How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Featureflip Feature Flags API

Feature flags within a resolved organization + project — mirrorsEnvironmentsController's resolve-then-dispatch shape one level deeper.`{project}` is resolved key-or-guid, scoped to the resolved org (with the service-tokenproject allowlist forwarded), via ResolveProjectIdAsyncfor every action. `{flag}` (get/update/archive/restore/delete) is then resolvedkey-or-guid, scoped to the resolved project, viaResolveFlagIdAsync. Dispatched commands/queries alwaysuse the resolved GUIDs, never the raw route strings. Writes (create/update/archive/restore/delete) require at least Member(RequireRole); a Viewer attempting one gets a 403`forbidden` envelope. Flag deletion/variation-removal guards (`FLAG_HAS_DEPENDENTS`,plan limits on create, etc.) surface as-is via the existing handlers' customValidationException, whichPublicApiExceptionFilterAttribute maps to a 400 `validation_failed`envelope automatically — no action here special-cases them. Defers flag *runtime config*(env-config, toggle, targeting rules, prerequisites) and variations to their own controllers(phase 3b Task 3 / phase 3c).

Featureflip Feature Flags API is one of 10 APIs that Featureflip publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Feature Flags. The published artifact set on APIs.io includes an OpenAPI specification, an API reference, and API documentation.

This API exposes 22 operations across 14 paths, and defines 28 schemas. It is described by OpenAPI 3.2.0, at version v1.

Requests are made against a single base URL, https://api.featureflip.io.

22 operations 14 paths 28 schemas 3 DELETE7 GET6 POST6 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1
Base URL
https://api.featureflip.io
Authentication
API Key
Resource Areas
1

Authentication & Security 1

Featureflip Feature Flags API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (Bearer). By default, every request must be authenticated.

  • Bearer — JWT Authorization header using the Bearer scheme. Enter 'Bearer' [space] and then your token in the text input below.

Paths & Operations 22

Across 14 paths, the API surfaces 22 operations — 3 DELETE, 7 GET, 6 POST, 6 PUT. Each is listed below with its method, path, parameters, and response codes.

Feature Flags 22

Feature flags within a resolved organization + project — mirrors EnvironmentsController's resolve-then-dispatch shape one level deeper.

POST
/api/v1/orgs/{org}/projects/{project}/flags
Creates a feature flag in the resolved project
postApiV1OrgsByOrgProjectsByProjectFlags 2 params body → 201400403404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags
Lists feature flags in the resolved project, cursor-paginated
getApiV1OrgsByOrgProjectsByProjectFlags 8 params → 200404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags/removal-candidates
Lists confidently-dead (or, with staleness=stale, stale-or-dead) flags the…
getApiV1OrgsByOrgProjectsByProjectFlagsRemovalCandidates 5 params → 200404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags/{flag}
Gets a feature flag in the resolved project by key or id
getApiV1OrgsByOrgProjectsByProjectFlagsByFlag 3 params → 200404401429
PUT
/api/v1/orgs/{org}/projects/{project}/flags/{flag}
Updates a flag's name/description/tags/client-side visibility
putApiV1OrgsByOrgProjectsByProjectFlagsByFlag 3 params body → 204403404401429
DELETE
/api/v1/orgs/{org}/projects/{project}/flags/{flag}
Deletes a flag
deleteApiV1OrgsByOrgProjectsByProjectFlagsByFlag 3 params → 204400403404401429
POST
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/archive
Archives a flag
postApiV1OrgsByOrgProjectsByProjectFlagsByFlagArchive 3 params → 204403404401429
POST
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/restore
Restores a previously archived flag
postApiV1OrgsByOrgProjectsByProjectFlagsByFlagRestore 3 params → 204403404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments
Gets the resolved flag's config in every environment of the resolved project
getApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironments 3 params → 200404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}
Gets the resolved flag's config in a single resolved environment
getApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnv 4 params → 200404401429
PUT
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}
Updates the resolved flag's default variation, strategy, and (optionally)…
putApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnv 4 params body → 204400403404401429
POST
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/toggle
Enables or disables the resolved flag in a resolved environment
postApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvToggle 4 params body → 204400403404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/targeting
Gets the resolved flag's full targeting configuration (enabled flag + ordered…
getApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvTargeting 4 params → 200404401429
PUT
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/targeting
Declaratively replaces the resolved flag's entire targeting rule set in the…
putApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvTargeting 4 params body → 204400403404401429
POST
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/rules
Creates a targeting rule on the resolved flag in the resolved environment
postApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvRules 4 params body → 201400403404401429
GET
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/rules/{ruleId}
Gets a single targeting rule on the resolved flag in the resolved environment…
getApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvRulesByRuleId 5 params → 200404401429
PUT
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/rules/{ruleId}
Updates a targeting rule's variation/description/rollout/segment/conditions…
putApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvRulesByRuleId 5 params body → 204400403404401429
DELETE
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/rules/{ruleId}
Deletes a targeting rule from the resolved flag in the resolved environment
deleteApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvRulesByRuleId 5 params → 204403404401429
PUT
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/environments/{env}/rules/reorder
Reorders the resolved flag's targeting rules in the resolved environment by…
putApiV1OrgsByOrgProjectsByProjectFlagsByFlagEnvironmentsByEnvRulesReorder 4 params body → 204403404401429
POST
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/variations
Adds a variation to the resolved flag
postApiV1OrgsByOrgProjectsByProjectFlagsByFlagVariations 3 params body → 201400403404401429
PUT
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/variations/{variationId}
Updates a variation's name/value/description
putApiV1OrgsByOrgProjectsByProjectFlagsByFlagVariationsByVariationId 4 params body → 204403404401429
DELETE
/api/v1/orgs/{org}/projects/{project}/flags/{flag}/variations/{variationId}
Removes a variation from the resolved flag
deleteApiV1OrgsByOrgProjectsByProjectFlagsByFlagVariationsByVariationId 4 params → 204400403404401429

Schemas 28

The contract defines 28 schemas that model the data the API accepts and returns. The most detailed are PublicFlagResponse (12 properties), PublicFlagListItem (9 properties), PublicTargetingRuleResponse (8 properties), PublicCreateFeatureFlagRequest (7 properties). Each schema is shown below with its type and property counts.

PublicApiErrorEnvelope
object
The frozen public-API error contract. error codes are stable snakecase strings. Wire keys are frozen snakecase too (error, message, docsurl, fields, retryafter…
7 properties
PublicConditionGroupResponse
object
A condition group within a PublicTargetingRuleResponse. Maps 1:1 onto ConditionGroupDto. Operator is a bare wire string naming one of the ConditionGroupOperato…
2 properties
NextAction
object
2 properties
PublicVariationResponse
object
A single variation on a flag, as returned in Variations.
6 properties
PublicPutTargetingRequest
object
Request body for PUT .../targeting — a declarative full replace of the environment's ordered targeting rule set. Rules are applied in array order (index = prio…
1 property
PublicUpdateFeatureFlagRequest
object
Request body for PUT /api/v1/orgs/{org}/projects/{project}/flags/{flag}. See PublicCreateFeatureFlagRequest for why this is named distinctly from the dashboard…
4 properties
PublicFlagRemovalCandidatePagedResult
object
A page of results plus an opaque cursor for the next page, or null when this is the last page. Wire keys are frozen: items (already lowercase under the camelCa…
2 properties
ActionCapability
object
One entry in a resource's actions block: may the caller perform it, and if not, why.
2 properties
PublicFlagResponse
object
Public detail representation of a feature flag, returned by GET .../flags/{flag} and the body of a successful create. Drops internal/dashboard-only fields pres…
12 properties
PublicFlagListItem
object
Public list-item representation of a feature flag, returned by GET .../flags. Narrower than PublicFlagResponse — drops Variations (a summary-only shape upstrea…
9 properties
PublicUpdateFlagEnvConfigRequest
object
Request body for PUT .../flags/{flag}/environments/{env}. Named distinctly from the dashboard's own UpdateFlagEnvironmentConfigurationRequest — see PublicCreat…
3 properties
PublicConditionGroupRequest
object
Request-side condition group, symmetric with PublicConditionGroupResponse.
2 properties
PublicUpdateTargetingRuleRequest
object
Request body for PUT .../rules/{ruleId}. Same shape as PublicCreateTargetingRuleRequest — see its remarks on operator validation/canonicalization, which applie…
5 properties
PublicFlagRemovalCandidate
object
One dead flag the Featureflip Flag Cleanup Action should remove, returned by GET .../flags/removal-candidates. Treatment is the kill decision: true → keep the…
4 properties
PublicFlagEnvConfigResponse
object
Public representation of a flag's config within a single environment, returned by GET .../flags/{flag}/environments and GET .../flags/{flag}/environments/{env}…
7 properties
PublicAddVariationRequest
object
Request body for POST /api/v1/orgs/{org}/projects/{project}/flags/{flag}/variations. Named distinctly from the dashboard's own AddVariationRequest — see Public…
4 properties
PublicCreateFeatureFlagRequest
object
Request body for POST /api/v1/orgs/{org}/projects/{project}/flags. Named distinctly from the dashboard's own CreateFeatureFlagRequest — see PublicCreateEnviron…
7 properties
PublicConditionRequest
object
Request-side condition, symmetric with PublicConditionResponse.
4 properties
PublicFlagListItemPagedResult
object
A page of results plus an opaque cursor for the next page, or null when this is the last page. Wire keys are frozen: items (already lowercase under the camelCa…
3 properties
PublicCreateTargetingRuleRequest
object
Request body for POST .../rules. The Application-side CreateTargetingRuleDto/CreateConditionGroupDto/CreateConditionDto all take their Operator as a bare strin…
5 properties
PublicTargetingRuleResponse
object
A single targeting rule, returned by GET .../rules/{ruleId}, POST .../rules (201 body), and nested within PublicTargetingConfigResponse. Maps 1:1 onto Targetin…
8 properties
PublicCreateVariationDto
object
A variation supplied at flag-creation time. Maps 1:1 onto CreateVariationDto.
4 properties
PublicToggleFlagRequest
object
Request body for POST .../flags/{flag}/environments/{env}/toggle. Named distinctly from the dashboard's own ToggleFlagInEnvironmentRequest (which uses IsEnable…
1 property
PublicUpdateVariationRequest
object
Request body for PUT /api/v1/orgs/{org}/projects/{project}/flags/{flag}/variations/{variationId}. The variation's key is immutable via this endpoint (mirrors U…
3 properties
PublicTargetingConfigResponse
object
The full targeting configuration for a flag in a single environment, returned by GET .../targeting. Maps 1:1 onto TargetingConfigurationDto — including its IsE…
3 properties
PublicReorderRulesRequest
object
Request body for PUT .../rules/reorder. Must include every existing rule id exactly once — ReorderTargetingRulesCommandHandler rejects duplicate, omitted, or u…
1 property
PublicConditionResponse
object
A single condition within a PublicConditionGroupResponse. Maps 1:1 onto ConditionDto. Operator is a bare wire string naming one of the OperatorType members (e.…
4 properties
PublicPrerequisiteDto
object
A single prerequisite entry on a flag's per-environment config. Maps 1:1 onto PrerequisiteDto (read side) and PrerequisiteInput (write side).
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

featureflip-feature-flags-api-openapi.yml Raw ↑

Other APIs Featureflip publishes across the network.

MCP Server (local)
Featureflip Client SDK API
Featureflip Environments API
Featureflip Me API
Featureflip Organizations API
Featureflip Projects API
Featureflip SDK Keys API
Featureflip Server SDK API
Featureflip User Segments API
Where this information came from

This is an independent, third-party profile of Featureflip Feature Flags API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.