Comment on a task list
comments:writePath parameters
project_idstringrequiredThe project SLUG.
task_list_idstringrequiredThe task-list SLUG.
Request body
contentstringrequiredRich-text comment body (plain text in).
Request
curl -X POST "https://app.fareeqy.com/api/v1/projects/تطوير-الموقع/task-lists/الصفحة-الرئيسية/comments" \
-H "Authorization: Bearer $FAREEQY_API_KEY" \
-H "Content-Type: application/json" \
-d '{"content":"خلصنا الهيدر، باقي قسم المزايا."}'Response
{
"data": {
"id": 512,
"content": "راجعت النسخة الأخيرة، ينقصنا حالة الخطأ في النموذج.",
"author": "عبدالله المطيري",
"created_at": "2026-07-15T09:48:03.000+03:00"
}
}Refusals:401403404409422429Show failure examplesHide failure examples
defaultMissing or invalid API key.
{
"error": {
"code": "unauthorized",
"message": "Invalid or missing API key."
}
}forbiddenTwo different refusals share this status, and a client must tell them apart by error.code. forbidden means the key's scope or allowlist does not permit this operation, or Pundit denied the action. plan_upgrade_required means the company's plan carries no API access at all, so no key on it can ever succeed and there is nothing to retry.
{
"error": {
"code": "forbidden",
"message": "This API key is not permitted to perform this operation."
}
}{
"error": {
"code": "plan_upgrade_required",
"message": "خطة «الاحترافي» لا تشمل الوصول إلى API. رقِّ إلى «المتطور» أو «الانتاجي» لتفعيله. — The الاحترافي plan does not include API access. Upgrade to «المتطور» or «الانتاجي» to enable it."
}
}defaultResource not found or not accessible — also returned for EVERY endpoint when the company's rest_api feature flag is disabled (the surface is hidden). Lookups drill through the URL hierarchy, so another company's record is a 404 and never a leak. A path that matches no route at all answers 404 with the distinct code unknown_endpoint and echoes the path back, so a mistyped or half-built URL is told apart from a record that is missing or out of reach.
{
"error": {
"code": "not_found",
"message": "Resource not found, or you do not have access to it."
}
}defaultA uniqueness/record conflict; retry.
{
"error": {
"code": "conflict",
"message": "Could not complete due to a conflict; please retry."
}
}defaultA caller-fixable bad request (validation error, bad date, bad enum).
{
"error": {
"code": "unprocessable_entity",
"message": "Title can't be blank"
}
}rate_limit_exceededEither the company's daily API allowance is spent (rate_limit_exceeded), or the per-key / per-IP burst throttle of 300 requests per minute fired. Both come back after a wait, so Retry-After is honest here. The two bodies are not the same shape. The daily-quota refusal uses the standard error envelope. The burst throttle is served by Rack::Attack ahead of the application, so its body is a flat {"error": "<string>"} with no code. A client that reads error.code has to tolerate error being a plain string.
{
"error": {
"code": "rate_limit_exceeded",
"message": "استهلكت رصيد اليوم من طلبات API في خطة «المتطور» (1000 طلب يوميًا). يتجدد الرصيد عند منتصف الليل بتوقيت Asia/Riyadh. — Daily API quota exhausted: the المتطور plan allows 1000 calls per day. It resets at midnight Asia/Riyadh."
}
}{
"error": "Rate limit exceeded. Please try again later."
}