Commerce

Check entitlement access

Checks whether an account has access to a feature. For numbered metered features, include requestedQuantity. For enum features, include enumValues.

post/commerce/entitlements/challenge

Request

  • Base URL: https://rest.test.zuora.com
  • URL: https://rest.test.zuora.com/commerce/entitlements/challenge
  • Auth: HTTP bearer

Headers

Idempotency-Keystring

Specify a unique idempotency key if you want to perform an idempotent POST or PATCH request. Do not use this header in other request types.

With this header specified, the Zuora server can identify subsequent retries of the same request using this value, which prevents the same operation from being performed multiple times by accident.

Accept-Encodingstring

Include the Accept-Encoding: gzip header to compress responses as a gzipped file. It can significantly reduce the bandwidth required for a response.

If specified, Zuora automatically compresses responses that contain over 1000 bytes of data, and the response contains a Content-Encoding header with the compression algorithm so that your client can decompress it.

Content-Encodingstring

Include the Content-Encoding: gzip header to compress a request. With this header specified, you should upload a gzipped file for the request payload instead of sending the JSON payload.

Zuora-Entity-Idsstring

An entity ID. If you have Zuora Multi-entity enabled and the OAuth token is valid for more than one entity, you must use this header to specify which entity to perform the operation in. If the OAuth token is only valid for a single entity, or you do not have Zuora Multi-entity enabled, you should not set this header.

Zuora-Org-Idsstring

Comma separated IDs. If you have <a href="https://docs.zuora.com/en/zuora-platform/organization-and-entity-management/multi-org/overview-of-multi-org" target="_blank">Zuora Multi-Org</a> enabled, you can use this header to specify which orgs to perform the operation in. If you do not have Zuora Multi-Org enabled, you should not set this header.

The IDs must be a sub-set of the user's accessible orgs. If you specify an org that the user does not have access to, the operation fails. This header is important in Multi-Org (MO) setups because it defines the organization context under which the API should operate—mainly used for read access or data visibility filtering. If the header is not set, the operation is performed in scope of the user's accessible orgs.

Zuora-Track-Idstring

A custom identifier for tracing the API call. If you set a value for this header, Zuora returns the same value in the response headers. This header enables you to associate your system process identifiers with Zuora API calls, to assist with troubleshooting in the event of an issue.

The value of this field must use the US-ASCII character set and must not include any of the following characters: colon (:), semicolon (;), double quote ("), and quote (').

Zuora-Versionstring

The minor API version.

For a list of available minor versions, see API upgrades.

Request body

accountKeystring required

Account number or account ID to evaluate.

featureKeystring required

Unique key of the catalog feature to check.

quantitynumber

Quantity to evaluate for a numbered metered feature. Prefer requestedQuantity.

requestedQuantitynumber

Requested consumption quantity for a numbered metered feature.

effectiveDatestring date

Date to evaluate access, in YYYY-MM-DD format. If omitted, the current date is used.

subscriptionKeystring

Subscription number or subscription ID used to scope the access check.

enumValuesstring[]

Enum values to evaluate when the feature type is enumType.

accountKeysstring[]

Additional account numbers or account IDs to include in the access check.

actionTypestring

Type of access decision to evaluate, for example a read check versus a consume check.

Example request

{
  "accountKey": "A00000001",
  "featureKey": "api_calls",
  "quantity": 1,
  "requestedQuantity": 100,
  "effectiveDate": "2026-03-15",
  "subscriptionKey": "A-S00000001",
  "enumValues": [
    "basic",
    "pro"
  ],
  "actionType": "check"
}

Response

OK

isValidboolean

Indicates whether the requested access is allowed.

cacheTtlSecondsinteger

Number of seconds the decision can be cached.

policystring

Entitlement policy applied to this decision, such as hard_block, allow, or warning.

totalBalancenumber

Total granted quantity for the numbered feature.

remainingBalancenumber

Remaining quantity available after this decision.

enforcementResult'allow' | 'deny' | 'warn'

Outcome of policy enforcement.

Supported values:

  • allow - Access is allowed.
  • deny - Access is denied.
  • warn - Access is allowed with a warning.
accessDeniedReasonstring nullable

Reason access was denied. Returned when isValid is false.

Common values include grant_revoked, no_active_grant, and limit_exceeded.

effectiveLimitnumber nullable

Effective quantity limit applied to this decision.

currentUsagenumber

Quantity already consumed for the numbered feature.

remainingnumber

Remaining quantity available for the numbered feature.

percentageUsednumber

Percentage of the effective limit that has been consumed.

resetAtstring date-time nullable

Date and time the metered balance resets.

overageQuantitynumber

Quantity that exceeds the effective limit.

chargeSourcestring nullable

Charge source associated with the evaluated entitlement, when applicable.

Example response

{
  "isValid": true,
  "entitlements": [
    {
      "id": "8ad088009840d1c2019855e15c993f2f",
      "entitlementKey": "EG-00000001",
      "entitlement_key": "EG-00000001",
      "entitlementNumber": "EG-00000001",
      "accountKey": "A00000001",
      "subscriptionKey": "A-S00000001",
      "planKey": "PRP-00000001",
      "plan_key": "PRP-00000001",
      "featureKey": "api_calls",
      "featureCode": "api_calls",
      "quantity": 10000,
      "startDate": "2026-01-01",
      "endDate": "2026-12-31",
      "revokedDate": "2026-06-01",
      "state": "active",
      "unit": "API Calls"
    }
  ],
  "cacheTtlSeconds": 60,
  "policy": "hard_block",
  "totalBalance": 10000,
  "remainingBalance": 8500,
  "enforcementResult": "allow",
  "effectiveLimit": 10000,
  "currentUsage": 1500,
  "remaining": 8500,
  "percentageUsed": 15,
  "resetAt": "2026-04-01T00:00:00Z",
  "chargeSource": "usage_charge"
}

Changes

No operation changes recorded.