Version
GET

Get a token

/v1/tokens/{token} in the Tokens API.

curl https://api.subscriby.net/v1/tokens/$TOKEN_ID \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN"

One of the caller's tokens, without its value.

  • id is an integer serialised as a string, the one identifier in the platform that is not a UUID. See Identifiers.
  • abilities is the gate strings only. Scope tuples (scope:team:…, scope:project:…) are split out into scopes for readability, so abilities_count counts real permissions rather than bookkeeping.
  • The plaintext value is never returned here. Lose it and the only recovery is to revoke the token and mint another.
GET
/v1/tokens/{token}

Requires ability

The token must hold this ability, or the call is refused with 403.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Path Parameters

token*integer

One of the caller's tokens, resolved by the route binder.

Responses

200OK

The token resource.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.

404Not found

An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on