Grant entitlement to customer

Grant a benefit/entitlement to a customer. Provide either benefitId or benefitKey to identify the benefit. Emits an entitlement.granted webhook event. --- **Related endpoints** - `GET /customers/{customerId}/entitlements` — List customer entitlements - `DELETE /customers/{customerId}/entitlements` — Revoke entitlement by benefit key - `GET /customers/{customerId}/entitlements/check` — Check customer entitlement - `DELETE /customers/{customerId}/entitlements/{entitlementId}` — Revoke entitlement by ID - `GET /entitlements` — List entitlements - `GET /entitlements/check` — Check entitlement access **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).

POST
/customers/{customerId}/entitlements

Grant a benefit/entitlement to a customer. Provide either benefitId or benefitKey to identify the benefit. Emits an entitlement.granted webhook event.


Related endpoints

  • GET /customers/{customerId}/entitlements — List customer entitlements
  • DELETE /customers/{customerId}/entitlements — Revoke entitlement by benefit key
  • GET /customers/{customerId}/entitlements/check — Check customer entitlement
  • DELETE /customers/{customerId}/entitlements/{entitlementId} — Revoke entitlement by ID
  • GET /entitlements — List entitlements
  • GET /entitlements/check — Check entitlement access

Common errors

  • 400 invalid_request — malformed payload or failed validation.
  • 401 authentication_error — missing, invalid, expired, or revoked credential. Codes: authentication_failed, invalid_api_key, expired_api_key, api_key_revoked, session_invalid, merchant_required. Carries a WWW-Authenticate: Bearer challenge.
  • 404 resource_missing — the referenced resource does not exist or is not visible to your key.

Idempotency

Pass an Idempotency-Key header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see the idempotency guide.

x-api-key<token>

Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.

In: header

Path Parameters

customerId*string

Customer UUID

Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

Stuck on an error response? Ask the RevKeen assistant to explain it.
curl -X POST "https://api.revkeen.com/v2/customers/00000000-0000-0000-0000-000000000000/entitlements" \
  -H "x-api-key: $REVKEEN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "benefitId": "00000000-0000-0000-0000-000000000000",
    "benefitKey": "string",
    "expiresAt": null,
    "metadata": {}
  }'
{  "data": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e",    "benefit_id": "1c2ea70b-3976-456a-b572-2d8f4680a169",    "benefit": {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "name": "string",      "description": "string",      "benefit_type": "string",      "benefit_key": "string",      "category": "string",      "icon_url": "string",      "display_order": "string",      "is_active": true,      "default_value": null,      "config": null    },    "granted_at": "2019-08-24T14:15:22Z",    "expires_at": "2019-08-24T14:15:22Z",    "metadata": {},    "status": "active",    "has_access": true,    "access_level": "full",    "subscription_id": "aa11a4c2-a467-43db-b413-c4ab0f5cf627",    "subscription_status": "string"  },  "message": "string"}

Check customer entitlement GET

Check if a customer has access to a specific benefit by key. This is the primary endpoint for feature gating and licensing checks. --- **Related endpoints** - `GET /customers/{customerId}/entitlements` — List customer entitlements - `POST /customers/{customerId}/entitlements` — Grant entitlement to customer - `DELETE /customers/{customerId}/entitlements` — Revoke entitlement by benefit key - `DELETE /customers/{customerId}/entitlements/{entitlementId}` — Revoke entitlement by ID - `GET /entitlements` — List entitlements - `GET /entitlements/check` — Check entitlement access **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key.

List customer entitlements GET

Retrieve all entitlements (benefits/features) for a specific customer. Includes computed access status based on subscription state. --- **Related endpoints** - `POST /customers/{customerId}/entitlements` — Grant entitlement to customer - `DELETE /customers/{customerId}/entitlements` — Revoke entitlement by benefit key - `GET /customers/{customerId}/entitlements/check` — Check customer entitlement - `DELETE /customers/{customerId}/entitlements/{entitlementId}` — Revoke entitlement by ID - `GET /entitlements` — List entitlements - `GET /entitlements/check` — Check entitlement access **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Pagination** Offset-based with `limit` (default 25, max 100) and `offset`. The response `pagination` block includes `total` and `hasMore`. See [the pagination guide](/docs/fundamentals/pagination) for SDK auto-paging helpers.