Developers

REST API

Everything the dashboard does, scriptable. Authenticate with a scoped API token in the Authorization header; the dashboard's own session cookies work too.

Authentication

Create a token in Settings → Tokens (or with buildfy tokens create) and send it as Authorization: Bearer bfy_… on any /v1 route. Tokens start with bfy_, are stored hashed, can be bound to one workspace or all of yours, and can expire. Creation and revocation are written to the workspace audit log; removing a member revokes their tokens for that workspace.

# Create a token in Dashboard → Settings → Tokens, or:
buildfy tokens create --name ci --scopes read,deploy --expires 90d

curl -s https://api.buildfyio.com/v1/orgs/$ORG_ID/projects/$PROJECT_ID/deployments \
  -H "Authorization: Bearer $BUILDFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"env":"production","branch":"main","trigger":"manual"}'

Permissions

readList projects, deployments, logs, domains. Every scope except env:read includes it.
deployTrigger, cancel and roll back deployments.
env:readRead environment variables, including secret values.
env:writeCreate, update, delete environment variables. Includes env:read.
domainsAdd, verify and remove domains.
adminEverything, including project settings, members and tokens.

A request the token is not allowed to make gets a 403 naming the missing permission; a revoked or expired token gets a 401.

HTTP/1.1 403 Forbidden
{
  "code": "insufficient_scope",
  "message": "insufficient_scope: env:write — this token does not have the \"env:write\" permission.",
  "details": { "requiredScope": "env:write", "tokenScopes": ["read", "deploy"] },
  "status": 403
}

GitHub Actions

Store a read,deploy token as the BUILDFY_TOKEN repository secret. Nothing else from your account goes into CI, and revoking the token is the whole rotation.

# .github/workflows/deploy.yml
name: Deploy to Buildfyio
on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - name: Trigger production deploy
        env:
          BUILDFY_TOKEN: ${{ secrets.BUILDFY_TOKEN }}   # read,deploy is enough
        run: |
          curl --fail-with-body -s \
            https://api.buildfyio.com/v1/orgs/${{ vars.BUILDFY_ORG_ID }}/projects/${{ vars.BUILDFY_PROJECT_ID }}/deployments \
            -H "Authorization: Bearer $BUILDFY_TOKEN" \
            -H "Content-Type: application/json" \
            -d '{"env":"production","branch":"main","trigger":"manual"}'

      # Or with the CLI, which also waits for the build to finish:
      # - run: npx @fyio/buildfyio-cli deploy --prod --branch main
      #   env: { BUILDFY_TOKEN: ${{ secrets.BUILDFY_TOKEN }} }
MethodPathDescription
POST/v1/user/tokensCreate an API token (plain token returned once)
GET/v1/user/tokensList your tokens (metadata only)
DELETE/v1/user/tokens/:idRevoke a token immediately
GET/v1/auth/meWho the token acts as, and their workspaces
GET/v1/orgsList your workspaces
GET/v1/orgs/:orgId/projectsList projects in a workspace
POST/v1/orgs/:orgId/projectsCreate a project from a Git repo
POST/v1/orgs/:orgId/projects/:projectId/deploymentsTrigger a deploy
GET/v1/orgs/:orgId/deployments/:idGet deployment status + URL
GET/v1/orgs/:orgId/deployments/:id/logs/streamSSE stream of build/deploy logs
GET/v1/orgs/:orgId/projects/:projectId/envList environment variables
POST/v1/orgs/:orgId/projects/:projectId/env/importUpsert a dotenv in one request
GET/v1/orgs/:orgId/projects/:projectId/domainsList domains