Public API: Flag attributes

Flag attributes are the named fields a feature-flag project can target on in its audience rules. An audience is a saved group of targeting conditions. Built-in attributes like browser, country, and deviceType are always there; you can also define your own, such as plan_tier or account_age_days.

All flag-attribute endpoints live under a project and authenticate with a Bearer token: a service token or a personal access token. The org comes from the token, so the path carries only {projectId} (and {attrId} for a single attribute), never {orgId}.

Plain text
https://app.avsb.cloud/api/v1/projects/{projectId}/flag-attributes
Plain text1 line

The first time you list attributes for a feature-flag project, the built-in attributes are seeded automatically and returned.

Scopes

A scope is a named permission on your token. It decides exactly what that token is allowed to read or change.

OperationScope
List / get attributesflags:read
Create / update / deleteflags:write

Every /api/v1 token is also rate-limited: a scoped token gets 600 reads and 120 writes per minute, and an admin:* token gets 600 requests per minute, reads and writes together. See Conventions for the response headers that show your remaining budget.

List flag attributes

GET /api/v1/projects/{projectId}/flag-attributes: built-in attributes first, then custom ones (oldest-created first), cursor-paginated (?limit=, up to 100, default 20; ?cursor=, the opaque value from page.nextCursor).

curl "https://app.avsb.cloud/api/v1/projects/<projectId>/flag-attributes?limit=20" \  -H "Authorization: Bearer avsb_svc_..."
Shell2 lines
Response
{  "data": [    {      "id": "<attrId>",      "projectId": "<projectId>",      "key": "browser",      "name": "Browser",      "type": "STRING",      "isBuiltIn": true,      "description": "Browser name (e.g. Chrome, Firefox, Safari)",      "suggestedValues": null,      "createdAt": "2026-06-18T00:00:00.000Z",      "updatedAt": "2026-06-18T00:00:00.000Z"    }  ],  "page": { "nextCursor": null, "hasMore": false }}
JSON17 lines

Get a flag attribute

GET /api/v1/projects/{projectId}/flag-attributes/{attrId}: one attribute by id.

curl https://app.avsb.cloud/api/v1/projects/<projectId>/flag-attributes/<attrId> \  -H "Authorization: Bearer avsb_svc_..."
Shell2 lines
Response
{  "data": {    "id": "<attrId>",    "projectId": "<projectId>",    "key": "plan_tier",    "name": "Plan Tier",    "type": "STRING",    "isBuiltIn": false,    "description": "The customer plan tier",    "suggestedValues": ["free", "pro", "enterprise"],    "createdAt": "2026-06-18T00:00:00.000Z",    "updatedAt": "2026-06-18T00:00:00.000Z"  }}
JSON14 lines

An id that does not exist, or belongs to another org's project, returns 404 worded the same either way:

404: attribute not found
{  "error": {    "code": "not_found",    "message": "Attribute not found",    "docUrl": "https://docs.avsb.cloud/docs/developer-reference/public-api/conventions#not-found-errors",    "requestId": "req_9f2c41ab7e0b4d1e8c35a6f0d2b91e77"  }}
JSON8 lines

This is the same error every other endpoint on this page returns for an id it cannot find, so the sections below do not repeat it.

Create a flag attribute

POST /api/v1/projects/{projectId}/flag-attributes: requires flags:write. The key must be a valid identifier (letters, digits, and underscores, not starting with a digit) and unique within the project. type is one of STRING, NUMBER, BOOLEAN, or JSON (defaults to STRING).

curl -X POST https://app.avsb.cloud/api/v1/projects/<projectId>/flag-attributes \  -H "Authorization: Bearer avsb_svc_..." \  -H "Content-Type: application/json" \  -d '{    "key": "plan_tier",    "name": "Plan Tier",    "type": "STRING",    "description": "The customer plan tier",    "suggestedValues": ["free", "pro", "enterprise"]  }'
Shell10 lines

Returns 201 with the created attribute in the same single-object shape as Get a flag attribute.

A duplicate key returns 409 rather than overwriting the existing attribute:

409: key already exists
{  "error": {    "code": "validation_failed",    "message": "An attribute with this key already exists in this project",    "docUrl": "https://docs.avsb.cloud/docs/developer-reference/public-api/conventions#validation-errors",    "requestId": "req_9f2c41ab7e0b4d1e8c35a6f0d2b91e77"  }}
JSON8 lines

Update a flag attribute

PATCH /api/v1/projects/{projectId}/flag-attributes/{attrId}: requires flags:write. Send only the fields you want to change. Built-in attributes cannot have their name or type changed.

curl -X PATCH https://app.avsb.cloud/api/v1/projects/<projectId>/flag-attributes/<attrId> \  -H "Authorization: Bearer avsb_svc_..." \  -H "Content-Type: application/json" \  -d '{ "description": "Updated description", "suggestedValues": ["free", "pro"] }'
Shell4 lines

Returns the updated attribute in the single-object shape.

Trying to rename a built-in attribute, or change its type, is refused:

400: built-in attribute
{  "error": {    "code": "validation_failed",    "message": "Built-in attributes cannot have their key, name, or type changed",    "docUrl": "https://docs.avsb.cloud/docs/developer-reference/public-api/conventions#validation-errors",    "requestId": "req_9f2c41ab7e0b4d1e8c35a6f0d2b91e77"  }}
JSON8 lines

Delete a flag attribute

DELETE /api/v1/projects/{projectId}/flag-attributes/{attrId}: requires flags:write.

curl -X DELETE https://app.avsb.cloud/api/v1/projects/<projectId>/flag-attributes/<attrId> \  -H "Authorization: Bearer avsb_svc_..."
Shell2 lines
Response
{ "data": { "id": "<attrId>" } }
JSON1 line

Built-in attributes cannot be deleted:

403: built-in attribute
{  "error": {    "code": "forbidden",    "message": "Built-in attributes cannot be deleted",    "docUrl": "https://docs.avsb.cloud/docs/developer-reference/public-api/conventions#refusals-at-403",    "requestId": "req_9f2c41ab7e0b4d1e8c35a6f0d2b91e77"  }}
JSON8 lines

Nor can one still referenced by an audience, which also returns 409; the message says how many:

409: still in use
{  "error": {    "code": "validation_failed",    "message": "This attribute is used in 2 audience(s) and cannot be deleted",    "docUrl": "https://docs.avsb.cloud/docs/developer-reference/public-api/conventions#validation-errors",    "requestId": "req_9f2c41ab7e0b4d1e8c35a6f0d2b91e77"  }}
JSON8 lines

Next steps

Was this helpful?