Get a pass window
/v1/projects/{project}/pass-windows/{window} in the Pass Windows API.
One window, with sellable and holders resolved for it. A window is resolved within the project: a window id that belongs to another project, another team, or to nothing at all is a 404 RESOURCE_NOT_FOUND, so an id's existence never leaks.
| Field | Type | Notes |
|---|---|---|
starts_at | string | ISO 8601, UTC. Store this. |
ends_at | string | ISO 8601, UTC. |
timezone | string | The IANA zone the plan's schedule was authored in. Render window times in this, never in UTC. |
local_range | string | The same window as a person reads it, already in timezone: what the dashboard, the portal and the bot all print. |
duration_minutes | integer | Derived from the two instants. |
status | string | scheduled, open, closed or canceled. Set by the scheduler as the window's start and end pass; canceled only by an explicit cancel. |
source | string | generated from the plan's slots, or manual when placed by hand. Manual windows survive a schedule rebuild; generated ones are regenerated. |
sellable | boolean | Whether a buyer could purchase this window right now: the plan's sales cutoff, resolved for the whole page in one query rather than per row. |
holders | integer | How many purchases currently hold the window. |
Why both UTC and a local range. A pass schedule is authored in the creator's zone and rendered in it everywhere else in the product. Returning only UTC would leave every consumer converting, and getting it wrong across a daylight-saving boundary.
starts_atis for storing and comparing;local_rangeis for showing.
Requires ability
The token must hold this ability, or the call is refused with 403.
MCP tool
Runs the same action from an agent, behind the same ability.
Authorization
bearerToken A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.
In: header
Path Parameters
The project, resolved by the route binder.
uuidThe window, resolved within the project with its holder count and sale flag.
uuidResponses
200OKapplication/json
The window.
401UnauthorizedAUTHENTICATION_REQUIREDapplication/json
The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).
403ForbiddenTOKEN_MISSING_ABILITYapplication/json
The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.
404Not foundRESOURCE_NOT_FOUNDapplication/json
An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.
429Too many requestsRATE_LIMITEDapplication/json
The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.
How is this guide?
Last updated on