Install
Works with Drupal: ^10.3 || ^11Using Composer to manage Drupal site dependencies
Alternative installation files
Release notes
The first stable release. It lands five contributor merge requests that had been open since 2021, 2022 and 2024, adds the module's first test coverage, and rebuilds the flag and unflag endpoints on top of JSON:API Resources.
What this module is for
Core JSON:API already exposes flagging entities, so creating and deleting flaggings needs no contrib module. What core cannot do is return flag state as part of the flagged entity. This module adds computed fields so a client fetching an article receives that state in the same response, instead of one filtered request per flag.
Endpoints
POST /jsonapi/flag/{flag}/{entity_id} 201, the created flagging as a resource object DELETE /jsonapi/flag/{flag}/{entity_id} 204
{flag} accepts a flag machine name or a uuid. {entity_id} accepts an id or a uuid. Both routes accept every authentication provider enabled on the site, the same set core JSON:API accepts.
Before the endpoints will answer
Core sets jsonapi.settings.read_only to TRUE by default, which makes both endpoints return 405. Turning it off is a site wide decision affecting every JSON:API write, not only this module's, so weigh it rather than flipping it. The README explains this in full.
The flaggable must be viewable
Both endpoints now answer 404 when the requesting account cannot view the entity being flagged. This is stricter than the unreleased patch that circulated in 2024, and it bites in places worth knowing: a flag targeting user breaks for accounts without access user profiles, and anonymous flagging breaks wherever anonymous lacks access content.