API Explorer
Evaluate flags, resolve types, and stream real-time updates over the Connect protocol.
Bearer token required. Pass Authorization: Bearer flg_... on all requests. Public flags can be evaluated without auth. Mint a token at console → profile or project settings — Auth docs →
Evaluation Service
6 endpointsFlag evaluation service — single flag, bulk, and type-specific resolution (boolean, string, number, object)
BulkEvaluateFlags
Evaluate multiple flags
flaggr.v1.BulkEvaluateFlagsRequestflagKeysarray<string>Flag keys to evaluate (empty = all flags)contextobjectEvaluation context containing user/request attributestargetingKeystringPrimary identifier for targeting (e.g., user ID)stringAttributesobjectString attributesnumberAttributesobjectNumber attributesboolAttributesobjectBoolean attributestimestampstringTimestamp when context was createdserviceIdstringService ID for scopingenvironmentenumEnvironment enumerationENVIRONMENT_UNSPECIFIEDENVIRONMENT_DEVELOPMENTENVIRONMENT_STAGINGENVIRONMENT_PRODUCTIONflaggr.v1.BulkEvaluateFlagsResponseflagsobjectMap of flag key to evaluation resultflagKeystringFlag key that was evaluatedvalueoneOfGeneric value that can hold different typesvariantstringVariant name if applicablereasonenumReason for the evaluation resulterrorCodeenumError codes for failed evaluationserrorMessagestringError message if evaluation failedmetadataobjectAdditional metadataevaluatedAtstringEvaluation timestampflagVersionint64Flag version used for this evaluationtotalintegerTotal flags evaluatedevaluatedAtstringEvaluation timestampEvaluateFlag
Evaluate a single flag
flaggr.v1.EvaluateFlagRequestflagKeystringFlag key to evaluatecontextobjectEvaluation context containing user/request attributestargetingKeystringPrimary identifier for targeting (e.g., user ID)stringAttributesobjectString attributesnumberAttributesobjectNumber attributesboolAttributesobjectBoolean attributestimestampstringTimestamp when context was createddefaultValueoneOfGeneric value that can hold different typesboolValue*booleanbool valuejsonValue*stringSerialized JSON for object typesnumberValue*doublenumber valuestringValue*stringstring valueserviceIdstringService ID for scopingenvironmentenumEnvironment enumerationENVIRONMENT_UNSPECIFIEDENVIRONMENT_DEVELOPMENTENVIRONMENT_STAGINGENVIRONMENT_PRODUCTIONflaggr.v1.EvaluateFlagResponseflagKeystringFlag key that was evaluatedvalueoneOfGeneric value that can hold different typesboolValue*booleanbool valuejsonValue*stringSerialized JSON for object typesnumberValue*doublenumber valuestringValue*stringstring valuevariantstringVariant name if applicablereasonenumReason for the evaluation resultEVALUATION_REASON_UNSPECIFIEDEVALUATION_REASON_STATICEVALUATION_REASON_DEFAULTEVALUATION_REASON_TARGETING_MATCHEVALUATION_REASON_SPLITEVALUATION_REASON_CACHEDEVALUATION_REASON_FLAG_NOT_FOUNDEVALUATION_REASON_ERROREVALUATION_REASON_DISABLEDerrorCodeenumError codes for failed evaluationsEVALUATION_ERROR_CODE_UNSPECIFIEDEVALUATION_ERROR_CODE_PROVIDER_NOT_READYEVALUATION_ERROR_CODE_FLAG_NOT_FOUNDEVALUATION_ERROR_CODE_PARSE_ERROREVALUATION_ERROR_CODE_TYPE_MISMATCHEVALUATION_ERROR_CODE_GENERALEVALUATION_ERROR_CODE_INVALID_CONTEXTerrorMessagestringError message if evaluation failedmetadataobjectAdditional metadataevaluatedAtstringEvaluation timestampflagVersionint64Flag version used for this evaluationResolveBoolean
Type-specific evaluation methods
flaggr.v1.ResolveBooleanRequestflagKeystringflag keydefaultValuebooleandefault valuecontextobjectEvaluation context containing user/request attributestargetingKeystringPrimary identifier for targeting (e.g., user ID)stringAttributesobjectString attributesnumberAttributesobjectNumber attributesboolAttributesobjectBoolean attributestimestampstringTimestamp when context was createdserviceIdstringservice idflaggr.v1.ResolveBooleanResponsevaluebooleanvaluevariantstringvariantreasonenumReason for the evaluation resultEVALUATION_REASON_UNSPECIFIEDEVALUATION_REASON_STATICEVALUATION_REASON_DEFAULTEVALUATION_REASON_TARGETING_MATCHEVALUATION_REASON_SPLITEVALUATION_REASON_CACHEDEVALUATION_REASON_FLAG_NOT_FOUNDEVALUATION_REASON_ERROREVALUATION_REASON_DISABLEDerrorCodeenumError codes for failed evaluationsEVALUATION_ERROR_CODE_UNSPECIFIEDEVALUATION_ERROR_CODE_PROVIDER_NOT_READYEVALUATION_ERROR_CODE_FLAG_NOT_FOUNDEVALUATION_ERROR_CODE_PARSE_ERROREVALUATION_ERROR_CODE_TYPE_MISMATCHEVALUATION_ERROR_CODE_GENERALEVALUATION_ERROR_CODE_INVALID_CONTEXTerrorMessagestringerror messagemetadataobjectmetadataResolveNumber
flaggr.v1.ResolveNumberRequestflagKeystringflag keydefaultValuedoubledefault valuecontextobjectEvaluation context containing user/request attributestargetingKeystringPrimary identifier for targeting (e.g., user ID)stringAttributesobjectString attributesnumberAttributesobjectNumber attributesboolAttributesobjectBoolean attributestimestampstringTimestamp when context was createdserviceIdstringservice idflaggr.v1.ResolveNumberResponsevaluedoublevaluevariantstringvariantreasonenumReason for the evaluation resultEVALUATION_REASON_UNSPECIFIEDEVALUATION_REASON_STATICEVALUATION_REASON_DEFAULTEVALUATION_REASON_TARGETING_MATCHEVALUATION_REASON_SPLITEVALUATION_REASON_CACHEDEVALUATION_REASON_FLAG_NOT_FOUNDEVALUATION_REASON_ERROREVALUATION_REASON_DISABLEDerrorCodeenumError codes for failed evaluationsEVALUATION_ERROR_CODE_UNSPECIFIEDEVALUATION_ERROR_CODE_PROVIDER_NOT_READYEVALUATION_ERROR_CODE_FLAG_NOT_FOUNDEVALUATION_ERROR_CODE_PARSE_ERROREVALUATION_ERROR_CODE_TYPE_MISMATCHEVALUATION_ERROR_CODE_GENERALEVALUATION_ERROR_CODE_INVALID_CONTEXTerrorMessagestringerror messagemetadataobjectmetadataResolveObject
flaggr.v1.ResolveObjectRequestflagKeystringflag keydefaultValuestringJSON stringcontextobjectEvaluation context containing user/request attributestargetingKeystringPrimary identifier for targeting (e.g., user ID)stringAttributesobjectString attributesnumberAttributesobjectNumber attributesboolAttributesobjectBoolean attributestimestampstringTimestamp when context was createdserviceIdstringservice idflaggr.v1.ResolveObjectResponsevaluestringJSON stringvariantstringvariantreasonenumReason for the evaluation resultEVALUATION_REASON_UNSPECIFIEDEVALUATION_REASON_STATICEVALUATION_REASON_DEFAULTEVALUATION_REASON_TARGETING_MATCHEVALUATION_REASON_SPLITEVALUATION_REASON_CACHEDEVALUATION_REASON_FLAG_NOT_FOUNDEVALUATION_REASON_ERROREVALUATION_REASON_DISABLEDerrorCodeenumError codes for failed evaluationsEVALUATION_ERROR_CODE_UNSPECIFIEDEVALUATION_ERROR_CODE_PROVIDER_NOT_READYEVALUATION_ERROR_CODE_FLAG_NOT_FOUNDEVALUATION_ERROR_CODE_PARSE_ERROREVALUATION_ERROR_CODE_TYPE_MISMATCHEVALUATION_ERROR_CODE_GENERALEVALUATION_ERROR_CODE_INVALID_CONTEXTerrorMessagestringerror messagemetadataobjectmetadataResolveString
flaggr.v1.ResolveStringRequestflagKeystringflag keydefaultValuestringdefault valuecontextobjectEvaluation context containing user/request attributestargetingKeystringPrimary identifier for targeting (e.g., user ID)stringAttributesobjectString attributesnumberAttributesobjectNumber attributesboolAttributesobjectBoolean attributestimestampstringTimestamp when context was createdserviceIdstringservice idflaggr.v1.ResolveStringResponsevaluestringvaluevariantstringvariantreasonenumReason for the evaluation resultEVALUATION_REASON_UNSPECIFIEDEVALUATION_REASON_STATICEVALUATION_REASON_DEFAULTEVALUATION_REASON_TARGETING_MATCHEVALUATION_REASON_SPLITEVALUATION_REASON_CACHEDEVALUATION_REASON_FLAG_NOT_FOUNDEVALUATION_REASON_ERROREVALUATION_REASON_DISABLEDerrorCodeenumError codes for failed evaluationsEVALUATION_ERROR_CODE_UNSPECIFIEDEVALUATION_ERROR_CODE_PROVIDER_NOT_READYEVALUATION_ERROR_CODE_FLAG_NOT_FOUNDEVALUATION_ERROR_CODE_PARSE_ERROREVALUATION_ERROR_CODE_TYPE_MISMATCHEVALUATION_ERROR_CODE_GENERALEVALUATION_ERROR_CODE_INVALID_CONTEXTerrorMessagestringerror messagemetadataobjectmetadataFlag Stream Service
1 endpointsReal-time flag streaming — server-sent updates, bidirectional sync, and configuration fetch
GetConfiguration
LiveGet current configuration (unary, for initial load)
flaggr.v1.StreamFlagsRequestserviceIdstringService ID to subscribe toenvironmentenumEnvironment enumerationENVIRONMENT_UNSPECIFIEDENVIRONMENT_DEVELOPMENTENVIRONMENT_STAGINGENVIRONMENT_PRODUCTIONflagKeysarray<string>Specific flag keys to watch (empty = all flags)lastKnownVersionstringLast known configuration version (for delta sync)clientIdstringClient identifier for connection trackingapiTokenstringAPI token for authenticationflaggr.v1.ConfigurationSyncconfigurationobjectCollection of flags for bulk operationsflagsobjectMap of flag key to flag definitionversionstringConfiguration versiongeneratedAtstringWhen this configuration was generatedserviceIdstringService ID for scoped configurationsprojectIdstringProject ID for scoped configurationstimestampstringTimestamp of syncREST API — Control Plane
33 endpointsThe management and evaluation surface at flaggr.dev/api — flag CRUD, batch evaluation, SSE streaming, bulk operations, and the public demo service that powers the landing-page grid.
Every endpoint shows generated cURL / JavaScript / Python / Go examples and a live Try it panel — paste a flg_ token (console → profile) to hit any endpoint, including mutations. Public demo endpoints need nothing at all.
Evaluation
5Server-side flag evaluation — the same engine the SDKs hit. Public flags evaluate without auth.
Evaluate a single flag
Public flagsEvaluates one flag against the supplied context — the primary server-side eval path. Returns the resolved value, reason, variant, and per-phase timing breakdown.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
- Flags marked `isPublic` evaluate without any token — useful for client-side reads of deliberately public config.
- Rate limits: 1,000/min per IP · 5,000/min per token · 10,000/min per service.
curl -X POST 'https://flaggr.dev/api/flags/evaluate' \
-H 'Content-Type: application/json' \
-d '{ "flagKey": "checkout-v2", "serviceId": "web-app", "environment": "production", "defaultValue": false, "context": { "targetingKey": "user-123", "email": "alice@example.com", "plan": "enterprise" }}'{
"flagKey": "checkout-v2",
"serviceId": "web-app",
"environment": "production",
"defaultValue": false,
"context": {
"targetingKey": "user-123",
"email": "alice@example.com",
"plan": "enterprise"
}
}{
"flagKey": "checkout-v2",
"value": true,
"reason": "TARGETING_MATCH",
"variant": "enabled",
"_debug": {
"timings": { "rateLimit": 2, "validation": 1, "cacheGet": 0.5, "evaluate": 3 },
"cacheHit": false,
"totalMs": 12
}
}import { FlaggrProvider } from "@flaggr/sdk";
// SDKs evaluate locally against a hydrated snapshot — this endpoint is the
// server-side path for one-off checks and non-SDK clients.Bulk evaluate flags
Bearer tokenEvaluates many flags in one request — the grouped-eval path SDKs use to hydrate or refresh. All flags share one context; per-flag results return in order.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
- Normal cap: 100 flags per request. Public demo services may send up to 4,096.
- Response times: warm batches of 4,096 flags measure ~110ms — the engine prefetches experiments once instead of per-flag.
curl -X POST 'https://flaggr.dev/api/flags/evaluate/batch' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "serviceId": "web-app", "environment": "production", "flags": [ { "key": "checkout-v2", "defaultValue": false }, { "key": "new-onboarding", "defaultValue": false } ], "context": { "targetingKey": "user-123", "plan": "enterprise" }}'{
"serviceId": "web-app",
"environment": "production",
"flags": [
{ "key": "checkout-v2", "defaultValue": false },
{ "key": "new-onboarding", "defaultValue": false }
],
"context": { "targetingKey": "user-123", "plan": "enterprise" }
}{
"flags": [
{ "key": "checkout-v2", "value": true, "reason": "TARGETING_MATCH", "variant": "enabled" },
{ "key": "new-onboarding", "value": false, "reason": "DISABLED", "variant": null }
],
"_meta": {
"evaluationTimeMs": 4,
"flagCount": 2,
"timings": { "auth": 8, "storage": 12, "evaluate": 4, "total": 26 }
}
}Query evaluation logs
Bearer tokenRecent evaluation events — who evaluated what, when, and what they got. Powers the console's eval log views.
curl -X GET 'https://flaggr.dev/api/evaluations' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"evaluations": [
{
"flagKey": "checkout-v2",
"value": true,
"reason": "TARGETING_MATCH",
"evaluatedAt": "2026-09-24T03:11:46.470Z",
"context": { "targetingKey": "user-123" }
}
],
"nextCursor": "eyJ0cyI6MTc5MDIxOTUwNjQ3MH0=",
"hasMore": true
}Evaluation volume stats
Bearer tokenAggregated evaluation counts and latency buckets over a window — used by the analytics dashboards and toggle-impact analysis.
curl -X GET 'https://flaggr.dev/api/evaluations/stats' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"total": 142031,
"perMinute": 98.6,
"p50Ms": 4,
"p95Ms": 18,
"p99Ms": 41,
"byFlag": [{ "key": "checkout-v2", "count": 51220 }]
}Browse evaluation contexts
Bearer tokenRecent evaluation contexts grouped by targetingKey — who evaluated, their attributes, and what each flag resolved to. `key` narrows to a single context's flag→value map. Backed by the in-memory eval ring (last ~1,000 evals on the instance).
curl -X GET 'https://flaggr.dev/api/contexts' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"contexts": [
{
"targetingKey": "user-alice-1",
"attributes": { "plan": "pro", "region": "au" },
"evalCount": 4, "flagCount": 2,
"flags": [{ "flagKey": "checkout-v2", "value": true, "reason": "TARGETING_MATCH" }]
}
],
"window": "recent"
}Flag Management
9CRUD, toggles, version history, and post-toggle safety analysis for feature flags.
List flags
Bearer tokenLists flags for a project with filtering, pagination, and sparse fieldsets. Supports both offset and cursor pagination; public demo services may be listed without a token.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
- Public demo service lists emit a weak `ETag` over the result set — send it as `If-None-Match` to get `304 Not Modified` on unchanged revalidations.
- `fields` whitelist: key, name, description, type, enabled, defaultValue, serviceId, environment, tags, variants, targeting, isPublic, createdAt, updatedAt.
curl -X GET 'https://flaggr.dev/api/flags' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"flags": [
{
"key": "checkout-v2",
"name": "Checkout v2",
"type": "boolean",
"enabled": true,
"serviceId": "web-app",
"environment": "production",
"updatedAt": "2026-09-24T03:11:46.470Z"
}
],
"total": 42,
"limit": 50,
"offset": 0,
"hasMore": false
}Create a flag
Bearer tokenCreates a flag in a service + environment. Publishes a `flag-update` event, writes a version snapshot, and logs an audit entry.
- Session-authenticated mutations require the CSRF pair (cookie + `x-csrf-token` header). Bearer-token requests skip CSRF entirely — any write-scoped `flg_` token works here.
- Duplicate keys in the same service+environment return 409.
curl -X POST 'https://flaggr.dev/api/flags' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "key": "checkout-v2", "name": "Checkout v2", "description": "New checkout flow", "type": "boolean", "enabled": false, "defaultValue": false, "serviceId": "web-app", "environment": "production", "tags": ["checkout"], "variants": [], "targeting": [], "isPublic": false}'{
"key": "checkout-v2",
"name": "Checkout v2",
"description": "New checkout flow",
"type": "boolean",
"enabled": false,
"defaultValue": false,
"serviceId": "web-app",
"environment": "production",
"tags": ["checkout"],
"variants": [],
"targeting": [],
"isPublic": false
}{
"key": "checkout-v2",
"name": "Checkout v2",
"type": "boolean",
"enabled": false,
"serviceId": "web-app",
"environment": "production",
"createdAt": "2026-09-24T03:11:46.470Z",
"updatedAt": "2026-09-24T03:11:46.470Z"
}Get a flag
Bearer tokenFetches one flag by key within a service and environment.
curl -X GET 'https://flaggr.dev/api/flags/checkout-v2' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"key": "checkout-v2",
"name": "Checkout v2",
"type": "boolean",
"enabled": true,
"defaultValue": false,
"variants": [],
"targeting": [{ "name": "Enterprise", "conditions": [{ "attribute": "plan", "operator": "equals", "value": "enterprise" }], "value": true }],
"updatedAt": "2026-09-24T03:11:46.470Z"
}Update a flag
Bearer tokenPartial update — enabled state, targeting, variants, metadata. Publishes a `flag-update` event and snapshots the previous version.
- Session-authenticated mutations require the CSRF pair (cookie + `x-csrf-token` header). Bearer-token requests skip CSRF entirely — any write-scoped `flg_` token works here.
curl -X PATCH 'https://flaggr.dev/api/flags/checkout-v2' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "enabled": true, "description": "Rolled out to enterprise", "targeting": [ { "name": "Enterprise", "conditions": [{ "attribute": "plan", "operator": "equals", "value": "enterprise" }], "value": true } ]}'{
"enabled": true,
"description": "Rolled out to enterprise",
"targeting": [
{ "name": "Enterprise", "conditions": [{ "attribute": "plan", "operator": "equals", "value": "enterprise" }], "value": true }
]
}{
"key": "checkout-v2",
"enabled": true,
"updatedAt": "2026-09-24T03:15:02.118Z",
"version": 7
}Delete a flag
Bearer tokenDeletes a flag and publishes a `flag-deleted` event to all subscribers.
- Session-authenticated mutations require the CSRF pair (cookie + `x-csrf-token` header). Bearer-token requests skip CSRF entirely — any write-scoped `flg_` token works here.
curl -X DELETE 'https://flaggr.dev/api/flags/checkout-v2' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{ "success": true, "key": "checkout-v2" }Toggle a flag
Bearer tokenFlips `enabled` on or off — the hot path. Returns immediately after the write commits; versioning, audit, and fanout run deferred via `runAfterResponse`.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
- Toggle accepts write-scoped tokens — no CSRF needed, unlike the session-auth management routes.
curl -X POST 'https://flaggr.dev/api/flags/checkout-v2/toggle' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "serviceId": "web-app", "environment": "production", "enabled": true}'{
"serviceId": "web-app",
"environment": "production",
"enabled": true
}{
"key": "checkout-v2",
"enabled": true,
"previousValue": false,
"updatedAt": "2026-09-24T03:15:02.118Z"
}Post-toggle drift analysis
Bearer tokenSymmetric before/after analysis around the last toggle — error-rate shift, p99 latency shift, and traffic ratio, classified healthy | warning | degraded.
curl -X GET 'https://flaggr.dev/api/flags/checkout-v2/toggle-impact' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"flagKey": "checkout-v2",
"healthStatus": "healthy",
"before": { "errorRate": 0.012, "p99LatencyMs": 210, "evaluations": 8420 },
"after": { "errorRate": 0.014, "p99LatencyMs": 224, "evaluations": 8391 },
"delta": { "errorRateShift": 0.002, "p99LatencyShiftMs": 14, "trafficRatio": 0.99 },
"advice": "No significant drift detected."
}Flag evaluation time series
Bearer tokenPer-flag evaluation volume and latency over time — the data behind the console's flag metrics charts.
curl -X GET 'https://flaggr.dev/api/flags/checkout-v2/metrics' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"flagKey": "checkout-v2",
"window": "1h",
"interval": "5m",
"series": [
{ "ts": "2026-09-24T03:00:00Z", "evaluations": 420, "errors": 3, "p95Ms": 18 }
]
}Flag version history
Bearer tokenImmutable version snapshots — every mutation writes one. Feed for the console's diff/rollback UI.
curl -X GET 'https://flaggr.dev/api/flags/checkout-v2/history' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"versions": [
{
"version": 7,
"changeType": "update",
"changedBy": "user@example.com",
"changeSummary": "Enabled for enterprise",
"snapshot": { "enabled": true },
"createdAt": "2026-09-24T03:15:02.118Z"
}
]
}Triggers & Watching
6Scoped trigger URLs for CI/CD flag actions, member flag-watching, and the audit-sourced notification feed.
Create a flag trigger
Bearer tokenMint a scoped, revocable trigger URL for CI/CD — `POST` it (no auth headers; the token is the capability) to enable, disable, or toggle the flag. The raw token is returned exactly once — only its SHA-256 hash is stored.
- Token shown once at creation — store it as a CI secret.
- Trigger executions audit-log as `trigger:{name}` and bump `useCount`.
curl -X POST 'https://flaggr.dev/api/flags/checkout-v2/triggers' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "serviceId": "web", "environment": "production", "action": "enable", "name": "deploy-complete"}'{
"serviceId": "web",
"environment": "production",
"action": "enable",
"name": "deploy-complete"
}{
"id": "trg-abc",
"action": "enable",
"token": "ftr_…",
"url": "/api/triggers/ftr_…",
"example": "curl -X POST https://flaggr.dev/api/triggers/ftr_…"
}List flag triggers
Bearer tokenActive triggers for a flag — metadata only, never the raw token.
curl -X GET 'https://flaggr.dev/api/flags/checkout-v2/triggers' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{ "triggers": [{ "id": "trg-abc", "name": "deploy-complete", "action": "enable", "useCount": 3, "lastUsedAt": "2026-09-24T11:33Z" }] }Revoke a trigger
Bearer tokenImmediately invalidates the trigger URL — the capability is gone.
curl -X DELETE 'https://flaggr.dev/api/flags/checkout-v2/triggers/example-triggerId' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{ "revoked": true, "id": "trg-abc" }Execute a trigger
No authThe capability URL — `POST` with no auth headers. The token alone grants exactly one scoped action on one flag in one environment. Rate-limited to 30 executions/minute per token.
- 404 for unknown AND revoked tokens — no oracle.
- Same mutation path as the toggle route — version snapshot, audit, SSE fanout, cache invalidation.
- Paste your trigger URL into the editable URL field to try it.
curl -X POST 'https://flaggr.dev/api/triggers/example-token' \
{ "flagKey": "checkout-v2", "action": "enable", "enabled": true, "executedAt": "2026-09-24T11:33Z" }Watch a flag
Bearer tokenFollow a flag — its mutations surface as unread items in the notifications bell (audit-sourced feed). Idempotent. `DELETE` unfollows, `GET` returns current watch state.
curl -X POST 'https://flaggr.dev/api/flags/checkout-v2/watch' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "serviceId": "web", "environment": "production" }'{ "serviceId": "web", "environment": "production" }{ "watching": true, "flagKey": "checkout-v2", "environment": "production" }Notification feed
Bearer tokenRecent audit events on flags the caller watches, plus unread count. `POST` marks all watched-flag notifications as read.
curl -X GET 'https://flaggr.dev/api/notifications' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"notifications": [{ "flagKey": "checkout-v2", "action": "flag.toggle", "actorEmail": "alice@x.io", "unread": true }],
"unreadCount": 1, "watching": 3
}Bulk Operations
3Batched create, update, and delete — one request, one storage round-trip per service/environment group.
Bulk create flags
Bearer tokenCreates many flags in one request — used by import flows and environment bootstrapping. Per-flag results with `succeeded`/`failed` counts.
- Session-authenticated mutations require the CSRF pair (cookie + `x-csrf-token` header). Bearer-token requests skip CSRF entirely — any write-scoped `flg_` token works here.
- Partial success returns 207 Multi-Status with per-flag errors.
curl -X POST 'https://flaggr.dev/api/flags/bulk' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "flags": [ { "key": "new-header", "name": "New Header", "type": "boolean", "enabled": false, "defaultValue": false, "serviceId": "web-app", "environment": "staging" } ]}'{
"flags": [
{
"key": "new-header",
"name": "New Header",
"type": "boolean",
"enabled": false,
"defaultValue": false,
"serviceId": "web-app",
"environment": "staging"
}
]
}{
"success": true,
"total": 1,
"succeeded": 1,
"failed": 0,
"results": [{ "key": "new-header", "status": "success" }]
}Bulk update flags
Bearer tokenUpdates many flags atomically per service+environment — one SELECT + one UPDATE, then pub/sub fanout. This is the endpoint the pixel-grid demo writes through.
- Session-authenticated mutations require the CSRF pair (cookie + `x-csrf-token` header). Bearer-token requests skip CSRF entirely — any write-scoped `flg_` token works here.
- Fanout publishes before version/audit writes — SSE subscribers see the commit immediately, not after durability work.
- Normal cap: 100 updates. Public demo services may send up to 4,096 (enabled-only).
curl -X PATCH 'https://flaggr.dev/api/flags/bulk' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "flags": [ { "key": "checkout-v2", "serviceId": "web-app", "environment": "production", "updates": { "enabled": true } }, { "key": "new-onboarding", "serviceId": "web-app", "environment": "production", "updates": { "enabled": false, "description": "Paused" } } ]}'{
"flags": [
{
"key": "checkout-v2",
"serviceId": "web-app",
"environment": "production",
"updates": { "enabled": true }
},
{
"key": "new-onboarding",
"serviceId": "web-app",
"environment": "production",
"updates": { "enabled": false, "description": "Paused" }
}
]
}{
"success": true,
"total": 2,
"succeeded": 2,
"failed": 0,
"results": [
{ "key": "checkout-v2", "status": "success", "flag": { "key": "checkout-v2", "enabled": true } }
]
}Bulk delete flags
Bearer tokenDeletes many flags in one request with per-flag results and `flag-deleted` events.
- Session-authenticated mutations require the CSRF pair (cookie + `x-csrf-token` header). Bearer-token requests skip CSRF entirely — any write-scoped `flg_` token works here.
curl -X DELETE 'https://flaggr.dev/api/flags/bulk' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "flags": [ { "key": "old-experiment", "serviceId": "web-app", "environment": "staging" } ]}'{
"flags": [
{ "key": "old-experiment", "serviceId": "web-app", "environment": "staging" }
]
}{ "success": true, "total": 1, "succeeded": 1, "failed": 0, "results": [{ "key": "old-experiment", "status": "success" }] }Streaming
2Server-Sent Events feeds for real-time flag propagation — the transport SDKs use for push updates.
Flag update stream (SSE)
Bearer tokenLiveServer-Sent Events feed of flag mutations for a service — `connected` on open, then one `flag-update` per mutation carrying the full flag object, and periodic `ping` keepalives.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
- EventSource in browsers can't set headers — use the `eventsource` npm package, or a public demo service (no token needed).
- Backed by Redis pub/sub in multi-instance deploys, in-process bus otherwise.
curl -X GET 'https://flaggr.dev/api/flags/stream' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \ -H 'Accept: text/event-stream' \ -N \
data: {"type":"connected","serviceId":"web-app","timestamp":1790219485135,"realTimeMethod":"redis-pubsub"}
data: {"type":"flag-update","flagKey":"checkout-v2","serviceId":"web-app","eventType":"UPDATED","timestamp":"2026-09-24T03:15:02.118Z","flag":{"key":"checkout-v2","enabled":true}}
data: {"type":"ping","timestamp":1790219545000}import { FlaggrProvider } from "@flaggr/sdk";
const provider = new FlaggrProvider({
baseUrl: "https://flaggr.dev",
serviceId: "web-app",
environment: "production",
apiKey: "flg_…",
updateMode: "stream", // SSE push — this endpoint under the hood
});Connect config stream (SSE)
Bearer tokenLiveThe Connect-protocol stream SDKs use — emits a full configuration snapshot on connect, then incremental flag events. Pairs with `/api/connect/evaluate`.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
curl -X GET 'https://flaggr.dev/api/connect/stream' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \ -H 'Accept: text/event-stream' \ -N \
data: {"type":"configuration","flags":[{...}],"configVersion":"v1790219485135"}
data: {"type":"flag-update","flagKey":"checkout-v2","eventType":"UPDATED"}OpenFeature (OFREP)
3Vendor-neutral OpenFeature Remote Evaluation Protocol — drop-in compatible with OFREP SDKs.
OFREP single evaluation
Bearer tokenOpenFeature Remote Evaluation Protocol — evaluate one flag for a context. Compatible with any OFREP-compliant SDK.
- Pass `Authorization: Bearer flg_…` — tokens carry read or write scopes.
- Requires `serviceId`/`environment` via headers or token claims.
curl -X POST 'https://flaggr.dev/api/ofrep/v1/evaluate/flags/checkout-v2' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "context": { "targetingKey": "user-123", "plan": "enterprise" }}'{
"context": { "targetingKey": "user-123", "plan": "enterprise" }
}{
"key": "checkout-v2",
"value": true,
"reason": "TARGETING_MATCH",
"variant": "enabled",
"metadata": { "flagSetId": "web-app" }
}OFREP bulk evaluation
Bearer tokenEvaluates all flags in the flagset for one context — the OFREP hydration call.
curl -X POST 'https://flaggr.dev/api/ofrep/v1/evaluate/flags' \
-H 'Authorization: Bearer flg_YOUR_TOKEN' \
-H 'Content-Type: application/json' \
-d '{ "context": { "targetingKey": "user-123", "plan": "enterprise" }}'{
"context": { "targetingKey": "user-123", "plan": "enterprise" }
}{
"flags": [
{ "key": "checkout-v2", "value": true, "reason": "TARGETING_MATCH", "variant": "enabled" }
],
"metadata": { "flagSetId": "web-app" }
}OFREP metadata
Bearer tokenProvider metadata for OFREP client negotiation — name, capabilities, flagset.
curl -X GET 'https://flaggr.dev/api/ofrep/v1/metadata' \ -H 'Authorization: Bearer flg_YOUR_TOKEN' \
{
"name": "Flaggr",
"capabilities": ["flag-evaluation", "bulk-evaluation"],
"metadata": { "version": "0.2.0" }
}Public Demo Service
4The pixel-grid service (4,096 flags powering the landing-page demo) is addressable without a token — the only public-mutable surface.
List the pixel grid
Public demoThe grid's bootstrap + poll read — the standard list endpoint pointed at the public demo service, with sparse fieldsets and conditional-request support.
- No token required — `pixel-grid` is the only allowlisted public demo service.
- Responses carry `ETag`; send `If-None-Match` to get `304 Not Modified` when the grid hasn't changed (~15ms, 0 bytes).
- Try it below — this endpoint is live right now.
curl -X GET 'https://flaggr.dev/api/flags?serviceId=pixel-grid&environment=development&limit=4096&fields=key,enabled' \
{
"flags": [
{ "key": "px-0", "enabled": false },
{ "key": "px-1", "enabled": true }
],
"total": 4096,
"limit": 4096,
"offset": 0,
"hasMore": false
}Evaluate the whole grid
Public demoThe grid's batch mode — all 4,096 cells evaluated through the real grouped-eval path in one request. The 100-flag cap relaxes to 4,096 for demo services.
- The demo sends all 4,096 keys — ~175KB request, ~210KB response, ~110ms warm.
curl -X POST 'https://flaggr.dev/api/flags/evaluate/batch' \
-H 'Content-Type: application/json' \
-d '{ "serviceId": "pixel-grid", "environment": "development", "flags": [ { "key": "px-0", "defaultValue": false }, { "key": "px-1", "defaultValue": false } ]}'{
"serviceId": "pixel-grid",
"environment": "development",
"flags": [
{ "key": "px-0", "defaultValue": false },
{ "key": "px-1", "defaultValue": false }
]
}{
"flags": [
{ "key": "px-0", "value": false, "reason": "STATIC", "variant": null },
{ "key": "px-1", "value": true, "reason": "STATIC", "variant": "enabled" }
],
"_meta": { "evaluationTimeMs": 89, "flagCount": 4096 }
}Stream grid updates
Public demoLiveThe real SSE feed for the demo service — a bulk pattern apply arrives as a burst of per-flag `flag-update` events.
- Anonymous-friendly — the landing page's `EventSource` needs no token against this service.
curl -X GET 'https://flaggr.dev/api/flags/stream?serviceId=pixel-grid&environment=development' \ -H 'Accept: text/event-stream' \ -N \
data: {"type":"connected","serviceId":"pixel-grid","realTimeMethod":"redis-pubsub"}
data: {"type":"flag-update","flagKey":"px-512","serviceId":"pixel-grid","flag":{"key":"px-512","enabled":true}}Write to the grid
Public demoAnonymous writes, restricted to the demo service: only `updates.enabled` applies, one write per IP per 2s, attributed to a `public-demo` actor in the audit log.
- The demo client diffs patterns and sends only changed cells — sparse patterns are ~1–2K updates, not 4,096.
- Any non-demo serviceId in the request reverts to full CSRF + write-token requirements.
curl -X PATCH 'https://flaggr.dev/api/flags/bulk?summary=true' \
-H 'Content-Type: application/json' \
-d '{ "flags": [ { "key": "px-0", "serviceId": "pixel-grid", "environment": "development", "updates": { "enabled": true } }, { "key": "px-1", "serviceId": "pixel-grid", "environment": "development", "updates": { "enabled": false } } ]}'{
"flags": [
{ "key": "px-0", "serviceId": "pixel-grid", "environment": "development", "updates": { "enabled": true } },
{ "key": "px-1", "serviceId": "pixel-grid", "environment": "development", "updates": { "enabled": false } }
]
}{ "success": true, "total": 2, "succeeded": 2, "failed": 0 }Health
1Liveness and dependency checks for the control plane.
Application health
No authLiveness + dependency probe — reports storage, cache, and pub/sub connectivity. Used by uptime checks and deploy verification.
curl -X GET 'https://flaggr.dev/api/health' \
{
"status": "ok",
"timestamp": "2026-09-24T03:15:02.118Z",
"checks": {
"database": "ok",
"cache": "ok",
"pubsub": "redis-pubsub"
}
}Generated from protobuf definitions using protoc-gen-connect-openapi · Protocol docs