POST /v1/pages/{page_id}/blocksAppend ONE block to the page DRAFT, preserving every existing block byte-for-byte. Optionally wire an uploaded file (public_path from List files) into IMAGE/FILE/CAROUSEL/PRODUCT blocks. Requires expected_updated_at.
Requires scope: pages:write. Plan entitlement: public_api (Creator and Pro).
Consequential operation — send an Idempotency-Key header.
curl "https://app.getbioflow.com/v1/pages/PAGE_ID/blocks" \
-X POST \
-H "Authorization: Bearer bf_live_YOUR_KEY" \
-H "Idempotency-Key: a-unique-id-per-attempt" \
-H "Content-Type: application/json" \
-d '{
"expected_updated_at": "string",
"kind": "string",
"data": {},
"file_url": "string",
"file_name": "string"
}'| Name | In | Type | Required | Description |
|---|---|---|---|---|
page_id | path | string | yes | Page ID from List pages |
| Field | Type | Required | Description |
|---|---|---|---|
expected_updated_at | string | yes | Concurrency stamp: the draft.updated_at you last read. A mismatch is refused with 409 stale_snapshot — re-read the page and retry. |
kind | string | yes | Block kind, e.g. LINK |
data | object | no | — |
file_url | string | no | public_path of a workspace file from List files |
file_name | string | no | — |
| Field | Type | Description |
|---|---|---|
id | string | — |
title | string | — |
description | string | — |
slug | string | — |
status | DRAFT | PUBLISHED | ARCHIVED | — |
locale | string | — |
public_url | string | null | Live URL when routed; null for unrouted drafts |
theme | object | — |
draft | object | — |
published | object | — |
Every response also carries X-Request-Id plus the IETF draft-11 RateLimit / RateLimit-Policy headers.
| Code | Status | Meaning |
|---|---|---|
invalid_request | 400 | The request body or parameters failed validation |
invalid_api_key | 401 | Missing, malformed, unknown, disabled, or expired API key |
insufficient_scope | 403 | The API key was not granted the required scope |
feature_not_enabled | 403 | The workspace plan does not include public API access |
test_key_read_only | 403 | Test-mode keys are restricted to read operations |
rate_limited | 429 | Per-key rate limit exceeded |
quota_exhausted | 429 | Monthly API quota exhausted |
internal_error | 500 | Something went wrong on our side |
All errors are RFC 9457 application/problem+json — branch on code, quote request_id to support. Full registry on the API docs hub; interactive playground in the API reference.