Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Response

What is due next, or nulls when nothing is scheduled.

What this organisation owes next, as the payment provider states it.

currentPeriodEnd
string<date-time> | null
required

When the period now running ends, which is when the next bill lands. Null when nothing is scheduled: an organisation whose purchases are all pay as you go has no upcoming invoice, and neither has one that has ended everything.

amountMinor
integer | null
required

The total, in the currency's MINOR unit, exactly as the payment provider states it. Nothing on this side computes, estimates or annualises it. Null when nothing is scheduled.

currency
string | null
required

ISO 4217, lower case. Null when nothing is scheduled.

lineCount
integer
required

How many lines the next bill has, in ROWS. Zero when nothing is scheduled.