Access and plans
Which Koast plans can use the REST API, webhooks, the CLI and the MCP server, and what a refused call looks like.
| Surface | Who can use it |
|---|---|
REST API (https://api.koast.ai/v1) | Agency plans with an active subscription |
| Webhooks | Agency plans with an active subscription |
koast CLI | Same as the REST API: it is a REST client |
MCP server (https://mcp.koast.ai/mcp) | Every paid plan with an active subscription |
The free plan and cancelled subscriptions get none of them. A subscription that is past due still counts as active.
What a refused call looks like
A credential from an organization that isn't on an active Agency plan gets 403 plan_required on every /v1 endpoint, before anything else runs:
HTTP/1.1 403 Forbidden
Koast-Request-Id: 56fa02f9-f50c-4324-a49b-de7484d5da8f
Content-Type: application/json; charset=utf-8{
"error": {
"code": "plan_required",
"message": "The Koast API is available on Agency plans with an active subscription.",
"details": null,
"requestId": "56fa02f9-f50c-4324-a49b-de7484d5da8f"
}
}The same answer comes back for a key created on a non-Agency plan, and for an OAuth token of someone whose organization isn't on Agency.
In the app
- In Settings, API Keys, the API switch on a key is locked on non-Agency plans. The note reads Requires an Agency plan.
- Creating a webhook endpoint, enabling one or switching one back on needs an Agency plan. Listing, reading, disabling and deleting endpoints stay open, so an organization that leaves Agency can clean up.
Changing plan
- Upgrade to Agency: turn on API access on an existing key, or create a new key with API on. Nothing else changes.
- Leave Agency:
/v1calls start answeringplan_requiredstraight away. MCP keeps working on any paid plan.
See Authentication for the other checks a key goes through.