Skip to main content
GET
Error

Authorizations

Authorization
string
header
required

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Headers

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Response

The plan and its entitlements.

plan
enum<string>

unknown means entitlements could not be resolved, and everything is enabled.

Available options:
free,
pro,
unknown
resolved
boolean

false when this is the fail-open default rather than a plan's answer — the same case plan: unknown names, said in a field a client can branch on. The body is still complete and still truthful: UserKit's own catalogue is compiled in, so every feature is here with every ceiling gone. What the field buys is a screen not presenting an outage as an upgrade.

features
object

Keyed by feature key.