Version
READ

list_access_codes

Paginated list of access codes for a plan, with first/last-4 masked prefixes only — full codes are never surfaced.

List access codes for a plan. Requires plan_id, accepts an optional status filter (unredeemed, redeemed, expired, or all). Results are scoped to the caller's team.

Codes are returned with a masked prefix (first 4 + asterisks + last 4). The plaintext value is delivered to the creator's connector chat by bulk_generate_access_codes — the MCP layer is read-only on the secret itself.

The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.

The REST endpoint and this tool share one action, so validation, permissions and events are identical.

Annotations

Read-only

It reads and never changes anything.

Arguments

plan_id*string

UUID of the plan to list codes for.

statusstringoptional

Filter by code state. One of: unredeemed, redeemed, expired, all.

allunredeemedredeemedexpired
limitintegeroptional

Maximum codes to return per page (1..100).

min1max100
pageintegeroptional

1-indexed page number.

min1

What it returns

{  "data": [    {      "id": "5b7e2d40-1a86-4c39-97f2-e83d0b16c5a4",      "plan_id": "c4e82f16-93a7-4d5b-b81c-6e0f27a94d3b",      "code_masked": "A3F1****7Z9P",      "redeemed_at": null,      "expires_at": "2026-08-01T00:00:00Z",      "redeemed_by": null,      "created_at": "2026-05-18T10:05:00Z"    }  ],  "meta": {    "page": 1,    "limit": 25,    "total": 47,    "has_more": true,    "status": "unredeemed"  }}

How it fails

TOKEN_MISSING_ABILITY

token lacks project-access-code:view-any.

How is this guide?

Last updated on