Overview

Bugnet exposes the same REST API the dashboard uses, so you can build custom integrations, automate triage, and manage projects programmatically. There are two ways in:

  • Public API — what a game client or public web page calls: bug submission, sessions, telemetry, and the public tracker, roadmap and changelog. Authenticated with the project API key, or not at all.
  • REST API — everything a team member can do in the dashboard. Authenticated with a user session token.
  • Base URL: https://api.bugnet.io (paths below start with /api/). https://bugnet.io/api/… reaches the same API.
  • Versioned paths: every /api/… route is also served under /api/v1/…. Pin to /api/v1/ in long-lived integrations.
  • Request and response bodies are JSON (UTF-8) unless an endpoint says it takes a file upload.
  • Projects are addressed by slug. Bug reports are addressed by their per-project report number (the #12 in the dashboard), not their UUID — :number below.
🔎

Prefer an interactive reference? The API Explorer renders Bugnet’s OpenAPI specs with full request and response schemas, and lets you send test requests. Download the specs directly: public.yaml (SDK & public endpoints) and rest.yaml (core REST resources).

Bash
# Example: list your projects
curl https://api.bugnet.io/api/projects \
  -H "Authorization: Bearer YOUR_SESSION_TOKEN"

Authentication

Which credential an endpoint takes depends on who is calling it.

Session token (REST API)

Sign in with POST /api/auth/login (email and password) to get a session token, then send it on every request. Tokens last 30 days; POST /api/auth/logout revokes one early. A session token acts as that user on every project in their account, so keep it on a server.

HTTP
Authorization: Bearer YOUR_SESSION_TOKEN

Project API key (SDK / Public API)

Game clients authenticate with the project’s API key (sk_live_…), shown on the project’s Integrate tab and rotated with POST /api/projects/:slug/rotate-key. Most SDK endpoints take it in a header:

HTTP
X-API-Key: sk_live_YOUR_PROJECT_KEY

The two session endpoints (/api/sessions/start and /api/sessions/end) take it as api_key in the JSON body instead. An API key is accepted only while the project’s Public setting (is_public) is on, which is the default; turning it off makes every SDK call fail with 401 invalid API key.

⚠️

Never ship a session token in a game build. The API key can only file reports and telemetry into one project; a session token can read and change everything its user can.

Rate Limits

Limits are counted per client IP over a one-minute window. Every request counts toward the global budget; some routes also have their own, tighter budget, and whichever runs out first applies.

Applies toLimit
Every request (global)300 requests/minute
Public & SDK endpoints (bug submit, sessions, events, tracker, roadmap, changelog, branding, files)30 requests/minute
/api/perf/snapshot and /api/session-replays120 requests/minute
Login, signup and resend-verification10 requests/minute

Responses carry the budget that applied:

  • X-RateLimit-Limit — requests allowed in the window
  • X-RateLimit-Remaining — requests left in the window
  • X-RateLimit-Reset — Unix time (seconds) the window resets

Past the limit the API returns 429 Too Many Requests with a Retry-After header (seconds). Wait that long before retrying.

Response Format

Every JSON response uses the same envelope, with an ok boolean saying whether the request succeeded.

Success Response

JSON
{
  "ok": true,
  "data": {
    "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
    "report_number": 42
  }
}

Error Response

JSON
{
  "ok": false,
  "error": "title and description are required"
}

Common HTTP Status Codes

CodeMeaning
200Success (also returned when a submitted report was stacked onto an existing one)
201Created
400Bad request — malformed JSON or a validation error
401Missing or invalid session token or API key
403You lack the permission, the feature isn’t on your plan, or a plan limit is reached
404Not found — also returned for projects you are not a member of
409Conflict (e.g. email already registered, label already exists)
429Rate limited
500Server error

Enumerations

FieldValues
statusopen, in_progress, resolved, closed, wont_fix
prioritycritical, high, medium, low
categorycrash, visual, gameplay, performance, audio, ui, network, other

SDK Endpoints

Called from inside your game. All use the project API key. Full schemas are in the Public API explorer.

Bug reports

POST /api/bugs/submit

Submit a bug report. Requires title and description; optional priority, category, platform, game_version, os_info, device_info, steps_to_reproduce, expected_behavior, actual_behavior, screenshot (base64), steam_id, reporter_name, reporter_email, metadata (any JSON, ≤16 KB), attachments (up to 10 base64 files), auto_captured. Returns 201 with the new report, or 200 with deduplicated: true when grouping stacked it onto an existing report with the same title. Body limit 20 MB.

POST /api/bugs/:id/attachments

Attach one file to a report you just submitted, using the id from the submit response. Body: {filename, mime_type, data} with base64 data. Text, image, video and JSON only, ≤10 MB.

GET /api/bugs/settings

The project’s SDK settings: screenshot capture, session capture (Studio Plus only), auto-filing of errors, editor-error and warning capture, and the in-game widget theme.

Example: submit a bug report

Bash
curl -X POST https://api.bugnet.io/api/bugs/submit \
  -H "X-API-Key: sk_live_YOUR_PROJECT_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "Player falls through floor on level 3",
    "description": "Near the bridge the collision mesh has a gap.",
    "category": "gameplay",
    "priority": "high",
    "platform": "Windows",
    "game_version": "1.2.0",
    "steps_to_reproduce": "1. Start level 3\n2. Walk to the bridge\n3. Jump near the left railing"
  }'
JSON
{
  "ok": true,
  "data": {
    "id": "0b6e3f5c-8a1d-4f2e-9c47-5d3a2b1e0f98",
    "report_number": 42,
    "message": "Bug report submitted successfully!",
    "category": "gameplay",
    "priority": "high",
    "sentiment_score": 0,
    "sentiment_level": "calm",
    "possible_duplicates": [17]
  }
}

Sessions

POST /api/sessions/start

Start a play session. Body: {api_key, session_token, platform, game_version, device_info, os_info, steam_id, player_name} — api_key and a client-generated session_token are required. Returns 409 if the token was already used.

POST /api/sessions/end

End a session. Body: {api_key, session_token, crashed}. Sessions ending with crashed: true lower the crash-free rate.

Telemetry

POST /api/events/track

Track one custom event. Body: event_name (required, ≤100 chars), event_data (JSON object, ≤4 KB), session_token, platform, game_version. Studio and Studio Plus only.

POST /api/events/track/batch

Track 1–50 events in one request. Body: {events: [...]}, each shaped like a single event.

POST /api/perf/snapshot

Attach performance metrics to a report. Body: bug_report_id (required) plus any of fps, frame_time_ms, memory_used_mb, memory_total_mb, draw_calls, triangles, cpu_usage, gpu_usage, load_time_sec, network_latency_ms, custom_metrics (string).

POST /api/session-replays

Upload a session recording for a report as multipart/form-data: bug_report_id, file (WebM, MP4 or GIF), optional duration_sec and metadata. Studio Plus only.

Public Endpoints

No authentication. These power the public tracker, roadmap and changelog, and are safe to call from any web page.

Public tracker

GET /api/tracker/:slug

Public bug list, 25 per page, most-upvoted first. Query: status, category, q (search, if the tracker allows it), page. 404 unless the tracker is enabled.

GET /api/tracker/:slug/bugs/:number

One public bug with its non-internal comments.

POST /api/tracker/:slug/bugs/:number/vote

Upvote a bug. Optional body {player_id}; without it the voter is identified by IP. One vote per voter — repeats return the current count with is_new: false.

Public roadmap

GET /api/roadmap/:slug

Roadmap settings and the bugs in the statuses the roadmap shows. 404 unless the roadmap is enabled.

POST /api/roadmap/:slug/bugs/:number/vote

Upvote a roadmap item. Same rules as the tracker vote; 403 unless the roadmap shows upvotes.

Changelog, branding and files

GET /api/projects/:slug/changelog

Up to 50 published changelog entries, newest first.

GET /api/branding/:slug

Public branding: logo, colors, company name, support email.

GET /api/files/:key

Download an uploaded screenshot, attachment or replay. Use the file_url / screenshot_url values returned elsewhere — they already include this prefix.

Status

GET /health

Health check at the API root (not under /api). Returns {"status": "healthy"} with 200, or 503 when the database is unreachable. Not wrapped in the response envelope.

GET /api/maintenance/active

The maintenance banner currently in effect, if any.

Example: health check

Bash
curl https://api.bugnet.io/health
JSON
{"status":"healthy"}

Auth Endpoints

Sign in, manage the signed-in user, and export or delete their data.

POST /api/auth/signup

Create an account and sign in. Body: {name, email, password} — password at least 8 characters. Returns 409 if the email is taken.

POST /api/auth/login

Sign in. Body: {email, password}. Returns a session token.

POST /api/auth/logout

Revoke the session token used for this request.

GET /api/auth/me

The signed-in user’s profile.

PATCH /api/auth/profile

Update your profile. Body (any of): {display_name, avatar_url, theme, role}.

POST /api/auth/change-password

Change password. Body: {current_password, new_password}. Email/password accounts only.

POST /api/auth/support-share-code

Create a temporary code you can give Bugnet support so they can find your account. Query: hours (1, 3 or 24; default 1).

DELETE /api/auth/support-share-code

Revoke your support share code.

GET /api/account/export

Download your profile, projects, reports and comments as JSON.

DELETE /api/auth/account

Permanently delete your account and cancel any subscription you pay for. Body: {"confirmation": "DELETE"}.

GET /api/auth/verify-email

Verify an email address. Query: token (from the verification email).

POST /api/auth/resend-verification

Resend the verification email.

Example: sign in

Bash
curl -X POST https://api.bugnet.io/api/auth/login \
  -H "Content-Type: application/json" \
  -d '{"email": "dev@example.com", "password": "your_password"}'
JSON
{
  "ok": true,
  "data": {
    "token": "3f9a1c...",
    "user_id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
    "email": "dev@example.com",
    "name": "Dev",
    "onboarding_done": true,
    "email_verified": true
  }
}

Project Endpoints

Projects belong to your account. You see every project in the account you work in.

GET /api/projects

List your projects with bug counts.

POST /api/projects

Create a project. Body: {name, slug, description, website_url} — only name is required. The stored slug gets a short prefix to keep it unique (e.g. a1b2c3-my-game), so use the slug in the response. Also returns the new api_key.

GET /api/projects/:slug

Project details, SDK settings, API key, stats and your role.

PATCH /api/projects/:slug

Update a project. Body (any of): name, description, website_url, logo_url, is_public, screenshot_capture, session_capture, auto_file_errors, capture_editor_errors, capture_warnings, bug_grouping.

DELETE /api/projects/:slug

Delete a project and its reports. Account owner (or the teammate who created it) only.

POST /api/projects/:slug/rotate-key

Issue a new API key. The old key stops working immediately.

GET /api/projects/:slug/setup-status

Whether the SDK has sent its first report, session and so on (drives the onboarding checklist).

POST /api/projects/:slug/send-test-report

File a sample report to check your integration end to end.

Example: create a project

Bash
curl -X POST https://api.bugnet.io/api/projects \
  -H "Authorization: Bearer YOUR_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "My Cool Game",
    "slug": "my-cool-game",
    "description": "An awesome platformer",
    "website_url": "https://mycoolga.me"
  }'

Bug Endpoints

Manage reports inside a project. :number is the report number, not the UUID. To file reports from a game, use POST /api/bugs/submit above.

Reports

GET /api/projects/:slug/bugs

List reports, 25 per page. Query: status, priority, category, q (full-text search), assigned_to (user ID or unassigned), label (label ID), source (user or system), error_type (an exception/error class such as NullReferenceException), sort (priority, upvotes, updated; default newest), page.

POST /api/projects/:slug/bugs

Create a report as yourself. Body: title and description (required), priority, category, platform, game_version, os_info, device_info, steps_to_reproduce, expected_behavior, actual_behavior.

GET /api/projects/:slug/bugs/:number

A report with its comments and labels.

GET /api/projects/:slug/error-types

The exception/error classes found in the project’s reports, each with a report count, most common first: [{error_type, count}]. Every report’s error_type is read from its title and stack trace (e.g. NullReferenceException, TypeError, ZeroDivisionError, SIGSEGV), and is empty when it names none.

PATCH /api/projects/:slug/bugs/:number

Update a report. Body (any of): title, description, status, priority, category, assigned_to (needs bugs.assign), is_private, platform.

DELETE /api/projects/:slug/bugs/:number

Delete a report. Deleted reports still count toward your plan’s report quota.

PATCH /api/projects/:slug/bugs/bulk

Update up to 100 reports. Body: bug_ids or bug_numbers, plus any of status, priority, category, assigned_to, is_private.

DELETE /api/projects/:slug/bugs/bulk

Delete up to 100 reports. Body: bug_ids or bug_numbers.

GET /api/projects/:slug/bugs/similar

Find reports similar to a title. Query: title.

GET /api/projects/:slug/bugs/export

Download reports as CSV. Query: status, priority.

Comments, activity and attachments

POST /api/projects/:slug/bugs/:number/comments

Add a comment. Body: {body, is_internal}. Internal comments never appear on the public tracker.

GET /api/projects/:slug/bugs/:number/activity

The report’s activity log.

GET /api/projects/:slug/bugs/:number/attachments

List attachments.

POST /api/projects/:slug/bugs/:number/attachments

Upload an attachment as multipart/form-data field file (≤10 MB; text, image, video or JSON).

GET /api/projects/:slug/activity

Recent activity across the project. Query: action to filter by action type.

GET /api/projects/:slug/audit-log

Project audit log of settings, label, member and integration changes. Query: page.

Grouping and occurrences

GET /api/projects/:slug/bugs/:number/occurrences

The individual submissions stacked onto this report, 50 per page. Query: page.

POST /api/projects/:slug/bugs/:number/split

Split selected occurrences off into their own report.

Dependencies, due dates and custom fields

GET /api/projects/:slug/bugs/:number/dependencies

Reports this one blocks or is blocked by.

POST /api/projects/:slug/bugs/:number/dependencies

Link two reports. Body: {related_number, relationship} where relationship is blocks or blocked_by.

DELETE /api/projects/:slug/dependencies/:depId

Remove a dependency link.

PATCH /api/projects/:slug/bugs/:number/due-date

Set or clear a due date. Body: {due_date} (null clears it).

GET /api/projects/:slug/bugs/:number/custom-fields

Custom field values for a report.

POST /api/projects/:slug/bugs/:number/custom-fields

Set a custom field value. Body: {field_id, value}.

Example: list open high-priority reports

Bash
curl "https://api.bugnet.io/api/projects/my-cool-game/bugs?status=open&priority=high&sort=updated&page=1" \
  -H "Authorization: Bearer YOUR_SESSION_TOKEN"

Example: resolve a report

Bash
curl -X PATCH https://api.bugnet.io/api/projects/my-cool-game/bugs/42 \
  -H "Authorization: Bearer YOUR_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"status": "resolved"}'

Labels & Organization

Labels, templates, custom fields, SLA rules, saved filters and saved views.

Labels

GET /api/projects/:slug/labels

List labels.

POST /api/projects/:slug/labels

Create a label. Body: {name, color} (color defaults to #2E5BFF).

PATCH /api/projects/:slug/labels/:labelId

Rename or recolor a label. Body: {name, color}.

DELETE /api/projects/:slug/labels/:labelId

Delete a label and remove it from every report.

POST /api/projects/:slug/bugs/:number/labels

Apply a label. Body: {label_id}.

DELETE /api/projects/:slug/bugs/:number/labels/:labelId

Remove a label from a report.

Templates and custom fields

GET /api/projects/:slug/templates

List bug templates.

POST /api/projects/:slug/templates

Create a template. Body: {name, description, priority, category, body_template}.

PATCH /api/projects/:slug/templates/:templateId

Update a template.

DELETE /api/projects/:slug/templates/:templateId

Delete a template.

GET /api/projects/:slug/custom-fields

List custom field definitions.

POST /api/projects/:slug/custom-fields

Define a custom field. Body: {name, field_type, options, is_required}.

DELETE /api/projects/:slug/custom-fields/:fieldId

Delete a custom field.

SLA rules

GET /api/projects/:slug/sla

Response and resolution targets per priority.

PUT /api/projects/:slug/sla

Replace the SLA rules. Body: {rules: [{priority, response_hours, resolve_hours}]}.

Saved filters and views

GET /api/saved-filters

Your saved filters.

POST /api/saved-filters

Save a filter. Body: {name, project_id, filters}.

DELETE /api/saved-filters/:filterId

Delete a saved filter.

GET /api/saved-views

Your saved views.

POST /api/saved-views

Save a view. Body: {name, project_id, filters, sort_by, pinned}.

PATCH /api/saved-views/:viewId

Update a view (including position for ordering).

DELETE /api/saved-views/:viewId

Delete a saved view.

Import

POST /api/projects/:slug/import

Bulk-import reports from another tracker. Body: {bugs: [{title, description, status, priority, category, platform, game_version, steps_to_reproduce, external_id, external_url, source}]}.

GET /api/projects/:slug/imports

Previously imported reports and where they came from.

Account & Team Endpoints

Your team is a roster on your account, and the account owns every project on it. One invitation gives someone the whole account; removing them takes all of it away. The project-scoped routes further down are views onto the same roster.

GET /api/account

The account you work in: name, your role, plan, members, pending invitations, projects, usage and limits.

PATCH /api/account

Rename the account. Body: {name}. Owner or admin only.

GET /api/account/members

List the account roster and any pending invitations.

PATCH /api/account/members/:userId

Change a member’s role across the whole account. Body: {role} — admin or member.

DELETE /api/account/members/:userId

Remove a member from the account and from every project on it. Passing your own user ID leaves the account.

POST /api/account/invites

Invite someone to the account. Body: {email, role}. Returns the invitation token. Counts toward your plan’s seat limit.

POST /api/account/invites/accept

Accept an invitation. Body: {token}.

DELETE /api/account/invites/:inviteId

Revoke a pending invitation.

The project-scoped equivalents act on the account that project belongs to: GET /api/projects/:slug/members, PATCH and DELETE /api/projects/:slug/members/:userId, POST /api/projects/:slug/invites, DELETE /api/projects/:slug/invites/:inviteId, and POST /api/invites/accept.

Permissions

Permissions are set per member on the account and apply to every project in it. The project-scoped routes GET /api/projects/:slug/permissions and GET/PUT/DELETE /api/projects/:slug/permissions/:userId act on the same account-wide overrides.

GET /api/permissions

Your effective permissions in the account you work in.

GET /api/permissions/available

The permission catalog: groups, keys and each role’s defaults.

GET /api/account/members/:userId/permissions

A member’s effective permissions and overrides.

PUT /api/account/members/:userId/permissions

Grant or revoke permissions for a member. Body: permissions (key → true/false), groups (group → true/false), reset (drop existing overrides first). Needs team.permissions; owners are never edited and only the owner edits an admin.

DELETE /api/account/members/:userId/permissions

Reset a member to their role defaults.

Analytics Endpoints

Dashboard analytics, crash data, release health, performance, regressions, satisfaction, players and events. All take a session token.

Dashboard and usage

GET /api/analytics/dashboard

Cross-project analytics for the signed-in user: reports by status, priority and category, and trends.

GET /api/usage

Report and session volume for each of your projects (today, 7 and 30 days).

GET /api/projects/:slug/usage

The same usage figures for one project.

Crashes and release health

GET /api/projects/:slug/crash-analytics

Crash-free session rate and its 30-day trend, top crash signatures, platform breakdown.

GET /api/projects/:slug/bad-deploy

Compares the crash rate of the two newest game versions (each with at least 10 sessions) to flag a bad release.

GET /api/projects/:slug/crash-groups

Crash reports clustered by signature. Studio and up.

GET /api/projects/:slug/release-health

Health score, grade and crash-free rate for each game version.

GET /api/projects/:slug/release-health/version

Drill-down for one version. Query: version.

Regressions and triage

GET /api/projects/:slug/regressions/detect

Find new reports that look like previously resolved ones.

GET /api/projects/:slug/regressions

Regressions that have been confirmed or dismissed.

POST /api/projects/:slug/regressions

Confirm or dismiss a detected regression. Body: {original_bug_id, new_bug_id, status, resolved_version, regressed_version} with status confirmed or dismissed.

GET /api/projects/:slug/bugs/:number/triage

Auto-triage suggestions for one report. Studio and up.

GET /api/projects/:slug/churn-risk

Players whose recent reports suggest they may stop playing. Studio and up.

Performance and replays

GET /api/projects/:slug/bugs/:number/perf

The performance snapshot captured with a report.

GET /api/projects/:slug/perf-summary

Project-wide performance averages.

GET /api/projects/:slug/bugs/:number/replays

Session replays attached to a report (Studio Plus).

Satisfaction

POST /api/projects/:slug/bugs/:number/satisfaction

Rate how a report was handled. Body: {rating, comment} with rating 1–5.

GET /api/projects/:slug/bugs/:number/satisfaction

The rating for one report.

GET /api/projects/:slug/satisfaction

Rating distribution, monthly trend and per-category averages.

Players

GET /api/projects/:slug/players

Players seen through sessions and reports.

GET /api/projects/:slug/players/:playerId

One player’s profile.

PATCH /api/projects/:slug/players/:playerId

Update a player’s notes and sentiment. Body: {notes, sentiment} with sentiment positive, neutral or negative.

GET /api/projects/:slug/players/:playerId/sessions

A player’s sessions.

GET /api/projects/:slug/players/:playerId/bugs

Reports linked to a player.

GET /api/projects/:slug/customers/overview

Player totals and contact overview.

Events and live logs

Studio+
GET /api/projects/:slug/events

Event names with counts and unique sessions. Query: days (1–90, default 30).

GET /api/projects/:slug/events/summary

Daily volume and the top 5 events. Query: days.

GET /api/projects/:slug/events/:name/details

One event’s daily trend, platform breakdown and last 50 raw events. Query: days.

GET /api/projects/:slug/log-stack

A reverse-chronological feed of events, reports and team activity. Query: days (1, 7, 30 or 90), page. Studio plan and up; returns 403 on the free plan.

Integration Endpoints

Webhooks, Slack, Microsoft Teams, PagerDuty, Opsgenie, Sentry, Linear, ClickUp, Jira, Asana, Trello, Airtable, monday.com, Notion, Google Play, App Store, Discord, GitHub/GitLab, Steam, alerts and notifications. See Integrations for payloads and setup.

Webhooks

GET /api/projects/:slug/webhooks/generic

List webhooks.

POST /api/projects/:slug/webhooks/generic

Create a webhook. Body: {url, name, event_types, secret} — event_types is a comma-separated string (default bug_created,bug_updated,comment_added).

DELETE /api/projects/:slug/webhooks/generic/:webhookId

Delete a webhook.

POST /api/projects/:slug/webhooks/generic/:webhookId/test

Send a test payload and report the receiver’s HTTP status.

GET /api/projects/:slug/webhooks/generic/:webhookId/deliveries

Recorded deliveries for a webhook.

Slack, Microsoft Teams, Linear, ClickUp & other providers

One set of routes for every provider; :provider is slack, teams, pagerduty, opsgenie, sentry, linear, clickup, jira, asana, trello, airtable, monday, notion, googleplay or appstore. Writes need the project.integrations permission.

GET /api/integrations/providers

Providers a project can connect to, with the events each accepts.

GET /api/projects/:slug/integrations

List the project’s connections. Query: provider. Credentials are never returned; secret_hint identifies each one.

POST /api/projects/:slug/integrations/:provider

Connect. Body: {secret, name, event_types, min_priority, config} — secret is the Slack incoming webhook or Teams Workflows URL, the Linear API key or the ClickUp API token; config is {team_id} for Linear and {list_id} for ClickUp; event_types is an array of bug_created, bug_updated, comment_added, digest (trackers take the first two).

POST /api/projects/:slug/integrations/:provider/targets

Where a tracker can file: Linear teams, ClickUp/Trello lists, Jira/Asana/Sentry projects, Airtable tables, monday.com boards, Notion databases. Body: {secret, config}, or {id} of a saved connection.

PATCH /api/projects/:slug/integrations/:provider/:id

Change any of name, secret, event_types, min_priority, is_active.

DELETE /api/projects/:slug/integrations/:provider/:id

Disconnect.

POST /api/projects/:slug/integrations/:provider/:id/test

Send a test message (chat) or check the key and team/list still work (trackers); 502 with the tool’s answer if it is rejected.

GET /api/projects/:slug/integrations/:provider/:id/deliveries

The connection’s 50 most recent messages and their delivery status.

POST /api/projects/:slug/integrations/:provider/:id/sync

Google Play / App Store: import reviews now (otherwise hourly). Returns {fetched, new, filed}.

GET /api/projects/:slug/store-reviews

Imported store reviews, newest first. Query: provider, max_rating, page (50 per page).

POST /api/projects/:slug/store-reviews/:id/reply

Post or replace the public developer reply. Body: {body}. Google Play allows 350 characters.

GET /api/projects/:slug/bugs/:number/issues

Issues trackers filed for a report (links) and the tracker connections that could file it (trackers).

POST /api/projects/:slug/bugs/:number/issues

File a report in a tracker now. Body: {integration_id}. Filing it again through the same connection returns the existing issue.

Discord

GET /api/projects/:slug/webhooks/discord

List Discord channels.

POST /api/projects/:slug/webhooks/discord

Add a Discord webhook. Body: {webhook_url, channel_name, event_types}.

PATCH /api/projects/:slug/webhooks/discord/:webhookId

Update it. Body (any of): webhook_url, channel_name, event_types, is_active.

DELETE /api/projects/:slug/webhooks/discord/:webhookId

Remove it.

POST /api/projects/:slug/webhooks/discord/:webhookId/test

Post a test message to the channel.

Git (GitHub / GitLab)

GET /api/projects/:slug/git

The connected repository.

POST /api/projects/:slug/git

Connect a repository. Body: {provider, repo_url, access_token} with provider github or gitlab.

PATCH /api/projects/:slug/git

Update it. Body: {auto_create_issues, access_token}.

DELETE /api/projects/:slug/git

Disconnect the repository.

GET /api/projects/:slug/git/issues

Search the repository’s issues. Query: q.

POST /api/projects/:slug/bugs/:number/issue

Create an issue in the connected repository from a report, or link an existing one with {issue_number, issue_url, issue_title}.

GET /api/projects/:slug/bugs/:number/issue

The issue linked to a report.

Steam

GET /api/projects/:slug/steam

The connected Steam app.

POST /api/projects/:slug/steam

Connect a Steam app. Body: {app_id}.

PATCH /api/projects/:slug/steam

Update it. Body: {sync_enabled}.

DELETE /api/projects/:slug/steam

Disconnect Steam.

POST /api/projects/:slug/steam/sync

Fetch new reviews now.

GET /api/projects/:slug/steam/dashboard

Review sentiment and recent reviews.

GET /api/projects/:slug/steam/reviews

List synced reviews.

GET /api/projects/:slug/steam/review-history

Positive and negative reviews over time.

GET /api/projects/:slug/steam/refund-signals

Reviews that suggest a refund.

GET /api/projects/:slug/steam/sync-stats

Sync run history.

Alerts and notifications

GET /api/projects/:slug/alerts

List alert rules.

POST /api/projects/:slug/alerts

Create an alert rule. Body: {metric, threshold, window_hours}.

PATCH /api/projects/:slug/alerts/:ruleId

Update a rule. Body (any of): threshold, window_hours, enabled.

DELETE /api/projects/:slug/alerts/:ruleId

Delete a rule.

GET /api/notifications/preferences

Your email notification preferences.

PUT /api/notifications/preferences

Update them. Body: {email_bug_created, email_bug_status, email_bug_assigned, email_bug_commented, email_weekly_digest}.

Public Page & Widget Settings

Configure what the public endpoints show.

GET /api/projects/:slug/tracker-settings

Public tracker settings.

PUT /api/projects/:slug/tracker-settings

Update them: enabled, page_title, page_description, accent_color, logo_url, allow_search, allow_upvotes, show_categories, show_priority, show_status_filter, custom_css.

GET /api/projects/:slug/roadmap-settings

Public roadmap settings.

PUT /api/projects/:slug/roadmap-settings

Update them.

GET /api/projects/:slug/changelog/all

Every changelog entry, drafts included.

POST /api/projects/:slug/changelog

Create an entry. Body: {title, body, version, publish}.

PATCH /api/projects/:slug/changelog/:entryId

Update or publish an entry.

DELETE /api/projects/:slug/changelog/:entryId

Delete an entry.

POST /api/projects/:slug/changelog/auto-generate

Draft an entry from recently resolved reports.

GET /api/projects/:slug/branding

Branding settings.

PUT /api/projects/:slug/branding

Update branding.

GET /api/projects/:slug/widget-settings

In-game widget theme.

PUT /api/projects/:slug/widget-settings

Update the widget theme (Studio and up).

POST /api/projects/:slug/widget-settings/background

Upload a widget background image.

Billing Endpoints

Plan, usage and payment management. See Billing API for details.

GET /api/billing/subscription

The account’s plan, usage and limits, plus a features map of which plan-gated features the account carries.

POST /api/billing/create-checkout

Start a Stripe Checkout session for a plan.

GET /api/billing/verify-session

Confirm a completed checkout.

POST /api/billing/portal

Open the Stripe customer portal.

GET /api/billing/invoices

Your invoices.

GET /api/billing/payment-methods

Saved payment methods.

POST /api/billing/setup-intent

Start adding a payment method.

POST /api/billing/payment-method

Set the default payment method.

DELETE /api/billing/payment-method

Remove a payment method.

POST /api/billing/schedule-downgrade

Downgrade at the end of the billing period.

GET /api/billing/pending-downgrade

A scheduled downgrade, if any.

DELETE /api/billing/pending-downgrade

Cancel a scheduled downgrade.