Version
GET

List a project's pass windows

/v1/projects/{project}/pass-windows in the Pass Windows API.

curl "https://api.subscriby.net/v1/projects/$PROJECT_ID/pass-windows?status=scheduled&sellable_only=true" \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN"

The project's windows across every pass plan, soonest first, 50 per page (per_page 1 to 100; limit is accepted as an alias). Filters are validated before they reach the query: an unknown status or a malformed date is a 422 VALIDATION_FAILED naming the field, not an empty page.

The list also opens to project-subscription-plan:view-any. The list shipped under the plan ability before the pass-window:* family had any surface, and it is what the n8n node and the MCP tool docs named. A token holding only project-subscription-plan:view-any therefore still satisfies the pass-window:view-any gate. Mint new tokens with the precise ability; the alias exists so old ones keep working.

GET
/v1/projects/{project}/pass-windows

Requires ability

The token must hold this ability, or the call is refused with 403.

Runs the same action from an agent, behind the same ability.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Path Parameters

project*string

The project, resolved by the route binder.

Formatuuid

Query Parameters

plan_id?|

One pass plan of the project only.

Formatuuid
status?|

One state only: scheduled, open, closed or canceled. Anything else is refused.

from?|

Only windows starting at or after this moment, ISO 8601.

Formatdate-time
to?|

Only windows starting at or before this moment, ISO 8601.

Formatdate-time
sellable_only?boolean

Keep only windows a buyer could still purchase.

page?integer

The 1-based page to return. A page past the last answers an empty data array with meta.total still filled, so a loop can stop without guessing.

Range1 <= value
Default1
per_page?integer

Rows per page, 1 to 100. A higher value clamps to the cap silently. Defaults to 50.

Range1 <= value <= 100
Default50
sort_by?string

The column to order by. Defaults to created_at; a column the endpoint does not offer falls back to the default rather than failing.

Default"created_at"
sort_direction?string

asc or desc. Defaults to desc.

Default"desc"

Value in

  • "asc"
  • "desc"
limit?integer

Legacy alias of per_page, kept for clients that predate it. per_page wins when both are sent.

Range1 <= value <= 100

Responses

200OK

The page, soonest first.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.

404Not found

An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.

422Validation failed

The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields. On this endpoint: VALIDATION_FAILED: when status is not one of the four states, plan_id is not a UUID, or from or to is not a date.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on