Bulk toggle the current user’s subscription states
Unavailable through the public API: current access controls reject this preference-centre operation. Use PATCH /users//subscriptions from a trusted server with a project secret key instead. The intended contract subscribes or unsubscribes the user bound to the calling session token across one or more subscription types. Designed for browser-side preference-centre opt-out flows: pass a publishable key (pk_…) plus a user session token (see POST /users/{userId}/sessions) in the X-Spotzee-User-Token header. Up to 100 toggles per request. Toggling to the current state is a no-op (idempotent).
Idempotent — pass an Idempotency-Key header to make safely retryable. On a replay the original response is returned with Idempotent-Replayed: true. See the API conventions guide for the full state machine, TTL, and mismatch behaviour.
Authorizations
Project-scoped publishable key (pk_…). Safe for browser use. Allowed only on a strict allow-list of endpoints.
Short-lived signed token that scopes the call to one user. Mint via POST /users/{userId}/sessions (sk_-only). Required alongside a publishable key on the preference-centre endpoints.
Body
1 - 100 elementsResponse
The refreshed subscription states for the user bound to the session.
Paginated response of UserSubscriptionList.
Page of results, ordered per the request’s sort and direction.
Opaque cursor for the next page. null when no further pages exist.
Opaque cursor for the previous page. null when on the first page.
Page size used to build this response.