Version
GET

List a project's members

/v1/projects/{project}/members in the Members API.

curl "https://api.subscriby.net/v1/projects/$PROJECT_ID/members?status=customer" \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN"

Newest first, paged with page and per_page (default 25; limit is accepted as an alias). status narrows to one lifecycle state. identity looks one member up by the account they connected, connector:external_id, for a workflow that starts from a platform event and needs the member behind an account id; the page then holds that one member with their identities embedded, or no rows.

GET
/v1/projects/{project}/members

Requires ability

The token must hold this ability, or the call is refused with 403.

Run the same action from an agent, behind the same ability.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Path Parameters

project*string

The project, resolved by the route binder.

Formatuuid

Query Parameters

status?|

Narrow the page to one lifecycle state: lead, trialing, customer, churned or banned. Any other value is refused rather than answered with an empty page, so a typo in an automation is noticed.

identity?|

Find the member who connected a given account: the connector key and the platform's own id for the account joined by a colon, connector:123456789. The page then holds that one member with their identities embedded, or no rows when nobody in the project connected that account. A value with no connector before the colon is refused.

Match^[a-z0-9][a-z0-9-]*:\S+$
Lengthlength <= 255
page?integer

The 1-based page to return. A page past the last answers an empty data array with meta.total still filled, so a loop can stop without guessing.

Range1 <= value
Default1
per_page?integer

Rows per page, 1 to 100. A higher value clamps to the cap silently. Defaults to 25.

Range1 <= value <= 100
Default25
sort_by?string

The column to order by. Defaults to created_at; a column the endpoint does not offer falls back to the default rather than failing.

Default"created_at"
sort_direction?string

asc or desc. Defaults to desc.

Default"desc"

Value in

  • "asc"
  • "desc"
limit?integer

Legacy alias of per_page, kept for clients that predate it. per_page wins when both are sent.

Range1 <= value <= 100

Responses

200OK

The page, newest first; one row or none when narrowed to an account, with its connected accounts embedded.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.

404Not found

An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.

422Validation failed

The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields. On this endpoint: VALIDATION_FAILED: when status is not one of the five states, or identity has no connector before the colon.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on