A valid request URL is required to generate request examples{
"billingPeriod": "<string>",
"asOf": "2023-11-07T05:31:56Z",
"totals": {
"activeMs": 123,
"leaseCount": 123,
"deviceCount": 123,
"reportedMinutes": 123
},
"devices": [
{
"deviceId": "<string>",
"backendKind": "<string>",
"activeMs": 123,
"leaseCount": 123,
"reportedMinutes": 123
}
],
"concurrency": {
"limit": 123,
"inUse": 123
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Read your org's usage this period
Settled usage for the current billing period, per device, derived from the same per-lease rows billing reads. Built for a headless integrator: the hosted product shows this in a browser, and this endpoint is how you read it without one.
activeMs is measured active time, corrections already applied, which is the quantity this control plane measures and therefore the one it reports. reportedMinutes is minutes AS ALREADY REPORTED to billing, echoed rather than recalculated here, because the per-lease rounding rule has a single owner and a second implementation of it would be a second source of truth for an invoice. It is ABSENT until reporting has happened, which is a different fact from zero: read it as not reported yet, never as free.
Only settled leases appear. A lease you are holding right now is still open and is not in these numbers, so this is an account of what has finished rather than a live meter.
A key narrowed to a subset of devices sees only that subset.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"billingPeriod": "<string>",
"asOf": "2023-11-07T05:31:56Z",
"totals": {
"activeMs": 123,
"leaseCount": 123,
"deviceCount": 123,
"reportedMinutes": 123
},
"devices": [
{
"deviceId": "<string>",
"backendKind": "<string>",
"activeMs": 123,
"leaseCount": 123,
"reportedMinutes": 123
}
],
"concurrency": {
"limit": 123,
"inUse": 123
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Response
This period's usage.
Settled usage for one billing period, plus the live concurrency reading. Open leases are absent from the settled half: it is an account of what has finished, not a live meter.
The UTC month these rows settle into, as YYYY-MM-DD.
Database clock at read time, so you can judge freshness.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
The concurrency ceiling and what is against it. THE ONE LIVE READING in this body: everything else here is settled work, and this is the state of the fleet as the read happened.
limit is the ceiling the run gate actually enforces, read from the gate rather than reproduced beside it. It is org wide, and a credential narrowed to a subset of devices still sees the whole organisation's numbers, because the whole ceiling is what its next run meets.
inUse below limit IS NOT A PROMISE that a run will start. A device may already be driving one, and a lease may be held elsewhere; those are separate refusals, and starting the run is the only thing that answers them.
ABSENT on a deployment with no agent tier composed, which is a different fact from a ceiling of zero.
Show child attributes
Show child attributes