Looking for direct sandbox runtime access? The Sandbox API tab covers the dedicated sandbox host at
https://sandbox.brimble.io. The Core API also exposes sandbox endpoints under /v1/sandboxes, authenticated with the same API key.Base URL
All endpoints are relative to:GET https://api.brimble.io/core/v1/projects.
Authentication
Create an API key in the dashboard (see API keys) and send it in thex-brimble-key header on every request:
Permission scopes
Each API key carries permission scopes such asproject.read or project.deploy. Every endpoint in this reference lists the scope it needs. A key without that scope gets 403:
Session tokens
Dashboard session tokens (Authorization: Bearer <token>) are also accepted. Use an API key for scripts, CI, and integrations.
Teams
Requests act on your personal workspace unless you target a team:- Pass
teamIdas a query parameter on reads, or in the request body on writes. - An API key created inside a team workspace already acts in that team.
Responses
Successful responses are JSON with amessage and a data payload:
Errors
Errors return a non-2xx status and a human-readablemessage:
400 with every invalid field:
Rate limits
Requests made with an API key are rate limited. Every response carries these headers:
Command execution (
/exec, /code) and file transfer (/files) endpoints count against their own buckets, so heavy sandbox runtime traffic doesn’t starve the rest of your integration. On 429, wait for the reset before retrying.
Idempotency
Object storage write endpoints (creating, updating, and deleting buckets and credentials) accept anIdempotency-Key header. Retrying with the same key and body returns the original result instead of repeating the operation. Send a unique value (a UUID works) per logical operation, and reuse it on retries.
Streaming
Sandbox command execution (/exec, /code) returns one JSON response when the command finishes. Send "stream": true in the body to receive output as Server-Sent Events (text/event-stream) while it runs. Each event is a data: line carrying JSON with a type:
: (: open, : ping) are keep-alives. Ignore them.
Webhooks
To receive events from Brimble instead of polling, configure a webhook destination withPATCH /v1/webhooks or from the dashboard. See Webhooks for setup and Webhook events for every payload.