# Bonitasoft (Ofelia) — Bonita > Bonitasoft is the French open-source company behind Bonita, a BPMN 2.0 business > process management and process automation platform. Bonita is software the > customer runs — on premises, in a container, or as managed Bonita Cloud — so the > API is served by each deployment at `/bonita/API`, not by a vendor host. > Every HTTP-reachable Bonita feature is described by one first-party OpenAPI > 3.0.2 document (153 paths, 224 operations, 162 schemas), published open source > and versioned independently of the product. In June 2026 the company rebranded > to Ofelia; the product is still Bonita and the GitHub organization is still > `bonitasoft`, but all web, documentation and community hosts moved from > bonitasoft.com to ofelia.com behind 301 redirects. GENERATED, NOT PUBLISHED. Bonitasoft does not serve an llms.txt. This file was generated by API Evangelist on 2026-08-17 from the company's public surface and from the artifacts in this repository (github.com/api-evangelist/bonitasoft). /llms.txt returns 404 on www.ofelia.com, documentation.ofelia.com, api-documentation.ofelia.com and community.ofelia.com. ## What you can call - [Bonita Web REST API](https://documentation.ofelia.com/bonita/latest/api/rest-api-overview): BPM (processes, cases, tasks, activities, flow nodes, timers, messages, signals), identity (users, groups, roles, memberships, profiles), applications and pages, Business Data Model queries, documents and comments, platform and license administration. 224 operations. - [Bonita Engine Java API](https://documentation.ofelia.com/bonita/latest/api/engine-api-overview): the in-JVM alternative to REST, for code running inside the engine. - [REST API extensions](https://documentation.ofelia.com/bonita/latest/api/rest-api-extensions): the supported way to add custom endpoints, served at `{bonita_context}/API/extension/{pathTemplate}`. ## Specifications - [OpenAPI 3.0.2, version 1.0.9](https://api-documentation.ofelia.com/latest/openapi.yaml): the live document, served as application/x-yaml. Also on every release at https://github.com/bonitasoft/bonita-openapi/releases as `bonita-openapi-.yaml`. - [Postman Collection v2.1.0](https://api-documentation.ofelia.com/latest/postman.json): generated from the OpenAPI each release. - [Interactive reference (ReDoc)](https://api-documentation.ofelia.com/latest/), per-version at `https://api-documentation.ofelia.com/{version}/`. - Local copy in this repository: `openapi/bonitasoft-bonita-openapi.yml` (verbatim), `openapi/_original/bonitasoft-bonita-openapi.yaml`. ## Base URL There is no single base URL. Substitute the host of the deployment you are calling: - Pattern: `{scheme}://{host}:{port}/bonita/API` - Bonita Cloud production: `https://{customer-name}.bonitacloud.com/bonita` - Bonita Cloud non-production: `https://{customer-name}-integration.bonitacloud.com/bonita` - Local (Docker Official Image): `http://localhost:8080/bonita` - The OpenAPI `servers[]` block declares `http://localhost:8080/bonita` and labels it "Sample url for a local development server." Never point a script at a `/bonita/API` host you do not own. `POST /API/bpm/case` starts real work in a real organization. ## Authentication Session cookie plus CSRF token, not an API key. 1. `POST /loginservice` with `application/x-www-form-urlencoded` `username`, `password`, `redirect=false`. Returns `204` with a `JSESSIONID` cookie and an `X-Bonita-API-Token` cookie. 2. Send the `JSESSIONID` cookie on every request. 3. Send `X-Bonita-API-Token: ` on every `POST`, `PUT` and `DELETE`. CSRF protection is on by default on fresh installations; omitting this header is the most common cause of a 401. 4. `GET /logoutservice?redirect=false` to end the session. Bonita Enterprise configured for OIDC SSO also accepts `Authorization: Bearer `. Platform administration is a separate session via `POST /platformloginservice`. Authorization is **not OAuth scopes**. Bonita maps endpoints to permissions and permissions to profiles (User, Administrator, Super Administrator), with both static and dynamic authorization checks enabled by default. A `403` is a configuration answer, not a retryable one. - [REST API authorization](https://documentation.ofelia.com/bonita/latest/identity/rest-api-authorization) - [API permissions overview](https://documentation.ofelia.com/bonita/latest/identity/api-permissions-overview) - [SSO with OIDC](https://documentation.ofelia.com/bonita/latest/identity/single-sign-on-with-oidc) ## Conventions you must know - **Pagination is required, not optional.** `p` (page index, from 0) and `c` (page size, default 20) are declared `required: true` on list operations. A list call without both returns `400`, not a defaulted first page. `o` orders, `f` filters (`f={name}={value}`, url-encoded), `s` searches. Pagination state comes back in the `content-range` **response header**, and list bodies are bare JSON arrays. - **Related objects are inlined with repeatable `d=`.** e.g. `/API/bpm/flowNode/143?d=processId&d=caseId&d=assigned_id`. `d=` is documented in the spec's prose but not declared per operation, so a generated client will not discover it. - **Completed work moves to the archive.** A finished case, task or flow node 404s on the live resource. Retry against `/API/bpm/archivedCase`, `/API/bpm/archivedTask`, `/API/bpm/archivedHumanTask`, `/API/bpm/archivedFlowNode`, `/API/bpm/archivedActivity`. Archived records carry `sourceObjectId` back to the live id. - **No idempotency.** There is no idempotency-key header or parameter anywhere. Retrying `POST /API/bpm/case` creates a second case. Dedupe on your own side. - **Errors are shallow.** `application/json` with a single free-text `message`. No RFC 9457 problem details, no error code, no type URI. Branch on the HTTP status, not the message. - **One rate limit.** Community Edition 2024.3+ caps case creation (150/month per the pricing page) and returns `429` with `Retry-After` as an **absolute date-time**, not delay-seconds. No `X-RateLimit-*` headers anywhere. - **The Business Data Model is per-deployment.** `/API/bdm/businessData/{businessDataType}?q=` addresses queries by name, declared at design time. You cannot enumerate a customer's business entities from the published contract. Full detail: `conventions/bonitasoft-conventions.yml`, `errors/bonitasoft-problem-types.yml`, `rate-limits/bonitasoft-rate-limits.yml`, `data-model/bonitasoft-data-model.yml`. ## Get a callable instance in one command docker run --name bonita -p 8080:8080 -d bonita Then `http://localhost:8080/bonita`, default tenant admin `install` / `install` (published by the vendor for a fresh local container; change it before exposing anything). The OpenAPI repository also ships a `docker-compose.yaml` that starts Swagger UI **and** a live Bonita so the contract can be exercised against a real runtime. See `sandbox/bonitasoft-sandbox.yml`. ## Client libraries - Java: `org.bonitasoft.web:bonita-java-client` 3.0.1 (2025-03-21) — the only first-party REST client, named in the OpenAPI description itself. - Everything else: raw HTTP plus the OpenAPI/Postman artifacts. There is no first-party JavaScript, Python, Go, Ruby, PHP or .NET client. - Docker Official Image: `bonita` (tag 2026.2-u0, 2026-06-30). - Build/deploy CLI: `bonita-project-maven-plugin` 2.1.2 (13 goals) and the `bonita-update` / `check-update-dryrun` scripts. See `packages/bonitasoft-packages.yml` and `cli/bonitasoft-cli.yml`. ## Editions and price - **Bonita Free (Community)** — $0, no credit card, 150 process instances per month, full REST API. - **Bonita Enterprise** — custom pricing; adds Bonita Fabric, Work Hub, AI connectors, IDP, RBAC/SSO, HA, professional services. Release notes reveal finer tiers (Teamwork, Efficiency, Performance, Enterprise, Scale) that the pricing page does not list. - **Ofelia Assistant / Ofelia Workflow** — contact sales; private preview stated for Q3 2026, general availability early 2027. No API published for them yet. `plans/bonitasoft-plans-pricing.yml`. ## Versioning and change - API contract: semver, currently **1.0.9** (2026-06-19), first released 1.0.0 on 2025-02-20. - Product: `YYYY.#-uX`, currently **2026.2-u1** (2026-07-17). Two main versions a year, a maintenance update at least monthly, all updates of a main version cross-compatible. - No published deprecation or end-of-life policy — but 33 of 224 operations carry `deprecated: true` in the spec (the whole legacy Application/Profile/Theme write surface and the design-time process/BDM writes). - No public status page on any host. `lifecycle/bonitasoft-lifecycle.yml`, `changelog/bonitasoft-changelog.yml`. ## Security - Vulnerability reporting policy: , contact `product-security@ofelia.com`. Coordinated disclosure with MITRE CVE assignment; no bug bounty; no safe-harbour statement; **not** advertised at `/.well-known/security.txt`. - ISO 27001 certified (Bureau Veritas, 2022) for Bonita Cloud, published on . No SOC 2. No trust centre. - GDPR: published DPA naming eight sub-processors and EU hosting on AWS Europe, plus BDM data retention rules as a product feature since 2026.1. - Domain posture is strong: DNSSEC, CAA, SPF, DMARC `p=reject`, HSTS with a one-year max-age. `security/`, `conformance/bonitasoft-conformance.yml`. ## Agent surfaces - **No MCP server** — hosted or stdio. Zero matches for "mcp" across 157 public repositories. `mcp/bonitasoft-mcp.yml` holds a derived candidate tool list only (`deployment.mode: none`). - **No A2A agent card** at either `/.well-known/agent-card.json` or `/.well-known/agent.json` on any host. - **No llms.txt**, no `/.well-known/` document of any kind. - **No webhooks and no AsyncAPI.** Bonita's events are internal BPMN message/signal/timer events you POST to, not deliveries you subscribe to. - What does exist: the OpenAPI, the Postman collection, and — on the other side of the boundary — first-party AI connectors (`bonita-connector-ai`, `bonita-connector-ai-agent`, an Ollama connector) that let a Bonita process call a model. Packaged agent skills grounded in real operationIds: `skills/_index.yml`. ## Docs - [Documentation home](https://documentation.ofelia.com/bonita/latest/) - [API index](https://documentation.ofelia.com/bonita/latest/api/api-index) - [Getting started](https://documentation.ofelia.com/bonita/latest/getting-started/getting-started-index) - [Release notes](https://documentation.ofelia.com/bonita/latest/release-notes) - [Bonita Cloud docs](https://documentation.ofelia.com/cloud/latest/) and [SLA](https://documentation.ofelia.com/cloud/latest/sla/service-availability) - [Community forum](https://community.ofelia.com/) - [GitHub organization](https://github.com/bonitasoft) — 157 public repositories; engine LGPL-2.1, OpenAPI GPL-2.0 - [Pricing](https://www.ofelia.com/pricing) · [Downloads](https://www.ofelia.com/downloads) · [Blog](https://www.ofelia.com/blog) - [Terms](https://www.ofelia.com/terms-and-conditions) · [Personal data protection policy](https://www.ofelia.com/personal-data-protection-policy)