OpenAPI reference · Health
Authenticated key smoke test
/health/authReturns the resolved workspace + principal so customers can wire up smoke tests for their API key. Counts against the read-bucket rate limit.
Authorization
AuthorizationstringrequiredBearer token in the Authorization header.
Pass
Authorization: Bearer scripe_sk_live_<...>(orscripe_sk_test_<...>for test keys) on every request. Keys are scoped to a single workspace and can be revoked from the Scripe dashboard.The same header also accepts an OAuth 2.1 access token (
scripe_oat_*); both credentials share one scope vocabulary and every operation below documents the scope it requires. An API key can hold every scope named on this surface exceptwebhooks:manage, which is grantable to OAuth tokens only today — the webhook-endpoint operations answer403 scope_missingto every API key. Operations that name no scope accept any valid token of the workspace.
Header parameters
Scripe-Api-VersionstringPin the API version. Format
YYYY-MM-DD. Omit to receive the currently rolling default. Unknown versions return400 version_unsupported.
Responses
- 200
Auth succeeded.
- 401
Missing, malformed, expired, or revoked API key.
- 403
Plan not eligible, scope missing, or workspace mismatch.
- 429
Sliding-window rate limit exceeded.
Example request
curl --request GET \
--url 'https://api.scripe.io/v1/health/auth' \
--header 'Authorization: Bearer <token>'Example response (200)
{
"status": "ok",
"version": "string",
"workspace": {
"id": "string"
},
"principal": {
"type": "api_key",
"id": "key_a1b2c3d4e5f6g7h8"
}
}