Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

id
string
required

The order id, as GET /v1/fulfilments reports it.

Response

Verified current renewal state.

Fresh Stripe-backed renewal state for one paid monthly Cloud order. invoiceReview is omitted for a current paid invoice.

renews
boolean
required

Whether the subscription still schedules a future renewal. An already open invoice may collect even when false.

paidThrough
string<date-time>
required

End of the latest verified paid Stripe invoice period. This date may be in the past when an invoice needs review; supplier availability is checked separately.

invoiceReview
boolean

Present and true when the latest subscription invoice is draft or open and needs review. A draft may precede any charge attempt; an open invoice can still collect after renewal is turned off.