A valid request URL is required to generate request examples{
"data": {
"device_id": "dev_demo_a",
"device_version": 12,
"proxy": {
"id": "px_demo_1",
"version": 7,
"name": "US egress 01",
"lifecycle": "active",
"country_code": "US",
"egress_ip": "203.0.113.24",
"service_window": {
"starts_at": "2026-10-01T00:00:00Z",
"ends_at": "2026-10-31T00:00:00Z",
"duration_seconds": 2592000
},
"renewal_mode": "manual",
"binding": {
"state": "connected",
"device_id": "dev_demo_a",
"operation_id": null,
"observed_egress_ip": "203.0.113.24",
"verified_at": "2026-10-01T00:00:00Z",
"message": null
},
"acquired_order_id": "po_demo_ready",
"created_at": "2026-10-01T00:00:00Z",
"updated_at": "2026-10-01T00:00:00Z",
"archived_at": null,
"allowed_actions": [
{
"action": "unbind",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "transfer",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "renew",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "rename",
"allowed": true,
"reason_code": null,
"message": null
}
]
},
"binding": {
"state": "connected",
"device_id": "dev_demo_a",
"operation_id": null,
"observed_egress_ip": "203.0.113.24",
"verified_at": "2026-10-01T00:00:00Z",
"message": null
},
"change_eligibility": {
"allowed": true,
"reason_code": null,
"message": null
},
"allowed_actions": [
{
"action": "replace",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "unbind",
"allowed": true,
"reason_code": null,
"message": null
}
]
},
"snapshot": {
"freshness": "fresh",
"observed_at": "2026-10-01T00:00:00Z",
"served_at": "2026-10-01T00:00:00Z",
"message": null
},
"request_id": "req_demo_1"
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}Read a device's confirmed Proxy relationship
Requires a first-party interactive organization session with devices:read. Financial commands require an administrator and the configured checkout step-up policy. Network commands also require devices:act, current device authority and explicit consent. New purchase/connection commands require current admission. No credentials are returned. A deployment without the durable composition returns capability_unavailable (422). Renewal, order target/delivery edits, operation resume and event feeds are not available. Preserve command identity after an uncertain reply and read the original order or operation.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"data": {
"device_id": "dev_demo_a",
"device_version": 12,
"proxy": {
"id": "px_demo_1",
"version": 7,
"name": "US egress 01",
"lifecycle": "active",
"country_code": "US",
"egress_ip": "203.0.113.24",
"service_window": {
"starts_at": "2026-10-01T00:00:00Z",
"ends_at": "2026-10-31T00:00:00Z",
"duration_seconds": 2592000
},
"renewal_mode": "manual",
"binding": {
"state": "connected",
"device_id": "dev_demo_a",
"operation_id": null,
"observed_egress_ip": "203.0.113.24",
"verified_at": "2026-10-01T00:00:00Z",
"message": null
},
"acquired_order_id": "po_demo_ready",
"created_at": "2026-10-01T00:00:00Z",
"updated_at": "2026-10-01T00:00:00Z",
"archived_at": null,
"allowed_actions": [
{
"action": "unbind",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "transfer",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "renew",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "rename",
"allowed": true,
"reason_code": null,
"message": null
}
]
},
"binding": {
"state": "connected",
"device_id": "dev_demo_a",
"operation_id": null,
"observed_egress_ip": "203.0.113.24",
"verified_at": "2026-10-01T00:00:00Z",
"message": null
},
"change_eligibility": {
"allowed": true,
"reason_code": null,
"message": null
},
"allowed_actions": [
{
"action": "replace",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "unbind",
"allowed": true,
"reason_code": null,
"message": null
}
]
},
"snapshot": {
"freshness": "fresh",
"observed_at": "2026-10-01T00:00:00Z",
"served_at": "2026-10-01T00:00:00Z",
"message": null
},
"request_id": "req_demo_1"
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "version_conflict",
"message": "The device or resource changed. Refresh its status before confirming again.",
"request_id": "req_demo_2",
"details": {
"retryable": false,
"recovery_action": "refresh_and_confirm",
"resource_versions": {
"px_demo_1": 8
},
"device_versions": {
"dev_demo_a": 13,
"dev_demo_b": 4
}
}
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Path Parameters
Opaque organization-scoped identifier.
Response
Authorized current projection.
Show child attributes
Show child attributes
{
"device_id": "dev_demo_a",
"device_version": 12,
"proxy": {
"id": "px_demo_1",
"version": 7,
"name": "US egress 01",
"lifecycle": "active",
"country_code": "US",
"egress_ip": "203.0.113.24",
"service_window": {
"starts_at": "2026-10-01T00:00:00Z",
"ends_at": "2026-10-31T00:00:00Z",
"duration_seconds": 2592000
},
"renewal_mode": "manual",
"binding": {
"state": "connected",
"device_id": "dev_demo_a",
"operation_id": null,
"observed_egress_ip": "203.0.113.24",
"verified_at": "2026-10-01T00:00:00Z",
"message": null
},
"acquired_order_id": "po_demo_ready",
"created_at": "2026-10-01T00:00:00Z",
"updated_at": "2026-10-01T00:00:00Z",
"archived_at": null,
"allowed_actions": [
{
"action": "unbind",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "transfer",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "renew",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "rename",
"allowed": true,
"reason_code": null,
"message": null
}
]
},
"binding": {
"state": "connected",
"device_id": "dev_demo_a",
"operation_id": null,
"observed_egress_ip": "203.0.113.24",
"verified_at": "2026-10-01T00:00:00Z",
"message": null
},
"change_eligibility": {
"allowed": true,
"reason_code": null,
"message": null
},
"allowed_actions": [
{
"action": "replace",
"allowed": true,
"reason_code": null,
"message": null
},
{
"action": "unbind",
"allowed": true,
"reason_code": null,
"message": null
}
]
}
Show child attributes
Show child attributes
Opaque organization-bound identifier.
1 - 128^[A-Za-z0-9][A-Za-z0-9_-]*$