Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint.

OSS setup lock. On Bifrost OSS, while dashboard auth is not active (no admin account, or auth disabled), every management endpoint except the public ones (/health, /api/version, /api/session/is-auth-enabled, /api/session/login, ...) requires the operator's setup token in the X-Bifrost-Setup-Token header, in place of Authorization. The token is set with setup_token in config.json or the BIFROST_SETUP_TOKEN environment variable. A missing header returns 401, a wrong token 403. The header stops working once dashboard auth is enabled. The dashboard instead trades the token once for an HttpOnly bifrost_setup_session cookie via POST /api/session/setup. See Required permissions for how permissions are derived and which endpoints are exempt.

Body

application/json

A notification to publish. IDs and both timestamps are assigned by the server and cannot be supplied.

audience
enum<string>
required

Who the notification reaches. all is every dashboard user; roles limits it to the listed RBAC roles, enforced on both the list endpoint and the WebSocket fan-out.

Available options:
all,
roles
severity
enum<string>
required

Visual weight the dashboard gives the notification.

Available options:
info,
success,
warning,
error
title
string
required

Trimmed before validation.

Required string length: 1 - 160
message
string
required

Trimmed before validation.

Required string length: 1 - 4000
role_ids
integer<int64>[]

Required when audience is roles, and must be empty otherwise. Duplicates are removed and the list is sorted before it is stored.

Required range: x >= 1
action_label
string

Label for the notification's action. Must be supplied together with action_path, or not at all.

action_path
string

Dashboard-internal absolute path the action opens, for example /workspace/providers. Absolute URLs, host-relative // paths, and anything not starting with / are rejected, so a notification cannot be used to send users off-site.

Pattern: ^/(?!/).*

Response

Notification published and broadcast

A persisted dashboard notification.

id
string<uuid>
required
audience
enum<string>
required

Who the notification reaches. all is every dashboard user; roles limits it to the listed RBAC roles, enforced on both the list endpoint and the WebSocket fan-out.

Available options:
all,
roles
severity
enum<string>
required

Visual weight the dashboard gives the notification.

Available options:
info,
success,
warning,
error
title
string
required
message
string
required
created_at
string<date-time>
required
expires_at
string<date-time>
required

Always 30 days after created_at. Expired rows are pruned hourly and are not returned once pruned.

role_ids
integer<int64>[]
action_label
string
action_path
string