Barrion Docs
Public API

Credits

Read your balance and credit history, and understand what an API pentest is charged.

API pentests spend the same credits as pentests you start from the dashboard, at the same prices. Passive scans are free. Reading credits needs credits:read.

How a pentest is charged

  1. When the run starts, its level's credits are held: they leave your available balance so nothing else can spend them.
  2. When it finishes, it is charged what it actually used, never less than 100 credits and never more than it held. The rest comes back to your balance, usually within a minute or two of the run ending.
  3. A run that fails is not charged.
  4. A run that is cancelled is charged only for the work it got through, with no minimum. Cancelled before it started, it costs nothing.
  5. On Standard and Deep, part of the held credits pays for the expert review. That part stays held after the run finishes, and is charged when a reviewer signs the report off.

The 100-credit minimum means even a very short run costs 100 credits. If a pipeline starts a pentest on every push, that adds up quickly: start pentests from a scheduled job or a release, and use free passive scans on every deploy.

Level (depth)Credits held
Light (LEAD)400
Standard (STANDARD)1,000
Deep (DEEP)4,000

A run is only started when your balance covers its whole level. Each key's own budget applies as well, see The credit budget. The full pricing is on Credits.

Get your balance

GET /v1/credits/balance · permission credits:read

curl https://api.barrion.io/v1/credits/balance \
  -H "Authorization: Bearer $BARRION_API_KEY"
const res = await fetch("https://api.barrion.io/v1/credits/balance", {
  headers: { Authorization: `Bearer ${process.env.BARRION_API_KEY}` },
});
const balance = (await res.json()) as CreditBalance;
balance = requests.get(
    "https://api.barrion.io/v1/credits/balance",
    headers={"Authorization": f"Bearer {os.environ['BARRION_API_KEY']}"},
).json()

Response 200

type CreditBalance = {
  available: number;            // what you can spend now: plan + purchased
  held: number;                 // reserved by unsettled runs, already out of available
  plan: number;
  purchased: number;
  nextExpiry: { amount: number; at: string; bucket: "PLAN" | "PURCHASED" | "MIXED" } | null;
  includedPerCycle: number;     // what your plan grants each cycle
  nextGrantAt: string | null;   // null without a subscription
  topupUnitPrice: number;
  capacity: number;
  usedFraction: number;
  lowBalance: boolean;
};
{
  "available": 800,
  "held": 400,
  "plan": 400,
  "purchased": 400,
  "nextExpiry": { "amount": 400, "at": "2026-11-01T00:00:00.000Z", "bucket": "PLAN" },
  "includedPerCycle": 1000,
  "nextGrantAt": "2026-10-01T00:00:00.000Z",
  "topupUnitPrice": 0.5,
  "capacity": 1000,
  "usedFraction": 0.2,
  "lowBalance": false
}

List your credit history

GET /v1/credits/usage · permission credits:read

Prop

Type

curl "https://api.barrion.io/v1/credits/usage?limit=50" \
  -H "Authorization: Bearer $BARRION_API_KEY"

Response 200

type CreditHistoryPage = {
  entries: CreditEntry[];       // newest first
  nextCursor: string | null;    // null on the last page
  allowance: object | null;     // your allowance, when you only see your own spending
};

type CreditEntry = {
  id: string;
  reason: string;               // e.g. HOLD, HOLD_SETTLE, HOLD_RELEASE, GRANT_PLAN_CYCLE, PURCHASE_TOPUP, EXPIRE
  detail: string | null;        // why the row moved, when the reason alone does not say
  amount: number;               // signed
  planDelta: number;
  purchasedDelta: number;
  planBalanceAfter: number;
  purchasedBalanceAfter: number;
  sourceRef: string | null;     // the pentest id on a run's rows
  createdAt: string;
  apiKey?: { id: string; name: string }; // on rows of a run an API key started
};
{
  "entries": [
    {
      "id": "9a0c...",
      "reason": "HOLD",
      "detail": null,
      "amount": -400,
      "planDelta": -400,
      "purchasedDelta": 0,
      "planBalanceAfter": 400,
      "purchasedBalanceAfter": 400,
      "sourceRef": "3f9e2c7a-...",
      "createdAt": "2026-09-28T10:02:11.000Z",
      "apiKey": { "id": "b81d...", "name": "Release pipeline" }
    }
  ],
  "nextCursor": "eyJ...",
  "allowance": null
}
  • Rows from a run a key started carry apiKey, so you can tell pipeline spend from dashboard spend.
  • In an organization, your role decides how much you see: the whole organization's history, or only your own spending. When it is only your own, allowance shows your spending allowance for the cycle.