# Open the Stripe customer portal

Answers a one-time `url` for Stripe's own hosted portal, where a person changes the card, reads invoices and cancels. We deliberately do not rebuild any of that. A workspace with no Stripe customer gets one made rather than a refusal. Needs the workspace's owner or admin seat.

Access class: `workspace:admin`.

## Endpoint

`POST /v1/billing/portal-session`

## Request body

Content type: `application/json`.

```json
{
  "body": {},
  "params": {},
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "url": "string"
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
