List the features enabled for the tenant
Returns every product feature of the tenant in X-Tenant-Id and
whether it is enabled. The list is complete: a feature that is not
contracted comes back with enabled: false, so “not contracted” and
“unknown feature” never look the same.
The state is the one the API checks on each operation. When a feature
is off here, the operation it gates answers 403 feature_disabled.
Call this before offering a feature to your customer, and cache the
result for a few minutes at most.
Read-only. Features are turned on and off by CorpX under your contract. Any credential of the tenant can call this route, whatever its scopes.
A feature being on does not grant scopes: each operation still needs the scope listed on it. New features can appear in this list; treat an unknown key as not relevant to you.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.