openapi: 3.0.1 info: title: Polar benefits customer_portal API description: Polar is an open-source Merchant of Record (MoR) and monetization platform for developers. This document models the core organization-facing REST surface of the Polar API - products and prices, checkouts, customers, subscriptions, orders, benefits and license keys, usage meters and events, and webhooks. All requests are authenticated with a Bearer Organization Access Token. The canonical, machine-generated specification is published by Polar at https://api.polar.sh/openapi.json; this is a curated subset for the API Evangelist catalog. termsOfService: https://polar.sh/legal/terms contact: name: Polar Support email: support@polar.sh url: https://polar.sh/docs license: name: Apache-2.0 url: https://github.com/polarsource/polar/blob/main/LICENSE version: 2026-04 servers: - url: https://api.polar.sh/v1 description: Production environment - url: https://sandbox-api.polar.sh/v1 description: Sandbox environment security: - oat: [] tags: - name: customer_portal description: Customer-facing portal endpoints (Customer Session token). paths: /customer-portal/license-keys/validate: post: operationId: customerPortal:validateLicenseKey tags: - customer_portal summary: Validate License Key (Customer Portal) description: Customer-facing license key validation using a Customer Session token rather than an Organization Access Token. security: - customer_session: [] requestBody: required: true content: application/json: schema: type: object required: - key - organization_id properties: key: type: string organization_id: type: string format: uuid responses: '200': description: The validation result. content: application/json: schema: $ref: '#/components/schemas/LicenseKey' components: schemas: LicenseKey: type: object properties: id: type: string format: uuid key: type: string status: type: string enum: - granted - revoked - disabled organization_id: type: string format: uuid customer_id: type: string format: uuid benefit_id: type: string format: uuid usage: type: integer limit_usage: type: integer nullable: true expires_at: type: string format: date-time nullable: true securitySchemes: oat: type: http scheme: bearer description: Organization Access Token used for backend, organization-scoped operations. pat: type: http scheme: bearer description: Personal Access Token scoped to a user. customer_session: type: http scheme: bearer description: Customer Session token used for customer portal endpoints.