Skip to content
bucker

API reference

alert-rules

5 operations. Shapes are sketches of the declared schemas, bounded in depth — the authoritative document is linked from the index.

GET/orgs/{orgSlug}/projects/{projectSlug}/alert-rules

Requires bearerAuth

Parameters

Parameters for GET /orgs/{orgSlug}/projects/{projectSlug}/alert-rules
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
projectSlugrequiredpathstringmin length 1
cursorquerystringmax length 500
limitqueryintegerdefault 25, min 1, max 100

Response 200

{
  data: {
    id: string
    projectId: string
    name: string
    enabled: boolean
    type: "issue" | "metric"
    conditionMatch: "all" | "any"
    conditions: {
      id: "first_seen"
    } | {
      id: "regression"
    } | {
      id: "event_count"
      value: integer
      windowMinutes: integer
      comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    } | {
      id: "user_count"
      value: integer
      windowMinutes: integer
      comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    } | {
      id: "issue_level"
      level: "debug" | "info" | "warning" | "error" | "fatal"
      match: "eq" | "gte"
    } | {
      id: "environment"
      value: string
    } | … 1 more | {
      id: "metric"
      aggregate: "event_count" | "user_count" | "issue_count"
      windowMinutes: integer
      comparator: "gt" | "gte" | "lt" | "lte" | "eq"
      threshold: number
    } | {
      id: "anomaly"
      aggregate: "event_count" | "user_count" | "issue_count"
      sensitivity: number
      direction: "above" | "below" | "both"
      minValue: integer
      environment?: string
    }[]
    filters: {
      id: "level"
      comparator: "eq" | "gte"
      value: "debug" | "info" | "warning" | "error" | "fatal"
    } | {
      id: "environment"
      value: string
    } | {
      id: "release"
      value: string
      match: "equals" | "contains"
    } | {
      id: "tag"
      key: string
      value: string
      match: "equals" | "contains"
    } | {
      id: "issue_age"
      comparator: "older_than" | "newer_than"
      minutes: integer
    }[]
    actions: {
      kind: "notify_channel"
      channelId: string
    } | {
      kind: "agent_investigate"
      objective?: string
      maxTier?: string
    } | {
      kind: "notify_owner"
      fallbackChannelId: string
      subject: "ALERTS" | "APPROVALS" | "INCIDENTS" | "REMEDIATION" | "DIGESTS"
    }[]
    frequencyMinutes: integer
    createdAt: string
    updatedAt: string
  }[]
  nextCursor: string | null
  hasMore: boolean
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl https://api.bucker.io/orgs/{orgSlug}/projects/{projectSlug}/alert-rules \
  -H 'authorization: Bearer $BUCKER_TOKEN'

POST/orgs/{orgSlug}/projects/{projectSlug}/alert-rules

Requires bearerAuth

Parameters

Parameters for POST /orgs/{orgSlug}/projects/{projectSlug}/alert-rules
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
projectSlugrequiredpathstringmin length 1

Request body (required) · application/json

{
  name: string
  enabled?: boolean
  type: "issue" | "metric"
  conditionMatch?: "all" | "any"
  conditions: {
    id: "first_seen"
  } | {
    id: "regression"
  } | {
    id: "event_count"
    value: integer
    windowMinutes: integer
    comparator?: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "user_count"
    value: integer
    windowMinutes: integer
    comparator?: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "issue_level"
    level: "debug" | "info" | "warning" | "error" | "fatal"
    match?: "eq" | "gte"
  } | {
    id: "environment"
    value: string
  } | … 1 more | {
    id: "metric"
    aggregate: "event_count" | "user_count" | "issue_count"
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    threshold: number
  } | {
    id: "anomaly"
    aggregate: "event_count" | "user_count" | "issue_count"
    sensitivity?: number
    direction?: "above" | "below" | "both"
    minValue?: integer
    environment?: string
  }[]
  filters?: {
    id: "level"
    comparator?: "eq" | "gte"
    value: "debug" | "info" | "warning" | "error" | "fatal"
  } | {
    id: "environment"
    value: string
  } | {
    id: "release"
    value: string
    match?: "equals" | "contains"
  } | {
    id: "tag"
    key: string
    value: string
    match?: "equals" | "contains"
  } | {
    id: "issue_age"
    comparator: "older_than" | "newer_than"
    minutes: integer
  }[]
  actions: {
    kind: "notify_channel"
    channelId: string
  } | {
    kind: "agent_investigate"
    objective?: string
    maxTier?: string
  } | {
    kind: "notify_owner"
    fallbackChannelId: string
    subject?: "ALERTS" | "APPROVALS" | "INCIDENTS" | "REMEDIATION" | "DIGESTS"
  }[]
  frequencyMinutes?: integer
}

Response 201

{
  id: string
  projectId: string
  name: string
  enabled: boolean
  type: "issue" | "metric"
  conditionMatch: "all" | "any"
  conditions: {
    id: "first_seen"
  } | {
    id: "regression"
  } | {
    id: "event_count"
    value: integer
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "user_count"
    value: integer
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "issue_level"
    level: "debug" | "info" | "warning" | "error" | "fatal"
    match: "eq" | "gte"
  } | {
    id: "environment"
    value: string
  } | … 1 more | {
    id: "metric"
    aggregate: "event_count" | "user_count" | "issue_count"
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    threshold: number
  } | {
    id: "anomaly"
    aggregate: "event_count" | "user_count" | "issue_count"
    sensitivity: number
    direction: "above" | "below" | "both"
    minValue: integer
    environment?: string
  }[]
  filters: {
    id: "level"
    comparator: "eq" | "gte"
    value: "debug" | "info" | "warning" | "error" | "fatal"
  } | {
    id: "environment"
    value: string
  } | {
    id: "release"
    value: string
    match: "equals" | "contains"
  } | {
    id: "tag"
    key: string
    value: string
    match: "equals" | "contains"
  } | {
    id: "issue_age"
    comparator: "older_than" | "newer_than"
    minutes: integer
  }[]
  actions: {
    kind: "notify_channel"
    channelId: string
  } | {
    kind: "agent_investigate"
    objective?: string
    maxTier?: string
  } | {
    kind: "notify_owner"
    fallbackChannelId: string
    subject: "ALERTS" | "APPROVALS" | "INCIDENTS" | "REMEDIATION" | "DIGESTS"
  }[]
  frequencyMinutes: integer
  createdAt: string
  updatedAt: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl -X POST https://api.bucker.io/orgs/{orgSlug}/projects/{projectSlug}/alert-rules \
  -H 'authorization: Bearer $BUCKER_TOKEN' \
  -H 'content-type: application/json' \
  -d '{ … }'

DELETE/orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId}

Requires bearerAuth

Parameters

Parameters for DELETE /orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId}
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
projectSlugrequiredpathstringmin length 1
ruleIdrequiredpathstringmin length 1

Response 204

No body.

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl -X DELETE https://api.bucker.io/orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId} \
  -H 'authorization: Bearer $BUCKER_TOKEN'

GET/orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId}

Requires bearerAuth

Parameters

Parameters for GET /orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId}
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
projectSlugrequiredpathstringmin length 1
ruleIdrequiredpathstringmin length 1

Response 200

{
  id: string
  projectId: string
  name: string
  enabled: boolean
  type: "issue" | "metric"
  conditionMatch: "all" | "any"
  conditions: {
    id: "first_seen"
  } | {
    id: "regression"
  } | {
    id: "event_count"
    value: integer
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "user_count"
    value: integer
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "issue_level"
    level: "debug" | "info" | "warning" | "error" | "fatal"
    match: "eq" | "gte"
  } | {
    id: "environment"
    value: string
  } | … 1 more | {
    id: "metric"
    aggregate: "event_count" | "user_count" | "issue_count"
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    threshold: number
  } | {
    id: "anomaly"
    aggregate: "event_count" | "user_count" | "issue_count"
    sensitivity: number
    direction: "above" | "below" | "both"
    minValue: integer
    environment?: string
  }[]
  filters: {
    id: "level"
    comparator: "eq" | "gte"
    value: "debug" | "info" | "warning" | "error" | "fatal"
  } | {
    id: "environment"
    value: string
  } | {
    id: "release"
    value: string
    match: "equals" | "contains"
  } | {
    id: "tag"
    key: string
    value: string
    match: "equals" | "contains"
  } | {
    id: "issue_age"
    comparator: "older_than" | "newer_than"
    minutes: integer
  }[]
  actions: {
    kind: "notify_channel"
    channelId: string
  } | {
    kind: "agent_investigate"
    objective?: string
    maxTier?: string
  } | {
    kind: "notify_owner"
    fallbackChannelId: string
    subject: "ALERTS" | "APPROVALS" | "INCIDENTS" | "REMEDIATION" | "DIGESTS"
  }[]
  frequencyMinutes: integer
  createdAt: string
  updatedAt: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl https://api.bucker.io/orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId} \
  -H 'authorization: Bearer $BUCKER_TOKEN'

PATCH/orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId}

Requires bearerAuth

Parameters

Parameters for PATCH /orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId}
NameInTypeNotes
orgSlugrequiredpathstringmin length 1
projectSlugrequiredpathstringmin length 1
ruleIdrequiredpathstringmin length 1

Request body (required) · application/json

{
  name?: string
  enabled?: boolean
  type?: "issue" | "metric"
  conditionMatch?: "all" | "any"
  conditions?: {
    id: "first_seen"
  } | {
    id: "regression"
  } | {
    id: "event_count"
    value: integer
    windowMinutes: integer
    comparator?: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "user_count"
    value: integer
    windowMinutes: integer
    comparator?: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "issue_level"
    level: "debug" | "info" | "warning" | "error" | "fatal"
    match?: "eq" | "gte"
  } | {
    id: "environment"
    value: string
  } | … 1 more | {
    id: "metric"
    aggregate: "event_count" | "user_count" | "issue_count"
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    threshold: number
  } | {
    id: "anomaly"
    aggregate: "event_count" | "user_count" | "issue_count"
    sensitivity?: number
    direction?: "above" | "below" | "both"
    minValue?: integer
    environment?: string
  }[]
  filters?: {
    id: "level"
    comparator?: "eq" | "gte"
    value: "debug" | "info" | "warning" | "error" | "fatal"
  } | {
    id: "environment"
    value: string
  } | {
    id: "release"
    value: string
    match?: "equals" | "contains"
  } | {
    id: "tag"
    key: string
    value: string
    match?: "equals" | "contains"
  } | {
    id: "issue_age"
    comparator: "older_than" | "newer_than"
    minutes: integer
  }[]
  actions?: {
    kind: "notify_channel"
    channelId: string
  } | {
    kind: "agent_investigate"
    objective?: string
    maxTier?: string
  } | {
    kind: "notify_owner"
    fallbackChannelId: string
    subject?: "ALERTS" | "APPROVALS" | "INCIDENTS" | "REMEDIATION" | "DIGESTS"
  }[]
  frequencyMinutes?: integer
}

Response 200

{
  id: string
  projectId: string
  name: string
  enabled: boolean
  type: "issue" | "metric"
  conditionMatch: "all" | "any"
  conditions: {
    id: "first_seen"
  } | {
    id: "regression"
  } | {
    id: "event_count"
    value: integer
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "user_count"
    value: integer
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
  } | {
    id: "issue_level"
    level: "debug" | "info" | "warning" | "error" | "fatal"
    match: "eq" | "gte"
  } | {
    id: "environment"
    value: string
  } | … 1 more | {
    id: "metric"
    aggregate: "event_count" | "user_count" | "issue_count"
    windowMinutes: integer
    comparator: "gt" | "gte" | "lt" | "lte" | "eq"
    threshold: number
  } | {
    id: "anomaly"
    aggregate: "event_count" | "user_count" | "issue_count"
    sensitivity: number
    direction: "above" | "below" | "both"
    minValue: integer
    environment?: string
  }[]
  filters: {
    id: "level"
    comparator: "eq" | "gte"
    value: "debug" | "info" | "warning" | "error" | "fatal"
  } | {
    id: "environment"
    value: string
  } | {
    id: "release"
    value: string
    match: "equals" | "contains"
  } | {
    id: "tag"
    key: string
    value: string
    match: "equals" | "contains"
  } | {
    id: "issue_age"
    comparator: "older_than" | "newer_than"
    minutes: integer
  }[]
  actions: {
    kind: "notify_channel"
    channelId: string
  } | {
    kind: "agent_investigate"
    objective?: string
    maxTier?: string
  } | {
    kind: "notify_owner"
    fallbackChannelId: string
    subject: "ALERTS" | "APPROVALS" | "INCIDENTS" | "REMEDIATION" | "DIGESTS"
  }[]
  frequencyMinutes: integer
  createdAt: string
  updatedAt: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 401 · `unauthorized` — no credential, or one that is expired, revoked or not valid for this resource. `mfa_required` when the credential is good but a second factor is owed.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 403 · `forbidden` — the credential is valid and its scopes or this principal’s membership do not reach this resource. Scopes are re-intersected with live memberships on every request, so this can appear for a token that worked yesterday.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 404 · `not_found` — no such resource, OR one this principal cannot see. The two are deliberately one answer: a 403 would confirm the existence of something whose identifier is guessable.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl -X PATCH https://api.bucker.io/orgs/{orgSlug}/projects/{projectSlug}/alert-rules/{ruleId} \
  -H 'authorization: Bearer $BUCKER_TOKEN' \
  -H 'content-type: application/json' \
  -d '{ … }'