Partner resource access
Use cascade access to explain an existing entitlement from another publication of the same partner. Follow with a content check for a serving decision. Cascade access describes the relationship.
Read partner cascade access
GET /api/v1/user/cascade-access
Explain plan and ticket/event entitlements applied to this resource from another resource of the same partner. It reads the current user’s eligible subscriptions and assigned tickets; it does not provision or grant a new entitlement.
Before you call
Use an existing member token and resource context. A qualifying source membership or assigned ticket must exist in another resource of the same partner to produce a match. Use the API base and resource public key already supplied for your integration; these pages do not issue credentials.
Request
GET with no request body or request Content-Type requirement. Response media type is JSON. Requires the user role or inherited permission and active member context. See credential transport.
| Name | Location | Type | Requirement / default | Meaning and constraint |
|---|---|---|---|---|
resource | header | string | required context | Public resource key; not the secret. |
token | header | string | member context | Existing member-session token. |
firebase-token | header | string | Firebase-enabled member context | Configured Firebase ID token alongside the Wallkit token. |
No query/body input, filter or sort is read. Helper-level missing/exceptional results are represented as null/empty, so an empty result does not distinguish all internal causes. Cached selections can be reused; this operation does not record a content view.
Result
HTTP 200 JSON.
| Field / projection | Type / presence | Meaning |
|---|---|---|
| top-level object | plan match and event matches | Use field definitions for every nested projection. No entitlement or content view is created. |
Example: read partner cascade access
A Monthly membership in another partner publication supplies Reader plan access in the selected publication. No event matches are attached. Supply the sample configuration and runtimes. These three requests are equivalent.
cURL
curl "${WALLKIT_API_BASE}/api/v1/user/cascade-access" \
-H "resource: ${RESOURCE_KEY}" \
-H "token: ${USER_TOKEN}"
JavaScript
// Node.js 18+; built-in fetch. Supply existing integration configuration.
async function main() {
const url = new URL("/api/v1/user/cascade-access", process.env.WALLKIT_API_BASE);
const headers = { resource: process.env.RESOURCE_KEY, token: process.env.USER_TOKEN };
const response = await fetch(url, { method: "GET", headers });
const body = await response.json();
console.log(response.status, body);
}
main().catch(console.error);
Python
# Python 3; standard library only.
import json
import os
from urllib.error import HTTPError
from urllib.parse import urlencode, urljoin
from urllib.request import Request, urlopen
url = urljoin(os.environ["WALLKIT_API_BASE"], "/api/v1/user/cascade-access")
headers = {"resource": os.environ["RESOURCE_KEY"], "token": os.environ["USER_TOKEN"]}
request = Request(url, headers=headers, method="GET")
try:
with urlopen(request) as response:
print(response.status, json.load(response))
except HTTPError as error:
print(error.code, json.load(error))
HTTP 200 response excerpt:
{
"cascade_access_plan": {
"applied_plan": {
"id": 1001,
"title": "Reader plan"
},
"source_resource": {
"title": "Example partner publication",
"key": "example-other-resource",
"host": "https://example.com/other"
},
"source_subscription": {
"id": 2001,
"title": "Monthly"
}
},
"cascade_access_ti_event": []
}
Alternate result
No entitlement is returned. Cached/helper-level empty results cannot distinguish every underlying cause; check content access rather than treating this as a grant.
Response excerpt:
{
"cascade_access_plan": null,
"cascade_access_ti_event": []
}
Recovery
| HTTP status | API code / response | Cause | Next action |
|---|---|---|---|
| 401 | auth_failed | Required identity is missing. | Supply the existing member token and check its selected resource context. |
| 401 | auth_access_fail | Inactive account or locked/suspended resource relationship. | Ask the administrator to check account activation and the resource relationship’s lock/suspension state. |
| 401 / 403 | access | Role does not permit the operation. | Use an identity permitted for this action; ask the administrator to check the assigned role. |
| 404 | resource_not_exists | Required resource is missing or unknown. | Check the resource public key and selected integration context with the administrator. |
| 409 | user_cascade_access_error | Exception constructing the overall cascade response. | Check the established member/resource context and contact support with req_guid. |
Common identity/configuration errors explain applicable session failures. Follow this operation’s exceptions rather than assuming every call uses the same envelope.
Next task
Check the target content to obtain the actual allow/deny result for the current visitor.