Account card API

Account card endpoints in the Brix REST API: 3 operations (GET, POST). Each lists its path, auth, required permission and a curl example.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/account-card/{token}

Bearer token

Public, no login: the account name and its saved card and backup card, for the account-card link staff send to an account we bill. Signed-token-gated (acard~, 30 days).

ParameterInTypeRequiredDescription
tokenpathstringyesIdentifier for token.
curl "https://api.brixsignage.com/v1/account-card/{token}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/account-card/{token}/card

Bearer token

Public, no login: open Stripe's card page for the token's account. Body { role?: 'primary'|'backup' } → { url }.

ParameterInTypeRequiredDescription
tokenpathstringyesIdentifier for token.
curl -X POST "https://api.brixsignage.com/v1/account-card/{token}/card" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/account-card/{token}/card/complete

Bearer token

Public, no login: save the card from Stripe's return. Body { sessionId } → { accountName, card, backupCard }; another workspace's session is 404.

ParameterInTypeRequiredDescription
tokenpathstringyesIdentifier for token.
curl -X POST "https://api.brixsignage.com/v1/account-card/{token}/card/complete" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.