BugsRadar

Management API

Updated 11 October 2026 · BugsRadar team

The management API does from a script what you do in the web app: creates projects and channels, reads and rotates API keys, binds channels to projects and sets rules. It is made for CI pipelines, deploy scripts and Terraform-style setups where every new service gets its own project without a visit to the web app. The API comes with the Business plan.

Token and base URL

In the web app open Settings → Management API and create a token. Name it after what uses it, say CI or Terraform: the name is what the audit log shows for the token's actions. The token is shown once; keep it in the secrets of your CI, never in a repository. Revoking a token stops it at once.

Every request carries the token in the Authorization header and goes to the base URL:

Authorization: Bearer brm_…
https://api.bugsradar.com/api/management/v1/

A token acts as the owner of the account: it sees and changes the owner's own projects and channels. Projects of organizations the owner belongs to as a member are not reachable through it.

Requests and errors

Bodies are JSON, answers are JSON. Ids are GUIDs, dates are UTC in ISO 8601. The HTTP code tells the outcome:

CodeMeaning
200Done; the resource is in the body.
201Created; the resource is in the body, its address in Location.
204Done; nothing to return.
400The request is wrong or the plan does not allow it; {"error": "…"} says why.
401No token, a revoked token, or the plan has no management API.
404No such project or channel in this account.

Projects

RequestWhat it does
GET /projectsEvery project of the account.
POST /projectsCreates a project: {"name": "Payments API", "teamId": null}. teamId puts it into a team of the organization.
GET /projects/{id}One project.
PATCH /projects/{id}Renames (name) or sets the allowed IP addresses (allowedIps, a list of addresses and CIDR ranges; an empty list accepts from anywhere). A field you leave out stays as it is.
DELETE /projects/{id}Deletes the project; both keys stop at once.

A project looks like this:

{
  "id": "6f1c…",
  "name": "Payments API",
  "teamId": null,
  "channelIds": ["a2b3…"],
  "rules": [
    { "channelId": "a2b3…", "minLevel": "error", "modules": ["Payments"], "environments": ["Production"] }
  ],
  "allowedIps": ["203.0.113.0/24"],
  "dateUpdated": "2026-10-11T12:00:00"
}

Creating a project from a shell:

curl -fsS -X POST https://api.bugsradar.com/api/management/v1/projects \
  -H "Authorization: Bearer $BUGSRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "Payments API"}'

API keys

Every project has two keys, primary and secondary; applications report errors with either. Rotate without losing errors: move the applications to the other key, then regenerate the old one.

RequestWhat it does
GET /projects/{id}/keysBoth keys: {"id": "…", "primary": "…", "secondary": "…"}.
POST /projects/{id}/keys/primary/regenerate
POST /projects/{id}/keys/secondary/regenerate
A new key in that slot: {"id": "…", "slot": "primary", "apiKey": "…"}. The old key stops at once; the other key keeps working.
curl -fsS https://api.bugsradar.com/api/management/v1/projects/$PROJECT_ID/keys \
  -H "Authorization: Bearer $BUGSRADAR_TOKEN"

The keys are secret: put them only into code that runs on your servers. Where a key may go

Channels of a project

RequestWhat it does
PUT /projects/{id}/channelsThe full list of the account's channels bound to the project: {"channelIds": ["…", "…"]}. Channels not in the list are detached; a detached channel loses its rule. Channels that members of the organization attached themselves are not touched.
curl -fsS -X PUT https://api.bugsradar.com/api/management/v1/projects/$PROJECT_ID/channels \
  -H "Authorization: Bearer $BUGSRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"channelIds": ["a2b3…", "c4d5…"]}'

Rules

A rule is a filter on one channel of one project: the channel gets an error only when it fits every condition. A condition you leave out fits any error. How rules work

RequestWhat it does
PUT /projects/{id}/channels/{channelId}/ruleSets the filter: {"minLevel": "error", "modules": ["Payments"], "environments": ["Production"]}. Levels: trace, debug, information, warning, error, critical. A body without a single condition removes the filter.
DELETE /projects/{id}/channels/{channelId}/ruleRemoves the filter: the channel gets every error again.

Channels

RequestWhat it does
GET /channelsEvery channel of the account, with the mask of its secret and its delivery state.
POST /channelsCreates a channel; the credentials are checked with the service before saving and never returned.
GET /channels/{id}One channel.
PATCH /channels/{id}name, isEnabled (pause and resume), isLiveCounterOn (repeats update the message or come as summaries). A field you leave out stays as it is.
DELETE /channels/{id}Deletes the channel and its bindings. The last channel of a project cannot be deleted: give the project another channel first.
POST /channels/{id}/testSends a test message: {"ok": true, "statusCode": 200, "error": null}.

The body of POST /channels names the service in type and carries its credentials in the object of the same name. Credentials cannot be changed later: other credentials are another channel.

typeCredentialsPlan
telegram"telegram": {"botToken": "…", "chatId": "…"}Any
discord"discord": {"webhookUrl": "…"}Any
pushover"pushover": {"appToken": "…", "userKey": "…"}Any
slack"slack": {"webhookUrl": "…"}Business
microsoftTeams"microsoftTeams": {"webhookUrl": "…"}Business
googleChat"googleChat": {"webhookUrl": "…"}Business
pagerDuty"pagerDuty": {"integrationKey": "…"}Business
curl -fsS -X POST https://api.bugsradar.com/api/management/v1/channels \
  -H "Authorization: Bearer $BUGSRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"type": "slack", "name": "#payments-alerts", "slack": {"webhookUrl": "https://hooks.slack.com/services/…"}}'

Where the credentials come from for each service: channel setup guides.

Limits and the audit log

The plan's limits apply as in the web app: the Business plan has no limits on projects and channels; an account that has more than its plan includes cannot add anything new until the extras are removed. Up to 20 tokens per account. Everything a token does is written to the audit log of the organization under the token's name, with the address the request came from.

Next: Rules →