Appbricx
Docs
PricingStart free

Start here

OverviewGetting startedProjects & editorBring your own key

Build with your agent

Coding agents quickstartAccess tokensMCP serverApp contractCustom UI & brandingBefore-write rulesDeveloper CLIDeveloper HTTP API

End-to-end walkthroughs

Lead intakeMulti-user TodoMulti-tenant SaaSSlack on signup

AI & keys

AI keys — how resolution worksBYOK deep dive

Integrations

Integrations catalog

Full-stack runtime

Runtime overviewNamed queriesAuth & RLSAuto CRUD REST APIWorkflowsWebhooks & schedulesTopics & CDCData templatesSecrets & env

Ship & own

Publish & domainsExport & GitHubSelf-host & deploy

Developers

Developer guide

Developer HTTP API

The HTTP door to the same operations as the MCP server and the CLI. JSON in, JSON out.

Base URL and auth

https://appbricx.com/api/dev/v1
Authorization: Bearer apx_pat_...
  • Use an access token. Tokens work on /dev/v1 and /mcp only; they are never accepted by the rest of the Appbricx API (billing, admin, workspace settings).
  • The web app's signed-in session also works here, with every scope across all of the user's workspaces.
  • Send content-type: application/json on requests with a body.

Endpoints

"read" endpoints work with any valid token. Writing endpoints also need a non-viewer role in the project's workspace.

MethodPathScopeWhat it does
GET/mereadUser, auth kind, scopes, workspaces
GET/docsreadThe contract guide (text/markdown)
POST/tokenssession onlyMint a token. A token can't mint another token (403 SESSION_REQUIRED)
GET/tokensreadYour active tokens (prefix, scopes, expiry, last used)
DELETE/tokens/:idreadRevoke one of your tokens
GET/projectsreadProjects in reach, newest first (max 200)
POST/projectsapplyCreate a project: { name, description?, workspaceId? }
GET/projects/:idreadBuild state and preview path
GET/projects/:id/contractread{ contract, built }
POST/projects/:id/checkread{ contract } → { report }; no changes
POST/projects/:id/applyapply{ contract, force? } → build dev
POST/projects/:id/patchapply{ edits, dryRun?, force? } → typed edit ops
POST/projects/:id/verifyread{ report } — static, data, browser
POST/projects/:id/screenshotread{ route?, as?, width?, height?, fullPage? } → PNG (base64 in JSON, or raw with ?format=png)
POST/projects/:id/data/queryread{ table, where?, orderBy?, desc?, limit? } → dev rows (read-only, max 200)
GET/projects/:id/logsread?limit=&workflow= → workflow runs and notifications
POST/projects/:id/deploydeploy{ environment?, allowDestructive?, skipVerify? } → publish, verify-gated
POST/components/checkread{ name, source, sample? } → run one component through every gate

HTTP bodies use camelCase (dryRun, fullPage, skipVerify); the MCP tools use snake_case for the same fields. data/query also accepts entity in place of table.

Examples

export API=https://appbricx.com/api/dev/v1
export AUTH="Authorization: Bearer $APPBRICX_TOKEN"
export P=3f2c9a10-...   # project id

Check

curl -sS -X POST "$API/projects/$P/check" -H "$AUTH" \
  -H "content-type: application/json" \
  -d "{\"contract\": $(cat appbricx.json)}"
# → { "report": { "ok": true, "errors": [], "fixes": [...], "warnings": [], "summary": {...} } }

Apply

curl -sS -X POST "$API/projects/$P/apply" -H "$AUTH" \
  -H "content-type: application/json" \
  -d "{\"contract\": $(cat appbricx.json)}"
# → { "report": {...}, "summary": "... demo sign-ins per role ...", "warnings": [], "changed": true }

Verify

curl -sS -X POST "$API/projects/$P/verify" -H "$AUTH"
# → { "report": { "status": "pass", "ms": 25000, "stages": [
#       { "stage": "static",  "status": "pass", "checks": [...] },
#       { "stage": "data",    "status": "pass", "checks": [...] },
#       { "stage": "browser", "status": "pass", "checks": [...] } ] } }

Each check has id, status, evidence and, when it fails, a fix. skipped is never a pass.

Screenshot

# The PNG itself
curl -sS -X POST "$API/projects/$P/screenshot?format=png" -H "$AUTH" \
  -H "content-type: application/json" \
  -d '{"route": "/jobs", "as": "technician"}' -o jobs.png

# JSON: png (base64), url, signedInAs, viewport, errors, overflowX, text
curl -sS -X POST "$API/projects/$P/screenshot" -H "$AUTH" \
  -H "content-type: application/json" \
  -d '{"as": "guest"}'

as is a persona id, a demo login email or "guest". The default viewport is 390×844.

Errors

Errors are JSON with a message and, usually, a code:

{ "error": "This token lacks the \"deploy\" scope", "code": "FORBIDDEN_SCOPE" }
StatusCodeMeaning
400— / BAD_REQUEST / BAD_QUERYValidation failed (details lists fields) or a query names an unknown table or column
401UNAUTHENTICATEDMissing, invalid, expired or revoked token, or the user left the token's workspace
403FORBIDDEN_SCOPEThe token lacks the scope
403SESSION_REQUIRED / INVALID_SCOPEToken minting rules (see Access tokens)
404—Project not found, or outside the token's reach (never "forbidden")
409PROJECT_BUSYAnother build is running; retry
409HAND_EDITED_FILESCompiled files were edited by hand; files lists them. Re-run with force: true to back them up and regenerate
409NOT_BUILTNothing to screenshot yet; apply first
422CONTRACT_INVALIDThe contract can't be built; read report.errors
422VERIFY_FAILEDDeploy refused because verify is red; report is included
422SCREENSHOT_FAILEDThe screenshot couldn't be taken (message says why)
500BUILD_FAILEDThe build failed at stage

Next

  • App contract
  • Access tokens
  • Developer CLI
Appbricx

Full-stack AI app builder for teams. Hosted cloud or private deploy into your account — multi-tenant, sandboxed, credit-metered.

Product

For coding agentsHow it worksDemoCapabilitiesPricingPrivate cloudBYOKFAQ

Resources

DocumentationBlogFor freelancersFor agenciesSupport

Company

ContactPrivate cloud / agencyPrivacyTerms

© 2026 Appbricx. All rights reserved.

TermsPrivacyCookiesAcceptable Use