Skip to content

List your support tickets

GET
/tickets
curl --request GET \
--url https://api.nsin.cloud/tickets \
--header 'Authorization: Bearer <token>'

Your tickets, most recently updated first.

Tickets.

Media type application/json
Array
object
id
integer
user_id
integer
subject
string
status

For example open or closed.

string
closed_at
string format: date-time
closed_by_user_id
integer
user_last_read_message_id
integer
staff_last_read_message_id
integer
messages

The thread. Populated when fetching a single ticket.

Array<object>
object
id
integer
ticket_id
integer
author_user_id
integer
author

The message author.

object
key
additional properties
any
body
string
is_staff

True when written by support staff.

boolean
attachments
Array<object>
object
id
integer
message_id
integer
original_name
string
content_type
string
size_bytes
integer
url

Where to download the attachment.

string
created_at
string format: date-time
created_at
string format: date-time
updated_at
string format: date-time
is_unread

There are replies you have not read.

boolean
Example generated
[
{
"id": 1,
"user_id": 1,
"subject": "example",
"status": "example",
"closed_at": "2026-04-15T12:00:00Z",
"closed_by_user_id": 1,
"user_last_read_message_id": 1,
"staff_last_read_message_id": 1,
"messages": [
{
"id": 1,
"ticket_id": 1,
"author_user_id": 1,
"author": {},
"body": "example",
"is_staff": true,
"attachments": [
{
"id": 1,
"message_id": 1,
"original_name": "example",
"content_type": "example",
"size_bytes": 1,
"url": "example"
}
],
"created_at": "2026-04-15T12:00:00Z"
}
],
"created_at": "2026-04-15T12:00:00Z",
"updated_at": "2026-04-15T12:00:00Z",
"is_unread": true
}
]

Missing, malformed, revoked or expired API key, or a key whose owning user row is gone. A key whose owning account has merely been deactivated is not this: that is 403 with code: account_suspended, because the credential itself is intact and re-issuing it changes nothing.

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Examples
Example invalidKey
{
"error": "invalid API key"
}

The key exceeded its request budget (300 requests per minute by default).

Media type application/json

The error shape used by every endpoint. error is always present. code is present only on the failures that have one — do not require it, and do not parse error to recover it.

object
error
required

Human-readable description of what went wrong.

string
code

Stable machine-readable reason. Present on some failures only; the wording of error may change, this will not.

  • account_suspended403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.
  • domain_disabled409, not 403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.
  • managed_by_reseller403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.
  • invite_email_mismatch403 from POST /invites/{token}/accept. The invitation was addressed to a different email; the body also carries invited_email, masked.

A panel session — not an API key — can additionally see session_check_failed on a 503, which means the session could not be verified, not that it is invalid. Retry it; do not discard the token.

string
Examples
Example limited
{
"error": "rate limit exceeded"
}