openapi: 3.0.3 info: title: Castor EDC / CDMS Audit Trail Studies API description: 'The Castor EDC / CDMS API is a RESTful interface to Castor''s cloud electronic data capture (EDC) and clinical data management platform. It exposes study configuration and collected data - studies, participants (records), institutes (sites), users, fields and field metadata, study data points, repeating data (reports), surveys and survey packages, the audit trail, and batch data export. Authentication is OAuth2 with the Client Credentials flow: request an access token from POST /oauth/token using an API Client ID and Client Secret generated in Castor User Settings, then send it as a Bearer token. Access tokens are valid for 5 hours. Most identifiers (study, field, report / repeating-data instance, survey package instance) are uppercase GUIDs in 8-4-4-4-12 format; the participant ID is the exception. Endpoint status: paths that this document marks with `x-endpoint-status: confirmed` were observed directly in Castor''s published API reference and helpdesk documentation. Paths marked `x-endpoint-status: modeled` reflect the documented resource model and the coverage of the official R and Python wrapper packages, but the exact path or shape was inferred and should be verified against https://data.castoredc.com/api during reconciliation.' version: '1.0' contact: name: Castor url: https://www.castoredc.com license: name: Proprietary url: https://www.castoredc.com/legal/ servers: - url: https://data.castoredc.com/api description: Castor EU (default) - url: https://us.castoredc.com/api description: Castor US region security: - oauth2ClientCredentials: [] tags: - name: Studies description: Studies accessible to the API client. paths: /oauth/token: post: operationId: getAccessToken tags: - Studies summary: Obtain an OAuth2 access token description: Exchange an API Client ID and Client Secret for a Bearer access token using the client_credentials grant. The returned token is valid for 5 hours. security: [] x-endpoint-status: confirmed requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object required: - client_id - client_secret - grant_type properties: client_id: type: string client_secret: type: string grant_type: type: string enum: - client_credentials responses: '200': description: An access token. content: application/json: schema: type: object properties: access_token: type: string token_type: type: string example: Bearer expires_in: type: integer example: 18000 '401': $ref: '#/components/responses/Unauthorized' /study: get: operationId: listStudies tags: - Studies summary: List studies description: Lists all studies the authenticated API client has access to. x-endpoint-status: confirmed parameters: - $ref: '#/components/parameters/Page' responses: '200': description: A paginated list of studies. content: application/json: schema: $ref: '#/components/schemas/StudyCollection' '401': $ref: '#/components/responses/Unauthorized' /study/{study_id}: get: operationId: getStudy tags: - Studies summary: Retrieve a study description: Retrieves a single study by its GUID. x-endpoint-status: confirmed parameters: - $ref: '#/components/parameters/StudyId' responses: '200': description: A study. content: application/json: schema: $ref: '#/components/schemas/Study' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: parameters: Page: name: page in: query required: false description: Page number for paginated (HAL) collections. schema: type: integer minimum: 1 StudyId: name: study_id in: path required: true description: The study GUID (uppercase, 8-4-4-4-12 format). schema: type: string schemas: Study: type: object properties: study_id: type: string format: uuid name: type: string created_by: type: string live: type: boolean randomization_enabled: type: boolean surveys_enabled: type: boolean created_on: type: string format: date-time StudyCollection: type: object properties: _embedded: type: object properties: study: type: array items: $ref: '#/components/schemas/Study' page_count: type: integer total_items: type: integer responses: NotFound: description: The requested resource was not found. Unauthorized: description: Missing or invalid access token. securitySchemes: oauth2ClientCredentials: type: oauth2 flows: clientCredentials: tokenUrl: https://data.castoredc.com/api/oauth/token scopes: {}