A valid request URL is required to generate request examples{
"rules": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"key": "<string>",
"name": "<string>",
"kind": "event",
"event_type": "<string>",
"points": 123,
"award_limit": "once",
"limit_value": 123,
"segment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"active": true,
"awards": 123,
"earners": 123,
"sightings": 123,
"last_seen": "2023-11-07T05:31:56Z",
"created_by": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"metric_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
],
"event_types": [
"<string>"
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}List point rules
Requires engagement:manage — the same permission as onboarding, the changelog and surveys, and for their reason: what your product rewards is your own copy about your own users, and it changes in the same hour of the day as an onboarding step.
Inactive rules are listed and marked. Every rule comes back with awards and earners, which are the numbers active cannot give — thousands of awards over a handful of people is a ceiling somebody left at unlimited.
event_types is the vocabulary an event rule may name, derived from the facts this system publishes about one person, minus this module’s own. A rule paying for points.awarded would pay for being paid, forever, at whatever rate the queue drains.
A valid request URL is required to generate request examples{
"rules": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"key": "<string>",
"name": "<string>",
"kind": "event",
"event_type": "<string>",
"points": 123,
"award_limit": "once",
"limit_value": 123,
"segment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"active": true,
"awards": 123,
"earners": 123,
"sightings": 123,
"last_seen": "2023-11-07T05:31:56Z",
"created_by": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"metric_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
],
"event_types": [
"<string>"
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Autorizações
A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.
Cabeçalhos
The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.
Parâmetros de consulta
Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.
live, test