POST
Create an annotation

Authorizations

Origin
string
header
required

Same-origin CSRF check. The Origin header must match the request host; enforced for every mutating verb (POST, PUT, PATCH, DELETE).

Body

application/json
appId
integer<int64>
required
body
string
required
tag
enum<string>
required
Available options:
concern,
positive,
follow_up,
other
visibility
enum<string>
required
Available options:
export,
private

Response

200 - application/json

Created.

id
integer<int64>
required
appId
integer<int64>
required
body
string
required

Markdown.

tag
enum<string>
required
Available options:
concern,
positive,
follow_up,
other
visibility
enum<string>
required

Notes flagged private are unconditionally excluded from audit-bundle exports.

Available options:
export,
private
updatedAt
integer<int64>
required
deletedAt
integer<int64> | null

Set during the 30-second soft-delete window; null if active.