# Workspace: billing

> Whether a plan can be bought here, which ones, and whether a subscription exists to manage; A Stripe Checkout link for a paid plan (review P-14); A link to Stripe's customer portal, where the subscription is changed or cancelled

## Whether a plan can be bought here, which ones, and whether a subscription exists to manage

`GET /v1/workspace/billing` · operation `getBilling`

Requires the `batondeck:billing:read` permission (action `plan:read`).

**Responses**

| Status | Meaning |
|---|---|
| 200 | Whether a plan can be bought here, which ones, and whether a subscription exists to manage |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "enabled": {
      "type": "boolean"
    },
    "purchasable": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "managed": {
      "type": "boolean"
    }
  },
  "required": [
    "enabled",
    "purchasable",
    "managed"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/workspace/billing' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## A Stripe Checkout link for a paid plan (review P-14)

`POST /v1/workspace/billing/checkout` · operation `openCheckout`

Requires the `batondeck:billing:manage` permission (action `plan:change`).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. **Not reachable with an API key** — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

**Request body** (`application/json`)

| Field | Type | Required | Notes |
|---|---|---|---|
| `plan` | "pro" \\| "team" \\| "enterprise" | yes |  |

<details>
<summary>Request schema</summary>

```json
{
  "type": "object",
  "properties": {
    "plan": {
      "type": "string",
      "enum": [
        "pro",
        "team",
        "enterprise"
      ]
    }
  },
  "required": [
    "plan"
  ],
  "additionalProperties": false
}
```

</details>

**Responses**

| Status | Meaning |
|---|---|
| 200 | A Stripe Checkout link for a paid plan (review P-14) |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "url": {
      "type": "string"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/workspace/billing/checkout' \
  -H "Authorization: Bearer $BATONDECK_API_KEY" \
  -H 'content-type: application/json' \
  -d @body.json
```


## A link to Stripe's customer portal, where the subscription is changed or cancelled

`POST /v1/workspace/billing/portal` · operation `openBillingPortal`

Requires the `batondeck:billing:manage` permission (action `plan:change`).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. **Not reachable with an API key** — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

**Request body** (`application/json`)

<details>
<summary>Request schema</summary>

```json
{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
```

</details>

**Responses**

| Status | Meaning |
|---|---|
| 200 | A link to Stripe's customer portal, where the subscription is changed or cancelled |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "url": {
      "type": "string"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/workspace/billing/portal' \
  -H "Authorization: Bearer $BATONDECK_API_KEY" \
  -H 'content-type: application/json' \
  -d @body.json
```
