Requirements
Requirements are the anchor of the coverage model. Each one carries a significance derived from development complexity and business impact, and coverage is judged against that significance rather than against a bare "has at least one linked test case" check. Requirements are soft-deleted: a deleted one can be listed with withDeleted=true and brought back with the restore action.
List requirements
/api/v1/requirementsLists requirement resources as a JSON:API collection document. Narrow the set with filter, order it with sort, embed related resources with include, select attributes with fields[<type>], and page with page[size] plus page[number] (offset) or page[after] (cursor, taken from the previous response's links.next).
Query parameters
filterstring- A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
requirementKey = "A-REQ-1"sortstring- Comma-separated sort fields; prefix a field with "-" for descending order (e.g. "-createdAt,title"). Permitted fields: id, organizationId, projectId, requirementKey, status, name, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, ownerId, deletedAt, requirementKeyNumeric, significance.
-requirementKeyincludestring- Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser.
createdByUserfields[requirements]string[]- Sparse fieldset for resource type "requirements" - comma-separated subset of its exposed fields: id, organizationId, projectId, requirementKey, status, name, reference, description, version, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, createdBy, updatedBy, ownerId, deletedAt, requirementKeyNumeric, coveredOverride, significance, createdByUser, ownerUser, updatedByUser, requirementFolder, organization, project, customFields.
requirementKey,status,namepage[size]integer- Number of resources per page (applies to both offset and cursor pagination). Minimum 1, maximum 100, default 25 when omitted.
25page[number]integer- 1-indexed page number for offset-based pagination. Mutually exclusive with "page[after]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
2page[after]string- Opaque cursor for cursor-based pagination - always taken verbatim from a previous response's "links.next" value, never client-constructed or decoded. Mutually exclusive with "page[number]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
withDeletedboolean- Include soft-deleted rows in the collection. Only present on soft-delete-enabled entities. Default false (soft-deleted rows excluded) when omitted.
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Filterable fields23
Show fields and operators
| Field | Type | Operators |
|---|---|---|
id | uuid | = != in (…) not in (…) is null is not null |
organizationId | uuid | = != in (…) not in (…) is null is not null |
projectId | uuid | = != in (…) not in (…) is null is not null |
requirementKey | string | = != in (…) not in (…) ~ is null is not null |
status | enum | = != in (…) not in (…) is null is not nullDRAFT, READY, COVERED, ARCHIVED, IN_REVIEW, CHANGES_REQUESTED, APPROVED |
name | string | ~ is null is not null is empty is not empty |
reference | string | = != in (…) not in (…) ~ is null is not null |
description | string | ~ is null is not null is empty is not empty |
version | int | = != < <= > >= in (…) not in (…) is null is not null |
rank | int | = != < <= > >= in (…) not in (…) is null is not null |
requirementType | string | = != in (…) not in (…) is null is not null |
complexity | enum | = != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH |
impact | enum | = != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH |
folderId | uuid | = != in (…) not in (…) is null is not null |
createdAt | datetime | = != < <= > >= is null is not null |
updatedAt | datetime | = != < <= > >= is null is not null |
createdBy | uuid | = != in (…) not in (…) is null is not null |
updatedBy | uuid | = != in (…) not in (…) is null is not null |
ownerId | uuid | = != in (…) not in (…) is null is not null |
deletedAt | datetime | = != < <= > >= is null is not null |
requirementKeyNumeric | int | = != < <= > >= in (…) not in (…) is null is not null |
coveredOverride | bool | = != is null is not null |
significance | enum | = != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH, CRITICAL |
Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser, testCaseExecutions, testCollectionRequirements.
Returns the same attributes as Get a requirement.
Responses
- 200Success.
11 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INVALID_TYPED_JSON_FILTERUNKNOWN_SORT_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDUNKNOWN_TYPEUNKNOWN_FIELDCONFLICTING_PAGINATIONINVALID_PAGE_SIZEPAGE_SIZE_EXCEEDEDINVALID_PAGE_NUMBERINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements?page%5Bsize%5D=25" \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json"application/vnd.api+json
{
"data": [
{
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Expired cards are refused at checkout",
"requirementKey": "KAN-REQ-7",
"status": "DRAFT",
"complexity": "HIGH",
"impact": "HIGH",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
}
],
"links": {
"self": "/requirements?page[size]=25",
"first": "/requirements?page[size]=25&page[number]=1",
"prev": null,
"next": "/requirements?page[size]=25&page[number]=2",
"last": "/requirements?page[size]=25&page[number]=6"
},
"meta": {
"totalCount": 128
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Create a requirement
/api/v1/requirementsCreates a requirement from a JSON:API resource object - data.type names the resource type and data.attributes carries the writable attributes - and returns the created resource.
Needs a read-and-write token. A read-only token gets 403.
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+jsonContent-Typestringrequired- Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+json
Attributes you can send13
namestringrequiredprojectIduuidrequiredrankintegerrequiredcomplexitystring | nullLOWMEDIUMHIGHcoveredOverridebooleandefaultfalsecustomFieldsobjectdescriptionstring | nullmax 50000 charsfolderIduuid | null
Show the remaining 5
impactstring | nullLOWMEDIUMHIGHownerIduuid | nullreferencestring | nullrequirementTypestring | nullFunctionalNon-FunctionalBusinessTechnicalUser InterfacenullstatusstringdefaultDRAFTDRAFTREADYCOVEREDARCHIVEDIN_REVIEWCHANGES_REQUESTEDAPPROVED
Returns the same attributes as Get a requirement.
Responses
- 201Created.
11 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 415The Content-Type was not application/vnd.api+json.
MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
INVALID_INPUTVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements" \
-X POST \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json" \
-H "Content-Type: application/vnd.api+json" \
-d '{
"data": {
"type": "requirements",
"attributes": {
"name": "Expired cards are refused at checkout",
"projectId": "03ff802c-4fcb-4718-8eb8-12ecc999f758",
"rank": 1,
"status": "DRAFT"
}
}
}'application/vnd.api+json
{
"data": [
{
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Expired cards are refused at checkout",
"requirementKey": "KAN-REQ-7",
"status": "DRAFT",
"complexity": "HIGH",
"impact": "HIGH",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
}
],
"links": {
"self": "/requirements?page[size]=25",
"first": "/requirements?page[size]=25&page[number]=1",
"prev": null,
"next": "/requirements?page[size]=25&page[number]=2",
"last": "/requirements?page[size]=25&page[number]=6"
},
"meta": {
"totalCount": 128
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Count and aggregate requirements
/api/v1/requirements/aggregateAggregates requirement resources - a count and per-column aggregations, optionally grouped - over the same filter the collection route accepts.
Query parameters
aggregations[count]boolean- Include the row count in the aggregate result. When no aggregation is requested at all, the runtime defaults to count.
aggregations[sum][]string[]- Column(s) to sum - repeat the bracketed key per column (aggregations[sum][]=a&aggregations[sum][]=b). Permitted columns: version, rank, requirementKeyNumeric.
aggregations[avg][]string[]- Column(s) to average - repeat the bracketed key per column (aggregations[avg][]=a&aggregations[avg][]=b). Permitted columns: version, rank, requirementKeyNumeric.
aggregations[min][]string[]- Column(s) to take the minimum of - repeat the bracketed key per column (aggregations[min][]=a&aggregations[min][]=b). Permitted columns: requirementKey, name, reference, description, version, rank, requirementType, createdAt, updatedAt, deletedAt, requirementKeyNumeric.
aggregations[max][]string[]- Column(s) to take the maximum of - repeat the bracketed key per column (aggregations[max][]=a&aggregations[max][]=b). Permitted columns: requirementKey, name, reference, description, version, rank, requirementType, createdAt, updatedAt, deletedAt, requirementKeyNumeric.
aggregations[groupBy][]string[]- Column(s) to group by - repeating the bracketed key switches the response to the grouped shape (aggregations[groupBy][]=a&aggregations[groupBy][]=b). Permitted columns: id, organizationId, projectId, requirementKey, status, name, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, ownerId, deletedAt, requirementKeyNumeric, significance.
filterstring- A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
requirementKey = "A-REQ-1"
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Filterable fields23
Show fields and operators
| Field | Type | Operators |
|---|---|---|
id | uuid | = != in (…) not in (…) is null is not null |
organizationId | uuid | = != in (…) not in (…) is null is not null |
projectId | uuid | = != in (…) not in (…) is null is not null |
requirementKey | string | = != in (…) not in (…) ~ is null is not null |
status | enum | = != in (…) not in (…) is null is not nullDRAFT, READY, COVERED, ARCHIVED, IN_REVIEW, CHANGES_REQUESTED, APPROVED |
name | string | ~ is null is not null is empty is not empty |
reference | string | = != in (…) not in (…) ~ is null is not null |
description | string | ~ is null is not null is empty is not empty |
version | int | = != < <= > >= in (…) not in (…) is null is not null |
rank | int | = != < <= > >= in (…) not in (…) is null is not null |
requirementType | string | = != in (…) not in (…) is null is not null |
complexity | enum | = != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH |
impact | enum | = != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH |
folderId | uuid | = != in (…) not in (…) is null is not null |
createdAt | datetime | = != < <= > >= is null is not null |
updatedAt | datetime | = != < <= > >= is null is not null |
createdBy | uuid | = != in (…) not in (…) is null is not null |
updatedBy | uuid | = != in (…) not in (…) is null is not null |
ownerId | uuid | = != in (…) not in (…) is null is not null |
deletedAt | datetime | = != < <= > >= is null is not null |
requirementKeyNumeric | int | = != < <= > >= in (…) not in (…) is null is not null |
coveredOverride | bool | = != is null is not null |
significance | enum | = != < <= > >= in (…) not in (…) is null is not nullLOW, MEDIUM, HIGH, CRITICAL |
Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser, testCaseExecutions, testCollectionRequirements.
Responses
- 200Success.
11 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements/aggregate?aggregations%5Bcount%5D=true" \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json"application/vnd.api+json
{
"data": {
"type": "requirements_aggregate",
"id": "(aggregate)",
"attributes": {
"count": 128
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Get a requirement
/api/v1/requirements/{id}Returns the requirement with this id as a JSON:API resource document; include embeds related resources and fields[<type>] selects the attributes returned.
Path parameters
iduuidrequired- The resource id (a UUID).
Query parameters
includestring- Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, requirementFolder, organization, ownerUser, project, updatedByUser.
createdByUserfields[requirements]string[]- Sparse fieldset for resource type "requirements" - comma-separated subset of its exposed fields: id, organizationId, projectId, requirementKey, status, name, reference, description, version, rank, requirementType, complexity, impact, folderId, createdAt, updatedAt, createdBy, updatedBy, ownerId, deletedAt, requirementKeyNumeric, coveredOverride, significance, createdByUser, ownerUser, updatedByUser, requirementFolder, organization, project, customFields.
requirementKey,status,name
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Attributes returned24
complexitystring | nullLOWMEDIUMHIGHcoveredOverridebooleandefaultfalsecreatedAtdate-timeread-onlycreatedByuuid | nullread-onlycustomFieldsobjectdeletedAtdate-time | nullread-onlydescriptionstring | nullmax 50000 charsfolderIduuid | null
Show the remaining 16
iduuidread-onlyimpactstring | nullLOWMEDIUMHIGHnamestringorganizationIduuidread-onlyownerIduuid | nullprojectIduuidrankintegerreferencestring | nullrequirementKeystringread-onlyrequirementKeyNumericinteger | nullread-onlyrequirementTypestring | nullFunctionalNon-FunctionalBusinessTechnicalUser Interfacenullsignificancestring | nullread-onlyLOWMEDIUMHIGHCRITICALstatusstringdefaultDRAFTDRAFTREADYCOVEREDARCHIVEDIN_REVIEWCHANGES_REQUESTEDAPPROVEDupdatedAtdate-timeread-onlyupdatedByuuid | nullread-onlyversionintegerread-onlydefault1
Responses
- 200Success.
12 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
UNKNOWN_TYPEUNKNOWN_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 410Gone.
GONE - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json"application/vnd.api+json
{
"data": {
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Expired cards are refused at checkout",
"requirementKey": "KAN-REQ-7",
"status": "DRAFT",
"complexity": "HIGH",
"impact": "HIGH",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Update a requirement
/api/v1/requirements/{id}Updates the requirement with this id from a JSON:API resource object carrying only the attributes to change, and returns the updated resource. A resource that carries an ETag requires it back as If-Match.
Needs a read-and-write token. A read-only token gets 403.
Version-locked: send the ETag from your last read as If-Match.
Path parameters
iduuidrequired- The resource id (a UUID).
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+jsonContent-Typestringrequired- Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+jsonIf-Matchstringrequired- The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"
Attributes you can send13
complexitystring | nullLOWMEDIUMHIGHcoveredOverridebooleandefaultfalsecustomFieldsobjectdescriptionstring | nullmax 50000 charsfolderIduuid | nullimpactstring | nullLOWMEDIUMHIGHnamestringownerIduuid | null
Show the remaining 5
projectIduuidrankintegerreferencestring | nullrequirementTypestring | nullFunctionalNon-FunctionalBusinessTechnicalUser InterfacenullstatusstringdefaultDRAFTDRAFTREADYCOVEREDARCHIVEDIN_REVIEWCHANGES_REQUESTEDAPPROVED
Returns the same attributes as Get a requirement.
Responses
- 200Success.
13 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.
STALE_OBJECT - 415The Content-Type was not application/vnd.api+json.
MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_ERRORVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 428This resource is version-locked: send its ETag in an If-Match header.
MISSING_IF_MATCH - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
-X PATCH \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json" \
-H 'If-Match: W/"3"' \
-H "Content-Type: application/vnd.api+json" \
-d '{
"data": {
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"status": "DRAFT"
}
}
}'application/vnd.api+json
{
"data": {
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Expired cards are refused at checkout",
"requirementKey": "KAN-REQ-7",
"status": "DRAFT",
"complexity": "HIGH",
"impact": "HIGH",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Delete a requirement
/api/v1/requirements/{id}Deletes the requirement with this id.
Needs a read-and-write token. A read-only token gets 403.
Version-locked: send the ETag from your last read as If-Match.
Path parameters
iduuidrequired- The resource id (a UUID).
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+jsonIf-Matchstringrequired- The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"
Returns the same attributes as Get a requirement.
Responses
- 200Success.
13 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.
STALE_OBJECT - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 428This resource is version-locked: send its ETag in an If-Match header.
MISSING_IF_MATCH - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
-X DELETE \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json" \
-H 'If-Match: W/"3"'application/vnd.api+json
{
"data": {
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Expired cards are refused at checkout",
"requirementKey": "KAN-REQ-7",
"status": "DRAFT",
"complexity": "HIGH",
"impact": "HIGH",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Restore a requirement
/api/v1/requirements/{id}/actions/restoreRestores the soft-deleted requirement with this id and returns it.
Needs a read-and-write token. A read-only token gets 403.
Version-locked: send the ETag from your last read as If-Match.
Path parameters
iduuidrequired- The resource id (a UUID).
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+jsonIf-Matchstringrequired- The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"
Returns the same attributes as Get a requirement.
Responses
- 200Success.
13 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.
STALE_OBJECT - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 428This resource is version-locked: send its ETag in an If-Match header.
MISSING_IF_MATCH - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33/actions/restore" \
-X POST \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json" \
-H 'If-Match: W/"3"'application/vnd.api+json
{
"data": {
"type": "requirements",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Expired cards are refused at checkout",
"requirementKey": "KAN-REQ-7",
"status": "DRAFT",
"complexity": "HIGH",
"impact": "HIGH",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirements/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}List requirement folders
/api/v1/requirement_foldersLists requirement folder resources as a JSON:API collection document. Narrow the set with filter, order it with sort, embed related resources with include, select attributes with fields[<type>], and page with page[size] plus page[number] (offset) or page[after] (cursor, taken from the previous response's links.next).
Query parameters
filterstring- A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
name = "example"sortstring- Comma-separated sort fields; prefix a field with "-" for descending order (e.g. "-createdAt,title"). Permitted fields: id, organizationId, projectId, name, parentFolderId, rank.
-nameincludestring- Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, organization, requirementFolder, project, updatedByUser.
createdByUserfields[requirement_folders]string[]- Sparse fieldset for resource type "requirement_folders" - comma-separated subset of its exposed fields: id, organizationId, projectId, name, description, parentFolderId, rank, createdAt, updatedAt, createdBy, updatedBy, createdByUser, updatedByUser, organization, requirementFolder, project.
name,description,rankpage[size]integer- Number of resources per page (applies to both offset and cursor pagination). Minimum 1, maximum 100, default 25 when omitted.
25page[number]integer- 1-indexed page number for offset-based pagination. Mutually exclusive with "page[after]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
2page[after]string- Opaque cursor for cursor-based pagination - always taken verbatim from a previous response's "links.next" value, never client-constructed or decoded. Mutually exclusive with "page[number]" - supplying both is rejected with a 400 (CONFLICTING_PAGINATION).
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Filterable fields11
Show fields and operators
| Field | Type | Operators |
|---|---|---|
id | uuid | = != in (…) not in (…) is null is not null |
organizationId | uuid | = != in (…) not in (…) is null is not null |
projectId | uuid | = != in (…) not in (…) is null is not null |
name | string | = != in (…) not in (…) is null is not null |
description | string | ~ is null is not null is empty is not empty |
parentFolderId | uuid | = != in (…) not in (…) is null is not null |
rank | int | = != < <= > >= in (…) not in (…) is null is not null |
createdAt | datetime | = != < <= > >= is null is not null |
updatedAt | datetime | = != < <= > >= is null is not null |
createdBy | uuid | = != in (…) not in (…) is null is not null |
updatedBy | uuid | = != in (…) not in (…) is null is not null |
Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, organization, requirementFolder, requirementFolders, project, updatedByUser, requirements.
Returns the same attributes as Get a requirement folder.
Responses
- 200Success.
11 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INVALID_TYPED_JSON_FILTERUNKNOWN_SORT_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDUNKNOWN_TYPEUNKNOWN_FIELDCONFLICTING_PAGINATIONINVALID_PAGE_SIZEPAGE_SIZE_EXCEEDEDINVALID_PAGE_NUMBERINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirement_folders?page%5Bsize%5D=25" \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json"application/vnd.api+json
{
"data": [
{
"type": "requirement_folders",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Checkout",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
}
],
"links": {
"self": "/requirement_folders?page[size]=25",
"first": "/requirement_folders?page[size]=25&page[number]=1",
"prev": null,
"next": "/requirement_folders?page[size]=25&page[number]=2",
"last": "/requirement_folders?page[size]=25&page[number]=6"
},
"meta": {
"totalCount": 128
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Create a requirement folder
/api/v1/requirement_foldersCreates a requirement folder from a JSON:API resource object - data.type names the resource type and data.attributes carries the writable attributes - and returns the created resource.
Needs a read-and-write token. A read-only token gets 403.
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+jsonContent-Typestringrequired- Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+json
Attributes you can send5
namestringrequiredprojectIduuidrequiredrankintegerrequireddescriptionstring | nullparentFolderIduuid | null
Returns the same attributes as Get a requirement folder.
Responses
- 201Created.
11 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 415The Content-Type was not application/vnd.api+json.
MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
INVALID_INPUTVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirement_folders" \
-X POST \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json" \
-H "Content-Type: application/vnd.api+json" \
-d '{
"data": {
"type": "requirement_folders",
"attributes": {
"name": "Checkout",
"projectId": "03ff802c-4fcb-4718-8eb8-12ecc999f758",
"rank": 1
}
}
}'application/vnd.api+json
{
"data": [
{
"type": "requirement_folders",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Checkout",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
}
],
"links": {
"self": "/requirement_folders?page[size]=25",
"first": "/requirement_folders?page[size]=25&page[number]=1",
"prev": null,
"next": "/requirement_folders?page[size]=25&page[number]=2",
"last": "/requirement_folders?page[size]=25&page[number]=6"
},
"meta": {
"totalCount": 128
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Count and aggregate requirement folders
/api/v1/requirement_folders/aggregateAggregates requirement folder resources - a count and per-column aggregations, optionally grouped - over the same filter the collection route accepts.
Query parameters
aggregations[count]boolean- Include the row count in the aggregate result. When no aggregation is requested at all, the runtime defaults to count.
aggregations[sum][]string[]- Column(s) to sum - repeat the bracketed key per column (aggregations[sum][]=a&aggregations[sum][]=b). Permitted columns: rank.
aggregations[avg][]string[]- Column(s) to average - repeat the bracketed key per column (aggregations[avg][]=a&aggregations[avg][]=b). Permitted columns: rank.
aggregations[min][]string[]- Column(s) to take the minimum of - repeat the bracketed key per column (aggregations[min][]=a&aggregations[min][]=b). Permitted columns: name, description, rank, createdAt, updatedAt.
aggregations[max][]string[]- Column(s) to take the maximum of - repeat the bracketed key per column (aggregations[max][]=a&aggregations[max][]=b). Permitted columns: name, description, rank, createdAt, updatedAt.
aggregations[groupBy][]string[]- Column(s) to group by - repeating the bracketed key switches the response to the grouped shape (aggregations[groupBy][]=a&aggregations[groupBy][]=b). Permitted columns: id, organizationId, projectId, name, parentFolderId, rank.
filterstring- A FiltrQL expression, url-encoded. Combine conditions with AND / OR and parentheses. The fields you can filter on, and the operators each accepts, are listed under Filterable fields.
name = "example"
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Filterable fields11
Show fields and operators
| Field | Type | Operators |
|---|---|---|
id | uuid | = != in (…) not in (…) is null is not null |
organizationId | uuid | = != in (…) not in (…) is null is not null |
projectId | uuid | = != in (…) not in (…) is null is not null |
name | string | = != in (…) not in (…) is null is not null |
description | string | ~ is null is not null is empty is not empty |
parentFolderId | uuid | = != in (…) not in (…) is null is not null |
rank | int | = != < <= > >= in (…) not in (…) is null is not null |
createdAt | datetime | = != < <= > >= is null is not null |
updatedAt | datetime | = != < <= > >= is null is not null |
createdBy | uuid | = != in (…) not in (…) is null is not null |
updatedBy | uuid | = != in (…) not in (…) is null is not null |
Filter through a relation with ANY, ALL or NONE, for example createdByUser ANY (id = "…"). Relations: createdByUser, organization, requirementFolder, requirementFolders, project, updatedByUser, requirements.
Responses
- 200Success.
11 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirement_folders/aggregate?aggregations%5Bcount%5D=true" \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json"application/vnd.api+json
{
"data": {
"type": "requirementFolders_aggregate",
"id": "(aggregate)",
"attributes": {
"count": 128
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Get a requirement folder
/api/v1/requirement_folders/{id}Returns the requirement folder with this id as a JSON:API resource document; include embeds related resources and fields[<type>] selects the attributes returned.
Path parameters
iduuidrequired- The resource id (a UUID).
Query parameters
includestring- Comma-separated relation names to include; dot-notation for nested includes (up to 3 levels deep). Permitted top-level relations: createdByUser, organization, requirementFolder, project, updatedByUser.
createdByUserfields[requirement_folders]string[]- Sparse fieldset for resource type "requirement_folders" - comma-separated subset of its exposed fields: id, organizationId, projectId, name, description, parentFolderId, rank, createdAt, updatedAt, createdBy, updatedBy, createdByUser, updatedByUser, organization, requirementFolder, project.
name,description,rank
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+json
Attributes returned11
createdAtdate-timeread-onlycreatedByuuid | nullread-onlydescriptionstring | nulliduuidread-onlynamestringorganizationIduuidread-onlyparentFolderIduuid | nullprojectIduuid
Show the remaining 3
rankintegerupdatedAtdate-timeread-onlyupdatedByuuid | nullread-only
Responses
- 200Success.
12 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
UNKNOWN_TYPEUNKNOWN_FIELDINCLUDE_DEPTH_EXCEEDEDUNKNOWN_RELATIONINCLUDE_RESOURCES_EXCEEDEDINPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 410Gone.
GONE - 415The Content-Type was not application/vnd.api+json.
PARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json"application/vnd.api+json
{
"data": {
"type": "requirement_folders",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Checkout",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Update a requirement folder
/api/v1/requirement_folders/{id}Updates the requirement folder with this id from a JSON:API resource object carrying only the attributes to change, and returns the updated resource. A resource that carries an ETag requires it back as If-Match.
Needs a read-and-write token. A read-only token gets 403.
Version-locked: send the ETag from your last read as If-Match.
Path parameters
iduuidrequired- The resource id (a UUID).
Headers
Authorizationstringrequired- Your API token as a bearer credential.
Bearer $BESTEST_TOKENAcceptstring- Send application/vnd.api+json, or leave it out. Asking for application/json returns 406 Not Acceptable.
application/vnd.api+jsonContent-Typestringrequired- Must be application/vnd.api+json on any request with a body. Anything else returns 415 Unsupported Media Type.
application/vnd.api+jsonIf-Matchstringrequired- The ETag from your last read of this resource, sent back verbatim. Missing returns 428 Precondition Required; stale (someone changed it since you read it) returns 412 Precondition Failed. Read it again and retry.
W/"3"
Attributes you can send5
descriptionstring | nullnamestringparentFolderIduuid | nullprojectIduuidrankinteger
Returns the same attributes as Get a requirement folder.
Responses
- 200Success.
13 error responses
- 400The request is malformed: an unknown field, a filter that does not parse, or conflicting paging parameters.
INPUT_DEPTH_EXCEEDEDGRAPHQL_PARSE_FAILEDGRAPHQL_VALIDATION_FAILEDBAD_USER_INPUT - 401The token has expired or could not be authenticated.
TOKEN_EXPIREDUNAUTHENTICATED - 403The token is missing or not recognised, belongs to another region, or is read-only and this is a write.
FORBIDDEN - 404No such resource, or it is outside the Space your token reaches.
NOT_FOUND - 406The Accept header asked for something other than application/vnd.api+json.
NOT_ACCEPTABLE - 409The write conflicts with existing data, for example a duplicate or a reference to something that does not exist.
UNIQUE_VIOLATIONFOREIGN_KEY_VIOLATIONCONFLICT - 412The If-Match ETag is stale: the resource changed since you read it. Read it again and retry.
STALE_OBJECT - 415The Content-Type was not application/vnd.api+json.
MISSING_CONTENT_TYPEINVALID_CONTENT_TYPEINVALID_CONTENT_TYPE_PARAMSPARAMETERIZED_ACCEPT - 422The body is well-formed but a value is invalid, such as an enum outside its list or a missing required attribute.
VALIDATION_ERRORVALIDATION_FAILEDCHECK_VIOLATIONMISSING_REQUIREDATMOST_EXCEEDEDHOOK_ABORT - 428This resource is version-locked: send its ETag in an If-Match header.
MISSING_IF_MATCH - 429Rate limited (RATE_LIMITED). Limits are per person and shared with MCP. Back off a few seconds and retry.
RATE_LIMITEDQUOTA_EXCEEDED - 500Server error. Safe to retry a read; check before retrying a write.
INTERNAL_ERROR - 503Temporarily unavailable. Retry with backoff.
UNAVAILABLE
curl
curl "https://prod-eu.getbestest.com/api/v1/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33" \
-X PATCH \
-H "Authorization: Bearer $BESTEST_TOKEN" \
-H "Accept: application/vnd.api+json" \
-H 'If-Match: W/"3"' \
-H "Content-Type: application/vnd.api+json" \
-d '{
"data": {
"type": "requirement_folders",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Checkout"
}
}
}'application/vnd.api+json
{
"data": {
"type": "requirement_folders",
"id": "3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33",
"attributes": {
"name": "Checkout",
"updatedAt": "2026-10-05T09:30:00Z"
},
"links": {
"self": "/requirement_folders/3f2b9c14-8d5e-4a71-9f60-2c1e7b4a8d33"
}
},
"jsonapi": {
"version": "1.1"
}
}Show an error response
every 4xx and 5xx has this shape
{
"errors": [
{
"status": "400",
"title": "Bad Request",
"code": "UNKNOWN_FIELD",
"detail": "Unknown field \"displayName\" on resource type \"users\". Valid fields: id, externalId, role, ...",
"source": {
"parameter": "fields[users]"
}
}
]
}Related-resource endpoints
Each to-many relation has its own URL, such as a test case's steps or a cycle's executions. They return a paginated collection of the related resource and take that resource's own filter, sort, paging and fields parameters, so they are listed rather than documented one by one. For to-one relations, use ?include= on the parent request instead: one round trip instead of two.
Show all 4
- GET
/api/v1/requirements/{id}/testCaseExecutions - GET
/api/v1/requirements/{id}/testCollectionRequirements - GET
/api/v1/requirement_folders/{id}/requirementFolders - GET
/api/v1/requirement_folders/{id}/requirements
