REST API reference

Requirements

Requirements are the anchor of the coverage model. Each one carries a significance derived from development complexity and business impact, and coverage is judged against that significance rather than against a bare "has at least one linked test case" check. Requirements are soft-deleted: a deleted one can be listed with withDeleted=true and brought back with the restore action.

List requirements

GET/api/v1/requirements

Lists requirement resources as a JSON:API collection document. Narrow the set with filter, order it with sort, embed related resources with include, select attributes with fields[<type>], and page with page[size] plus page[number] (offset) or page[after] (cursor, taken from the previous response's links.next).

Query parameters

filterstring
A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
requirementKey = "A-REQ-1"
sortstring
Comma-separated sort fields; prefix a field with "-" for descending order (e.g. "-createdAt,title"). Permitted fields: id, organizationId, projectId, requirementKey, status, name, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, ownerId, deletedAt, requirementKeyNumeric, significance.
-requirementKey
includestring
Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser.
createdByUser
fields[requirements]string[]
Sparse fieldset for resource type "requirements" - comma-separated subset of its exposed fields: id, organizationId, projectId, requirementKey, status, name, reference, description, version, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, createdBy, updatedBy, ownerId, deletedAt, requirementKeyNumeric, coveredOverride, significance, createdByUser, ownerUser, updatedByUser, requirementFolder, organization, project, customFields.
requirementKey,status,name
page[size]integer
Number of resources per page (applies to both offset and cursor pagination). Minimum 1, maximum 100, default 25 when omitted.
25
page[number]integer
1-indexed page number for offset-based pagination. Mutually exclusive with "page[after]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
2
page[after]string
Opaque cursor for cursor-based pagination - always taken verbatim from a previous response's "links.next" value, never client-constructed or decoded. Mutually exclusive with "page[number]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
withDeletedboolean
Include soft-deleted rows in the collection. Only present on soft-delete-enabled entities. Default false (soft-deleted rows excluded) when omitted.

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json

Filterable fields23

Show fields and operators
FieldTypeOperators
iduuid= != in (…) not in (…) is null is not null
organizationIduuid= != in (…) not in (…) is null is not null
projectIduuid= != in (…) not in (…) is null is not null
requirementKeystring= != in (…) not in (…) ~ is null is not null
statusenum= != in (…) not in (…) is null is not nullDRAFT, READY, COVERED, ARCHIVED, IN_REVIEW, CHANGES_REQUESTED, APPROVED
namestring~ is null is not null is empty is not empty
referencestring= != in (…) not in (…) ~ is null is not null
descriptionstring~ is null is not null is empty is not empty
versionint= != < <= > >= in (…) not in (…) is null is not null
rankint= != < <= > >= in (…) not in (…) is null is not null
requirementTypestring= != in (…) not in (…) is null is not null
complexityenum= != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH
impactenum= != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH
folderIduuid= != in (…) not in (…) is null is not null
createdAtdatetime= != < <= > >= is null is not null
updatedAtdatetime= != < <= > >= is null is not null
createdByuuid= != in (…) not in (…) is null is not null
updatedByuuid= != in (…) not in (…) is null is not null
ownerIduuid= != in (…) not in (…) is null is not null
deletedAtdatetime= != < <= > >= is null is not null
requirementKeyNumericint= != < <= > >= in (…) not in (…) is null is not null
coveredOverridebool= != is null is not null
significanceenum= != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH, CRITICAL

Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser, testCaseExecutions, testCollectionRequirements.

Returns the same attributes as Get a requirement.

Responses

  • 200Success.
11 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INVALID_TYPED_JSON_FILTERUNKNOWN_SORT_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDUNKNOWN_TYPEUNKNOWN_FIELDCONFLICTING_PAGINATIONINVALID_PAGE_SIZEPAGE_SIZE_EXCEEDEDINVALID_PAGE_NUMBERINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements?page%5Bsize%5D=25" \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json"
Response

application/vnd.api+json

{
  "data": [
    {
      "type": "requirements",
      "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
      "attributes": {
        "name": "Expired cards are refused at checkout",
        "requirementKey": "KAN-REQ-7",
        "status": "DRAFT",
        "complexity": "HIGH",
        "impact": "HIGH",
        "updatedAt": "2026-10-05T09:30:00Z"
      },
      "links": {
        "self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
      }
    }
  ],
  "links": {
    "self": "/requirements?page[size]=25",
    "first": "/requirements?page[size]=25&page[number]=1",
    "prev": null,
    "next": "/requirements?page[size]=25&page[number]=2",
    "last": "/requirements?page[size]=25&page[number]=6"
  },
  "meta": {
    "totalCount": 128
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Create a requirement

POST/api/v1/requirements

Creates a requirement from a JSON:API resource object - data.type names the resource type and data.attributes carries the writable attributes - and returns the created resource.

Needs a read-and-write token. A read-only token gets 403.

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Content-Typestringrequired
Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+json

Attributes you can send13

namestringrequired
projectIduuidrequired
rankintegerrequired
complexitystring | null
LOWMEDIUMHIGH
coveredOverridebooleandefault false
customFieldsobject
descriptionstring | nullmax 50000 chars
folderIduuid | null
Show the remaining 5
impactstring | null
LOWMEDIUMHIGH
ownerIduuid | null
referencestring | null
requirementTypestring | null
FunctionalNon-FunctionalBusinessTechnicalUser Interfacenull
statusstringdefault DRAFT
DRAFTREADYCOVEREDARCHIVEDIN_REVIEWCHANGES_REQUESTEDAPPROVED

Returns the same attributes as Get a requirement.

Responses

  • 201Created.
11 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 415The Content-Type was not application/vnd.api+json.MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.INVALID_INPUTVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements" \
  -X POST \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json" \
  -H "Content-Type: application/vnd.api+json" \
  -d '{
  "data": {
    "type": "requirements",
    "attributes": {
      "name": "Expired cards are refused at checkout",
      "projectId": "03ff802c-4fcb-4718-8eb8-12ecc999f758",
      "rank": 1,
      "status": "DRAFT"
    }
  }
}'
Response

application/vnd.api+json

{
  "data": [
    {
      "type": "requirements",
      "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
      "attributes": {
        "name": "Expired cards are refused at checkout",
        "requirementKey": "KAN-REQ-7",
        "status": "DRAFT",
        "complexity": "HIGH",
        "impact": "HIGH",
        "updatedAt": "2026-10-05T09:30:00Z"
      },
      "links": {
        "self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
      }
    }
  ],
  "links": {
    "self": "/requirements?page[size]=25",
    "first": "/requirements?page[size]=25&page[number]=1",
    "prev": null,
    "next": "/requirements?page[size]=25&page[number]=2",
    "last": "/requirements?page[size]=25&page[number]=6"
  },
  "meta": {
    "totalCount": 128
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Count and aggregate requirements

GET/api/v1/requirements/aggregate

Aggregates requirement resources - a count and per-column aggregations, optionally grouped - over the same filter the collection route accepts.

Query parameters

aggregations[count]boolean
Include the row count in the aggregate result. When no aggregation is requested at all, the runtime defaults to count.
aggregations[sum][]string[]
Column(s) to sum - repeat the bracketed key per column (aggregations[sum][]=a&aggregations[sum][]=b). Permitted columns: version, rank, requirementKeyNumeric.
aggregations[avg][]string[]
Column(s) to average - repeat the bracketed key per column (aggregations[avg][]=a&aggregations[avg][]=b). Permitted columns: version, rank, requirementKeyNumeric.
aggregations[min][]string[]
Column(s) to take the minimum of - repeat the bracketed key per column (aggregations[min][]=a&aggregations[min][]=b). Permitted columns: requirementKey, name, reference, description, version, rank, requirementType, createdAt, updatedAt, deletedAt, requirementKeyNumeric.
aggregations[max][]string[]
Column(s) to take the maximum of - repeat the bracketed key per column (aggregations[max][]=a&aggregations[max][]=b). Permitted columns: requirementKey, name, reference, description, version, rank, requirementType, createdAt, updatedAt, deletedAt, requirementKeyNumeric.
aggregations[groupBy][]string[]
Column(s) to group by - repeating the bracketed key switches the response to the grouped shape (aggregations[groupBy][]=a&aggregations[groupBy][]=b). Permitted columns: id, organizationId, projectId, requirementKey, status, name, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, ownerId, deletedAt, requirementKeyNumeric, significance.
filterstring
A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
requirementKey = "A-REQ-1"

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json

Filterable fields23

Show fields and operators
FieldTypeOperators
iduuid= != in (…) not in (…) is null is not null
organizationIduuid= != in (…) not in (…) is null is not null
projectIduuid= != in (…) not in (…) is null is not null
requirementKeystring= != in (…) not in (…) ~ is null is not null
statusenum= != in (…) not in (…) is null is not nullDRAFT, READY, COVERED, ARCHIVED, IN_REVIEW, CHANGES_REQUESTED, APPROVED
namestring~ is null is not null is empty is not empty
referencestring= != in (…) not in (…) ~ is null is not null
descriptionstring~ is null is not null is empty is not empty
versionint= != < <= > >= in (…) not in (…) is null is not null
rankint= != < <= > >= in (…) not in (…) is null is not null
requirementTypestring= != in (…) not in (…) is null is not null
complexityenum= != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH
impactenum= != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH
folderIduuid= != in (…) not in (…) is null is not null
createdAtdatetime= != < <= > >= is null is not null
updatedAtdatetime= != < <= > >= is null is not null
createdByuuid= != in (…) not in (…) is null is not null
updatedByuuid= != in (…) not in (…) is null is not null
ownerIduuid= != in (…) not in (…) is null is not null
deletedAtdatetime= != < <= > >= is null is not null
requirementKeyNumericint= != < <= > >= in (…) not in (…) is null is not null
coveredOverridebool= != is null is not null
significanceenum= != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH, CRITICAL

Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser, testCaseExecutions, testCollectionRequirements.

Responses

  • 200Success.
11 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements/aggregate?aggregations%5Bcount%5D=true" \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json"
Response

application/vnd.api+json

{
  "data": {
    "type": "requirements_aggregate",
    "id": "(aggregate)",
    "attributes": {
      "count": 128
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Get a requirement

GET/api/v1/requirements/{id}

Returns the requirement with this id as a JSON:API resource document; include embeds related resources and fields[<type>] selects the attributes returned.

Path parameters

iduuidrequired
The resource id (a UUID).

Query parameters

includestring
Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser.
createdByUser
fields[requirements]string[]
Sparse fieldset for resource type "requirements" - comma-separated subset of its exposed fields: id, organizationId, projectId, requirementKey, status, name, reference, description, version, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, createdBy, updatedBy, ownerId, deletedAt, requirementKeyNumeric, coveredOverride, significance, createdByUser, ownerUser, updatedByUser, requirementFolder, organization, project, customFields.
requirementKey,status,name

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json

Attributes returned24

complexitystring | null
LOWMEDIUMHIGH
coveredOverridebooleandefault false
createdAtdate-timeread-only
createdByuuid | nullread-only
customFieldsobject
deletedAtdate-time | nullread-only
descriptionstring | nullmax 50000 chars
folderIduuid | null
Show the remaining 16
iduuidread-only
impactstring | null
LOWMEDIUMHIGH
namestring
organizationIduuidread-only
ownerIduuid | null
projectIduuid
rankinteger
referencestring | null
requirementKeystringread-only
requirementKeyNumericinteger | nullread-only
requirementTypestring | null
FunctionalNon-FunctionalBusinessTechnicalUser Interfacenull
significancestring | nullread-only
LOWMEDIUMHIGHCRITICAL
statusstringdefault DRAFT
DRAFTREADYCOVEREDARCHIVEDIN_REVIEWCHANGES_REQUESTEDAPPROVED
updatedAtdate-timeread-only
updatedByuuid | nullread-only
versionintegerread-onlydefault 1

Responses

  • 200Success.
12 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.UNKNOWN_TYPEUNKNOWN_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 410Gone.GONE
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json"
Response

application/vnd.api+json

{
  "data": {
    "type": "requirements",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Expired cards are refused at checkout",
      "requirementKey": "KAN-REQ-7",
      "status": "DRAFT",
      "complexity": "HIGH",
      "impact": "HIGH",
      "updatedAt": "2026-10-05T09:30:00Z"
    },
    "links": {
      "self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Update a requirement

PATCH/api/v1/requirements/{id}

Updates the requirement with this id from a JSON:API resource object carrying only the attributes to change, and returns the updated resource. A resource that carries an ETag requires it back as If-Match.

Needs a read-and-write token. A read-only token gets 403.

Version-locked: send the ETag from your last read as If-Match.

Path parameters

iduuidrequired
The resource id (a UUID).

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Content-Typestringrequired
Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+json
If-Matchstringrequired
The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"

Attributes you can send13

complexitystring | null
LOWMEDIUMHIGH
coveredOverridebooleandefault false
customFieldsobject
descriptionstring | nullmax 50000 chars
folderIduuid | null
impactstring | null
LOWMEDIUMHIGH
namestring
ownerIduuid | null
Show the remaining 5
projectIduuid
rankinteger
referencestring | null
requirementTypestring | null
FunctionalNon-FunctionalBusinessTechnicalUser Interfacenull
statusstringdefault DRAFT
DRAFTREADYCOVEREDARCHIVEDIN_REVIEWCHANGES_REQUESTEDAPPROVED

Returns the same attributes as Get a requirement.

Responses

  • 200Success.
13 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.STALE_OBJECT
  • 415The Content-Type was not application/vnd.api+json.MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_ERRORVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 428This resource is version-locked: send its ETag in an If-Match header.MISSING_IF_MATCH
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
  -X PATCH \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json" \
  -H 'If-Match: W/"3"' \
  -H "Content-Type: application/vnd.api+json" \
  -d '{
  "data": {
    "type": "requirements",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "status": "DRAFT"
    }
  }
}'
Response

application/vnd.api+json

{
  "data": {
    "type": "requirements",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Expired cards are refused at checkout",
      "requirementKey": "KAN-REQ-7",
      "status": "DRAFT",
      "complexity": "HIGH",
      "impact": "HIGH",
      "updatedAt": "2026-10-05T09:30:00Z"
    },
    "links": {
      "self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Delete a requirement

DEL/api/v1/requirements/{id}

Deletes the requirement with this id.

Needs a read-and-write token. A read-only token gets 403.

Version-locked: send the ETag from your last read as If-Match.

Path parameters

iduuidrequired
The resource id (a UUID).

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
If-Matchstringrequired
The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"

Returns the same attributes as Get a requirement.

Responses

  • 200Success.
13 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.STALE_OBJECT
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 428This resource is version-locked: send its ETag in an If-Match header.MISSING_IF_MATCH
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
  -X DELETE \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json" \
  -H 'If-Match: W/"3"'
Response

application/vnd.api+json

{
  "data": {
    "type": "requirements",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Expired cards are refused at checkout",
      "requirementKey": "KAN-REQ-7",
      "status": "DRAFT",
      "complexity": "HIGH",
      "impact": "HIGH",
      "updatedAt": "2026-10-05T09:30:00Z"
    },
    "links": {
      "self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Restore a requirement

POST/api/v1/requirements/{id}/actions/restore

Restores the soft-deleted requirement with this id and returns it.

Needs a read-and-write token. A read-only token gets 403.

Version-locked: send the ETag from your last read as If-Match.

Path parameters

iduuidrequired
The resource id (a UUID).

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
If-Matchstringrequired
The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"

Returns the same attributes as Get a requirement.

Responses

  • 200Success.
13 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.STALE_OBJECT
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 428This resource is version-locked: send its ETag in an If-Match header.MISSING_IF_MATCH
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33/actions/restore" \
  -X POST \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json" \
  -H 'If-Match: W/"3"'
Response

application/vnd.api+json

{
  "data": {
    "type": "requirements",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Expired cards are refused at checkout",
      "requirementKey": "KAN-REQ-7",
      "status": "DRAFT",
      "complexity": "HIGH",
      "impact": "HIGH",
      "updatedAt": "2026-10-05T09:30:00Z"
    },
    "links": {
      "self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

List requirement folders

GET/api/v1/requirement_folders

Lists requirement folder resources as a JSON:API collection document. Narrow the set with filter, order it with sort, embed related resources with include, select attributes with fields[<type>], and page with page[size] plus page[number] (offset) or page[after] (cursor, taken from the previous response's links.next).

Query parameters

filterstring
A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
name = "example"
sortstring
Comma-separated sort fields; prefix a field with "-" for descending order (e.g. "-createdAt,title"). Permitted fields: id, organizationId, projectId, name, parentFolderId, rank.
-name
includestring
Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, organization, requirementFolder, project, updatedByUser.
createdByUser
fields[requirement_folders]string[]
Sparse fieldset for resource type "requirement_folders" - comma-separated subset of its exposed fields: id, organizationId, projectId, name, description, parentFolderId, rank, createdAt, updatedAt, createdBy, updatedBy, createdByUser, updatedByUser, organization, requirementFolder, project.
name,description,rank
page[size]integer
Number of resources per page (applies to both offset and cursor pagination). Minimum 1, maximum 100, default 25 when omitted.
25
page[number]integer
1-indexed page number for offset-based pagination. Mutually exclusive with "page[after]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
2
page[after]string
Opaque cursor for cursor-based pagination - always taken verbatim from a previous response's "links.next" value, never client-constructed or decoded. Mutually exclusive with "page[number]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json

Filterable fields11

Show fields and operators
FieldTypeOperators
iduuid= != in (…) not in (…) is null is not null
organizationIduuid= != in (…) not in (…) is null is not null
projectIduuid= != in (…) not in (…) is null is not null
namestring= != in (…) not in (…) is null is not null
descriptionstring~ is null is not null is empty is not empty
parentFolderIduuid= != in (…) not in (…) is null is not null
rankint= != < <= > >= in (…) not in (…) is null is not null
createdAtdatetime= != < <= > >= is null is not null
updatedAtdatetime= != < <= > >= is null is not null
createdByuuid= != in (…) not in (…) is null is not null
updatedByuuid= != in (…) not in (…) is null is not null

Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, organization, requirementFolder, requirementFolders, project, updatedByUser, requirements.

Returns the same attributes as Get a requirement folder.

Responses

  • 200Success.
11 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INVALID_TYPED_JSON_FILTERUNKNOWN_SORT_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDUNKNOWN_TYPEUNKNOWN_FIELDCONFLICTING_PAGINATIONINVALID_PAGE_SIZEPAGE_SIZE_EXCEEDEDINVALID_PAGE_NUMBERINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirement_folders?page%5Bsize%5D=25" \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json"
Response

application/vnd.api+json

{
  "data": [
    {
      "type": "requirement_folders",
      "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
      "attributes": {
        "name": "Checkout",
        "updatedAt": "2026-10-05T09:30:00Z"
      },
      "links": {
        "self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
      }
    }
  ],
  "links": {
    "self": "/requirement_folders?page[size]=25",
    "first": "/requirement_folders?page[size]=25&page[number]=1",
    "prev": null,
    "next": "/requirement_folders?page[size]=25&page[number]=2",
    "last": "/requirement_folders?page[size]=25&page[number]=6"
  },
  "meta": {
    "totalCount": 128
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Create a requirement folder

POST/api/v1/requirement_folders

Creates a requirement folder from a JSON:API resource object - data.type names the resource type and data.attributes carries the writable attributes - and returns the created resource.

Needs a read-and-write token. A read-only token gets 403.

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Content-Typestringrequired
Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+json

Attributes you can send5

namestringrequired
projectIduuidrequired
rankintegerrequired
descriptionstring | null
parentFolderIduuid | null

Returns the same attributes as Get a requirement folder.

Responses

  • 201Created.
11 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 415The Content-Type was not application/vnd.api+json.MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.INVALID_INPUTVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirement_folders" \
  -X POST \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json" \
  -H "Content-Type: application/vnd.api+json" \
  -d '{
  "data": {
    "type": "requirement_folders",
    "attributes": {
      "name": "Checkout",
      "projectId": "03ff802c-4fcb-4718-8eb8-12ecc999f758",
      "rank": 1
    }
  }
}'
Response

application/vnd.api+json

{
  "data": [
    {
      "type": "requirement_folders",
      "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
      "attributes": {
        "name": "Checkout",
        "updatedAt": "2026-10-05T09:30:00Z"
      },
      "links": {
        "self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
      }
    }
  ],
  "links": {
    "self": "/requirement_folders?page[size]=25",
    "first": "/requirement_folders?page[size]=25&page[number]=1",
    "prev": null,
    "next": "/requirement_folders?page[size]=25&page[number]=2",
    "last": "/requirement_folders?page[size]=25&page[number]=6"
  },
  "meta": {
    "totalCount": 128
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Count and aggregate requirement folders

GET/api/v1/requirement_folders/aggregate

Aggregates requirement folder resources - a count and per-column aggregations, optionally grouped - over the same filter the collection route accepts.

Query parameters

aggregations[count]boolean
Include the row count in the aggregate result. When no aggregation is requested at all, the runtime defaults to count.
aggregations[sum][]string[]
Column(s) to sum - repeat the bracketed key per column (aggregations[sum][]=a&aggregations[sum][]=b). Permitted columns: rank.
aggregations[avg][]string[]
Column(s) to average - repeat the bracketed key per column (aggregations[avg][]=a&aggregations[avg][]=b). Permitted columns: rank.
aggregations[min][]string[]
Column(s) to take the minimum of - repeat the bracketed key per column (aggregations[min][]=a&aggregations[min][]=b). Permitted columns: name, description, rank, createdAt, updatedAt.
aggregations[max][]string[]
Column(s) to take the maximum of - repeat the bracketed key per column (aggregations[max][]=a&aggregations[max][]=b). Permitted columns: name, description, rank, createdAt, updatedAt.
aggregations[groupBy][]string[]
Column(s) to group by - repeating the bracketed key switches the response to the grouped shape (aggregations[groupBy][]=a&aggregations[groupBy][]=b). Permitted columns: id, organizationId, projectId, name, parentFolderId, rank.
filterstring
A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
name = "example"

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json

Filterable fields11

Show fields and operators
FieldTypeOperators
iduuid= != in (…) not in (…) is null is not null
organizationIduuid= != in (…) not in (…) is null is not null
projectIduuid= != in (…) not in (…) is null is not null
namestring= != in (…) not in (…) is null is not null
descriptionstring~ is null is not null is empty is not empty
parentFolderIduuid= != in (…) not in (…) is null is not null
rankint= != < <= > >= in (…) not in (…) is null is not null
createdAtdatetime= != < <= > >= is null is not null
updatedAtdatetime= != < <= > >= is null is not null
createdByuuid= != in (…) not in (…) is null is not null
updatedByuuid= != in (…) not in (…) is null is not null

Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, organization, requirementFolder, requirementFolders, project, updatedByUser, requirements.

Responses

  • 200Success.
11 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirement_folders/aggregate?aggregations%5Bcount%5D=true" \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json"
Response

application/vnd.api+json

{
  "data": {
    "type": "requirementFolders_aggregate",
    "id": "(aggregate)",
    "attributes": {
      "count": 128
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Get a requirement folder

GET/api/v1/requirement_folders/{id}

Returns the requirement folder with this id as a JSON:API resource document; include embeds related resources and fields[<type>] selects the attributes returned.

Path parameters

iduuidrequired
The resource id (a UUID).

Query parameters

includestring
Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, organization, requirementFolder, project, updatedByUser.
createdByUser
fields[requirement_folders]string[]
Sparse fieldset for resource type "requirement_folders" - comma-separated subset of its exposed fields: id, organizationId, projectId, name, description, parentFolderId, rank, createdAt, updatedAt, createdBy, updatedBy, createdByUser, updatedByUser, organization, requirementFolder, project.
name,description,rank

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json

Attributes returned11

createdAtdate-timeread-only
createdByuuid | nullread-only
descriptionstring | null
iduuidread-only
namestring
organizationIduuidread-only
parentFolderIduuid | null
projectIduuid
Show the remaining 3
rankinteger
updatedAtdate-timeread-only
updatedByuuid | nullread-only

Responses

  • 200Success.
12 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.UNKNOWN_TYPEUNKNOWN_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 410Gone.GONE
  • 415The Content-Type was not application/vnd.api+json.PARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json"
Response

application/vnd.api+json

{
  "data": {
    "type": "requirement_folders",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Checkout",
      "updatedAt": "2026-10-05T09:30:00Z"
    },
    "links": {
      "self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Update a requirement folder

PATCH/api/v1/requirement_folders/{id}

Updates the requirement folder with this id from a JSON:API resource object carrying only the attributes to change, and returns the updated resource. A resource that carries an ETag requires it back as If-Match.

Needs a read-and-write token. A read-only token gets 403.

Version-locked: send the ETag from your last read as If-Match.

Path parameters

iduuidrequired
The resource id (a UUID).

Headers

Authorizationstringrequired
Your API token as a bearer credential.
Bearer $BESTEST_TOKEN
Acceptstring
Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Content-Typestringrequired
Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+json
If-Matchstringrequired
The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"

Attributes you can send5

descriptionstring | null
namestring
parentFolderIduuid | null
projectIduuid
rankinteger

Returns the same attributes as Get a requirement folder.

Responses

  • 200Success.
13 error responses
  • 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT
  • 401The token has expired or could not be authenticated.TOKEN_EXPIREDUNAUTHENTICATED
  • 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.FORBIDDEN
  • 404No such resource, or it is outside the Space your token reaches.NOT_FOUND
  • 406The Accept header asked for something other than application/vnd.api+json.NOT_ACCEPTABLE
  • 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT
  • 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.STALE_OBJECT
  • 415The Content-Type was not application/vnd.api+json.MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT
  • 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.VALIDATION_ERRORVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT
  • 428This resource is version-locked: send its ETag in an If-Match header.MISSING_IF_MATCH
  • 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.RATE_LIMITEDQUOTA_EXCEEDED
  • 500Server error. Safe to retry a read; check before retrying a write.INTERNAL_ERROR
  • 503Temporarily unavailable. Retry with backoff.UNAVAILABLE
Request

curl

curl "https://prod-eu.getbestest.com/api/v1/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
  -X PATCH \
  -H "Authorization: Bearer $BESTEST_TOKEN" \
  -H "Accept: application/vnd.api+json" \
  -H 'If-Match: W/"3"' \
  -H "Content-Type: application/vnd.api+json" \
  -d '{
  "data": {
    "type": "requirement_folders",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Checkout"
    }
  }
}'
Response

application/vnd.api+json

{
  "data": {
    "type": "requirement_folders",
    "id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
    "attributes": {
      "name": "Checkout",
      "updatedAt": "2026-10-05T09:30:00Z"
    },
    "links": {
      "self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
    }
  },
  "jsonapi": {
    "version": "1.1"
  }
}
Show an error response
Error

every 4xx and 5xx has this shape

{
  "errors": [
    {
      "status": "400",
      "title": "Bad Request",
      "code": "UNKNOWN_FIELD",
      "detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
      "source": {
        "parameter": "fields[users]"
      }
    }
  ]
}

Related-resource endpoints

Each to-many relation has its own URL, such as a test case's steps or a cycle's executions. They return a paginated collection of the related resource and take that resource's own filter, sort, paging and fields parameters, so they are listed rather than documented one by one. For to-one relations, use ?include= on the parent request instead: one round trip instead of two.

Show all 4
  • GET/api/v1/requirements/{id}/testCaseExecutions
  • GET/api/v1/requirements/{id}/testCollectionRequirements
  • GET/api/v1/requirement_folders/{id}/requirementFolders
  • GET/api/v1/requirement_folders/{id}/requirements