BuzzerBeater Public API (v1)
The public API lets tools built by the community — roster managers, training planners, scouting
sheets, league statistics, the next "BB Manager" — read BuzzerBeater on behalf of the managers who
use them. It replaces the legacy XML bbapi with JSON over HTTPS, OAuth 2.0 sign-in, scopes the
manager chooses, and quotas that keep the game fast and fair for everybody.
| Base URL | https://sb1-api.buzzerbeater.com/v1 |
| Sign-in page | https://play.buzzerbeater.com/oauth/authorize |
| Token endpoint | POST https://sb1-api.buzzerbeater.com/v1/oauth/token |
| Interactive reference | https://sb1-api.buzzerbeater.com/v1/reference |
| OpenAPI document | https://sb1-api.buzzerbeater.com/v1/public.json |
| Format | JSON, UTF-8, camelCase properties, enums as strings, dates in ISO 8601 UTC |
The addresses above are the ones this world answers on. If the game moves to other addresses, only the hosts change: paths, scopes and payloads stay the same within
v1.
Principles
- Read-only. The API never plays for anyone: no bids, no lineups, no training changes, no messages. A tool helps a manager decide; the manager acts in the game.
- Never more than the game shows. A token stands for one manager, and every call answers exactly what that manager could see in the game at that moment — your own players' skills, but only the public figures of somebody else's; your own training history, never another club's.
- The manager is in control. They choose the scopes when they sign in, see every application they allowed in Settings → API & third-party apps, and can revoke any of them at any time.
- Built for tools, not for copying the game. Quotas are per manager, and the number of other clubs and players a manager can look into per day is capped. Walking the whole world, mirroring the database, or feeding another game is not possible by design and not allowed by the terms.
Guides
- Getting started — your first call in five minutes with a personal token.
- Authentication — OAuth 2.0 with PKCE for applications, personal tokens for scripts.
- Scopes and privacy — what each scope reveals, and when skills are visible.
- Endpoints — every resource, with its scope and an example.
- Quotas, rate limits and errors — headers, status codes, retrying.
- Migrating from bbapi — the legacy XML pages and their v1 equivalents.
- Terms of use — what applications may and may not do.