Meet the new Scripe, live on October 7.Register

OpenAPI reference · Health

Authenticated key smoke test

GET/health/auth

Returns the resolved workspace + principal so customers can wire up smoke tests for their API key. Counts against the read-bucket rate limit.

Authorization

  • Authorizationstringrequired

    Bearer token in the Authorization header.

    Pass Authorization: Bearer scripe_sk_live_<...> (or scripe_sk_test_<...> for test keys) on every request. Keys are scoped to a single workspace and can be revoked from the Scripe dashboard.

    The same header also accepts an OAuth 2.1 access token (scripe_oat_*); both credentials share one scope vocabulary and every operation below documents the scope it requires. An API key can hold every scope named on this surface except webhooks:manage, which is grantable to OAuth tokens only today — the webhook-endpoint operations answer 403 scope_missing to every API key. Operations that name no scope accept any valid token of the workspace.

Header parameters

  • Scripe-Api-Versionstring

    Pin the API version. Format YYYY-MM-DD. Omit to receive the currently rolling default. Unknown versions return 400 version_unsupported.

Responses

  • 200

    Auth succeeded.

  • 401

    Missing, malformed, expired, or revoked API key.

  • 403

    Plan not eligible, scope missing, or workspace mismatch.

  • 429

    Sliding-window rate limit exceeded.

Example request

bash
curl --request GET \
  --url 'https://api.scripe.io/v1/health/auth' \
  --header 'Authorization: Bearer <token>'

Example response (200)

json
{
  "status": "ok",
  "version": "string",
  "workspace": {
    "id": "string"
  },
  "principal": {
    "type": "api_key",
    "id": "key_a1b2c3d4e5f6g7h8"
  }
}