Skip to main content
GET
List standing authorisations, newest first, optionally filtered.

Authorizations

Authorization
string
header
required

Authorization: Bearer vsk_live_…. Chosen over a bespoke X-API-KEY header because every client, proxy and log-redaction rule already knows this one. What a key may DO is its scopes — see x-scopes at the root of this document and x-required-scope on each operation. The scope list is not written here because OpenAPI reserves a requirement’s scope array for oauth2 and openIdConnect and requires it to be empty for an http scheme.

Query Parameters

limit
integer
default:25

How many to return. A value outside the range is refused, not clamped. How many authorisations to return.

Required range: 1 <= x <= 100
cursor
string<uuid>

The next_cursor from the previous page. Opaque. Where to resume.

status
enum<string>

Only authorisations in this status. An unknown value is refused, not answered with an empty page. One status.

Available options:
invited,
active,
declined,
expired_unsigned,
cancelled,
revoked,
expired,
invalidated
brand_id
string<uuid>

Only authorisations covering this brand. A brand id.

reference
string

Only authorisations whose reference is exactly this, compared in Unicode NFC. Your reference.

Required string length: 1 - 255
Example:

"ntt-signatory-2026"

Response

A page of authorisations, newest first, with the cursor for the next.

The page.

data
object[]
required

The authorisations on this page.

has_more
boolean
required

Whether another page follows.

next_cursor
string<uuid> | null
required

Pass as cursor for the next page; null on the last. Opaque.