Alert rules API

Alert rules endpoints in the Brix REST API: 6 operations (GET, POST, PATCH, DELETE), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/alert-rules

Bearer token alert-rule.view

List the alert rules configured for your workspace. Each rule includes its name, trigger, scope configuration, and whether it is enabled. Results are limited to the organization nodes you have access to. Microsoft Teams workflow URLs in config.teamsUrls and web addresses in config.recipients are credentials, so the response shows them masked: the host and the last four characters, for example https://prod-12.westus.logic.azure.com/…?sig=••••a1b2.

ParameterInTypeRequiredDescription
limitqueryintegernoPage size. Omit to get every row; pass it to page by `cursor`.
cursorquerystringnoThe `nextCursor` of the previous page.
curl "https://api.brixsignage.com/v1/alert-rules" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of AlertRule
data[].idstringAlert rule id.
data[].spaceIdstring
data[].namestring
data[].triggerstringThe first trigger code, e.g. `connection-lost`.
data[].configAlertRuleConfigThe rule's trigger, scope and delivery settings. Other keys pass through unchanged.
data[].config.codesarray of stringEvery trigger code the rule watches; the first is also `trigger`.
data[].config.severitystring
data[].config.scopeKindstring`workspace`, `org_unit`, `location`, `screen_group` or `screen`.
data[].config.scopeIdstring
data[].config.thresholdsobject
data[].config.channelsarray of string`in-app`, `email`, `webhook`, `teams`.
data[].config.recipientsarray of stringEmail addresses, `role:` tokens and webhook URLs. Webhook URLs are Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data[].config.teamsUrlsarray of stringMicrosoft Teams workflow URLs for the `teams` channel. Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data[].enabledboolean
data[].nodeIdstring | nullHome location; null = workspace root.
data[].createdAtstringISO-8601 timestamp (UTC).
data[].updatedAtstringISO-8601 timestamp (UTC).
data[].deletedAtstring | null
nextCursorstring | nullPresent when `?limit` was passed. Send it back as `?cursor=` for the next page; null on the last page.
totalintegerTotal matching rows, when the route computes it.

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/alert-rules

Bearer token alert-rule.create

Create an alert rule with a name, trigger, optional config, optional enabled flag, and optional nodeId. If the scope named in config does not resolve to an existing target, the request is refused rather than saved. A Microsoft Teams channel is also refused unless config.teamsUrls contains at least one valid Microsoft Teams Workflow HTTPS URL. The response shows each URL masked. **Notes.** - The 201 body is the row as written, not re-read: nodeId is absent when the create did not set one.

Request body application/json

FieldTypeRequiredDescription
namestringyes
triggerstringyes
configAlertRuleConfignoThe rule's trigger, scope and delivery settings. Other keys pass through unchanged.
config.codesarray of stringnoEvery trigger code the rule watches; the first is also `trigger`.
config.severitystringno
config.scopeKindstringno`workspace`, `org_unit`, `location`, `screen_group` or `screen`.
config.scopeIdstringno
config.thresholdsobjectno
config.channelsarray of stringno`in-app`, `email`, `webhook`, `teams`.
config.recipientsarray of stringnoEmail addresses, `role:` tokens and webhook URLs. Webhook URLs are Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
config.teamsUrlsarray of stringnoMicrosoft Teams workflow URLs for the `teams` channel. Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
enabledbooleanno
nodeIdstring | nullno
curl -X POST "https://api.brixsignage.com/v1/alert-rules" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 201 Success.

FieldTypeDescription
dataobject
data.idstringAlert rule id.
data.spaceIdstring
data.namestring
data.triggerstringThe first trigger code, e.g. `connection-lost`.
data.configAlertRuleConfigThe rule's trigger, scope and delivery settings. Other keys pass through unchanged.
data.config.codesarray of stringEvery trigger code the rule watches; the first is also `trigger`.
data.config.severitystring
data.config.scopeKindstring`workspace`, `org_unit`, `location`, `screen_group` or `screen`.
data.config.scopeIdstring
data.config.thresholdsobject
data.config.channelsarray of string`in-app`, `email`, `webhook`, `teams`.
data.config.recipientsarray of stringEmail addresses, `role:` tokens and webhook URLs. Webhook URLs are Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data.config.teamsUrlsarray of stringMicrosoft Teams workflow URLs for the `teams` channel. Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data.enabledboolean
data.nodeIdstring | null
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).
data.deletedAtstring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 The location does not exist.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 `name` or `trigger` is missing, the scope target does not exist, or a Microsoft Teams URL is not a workflow URL.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/alert-rules/{id}

Bearer token alert-rule.view

Get one alert rule, including its full trigger configuration. Access is limited to the organization nodes you can see. Microsoft Teams workflow URLs in config.teamsUrls and web addresses in config.recipients are credentials, so the response shows them masked: the host and the last four characters, for example https://prod-12.westus.logic.azure.com/…?sig=••••a1b2.

ParameterInTypeRequiredDescription
idpathstringyesAlert rule id.
curl "https://api.brixsignage.com/v1/alert-rules/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataAlertRule
data.idstringAlert rule id.
data.spaceIdstring
data.namestring
data.triggerstringThe first trigger code, e.g. `connection-lost`.
data.configAlertRuleConfigThe rule's trigger, scope and delivery settings. Other keys pass through unchanged.
data.config.codesarray of stringEvery trigger code the rule watches; the first is also `trigger`.
data.config.severitystring
data.config.scopeKindstring`workspace`, `org_unit`, `location`, `screen_group` or `screen`.
data.config.scopeIdstring
data.config.thresholdsobject
data.config.channelsarray of string`in-app`, `email`, `webhook`, `teams`.
data.config.recipientsarray of stringEmail addresses, `role:` tokens and webhook URLs. Webhook URLs are Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data.config.teamsUrlsarray of stringMicrosoft Teams workflow URLs for the `teams` channel. Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data.enabledboolean
data.nodeIdstring | nullHome location; null = workspace root.
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).
data.deletedAtstring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

PATCH/v1/alert-rules/{id}

Bearer token alert-rule.edit

Update an alert rule's name, trigger, config, enabled flag, or nodeId. The same scope validation used when creating a rule applies here. To keep a saved URL, send its masked value back unchanged. To replace it, send the new URL. A masked value that matches no saved URL is refused.

ParameterInTypeRequiredDescription
idpathstringyesAlert rule id.

Request body application/json

FieldTypeRequiredDescription
namestringno
triggerstringno
configAlertRuleConfignoThe rule's trigger, scope and delivery settings. Other keys pass through unchanged.
config.codesarray of stringnoEvery trigger code the rule watches; the first is also `trigger`.
config.severitystringno
config.scopeKindstringno`workspace`, `org_unit`, `location`, `screen_group` or `screen`.
config.scopeIdstringno
config.thresholdsobjectno
config.channelsarray of stringno`in-app`, `email`, `webhook`, `teams`.
config.recipientsarray of stringnoEmail addresses, `role:` tokens and webhook URLs. Webhook URLs are Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
config.teamsUrlsarray of stringnoMicrosoft Teams workflow URLs for the `teams` channel. Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
enabledbooleanno
nodeIdstring | nullno
baseUpdatedAtstringnoThe `updatedAt` your edit is based on; 409 with the current row if it moved.
curl -X PATCH "https://api.brixsignage.com/v1/alert-rules/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataAlertRule
data.idstringAlert rule id.
data.spaceIdstring
data.namestring
data.triggerstringThe first trigger code, e.g. `connection-lost`.
data.configAlertRuleConfigThe rule's trigger, scope and delivery settings. Other keys pass through unchanged.
data.config.codesarray of stringEvery trigger code the rule watches; the first is also `trigger`.
data.config.severitystring
data.config.scopeKindstring`workspace`, `org_unit`, `location`, `screen_group` or `screen`.
data.config.scopeIdstring
data.config.thresholdsobject
data.config.channelsarray of string`in-app`, `email`, `webhook`, `teams`.
data.config.recipientsarray of stringEmail addresses, `role:` tokens and webhook URLs. Webhook URLs are Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data.config.teamsUrlsarray of stringMicrosoft Teams workflow URLs for the `teams` channel. Masked: a delivery URL is a credential (a Microsoft Teams workflow URL carries it in `sig=`), so every response shows the host and the last four characters only — `https://prod-12.westus.logic.azure.com/…?sig=••••a1b2`. On update, send a masked value back unchanged to keep the saved URL, or a full URL to replace it.
data.enabledboolean
data.nodeIdstring | nullHome location; null = workspace root.
data.createdAtstringISO-8601 timestamp (UTC).
data.updatedAtstringISO-8601 timestamp (UTC).
data.deletedAtstring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No rule with this id.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `conflict`: changed since `baseUpdatedAt`; the body carries `current`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 The scope target does not exist, a Microsoft Teams URL is not a workflow URL, or a masked URL matches no saved URL.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

DELETE/v1/alert-rules/{id}

Bearer token alert-rule.delete

Delete an alert rule. It moves to the recycle bin and stops firing immediately.

ParameterInTypeRequiredDescription
idpathstringyesAlert rule id.
curl -X DELETE "https://api.brixsignage.com/v1/alert-rules/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.deletedtrue

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such alert rule in this workspace.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/alert-rules/{id}/restore

Bearer token alert-rule.delete

Restore an alert rule that was deleted within the last 30 days. The rule resumes firing once restored.

ParameterInTypeRequiredDescription
idpathstringyesAlert rule id.
curl -X POST "https://api.brixsignage.com/v1/alert-rules/{id}/restore" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataobject
data.idstring
data.restoredtrue

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such alert rule in this workspace, or it was purged.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `not_deleted`: the rule is not in the recycle bin.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.