TransaktDocs
API referenceEntitlements

Get a tenant entitlement

GET
/api/v1/entitlements/{tenantId}

What the tenant (a customer's Microsoft Entra tenant id) holds for one of your products: status, access level, edition, plans, licence model, feature capabilities, seat quantity and validity. Ask with plan for a plan-scoped answer. status is None when the tenant never bought the product. Scope entitlements:read (app role Entitlement.Read.All).

Errors: api_client.product_not_allowed, entitlement.user_tenant_mismatch, product.not_found, plan.not_found, auth.credentials_invalid, auth.forbidden, request.rate_limited.

Authorization

headerAuthorizationBearer <token>

A Microsoft Entra client-credentials token for the Transakt API (scope api://{apiAppId}/.default), issued in the tenant recorded on the API client credential, with the app role matching the operation: Entitlement.Read.All, Catalogue.Read.All or Usage.Write.All.

Scope: api://{apiAppId}/.default

Path Parameters

tenantId*string
Formatuuid

Query Parameters

product?string
plan?string

Response Body

OK

application/json
  1. response

Entitlement (6.5.8).

tenantId*string
Formatuuid
product*
status*EntitlementStatus

The API's EntitlementStatus: None when never bought, else the described subscription's status.

Value in"None""PendingActivation""Active""Suspended""Cancelled""Expired"
accessLevel*AccessLevel
Value in"Full""ReadOnly""None"
plans*array<>
plan*null|
edition*null|
licenceModel*null|
licenceOutcome*LicenceOutcome
Value in"Licensed""NotLicensed""Unconfirmed""ConsentRequired""NotApplicable"
capabilities*
quantity*|
Formatint32
validUntil*|
Formatdate-time
isTrial*boolean
trialEndsAt*|
Formatdate-time
cancelledAt*|
Formatdate-time
sources*array<>
marketplace*null|
version*integer
Formatint64
evaluatedAt*string
Formatdate-time
curl -X GET "https://example.com/api/v1/entitlements/497f6eca-6276-4993-bfeb-53cbbbba6f08"
{  "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",  "product": {    "slug": "string",    "name": "string"  },  "status": "None",  "accessLevel": "Full",  "plans": [    {      "slug": "string",      "name": "string"    }  ],  "plan": null,  "edition": null,  "licenceModel": null,  "licenceOutcome": "Licensed",  "capabilities": {    "property1": true,    "property2": true  },  "quantity": null,  "validUntil": null,  "isTrial": true,  "trialEndsAt": null,  "cancelledAt": null,  "sources": [    "Marketplace"  ],  "marketplace": null,  "version": 0,  "evaluatedAt": "2019-08-24T14:15:22Z"}

Check whether a user may use a product (by email) POST

As the GET form, with the question in the body: `userObjectId` or `email`. An email is resolved to the one active member of the organisation that holds the tenant; otherwise the answer is `422 entitlement.user_not_resolved` and you should ask by object id. Errors: [`request.validation_failed`](/errors/request.validation_failed/), [`api_client.product_not_allowed`](/errors/api_client.product_not_allowed/), [`entitlement.user_tenant_mismatch`](/errors/entitlement.user_tenant_mismatch/), [`entitlement.user_not_resolved`](/errors/entitlement.user_not_resolved/), [`product.not_found`](/errors/product.not_found/), [`plan.not_found`](/errors/plan.not_found/), [`auth.credentials_invalid`](/errors/auth.credentials_invalid/), [`auth.forbidden`](/errors/auth.forbidden/), [`request.rate_limited`](/errors/request.rate_limited/).

Check whether a user may use a product GET

The user question: may this user of the tenant use the product? Send `userObjectId`, or a delegated user token (scope `Entitlement.Read`) to ask about the signed-in user. The answer's `licenceOutcome` is `Licensed`, `NotLicensed`, `Unconfirmed` (Microsoft could not confirm: apply your own grace policy) or `ConsentRequired` (repeat with the user's delegated token). Questions by email use the POST form so that personal data never appears in a URL. Errors: [`request.validation_failed`](/errors/request.validation_failed/), [`api_client.product_not_allowed`](/errors/api_client.product_not_allowed/), [`entitlement.user_tenant_mismatch`](/errors/entitlement.user_tenant_mismatch/), [`product.not_found`](/errors/product.not_found/), [`plan.not_found`](/errors/plan.not_found/), [`auth.credentials_invalid`](/errors/auth.credentials_invalid/), [`auth.forbidden`](/errors/auth.forbidden/), [`request.rate_limited`](/errors/request.rate_limited/).