Version
GET

Get a payment method

/v1/projects/{project}/payment-methods/{method} in the Payment Methods API.

The method without its credentials. A method is resolved within the project: a method id that does not belong to the project, or a project outside the caller's tenant, is 404 RESOURCE_NOT_FOUND, so foreign rows never leak.

  • provider is the stored provider key: a gateway slug (stripe, paypal, razorpay, paystack, ceypay, skrill, coinpayments, accesscode) or a connector:provider key for a currency a connector brings (telegram:stars for Telegram Stars). A project carries one method per provider key and mode, so two connectors can each bring their own currency to the same project. Rows created before provider keys existed carried platformcurrency; the connector's data migration rewrites them, and until it has run that word still reads as the native method of the project's connector.
  • connector is the connector behind a native payment method (telegram for a telegram:stars row), null for every gateway and for access codes. A connector declares its native providers through its manifest's native_payments capability, and the dashboard offers one option per provider of every connector that is connected on the project.
  • mode is test or live. Drives which set of provider credentials is used.
  • linked is true once the provider handshake (OAuth callback, API-key verify, etc.) has completed successfully.
  • active is the creator's toggle. A linked-but-inactive method cannot be used to charge subscribers.

Credentials never leave. Provider credentials (API keys, webhook secrets, connected account ids, Stripe Connect onboarding state) live in the encrypted configuration and are never serialised through REST or MCP, even for tokens with view ability. The dashboard is the only surface that reveals them, and only to the creator.

GET
/v1/projects/{project}/payment-methods/{method}

The token must hold this ability, or the call is refused with 403.

Runs the same action from an agent, behind the same ability.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Path Parameters

project*string

The project, resolved by the route binder.

Formatuuid
method*string

The method, resolved within the project by the route binder.

Formatuuid

Responses

200OK

The method without its credentials.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.

404Not found

An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on