Version
POST

Create a project

/v1/projects in the Projects API.

curl -X POST https://api.subscriby.net/v1/projects \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN" \  -H "Idempotency-Key: $(uuidgen)" \  -H "Content-Type: application/json" \  -d '{    "name": "Research Premium",    "description": "Weekly deep-dive research notes.",    "handle": "research-premium",    "metrics": true  }'

Banner and photo are optional image uploads. Send multipart/form-data when you want the API to accept the raw image:

curl -X POST https://api.subscriby.net/v1/projects \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN" \  -H "Idempotency-Key: $(uuidgen)" \  -F "name=Research Premium" \  -F "description=Weekly deep-dive research notes." \  -F "banner=@./banner.jpg" \  -F "photo=@./avatar.jpg"

Answers 201 with the project and emits project.created. Creating a project enforces the creator's tier project limit; exceeding it is 403 TEAM_TIER_REQUIRED with a required_capability hint in error.context.

Validation rules

Enforced on both create and update (every field is optional on update):

  • name: required on create. String, 5–255 characters.
  • description: optional. String, max 1,000 characters. HTML is filtered to a safe subset before storage.
  • terms, privacy: optional. URLs, max 255 characters each.
  • banner, photo: optional. Image uploads, max 5 MB each, sent as multipart/form-data.
  • handle: optional. Lowercase alpha-dash ASCII, 5–255 characters, unique. Requires a Subscriby tier that includes the custom-handle capability; Free-tier tokens receive TEAM_TIER_REQUIRED when a handle is supplied.
  • metrics, active: optional booleans.
  • outage_compensations: optional boolean, true on every new project. Outage Compensation: when a platform refuses the project's connector for an hour or more and later answers again, every member whose paid access overlapped the gap gets the lost time added to the end of their access automatically, so nobody pays for days they could not use. Set it to false when the creator would rather settle outages themselves, for example with refunds or coupons. See Connector outages.
  • team_id: optional UUID; must be a team the token's owner belongs to. Defaults to the token's scoped team.

Artwork is processed after the request. The response body returns the project's metadata only, not the hosted image URLs. Image processing (resize, re-encode, upload to storage) runs on the server after a successful create or update; clients that need the hosted URL should fetch the project once upload is complete.

POST
/v1/projects

Requires ability

The token must hold this ability, or the call is refused with 403.

Fires one event

Delivered to every endpoint subscribed to it once the change is made.

Runs the same action from an agent, behind the same ability.

Idempotent

Send the header on every call; the same key replays the original response for 24 hours.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Header Parameters

Idempotency-Key*string

A key unique to this operation, such as a fresh UUID. The same key replays the original 2xx response for 24 hours (with Idempotent-Replay: true), so a retry after a timeout never repeats the write; the same key with a different body is refused with 409.

Formatuuid

Request body

FILESWhat the request carries

A new project. Send JSON, or multipart/form-data when uploading the banner or photo; the response carries the project's metadata only, and the hosted image URLs appear on a later read once processing has finished.

Responses

201Created

The new project.

400Bad request

Every write needs an Idempotency-Key header. Send a fresh UUID per distinct operation.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description. On this endpoint: TEAM_TIER_REQUIRED: when the creator's tier project limit is reached, or a handle is sent without the custom-handle capability; error.context.required_capability names it.

409Conflict

The key was already used in the last 24 hours with a different request body.

422Validation failed

The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields. On this endpoint: VALIDATION_FAILED: with per-field messages under error.fields.

425Too early

The first request with this key is still running; retry in a few seconds and the original response is replayed.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on