List a project's pass windows
/v1/projects/{project}/pass-windows in the Pass Windows API.
curl "https://api.subscriby.net/v1/projects/$PROJECT_ID/pass-windows?status=scheduled&sellable_only=true" \ -H "Authorization: Bearer $SUBSCRIBY_TOKEN"The project's windows across every pass plan, soonest first, 50 per page (per_page 1 to 100; limit is accepted as an alias). Filters are validated before they reach the query: an unknown status or a malformed date is a 422 VALIDATION_FAILED naming the field, not an empty page.
The list also opens to
project-subscription-plan:view-any. The list shipped under the plan ability before thepass-window:*family had any surface, and it is what the n8n node and the MCP tool docs named. A token holding onlyproject-subscription-plan:view-anytherefore still satisfies thepass-window:view-anygate. Mint new tokens with the precise ability; the alias exists so old ones keep working.
Requires ability
The token must hold this ability, or the call is refused with 403.
MCP tool
Runs the same action from an agent, behind the same ability.
Authorization
bearerToken A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.
In: header
Path Parameters
The project, resolved by the route binder.
uuidQuery Parameters
One pass plan of the project only.
uuidOne state only: scheduled, open, closed or canceled. Anything else is refused.
Only windows starting at or after this moment, ISO 8601.
date-timeOnly windows starting at or before this moment, ISO 8601.
date-timeKeep only windows a buyer could still purchase.
The 1-based page to return. A page past the last answers an empty data array with meta.total still filled, so a loop can stop without guessing.
1 <= value1Rows per page, 1 to 100. A higher value clamps to the cap silently. Defaults to 50.
1 <= value <= 10050The column to order by. Defaults to created_at; a column the endpoint does not offer falls back to the default rather than failing.
"created_at"asc or desc. Defaults to desc.
"desc"Value in
- "asc"
- "desc"
Legacy alias of per_page, kept for clients that predate it. per_page wins when both are sent.
1 <= value <= 100Responses
200OKapplication/json
The page, soonest first.
401UnauthorizedAUTHENTICATION_REQUIREDapplication/json
The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).
403ForbiddenTOKEN_MISSING_ABILITYapplication/json
The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.
404Not foundRESOURCE_NOT_FOUNDapplication/json
An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.
422Validation failedVALIDATION_FAILEDapplication/json
The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields.
On this endpoint: VALIDATION_FAILED: when status is not one of the four states, plan_id is not a UUID, or from or to is not a date.
429Too many requestsRATE_LIMITEDapplication/json
The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.
How is this guide?
Last updated on