Whether the workspace may connect new domains
The lean read the MCP server's check-billing-status tool uses: whether a new connection is refused right now, and if so the same code, title and details the refusal carries (billing_required), plus the plan and this month's usage. It has no dates, amounts, invoices or card; owners and admins read those from GET /billing/status. Any workspace credential may read it: a tenant API key of any role, a delegated agent token with domains:read, or a widget token minted with scope app. A connect-scoped widget token (an end user's) is refused with 403.
Long-lived tenant API key, cd_live_… (production) or cd_test_… (staging, development), stored hashed. Keys created before the switch to cd_ start with sk_live_… / sk_test_… and are still accepted. Scoped to the owning application's tenant.
In: header
Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/billing/standing"{ "configured": true, "restricted": true, "first_domain_free": true, "attention": true, "code": "string", "title": "string", "details": "string", "billing_url": "string", "plan": { "id": "string", "name": "string", "hard_cap": true }, "usage": { "used": 0, "quota": 0, "period": "string" }}{ "code": "string", "title": "string", "details": "string"}{ "code": "string", "title": "string", "details": "string"}