# Get a customer

`GET /api/v1/customers/{id}`

One customer by id. Requires the "customers:read" scope.

Scope: `customers:read`

## Parameters

- `id` (path, string, required) — Awrora id (UUID) for the customer.

## Responses

- `200` — The customer.
- `401` — Missing, invalid, revoked or expired API key — codes "api_key_missing", "api_key_invalid", "api_key_revoked", "api_key_expired".
- `403` — The API app is off, the plan does not include the API, or the key lacks the required scope — codes "app_not_enabled", "plan_upgrade_required", "insufficient_scope" (the last carries "required_scope").
- `404` — No such resource. The same response is returned for a resource that belongs to another organization — code "not_found".
- `429` — Rate limit exceeded — code "rate_limited". See the x-ratelimit-* headers.
- `500` — Something went wrong on our side — code "internal_error".

## Response `200`

- `id` (string, required) — Awrora id (UUID) for the customer record.
- `name` (string, required) — Customer name.
- `email` (string, required) — Customer email. Unique within the organization.
- `phone` (string | null, required) — Phone number, or null.
- `tags` (string[], required) — Merchant-defined tags. May be empty.
- `email_subscription` (boolean, required) — True when the customer has opted in to marketing email.
- `created_at` (string, required) — ISO 8601 timestamp with offset.

## Example

```bash
curl -X GET "https://your-site.awrora.app/api/v1/customers/id_8f2k3n" \
  -H "Authorization: Bearer $AWRORA_API_KEY"
```