BizKitHub
DocsAPI ReferenceIssue/bff/issue/support-reply
postIssueAdmin BFF

/bff/issue/support-reply

Admin-facing counterpart of POST /api/v1/support/issue/:externalId/comment. Delegates to the shared processSupportTicketReply primitive so both surfaces produce the same on-disk state (channel: "email_in", authorKind: "human", skipReporterEcho: true, auto-reopen if closed). Difference from the public path: trustPolicy: "trust" — the LLM spam classifier is skipped because the caller is authenticated via cookie. Confidentiality gate (assertIssueAccessibleForIdentity) applies — non-root operators cannot reply on a secured ticket they cannot see.

IssuepostBffIssueSupport-reply

Parameters

JSON body

Request body

application/json
issueKeystringRequired

Issue key of the support ticket to reply on.

ExampleBIZKIT-22
messagestringRequired

Reply text. Server-side rules: leading/trailing whitespace trimmed, silently truncated at 5000 chars, rejected as MESSAGE_TOO_SHORT if fewer than 3 non-whitespace chars remain. A per-issue 24h volume ceiling applies; the LLM spam classifier is SKIPPED because the caller is cookie-authenticated.

Length: 1–10000
ExampleThanks — I confirmed the issue on our staging env too. Attaching a screenshot.

Response schema

1 status code documented

200Success
object | object
One of 2:
Variant 1
success"true"Required
Variant 2
success"false"Required
error"MESSAGE_TOO_SHORT" | "RATE_LIMITED" | "UPSTREAM_ERROR" | "NO_AUTHOR"Required
messagestringOptional

Human-readable explanation. Present on RATE_LIMITED and UPSTREAM_ERROR — surface verbatim in the admin UI.

Response example

application/json
{
  "success": true
}

Request example

POST /bff/issue/support-reply

post
curl -X POST "https://api.bizkithub.com/bff/issue/support-reply" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{
  "issueKey": "BIZKIT-22",
  "message": "Thanks — I confirmed the issue on our staging env too. Attaching a screenshot."
}'

Need an API key?

All BizKitHub public API endpoints require authentication via API key.

Get API Key