List entitlements

Retrieve all entitlements for a customer. Pass `customer_id` as a query parameter. Includes computed access status based on subscription state. --- **Related endpoints** - `GET /customers/{customerId}/entitlements` — List customer entitlements - `POST /customers/{customerId}/entitlements` — Grant entitlement to customer - `DELETE /customers/{customerId}/entitlements` — Revoke entitlement by benefit key - `GET /customers/{customerId}/entitlements/check` — Check customer entitlement - `DELETE /customers/{customerId}/entitlements/{entitlementId}` — Revoke entitlement by ID - `GET /entitlements/check` — Check entitlement access **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Pagination** Offset-based with `limit` (default 25, max 100) and `offset`. The response `pagination` block includes `total` and `hasMore`. See [the pagination guide](/docs/fundamentals/pagination) for SDK auto-paging helpers.

GET
/entitlements

Retrieve all entitlements for a customer. Pass customer_id as a query parameter. Includes computed access status based on subscription state.


Related endpoints

  • GET /customers/{customerId}/entitlements — List customer entitlements
  • POST /customers/{customerId}/entitlements — Grant entitlement to customer
  • DELETE /customers/{customerId}/entitlements — Revoke entitlement by benefit key
  • GET /customers/{customerId}/entitlements/check — Check customer entitlement
  • DELETE /customers/{customerId}/entitlements/{entitlementId} — Revoke entitlement by ID
  • GET /entitlements/check — Check entitlement access

Common errors

  • 400 invalid_request — malformed payload or failed validation.
  • 401 authentication_error — missing, invalid, expired, or revoked credential. Codes: authentication_failed, invalid_api_key, expired_api_key, api_key_revoked, session_invalid, merchant_required. Carries a WWW-Authenticate: Bearer challenge.
  • 404 resource_missing — the referenced resource does not exist or is not visible to your key.

Pagination

Offset-based with limit (default 25, max 100) and offset. The response pagination block includes total and hasMore. See the pagination guide for SDK auto-paging helpers.

x-api-key<token>

Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.

In: header

Query Parameters

customer_id*string

Customer UUID (required)

Formatuuid
include_expired?|

Include expired entitlements

Defaultfalse
benefit_type?string

Filter by benefit type

category?string

Filter by category

limit?integer

Maximum results (1-100)

Range1 <= value <= 100
Default50
offset?|

Results to skip

Range0 <= value
Default0

Response Body

application/json

application/json

application/json

application/json

application/json

Stuck on an error response? Ask the RevKeen assistant to explain it.
curl "https://api.revkeen.com/v2/entitlements?customer_id=value" \
  -H "x-api-key: $REVKEEN_API_KEY"
{  "data": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e",      "benefit_id": "1c2ea70b-3976-456a-b572-2d8f4680a169",      "benefit": {        "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",        "name": "string",        "description": "string",        "benefit_type": "string",        "benefit_key": "string",        "category": "string",        "icon_url": "string",        "display_order": "string",        "is_active": true,        "default_value": null,        "config": null      },      "granted_at": "2019-08-24T14:15:22Z",      "expires_at": "2019-08-24T14:15:22Z",      "metadata": {},      "status": "active",      "has_access": true,      "access_level": "full",      "subscription_id": "aa11a4c2-a467-43db-b413-c4ab0f5cf627",      "subscription_status": "string"    }  ],  "pagination": {    "limit": 0,    "offset": 0,    "total": 0  },  "customer": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "email": "string",    "name": "string"  }}

Check entitlement access GET

Check if a customer has access to a specific benefit by key. This is the primary endpoint for feature gating and licensing checks. --- **Related endpoints** - `GET /customers/{customerId}/entitlements` — List customer entitlements - `POST /customers/{customerId}/entitlements` — Grant entitlement to customer - `DELETE /customers/{customerId}/entitlements` — Revoke entitlement by benefit key - `GET /customers/{customerId}/entitlements/check` — Check customer entitlement - `DELETE /customers/{customerId}/entitlements/{entitlementId}` — Revoke entitlement by ID - `GET /entitlements` — List entitlements **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key.

Create a test event POST

Creates a simulated test event that triggers webhook delivery to configured endpoints. Useful for testing webhook integrations. --- **Related endpoints** - `GET /events` — List events - `GET /events/{id}` — Retrieve an event - `POST /events/{id}/resend` — Resend webhook for an event **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).