Featureflip Feature Flags API
Feature flags within a resolved organization + project — mirrorsEnvironmentsController's resolve-then-dispatch shape one level deeper.`{project}` is resolved key-or-guid, scoped to the resolved org (with the service-tokenproject allowlist forwarded), via ResolveProjectIdAsyncfor every action. `{flag}` (get/update/archive/restore/delete) is then resolvedkey-or-guid, scoped to the resolved project, viaResolveFlagIdAsync. Dispatched commands/queries alwaysuse the resolved GUIDs, never the raw route strings. Writes (create/update/archive/restore/delete) require at least Member(RequireRole); a Viewer attempting one gets a 403`forbidden` envelope. Flag deletion/variation-removal guards (`FLAG_HAS_DEPENDENTS`,plan limits on create, etc.) surface as-is via the existing handlers' customValidationException, whichPublicApiExceptionFilterAttribute maps to a 400 `validation_failed`envelope automatically — no action here special-cases them. Defers flag *runtime config*(env-config, toggle, targeting rules, prerequisites) and variations to their own controllers(phase 3b Task 3 / phase 3c).
Featureflip Feature Flags API is one of 10 APIs that Featureflip publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Feature Flags. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, and API documentation.
This API exposes 22 operations across 14 paths, and defines 28 schemas. It is described by OpenAPI 3.2.0, at version v1.
Requests are made against a single base URL, https://api.featureflip.io.
Metadata
The identity and technical contract details declared by the specification.
Authentication & Security 1
Featureflip Feature Flags API declares
1 security scheme
for authenticating requests.
An API key is passed in the header as Authorization (Bearer).
By default, every request must be authenticated.
Bearer— JWT Authorization header using the Bearer scheme. Enter 'Bearer' [space] and then your token in the text input below.
Paths & Operations 22
Across 14 paths, the API surfaces 22 operations — 3 DELETE, 7 GET, 6 POST, 6 PUT. Each is listed below with its method, path, parameters, and response codes.
Feature flags within a resolved organization + project — mirrors EnvironmentsController's resolve-then-dispatch shape one level deeper.
Schemas 28
The contract defines 28 schemas that model the data the API accepts and returns. The most detailed are PublicFlagResponse (12 properties), PublicFlagListItem (9 properties), PublicTargetingRuleResponse (8 properties), PublicCreateFeatureFlagRequest (7 properties). Each schema is shown below with its type and property counts.
Specification
The full machine-readable OpenAPI contract behind this narrative.
Source
More from Featureflip 9
Other APIs Featureflip publishes across the network.
This is an independent, third-party profile of Featureflip Feature Flags API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.