list_access_codes
Paginated list of access codes for a plan, with first/last-4 masked prefixes only — full codes are never surfaced.
List access codes for a plan. Requires plan_id, accepts an optional status filter (unredeemed, redeemed, expired, or all). Results are scoped to the caller's team.
Codes are returned with a masked prefix (first 4 + asterisks + last 4). The
plaintext value is delivered to the creator's connector chat by
bulk_generate_access_codes — the
MCP layer is read-only on the secret itself.
Requires ability
The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.
Runs the same action as
The REST endpoint and this tool share one action, so validation, permissions and events are identical.
Annotations
It reads and never changes anything.
Arguments
plan_id*stringUUID of the plan to list codes for.
statusstringoptionalFilter by code state. One of: unredeemed, redeemed, expired, all.
allunredeemedredeemedexpiredlimitintegeroptionalMaximum codes to return per page (1..100).
1max100pageintegeroptional1-indexed page number.
1What it returns
{ "data": [ { "id": "5b7e2d40-1a86-4c39-97f2-e83d0b16c5a4", "plan_id": "c4e82f16-93a7-4d5b-b81c-6e0f27a94d3b", "code_masked": "A3F1****7Z9P", "redeemed_at": null, "expires_at": "2026-08-01T00:00:00Z", "redeemed_by": null, "created_at": "2026-05-18T10:05:00Z" } ], "meta": { "page": 1, "limit": 25, "total": 47, "has_more": true, "status": "unredeemed" }}How it fails
TOKEN_MISSING_ABILITYtoken lacks project-access-code:view-any.
How is this guide?
Last updated on