxxxxxxxx"
X-Usakey-Signature Header Required
string Maximum length: 1024

Example Value

"example-token"

Request body

Required
application/json

Example Value

{
  "instance_id": "01K5QWERTY1234567890ABCDEFG"
}

Responses

200

Success

Released concurrent-use lease

application/json

Example Value

{
  "data": {
    "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "released"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
413

Request too large

The runtime request body exceeds the route-specific byte limit

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Products

13 operations

Manage products and their signing-key state.

GET /mgmt/v1/products List products

Retrieve a list of products. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_products_index

Parameters

NameLocationRequiredType and description
limit Query Optional
integer Minimum: 1 Maximum: 200

Example Value

50
cursor Query Optional
string

Example Value

"string"

Responses

200

Success

Successful Product operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "code": "string",
      "description": "Example description",
      "environment": "live",
      "status": "active",
      "trust_bundle_sequence": 1,
      "signing_status": "pending",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z",
      "version": 1
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/products Create a product

Create a product. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
products:write
Operation ID
mgmt_v1_products_create

Parameters

NameLocationRequiredType and description
Idempotency-Key Header Required
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "code": "string",
  "description": "Example description",
  "environment": "string"
}

Responses

201

Created

Successful Product operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "code": "string",
    "description": "Example description",
    "environment": "live",
    "status": "active",
    "trust_bundle_sequence": 1,
    "signing_status": "pending",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z",
    "version": 1
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/products/{id} Retrieve a product

Retrieve the current state and configuration of the specified a product.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_products_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Successful Product operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "code": "string",
    "description": "Example description",
    "environment": "live",
    "status": "active",
    "trust_bundle_sequence": 1,
    "signing_status": "pending",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z",
    "version": 1
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/products/{id} Update a product

Update the specified a product. See the request Schema for fields that can be changed.

Authentication
managementApiKey
Required scope
products:write
Operation ID
mgmt_v1_products_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "code": "string",
  "description": "Example description",
  "environment": "string"
}

Responses

200

Success

Successful Product operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "code": "string",
    "description": "Example description",
    "environment": "live",
    "status": "active",
    "trust_bundle_sequence": 1,
    "signing_status": "pending",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z",
    "version": 1
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/products/{id} Delete a product

Delete or disable the specified a product. Review the response codes and constraints before calling this operation.

Send the product's version in If-Match to archive it only if it has not changed since it was read. A stale If-Match returns 409 VERSION_CONFLICT and nothing is changed.

Authentication
managementApiKey
Required scope
products:write
Operation ID
mgmt_v1_products_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Responses

204

No content

Archived

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/products/{id}/integration-config Get a product's integration settings

Get the same usakey.config.json the Console downloads. Save it in the product repository during development; product apps must not fetch it over the network at runtime.

Returns the product's usakey.config.json, the same file the Console downloads. Save it in the product repository at development time; product apps must not fetch it at runtime. Archived products return 409 PRODUCT_ARCHIVED.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_products_integration_config

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Integration settings for the product app

application/json

Example Value

{
  "data": {
    "file_name": "Example name",
    "content": "string",
    "config": {
      "usakey_config_version": 1,
      "generated_at": "2026-09-21T00:00:00Z",
      "bundle_version": "string",
      "environment": "live",
      "api_url": "https://example.com/resource",
      "product": {
        "id": "id_aaaaaaaaaaaaaaaaaaaa",
        "name": "Example name"
      },
      "trust_anchor": {
        "signing_mode": "string",
        "key_id": "01K5QWERTY1234567890ABCDEFG",
        "trust_bundle_url": "https://example.com/resource",
        "minimum_trust_bundle_sequence": 1,
        "root_public_key": "string",
        "development_root_public_key": "string",
        "public_key_unavailable_reason": "string",
        "signing_keys_pending_reason": "string"
      },
      "entitlements": [
        {
          "name": "Example name",
          "type": "boolean",
          "policies": [
            "string"
          ]
        }
      ],
      "license_key_delivery": "manual",
      "stripe_license_claim_url": "https://example.com/resource"
    }
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/products/{product_id}/browser-runtime Retrieve a product

Retrieve the current state and configuration of the specified a product.

Returns the product browser Runtime settings: enabled, allowed_origins and version. Disabled by default. Archived products return 409 PRODUCT_ARCHIVED. Existing Product responses are unchanged. This endpoint does not allow cross-origin browser requests.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_product_browser_runtimes_show

Parameters

NameLocationRequiredType and description
product_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Browser Runtime settings of the product

application/json

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "enabled": true,
    "allowed_origins": [
      "string"
    ],
    "version": 0
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/products/{product_id}/browser-runtime Update a product

Update the specified a product. See the request Schema for fields that can be changed.

Changes only the supplied settings using Console validation. enabled must be a boolean. allowed_origins replaces the entire list of at most 20 exact HTTPS origins; test products also allow HTTP loopback origins. Wildcards, null, paths, query, fragment and userinfo are rejected. Disabling preserves the list. Clearing an enabled list fails validation. Invalid values return 422 VALIDATION_FAILED. If-Match checks the product version including origin-only changes (409 VERSION_CONFLICT). Archived products return 409 PRODUCT_ARCHIVED. Changes are audited as product.updated. Runtime OPTIONS consumes no Runtime allowance; these Management API calls use normal Management API quotas.

Authentication
managementApiKey
Required scope
products:write
Operation ID
mgmt_v1_product_browser_runtimes_update

Parameters

NameLocationRequiredType and description
product_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Request body

Required
application/json

Example Value

{
  "enabled": true,
  "allowed_origins": [
    "string"
  ]
}

Responses

200

Success

Browser Runtime settings of the product

application/json

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "enabled": true,
    "allowed_origins": [
      "string"
    ],
    "version": 0
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/products/{product_id}/trial-signup Get a product's trial sign-up settings

Returns whether the product accepts trials that the product app starts with email verification (POST /runtime/v1/trial-verifications): the trial policy used, the 24-hour limit and the current status. These are the settings on the product's edit page in the Console; the product response itself does not include them. Archived products return 409 PRODUCT_ARCHIVED.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_product_trial_signups_show

Parameters

NameLocationRequiredType and description
product_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Trial sign-up settings of the product

application/json

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "policy_id": "01K5QWERTY1234567890ABCDEFG",
    "daily_limit": 1,
    "status": "accepting",
    "started_last_24_hours": 0,
    "version": 0
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/products/{product_id}/trial-signup Change a product's trial sign-up settings

Changes the trial sign-up settings with the same checks as the Console. Only the fields sent are changed. Choosing or replacing the policy needs a plan with the trial_licenses entitlement (403 PLAN_ENTITLEMENT_REQUIRED); setting policy_id to null to stop accepting trials, and changing only daily_limit, are always allowed. Invalid values return 422 VALIDATION_FAILED with details.errors keyed by policy_id or daily_limit. Archived products return 409 PRODUCT_ARCHIVED. A change is recorded in the audit log as product.updated. Idempotency-Key is not used; sending the same body again gives the same result.

Authentication
managementApiKey
Required scope
products:write
Operation ID
mgmt_v1_product_trial_signups_update

Parameters

NameLocationRequiredType and description
product_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Request body

Required
application/json

Example Value

{
  "policy_id": "01K5QWERTY1234567890ABCDEFG",
  "daily_limit": 1
}

Responses

200

Success

Trial sign-up settings of the product

application/json

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "policy_id": "01K5QWERTY1234567890ABCDEFG",
    "daily_limit": 1,
    "status": "accepting",
    "started_last_24_hours": 0,
    "version": 0
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/products/{product_id}/sealed-files Get the sealed-file status and public key of a product

Returns whether the product seals files for licensed devices (docs/security/sealed-files.md) and, once enabled, its public sealing key. current_key.sealing_key is the one-line key the sealing tool (usakey-seal) takes; it is not a secret. status is enabled, disabled, not_entitled (the plan does not include sealed_files; an existing key stays but devices receive no file keys), or unavailable (this environment does not offer sealed files yet). Archived products return 409 PRODUCT_ARCHIVED.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_product_sealed_files_show

Parameters

NameLocationRequiredType and description
product_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Sealed-file status of the product

application/json

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "enabled",
    "current_key": {
      "key_id": "key_seal_0123456789abcdef0123",
      "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
      "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
      "created_at": "2026-09-21T00:00:00Z"
    }
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/products/{product_id}/sealed-files Turn on sealed files for a product

Turns sealed files on for the product. It needs a plan with the sealed_files entitlement (403 PLAN_ENTITLEMENT_REQUIRED) and an environment that offers sealed files (409 SEALED_FILES_UNAVAILABLE). The response is 200 with status enabled and current_key; 503 SEALED_FILES_KEY_UNAVAILABLE (retryable) means the sealing key could not be reached for a moment. Sending it again changes nothing. The first enablement is recorded in the audit log as product.sealed_files_enabled. There is no request body and Idempotency-Key is not used. Sealed files cannot be turned off here: files already distributed would stop opening.

Authentication
managementApiKey
Required scope
products:write
Operation ID
mgmt_v1_product_sealed_files_create

Parameters

NameLocationRequiredType and description
product_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Sealed files are enabled and the key exists

application/json

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "enabled",
    "current_key": {
      "key_id": "key_seal_0123456789abcdef0123",
      "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
      "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
      "created_at": "2026-09-21T00:00:00Z"
    }
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/stripe-integration Get the Stripe integration status

Get whether the workspace's own Stripe integration exists, its test or live mode, the license claim URL and the price-to-license mappings. The restricted key and signing secret are never returned.

The workspace's own Stripe integration as product apps use it, with its price-to-license mappings. The restricted API key and the webhook signing secret are never returned.

Authentication
managementApiKey
Required scope
products:read
Operation ID
mgmt_v1_stripe_integrations_show

Responses

200

Success

Stripe integration status

application/json

Example Value

{
  "data": {
    "registered": true,
    "mode": "test",
    "status": "active",
    "secure_claims_required": true,
    "license_claim_url": "https://example.com/resource",
    "last_event": {
      "type": "string",
      "result": "string",
      "at": "2026-09-21T00:00:00Z"
    },
    "offerings": [
      {
        "id": "id_aaaaaaaaaaaaaaaaaaaa",
        "name": "Example name",
        "stripe_price_id": "01K5QWERTY1234567890ABCDEFG",
        "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
        "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa",
        "status": "active",
        "license_duration_days": 1
      }
    ]
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Policies

5 operations

Manage license usage rules.

GET /mgmt/v1/policies List policies

Retrieve a list of policies. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
policies:read
Operation ID
mgmt_v1_policies_index

Responses

200

Success

Successful Policy operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "version": 1,
      "license_type": "perpetual",
      "validation_mode": "string",
      "perpetual_mode": "managed",
      "heartbeat_required": true,
      "revocation_guarantee_sec": 0,
      "fail_mode": "string",
      "identity_mode": "string",
      "license_unit_limit": 1,
      "max_machines": 1,
      "max_concurrent": 1,
      "concurrency_unit": "string",
      "cert_ttl_sec": 1,
      "heartbeat_sec": 1,
      "lease_ttl_sec": 1,
      "lease_heartbeat_sec": 1,
      "network_grace_sec": 1,
      "fingerprint_profile": {},
      "renewal_authority": "string",
      "billing_cycle": "string",
      "trial_days": 1,
      "entitlements": {},
      "status": "active",
      "created_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/policies Create a policy

Create a policy. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
policies:write
Operation ID
mgmt_v1_policies_create

Parameters

NameLocationRequiredType and description
Idempotency-Key Header Required
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Request body

Required
application/json

Schema

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "license_type": "string",
  "validation_mode": "string",
  "fail_mode": "string",
  "max_machines": 1,
  "max_concurrent": 1,
  "concurrency_unit": "string",
  "identity_mode": "string",
  "license_unit_limit": 1,
  "cert_ttl_sec": 1,
  "heartbeat_sec": 1,
  "lease_ttl_sec": 1,
  "lease_heartbeat_sec": 1,
  "network_grace_sec": 1,
  "fingerprint_profile": "standard",
  "renewal_authority": "string",
  "billing_cycle": "string",
  "trial_days": 1,
  "entitlements": {}
}

Responses

201

Created

Successful Policy operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "version": 1,
    "license_type": "perpetual",
    "validation_mode": "string",
    "perpetual_mode": "managed",
    "heartbeat_required": true,
    "revocation_guarantee_sec": 0,
    "fail_mode": "string",
    "identity_mode": "string",
    "license_unit_limit": 1,
    "max_machines": 1,
    "max_concurrent": 1,
    "concurrency_unit": "string",
    "cert_ttl_sec": 1,
    "heartbeat_sec": 1,
    "lease_ttl_sec": 1,
    "lease_heartbeat_sec": 1,
    "network_grace_sec": 1,
    "fingerprint_profile": {},
    "renewal_authority": "string",
    "billing_cycle": "string",
    "trial_days": 1,
    "entitlements": {},
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/policies/{id} Retrieve a policy

Retrieve the current state and configuration of the specified a policy.

Authentication
managementApiKey
Required scope
policies:read
Operation ID
mgmt_v1_policies_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Successful Policy operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "version": 1,
    "license_type": "perpetual",
    "validation_mode": "string",
    "perpetual_mode": "managed",
    "heartbeat_required": true,
    "revocation_guarantee_sec": 0,
    "fail_mode": "string",
    "identity_mode": "string",
    "license_unit_limit": 1,
    "max_machines": 1,
    "max_concurrent": 1,
    "concurrency_unit": "string",
    "cert_ttl_sec": 1,
    "heartbeat_sec": 1,
    "lease_ttl_sec": 1,
    "lease_heartbeat_sec": 1,
    "network_grace_sec": 1,
    "fingerprint_profile": {},
    "renewal_authority": "string",
    "billing_cycle": "string",
    "trial_days": 1,
    "entitlements": {},
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/policies/{id} Update a policy

Update the specified a policy. See the request Schema for fields that can be changed.

A stale If-Match returns 409 VERSION_CONFLICT and nothing is changed; read the policy again to get the current ETag.

Authentication
managementApiKey
Required scope
policies:write
Operation ID
mgmt_v1_policies_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Request body

Required
application/json

Schema

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "license_type": "string",
  "validation_mode": "string",
  "fail_mode": "string",
  "max_machines": 1,
  "max_concurrent": 1,
  "concurrency_unit": "string",
  "identity_mode": "string",
  "license_unit_limit": 1,
  "cert_ttl_sec": 1,
  "heartbeat_sec": 1,
  "lease_ttl_sec": 1,
  "lease_heartbeat_sec": 1,
  "network_grace_sec": 1,
  "fingerprint_profile": "standard",
  "renewal_authority": "string",
  "billing_cycle": "string",
  "trial_days": 1,
  "entitlements": {}
}

Responses

200

Success

Successful Policy operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "version": 1,
    "license_type": "perpetual",
    "validation_mode": "string",
    "perpetual_mode": "managed",
    "heartbeat_required": true,
    "revocation_guarantee_sec": 0,
    "fail_mode": "string",
    "identity_mode": "string",
    "license_unit_limit": 1,
    "max_machines": 1,
    "max_concurrent": 1,
    "concurrency_unit": "string",
    "cert_ttl_sec": 1,
    "heartbeat_sec": 1,
    "lease_ttl_sec": 1,
    "lease_heartbeat_sec": 1,
    "network_grace_sec": 1,
    "fingerprint_profile": {},
    "renewal_authority": "string",
    "billing_cycle": "string",
    "trial_days": 1,
    "entitlements": {},
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/policies/{id} Delete a policy

Delete or disable the specified a policy. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
policies:write
Operation ID
mgmt_v1_policies_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

204

No content

Retired

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Customers and users

5 operations

Manage customers and the users associated with them.

GET /mgmt/v1/customers List customers

Retrieve a list of customers. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_customers_index

Responses

200

Success

Successful Customer operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "email": "developer@example.com",
      "external_ref": "string",
      "notes": "string",
      "status": "active",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/customers Create a customer

Create a customer. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_customers_create

Parameters

NameLocationRequiredType and description
Idempotency-Key Header Required
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "notes": "string"
}

Responses

201

Created

Successful Customer operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "notes": "string",
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/customers/{id} Retrieve a customer

Retrieve the current state and configuration of the specified a customer.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_customers_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Successful Customer operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "notes": "string",
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/customers/{id} Update a customer

Update the specified a customer. See the request Schema for fields that can be changed.

Customers are shared by the live and test environments. A test API key cannot change a customer who holds a live license (403 ENVIRONMENT_MISMATCH). A stale If-Match returns 409 VERSION_CONFLICT and nothing is changed; read the customer again to get the current ETag.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_customers_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "notes": "string"
}

Responses

200

Success

Successful Customer operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "notes": "string",
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/customers/{id} Delete a customer

Delete or disable the specified a customer. Review the response codes and constraints before calling this operation.

Customers are shared by the live and test environments. A test API key cannot archive a customer who holds a live license (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_customers_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

204

No content

Archived

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Licenses

7 operations

Issue, update, and assign licenses.

POST /mgmt/v1/licenses/{id}/offline-certificates Issue a device-bound offline license

Issue a signed offline license package that can only be used on the specified device.

Repeating an identical device request safely redelivers the existing package as a 200 ZIP while it remains valid for the same active device and assignment. If the previous package is no longer eligible, send a newly generated device request.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_licenses_offline_certificates

Parameters

NameLocationRequiredType and description
id Path Required

Example Value

"id_aaaaaaaaaaaaaaaaaaaa"

Request body

Required
application/json

Example Value

{
  "request": {
    "format": "usakey-offline-request-v1",
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "device_signing_public_key": "string",
    "device_kem_public_key": "p256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
    "device_proof": "string",
    "machine_info": {
      "os": "string",
      "arch": "string"
    },
    "nonce": "example_valuexxxxxxxxx",
    "generated_at": 1
  },
  "expires_at": "2026-09-21T00:00:00Z",
  "license_assignment_id": "license_assignment_id_aaaaaaaaaaaaaaaaaaaa"
}

Responses

200

Success

Device-bound offline license ZIP package

application/vnd.usakey.offline+zip

Schema

string binary

Example Value

"string"
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/licenses/{id}/convert-trial Convert a trial license

Convert a trial license to a full license with the same key.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_licenses_convert_trial

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "target_policy_id": "target_policy_id_aaaaaaaaaaaaaaaaaaaa",
  "expires_at": "2026-09-21T00:00:00Z",
  "entitlement_overrides": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful License operation

application/json

Example Value

{
  "data": {}
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/licenses List licenses

Retrieve a list of licenses. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
licenses:read
Operation ID
mgmt_v1_licenses_index

Parameters

NameLocationRequiredType and description
limit Query Optional
integer Minimum: 1 Maximum: 200

Example Value

50
cursor Query Optional
string

Example Value

"string"

Responses

200

Success

Successful License operation

application/json

Example Value

{
  "data": [
    {}
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/licenses Create a license

Create a license. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_licenses_create

Parameters

NameLocationRequiredType and description
Idempotency-Key Header Required
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Request body

Required
application/json

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa",
  "customer_id": "customer_id_aaaaaaaaaaaaaaaaaaaa",
  "license_type": "perpetual",
  "expires_at": "2026-09-21T00:00:00Z",
  "expiry": "2026-09-21T00:00:00Z",
  "renewal_authority": "external_billing",
  "max_machines": 0,
  "max_concurrent": 0,
  "entitlements": {},
  "metadata": {},
  "license_unit_limit_override": 1
}

Responses

201

Created

Successful License operation

application/json

Example Value

{
  "data": {}
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/licenses/{id} Retrieve a license

Retrieve the current state and configuration of the specified a license.

Authentication
managementApiKey
Required scope
licenses:read
Operation ID
mgmt_v1_licenses_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Successful License operation

application/json

Example Value

{
  "data": {}
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/licenses/{id} Update a license

Update the specified a license. See the request Schema for fields that can be changed.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_licenses_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
If-Match Header Optional
string

Example Value

"string"

Recommended for conditional updates. Products and licenses expose the concurrency token as version; GET policies/{id} and customers/{id} expose it in the ETag response header. Send the ETag unchanged. Policy version is the historical policy number and must not be used for this header. A value that no longer matches returns 409 VERSION_CONFLICT and nothing is changed.

Request body

Required
application/json

Example Value

{
  "expires_at": "2026-09-21T00:00:00Z",
  "expiry": "2026-09-21T00:00:00Z",
  "renewal_authority": "string",
  "max_machines_override": 1,
  "max_concurrent_override": 1,
  "license_unit_limit_override": 1,
  "entitlements": {},
  "metadata": {},
  "status_action": "active",
  "reason": "string"
}

Responses

200

Success

Successful License operation

application/json

Example Value

{
  "data": {}
}
409

Conflict

Idempotency, version, machine, concurrency, or pending product signing-key conflict

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/licenses/{id} Delete a license

Delete or disable the specified a license. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_licenses_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

204

No content

Revoked

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Activated devices

4 operations

Inspect and deactivate devices registered to licenses.

GET /mgmt/v1/licenses/{license_id}/activations List activated devices

Retrieve a list of activated devices. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
licenses:read
Operation ID
mgmt_v1_activations_index

Parameters

NameLocationRequiredType and description
license_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
id Path Required

Example Value

"id_aaaaaaaaaaaaaaaaaaaa"

Responses

200

Success

Successful Activation operation

application/json

Example Value

{
  "data": [
    {
      "id": "id_aaaaaaaaaaaaaaaaaaaa",
      "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "machine": {},
      "device_signing_key_thumbprint": "string",
      "first_seen_at": "2026-09-21T00:00:00Z",
      "last_seen_at": "2026-09-21T00:00:00Z",
      "deactivated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/activations/{id} Get a device activation

Get one device activation and its periodic check state: the last check, when the next is due, whether it is overdue, the certificate expiry, and the app and SDK versions.

One device activation with its periodic check state, to confirm that a product app registered and keeps checking in. Rejected runtime requests are not included here; list them with GET /mgmt/v1/runtime_events.

Authentication
managementApiKey
Required scope
licenses:read
Operation ID
mgmt_v1_activations_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Device activation and periodic check state

application/json

Example Value

{
  "data": {
    "id": "id_aaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "machine": {},
    "device_signing_key_thumbprint": "string",
    "first_seen_at": "2026-09-21T00:00:00Z",
    "last_seen_at": "2026-09-21T00:00:00Z",
    "deactivated_at": "2026-09-21T00:00:00Z",
    "activated_at": "2026-09-21T00:00:00Z",
    "last_heartbeat_at": "2026-09-21T00:00:00Z",
    "heartbeat_interval_sec": 1,
    "next_heartbeat_due": {
      "earliest": "2026-09-21T00:00:00Z",
      "latest": "2026-09-21T00:00:00Z"
    },
    "heartbeat_overdue": true,
    "certificate_expires_at": "2026-09-21T00:00:00Z",
    "app_version": "string",
    "sdk_version": "string"
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/activations/{id} Delete an activated device

Delete or disable the specified an activated device. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
activations:delete
Operation ID
mgmt_v1_activations_destroy

Parameters

NameLocationRequiredType and description
id Path Required

Example Value

"id_aaaaaaaaaaaaaaaaaaaa"

Responses

204

No content

Force deactivated

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/runtime_events List rejected device requests

List device activation, periodic check and concurrent-use lease requests that were rejected or failed in the last 7 days (a signature mismatch, clock skew and so on), oldest first. Rejections with the same target, operation and result code are counted per hour. Successful requests are not included. Use it to confirm that a product app is not being refused while you test an integration. Refused sealed-file key requests are not included (see the device's page in the Console).

Runtime API requests for device activation, periodic checks and concurrent-use leases that were rejected or failed in the last 7 days, oldest first, to confirm that a product app is not being refused (for example DEVICE_PROOF_INVALID or CLOCK_SKEW). Successful requests are not listed; GET /mgmt/v1/activations/{id} shows the last periodic check. Requests with the same target, operation and result code within one hour are counted on one entry, and when a workspace records many different entries within an hour, the rest are counted on an entry without its targets (details_omitted). Requests refused by rate limits (RATE_LIMITED) and requests that name no known product or device activation are not listed. Only the API key's environment is included. Refused sealed-file key requests are not included; the seller sees them on the device's page in the Console.

Authentication
managementApiKey
Required scope
licenses:read
Operation ID
mgmt_v1_runtime_events_index

Parameters

NameLocationRequiredType and description
license_id Query Optional

Example Value

"license_id_aaaaaaaaaaaaaaaaaaaa"

Only requests for this license.

activation_id Query Optional

Example Value

"activation_id_aaaaaaaaaaaaaaaaaaaa"

Only requests from this device activation.

product_id Query Optional

Example Value

"product_id_aaaaaaaaaaaaaaaaaaaa"

Only requests for this product.

since Query Optional
string date-time

Example Value

"2026-09-21T00:00:00Z"

Only entries whose last occurrence is at or after this date and time (ISO 8601).

limit Query Optional
integer Minimum: 1 Maximum: 200

Example Value

50
cursor Query Optional
string

Example Value

"string"

Responses

200

Success

Rejected or failed runtime requests

application/json

Example Value

{
  "data": [
    {
      "operation": "activation_create",
      "outcome": "rejected",
      "code": "DEVICE_PROOF_INVALID",
      "http_status": 400,
      "occurrences": 1,
      "first_occurred_at": "2026-09-21T00:00:00Z",
      "last_occurred_at": "2026-09-21T00:00:00Z",
      "last_request_id": "01K5QWERTY1234567890ABCDEFG",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
      "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
      "details_omitted": true
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Webhooks

5 operations

Manage webhook destinations and signing secrets.

GET /mgmt/v1/webhooks List webhook endpoints

Retrieve a list of webhook endpoints. See Parameters for available filters and pagination controls.

Signing secrets are never returned. The url of a Slack, Microsoft Teams or Google Chat destination is not returned, because that URL itself lets anyone post into the channel.

Authentication
managementApiKey
Required scope
webhooks:read
Operation ID
mgmt_v1_webhook_endpoints_index

Responses

200

Success

Successful Webhook operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "url": "https://example.com/resource",
      "events": [
        "string"
      ],
      "status": "active",
      "secret_rotation": {
        "scheduled": true,
        "activates_at": "2026-09-21T00:00:00Z"
      },
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/webhooks Create a webhook endpoint

Create a webhook endpoint. See Example Value for the request JSON and the resulting response.

Creates a webhook endpoint and returns its signing secret once. Idempotency-Key is optional here; when it is sent, a retry with the same key and body returns the first response, including the signing secret, instead of creating another endpoint. Once the workspace has a live product, a test API key cannot create an endpoint, because webhook endpoints are shared by the live and test environments (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
webhooks:write
Operation ID
mgmt_v1_webhook_endpoints_create

Parameters

NameLocationRequiredType and description
Idempotency-Key Header Optional
string Minimum length: 16 Maximum length: 255

Example Value

"stringxxxxxxxxxx"

Optional. Use a new unique value for each new operation and reuse it only to retry the same request after an unknown result. Sending a different body with the same key returns 409 IDEMPOTENCY_CONFLICT.

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "url": "https://example.com/resource",
  "events": [
    "string"
  ]
}

Responses

201

Created

Successful Webhook operation

application/json

Example Value

{
  "data": {}
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/webhooks/{id} Retrieve a webhook endpoint

Retrieve the current state and configuration of the specified a webhook endpoint.

Signing secrets are never returned. The url of a Slack, Microsoft Teams or Google Chat destination is not returned, because that URL itself lets anyone post into the channel.

Authentication
managementApiKey
Required scope
webhooks:read
Operation ID
mgmt_v1_webhook_endpoints_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

200

Success

Successful Webhook operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "url": "https://example.com/resource",
    "events": [
      "string"
    ],
    "status": "active",
    "secret_rotation": {
      "scheduled": true,
      "activates_at": "2026-09-21T00:00:00Z"
    },
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/webhooks/{id} Update a webhook endpoint

Update the specified a webhook endpoint. See the request Schema for fields that can be changed.

Webhook endpoints are shared by the live and test environments, and every active endpoint receives the events of both. Once the workspace has a live product, a test API key cannot change an endpoint (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
webhooks:write
Operation ID
mgmt_v1_webhook_endpoints_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "url": "https://example.com/resource",
  "events": [
    "string"
  ]
}

Responses

200

Success

Successful Webhook operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "url": "https://example.com/resource",
    "events": [
      "string"
    ],
    "status": "active",
    "secret_rotation": {
      "scheduled": true,
      "activates_at": "2026-09-21T00:00:00Z"
    },
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/webhooks/{id} Delete a webhook endpoint

Delete or disable the specified a webhook endpoint. Review the response codes and constraints before calling this operation.

Webhook endpoints are shared by the live and test environments, and every active endpoint receives the events of both. Once the workspace has a live product, a test API key cannot disable an endpoint (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
webhooks:write
Operation ID
mgmt_v1_webhook_endpoints_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

204

No content

Disabled

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Events and usage

3 operations

Retrieve audit events and usage reports.

GET /mgmt/v1/events List events

Retrieve a list of events. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
events:read
Operation ID
mgmt_v1_audit_events_index

Parameters

NameLocationRequiredType and description
limit Query Optional
integer Minimum: 1 Maximum: 200

Example Value

50
cursor Query Optional
string

Example Value

"string"

Responses

200

Success

Successful Event operation

application/json

Example Value

{
  "data": [
    {
      "id": "id_aaaaaaaaaaaaaaaaaaaa",
      "type": "string",
      "actor": {},
      "target": {
        "environment": "live"
      },
      "request_id": "01K5QWERTY1234567890ABCDEFG",
      "data": {},
      "created_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/plan Get plan limits and usage

Get the plan's limits, recommended policy values and this month's usage. This call does not count toward the monthly quota.

Returns the workspace plan's limits, recommended policy values and this month's usage. This call does not count toward the monthly Management API quota, so it keeps answering after the quota is used up.

Authentication
managementApiKey
Required scope
reports:read
Operation ID
mgmt_v1_plans_show

Responses

200

Success

Plan limits and usage

application/json

Example Value

{
  "data": {
    "plan": {
      "code": "string",
      "name": "Example name",
      "trial": true,
      "ends_at": "2026-09-21T00:00:00Z"
    },
    "quotas": {
      "property": {
        "limit": 1,
        "used": 1,
        "remaining": 1,
        "limit_with_overage": 1,
        "resets_at": "2026-09-21T00:00:00Z"
      }
    },
    "policy_constraints": {
      "activation_sync_min_sec": 1,
      "revocation_exposure_max_sec": 1,
      "cert_ttl_max_sec": 1,
      "floating_sync_min_sec": 1,
      "floating_lease_ttl_min_sec": 1
    },
    "policy_defaults": {
      "heartbeat_sec": 1,
      "cert_ttl_sec": 1,
      "network_grace_sec": 1
    },
    "revocation_exposure_max_sec_by_plan": {
      "property": 1
    },
    "license_duration_max_sec": 1,
    "unavailable_features": [
      {
        "key": "string",
        "minimum_plan": "string",
        "minimum_plan_name": "Example name"
      }
    ]
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/reports/usage Retrieve API usage

Retrieve API usage and limits aggregated for a time period.

Authentication
managementApiKey
Required scope
reports:read
Operation ID
mgmt_v1_reports_usage

Responses

200

Success

Successful UsageReport operation

application/json

Example Value

{
  "data": {
    "period": {},
    "new_activations": 1,
    "active_machines": 1,
    "active_licenses": 1,
    "active_leases": 1
  }
}
429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Resellers

5 operations

Manage reseller registrations and state.

GET /mgmt/v1/resellers List resellers

Retrieve a list of resellers. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_resellers_index

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Reseller operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "email": "developer@example.com",
      "external_ref": "string",
      "organization_limit": 1,
      "user_limit": 1,
      "status": "active",
      "metadata": {},
      "archived_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/resellers Create a reseller

Create a reseller. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_resellers_create

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "organization_limit": 1,
  "user_limit": 1,
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful Reseller operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "organization_limit": 1,
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/resellers/{id} Retrieve a reseller

Retrieve the current state and configuration of the specified a reseller.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_resellers_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Reseller operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "organization_limit": 1,
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/resellers/{id} Update a reseller

Update the specified a reseller. See the request Schema for fields that can be changed.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_resellers_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Schema

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "organization_limit": 1,
  "user_limit": 1,
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Reseller operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "organization_limit": 1,
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/resellers/{id} Delete a reseller

Delete or disable the specified a reseller. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_resellers_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Organizations

5 operations

Manage organizations that separate users.

GET /mgmt/v1/organizations List organizations

Retrieve a list of organizations. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_organizations_index

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Organization operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "email": "developer@example.com",
      "external_ref": "string",
      "user_limit": 1,
      "status": "active",
      "metadata": {},
      "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
      "archived_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/organizations Create an organization

Create an organization. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organizations_create

Request body

Required
application/json

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "user_limit": 1,
  "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful Organization operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/organizations/{id} Retrieve an organization

Retrieve the current state and configuration of the specified an organization.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_organizations_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Organization operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/organizations/{id} Update an organization

Update the specified an organization. See the request Schema for fields that can be changed.

Organizations are shared by the live and test environments. A test API key cannot change an organization whose users hold a seat on a live license (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organizations_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "user_limit": 1,
  "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Organization operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/organizations/{id} Delete an organization

Delete or disable the specified an organization. Review the response codes and constraints before calling this operation.

Organizations are shared by the live and test environments. A test API key cannot archive an organization whose users hold a seat on a live license (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organizations_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Organization group memberships

3 operations

Manage the users assigned to groups.

GET /mgmt/v1/organization_groups/{organization_group_id}/memberships List organization group memberships

Retrieve a list of organization group memberships. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_organization_group_memberships_index

Parameters

NameLocationRequiredType and description
organization_group_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OrganizationGroupMembership operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa",
      "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "assigned_at": "2026-09-21T00:00:00Z",
      "revoked_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/organization_groups/{organization_group_id}/memberships Create an organization group membership

Create an organization group membership. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organization_group_memberships_create

Parameters

NameLocationRequiredType and description
organization_group_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa"
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful OrganizationGroupMembership operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa",
    "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "assigned_at": "2026-09-21T00:00:00Z",
    "revoked_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/organization_groups/{organization_group_id}/memberships/{id} Delete an organization group membership

Delete or disable the specified an organization group membership. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organization_group_memberships_destroy

Parameters

NameLocationRequiredType and description
organization_group_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Organization groups

5 operations

Manage user groups within an organization.

GET /mgmt/v1/organization_groups List organization groups

Retrieve a list of organization groups. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_organization_groups_index

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OrganizationGroup operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "status": "active",
      "metadata": {},
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/organization_groups Create an organization group

Create an organization group. See Example Value for the request JSON and the resulting response.

Creates a group in a customer organization. The organization must be active; for a suspended or archived organization the request returns 422 DIRECTORY_VALIDATION_FAILED with the reason in details.errors.base.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organization_groups_create

Request body

Required
application/json

Example Value

{
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful OrganizationGroup operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "status": "active",
    "metadata": {},
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/organization_groups/{id} Retrieve an organization group

Retrieve the current state and configuration of the specified an organization group.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_organization_groups_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OrganizationGroup operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "status": "active",
    "metadata": {},
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/organization_groups/{id} Update an organization group

Update the specified an organization group. See the request Schema for fields that can be changed.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organization_groups_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OrganizationGroup operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "status": "active",
    "metadata": {},
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/organization_groups/{id} Delete an organization group

Delete or disable the specified an organization group. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_organization_groups_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

License users

5 operations

Manage the identities and state of people who use products.

GET /mgmt/v1/license_users List license users

Retrieve a list of license users. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_license_users_index

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful LicenseUser operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "issuer": "https://example.com/resource",
      "subject": "string",
      "email": "developer@example.com",
      "name": "Example name",
      "status": "active",
      "two_factor_state": "string",
      "two_factor_method": "string",
      "metadata": {},
      "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
      "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
      "last_authenticated_at": "2026-09-21T00:00:00Z",
      "deprovisioned_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/license_users Create a license user

Create a license user. See Example Value for the request JSON and the resulting response.

Creates a license user. Linking it to an OIDC connection with `oidc_connection_id` requires the Team plan or higher and the `oidc_sso` entitlement; otherwise it returns HTTP 403 (`PLAN_ENTITLEMENT_REQUIRED`). On the Personal plan, omit this value and manage users as a local list with API assignments.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_license_users_create

Request body

Required
application/json

Example Value

{
  "issuer": "string",
  "subject": "string",
  "email": "developer@example.com",
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The API key lacks the required scope, or assigning `oidc_connection_id` requires the Team plan or higher with the `oidc_sso` entitlement; the request returns `PLAN_ENTITLEMENT_REQUIRED`.

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful LicenseUser operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "issuer": "https://example.com/resource",
    "subject": "string",
    "email": "developer@example.com",
    "name": "Example name",
    "status": "active",
    "two_factor_state": "string",
    "two_factor_method": "string",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
    "last_authenticated_at": "2026-09-21T00:00:00Z",
    "deprovisioned_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/license_users/{id} Retrieve a license user

Retrieve the current state and configuration of the specified a license user.

Authentication
managementApiKey
Required scope
customers:read
Operation ID
mgmt_v1_license_users_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful LicenseUser operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "issuer": "https://example.com/resource",
    "subject": "string",
    "email": "developer@example.com",
    "name": "Example name",
    "status": "active",
    "two_factor_state": "string",
    "two_factor_method": "string",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
    "last_authenticated_at": "2026-09-21T00:00:00Z",
    "deprovisioned_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/license_users/{id} Update a license user

Update the specified a license user. See the request Schema for fields that can be changed.

Updates a license user. Linking it to an OIDC connection with `oidc_connection_id` requires the Team plan or higher and the `oidc_sso` entitlement; otherwise it returns HTTP 403 (`PLAN_ENTITLEMENT_REQUIRED`). On the Personal plan, update local users without this value. Sending `null` or an empty string as `organization_id` removes the user from its customer organization (omitting it leaves it unchanged).

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_license_users_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "issuer": "string",
  "subject": "string",
  "email": "developer@example.com",
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The API key lacks the required scope, or assigning `oidc_connection_id` requires the Team plan or higher with the `oidc_sso` entitlement; the request returns `PLAN_ENTITLEMENT_REQUIRED`.

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful LicenseUser operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "issuer": "https://example.com/resource",
    "subject": "string",
    "email": "developer@example.com",
    "name": "Example name",
    "status": "active",
    "two_factor_state": "string",
    "two_factor_method": "string",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
    "last_authenticated_at": "2026-09-21T00:00:00Z",
    "deprovisioned_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/license_users/{id} Delete a license user

Delete or disable the specified a license user. Review the response codes and constraints before calling this operation.

License users are shared by the live and test environments. A test API key cannot deprovision a license user who holds a seat on a live license (403 ENVIRONMENT_MISMATCH); a live API key can deprovision any license user.

Authentication
managementApiKey
Required scope
customers:write
Operation ID
mgmt_v1_license_users_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

OIDC connections

6 operations

Manage customer identity-provider connections.

GET /mgmt/v1/oidc_connections List OIDC connections

Retrieve a list of OIDC connections. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
sso:read
Operation ID
mgmt_v1_oidc_connections_index

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OidcConnection operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "issuer": "https://example.com/resource",
      "client_id": "01K5QWERTY1234567890ABCDEFG",
      "authorization_endpoint": "https://example.com/resource",
      "token_endpoint": "https://example.com/resource",
      "jwks_uri": "https://example.com/resource",
      "scopes": [
        "string"
      ],
      "allowed_audiences": [
        "string"
      ],
      "pkce_required": true,
      "jit_provisioning": true,
      "status": "active",
      "metadata": {},
      "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
      "client_secret_rotated_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/oidc_connections Create an OIDC connection

Create an OIDC connection. See Example Value for the request JSON and the resulting response.

Creates an OIDC connection. It requires the Team plan or higher and the `oidc_sso` entitlement; the Personal plan returns HTTP 403 (`PLAN_ENTITLEMENT_REQUIRED`).

Authentication
managementApiKey
Required scope
sso:write
Operation ID
mgmt_v1_oidc_connections_create

Request body

Required
application/json

Example Value

{
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "issuer": "string",
  "client_id": "01K5QWERTY1234567890ABCDEFG",
  "client_secret": "example-token",
  "authorization_endpoint": "https://example.com/resource",
  "token_endpoint": "https://example.com/resource",
  "jwks_uri": "https://example.com/resource",
  "pkce_required": true,
  "jit_provisioning": true,
  "status": "active",
  "scopes": [
    "string"
  ],
  "allowed_audiences": [
    "string"
  ],
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The API key lacks the required scope, or the Team plan or higher with the `oidc_sso` entitlement is required; the request returns `PLAN_ENTITLEMENT_REQUIRED`.

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful OidcConnection operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "issuer": "https://example.com/resource",
    "client_id": "01K5QWERTY1234567890ABCDEFG",
    "authorization_endpoint": "https://example.com/resource",
    "token_endpoint": "https://example.com/resource",
    "jwks_uri": "https://example.com/resource",
    "scopes": [
      "string"
    ],
    "allowed_audiences": [
      "string"
    ],
    "pkce_required": true,
    "jit_provisioning": true,
    "status": "active",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "client_secret_rotated_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
GET /mgmt/v1/oidc_connections/{id} Retrieve an OIDC connection

Retrieve the current state and configuration of the specified an OIDC connection.

Authentication
managementApiKey
Required scope
sso:read
Operation ID
mgmt_v1_oidc_connections_show

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OidcConnection operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "issuer": "https://example.com/resource",
    "client_id": "01K5QWERTY1234567890ABCDEFG",
    "authorization_endpoint": "https://example.com/resource",
    "token_endpoint": "https://example.com/resource",
    "jwks_uri": "https://example.com/resource",
    "scopes": [
      "string"
    ],
    "allowed_audiences": [
      "string"
    ],
    "pkce_required": true,
    "jit_provisioning": true,
    "status": "active",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "client_secret_rotated_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
PATCH /mgmt/v1/oidc_connections/{id} Update an OIDC connection

Update the specified OIDC connection. To change the issuer, client_id, endpoints, jwks_uri, allowed_audiences, or the mfa_acr_values, max_age, trust_upstream_mfa, require_phishing_resistant_mfa, or requested_acr_values metadata, send client_secret in the same request; otherwise the API returns HTTP 422 (`OIDC_CLIENT_SECRET_REENTRY_REQUIRED`). Every owner of the workspace gets an email about these changes. Multi-factor authentication at the identity provider counts when the ID token amr contains mfa, otp, sms, hwk, swk, or pop, or when acr matches mfa_acr_values. With require_phishing_resistant_mfa set to true, only key-based methods (hwk, swk, pop, such as passkeys) and mfa_acr_values count. With trust_upstream_mfa set to true, a user without Usakey two-step verification who signs in after multi-factor authentication at the identity provider has two-step verification switched to the identity provider. requested_acr_values is sent as acr_values in the authorization request.

Authentication
managementApiKey
Required scope
sso:write
Operation ID
mgmt_v1_oidc_connections_update

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "client_secret": "example-token",
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "issuer": "string",
  "client_id": "01K5QWERTY1234567890ABCDEFG",
  "authorization_endpoint": "https://example.com/resource",
  "token_endpoint": "https://example.com/resource",
  "jwks_uri": "https://example.com/resource",
  "pkce_required": true,
  "jit_provisioning": true,
  "status": "active",
  "scopes": [
    "string"
  ],
  "allowed_audiences": [
    "string"
  ],
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The API key lacks the required scope, or changes other than disabling the connection require the Team plan or higher with the `oidc_sso` entitlement; the request returns `PLAN_ENTITLEMENT_REQUIRED`.

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful OidcConnection operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "issuer": "https://example.com/resource",
    "client_id": "01K5QWERTY1234567890ABCDEFG",
    "authorization_endpoint": "https://example.com/resource",
    "token_endpoint": "https://example.com/resource",
    "jwks_uri": "https://example.com/resource",
    "scopes": [
      "string"
    ],
    "allowed_audiences": [
      "string"
    ],
    "pkce_required": true,
    "jit_provisioning": true,
    "status": "active",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "client_secret_rotated_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/oidc_connections/{id} Delete an OIDC connection

Delete or disable the specified an OIDC connection. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
sso:write
Operation ID
mgmt_v1_oidc_connections_destroy

Parameters

NameLocationRequiredType and description
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/oidc_connections/{oidc_connection_id}/client-secret-rotation Rotate an OIDC client secret

Replace the client secret for an OIDC connection safely.

Rotates the OIDC client secret. It requires the Team plan or higher and the `oidc_sso` entitlement; the Personal plan returns HTTP 403 (`PLAN_ENTITLEMENT_REQUIRED`).

Authentication
managementApiKey
Required scope
sso:write
Operation ID
mgmt_v1_oidc_client_secret_rotations_create

Parameters

NameLocationRequiredType and description
oidc_connection_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "client_secret": "example-token"
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

The API key lacks the required scope, or the Team plan or higher with the `oidc_sso` entitlement is required; the request returns `PLAN_ENTITLEMENT_REQUIRED`.

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Client Secret rotated without returning the secret value

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "issuer": "https://example.com/resource",
    "client_id": "01K5QWERTY1234567890ABCDEFG",
    "authorization_endpoint": "https://example.com/resource",
    "token_endpoint": "https://example.com/resource",
    "jwks_uri": "https://example.com/resource",
    "scopes": [
      "string"
    ],
    "allowed_audiences": [
      "string"
    ],
    "pkce_required": true,
    "jit_provisioning": true,
    "status": "active",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "client_secret_rotated_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

License assignments

3 operations

Assign and revoke user-level product access.

GET /mgmt/v1/licenses/{license_id}/assignments List license assignments

Retrieve a list of license assignments. See Parameters for available filters and pagination controls.

Authentication
managementApiKey
Required scope
licenses:read
Operation ID
mgmt_v1_license_assignments_index

Parameters

NameLocationRequiredType and description
license_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful LicenseAssignment operation

application/json

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
      "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
      "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
      "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "license_units": 1,
      "assigned_at": "2026-09-21T00:00:00Z",
      "expires_at": "2026-09-21T00:00:00Z",
      "revoked_at": "2026-09-21T00:00:00Z",
      "entitlement_overrides": {},
      "metadata": {},
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/licenses/{license_id}/assignments Create a license assignment

Create a license assignment. See Example Value for the request JSON and the resulting response.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_license_assignments_create

Parameters

NameLocationRequiredType and description
license_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
  "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
  "expires_at": "2026-09-21T00:00:00Z",
  "entitlement_overrides": {},
  "metadata": {}
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful LicenseAssignment operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
    "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
    "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
    "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "license_units": 1,
    "assigned_at": "2026-09-21T00:00:00Z",
    "expires_at": "2026-09-21T00:00:00Z",
    "revoked_at": "2026-09-21T00:00:00Z",
    "entitlement_overrides": {},
    "metadata": {},
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/licenses/{license_id}/assignments/{id} Delete a license assignment

Delete or disable the specified a license assignment. Review the response codes and constraints before calling this operation.

Authentication
managementApiKey
Required scope
licenses:write
Operation ID
mgmt_v1_license_assignments_destroy

Parameters

NameLocationRequiredType and description
license_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"
id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Management API

Webhook secret rotation

3 operations

Rotate webhook signing secrets safely.

POST /mgmt/v1/webhooks/{webhook_id}/secret-rotation/promote Promote the next webhook secret

Promote the prepared signing secret to the active webhook signing secret.

Webhook endpoints are shared by the live and test environments, and every active endpoint receives the events of both. Once the workspace has a live product, a test API key cannot promote a scheduled signing-secret rotation (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
webhooks:write
Operation ID
mgmt_v1_webhook_secret_rotations_promote

Parameters

NameLocationRequiredType and description
webhook_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
200

Success

Successful Webhook operation

application/json

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "url": "https://example.com/resource",
    "events": [
      "string"
    ],
    "status": "active",
    "secret_rotation": {
      "scheduled": true,
      "activates_at": "2026-09-21T00:00:00Z"
    },
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
POST /mgmt/v1/webhooks/{webhook_id}/secret-rotation Start webhook secret rotation

Issue the next webhook signing secret while keeping the current secret valid.

Webhook endpoints are shared by the live and test environments, and every active endpoint receives the events of both. Once the workspace has a live product, a test API key cannot schedule a signing-secret rotation (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
webhooks:write
Operation ID
mgmt_v1_webhook_secret_rotations_create

Parameters

NameLocationRequiredType and description
webhook_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Request body

Required
application/json

Example Value

{
  "activates_at": "2026-09-21T00:00:00Z"
}

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
201

Created

Successful Webhook operation

application/json

Example Value

{
  "data": {}
}
402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
400

Bad request

Invalid request

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
422

Unprocessable content

State transition or validation failed

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
DELETE /mgmt/v1/webhooks/{webhook_id}/secret-rotation Cancel webhook secret rotation

Discard the prepared signing secret and cancel the rotation.

Webhook endpoints are shared by the live and test environments, and every active endpoint receives the events of both. Once the workspace has a live product, a test API key cannot cancel a scheduled signing-secret rotation (403 ENVIRONMENT_MISMATCH).

Authentication
managementApiKey
Required scope
webhooks:write
Operation ID
mgmt_v1_webhook_secret_rotations_destroy

Parameters

NameLocationRequiredType and description
webhook_id Path Required
string

Example Value

"01K5QWERTY1234567890ABCDEFG"

Responses

429

Rate limit exceeded

The applicable request window has been exceeded

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
401

Authentication required

Invalid credential or proof

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
403

Forbidden

License state or scope denied

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
404

Not found

Resource not found

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
204

No content

Operation completed with no response body

402

Payment required

Workspace trial or subscription has ended

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
503

Temporarily unavailable

A required API protection dependency is unavailable

application/json

Schema

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}

Shared schemas in OpenAPI

Schemas

Shared schemas referenced by requests and responses. Use Example Value to inspect the JSON shape, then Schema to review required fields, types, and constraints.

PublicId 0 fields

Schema

string Maximum length: 64 Pattern: ^[a-z_]+[0-9a-f]{20,24}$

Example Value

"id_aaaaaaaaaaaaaaaaaaaa"
MachineInfoInventoryField 0 fields

Schema

string Minimum length: 1 Maximum length: 128

Allowed values: schema_version, collected_at, platform, app, app_version, app_build, sdk, sdk_version 37 more

Example Value

"schema_version"
MachineInfo 47 fields

Strict safe allowlist for self-reported support and risk information. The encoded object is limited to 16 KiB, 512 JSON values, eight nesting levels, 64 keys per object, 64 values per array, 128 bytes per key, and 2 KiB per generic string; named string fields below are limited to 512 bytes. String length keywords approximate byte limits and the server enforces the encoded byte limits. Raw serial numbers, MAC addresses, machine UUIDs or IDs, hostnames, user or home data, environment values, file or application inventories, process lists, and secrets are forbidden. capabilities may name only present allowlisted values; unavailable_fields may name only absent allowlisted values; the inventories must not overlap.

Schema

object

Example Value

{
  "schema_version": 1,
  "collected_at": 0,
  "platform": "string",
  "app": "string",
  "app_version": "string",
  "app_build": "string",
  "sdk": "string",
  "sdk_version": "string",
  "os": "string",
  "os_version": "string",
  "os_build": "string",
  "os_edition": "string",
  "kernel_version": "string",
  "arch": "string",
  "cpu_vendor": "string",
  "cpu_model": "string",
  "cpu_physical_cores": 1,
  "cpu_logical_cores": 1,
  "cpu_load": 0.0,
  "memory_bytes": 1,
  "storage_bytes": 1,
  "manufacturer": "string",
  "model": "string",
  "chassis_type": "string",
  "locale": "string",
  "timezone": "string",
  "env_type": "string",
  "vm_detected": true,
  "vm_vendor": "string",
  "container_detected": true,
  "container_runtime": "string",
  "wsl_detected": true,
  "wsl_version": "string",
  "emulator_detected": true,
  "secure_boot_enabled": true,
  "tpm_present": true,
  "tpm_version": "string",
  "secure_enclave_present": true,
  "hardware_keystore_present": true,
  "root_detected": true,
  "jailbreak_detected": true,
  "debugger_detected": true,
  "clock_tamper_detected": true,
  "clock_rollback_detected": true,
  "capabilities": [
    "schema_version"
  ],
  "unavailable_fields": [
    "schema_version"
  ],
  "risk_signals": [
    {
      "kind": "clock_rollback",
      "confidence": 0,
      "source": "example.value"
    }
  ]
}
FieldRequiredType and descriptionExample Value
schema_version Optional
integer Minimum: 1 Maximum: 255
1
collected_at Optional
integer Minimum: 0 Maximum: 9223372036854775807

Unix timestamp

0
platform Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
app Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
app_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
app_build Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
sdk Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
sdk_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os Required
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os_build Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os_edition Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
kernel_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
arch Required
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
cpu_vendor Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
cpu_model Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
cpu_physical_cores Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
cpu_logical_cores Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
cpu_load Optional
number Minimum: 0 Maximum: 100

Heartbeats accept finite fractional percentages; activation and offline snapshots use integer percentages.

0.0
memory_bytes Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
storage_bytes Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
manufacturer Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
model Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
chassis_type Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
locale Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
timezone Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
env_type Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
vm_detected Optional
boolean
true
vm_vendor Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
container_detected Optional
boolean
true
container_runtime Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
wsl_detected Optional
boolean
true
wsl_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
emulator_detected Optional
boolean
true
secure_boot_enabled Optional
boolean
true
tpm_present Optional
boolean
true
tpm_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
secure_enclave_present Optional
boolean
true
hardware_keystore_present Optional
boolean
true
root_detected Optional
boolean
true
jailbreak_detected Optional
boolean
true
debugger_detected Optional
boolean
true
clock_tamper_detected Optional
boolean
true
clock_rollback_detected Optional
boolean
true
capabilities Optional
array<MachineInfoInventoryField> Maximum items: 64 Unique items: yes
[ "schema_version" ]
unavailable_fields Optional
array<MachineInfoInventoryField> Maximum items: 64 Unique items: yes
[ "schema_version" ]
risk_signals Optional
array<object> Maximum items: 16
[ { "kind": "clock_rollback", "confidence": 0, "source": "example.value" } ]
StableMachineInfo 47 fields

Proof-bound activation and offline machine information. It uses the common safe allowlist, but cpu_load must be an integer so canonical signed JSON stays portable across SDK languages.

Schema

MachineInfo + object

Example Value

{
  "os": "string",
  "arch": "string"
}
FieldRequiredType and descriptionExample Value
cpu_load Optional
number Minimum: 0 Maximum: 100

Heartbeats accept finite fractional percentages; activation and offline snapshots use integer percentages.

0.0
schema_version Optional
integer Minimum: 1 Maximum: 255
1
collected_at Optional
integer Minimum: 0 Maximum: 9223372036854775807

Unix timestamp

0
platform Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
app Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
app_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
app_build Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
sdk Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
sdk_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os Required
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os_build Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
os_edition Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
kernel_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
arch Required
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
cpu_vendor Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
cpu_model Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
cpu_physical_cores Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
cpu_logical_cores Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
memory_bytes Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
storage_bytes Optional
integer Minimum: 1 Maximum: 9223372036854775807
1
manufacturer Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
model Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
chassis_type Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
locale Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
timezone Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
env_type Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
vm_detected Optional
boolean
true
vm_vendor Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
container_detected Optional
boolean
true
container_runtime Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
wsl_detected Optional
boolean
true
wsl_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
emulator_detected Optional
boolean
true
secure_boot_enabled Optional
boolean
true
tpm_present Optional
boolean
true
tpm_version Optional
string Minimum length: 1 Maximum length: 512 Pattern: ^[^\x00-\x1F\x7F]+$
"string"
secure_enclave_present Optional
boolean
true
hardware_keystore_present Optional
boolean
true
root_detected Optional
boolean
true
jailbreak_detected Optional
boolean
true
debugger_detected Optional
boolean
true
clock_tamper_detected Optional
boolean
true
clock_rollback_detected Optional
boolean
true
capabilities Optional
array<MachineInfoInventoryField> Maximum items: 64 Unique items: yes
[ "schema_version" ]
unavailable_fields Optional
array<MachineInfoInventoryField> Maximum items: 64 Unique items: yes
[ "schema_version" ]
risk_signals Optional
array<object> Maximum items: 16
[ { "kind": "clock_rollback", "confidence": 0, "source": "example.value" } ]
ActivationRequest 13 fields

Schema

object

Example Value

{
  "license_key": "string",
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "device_signing_public_key": "string",
  "device_kem_public_key": "string",
  "device_proof": "string",
  "machine_signals": {
    "property": "string"
  },
  "machine_info": {
    "os": "string",
    "arch": "string"
  },
  "app_version": "string",
  "sdk_version": "string",
  "request_id": "01K5QWERTY1234567890ABCDEFG",
  "client_time": 1,
  "named_user_token": "Example name",
  "nonce": "stringxxxxxxxxxxxxxxxx"
}
FieldRequiredType and descriptionExample Value
license_key Required
string Maximum length: 512
"string"
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
device_signing_public_key Required
string Maximum length: 2048
"string"
device_kem_public_key Required
string Maximum length: 1024
"string"
device_proof Required
string Maximum length: 1024
"string"
machine_signals Optional
object
{ "property": "string" }
machine_info Required { "os": "string", "arch": "string" }
app_version Optional
string Maximum length: 255
"string"
sdk_version Optional
string Maximum length: 255
"string"
request_id Optional
string Maximum length: 255
"01K5QWERTY1234567890ABCDEFG"
client_time Optional
integer
1
named_user_token Optional
string Maximum length: 4096

Required for named-user policies. Get the token with email license verification in the app (POST /runtime/v1/email-verifications, Personal or higher) or from the customer portal (Team or higher). Without it, the request returns 401 NAMED_USER_TOKEN_REQUIRED, and details.available_methods lists the methods available (email or portal).

"Example name"
nonce Required
string Minimum length: 22 Maximum length: 255
"stringxxxxxxxxxxxxxxxx"
ActivationHeartbeatRequest 4 fields

Schema

value

Example Value

{
  "machine_info": {
    "os": "string",
    "arch": "string"
  }
}
FieldRequiredType and descriptionExample Value
app_version Optional
string Maximum length: 255
"string"
sdk_version Optional
string Maximum length: 255
"string"
machine_info Optional

Full self-reported support information, required on first receipt, whenever it changes, and at least once every 24 hours; must include os and arch and is limited to the server allowlist, 16 KiB, 512 JSON values, eight nesting levels, and 2 KiB per string value

{ "schema_version": 1, "collected_at": 0, "platform": "string", "app": "string", "app_version": "string", "app_build": "string", "sdk": "string", "sdk_version": "string", "os": "string", "os_version": "string", "os_build": "string", "os_edition": "string", "kernel_version": "string", "arch": "string", "cpu_vendor": "string", "cpu_model": "string", "cpu_physical_cores": 1, "cpu_logical_cores": 1, "cpu_load": 0.0, "memory_bytes": 1, "storage_bytes": 1, "manufacturer": "string", "model": "string", "chassis_type": "string", "locale": "string", "timezone": "string", "env_type": "string", "vm_detected": true, "vm_vendor": "string", "container_detected": true, "container_runtime": "string", "wsl_detected": true, "wsl_version": "string", "emulator_detected": true, "secure_boot_enabled": true, "tpm_present": true, "tpm_version": "string", "secure_enclave_present": true, "hardware_keystore_present": true, "root_detected": true, "jailbreak_detected": true, "debugger_detected": true, "clock_tamper_detected": true, "clock_rollback_detected": true, "capabilities": [ "schema_version" ], "unavailable_fields": [ "schema_version" ], "risk_signals": [ { "kind": "clock_rollback", "confidence": 0, "source": "example.value" } ] }
machine_info_digest Optional
string Pattern: ^[0-9a-f]{64}$

SHA-256 digest of the unchanged full machine_info; accepted only while the server has received full machine_info in the preceding 24 hours

"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
SealedFileKeyRequest 2 fields

Schema

object

Example Value

{
  "header": "example_value",
  "sdk_version": "string"
}
FieldRequiredType and descriptionExample Value
header Required
string Minimum length: 3 Maximum length: 2731 Pattern: ^[A-Za-z0-9_-]+$

Unpadded base64url of the exact header bytes of a version 1 sealed file (at most 2048 bytes of canonical JSON)

"example_value"
sdk_version Optional
string Maximum length: 255
"string"
LeaseAcquireRequest 2 fields

Schema

object

Example Value

{
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "instance_id": "01K5QWERTY1234567890ABCDEFG"
}
FieldRequiredType and descriptionExample Value
activation_id Required "activation_id_aaaaaaaaaaaaaaaaaaaa"
instance_id Required
string Minimum length: 16 Maximum length: 255
"01K5QWERTY1234567890ABCDEFG"
LeaseInstanceRequest 1 fields

Schema

object

Example Value

{
  "instance_id": "01K5QWERTY1234567890ABCDEFG"
}
FieldRequiredType and descriptionExample Value
instance_id Required
string Minimum length: 16 Maximum length: 255
"01K5QWERTY1234567890ABCDEFG"
OfflineRequest 16 fields

Device-signed usakey-offline-request-v1 JSON. The complete encoded request is limited to 64 KiB, 1,024 JSON values, and eight nesting levels.

Schema

value

Example Value

{
  "format": "usakey-offline-request-v1",
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "device_signing_public_key": "string",
  "device_kem_public_key": "p256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
  "device_proof": "string",
  "machine_info": {
    "os": "string",
    "arch": "string"
  },
  "nonce": "example_valuexxxxxxxxx",
  "generated_at": 1
}
FieldRequiredType and descriptionExample Value
v Optional
integer
1
format Required
string
"usakey-offline-request-v1"
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
device_signing_public_key Required
string Minimum length: 1 Maximum length: 2048

Ed25519 SubjectPublicKeyInfo PEM or ed25519-prefixed raw public key

"string"
device_kem_public_key Required
string Minimum length: 1 Maximum length: 1024 Pattern: ^p256:[A-Za-z0-9_-]+$

Uncompressed 65-byte P-256 SEC1 point encoded as unpadded base64url

"p256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
device_proof Optional
string Minimum length: 1 Maximum length: 1024
"string"
request_proof Optional
string Minimum length: 1 Maximum length: 1024

Legacy alias for device_proof; send exactly one proof field.

"string"
machine_signals Optional
object
{ "property": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
machine_info Required { "os": "string", "arch": "string" }
sdk_version Optional
string Maximum length: 255
"string"
app_version Optional
string Maximum length: 255
"string"
request_id Optional
string Maximum length: 255
"01K5QWERTY1234567890ABCDEFG"
nonce Required
string Minimum length: 22 Maximum length: 255 Pattern: ^[A-Za-z0-9_-]+$
"example_valuexxxxxxxxx"
generated_at Required
integer

Unix timestamp no older than 7 days and no more than 5 minutes in the future

1
display Optional
object
{ "product_name": "Example name", "device_code": "string" }
sealed_file_headers Optional
array<string> Minimum items: 1 Maximum items: 16 Unique items: yes

Optional headers of sealed files whose data keys the package should carry, each the unpadded base64url of the exact header bytes. They are covered by the device proof like every other field. The package then includes a sealed-file-keys.json entry; if any file cannot be delivered, no package is issued.

[ "example_value" ]
OfflineCertificateIssueRequest 3 fields

Schema

object

Example Value

{
  "request": {
    "format": "usakey-offline-request-v1",
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "device_signing_public_key": "string",
    "device_kem_public_key": "p256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
    "device_proof": "string",
    "machine_info": {
      "os": "string",
      "arch": "string"
    },
    "nonce": "example_valuexxxxxxxxx",
    "generated_at": 1
  },
  "expires_at": "2026-09-21T00:00:00Z",
  "license_assignment_id": "license_assignment_id_aaaaaaaaaaaaaaaaaaaa"
}
FieldRequiredType and descriptionExample Value
request Required { "format": "usakey-offline-request-v1", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "device_signing_public_key": "string", "device_kem_public_key": "p256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA", "device_proof": "string", "machine_info": { "os": "string", "arch": "string" }, "nonce": "example_valuexxxxxxxxx", "generated_at": 1 }
expires_at Optional
string date-time
"2026-09-21T00:00:00Z"
license_assignment_id Optional
PublicId

Required for offline named-user policies on Team or higher. The signed package expires within 7 days and cannot be used afterward.

"license_assignment_id_aaaaaaaaaaaaaaaaaaaa"
LicenseIssueRequest 12 fields

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa",
  "customer_id": "customer_id_aaaaaaaaaaaaaaaaaaaa",
  "license_type": "perpetual",
  "expires_at": "2026-09-21T00:00:00Z",
  "expiry": "2026-09-21T00:00:00Z",
  "renewal_authority": "external_billing",
  "max_machines": 0,
  "max_concurrent": 0,
  "entitlements": {},
  "metadata": {},
  "license_unit_limit_override": 1
}
FieldRequiredType and descriptionExample Value
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
policy_id Required "policy_id_aaaaaaaaaaaaaaaaaaaa"
customer_id Optional "customer_id_aaaaaaaaaaaaaaaaaaaa"
license_type Optional
value

Allowed values: perpetual, subscription, trial

"perpetual"
expires_at Optional
string date-time

Subscription expiry. Omit for perpetual licenses. On Evaluation, it must be within 1 hour of issuance.

"2026-09-21T00:00:00Z"
expiry Optional
string date-time

Legacy name for `expires_at`. Use `expires_at`; when both are provided, `expires_at` takes precedence.

"2026-09-21T00:00:00Z"
renewal_authority Optional
value

Allowed values: external_billing, calendar, manual

"external_billing"
max_machines Optional
integer Minimum: 0
0
max_concurrent Optional
integer Minimum: 0
0
entitlements Optional
object
{}
metadata Optional
object
{}
license_unit_limit_override Optional
integer | null
1
SignedEnvelope 4 fields

Schema

object

Example Value

{
  "data": "string",
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
ActivationData 3 fields

Schema

object

Example Value

{
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "certificate": "string",
  "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
}
FieldRequiredType and descriptionExample Value
activation_id Required "activation_id_aaaaaaaaaaaaaaaaaaaa"
certificate Required
string

PASETO v4.public license certificate

"string"
machine_info_digest Required
string Pattern: ^[0-9a-f]{64}$

SHA-256 digest of the full machine_info stored for this activation

"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
ActivationHeartbeatData 5 fields

Schema

object

Example Value

{
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "license_status": "active",
  "certificate": "string",
  "next_heartbeat_in": 10,
  "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
}
FieldRequiredType and descriptionExample Value
activation_id Required "activation_id_aaaaaaaaaaaaaaaaaaaa"
license_status Required
value

Allowed values: active, suspended, revoked, expired

"active"
certificate Required
string

PASETO v4.public license certificate

"string"
next_heartbeat_in Required
integer Minimum: 10
10
machine_info_digest Required
string Pattern: ^[0-9a-f]{64}$

SHA-256 digest of the full machine_info stored for this activation

"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
SealedFileKeyData 5 fields

Schema

object

Example Value

{
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "file_id": "esNxn3TKNIsd_Dyi2XYojA",
  "header_sha256": "f7511808a1669a5481adebe399a96ad043d29ebb887207743368c3fb812717e5",
  "enc": "BC1G-oCCtQBTqm4VEolqWH6MHHbpugqlixdHLXLURww-71zLlbPAaperQqYpqsHIyF9bJ66JOqwcEaZ1yHqSNPI",
  "wrapped_key": "j4LNTalkfJFXswg_u9NXmazh7FZQHrAs4iqPQNp0hHCsdQIZWcS3AOpEkYp2mape"
}
FieldRequiredType and descriptionExample Value
activation_id Required "activation_id_aaaaaaaaaaaaaaaaaaaa"
file_id Required
string Pattern: ^[A-Za-z0-9_-]{22}$

The file's random identifier from its header

"esNxn3TKNIsd_Dyi2XYojA"
header_sha256 Required
string Pattern: ^[0-9a-f]{64}$

SHA-256 of the exact header bytes; the device looks the key up by this value

"f7511808a1669a5481adebe399a96ad043d29ebb887207743368c3fb812717e5"
enc Required
string Pattern: ^[A-Za-z0-9_-]{87}$

HPKE encapsulated key (65-byte uncompressed P-256 point, base64url)

"BC1G-oCCtQBTqm4VEolqWH6MHHbpugqlixdHLXLURww-71zLlbPAaperQqYpqsHIyF9bJ66JOqwcEaZ1yHqSNPI"
wrapped_key Required
string Pattern: ^[A-Za-z0-9_-]{64}$

The 32-byte data key sealed with HPKE to the activation's KEM public key (48 bytes with the tag, base64url). The associated data binds the activation, the device KEM key thumbprint, the product, and the header digest.

"j4LNTalkfJFXswg_u9NXmazh7FZQHrAs4iqPQNp0hHCsdQIZWcS3AOpEkYp2mape"
LeaseData 4 fields

Schema

object

Example Value

{
  "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
  "instance_id": "01K5QWERTY1234567890ABCDEFG",
  "expires_at": 1,
  "heartbeat_in": 10
}
FieldRequiredType and descriptionExample Value
lease_id Required "lease_id_aaaaaaaaaaaaaaaaaaaa"
instance_id Required
string Minimum length: 16 Maximum length: 255
"01K5QWERTY1234567890ABCDEFG"
expires_at Required
integer

Unix timestamp

1
heartbeat_in Required
integer Minimum: 10
10
LeaseReleaseData 2 fields

Schema

object

Example Value

{
  "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "released"
}
FieldRequiredType and descriptionExample Value
lease_id Required "lease_id_aaaaaaaaaaaaaaaaaaaa"
status Required
value
"released"
SignedActivationResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "certificate": "string",
    "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
SignedActivationHeartbeatResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "license_status": "active",
    "certificate": "string",
    "next_heartbeat_in": 10,
    "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
SignedSealedFileKeyResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "file_id": "esNxn3TKNIsd_Dyi2XYojA",
    "header_sha256": "f7511808a1669a5481adebe399a96ad043d29ebb887207743368c3fb812717e5",
    "enc": "BC1G-oCCtQBTqm4VEolqWH6MHHbpugqlixdHLXLURww-71zLlbPAaperQqYpqsHIyF9bJ66JOqwcEaZ1yHqSNPI",
    "wrapped_key": "j4LNTalkfJFXswg_u9NXmazh7FZQHrAs4iqPQNp0hHCsdQIZWcS3AOpEkYp2mape"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
SignedLeaseResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
    "instance_id": "01K5QWERTY1234567890ABCDEFG",
    "expires_at": 1,
    "heartbeat_in": 10
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
SignedLeaseReleaseResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "lease_id": "lease_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "released"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
EmailVerificationStartRequest 7 fields

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "license_key": "string",
  "email": "developer@example.com",
  "device_signing_public_key": "string",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "locale": "ja",
  "sdk_version": "string"
}
FieldRequiredType and descriptionExample Value
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
license_key Required
string Minimum length: 1 Maximum length: 512
"string"
email Required
string email Minimum length: 3 Maximum length: 254

The address the license user entered in the app. Compared after trimming spaces and lowercasing

"developer@example.com"
device_signing_public_key Required
string Minimum length: 1 Maximum length: 2048

Ed25519 public key (PEM or ed25519:base64url) of the device that will activate. The confirmation must send the same key

"string"
nonce Required
string Minimum length: 22 Maximum length: 255
"stringxxxxxxxxxxxxxxxx"
locale Optional
string Minimum length: 2 Maximum length: 35

Language of the email (ja or en). Falls back to Accept-Language, then Japanese

"ja"
sdk_version Optional
string Maximum length: 255
"string"
EmailVerificationStartData 4 fields

Schema

object

Example Value

{
  "verification_id": "verification_id_aaaaaaaaaaaaaaaaaaaa",
  "expires_at": "2026-09-21T00:00:00Z",
  "resend_after_sec": 1,
  "code_length": 1
}
FieldRequiredType and descriptionExample Value
verification_id Required "verification_id_aaaaaaaaaaaaaaaaaaaa"
expires_at Required
string date-time

When the code stops working

"2026-09-21T00:00:00Z"
resend_after_sec Required
integer Minimum: 1

Seconds to wait before starting again for the same address

1
code_length Required
integer Minimum: 1

Number of digits in the emailed code

1
SignedEmailVerificationStartResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "verification_id": "verification_id_aaaaaaaaaaaaaaaaaaaa",
    "expires_at": "2026-09-21T00:00:00Z",
    "resend_after_sec": 1,
    "code_length": 1
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
EmailVerificationConfirmRequest 5 fields

Schema

object

Example Value

{
  "code": "123456",
  "second_factor_code": "string",
  "device_signing_public_key": "string",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "sdk_version": "string"
}
FieldRequiredType and descriptionExample Value
code Required
string Minimum length: 1 Maximum length: 32

The six-digit code from the email. Spaces and hyphens are ignored

"123456"
second_factor_code Optional
string Minimum length: 1 Maximum length: 64

An authenticator app code, a recovery code, or the approval code obtained by opening the link in the verification email and approving with a passkey. Required only for license users with two-factor authentication. The passkey approval code is bound to this verification, expires after at most 10 minutes, and can be used once

"string"
device_signing_public_key Required
string Minimum length: 1 Maximum length: 2048

The same Ed25519 public key sent to start the verification

"string"
nonce Required
string Minimum length: 22 Maximum length: 255
"stringxxxxxxxxxxxxxxxx"
sdk_version Optional
string Maximum length: 255
"string"
EmailVerificationConfirmData 2 fields

Schema

object

Example Value

{
  "named_user_token": "Example name",
  "expires_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
named_user_token Required
string Maximum length: 4096

Pass as named_user_token to POST /runtime/v1/activations

"Example name"
expires_at Required
string date-time
"2026-09-21T00:00:00Z"
SignedEmailVerificationConfirmResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "named_user_token": "Example name",
    "expires_at": "2026-09-21T00:00:00Z"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
EmailVerificationError 1 fields

Schema

Error + object

Example Value

{
  "error": {
    "code": "EMAIL_VERIFICATION_CODE_INVALID",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "details": {
      "remaining_attempts": 0
    }
  }
}
FieldRequiredType and descriptionExample Value
error Required
object
{ "code": "string", "message": "string", "request_id": "01K5QWERTY1234567890ABCDEFG", "retryable": true, "doc_url": "https://example.com/resource", "details": {} }
TrialVerificationStartRequest 6 fields

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "email": "developer@example.com",
  "device_signing_public_key": "string",
  "nonce": "stringxxxxxxxxxxxxxxxx",
  "locale": "ja",
  "sdk_version": "string"
}
FieldRequiredType and descriptionExample Value
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
email Required
string email Minimum length: 3 Maximum length: 254

The address the user entered. Compared after trimming spaces and lowercasing

"developer@example.com"
device_signing_public_key Required
string Minimum length: 1 Maximum length: 2048

Ed25519 public key (PEM or ed25519:base64url) of the device that will run the trial. The confirmation must use the same key

"string"
nonce Required
string Minimum length: 22 Maximum length: 255
"stringxxxxxxxxxxxxxxxx"
locale Optional
string Minimum length: 2 Maximum length: 35

Language of the email (ja or en). Falls back to Accept-Language, then Japanese

"ja"
sdk_version Optional
string Maximum length: 255
"string"
TrialVerificationConfirmRequest 12 fields

Schema

object

Example Value

{
  "code": "123456",
  "email": "developer@example.com",
  "device_signing_public_key": "string",
  "device_kem_public_key": "string",
  "device_proof": "string",
  "machine_signals": {
    "property": "string"
  },
  "machine_info": {
    "os": "string",
    "arch": "string"
  },
  "app_version": "string",
  "sdk_version": "string",
  "request_id": "01K5QWERTY1234567890ABCDEFG",
  "client_time": 1,
  "nonce": "stringxxxxxxxxxxxxxxxx"
}
FieldRequiredType and descriptionExample Value
code Required
string Minimum length: 1 Maximum length: 32

The six-digit code from the email. Spaces and hyphens are ignored

"123456"
email Required
string email Minimum length: 3 Maximum length: 254

The same address as the start request

"developer@example.com"
device_signing_public_key Required
string Maximum length: 2048

The same Ed25519 public key as the start request

"string"
device_kem_public_key Required
string Maximum length: 1024
"string"
device_proof Required
string Maximum length: 1024

Signature by the device signing key of the prefix Usakey-Trial-Proof-v1, a newline, and the canonical JSON of this body without device_proof

"string"
machine_signals Optional
object
{ "property": "string" }
machine_info Required { "os": "string", "arch": "string" }
app_version Optional
string Maximum length: 255
"string"
sdk_version Optional
string Maximum length: 255
"string"
request_id Optional
string Maximum length: 255
"01K5QWERTY1234567890ABCDEFG"
client_time Optional
integer
1
nonce Required
string Minimum length: 22 Maximum length: 255
"stringxxxxxxxxxxxxxxxx"
TrialSignupData 4 fields

Schema

ActivationData + object

Example Value

{
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "certificate": "string",
  "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
  "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa"
}
FieldRequiredType and descriptionExample Value
license_id Required "license_id_aaaaaaaaaaaaaaaaaaaa"
activation_id Required "activation_id_aaaaaaaaaaaaaaaaaaaa"
certificate Required
string

PASETO v4.public license certificate

"string"
machine_info_digest Required
string Pattern: ^[0-9a-f]{64}$

SHA-256 digest of the full machine_info stored for this activation

"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
SignedTrialSignupResponse 4 fields

Schema

SignedEnvelope + object

Example Value

{
  "data": {
    "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
    "certificate": "string",
    "machine_info_digest": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa"
  },
  "response_assertion": {
    "v": 1,
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "nonce": "string",
    "server_time": 1,
    "status": 1,
    "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  },
  "response_signature": "example-token",
  "signing_delegation": {
    "delegation": {
      "v": 1,
      "purpose": "runtime-response",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "parent_key_id": "01K5QWERTY1234567890ABCDEFG",
      "online_key_id": "01K5QWERTY1234567890ABCDEFG",
      "public_key": "string",
      "issued_at": 1,
      "expires_at": 1
    },
    "signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Required
value
"string"
response_assertion Required
object
{ "v": 1, "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "key_id": "01K5QWERTY1234567890ABCDEFG", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "request_id": "01K5QWERTY1234567890ABCDEFG", "nonce": "string", "server_time": 1, "status": 1, "body_sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }
response_signature Required
string
"example-token"
signing_delegation Required
object
{ "delegation": { "v": 1, "purpose": "runtime-response", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "parent_key_id": "01K5QWERTY1234567890ABCDEFG", "online_key_id": "01K5QWERTY1234567890ABCDEFG", "public_key": "string", "issued_at": 1, "expires_at": 1 }, "signature": "example-token" }
TrustBundleResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "bundle": {},
    "root_signature": "example-token"
  }
}
FieldRequiredType and descriptionExample Value
data Optional
object
{ "bundle": {}, "root_signature": "example-token" }
Error 1 fields

Schema

object

Example Value

{
  "error": {
    "code": "string",
    "message": "string",
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "retryable": true,
    "doc_url": "https://example.com/resource",
    "details": {}
  }
}
FieldRequiredType and descriptionExample Value
error Required
object
{ "code": "string", "message": "string", "request_id": "01K5QWERTY1234567890ABCDEFG", "retryable": true, "doc_url": "https://example.com/resource", "details": {} }
Pagination 2 fields

Schema

object

Example Value

{
  "next_cursor": "string",
  "has_more": true
}
FieldRequiredType and descriptionExample Value
next_cursor Required
string | null
"string"
has_more Required
boolean
true
Product 11 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "code": "string",
  "description": "Example description",
  "environment": "live",
  "status": "active",
  "trust_bundle_sequence": 1,
  "signing_status": "pending",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z",
  "version": 1
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
code Optional
string
"string"
description Optional
string | null
"Example description"
environment Optional
value

Allowed values: live, test

"live"
status Optional
string
"active"
trust_bundle_sequence Optional
integer | null
1
signing_status Optional
string

Allowed values: pending, ready

Whether a product signing key is ready for license issuance.

"pending"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
version Optional
integer | null
1
ProductResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "code": "string",
    "description": "Example description",
    "environment": "live",
    "status": "active",
    "trust_bundle_sequence": 1,
    "signing_status": "pending",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z",
    "version": 1
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "code": "string", "description": "Example description", "environment": "live", "status": "active", "trust_bundle_sequence": 1, "signing_status": "pending", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z", "version": 1 }
ProductListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "code": "string",
      "description": "Example description",
      "environment": "live",
      "status": "active",
      "trust_bundle_sequence": 1,
      "signing_status": "pending",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z",
      "version": 1
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Product>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "code": "string", "description": "Example description", "environment": "live", "status": "active", "trust_bundle_sequence": 1, "signing_status": "pending", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z", "version": 1 } ]
pagination Required { "next_cursor": "string", "has_more": true }
IntegrationConfig 10 fields

The contents of usakey.config.json.

Schema

object

Example Value

{
  "usakey_config_version": 1,
  "generated_at": "2026-09-21T00:00:00Z",
  "bundle_version": "string",
  "environment": "live",
  "api_url": "https://example.com/resource",
  "product": {
    "id": "id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name"
  },
  "trust_anchor": {
    "signing_mode": "string",
    "key_id": "01K5QWERTY1234567890ABCDEFG",
    "trust_bundle_url": "https://example.com/resource",
    "minimum_trust_bundle_sequence": 1,
    "root_public_key": "string",
    "development_root_public_key": "string",
    "public_key_unavailable_reason": "string",
    "signing_keys_pending_reason": "string"
  },
  "entitlements": [
    {
      "name": "Example name",
      "type": "boolean",
      "policies": [
        "string"
      ]
    }
  ],
  "license_key_delivery": "manual",
  "stripe_license_claim_url": "https://example.com/resource"
}
FieldRequiredType and descriptionExample Value
usakey_config_version Required
integer
1
generated_at Required
string date-time
"2026-09-21T00:00:00Z"
bundle_version Required
string
"string"
environment Required
value

Allowed values: live, test

"live"
api_url Required
string uri
"https://example.com/resource"
product Required
object
{ "id": "id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name" }
trust_anchor Required { "signing_mode": "string", "key_id": "01K5QWERTY1234567890ABCDEFG", "trust_bundle_url": "https://example.com/resource", "minimum_trust_bundle_sequence": 1, "root_public_key": "string", "development_root_public_key": "string", "public_key_unavailable_reason": "string", "signing_keys_pending_reason": "string" }
entitlements Required
array<object>
[ { "name": "Example name", "type": "boolean", "policies": [ "string" ] } ]
license_key_delivery Required
value

Allowed values: manual, stripe_checkout

"manual"
stripe_license_claim_url Optional
string uri

Present only while the workspace's own Stripe integration is active and this product has an active price mapping.

"https://example.com/resource"
IntegrationTrustAnchor 8 fields

Schema

object

Example Value

{
  "signing_mode": "string",
  "key_id": "01K5QWERTY1234567890ABCDEFG",
  "trust_bundle_url": "https://example.com/resource",
  "minimum_trust_bundle_sequence": 1,
  "root_public_key": "string",
  "development_root_public_key": "string",
  "public_key_unavailable_reason": "string",
  "signing_keys_pending_reason": "string"
}
FieldRequiredType and descriptionExample Value
signing_mode Required
string
"string"
key_id Optional
string | null
"01K5QWERTY1234567890ABCDEFG"
trust_bundle_url Required
string uri
"https://example.com/resource"
minimum_trust_bundle_sequence Required
integer Minimum: 1
1
root_public_key Optional
string
"string"
development_root_public_key Optional
string

Development servers only, for test-environment products. Never build it into a distributed product.

"string"
public_key_unavailable_reason Optional
string
"string"
signing_keys_pending_reason Optional
string
"string"
IntegrationConfigDocument 3 fields

Schema

object

Example Value

{
  "file_name": "Example name",
  "content": "string",
  "config": {
    "usakey_config_version": 1,
    "generated_at": "2026-09-21T00:00:00Z",
    "bundle_version": "string",
    "environment": "live",
    "api_url": "https://example.com/resource",
    "product": {
      "id": "id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name"
    },
    "trust_anchor": {
      "signing_mode": "string",
      "key_id": "01K5QWERTY1234567890ABCDEFG",
      "trust_bundle_url": "https://example.com/resource",
      "minimum_trust_bundle_sequence": 1,
      "root_public_key": "string",
      "development_root_public_key": "string",
      "public_key_unavailable_reason": "string",
      "signing_keys_pending_reason": "string"
    },
    "entitlements": [
      {
        "name": "Example name",
        "type": "boolean",
        "policies": [
          "string"
        ]
      }
    ],
    "license_key_delivery": "manual",
    "stripe_license_claim_url": "https://example.com/resource"
  }
}
FieldRequiredType and descriptionExample Value
file_name Required
string
"Example name"
content Required
string

The file exactly as the Console downloads it.

"string"
config Required { "usakey_config_version": 1, "generated_at": "2026-09-21T00:00:00Z", "bundle_version": "string", "environment": "live", "api_url": "https://example.com/resource", "product": { "id": "id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name" }, "trust_anchor": { "signing_mode": "string", "key_id": "01K5QWERTY1234567890ABCDEFG", "trust_bundle_url": "https://example.com/resource", "minimum_trust_bundle_sequence": 1, "root_public_key": "string", "development_root_public_key": "string", "public_key_unavailable_reason": "string", "signing_keys_pending_reason": "string" }, "entitlements": [ { "name": "Example name", "type": "boolean", "policies": [ "string" ] } ], "license_key_delivery": "manual", "stripe_license_claim_url": "https://example.com/resource" }
IntegrationConfigResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "file_name": "Example name",
    "content": "string",
    "config": {
      "usakey_config_version": 1,
      "generated_at": "2026-09-21T00:00:00Z",
      "bundle_version": "string",
      "environment": "live",
      "api_url": "https://example.com/resource",
      "product": {
        "id": "id_aaaaaaaaaaaaaaaaaaaa",
        "name": "Example name"
      },
      "trust_anchor": {
        "signing_mode": "string",
        "key_id": "01K5QWERTY1234567890ABCDEFG",
        "trust_bundle_url": "https://example.com/resource",
        "minimum_trust_bundle_sequence": 1,
        "root_public_key": "string",
        "development_root_public_key": "string",
        "public_key_unavailable_reason": "string",
        "signing_keys_pending_reason": "string"
      },
      "entitlements": [
        {
          "name": "Example name",
          "type": "boolean",
          "policies": [
            "string"
          ]
        }
      ],
      "license_key_delivery": "manual",
      "stripe_license_claim_url": "https://example.com/resource"
    }
  }
}
FieldRequiredType and descriptionExample Value
data Required { "file_name": "Example name", "content": "string", "config": { "usakey_config_version": 1, "generated_at": "2026-09-21T00:00:00Z", "bundle_version": "string", "environment": "live", "api_url": "https://example.com/resource", "product": { "id": "id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name" }, "trust_anchor": { "signing_mode": "string", "key_id": "01K5QWERTY1234567890ABCDEFG", "trust_bundle_url": "https://example.com/resource", "minimum_trust_bundle_sequence": 1, "root_public_key": "string", "development_root_public_key": "string", "public_key_unavailable_reason": "string", "signing_keys_pending_reason": "string" }, "entitlements": [ { "name": "Example name", "type": "boolean", "policies": [ "string" ] } ], "license_key_delivery": "manual", "stripe_license_claim_url": "https://example.com/resource" } }
ProductSealedFiles 3 fields

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "enabled",
  "current_key": {
    "key_id": "key_seal_0123456789abcdef0123",
    "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
    "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
    "created_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
status Required
string

Allowed values: enabled, disabled, not_entitled, unavailable

"enabled"
current_key Required
ProductSealingKey | null
{ "key_id": "key_seal_0123456789abcdef0123", "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y", "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y", "created_at": "2026-09-21T00:00:00Z" }
ProductSealingKey 4 fields

Schema

object

Example Value

{
  "key_id": "key_seal_0123456789abcdef0123",
  "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
  "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
  "created_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
key_id Required
string

Identifier of this key version, written into every file sealed with it

"key_seal_0123456789abcdef0123"
public_key Required
string Pattern: ^p256:[A-Za-z0-9_-]{87}$

Uncompressed P-256 public key, unpadded base64url. In deployed environments every product has the same public key (the environment's sealing key); key_id and the product ID tell products apart.

"p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y"
sealing_key Required
string

The one-line public key for the sealing tool (usakey-seal --key). Not a secret.

"usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y"
created_at Required
string date-time
"2026-09-21T00:00:00Z"
ProductSealedFilesResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "enabled",
    "current_key": {
      "key_id": "key_seal_0123456789abcdef0123",
      "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
      "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y",
      "created_at": "2026-09-21T00:00:00Z"
    }
  }
}
FieldRequiredType and descriptionExample Value
data Required { "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "status": "enabled", "current_key": { "key_id": "key_seal_0123456789abcdef0123", "public_key": "p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y", "sealing_key": "usakey-sealing-key:v1:prod_0123456789abcdef0123:key_seal_0123456789abcdef0123:p256:BC8ylpFJ44nP01V3Ei2l5hm8iUAyxR8cepHBhlWWLzsAqCUpcNOfUa05MSFt28Z9RVc7yJO2cKyY_V1rZon_v6Y", "created_at": "2026-09-21T00:00:00Z" } }
ProductBrowserRuntime 4 fields

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "enabled": true,
  "allowed_origins": [
    "string"
  ],
  "version": 0
}
FieldRequiredType and descriptionExample Value
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
enabled Required
boolean
true
allowed_origins Required
array<string> Maximum items: 20
[ "string" ]
version Required
integer Minimum: 0
0
ProductBrowserRuntimeResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "enabled": true,
    "allowed_origins": [
      "string"
    ],
    "version": 0
  }
}
FieldRequiredType and descriptionExample Value
data Required { "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "enabled": true, "allowed_origins": [ "string" ], "version": 0 }
ProductTrialSignup 6 fields

How the product accepts trials started from the product app with email verification.

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "policy_id": "01K5QWERTY1234567890ABCDEFG",
  "daily_limit": 1,
  "status": "accepting",
  "started_last_24_hours": 0,
  "version": 0
}
FieldRequiredType and descriptionExample Value
product_id Required "product_id_aaaaaaaaaaaaaaaaaaaa"
policy_id Required
string | null Maximum length: 64

The trial policy used for trials started from the app: an active trial policy of this product that uses license keys. null when the product does not accept them.

"01K5QWERTY1234567890ABCDEFG"
daily_limit Required
integer Minimum: 1 Maximum: 1000

The most trials the app can start for this product in any 24 hours. Defaults to 20.

1
status Required
string

Allowed values: accepting, off, not_entitled, policy_unavailable, daily_limit_reached

accepting: a start request sends a code. off: no policy is chosen. not_entitled: the current plan does not include trials. policy_unavailable: the chosen policy was retired or changed and can no longer be used; choose another. daily_limit_reached: started_last_24_hours has reached daily_limit.

"accepting"
started_last_24_hours Required
integer Minimum: 0

Trials started from the app in the last 24 hours, counted against daily_limit. A second device joining the same trial is not counted.

0
version Required
integer Minimum: 0

The product's version. Send it in If-Match to change the settings only if the product has not changed since it was read.

0
ProductTrialSignupResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "policy_id": "01K5QWERTY1234567890ABCDEFG",
    "daily_limit": 1,
    "status": "accepting",
    "started_last_24_hours": 0,
    "version": 0
  }
}
FieldRequiredType and descriptionExample Value
data Required { "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "policy_id": "01K5QWERTY1234567890ABCDEFG", "daily_limit": 1, "status": "accepting", "started_last_24_hours": 0, "version": 0 }
PlanQuota 5 fields

Schema

object

Example Value

{
  "limit": 1,
  "used": 1,
  "remaining": 1,
  "limit_with_overage": 1,
  "resets_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
limit Required
integer | null

null means unlimited.

1
used Required
integer
1
remaining Required
integer | null
1
limit_with_overage Optional
integer

The point where new usage is refused when the plan allows paid overage above the limit.

1
resets_at Optional
string date-time

Monthly quotas only.

"2026-09-21T00:00:00Z"
PlanLimits 7 fields

Schema

object

Example Value

{
  "plan": {
    "code": "string",
    "name": "Example name",
    "trial": true,
    "ends_at": "2026-09-21T00:00:00Z"
  },
  "quotas": {
    "property": {
      "limit": 1,
      "used": 1,
      "remaining": 1,
      "limit_with_overage": 1,
      "resets_at": "2026-09-21T00:00:00Z"
    }
  },
  "policy_constraints": {
    "activation_sync_min_sec": 1,
    "revocation_exposure_max_sec": 1,
    "cert_ttl_max_sec": 1,
    "floating_sync_min_sec": 1,
    "floating_lease_ttl_min_sec": 1
  },
  "policy_defaults": {
    "heartbeat_sec": 1,
    "cert_ttl_sec": 1,
    "network_grace_sec": 1
  },
  "revocation_exposure_max_sec_by_plan": {
    "property": 1
  },
  "license_duration_max_sec": 1,
  "unavailable_features": [
    {
      "key": "string",
      "minimum_plan": "string",
      "minimum_plan_name": "Example name"
    }
  ]
}
FieldRequiredType and descriptionExample Value
plan Required
object | null
{ "code": "string", "name": "Example name", "trial": true, "ends_at": "2026-09-21T00:00:00Z" }
quotas Required
object
{ "property": { "limit": 1, "used": 1, "remaining": 1, "limit_with_overage": 1, "resets_at": "2026-09-21T00:00:00Z" } }
policy_constraints Required
object
{ "activation_sync_min_sec": 1, "revocation_exposure_max_sec": 1, "cert_ttl_max_sec": 1, "floating_sync_min_sec": 1, "floating_lease_ttl_min_sec": 1 }
policy_defaults Required
object
{ "heartbeat_sec": 1, "cert_ttl_sec": 1, "network_grace_sec": 1 }
revocation_exposure_max_sec_by_plan Required
object
{ "property": 1 }
license_duration_max_sec Required
integer | null
1
unavailable_features Required
array<object>
[ { "key": "string", "minimum_plan": "string", "minimum_plan_name": "Example name" } ]
PlanLimitsResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "plan": {
      "code": "string",
      "name": "Example name",
      "trial": true,
      "ends_at": "2026-09-21T00:00:00Z"
    },
    "quotas": {
      "property": {
        "limit": 1,
        "used": 1,
        "remaining": 1,
        "limit_with_overage": 1,
        "resets_at": "2026-09-21T00:00:00Z"
      }
    },
    "policy_constraints": {
      "activation_sync_min_sec": 1,
      "revocation_exposure_max_sec": 1,
      "cert_ttl_max_sec": 1,
      "floating_sync_min_sec": 1,
      "floating_lease_ttl_min_sec": 1
    },
    "policy_defaults": {
      "heartbeat_sec": 1,
      "cert_ttl_sec": 1,
      "network_grace_sec": 1
    },
    "revocation_exposure_max_sec_by_plan": {
      "property": 1
    },
    "license_duration_max_sec": 1,
    "unavailable_features": [
      {
        "key": "string",
        "minimum_plan": "string",
        "minimum_plan_name": "Example name"
      }
    ]
  }
}
FieldRequiredType and descriptionExample Value
data Required { "plan": { "code": "string", "name": "Example name", "trial": true, "ends_at": "2026-09-21T00:00:00Z" }, "quotas": { "property": { "limit": 1, "used": 1, "remaining": 1, "limit_with_overage": 1, "resets_at": "2026-09-21T00:00:00Z" } }, "policy_constraints": { "activation_sync_min_sec": 1, "revocation_exposure_max_sec": 1, "cert_ttl_max_sec": 1, "floating_sync_min_sec": 1, "floating_lease_ttl_min_sec": 1 }, "policy_defaults": { "heartbeat_sec": 1, "cert_ttl_sec": 1, "network_grace_sec": 1 }, "revocation_exposure_max_sec_by_plan": { "property": 1 }, "license_duration_max_sec": 1, "unavailable_features": [ { "key": "string", "minimum_plan": "string", "minimum_plan_name": "Example name" } ] }
ActivationDetail 16 fields

Schema

object

Example Value

{
  "id": "id_aaaaaaaaaaaaaaaaaaaa",
  "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "machine": {},
  "device_signing_key_thumbprint": "string",
  "first_seen_at": "2026-09-21T00:00:00Z",
  "last_seen_at": "2026-09-21T00:00:00Z",
  "deactivated_at": "2026-09-21T00:00:00Z",
  "activated_at": "2026-09-21T00:00:00Z",
  "last_heartbeat_at": "2026-09-21T00:00:00Z",
  "heartbeat_interval_sec": 1,
  "next_heartbeat_due": {
    "earliest": "2026-09-21T00:00:00Z",
    "latest": "2026-09-21T00:00:00Z"
  },
  "heartbeat_overdue": true,
  "certificate_expires_at": "2026-09-21T00:00:00Z",
  "app_version": "string",
  "sdk_version": "string"
}
FieldRequiredType and descriptionExample Value
id Optional "id_aaaaaaaaaaaaaaaaaaaa"
license_id Optional "license_id_aaaaaaaaaaaaaaaaaaaa"
status Optional
string
"active"
machine Optional
object
{}
device_signing_key_thumbprint Optional
string
"string"
first_seen_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
last_seen_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
deactivated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
activated_at Optional
string date-time
"2026-09-21T00:00:00Z"
last_heartbeat_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
heartbeat_interval_sec Optional
integer | null
1
next_heartbeat_due Optional
object | null

When the next periodic check should arrive, between earliest and latest (the interval plus up to 10% jitter).

{ "earliest": "2026-09-21T00:00:00Z", "latest": "2026-09-21T00:00:00Z" }
heartbeat_overdue Optional
boolean

True when an active device has missed its periodic check window.

true
certificate_expires_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
app_version Optional
string | null
"string"
sdk_version Optional
string | null
"string"
ActivationDetailResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "id": "id_aaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "machine": {},
    "device_signing_key_thumbprint": "string",
    "first_seen_at": "2026-09-21T00:00:00Z",
    "last_seen_at": "2026-09-21T00:00:00Z",
    "deactivated_at": "2026-09-21T00:00:00Z",
    "activated_at": "2026-09-21T00:00:00Z",
    "last_heartbeat_at": "2026-09-21T00:00:00Z",
    "heartbeat_interval_sec": 1,
    "next_heartbeat_due": {
      "earliest": "2026-09-21T00:00:00Z",
      "latest": "2026-09-21T00:00:00Z"
    },
    "heartbeat_overdue": true,
    "certificate_expires_at": "2026-09-21T00:00:00Z",
    "app_version": "string",
    "sdk_version": "string"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "id": "id_aaaaaaaaaaaaaaaaaaaa", "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "machine": {}, "device_signing_key_thumbprint": "string", "first_seen_at": "2026-09-21T00:00:00Z", "last_seen_at": "2026-09-21T00:00:00Z", "deactivated_at": "2026-09-21T00:00:00Z", "activated_at": "2026-09-21T00:00:00Z", "last_heartbeat_at": "2026-09-21T00:00:00Z", "heartbeat_interval_sec": 1, "next_heartbeat_due": { "earliest": "2026-09-21T00:00:00Z", "latest": "2026-09-21T00:00:00Z" }, "heartbeat_overdue": true, "certificate_expires_at": "2026-09-21T00:00:00Z", "app_version": "string", "sdk_version": "string" }
RuntimeEvent 12 fields

Rejected or failed Runtime API requests with the same target, operation and result code within one hour. Request bodies, license keys, signatures and device keys are never stored.

Schema

object

Example Value

{
  "operation": "activation_create",
  "outcome": "rejected",
  "code": "DEVICE_PROOF_INVALID",
  "http_status": 400,
  "occurrences": 1,
  "first_occurred_at": "2026-09-21T00:00:00Z",
  "last_occurred_at": "2026-09-21T00:00:00Z",
  "last_request_id": "01K5QWERTY1234567890ABCDEFG",
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
  "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
  "details_omitted": true
}
FieldRequiredType and descriptionExample Value
operation Required
value

Allowed values: activation_create, activation_heartbeat, activation_deactivate, lease_acquire, lease_heartbeat, lease_release

"activation_create"
outcome Required
value

Allowed values: rejected, error

rejected for a 4xx answer the product app has to fix; error for a temporary 5xx failure on the Usakey side.

"rejected"
code Required
string Pattern: ^[A-Z][A-Z0-9_]{0,63}$

The error.code the Runtime API returned, such as DEVICE_PROOF_INVALID, CLOCK_SKEW or LICENSE_REVOKED.

"DEVICE_PROOF_INVALID"
http_status Required
integer Minimum: 400 Maximum: 599
400
occurrences Required
integer Minimum: 1
1
first_occurred_at Required
string date-time
"2026-09-21T00:00:00Z"
last_occurred_at Required
string date-time
"2026-09-21T00:00:00Z"
last_request_id Required
string | null

The request_id of the latest request, as the product app received it.

"01K5QWERTY1234567890ABCDEFG"
product_id Required
PublicId | null
"product_id_aaaaaaaaaaaaaaaaaaaa"
license_id Required
PublicId | null

Null when the request did not reach a license, such as a wrong license key.

"license_id_aaaaaaaaaaaaaaaaaaaa"
activation_id Required
PublicId | null
"activation_id_aaaaaaaaaaaaaaaaaaaa"
details_omitted Required
boolean

True for an entry that counts requests beyond the hourly limit of entries without their product, license and device activation.

true
RuntimeEventListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "operation": "activation_create",
      "outcome": "rejected",
      "code": "DEVICE_PROOF_INVALID",
      "http_status": 400,
      "occurrences": 1,
      "first_occurred_at": "2026-09-21T00:00:00Z",
      "last_occurred_at": "2026-09-21T00:00:00Z",
      "last_request_id": "01K5QWERTY1234567890ABCDEFG",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
      "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa",
      "details_omitted": true
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<RuntimeEvent>
[ { "operation": "activation_create", "outcome": "rejected", "code": "DEVICE_PROOF_INVALID", "http_status": 400, "occurrences": 1, "first_occurred_at": "2026-09-21T00:00:00Z", "last_occurred_at": "2026-09-21T00:00:00Z", "last_request_id": "01K5QWERTY1234567890ABCDEFG", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa", "activation_id": "activation_id_aaaaaaaaaaaaaaaaaaaa", "details_omitted": true } ]
pagination Required { "next_cursor": "string", "has_more": true }
StripeIntegrationStatus 7 fields

Schema

object

Example Value

{
  "registered": true,
  "mode": "test",
  "status": "active",
  "secure_claims_required": true,
  "license_claim_url": "https://example.com/resource",
  "last_event": {
    "type": "string",
    "result": "string",
    "at": "2026-09-21T00:00:00Z"
  },
  "offerings": [
    {
      "id": "id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "stripe_price_id": "01K5QWERTY1234567890ABCDEFG",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "license_duration_days": 1
    }
  ]
}
FieldRequiredType and descriptionExample Value
registered Required
boolean
true
mode Optional
value

Allowed values: test, live

"test"
status Optional
value

Allowed values: active, disabled

"active"
secure_claims_required Optional
boolean
true
license_claim_url Optional
string | null uri
"https://example.com/resource"
last_event Optional
object | null
{ "type": "string", "result": "string", "at": "2026-09-21T00:00:00Z" }
offerings Required
array<object>
[ { "id": "id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "stripe_price_id": "01K5QWERTY1234567890ABCDEFG", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "license_duration_days": 1 } ]
StripeIntegrationResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "registered": true,
    "mode": "test",
    "status": "active",
    "secure_claims_required": true,
    "license_claim_url": "https://example.com/resource",
    "last_event": {
      "type": "string",
      "result": "string",
      "at": "2026-09-21T00:00:00Z"
    },
    "offerings": [
      {
        "id": "id_aaaaaaaaaaaaaaaaaaaa",
        "name": "Example name",
        "stripe_price_id": "01K5QWERTY1234567890ABCDEFG",
        "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
        "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa",
        "status": "active",
        "license_duration_days": 1
      }
    ]
  }
}
FieldRequiredType and descriptionExample Value
data Required { "registered": true, "mode": "test", "status": "active", "secure_claims_required": true, "license_claim_url": "https://example.com/resource", "last_event": { "type": "string", "result": "string", "at": "2026-09-21T00:00:00Z" }, "offerings": [ { "id": "id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "stripe_price_id": "01K5QWERTY1234567890ABCDEFG", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "license_duration_days": 1 } ] }
Policy 27 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "version": 1,
  "license_type": "perpetual",
  "validation_mode": "string",
  "perpetual_mode": "managed",
  "heartbeat_required": true,
  "revocation_guarantee_sec": 0,
  "fail_mode": "string",
  "identity_mode": "string",
  "license_unit_limit": 1,
  "max_machines": 1,
  "max_concurrent": 1,
  "concurrency_unit": "string",
  "cert_ttl_sec": 1,
  "heartbeat_sec": 1,
  "lease_ttl_sec": 1,
  "lease_heartbeat_sec": 1,
  "network_grace_sec": 1,
  "fingerprint_profile": {},
  "renewal_authority": "string",
  "billing_cycle": "string",
  "trial_days": 1,
  "entitlements": {},
  "status": "active",
  "created_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
product_id Optional "product_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
version Optional
integer | null

Historical policy number. Use the ETag from GET policies/{id} for If-Match.

1
license_type Optional
value

Allowed values: perpetual, subscription, trial

"perpetual"
validation_mode Optional
string
"string"
perpetual_mode Optional
string | null

Allowed values: managed, offline_unmanaged, null

Derived for perpetual policies. offline plus license_key is offline_unmanaged; every other perpetual policy is managed.

"managed"
heartbeat_required Optional
boolean

False only for a device-bound offline_unmanaged perpetual policy.

true
revocation_guarantee_sec Optional
integer | null Minimum: 0

Maximum signed offline revocation window. Null means that online revocation is not promised.

0
fail_mode Optional
string
"string"
identity_mode Optional
string
"string"
license_unit_limit Optional
integer | null
1
max_machines Optional
integer | null
1
max_concurrent Optional
integer | null
1
concurrency_unit Optional
string
"string"
cert_ttl_sec Optional
integer | null
1
heartbeat_sec Optional
integer | null
1
lease_ttl_sec Optional
integer | null
1
lease_heartbeat_sec Optional
integer | null
1
network_grace_sec Optional
integer | null
1
fingerprint_profile Optional
object
{}
renewal_authority Optional
string
"string"
billing_cycle Optional
string
"string"
trial_days Optional
integer | null
1
entitlements Optional
object
{}
status Optional
string
"active"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
PolicyResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "version": 1,
    "license_type": "perpetual",
    "validation_mode": "string",
    "perpetual_mode": "managed",
    "heartbeat_required": true,
    "revocation_guarantee_sec": 0,
    "fail_mode": "string",
    "identity_mode": "string",
    "license_unit_limit": 1,
    "max_machines": 1,
    "max_concurrent": 1,
    "concurrency_unit": "string",
    "cert_ttl_sec": 1,
    "heartbeat_sec": 1,
    "lease_ttl_sec": 1,
    "lease_heartbeat_sec": 1,
    "network_grace_sec": 1,
    "fingerprint_profile": {},
    "renewal_authority": "string",
    "billing_cycle": "string",
    "trial_days": 1,
    "entitlements": {},
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "version": 1, "license_type": "perpetual", "validation_mode": "string", "perpetual_mode": "managed", "heartbeat_required": true, "revocation_guarantee_sec": 0, "fail_mode": "string", "identity_mode": "string", "license_unit_limit": 1, "max_machines": 1, "max_concurrent": 1, "concurrency_unit": "string", "cert_ttl_sec": 1, "heartbeat_sec": 1, "lease_ttl_sec": 1, "lease_heartbeat_sec": 1, "network_grace_sec": 1, "fingerprint_profile": {}, "renewal_authority": "string", "billing_cycle": "string", "trial_days": 1, "entitlements": {}, "status": "active", "created_at": "2026-09-21T00:00:00Z" }
PolicyListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "version": 1,
      "license_type": "perpetual",
      "validation_mode": "string",
      "perpetual_mode": "managed",
      "heartbeat_required": true,
      "revocation_guarantee_sec": 0,
      "fail_mode": "string",
      "identity_mode": "string",
      "license_unit_limit": 1,
      "max_machines": 1,
      "max_concurrent": 1,
      "concurrency_unit": "string",
      "cert_ttl_sec": 1,
      "heartbeat_sec": 1,
      "lease_ttl_sec": 1,
      "lease_heartbeat_sec": 1,
      "network_grace_sec": 1,
      "fingerprint_profile": {},
      "renewal_authority": "string",
      "billing_cycle": "string",
      "trial_days": 1,
      "entitlements": {},
      "status": "active",
      "created_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Policy>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "version": 1, "license_type": "perpetual", "validation_mode": "string", "perpetual_mode": "managed", "heartbeat_required": true, "revocation_guarantee_sec": 0, "fail_mode": "string", "identity_mode": "string", "license_unit_limit": 1, "max_machines": 1, "max_concurrent": 1, "concurrency_unit": "string", "cert_ttl_sec": 1, "heartbeat_sec": 1, "lease_ttl_sec": 1, "lease_heartbeat_sec": 1, "network_grace_sec": 1, "fingerprint_profile": {}, "renewal_authority": "string", "billing_cycle": "string", "trial_days": 1, "entitlements": {}, "status": "active", "created_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
Customer 8 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "notes": "string",
  "status": "active",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
email Optional
string | null
"developer@example.com"
external_ref Optional
string | null
"string"
notes Optional
string | null
"string"
status Optional
string
"active"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
CustomerResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "notes": "string",
    "status": "active",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "email": "developer@example.com", "external_ref": "string", "notes": "string", "status": "active", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
CustomerListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "email": "developer@example.com",
      "external_ref": "string",
      "notes": "string",
      "status": "active",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Customer>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "email": "developer@example.com", "external_ref": "string", "notes": "string", "status": "active", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
License 29 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "policy_id": "policy_id_aaaaaaaaaaaaaaaaaaaa",
  "policy_version": 1,
  "customer_id": "customer_id_aaaaaaaaaaaaaaaaaaaa",
  "license_type": "perpetual",
  "perpetual_mode": "managed",
  "heartbeat_required": true,
  "revocation_guarantee_sec": 0,
  "status": "active",
  "expires_at": "2026-09-21T00:00:00Z",
  "expiry": "2026-09-21T00:00:00Z",
  "renewal_authority": "string",
  "entitlements": {},
  "metadata": {},
  "current_period_start": "2026-09-21T00:00:00Z",
  "current_period_end": "2026-09-21T00:00:00Z",
  "renewal_count": 1,
  "key_hint": "string",
  "max_machines": 1,
  "max_concurrent": 1,
  "license_unit_limit": 1,
  "trial_days": 1,
  "trial_started_at": "2026-09-21T00:00:00Z",
  "trial_converted_at": "2026-09-21T00:00:00Z",
  "active_activations": 1,
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z",
  "version": 1
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
product_id Optional "product_id_aaaaaaaaaaaaaaaaaaaa"
policy_id Optional "policy_id_aaaaaaaaaaaaaaaaaaaa"
policy_version Optional
integer | null
1
customer_id Optional
PublicId | null
"customer_id_aaaaaaaaaaaaaaaaaaaa"
license_type Optional
value

Allowed values: perpetual, subscription, trial

"perpetual"
perpetual_mode Optional
string | null

Allowed values: managed, offline_unmanaged, null

"managed"
heartbeat_required Optional
boolean
true
revocation_guarantee_sec Optional
integer | null Minimum: 0

Null for offline_unmanaged and fail-open licenses; those licenses have no online revocation SLA.

0
status Optional
string
"active"
expires_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
expiry Optional
string | null date-time

Same value as `expires_at`. Use `expires_at`.

"2026-09-21T00:00:00Z"
renewal_authority Optional
string
"string"
entitlements Optional
object
{}
metadata Optional
object
{}
current_period_start Optional
string | null date-time
"2026-09-21T00:00:00Z"
current_period_end Optional
string | null date-time
"2026-09-21T00:00:00Z"
renewal_count Optional
integer | null
1
key_hint Optional
string
"string"
max_machines Optional
integer | null
1
max_concurrent Optional
integer | null
1
license_unit_limit Optional
integer | null
1
trial_days Optional
integer | null
1
trial_started_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
trial_converted_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
active_activations Optional
integer | null
1
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
version Optional
integer | null
1
LicenseResponse 1 fields

Schema

object

Example Value

{
  "data": {}
}
FieldRequiredType and descriptionExample Value
data Required
License
{}
LicenseListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {}
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<License>
[ {} ]
pagination Required { "next_cursor": "string", "has_more": true }
Activation 8 fields

Schema

object

Example Value

{
  "id": "id_aaaaaaaaaaaaaaaaaaaa",
  "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "machine": {},
  "device_signing_key_thumbprint": "string",
  "first_seen_at": "2026-09-21T00:00:00Z",
  "last_seen_at": "2026-09-21T00:00:00Z",
  "deactivated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
id Optional "id_aaaaaaaaaaaaaaaaaaaa"
license_id Optional "license_id_aaaaaaaaaaaaaaaaaaaa"
status Optional
string
"active"
machine Optional
object
{}
device_signing_key_thumbprint Optional
string
"string"
first_seen_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
last_seen_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
deactivated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
ActivationResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "id": "id_aaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "machine": {},
    "device_signing_key_thumbprint": "string",
    "first_seen_at": "2026-09-21T00:00:00Z",
    "last_seen_at": "2026-09-21T00:00:00Z",
    "deactivated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "id": "id_aaaaaaaaaaaaaaaaaaaa", "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "machine": {}, "device_signing_key_thumbprint": "string", "first_seen_at": "2026-09-21T00:00:00Z", "last_seen_at": "2026-09-21T00:00:00Z", "deactivated_at": "2026-09-21T00:00:00Z" }
ActivationListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "id": "id_aaaaaaaaaaaaaaaaaaaa",
      "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "machine": {},
      "device_signing_key_thumbprint": "string",
      "first_seen_at": "2026-09-21T00:00:00Z",
      "last_seen_at": "2026-09-21T00:00:00Z",
      "deactivated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Activation>
[ { "id": "id_aaaaaaaaaaaaaaaaaaaa", "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "machine": {}, "device_signing_key_thumbprint": "string", "first_seen_at": "2026-09-21T00:00:00Z", "last_seen_at": "2026-09-21T00:00:00Z", "deactivated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
Webhook 8 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "url": "https://example.com/resource",
  "events": [
    "string"
  ],
  "status": "active",
  "secret_rotation": {
    "scheduled": true,
    "activates_at": "2026-09-21T00:00:00Z"
  },
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
url Optional
string uri
"https://example.com/resource"
events Optional
array<string>
[ "string" ]
status Optional
string
"active"
secret_rotation Optional
object
{ "scheduled": true, "activates_at": "2026-09-21T00:00:00Z" }
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
WebhookResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "url": "https://example.com/resource",
    "events": [
      "string"
    ],
    "status": "active",
    "secret_rotation": {
      "scheduled": true,
      "activates_at": "2026-09-21T00:00:00Z"
    },
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "url": "https://example.com/resource", "events": [ "string" ], "status": "active", "secret_rotation": { "scheduled": true, "activates_at": "2026-09-21T00:00:00Z" }, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
WebhookListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "url": "https://example.com/resource",
      "events": [
        "string"
      ],
      "status": "active",
      "secret_rotation": {
        "scheduled": true,
        "activates_at": "2026-09-21T00:00:00Z"
      },
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Webhook>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "url": "https://example.com/resource", "events": [ "string" ], "status": "active", "secret_rotation": { "scheduled": true, "activates_at": "2026-09-21T00:00:00Z" }, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
Event 7 fields

Schema

object

Example Value

{
  "id": "id_aaaaaaaaaaaaaaaaaaaa",
  "type": "string",
  "actor": {},
  "target": {
    "environment": "live"
  },
  "request_id": "01K5QWERTY1234567890ABCDEFG",
  "data": {},
  "created_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
id Optional "id_aaaaaaaaaaaaaaaaaaaa"
type Optional
string
"string"
actor Optional
object
{}
target Optional
object
{ "environment": "live" }
request_id Optional
string | null
"01K5QWERTY1234567890ABCDEFG"
data Optional
object
{}
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
EventResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "id": "id_aaaaaaaaaaaaaaaaaaaa",
    "type": "string",
    "actor": {},
    "target": {
      "environment": "live"
    },
    "request_id": "01K5QWERTY1234567890ABCDEFG",
    "data": {},
    "created_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "id": "id_aaaaaaaaaaaaaaaaaaaa", "type": "string", "actor": {}, "target": { "environment": "live" }, "request_id": "01K5QWERTY1234567890ABCDEFG", "data": {}, "created_at": "2026-09-21T00:00:00Z" }
EventListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "id": "id_aaaaaaaaaaaaaaaaaaaa",
      "type": "string",
      "actor": {},
      "target": {
        "environment": "live"
      },
      "request_id": "01K5QWERTY1234567890ABCDEFG",
      "data": {},
      "created_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Event>
[ { "id": "id_aaaaaaaaaaaaaaaaaaaa", "type": "string", "actor": {}, "target": { "environment": "live" }, "request_id": "01K5QWERTY1234567890ABCDEFG", "data": {}, "created_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
Reseller 11 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "organization_limit": 1,
  "user_limit": 1,
  "status": "active",
  "metadata": {},
  "archived_at": "2026-09-21T00:00:00Z",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
email Optional
string | null
"developer@example.com"
external_ref Optional
string | null
"string"
organization_limit Optional
integer | null
1
user_limit Optional
integer | null
1
status Optional
string
"active"
metadata Optional
object
{}
archived_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
ResellerResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "organization_limit": 1,
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "email": "developer@example.com", "external_ref": "string", "organization_limit": 1, "user_limit": 1, "status": "active", "metadata": {}, "archived_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
ResellerListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "email": "developer@example.com",
      "external_ref": "string",
      "organization_limit": 1,
      "user_limit": 1,
      "status": "active",
      "metadata": {},
      "archived_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Reseller>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "email": "developer@example.com", "external_ref": "string", "organization_limit": 1, "user_limit": 1, "status": "active", "metadata": {}, "archived_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
Organization 11 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "user_limit": 1,
  "status": "active",
  "metadata": {},
  "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
  "archived_at": "2026-09-21T00:00:00Z",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
email Optional
string | null
"developer@example.com"
external_ref Optional
string | null
"string"
user_limit Optional
integer | null
1
status Optional
string
"active"
metadata Optional
object
{}
reseller_id Optional
PublicId | null
"reseller_id_aaaaaaaaaaaaaaaaaaaa"
archived_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
OrganizationResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "email": "developer@example.com",
    "external_ref": "string",
    "user_limit": 1,
    "status": "active",
    "metadata": {},
    "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
    "archived_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "email": "developer@example.com", "external_ref": "string", "user_limit": 1, "status": "active", "metadata": {}, "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa", "archived_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
OrganizationListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "email": "developer@example.com",
      "external_ref": "string",
      "user_limit": 1,
      "status": "active",
      "metadata": {},
      "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
      "archived_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<Organization>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "email": "developer@example.com", "external_ref": "string", "user_limit": 1, "status": "active", "metadata": {}, "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa", "archived_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
OrganizationGroup 7 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "status": "active",
  "metadata": {},
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
organization_id Optional "organization_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
status Optional
string
"active"
metadata Optional
object
{}
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
OrganizationGroupResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "status": "active",
    "metadata": {},
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "status": "active", "metadata": {}, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
OrganizationGroupListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "status": "active",
      "metadata": {},
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<OrganizationGroup>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "status": "active", "metadata": {}, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
OrganizationGroupMembership 8 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa",
  "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "assigned_at": "2026-09-21T00:00:00Z",
  "revoked_at": "2026-09-21T00:00:00Z",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
organization_group_id Optional "organization_group_id_aaaaaaaaaaaaaaaaaaaa"
license_user_id Optional "license_user_id_aaaaaaaaaaaaaaaaaaaa"
status Optional
string
"active"
assigned_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
revoked_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
OrganizationGroupMembershipResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa",
    "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "assigned_at": "2026-09-21T00:00:00Z",
    "revoked_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa", "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "assigned_at": "2026-09-21T00:00:00Z", "revoked_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
OrganizationGroupMembershipListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa",
      "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "assigned_at": "2026-09-21T00:00:00Z",
      "revoked_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<OrganizationGroupMembership>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "organization_group_id": "organization_group_id_aaaaaaaaaaaaaaaaaaaa", "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "assigned_at": "2026-09-21T00:00:00Z", "revoked_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
LicenseUser 15 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "issuer": "https://example.com/resource",
  "subject": "string",
  "email": "developer@example.com",
  "name": "Example name",
  "status": "active",
  "two_factor_state": "string",
  "two_factor_method": "string",
  "metadata": {},
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
  "last_authenticated_at": "2026-09-21T00:00:00Z",
  "deprovisioned_at": "2026-09-21T00:00:00Z",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
issuer Optional
string uri
"https://example.com/resource"
subject Optional
string
"string"
email Optional
string | null
"developer@example.com"
name Optional
string | null
"Example name"
status Optional
string
"active"
two_factor_state Optional
string
"string"
two_factor_method Optional
string | null
"string"
metadata Optional
object
{}
organization_id Optional
PublicId | null
"organization_id_aaaaaaaaaaaaaaaaaaaa"
oidc_connection_id Optional
PublicId | null

The associated OIDC connection ID. It is normally `null` for Personal-plan local-directory users because OIDC and the customer portal are unavailable.

"oidc_connection_id_aaaaaaaaaaaaaaaaaaaa"
last_authenticated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
deprovisioned_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
LicenseUserResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "issuer": "https://example.com/resource",
    "subject": "string",
    "email": "developer@example.com",
    "name": "Example name",
    "status": "active",
    "two_factor_state": "string",
    "two_factor_method": "string",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
    "last_authenticated_at": "2026-09-21T00:00:00Z",
    "deprovisioned_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "issuer": "https://example.com/resource", "subject": "string", "email": "developer@example.com", "name": "Example name", "status": "active", "two_factor_state": "string", "two_factor_method": "string", "metadata": {}, "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa", "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa", "last_authenticated_at": "2026-09-21T00:00:00Z", "deprovisioned_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
LicenseUserListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "issuer": "https://example.com/resource",
      "subject": "string",
      "email": "developer@example.com",
      "name": "Example name",
      "status": "active",
      "two_factor_state": "string",
      "two_factor_method": "string",
      "metadata": {},
      "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
      "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
      "last_authenticated_at": "2026-09-21T00:00:00Z",
      "deprovisioned_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<LicenseUser>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "issuer": "https://example.com/resource", "subject": "string", "email": "developer@example.com", "name": "Example name", "status": "active", "two_factor_state": "string", "two_factor_method": "string", "metadata": {}, "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa", "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa", "last_authenticated_at": "2026-09-21T00:00:00Z", "deprovisioned_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
OidcConnection 17 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "issuer": "https://example.com/resource",
  "client_id": "01K5QWERTY1234567890ABCDEFG",
  "authorization_endpoint": "https://example.com/resource",
  "token_endpoint": "https://example.com/resource",
  "jwks_uri": "https://example.com/resource",
  "scopes": [
    "string"
  ],
  "allowed_audiences": [
    "string"
  ],
  "pkce_required": true,
  "jit_provisioning": true,
  "status": "active",
  "metadata": {},
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "client_secret_rotated_at": "2026-09-21T00:00:00Z",
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
issuer Optional
string uri
"https://example.com/resource"
client_id Optional
string
"01K5QWERTY1234567890ABCDEFG"
authorization_endpoint Optional
string uri
"https://example.com/resource"
token_endpoint Optional
string uri
"https://example.com/resource"
jwks_uri Optional
string uri
"https://example.com/resource"
scopes Optional
array<string>
[ "string" ]
allowed_audiences Optional
array<string>
[ "string" ]
pkce_required Optional
boolean
true
jit_provisioning Optional
boolean
true
status Optional
string
"active"
metadata Optional
object
{}
organization_id Optional
PublicId | null
"organization_id_aaaaaaaaaaaaaaaaaaaa"
client_secret_rotated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
OidcConnectionResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "name": "Example name",
    "issuer": "https://example.com/resource",
    "client_id": "01K5QWERTY1234567890ABCDEFG",
    "authorization_endpoint": "https://example.com/resource",
    "token_endpoint": "https://example.com/resource",
    "jwks_uri": "https://example.com/resource",
    "scopes": [
      "string"
    ],
    "allowed_audiences": [
      "string"
    ],
    "pkce_required": true,
    "jit_provisioning": true,
    "status": "active",
    "metadata": {},
    "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
    "client_secret_rotated_at": "2026-09-21T00:00:00Z",
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "issuer": "https://example.com/resource", "client_id": "01K5QWERTY1234567890ABCDEFG", "authorization_endpoint": "https://example.com/resource", "token_endpoint": "https://example.com/resource", "jwks_uri": "https://example.com/resource", "scopes": [ "string" ], "allowed_audiences": [ "string" ], "pkce_required": true, "jit_provisioning": true, "status": "active", "metadata": {}, "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa", "client_secret_rotated_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
OidcConnectionListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "name": "Example name",
      "issuer": "https://example.com/resource",
      "client_id": "01K5QWERTY1234567890ABCDEFG",
      "authorization_endpoint": "https://example.com/resource",
      "token_endpoint": "https://example.com/resource",
      "jwks_uri": "https://example.com/resource",
      "scopes": [
        "string"
      ],
      "allowed_audiences": [
        "string"
      ],
      "pkce_required": true,
      "jit_provisioning": true,
      "status": "active",
      "metadata": {},
      "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
      "client_secret_rotated_at": "2026-09-21T00:00:00Z",
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<OidcConnection>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "name": "Example name", "issuer": "https://example.com/resource", "client_id": "01K5QWERTY1234567890ABCDEFG", "authorization_endpoint": "https://example.com/resource", "token_endpoint": "https://example.com/resource", "jwks_uri": "https://example.com/resource", "scopes": [ "string" ], "allowed_audiences": [ "string" ], "pkce_required": true, "jit_provisioning": true, "status": "active", "metadata": {}, "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa", "client_secret_rotated_at": "2026-09-21T00:00:00Z", "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
LicenseAssignment 14 fields

Schema

object

Example Value

{
  "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
  "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
  "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
  "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
  "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "license_units": 1,
  "assigned_at": "2026-09-21T00:00:00Z",
  "expires_at": "2026-09-21T00:00:00Z",
  "revoked_at": "2026-09-21T00:00:00Z",
  "entitlement_overrides": {},
  "metadata": {},
  "created_at": "2026-09-21T00:00:00Z",
  "updated_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
public_id Optional "public_id_aaaaaaaaaaaaaaaaaaaa"
license_id Optional "license_id_aaaaaaaaaaaaaaaaaaaa"
license_user_id Optional "license_user_id_aaaaaaaaaaaaaaaaaaaa"
source_group_id Optional
PublicId | null
"source_group_id_aaaaaaaaaaaaaaaaaaaa"
tenant_plan_id Optional
PublicId | null
"tenant_plan_id_aaaaaaaaaaaaaaaaaaaa"
status Optional
string
"active"
license_units Optional
integer | null
1
assigned_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
expires_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
revoked_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
entitlement_overrides Optional
object
{}
metadata Optional
object
{}
created_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
updated_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
LicenseAssignmentResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
    "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
    "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
    "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
    "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa",
    "status": "active",
    "license_units": 1,
    "assigned_at": "2026-09-21T00:00:00Z",
    "expires_at": "2026-09-21T00:00:00Z",
    "revoked_at": "2026-09-21T00:00:00Z",
    "entitlement_overrides": {},
    "metadata": {},
    "created_at": "2026-09-21T00:00:00Z",
    "updated_at": "2026-09-21T00:00:00Z"
  }
}
FieldRequiredType and descriptionExample Value
data Required { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa", "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa", "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa", "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "license_units": 1, "assigned_at": "2026-09-21T00:00:00Z", "expires_at": "2026-09-21T00:00:00Z", "revoked_at": "2026-09-21T00:00:00Z", "entitlement_overrides": {}, "metadata": {}, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" }
LicenseAssignmentListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa",
      "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa",
      "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
      "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
      "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa",
      "status": "active",
      "license_units": 1,
      "assigned_at": "2026-09-21T00:00:00Z",
      "expires_at": "2026-09-21T00:00:00Z",
      "revoked_at": "2026-09-21T00:00:00Z",
      "entitlement_overrides": {},
      "metadata": {},
      "created_at": "2026-09-21T00:00:00Z",
      "updated_at": "2026-09-21T00:00:00Z"
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<LicenseAssignment>
[ { "public_id": "public_id_aaaaaaaaaaaaaaaaaaaa", "license_id": "license_id_aaaaaaaaaaaaaaaaaaaa", "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa", "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa", "tenant_plan_id": "tenant_plan_id_aaaaaaaaaaaaaaaaaaaa", "status": "active", "license_units": 1, "assigned_at": "2026-09-21T00:00:00Z", "expires_at": "2026-09-21T00:00:00Z", "revoked_at": "2026-09-21T00:00:00Z", "entitlement_overrides": {}, "metadata": {}, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } ]
pagination Required { "next_cursor": "string", "has_more": true }
UsageReport 5 fields

Schema

object

Example Value

{
  "period": {},
  "new_activations": 1,
  "active_machines": 1,
  "active_licenses": 1,
  "active_leases": 1
}
FieldRequiredType and descriptionExample Value
period Optional
object
{}
new_activations Optional
integer | null
1
active_machines Optional
integer | null

Distinct machines among the activations created in the period that have not been deactivated. Includes devices on suspended or expired licenses, which keep their activations so the same devices can be used again after the license is resumed; this is not a count of devices that can use the product right now.

1
active_licenses Optional
integer | null
1
active_leases Optional
integer | null
1
UsageReportResponse 1 fields

Schema

object

Example Value

{
  "data": {
    "period": {},
    "new_activations": 1,
    "active_machines": 1,
    "active_licenses": 1,
    "active_leases": 1
  }
}
FieldRequiredType and descriptionExample Value
data Required { "period": {}, "new_activations": 1, "active_machines": 1, "active_licenses": 1, "active_leases": 1 }
UsageReportListResponse 2 fields

Schema

object

Example Value

{
  "data": [
    {
      "period": {},
      "new_activations": 1,
      "active_machines": 1,
      "active_licenses": 1,
      "active_leases": 1
    }
  ],
  "pagination": {
    "next_cursor": "string",
    "has_more": true
  }
}
FieldRequiredType and descriptionExample Value
data Required
array<UsageReport>
[ { "period": {}, "new_activations": 1, "active_machines": 1, "active_licenses": 1, "active_leases": 1 } ]
pagination Required { "next_cursor": "string", "has_more": true }
ProductInput 4 fields

Schema

object

Example Value

{
  "name": "Example name",
  "code": "string",
  "description": "Example description",
  "environment": "string"
}
FieldRequiredType and descriptionExample Value
name Optional
string
"Example name"
code Optional
string
"string"
description Optional
string
"Example description"
environment Optional
string
"string"
ProductBrowserRuntimeInput 2 fields

Schema

object

Example Value

{
  "enabled": true,
  "allowed_origins": [
    "string"
  ]
}
FieldRequiredType and descriptionExample Value
enabled Optional
boolean
true
allowed_origins Optional
array<string> Maximum items: 20
[ "string" ]
ProductTrialSignupInput 2 fields

Schema

object

Example Value

{
  "policy_id": "01K5QWERTY1234567890ABCDEFG",
  "daily_limit": 1
}
FieldRequiredType and descriptionExample Value
policy_id Optional
string | null Maximum length: 64

The trial policy to accept trials with: an active trial policy of this product that uses license keys. null or an empty string stops accepting trials.

"01K5QWERTY1234567890ABCDEFG"
daily_limit Optional
integer | null Minimum: 1 Maximum: 1000

The most trials the app can start in any 24 hours, from 1 to 1000. null resets it to the default 20.

1
PolicyInput 20 fields

Schema

object

Example Value

{
  "product_id": "product_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "license_type": "string",
  "validation_mode": "string",
  "fail_mode": "string",
  "max_machines": 1,
  "max_concurrent": 1,
  "concurrency_unit": "string",
  "identity_mode": "string",
  "license_unit_limit": 1,
  "cert_ttl_sec": 1,
  "heartbeat_sec": 1,
  "lease_ttl_sec": 1,
  "lease_heartbeat_sec": 1,
  "network_grace_sec": 1,
  "fingerprint_profile": "standard",
  "renewal_authority": "string",
  "billing_cycle": "string",
  "trial_days": 1,
  "entitlements": {}
}
FieldRequiredType and descriptionExample Value
product_id Optional "product_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
license_type Optional
string
"string"
validation_mode Optional
string

For a perpetual node-locked policy, offline selects offline_unmanaged. Use periodic or online for managed perpetual licensing. Named-user perpetual policies must be managed.

"string"
fail_mode Optional
string
"string"
max_machines Optional
integer | null
1
max_concurrent Optional
integer | null
1
concurrency_unit Optional
string
"string"
identity_mode Optional
string
"string"
license_unit_limit Optional
integer | null
1
cert_ttl_sec Optional
integer | null
1
heartbeat_sec Optional
integer | null
1
lease_ttl_sec Optional
integer | null
1
lease_heartbeat_sec Optional
integer | null
1
network_grace_sec Optional
integer | null
1
fingerprint_profile Optional
string | object

Send the device identification profile as a profile name string, for example standard. It is stored and returned as {"profile": name}. An object is listed only for compatibility with the earlier schema: an object or array is refused with 422 VALIDATION_FAILED, and risk_policy cannot be set through this API.

"standard"
renewal_authority Optional
string
"string"
billing_cycle Optional
string
"string"
trial_days Optional
integer | null
1
entitlements Optional
object
{}
CustomerInput 4 fields

Schema

object

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "notes": "string"
}
FieldRequiredType and descriptionExample Value
name Optional
string
"Example name"
email Optional
string
"developer@example.com"
external_ref Optional
string
"string"
notes Optional
string
"string"
LicenseUpdateInput 10 fields

Schema

object

Example Value

{
  "expires_at": "2026-09-21T00:00:00Z",
  "expiry": "2026-09-21T00:00:00Z",
  "renewal_authority": "string",
  "max_machines_override": 1,
  "max_concurrent_override": 1,
  "license_unit_limit_override": 1,
  "entitlements": {},
  "metadata": {},
  "status_action": "active",
  "reason": "string"
}
FieldRequiredType and descriptionExample Value
expires_at Optional
string | null date-time

Subscription expiry. Use `null` for no expiry. On Evaluation, it must be within 1 hour of issuance.

"2026-09-21T00:00:00Z"
expiry Optional
string | null date-time

Legacy name for `expires_at`. Use `expires_at`; when both are provided, `expires_at` takes precedence.

"2026-09-21T00:00:00Z"
renewal_authority Optional
string
"string"
max_machines_override Optional
integer | null
1
max_concurrent_override Optional
integer | null
1
license_unit_limit_override Optional
integer | null
1
entitlements Optional
object
{}
metadata Optional
object
{}
status_action Optional
string
"active"
reason Optional
string
"string"
ResellerInput 7 fields

Schema

object

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "organization_limit": 1,
  "user_limit": 1,
  "status": "active",
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
name Optional
string
"Example name"
email Optional
string
"developer@example.com"
external_ref Optional
string
"string"
organization_limit Optional
integer | null
1
user_limit Optional
integer | null
1
status Optional
string
"active"
metadata Optional
object
{}
OrganizationInput 7 fields

Schema

object

Example Value

{
  "name": "Example name",
  "email": "developer@example.com",
  "external_ref": "string",
  "user_limit": 1,
  "reseller_id": "reseller_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
name Optional
string
"Example name"
email Optional
string
"developer@example.com"
external_ref Optional
string
"string"
user_limit Optional
integer | null
1
reseller_id Optional
PublicId | null
"reseller_id_aaaaaaaaaaaaaaaaaaaa"
status Optional
string
"active"
metadata Optional
object
{}
OrganizationGroupInput 4 fields

Schema

object

Example Value

{
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "name": "Example name",
  "status": "active",
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
organization_id Optional "organization_id_aaaaaaaaaaaaaaaaaaaa"
name Optional
string
"Example name"
status Optional
string
"active"
metadata Optional
object
{}
OrganizationGroupMembershipInput 1 fields

Schema

object

Example Value

{
  "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa"
}
FieldRequiredType and descriptionExample Value
license_user_id Optional "license_user_id_aaaaaaaaaaaaaaaaaaaa"
LicenseUserInput 8 fields

License users are shared by the live and test environments. A test API key cannot change a license user who holds a seat on a live license, including suspending or deprovisioning it (403 ENVIRONMENT_MISMATCH). POST with an issuer and subject that already exist updates that user, so the same refusal applies to it.

Schema

object

Example Value

{
  "issuer": "string",
  "subject": "string",
  "email": "developer@example.com",
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "oidc_connection_id": "oidc_connection_id_aaaaaaaaaaaaaaaaaaaa",
  "status": "active",
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
issuer Optional
string
"string"
subject Optional
string
"string"
email Optional
string
"developer@example.com"
name Optional
string
"Example name"
organization_id Optional
PublicId | null
"organization_id_aaaaaaaaaaaaaaaaaaaa"
oidc_connection_id Optional
PublicId | null

Set this to associate the user with an OIDC connection. Team or higher with the `oidc_sso` entitlement is required. On Personal, omit it or use `null`; otherwise the API returns HTTP 403 (`PLAN_ENTITLEMENT_REQUIRED`).

"oidc_connection_id_aaaaaaaaaaaaaaaaaaaa"
status Optional
string
"active"
metadata Optional
object
{}
OidcConnectionCreateInput 14 fields

Schema

object

Example Value

{
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "issuer": "string",
  "client_id": "01K5QWERTY1234567890ABCDEFG",
  "client_secret": "example-token",
  "authorization_endpoint": "https://example.com/resource",
  "token_endpoint": "https://example.com/resource",
  "jwks_uri": "https://example.com/resource",
  "pkce_required": true,
  "jit_provisioning": true,
  "status": "active",
  "scopes": [
    "string"
  ],
  "allowed_audiences": [
    "string"
  ],
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
name Optional
string
"Example name"
organization_id Optional
PublicId | null
"organization_id_aaaaaaaaaaaaaaaaaaaa"
issuer Optional
string
"string"
client_id Optional
string
"01K5QWERTY1234567890ABCDEFG"
client_secret Required
string
"example-token"
authorization_endpoint Optional
string
"https://example.com/resource"
token_endpoint Optional
string
"https://example.com/resource"
jwks_uri Optional
string
"https://example.com/resource"
pkce_required Optional
boolean
true
jit_provisioning Optional
boolean
true
status Optional
string
"active"
scopes Optional
array<string>
[ "string" ]
allowed_audiences Optional
array<string>
[ "string" ]
metadata Optional
object
{}
OidcConnectionUpdateInput 14 fields

Schema

object

Example Value

{
  "client_secret": "example-token",
  "name": "Example name",
  "organization_id": "organization_id_aaaaaaaaaaaaaaaaaaaa",
  "issuer": "string",
  "client_id": "01K5QWERTY1234567890ABCDEFG",
  "authorization_endpoint": "https://example.com/resource",
  "token_endpoint": "https://example.com/resource",
  "jwks_uri": "https://example.com/resource",
  "pkce_required": true,
  "jit_provisioning": true,
  "status": "active",
  "scopes": [
    "string"
  ],
  "allowed_audiences": [
    "string"
  ],
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
client_secret Optional
string

Send this only when you change the settings used to verify portal users. The value is saved with the change and never returned.

"example-token"
name Optional
string
"Example name"
organization_id Optional
PublicId | null
"organization_id_aaaaaaaaaaaaaaaaaaaa"
issuer Optional
string
"string"
client_id Optional
string
"01K5QWERTY1234567890ABCDEFG"
authorization_endpoint Optional
string
"https://example.com/resource"
token_endpoint Optional
string
"https://example.com/resource"
jwks_uri Optional
string
"https://example.com/resource"
pkce_required Optional
boolean
true
jit_provisioning Optional
boolean
true
status Optional
string
"active"
scopes Optional
array<string>
[ "string" ]
allowed_audiences Optional
array<string>
[ "string" ]
metadata Optional
object
{}
OidcClientSecretRotationInput 1 fields

Schema

object

Example Value

{
  "client_secret": "example-token"
}
FieldRequiredType and descriptionExample Value
client_secret Required
string
"example-token"
LicenseAssignmentInput 5 fields

Schema

object

Example Value

{
  "license_user_id": "license_user_id_aaaaaaaaaaaaaaaaaaaa",
  "source_group_id": "source_group_id_aaaaaaaaaaaaaaaaaaaa",
  "expires_at": "2026-09-21T00:00:00Z",
  "entitlement_overrides": {},
  "metadata": {}
}
FieldRequiredType and descriptionExample Value
license_user_id Optional "license_user_id_aaaaaaaaaaaaaaaaaaaa"
source_group_id Optional
PublicId | null
"source_group_id_aaaaaaaaaaaaaaaaaaaa"
expires_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
entitlement_overrides Optional
object
{}
metadata Optional
object
{}
WebhookInput 3 fields

Schema

object

Example Value

{
  "name": "Example name",
  "url": "https://example.com/resource",
  "events": [
    "string"
  ]
}
FieldRequiredType and descriptionExample Value
name Optional
string
"Example name"
url Optional
string uri
"https://example.com/resource"
events Optional
array<string>
[ "string" ]
WebhookSecretRotationInput 1 fields

Schema

object

Example Value

{
  "activates_at": "2026-09-21T00:00:00Z"
}
FieldRequiredType and descriptionExample Value
activates_at Optional
string date-time
"2026-09-21T00:00:00Z"
TrialConversionInput 3 fields

Schema

object

Example Value

{
  "target_policy_id": "target_policy_id_aaaaaaaaaaaaaaaaaaaa",
  "expires_at": "2026-09-21T00:00:00Z",
  "entitlement_overrides": {}
}
FieldRequiredType and descriptionExample Value
target_policy_id Optional "target_policy_id_aaaaaaaaaaaaaaaaaaaa"
expires_at Optional
string | null date-time
"2026-09-21T00:00:00Z"
entitlement_overrides Optional
object
{}
LicenseIssueResponse 1 fields

Schema

object

Example Value

{
  "data": {}
}
FieldRequiredType and descriptionExample Value
data Required
License + object
{}
WebhookSecretResponse 1 fields

Schema

object

Example Value

{
  "data": {}
}
FieldRequiredType and descriptionExample Value
data Required
Webhook + object
{}