openapi: 3.0.3 info: title: Bloomerang REST API v2 Constituents Notes API description: The Bloomerang REST API v2 is a private-key, server-to-server API for reading and writing data in a Bloomerang donor management CRM account - constituents, transactions (donations, pledges, recurring donations), interactions, notes, relationships, and webhook subscriptions. Requests are authenticated with either a private API key sent in the X-Api-Key header (generated by an Administrator user under User Settings) or an OAuth 2.0 access token for third-party applications. Bloomerang does not offer a sandbox environment - all requests operate against production data. Endpoints for Constituents, Transactions, and Interactions are directly confirmed in Bloomerang's public documentation and third-party integration guides; endpoints for Households, Notes, Relationships, Custom Fields, Webhooks, Users, Funds, Campaigns, and Appeals are modeled from Bloomerang's REST API v1 resource parity, community client libraries, and CRM feature documentation, since Bloomerang does not publish a complete, versioned OpenAPI/Swagger document for v2. See review.yml in this repository for the endpointsConfirmed vs endpointsModeled breakdown. version: '2.0' contact: name: Bloomerang url: https://bloomerang.com/api/rest-api servers: - url: https://api.bloomerang.co/v2 description: Bloomerang REST API v2 (production - no sandbox is offered) security: - apiKeyAuth: [] - oauth2Bearer: [] tags: - name: Notes description: Freeform notes attached to a constituent record. paths: /notes: post: operationId: createNote tags: - Notes summary: Create a note description: Creates a freeform note attached to a constituent, optionally with file attachment IDs. Endpoint path modeled from Bloomerang's documented Note object and AttachmentIds property - see review.yml. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/NoteInput' responses: '200': description: The created note. content: application/json: schema: $ref: '#/components/schemas/Note' '401': $ref: '#/components/responses/Unauthorized' '422': $ref: '#/components/responses/ValidationError' /notes/{id}: parameters: - name: id in: path required: true description: The ID of the note. schema: type: integer get: operationId: getNote tags: - Notes summary: Retrieve a note description: Retrieves a note by ID. Endpoint modeled from Bloomerang's documented Note object - see review.yml. responses: '200': description: The requested note. content: application/json: schema: $ref: '#/components/schemas/Note' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: schemas: Note: allOf: - $ref: '#/components/schemas/NoteInput' - type: object properties: Id: type: integer Error: type: object properties: Message: type: string Errors: type: array items: type: string NoteInput: type: object required: - AccountId - Note properties: AccountId: type: integer Note: type: string Date: type: string format: date AttachmentIds: type: array items: type: integer responses: Unauthorized: description: Missing or invalid API key / access token. content: application/json: schema: $ref: '#/components/schemas/Error' ValidationError: description: The request payload failed validation. content: application/json: schema: $ref: '#/components/schemas/Error' NotFound: description: The requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: apiKeyAuth: type: apiKey in: header name: X-Api-Key description: Private API key generated by an Administrator user in Bloomerang under User Settings > Edit My User. Grants full read/write access - keep it secret. oauth2Bearer: type: oauth2 description: 'OAuth 2.0 access token for third-party applications, presented as `Authorization: Bearer {access_token}`.' flows: authorizationCode: authorizationUrl: https://crm.bloomerang.co/oauth/authorize tokenUrl: https://api.bloomerang.co/v2/oauth/token scopes: api: Full read/write access to account data.