Retrieve the subscription

View as Markdown
Returns the workspace's current subscription: a status of `active`, `trialing` or `past_due`. Returns `subscription: null` when there is none (never subscribed, canceled, or a trial that ended without payment). Payment-processor ids are never returned. Use it to decide between the two paths: with a subscription, change the plan with `POST /api/billing/change-plan`. Without one, subscribe from the dashboard. The caps here are the base plan values: `max_agents` does **not** include purchased agent add-ons. Use `GET /api/billing/limits` for the numbers that are actually enforced. **Consistency.** Cached server-side for up to 5 minutes. The cache is cleared by `POST /api/billing/change-plan` and by payment-processor subscription events, so a change made elsewhere normally shows within seconds. **Access** - **Required scope:** `read`. Available to every workspace role. - **Rate limit:** Billing — 15 requests/min per workspace, shared by every `/api/billing` route. See [Rate limits](/rate-limits). - **Plan:** Available on every plan, including workspaces with no plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Response

The current subscription, or null.
dataobject

Errors

401
Unauthorized Error
403
Forbidden Error
429
Too Many Requests Error