Returns the workspace’s current subscription: a status of active, trialing or
past_due. Returns subscription: null when there is none (never subscribed, canceled,
or a trial that ended without payment). Payment-processor ids are never returned.
Use it to decide between the two paths: with a subscription, change the plan with
POST /api/billing/change-plan. Without one, subscribe from the dashboard. The caps
here are the base plan values: max_agents does not include purchased agent add-ons.
Use GET /api/billing/limits for the numbers that are actually enforced.
Consistency. Cached server-side for up to 5 minutes. The cache is cleared by
POST /api/billing/change-plan and by payment-processor subscription events, so a change made
elsewhere normally shows within seconds.
Access
read. Available to every workspace role./api/billing route. See Rate limits.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.