Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Headers

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Path Parameters

id
string<uuid>
required

The customer, resolved inside the environment above.

Query Parameters

environment
enum<string>
default:live

Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.

Available options:
live,
test

Body

application/json
feature_id
string<uuid>
required

One of your own credit features. A boolean or metered feature answers 422 — neither holds a balance.

amount
integer<int64>
required

Signed and nonzero: positive grants units, negative removes them.

note
string
required

What was agreed. Required and never blank.

Response

The line was appended.

customer_id
string<uuid>
feature_key
string
amount
integer<int64>
balance
integer<int64>

The balance after the correction — folded under the same lock a spend takes, so it is true rather than a moment old.