A valid request URL is required to generate request examples{
"status": "none",
"since": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Check whether your organisation is provisioned
Your own organisation’s provisioning state, and when it last changed. The console renders one screen per status, so this is the read that decides which one a signed-in user sees.
IT ANSWERS ONLY ABOUT THE CALLER’S OWN ORGANISATION, taken from the verified credential and never from anything the caller supplies. none here is the organisation asking about itself, so it is not a cross-tenant disclosure and this endpoint is not an existence oracle for anybody else.
since is null exactly when status is none and the organisation has never left it.
MOUNTED ON EVERY HOSTED DEPLOYMENT, including one that cannot provision at all: no provisioning dependency configured, or a deployment that is not finished being set up. Those answer 503 with Retry-After, not 404. The route used to vanish on such a deployment, which meant it could not be described here, and an operation absent from this document is one no consumer contract check can protect.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"status": "none",
"since": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Response
Your organisation's provisioning state.
The caller's own organisation's provisioning state.
none never provisioned. pending an order is open and unpaid. active provisioned and not withdrawn. revoked provisioned once and withdrawn since.
none, pending, active, revoked When the organisation entered this state, or null when it has never left none.