openapi: 3.2.0 info: title: Basware APIs for Purchase-to-Pay and Master Data import… description: The Basware APIs documented here are for Purchase-to-Pay use cases and for importing Master Data to Basware services. version: v1 servers: - url: '' security: - Bearer: [] - oauth2authentication: [] tags: - name: Application Groups paths: /v1/applicationGroups: post: tags: - Application Groups summary: Creates new Application groups, fully overwrites previous record if exists description: 'Application groups give access to a specific set of applications for users imported through ''users'' API. Each user needs to be assigned to one or more application group(s) by specifying ''applicationGroupCode'' values in users API. Notes: 1. User ''loginType'' (set on users API) needs to be ''4'' (user authentication through Basware Access) when the user is imported to any system besides (or in addition to) P2P. 2. POSTing to applicationGroups API returns a link to ''redistribute users'' task status. This is because changes to applicationGroups will trigger changes to users assigned to those groups. When there are many users, the changes to users may take a while to complete. Accessing the link requires providing API credentials. Please see section "Usage scenario 4: Import users" of Basware Purchase-to-Pay API manual for details on managing users with Basware API. Check out also the example JSONs using a minimal feasible set of fields from the developer site.' parameters: - name: Content-Type in: header description: Specifies the media type of the resource. Value application/json is supported. schema: type: string example: application/json requestBody: content: application/json-patch+json: schema: type: array items: $ref: '#/components/schemas/ApplicationGroupEntity' application/json: schema: type: array items: $ref: '#/components/schemas/ApplicationGroupEntity' text/json: schema: type: array items: $ref: '#/components/schemas/ApplicationGroupEntity' application/*+json: schema: type: array items: $ref: '#/components/schemas/ApplicationGroupEntity' responses: '200': description: Success content: text/plain: schema: $ref: '#/components/schemas/ApplicationGroupEntity' application/json: schema: $ref: '#/components/schemas/ApplicationGroupEntity' text/json: schema: $ref: '#/components/schemas/ApplicationGroupEntity' '400': description: Bad request content: text/plain: schema: $ref: '#/components/schemas/ResponseEntityList' application/json: schema: $ref: '#/components/schemas/ResponseEntityList' text/json: schema: $ref: '#/components/schemas/ResponseEntityList' '401': description: Unauthorized '409': description: Conflict content: text/plain: schema: $ref: '#/components/schemas/ResponseEntityList' application/json: schema: $ref: '#/components/schemas/ResponseEntityList' text/json: schema: $ref: '#/components/schemas/ResponseEntityList' '500': description: Unexpected error content: text/plain: schema: $ref: '#/components/schemas/ResponseEntityList' application/json: schema: $ref: '#/components/schemas/ResponseEntityList' text/json: schema: $ref: '#/components/schemas/ResponseEntityList' operationId: postV1ApplicationGroups x-operation-id-source: derived get: tags: - Application Groups summary: Returns application groups description: Application groups give access to a specific set of applications for users imported through 'users' API. Each user needs to be assigned to one or more application group(s) by specifying 'applicationGroupCode' values in users API. parameters: - name: pageSize in: query description: A limit for the number of items to be returned for one request. Limit can range between 1 and 100 items. schema: type: integer format: int32 default: 100 - name: lastUpdated in: query description: Date filter. Returns items that have been updated after specified date. schema: type: string format: date-time - name: x-amz-meta-continuationtoken in: header description: Used to get next page of results when item count indicated by 'pageSize' is exceeded. A token is returned in header (not body) parameter 'X-amz-meta-continuationToken' of the response whenever there are more records to fetch. Post the received value here in a new HEADER parameter on the next GET request to receive the next page of results. When getting the next page of results, you must include the same query parameters that were used when getting the first page. schema: type: string example: 2913fb86-1258-4372-8e2c-d149ad982c6a responses: '200': description: Success content: text/plain: schema: $ref: '#/components/schemas/ApplicationGroupsResponse' application/json: schema: $ref: '#/components/schemas/ApplicationGroupsResponse' text/json: schema: $ref: '#/components/schemas/ApplicationGroupsResponse' '401': description: Unauthorized '404': description: Not Found '500': description: Unexpected error content: text/plain: schema: $ref: '#/components/schemas/ResponseEntityList' application/json: schema: $ref: '#/components/schemas/ResponseEntityList' text/json: schema: $ref: '#/components/schemas/ResponseEntityList' operationId: getV1ApplicationGroups x-operation-id-source: derived /v1/applicationGroups/{applicationGroupCode}: get: tags: - Application Groups summary: Returns single Application Group by application group code - identifier description: Application groups give access to a specific set of applications for users imported through 'users' API. Each user needs to be assigned to one or more application group(s) by specifying 'applicationGroupCode' values in users API. parameters: - name: applicationGroupCode in: path description: The external code of the entity to be fetched required: true schema: type: string responses: '200': description: Success content: text/plain: schema: $ref: '#/components/schemas/ApplicationGroupsResponse' application/json: schema: $ref: '#/components/schemas/ApplicationGroupsResponse' text/json: schema: $ref: '#/components/schemas/ApplicationGroupsResponse' '401': description: Unauthorized '404': description: Not found. Request was successful and no records were found. '500': description: Unexpected error content: text/plain: schema: $ref: '#/components/schemas/ResponseEntityList' application/json: schema: $ref: '#/components/schemas/ResponseEntityList' text/json: schema: $ref: '#/components/schemas/ResponseEntityList' operationId: getV1ApplicationGroupsByApplicationGroupCode x-operation-id-source: derived components: schemas: ErrorEntity: type: object properties: externalCode: type: - string - 'null' description: External code of record on which error occurred (when available). example: 4847-31231212-212121-1212 type: enum: - BUSINESS - VALIDATION - TECHNICAL - SECURITY type: string description: Error type. example: '' code: enum: - EXTERNAL_CODE_MISMATCH - SCHEMA_VALIDATION_ERROR - CONFLICT_IN_POST - DATA_ORIGIN_VALIDATION_ERROR - ACCESS_TOKEN_VALIDATION_ERROR - CREDENTIAL_VALIDATION_ERROR - PARAMETER_VALIDATION_ERROR - UNEXPECTED_ERROR - METHOD_NOT_ALLOWED - ENTITY_NOT_FOUND - DATA_VALIDATION_FAILED - SNS_PUBLISH_ERROR - SQS_PUBLISH_ERROR type: string description: Error code. example: '' message: type: - string - 'null' description: Specific error message. example: '' info: type: - string - 'null' description: Information about type of the error. example: '' additionalProperties: false ApplicationGroupEntity: required: - applicationGroupCode - applications - description type: object properties: applicationGroupCode: maxLength: 100 minLength: 1 type: string description: 'Identifier for the application group. Best practice: Use descriptive names, such as ''Auditors'', ''Reviewers'', etc.' example: Reviewers description: maxLength: 250 minLength: 1 type: string description: Freetext description for the applicationGroup. example: Basic users - access to P2P. active: type: boolean description: Determines whether the applicationGroup is active or not. Groups where active = 'false' do not give access to any applications. example: true default: type: boolean description: Used for specifying default application groups. Application groups where default = 'true' will be assigned automatically to all users who have no application group assigned through users API. example: true lastUpdated: type: string description: Timestamp when the record was last sent to API (set automatically by Basware API). format: date-time example: '2020-10-24T00:00:00' applications: type: array items: $ref: '#/components/schemas/Applications' additionalProperties: false ApplicationGroupsResponse: required: - applicationGroups type: object properties: applicationGroups: type: array items: $ref: '#/components/schemas/ApplicationGroupEntity' additionalProperties: false Applications: required: - code type: object properties: code: enum: - PurchaseToPay - Reporting - SupplierPortal - SupplierManagement - CloudscanWithSelfValidation - CloudscanWithBaswareValidation - BaswareAdmin - StrategicSourcing - SmartPDFSelfValidation - SmartPDFAdmin - BaswareAdminOrgMgmt - APAssuranceAdmin - APAssuranceUser - StatementMatchingUser - StatementMatchingAdmin type: string description: " Specifies code for the application. \n 1. PurchaseToPay = Basware Purchase-to-Pay (P2P)\n 2. Reporting = Basware Reporting\n 3. SupplierPortal = Access to Basware network, user can see only own company's suppliers. \n 4. SupplierManagement = Access to Basware network, user can see suppliers from any company within tenant. \n 5. CloudscanWithSelfValidation = CloudScan with Self-Validation\n 6. CloudscanWithBaswareValidation = CloudScan with Basware Validation\n 7. BaswareAdmin = Basware Admin (excl. organization management)\n 8. StrategicSourcing = Strategic Sourcing\n 9. SmartPDFSelfValidation = SmartPfd with self validation\n10. SmartPDFAdmin = SmartPdf Administration\n11. BaswareAdminOrgMgmt = Basware Admin - organization management (in piloting)\n12. APAssuranceUser = AP Assurance, user access\n13. APAssuranceAdmin = AP Assurance, administrator access\n14. StatementMatchingUser = Statement Matching, user access\n15. StatementMatchingAdmin = Statement Matching, administrator access\n \n Note: For accessing applications 2, 5, 6, 7, 9, 10 above, either loginType '4' (Basware Access login) or accessEnabledLogin = “True” is required on the user posted through users API." example: PurchaseToPay additionalProperties: false ResponseEntityList: type: object properties: requestId: type: - string - 'null' description: ID of the request on which error occurred (generated by Basware API). example: fbc082a2-65a4-469c-b230-d84a252f18fc hasErrors: type: boolean description: Specifies whether the request has errors. errors: type: - array - 'null' items: $ref: '#/components/schemas/ErrorEntity' additionalProperties: false description: Errors returned here are returned synchronously from Basware API middle layer. Additional errors coming from target system(s) may be returned through errorFeedbacks API. securitySchemes: Bearer: type: http description: Please insert basic authentication credentials into fields scheme: basic oauth2authentication: type: oauth2 description: Oauth2 client credentials flow. flows: clientCredentials: tokenUrl: https://api.basware.com/v1/tokens scopes: accountingDocuments.read: GET accountingDocuments accountingDocuments.write: POST/PATCH accountingDocuments accountingDocuments.delete: DELETE accountingDocuments accounts.read: GET accounts accounts.write: POST/PATCH accounts accounts.delete: DELETE accounts advancedPermissions.read: GET advancedPermissions advancedPermissions.write: POST/PATCH advancedPermissions advancedPermissions.delete: DELETE advancedPermissions advancedValidations.read: GET advancedValidations advancedValidations.write: POST/PATCH advancedValidations advancedValidations.delete: DELETE advancedValidations applicationGroups.read: GET applicationGroups applicationGroups.write: POST/PATCH applicationGroups companies.read: GET companies companies.write: POST/PATCH companies contracts.delete: DELETE contracts contracts.read: GET contracts contracts.write: POST/PATCH contracts costCenters.read: GET costCenters costCenters.write: POST/PATCH costCenters costCenters.delete: DELETE costCenters errorFeedbacks.read: GET errorFeedbacks errorFeedbacks.write: POST/PATCH errorFeedbacks errorFeedbacks.delete: DELETE errorFeedbacks exchangeRates.read: GET exchangeRates exchangeRates.write: POST/PATCH exchangeRates exchangeRates.delete: DELETE exchangeRates exportedContracts.read: GET exportedContracts exportedContracts.write: POST/PATCH exportedContracts exportedContracts.delete: DELETE exportedContracts exportedContractSpends.read: GET exportedContractSpends exportedContractSpends.write: POST/PATCH exportedContractSpends exportedContractSpends.delete: DELETE exportedContractSpends exportedPurchaseOrders.read: GET exportedPurchaseOrders exportedPurchaseOrders.write: POST/PATCH exportedPurchaseOrders exportedPurchaseOrders.delete: DELETE exportedPurchaseOrders exportedPurchaseRequisitions.read: GET exportedPurchaseRequisitions exportedPurchaseRequisitions.write: POST/PATCH exportedPurchaseRequisitions exportedPurchaseRequisitions.delete: DELETE exportedPurchaseRequisitions lists.read: GET lists lists.write: POST/PATCH lists lists.delete: DELETE lists matchingOrders.read: GET matchingOrders matchingOrders.write: POST/PATCH matchingOrders matchingOrders.delete: DELETE matchingOrders matchingOrderLines.read: GET matchingOrderLines matchingOrderLines.write: POST/PATCH matchingOrderLines matchingOrderLines.delete: DELETE matchingOrderLines paymentTerms.read: GET paymentTerms paymentTerms.write: POST/PATCH paymentTerms paymentTerms.delete: DELETE paymentTerms projects.read: GET projects projects.write: POST/PATCH projects projects.delete: DELETE projects purchaseOrders.read: GET purchaseOrders purchaseOrders.write: POST/PATCH purchaseOrders purchaseOrders.delete: DELETE purchaseOrders purchaseRequisitions.read: GET purchaseRequisitions purchaseRequisitions.write: POST/PATCH purchaseRequisitions purchaseRequisitions.delete: DELETE purchaseRequisitions purchaseGoodsReceipts.read: GET purchaseGoodsReceipts purchaseGoodsReceipts.write: POST/PATCH purchaseGoodsReceipts purchaseGoodsReceipts.delete: DELETE purchaseGoodsReceipts requestStatus.read: GET requestStatus requestStatus.write: POST/PATCH requestStatus subscriptions.read: GET subscriptions subscriptions.write: POST/PATCH subscriptions subscriptions.delete: DELETE subscriptions tasks.read: GET tasks taskStatus.read: GET taskStatus taxCodes.read: GET taxCodes taxCodes.write: POST/PATCH taxCodes taxCodes.delete: DELETE taxCodes users.read: GET users users.write: POST/PATCH users users.delete: DELETE users vendors.read: GET vendors vendors.write: POST/PATCH vendors vendors.delete: DELETE vendors