Retrieve an access credential
Present an API key (sb_live_… / sb_test_…), an OAuth2 access token, or a static token as a Bearer credential. The operator is implied by the credential; it is never in the path. Only a SHA-256 hash of an API key is stored server-side.
In: header
Path Parameters
UUIDv7 identifier of the resource.
uuidResponse Body
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/access-credentials/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "data": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "object": "access_credential", "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811", "unit_id": "5becc822-b69e-4e66-a762-ad8e868dcab6", "agreement_id": "67dd069b-637c-4b8e-8d92-17a313d06fb8", "contact_id": "f245e2a3-e141-4d41-912c-b1c1f5bd5598", "vendor": "noke", "credential_type": "pin", "external_credential_id": "string", "status": "pending", "issued_at": "2019-08-24T14:15:22Z", "suspended_at": "2019-08-24T14:15:22Z", "revoked_at": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" }}{ "error": { "code": "unauthorized", "message": "Missing or invalid credential." }}{ "error": { "code": "insufficient_scope", "message": "The credential lacks a scope required by this endpoint." }}{ "error": { "code": "not_found", "message": "Resource not found." }}{ "error": { "code": "validation_error", "message": "string", "details": [ { "field": "string", "issue": "string" } ] }}Delete a device DELETE
Permanently removes a device that nothing references. This is for a record that should never have existed — a duplicate, a typo, a mistaken entry. If ANY other record points at it the request is refused with 409 and `error.details` lists what was found; archive it instead where an archive verb exists. Deleting is not a GDPR erasure: erasure is handled separately and respects legal hold.
Retrieve an access event GET
Next Page