Get a subscription
Returns one subscription scoped to the authenticated tenant. An absent, soft-deleted, or cross-tenant id returns a uniform 404 not_found (no existence oracle). The response never carries the signing secret.
Authorizations
A bearer JWT issued by plugin-auth (lib-auth). The tenant identity is resolved from the validated token claims; the /v1 surface never reads a tenant from the body, path, or query. Machine callers obtain a token via the plugin-auth client-credentials flow. The /admin surface authorizes against an operator scope and carries no tenant context.
Path Parameters
The unique identifier of the subscription (UUIDv7).
Response
The subscription.
The non-secret projection of a subscription. It never carries the signing secret or any credential material.

