Skip to content

Get the domain's effective plan entitlements

GET
/domains/{domain}/features
curl --request GET \
--url https://api.nsin.cloud/domains/example.com/features \
--header 'Authorization: Bearer <token>'

What this domain’s plan actually allows — the resolved values after any per-subscription overrides, so this is the authority on whether a feature is available.

A limit of null means unlimited. Use this before calling a gated endpoint rather than inferring capability from the plan name. Readable by shared members.

domain
required
string

The domain name (for example example.com) — not a numeric id.

Example
example.com

Effective entitlements.

Media type application/json

The domain’s effective entitlements, after per-subscription overrides. A null limit means unlimited.

object
plan_id
integer
plan_name
string
plan_slug
string
has_active_plan
boolean
max_records

Null means unlimited.

integer
max_traffic_gb

Null means unlimited.

integer
max_rules_per_set

Rules allowed per rule type. Null means unlimited.

integer
max_cache_cap_mb

Ceiling for the domain’s cache_cap_mb.

integer
logs_enabled

Gates the raw-log and top-N analytics endpoints.

boolean
monitoring_enabled

Gates most analytics sections.

boolean
rules_enabled
boolean
cache_purge_enabled

Gates the cache purge endpoints.

boolean
custom_ssl_enabled

Gates custom certificate upload.

boolean
ws_enabled

WebSocket support.

boolean
host_header_edit_enabled
boolean
dedicated_support_enabled
boolean
domain_usage

Current usage against the limits above.

Array<object>
object
key
additional properties
any
plan_term_id
integer
billing_duration_days
integer
quota_reset_days
integer
quota_period_start
string format: date-time
quota_period_end
string format: date-time
Example generated
{
"plan_id": 1,
"plan_name": "example",
"plan_slug": "example",
"has_active_plan": true,
"max_records": 1,
"max_traffic_gb": 1,
"max_rules_per_set": 1,
"max_cache_cap_mb": 1,
"logs_enabled": true,
"monitoring_enabled": true,
"rules_enabled": true,
"cache_purge_enabled": true,
"custom_ssl_enabled": true,
"ws_enabled": true,
"host_header_edit_enabled": true,
"dedicated_support_enabled": true,
"domain_usage": [
{}
],
"plan_term_id": 1,
"billing_duration_days": 1,
"quota_reset_days": 1,
"quota_period_start": "2026-04-15T12:00:00Z",
"quota_period_end": "2026-04-15T12:00:00Z"
}

Missing domain.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Example
{
"error": "read-only API key"
}

Missing, malformed, revoked or expired API key, or a key whose owning user row is gone. A key whose owning account has merely been deactivated is not this: that is 403 with code: account_suspended, because the credential itself is intact and re-issuing it changes nothing.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Examples
Example invalidKey
{
"error": "invalid API key"
}

No such domain, or it is not visible to this account. Domains you cannot access are reported as not found rather than forbidden.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Example
{
"error": "read-only API key"
}

The key exceeded its request budget (300 requests per minute by default).

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Examples
Example limited
{
"error": "rate limit exceeded"
}