↗ Suggestion Box

API v1

Build feedback into your own app.

The supplied pages and your backend use the same versioned API.

Authentication

Anonymous visitors can read projects, boards, and accepted requests. Trusted servers use Authorization: Bearer <project-secret>. Native accounts use server-side cookie sessions; send X-CSRF-Token from the feedback_csrf cookie and the configured Origin on mutations.

Project secrets belong on your backend. External user IDs identify participants only after your backend authenticates them.

API contract

Download the OpenAPI specification for all routes, inputs, permissions, and responses. Import it into an API client or documentation viewer.

Lists default to 25 items, with a maximum of 100. Use limit and offset. Responses include items, has_more, limit, and offset. Popularity ordering can move as votes change.

Errors use {"error":{"code":"…","message":"…"}}. Validation errors include field names. Updates require the current resource version; refresh after a 409 conflict.

A backend submission

POST /api/v1/boards/{board_id}/requests
Authorization: Bearer <project-secret>
Content-Type: application/json

{"title":"Offline mode","description":"Let me read without a connection.","external_user_id":"glean-user-123"}

The service finds or creates the project-scoped participant automatically. The new request stays private until accepted.