Get Restriction Scope
Authentication
RS256-signed JWT access token signed with your registered private key.
Headers
RS256-signed JWT (Bearer format), signed with your registered private key. Must contain an accountId claim identifying the master account. A missing or invalid token returns HTTP 401.
Query parameters
Positive integer. Decimals and non-numeric values return 400.
Set to T for employer-track authorization.
Response
Always ok on success.
The restriction’s scope. One of: Active For Family, Active Except, Active For Some, Inactive.
Account IDs relevant to the scope. Omitted entirely for Active For Family (all accounts are implicitly in scope) and Inactive (no accounts). For Active For Some, the directly associated accounts, capped at a configurable limit (see truncated). For Active Except, the excluded accounts, always returned in full and never capped.
Present only for Active For Some. true if the account list was capped at the configured limit and more accounts exist beyond it; false if the full list was returned. Never present for other scopes (Active Except is always returned in full, uncapped).

