Get an API key
1
Open the cubic API integration
2
Generate a personal key
In the Members API card, click Generate API key. Keys start with
cbk_, and cubic only shows the full value once.3
Store it securely
Save the key in your secret manager or local environment.
This is the same personal key that the cubic MCP server and the cubic CLI use, and regenerating it replaces the key for all three. The key acts with your own cubic access. You only see organizations you can already view in cubic, and changes need an organization admin. See Roles and permissions.
Endpoints
The base URL is
https://www.cubic.dev. {org} is the GitHub organization login, such as acme. Each organization in the list includes githubAccountId, GitHub’s numeric account ID, and flags such as canManageSeats that show what your access allows.
The OpenAPI document describes every endpoint, parameter, and response. You can generate a client from it.
Authentication
Send the key in theAuthorization header as a bearer token.
Example requests
Members
A seat is a paid license for cubic reviews. Turning a seat off does not remove the person’s access to cubic. To remove someone, remove them from the GitHub organization. cubic removes their access when GitHub notifies it. See Roles and permissions for what each role can do.
The member list holds the people cubic tracks for the organization, including members with access to a repository cubic reviews and pull request authors. On paid plans, cubic refreshes it from GitHub every day.
Filter the member list
The list also takes
cursor and limit, described in Pagination. An unknown parameter returns 400 invalid_request, so a mistyped filter never lists everyone.
Update a member
Send the fields you want to change, each with the value from your latest read.
If the member changed since your read, the request fails with
409 member_state_changed and changes nothing. Read the member again, then retry. A request that asks for the member’s current state succeeds with "changed": false, so retrying a completed request is safe.
The response holds the member’s before and after state, changed, and availableSeats, the number of paid seats still free after the change.
Updates need an organization admin and an active paid subscription. The API never buys seats. When every paid seat is in use, turning a seat on fails with
seat_capacity_exceeded. Add seats in subscription settings first.Pagination
List endpoints return one page and anextCursor. To get the next page, send nextCursor back as cursor. nextCursor is null on the last page. Set the page size with limit, from 1 to 100. The default is 20.
Rate limits
Each API key can make 1,000 requests per 15 minutes. Every response after authentication includes these headers.
When you run out, cubic answers
429 rate_limited with a Retry-After header in seconds. If cubic cannot check the limit, it answers 503 rate_limiter_unavailable with Retry-After: 30 and no X-RateLimit-* headers. In both cases, wait for Retry-After before you retry.
Errors
Every error uses the same envelope.code, because messages can change. retriable says whether the same request can succeed if you send it again. Some errors include a correlationId. Quote it when you contact support. Validation errors include details, a list of path and message pairs for the fields that failed.