Version
GET

List referrals

/v1/projects/{project}/referrals in the Referral Program API.

curl "https://api.subscriby.net/v1/projects/7f3d1c92-8b45-4e6a-9d21-5c8e0a4b6f13/referrals?status=converted&since=2026-10-01" \  -H "Authorization: Bearer sbt_..."

Pages the friends affiliates brought in, newest first. status is touched, converted, expired or rejected; affiliate_id narrows to one affiliate; since keeps the referrals whose friend arrived on or after that instant, so a report can page only what happened after its last run.

GET
/v1/projects/{project}/referrals

The token must hold this ability, or the call is refused with 403.

Run the same action from an agent, behind the same ability.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Path Parameters

project*string

The project, resolved by the route binder.

Formatuuid

Query Parameters

status?ReferralStatus

Keep only referrals in this state: touched (the friend arrived, not yet paid), converted (their first payment settled), expired (the attribution window passed) or rejected.

Value in

  • "touched"
  • "converted"
  • "expired"
  • "rejected"
affiliate_id?string

Keep only the referrals one affiliate brought in.

Formatuuid
since?string

Keep only referrals whose friend arrived on or after this instant, ISO 8601, so a report can page what happened since its last run.

Formatdate-time
page?integer

The 1-based page to return. A page past the last answers an empty data array with meta.total still filled, so a loop can stop without guessing.

Range1 <= value
Default1
per_page?integer

Rows per page, 1 to 100. A higher value clamps to the cap silently. Defaults to 25.

Range1 <= value <= 100
Default25
sort_by?string

The column to order by. Defaults to created_at; a column the endpoint does not offer falls back to the default rather than failing.

Default"created_at"
sort_direction?string

asc or desc. Defaults to desc.

Default"desc"

Value in

  • "asc"
  • "desc"
limit?integer

Legacy alias of per_page, kept for clients that predate it. per_page wins when both are sent.

Range1 <= value <= 100

Responses

200OK

The page.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.

404Not found

An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.

422Validation failed

The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on