Place a pass window by hand
/v1/projects/{project}/plans/{plan}/pass-windows in the Pass Windows API.
Places a window by hand on a kind: pass plan. This is how schedule_mode: fixed gets its dates, and how a repeating plan gets the one-off that does not fit its pattern.
curl -X POST https://api.subscriby.net/v1/projects/$PROJECT_ID/plans/$PLAN_ID/pass-windows \ -H "Authorization: Bearer $SUBSCRIBY_TOKEN" \ -H "Idempotency-Key: $(uuidgen)" \ -H "Content-Type: application/json" \ -d '{ "starts_at": "2026-09-20 09:00", "duration_minutes": 180 }'Answers 201 with the new window: status: scheduled, source: manual, holders: 0. The request above and "starts_at": "2026-09-20T09:00:00-04:00" describe the same instant for a plan in America/New_York, and both come back as "2026-09-20T13:00:00+00:00". Raises pass.window_scheduled with source: manual.
A manual window is never touched by regeneration: editing pass.slots on the plan rebuilds the generated windows and leaves this one where you put it. Every pass series with a rule is asked to look at the new date afterwards, so a matching series absorbs it as described on the Plans page.
Each refusal below is a 422 VALIDATION_FAILED naming the field, the same wording the dashboard's panel shows.
Requires ability
The token must hold this ability, or the call is refused with 403.
Fires one event
Delivered to every endpoint subscribed to it once the change is made.
MCP tool
Runs the same action from an agent, behind the same ability.
Idempotent
Send the header on every call; the same key replays the original response for 24 hours.
Authorization
bearerToken A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.
In: header
Path Parameters
The project, resolved by the route binder.
uuidThe plan, resolved within the project.
uuidHeader Parameters
A key unique to this operation, such as a fresh UUID. The same key replays the original 2xx response for 24 hours (with Idempotent-Replay: true), so a retry after a timeout never repeats the write; the same key with a different body is refused with 409.
uuidRequest body
JSONWhat the request carriesRequiredapplication/json
A window to place by hand on a time-limited pass plan: when it starts and how long it lasts.
Responses
201Createdapplication/json
The window.
400Bad requestIDEMPOTENCY_KEY_MISSINGapplication/json
Every write needs an Idempotency-Key header. Send a fresh UUID per distinct operation.
401UnauthorizedAUTHENTICATION_REQUIREDapplication/json
The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).
403ForbiddenTOKEN_MISSING_ABILITYapplication/json
The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.
404Not foundRESOURCE_NOT_FOUNDapplication/json
An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.
409ConflictIDEMPOTENCY_KEY_REUSEDapplication/json
The key was already used in the last 24 hours with a different request body.
422Validation failedVALIDATION_FAILEDapplication/json
The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields.
On this endpoint: VALIDATION_FAILED: when the plan is not a time-limited pass: a subscription or a series has no windows of its own. VALIDATION_FAILED: when the start is in the past, judged in the plan's own zone. VALIDATION_FAILED: when the length is under the plan's floor or over its ceiling (5 minutes and 30 days by default). VALIDATION_FAILED: when the plan already has a window starting at that instant. VALIDATION_FAILED: when the plan stops selling a fixed number of minutes before a window **ends** and the window is not longer than that cutoff, so it would never be on sale while it runs.
425Too earlyIDEMPOTENCY_REPLAY_IN_PROGRESSapplication/json
The first request with this key is still running; retry in a few seconds and the original response is replayed.
429Too many requestsRATE_LIMITEDapplication/json
The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.
How is this guide?
Last updated on