> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apostra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get organization posture

> Returns the caller's posture for Organization settings in buyer and seller accounts. Available to all eligible organization contexts; returns 403 when no customer context is present, or 503 when a backing dependency is temporarily unavailable. The posture value describes the caller's relationship to the organization: `direct_parent_admin` (ADMIN on the parent organization or non-impersonated SUPER_ADMIN), `child_standalone` (direct non-propagated child member without organization-admin authority), `standalone` (PARENT or STANDALONE — the account is its own organization boundary), or `ineligible` (service token, workload, advertiser-scoped, impersonated, or other excluded principal class). The value drives which UI slice to render and never confers additional write authority — every write retains its own explicit-target authorization.



## OpenAPI

````yaml /v2/storefront-api-v2.yaml get /accounts/organization-posture
openapi: 3.0.0
info:
  title: Scope3 Storefront API
  version: 2.0.0
  description: >-
    REST API for partners to manage Seller Accounts, inventory sources, and
    billing.


    ## Authentication


    All endpoints require a Bearer token in the Authorization header:

    ```

    Authorization: Bearer your-api-key

    ```


    ## Base URL


    `https://api.apostra.com/api/v2/storefront`


    ## For AI Agents


    AI agents can use the MCP endpoint at `/mcp/v2/storefront` with three tools:

    - `initialize`: Start an MCP session

    - `api_call`: Make REST API calls

    - `ask_about_capability`: Learn about API features
servers:
  - url: https://api.apostra.com/api/v2/storefront
    description: Production server
security: []
tags:
  - name: Account
    description: Account management, service tokens, and preferences
  - name: Asks
    description: >-
      What you are waiting on Scope3 for — support, product, and supply asks in
      one list
  - name: Storefront
    description: Manage storefront and inventory sources
  - name: Storefront Agents
    description: List and manage registered sales, signals, and outcomes agents
  - name: Storefront Activity
    description: Audit log of configuration and inventory changes on the storefront
  - name: Storefront Billing
    description: Payout bank details and billing configuration for Seller Accounts
  - name: AI Usage
    description: Seller Account AI token usage visibility by model
  - name: MCP
    description: Model Context Protocol endpoints
paths:
  /accounts/organization-posture:
    servers:
      - url: https://api.apostra.com/api/v2
        description: Production server
    get:
      tags:
        - Account
      summary: Get organization posture
      description: >-
        Returns the caller's posture for Organization settings in buyer and
        seller accounts. Available to all eligible organization contexts;
        returns 403 when no customer context is present, or 503 when a backing
        dependency is temporarily unavailable. The posture value describes the
        caller's relationship to the organization: `direct_parent_admin` (ADMIN
        on the parent organization or non-impersonated SUPER_ADMIN),
        `child_standalone` (direct non-propagated child member without
        organization-admin authority), `standalone` (PARENT or STANDALONE — the
        account is its own organization boundary), or `ineligible` (service
        token, workload, advertiser-scoped, impersonated, or other excluded
        principal class). The value drives which UI slice to render and never
        confers additional write authority — every write retains its own
        explicit-target authorization.
      operationId: getOrganizationPosture
      responses:
        '200':
          description: Get organization posture
          content:
            application/json:
              schema:
                type: object
                properties:
                  authorityCustomerId:
                    type: integer
                    minimum: 0
                    exclusiveMinimum: true
                    maximum: 9007199254740991
                  authorityEpoch:
                    type: string
                    pattern: ^[0-9a-f]{16}$
                  posture:
                    type: string
                    enum:
                      - direct_parent_admin
                      - child_standalone
                      - standalone
                      - ineligible
                required:
                  - authorityCustomerId
                  - authorityEpoch
                  - posture
                additionalProperties: false
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            ACCESS_DENIED when no customer context is present;
            FEATURE_NOT_ENABLED when the posture resolver returns no posture
            (compatibility response).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: >-
            SERVICE_UNAVAILABLE — a retryable topology or backing failure
            prevented posture resolution. The response body contains only a
            stable generic message; diagnostic detail is logged server-side. The
            client should retry with backoff.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        data:
          type: string
          nullable: true
          enum:
            - null
        error:
          $ref: '#/components/schemas/ApiError'
      required:
        - data
        - error
      additionalProperties: false
      description: Standard error response
    ApiError:
      type: object
      properties:
        code:
          type: string
          description: Machine-readable error code
        message:
          type: string
          description: Human-readable error message
        field:
          description: Field path associated with the error
          type: string
        details:
          description: Additional error context
          type: object
          additionalProperties: {}
      required:
        - code
        - message
      additionalProperties: false
      description: Structured error object
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key or access token

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.