Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Headers

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Query Parameters

environment
enum<string>
default:live

Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.

Available options:
live,
test

Body

application/json
key
string
required

Lower case letters, digits, dot, dash or underscore. It is a string literal in your source.

Maximum string length: 80
enabled
boolean
default:false
segment_id
string<uuid> | null
rollout_percentage
integer | null
Required range: 0 <= x <= 100

Response

The flag.

flag
object

A release switch, aimed at a segment and never at a filter of its own. The bucketing salt is deliberately not part of this: it is the one value that would let somebody compute which bucket they are in and pick an identifier that lands inside a ramp.

propagation
object

How long a flip takes to reach a page, reported by the API rather than assumed by a screen — it is the sum of three things this API decides, and a screen that hard-coded it would go on claiming the old number.