GET https://payments-gateway.flokitai.com/api/entitlements/current
Request
Send x-app-token (preferred) or x-app-key, together with x-user-id. Use an opaque, stable, pseudonymous user reference. Do not use an email, phone number, or other direct personal identifier, and do not put the reference in a URL.
Response
This example contains fictional values:
Use active for the displayed access state and treat entitlement_key as opaque. States include trialing, active, grace, paused, canceled_paid_through, expired, refunded, and revoked. A browser checkout callback does not establish access.
An App credential does not authenticate a caller-supplied user reference. A client-side read is display information, not authorization proof. Before serving protected resources, your backend must verify its own user session and the corresponding server-verified entitlement.