Documentation menu

Nimbus API Developer documentation

A clear path from API overview to first request.

Find the essentials to authenticate, explore predictable endpoints, and build with confidence—without slowing down to search.

  • Reliable auth
  • Predictable endpoints
  • Quick answers

Request flow

A predictable path to data

REST · v1
GET /v1/projects 200 · application/json
Authorization: Bearer your_api_token

One clear sequence: authenticate, call an endpoint, handle the response.

01 Platform model

A clear path from request to cloud resource.

Nimbus gives your application one consistent API surface for working with cloud resources. Send authenticated HTTPS requests, use predictable endpoints, and handle structured JSON responses.

  • Manage cloud resources through a consistent set of operations.
  • Connect each request to your account with token-based authentication.
  • Build integrations around resource-oriented endpoints and JSON payloads.
  • Respond to failures using a consistent, machine-readable error format.

The pieces you’ll work with

A quick map of the documentation.

01 Resources

Cloud objects

The resources your integration reads and manages.

02 Access

Authentication

Credentials and request headers that establish access.

03 Operations

Endpoints

Routes and methods for each supported operation.

04 Results

Responses

Payloads and errors your client can handle consistently.

Authentication 01

Authenticate your requests

Nimbus uses project-scoped API keys sent as bearer tokens over HTTPS. Create a key, keep it server-side, and rotate it before it expires.

Request flow

  1. Credentials

    Create a scoped API key

    Generate a key in the Nimbus Console for the correct project. Grant only the scopes your integration needs, then store the key in a server-side secret manager.

    NIMBUS_API_KEY=••••••••
  2. Authorization header

    Send the token with each request

    Include the key in the standard bearer authorization header. Never place it in a URL or expose it in browser-side code.

    Authorization: Bearer $NIMBUS_API_KEY
  3. Request validation

    Validate requests and responses

    Use HTTPS for every call. Check the HTTP status and response body, and retain the request ID to help trace failures during debugging.

  4. Expiry and rotation

    Rotate keys without interruption

    On an expired or revoked key, replace the credential and retry deliberately. Deploy a replacement key, verify traffic, then revoke the old one; avoid indefinite retries on authorization errors.

Explore Endpoints

API reference / 01

Explore the endpoints

Start with a resource group, then follow its core operations to the details you need.

GROUP 01

Projects

Create and manage the projects that organize your cloud resources.

Key operations

  • GET /v1/projects
  • POST /v1/projects
  • GET /v1/projects/{project_id}

Implementation note: Scope resource requests to a project and retain its stable ID.

GROUP 02

Deployments

Launch, inspect, and cancel application deployments.

Key operations

  • POST /v1/deployments
  • GET /v1/deployments/{deployment_id}
  • POST /v1/deployments/{deployment_id}/cancel

Implementation note: Deployment creation is asynchronous; poll its resource for status.

GROUP 03

Environments

Configure the runtime environments attached to a project.

Key operations

  • GET /v1/projects/{project_id}/environments
  • POST /v1/environments
  • PATCH /v1/environments/{environment_id}

Implementation note: Use the environment ID when targeting runtime configuration.

GROUP 04

Secrets

Store and rotate sensitive values for your environments.

Key operations

  • GET /v1/environments/{environment_id}/secrets
  • PUT /v1/secrets/{secret_id}
  • DELETE /v1/secrets/{secret_id}

Implementation note: Treat secret values as write-only; replace the value to rotate it.

GROUP 05

Usage & events

Inspect platform usage and retrieve event records for a project.

Key operations

  • GET /v1/usage
  • GET /v1/events
  • GET /v1/events/{event_id}

Implementation note: Follow the response cursor when paging through event results.

Need a quick answer? Review the FAQ

Help / FAQ

Clear the last few blockers.

Quick answers for getting an integration ready to ship.

06 answers
How do I authenticate my first request?
Send your API key as a bearer token in the Authorization header. Keep secret keys on your server, never in client-side code.
What should I do when I hit a rate limit?
A rate-limited request returns 429. Respect Retry-After when present, and retry with exponential backoff.
How are API versions managed?
Use the version configured for your integration and check the versioning guide before upgrading. Review migration notes before adopting a newer version.
Should I use separate test and live environments?
Yes. Test with test credentials first, then use live credentials for production. Keep the two sets separate and never expose either secret in a public client.
How should my integration handle errors?
Check the HTTP status and error code, and log the request ID for diagnosis. Retry transient server errors with backoff; fix authentication or validation errors before retrying.
When should I contact support?
Start with the relevant guide and error response. If the issue persists, contact support with the request ID and a minimal reproduction—never include API secrets.