openapi: 3.2.0 info: title: Confluence Cloud REST Content permissions API description: This document describes the REST API and resources provided by Confluence. termsOfService: https://atlassian.com/terms/ version: 1.0.0 servers: - url: //your-domain.atlassian.net tags: - name: Content Permissions description: '' paths: /wiki/rest/api/content/{id}/permission/check: post: tags: - Content Permissions summary: Check content permissions description: 'Check if a user or a group can perform an operation to the specified content. The `operation` to check must be provided. The user’s account ID or the ID of the group can be provided in the `subject` to check permissions against a specified user or group. The following permission checks are done to make sure that the user or group has the proper access: - site permissions - space permissions - content restrictions **Permissions required**: Permission to access the Confluence site (''Can use'' global permission) if checking permission for self, otherwise ''Confluence Administrator'' global permission is required.' operationId: checkContentPermission parameters: - name: id in: path description: The ID of the content to check permissions against. required: true schema: type: string requestBody: description: The content permission request. content: application/json: schema: $ref: '#/components/schemas/ContentPermissionRequest' required: true responses: '200': description: Returned if the permission check completed successfully content: application/json: schema: $ref: '#/components/schemas/PermissionCheckResponse' '400': description: 'Returned if; - If any of the required fields are missing. - If specified `subject` or `operation` is invalid.' content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '403': description: Returned if the user does not have permission perform the check. content: {} '404': description: Returned if there is no content with the given ID. content: {} security: - basicAuth: [] - oAuthDefinitions: - read:confluence-content.permission x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:confluence-content.permission - scheme: oAuthDefinitions state: Beta scopes: - read:content.permission:confluence x-atlassian-data-security-policy: - app-access-rule-exempt: false x-codegen-request-body-name: body x-atlassian-connect-scope: READ components: schemas: Message: required: - args type: object additionalProperties: true properties: translation: type: string args: type: array items: oneOf: - type: string - type: object additionalProperties: true GenericLinks: type: object additionalProperties: oneOf: - type: object additionalProperties: true - type: string PermissionCheckResponse: required: - hasPermission type: object properties: hasPermission: type: boolean errors: type: array items: $ref: '#/components/schemas/Message' _links: $ref: '#/components/schemas/GenericLinks' description: 'This object represents the response for the content permission check API. If the user or group does not have permissions, the following errors may be returned: - Group does not have permission to the space - Group does not have permission to the content - User is not allowed to use Confluence - User does not have permission to the space - User does not have permission to the content - Anonymous users are not allowed to use Confluence - Anonymous user does not have permission to the space - Anonymous user does not have permission to the content' PermissionSubjectWithGroupId: required: - identifier - type type: object properties: type: type: string enum: - user - group identifier: type: string description: 'for `type=user`, identifier should be user''s accountId or `anonymous` for anonymous users for `type=group`, identifier should be ID of the group' description: The user or group that the permission applies to. ContentPermissionRequest: required: - operation - subject type: object properties: subject: $ref: '#/components/schemas/PermissionSubjectWithGroupId' operation: type: string description: The content permission operation to check. enum: - read - update - delete description: This object represents the request for the content permission check API. securitySchemes: basicAuth: type: http description: You can access this resource via basic auth. scheme: basic oAuthDefinitions: type: oauth2 description: This API uses OAuth 2 with the authorizationCode grant flow. flows: authorizationCode: authorizationUrl: https://auth.atlassian.com/authorize tokenUrl: https://auth.atlassian.com/oauth/token scopes: read:confluence-content.all: Read all content, including content body (expansions permitted). Note, APIs using this scope may also return data allowed by read:confluence-space.summary. However, this scope is not a substitute for read:confluence-space.summary. read:confluence-content.permission: Read content permissions. read:confluence-content.summary: Read a summary of the content, which is the content without expansions. Note, APIs using this scope may also return data allowed by read:confluence-space.summary. However, this scope is not a substitute for read:confluence-space.summary. write:confluence-content: Permits the creation of pages, blogs, comments and questions. read:confluence-space.summary: Read a summary of space information without expansions. write:confluence-space: Create, update and delete space information. write:confluence-file: Upload attachments. read:confluence-props: Read content properties. write:confluence-props: Write content properties. search:confluence: Search Confluence. Note, APIs using this scope may also return data allowed by read:confluence-space.summary and read:confluence-content.summary. However, this scope is not a substitute for read:confluence-space.summary or read:confluence-content.summary. manage:confluence-configuration: Manage global settings. read:confluence-groups: Read user groups. write:confluence-groups: Create, remove and update user groups. read:confluence-user: Read users. readonly:content.attachment:confluence: Download attachments of a Confluence page or blogpost that you have access to. read:content:confluence: View content. read:content-details:confluence: View content details. write:content:confluence: Create and update content. delete:content:confluence: Delete content. read:space-details:confluence: View space details. read:analytics.content:confluence: View analytics for content. read:audit-log:confluence: View audit records. write:audit-log:confluence: Create audit records. read:configuration:confluence: View Confluence settings. write:configuration:confluence: Update Confluence settings. read:page:confluence: View pages. write:page:confluence: Create and update pages. delete:page:confluence: Delete pages. read:blogpost:confluence: View blogposts. write:blogpost:confluence: Create and update blogposts. delete:blogpost:confluence: Delete blogposts. read:whiteboard:confluence: View whiteboards. write:whiteboard:confluence: Create and update whiteboards. delete:whiteboard:confluence: Delete whiteboards. read:custom-content:confluence: View custom content. write:custom-content:confluence: Create and update custom content. delete:custom-content:confluence: Delete custom content. read:attachment:confluence: View and download content attachments. write:attachment:confluence: Create and update attachments. delete:attachment:confluence: Delete attachments. read:comment:confluence: View comments. write:comment:confluence: Create and update comments. delete:comment:confluence: Delete comments. read:template:confluence: View content templates. write:template:confluence: Create, update and delete content templates. read:label:confluence: View labels. write:label:confluence: Add and remove labels. read:content.permission:confluence: Check content permissions. read:content.property:confluence: View content properties. write:content.property:confluence: Create, update and delete content properties. read:content.restriction:confluence: View content restrictions. write:content.restriction:confluence: Update content restrictions. read:content.metadata:confluence: View content summaries. read:watcher:confluence: View content watchers. write:watcher:confluence: Add and remove content watchers. read:group:confluence: View groups. write:group:confluence: Create and delete groups. read:inlinetask:confluence: View tasks. write:inlinetask:confluence: Update tasks. read:relation:confluence: View entity relationships. write:relation:confluence: Create and update entity relationships. read:space:confluence: View spaces. write:space:confluence: Create and update spaces. delete:space:confluence: Delete spaces. read:space.permission:confluence: View space permissions. write:space.permission:confluence: Update space permissions. read:space.property:confluence: View space properties. write:space.property:confluence: Create, update and delete space properties. read:user.property:confluence: View user properties. write:user.property:confluence: Create, update and delete user properties. read:space.setting:confluence: View space settings. write:space.setting:confluence: Update space settings. read:user:confluence: View user details. moderate:core-content:confluence: Moderate core contents moderate:comment:confluence: Moderate comments read:email-address:confluence: View email addresses of all users regardless of the user’s profile visibility settings. externalDocs: description: The online and complete version of the Confluence Cloud REST API docs. url: https://developer.atlassian.com/cloud/confluence/rest/ x-atlassian-narrative: documents: - title: About anchor: about body: 'This is the reference for the Confluence Cloud REST API. This API is the primary way to get and modify data in Confluence Cloud, whether you are developing an app or any other integration. Use it to interact with Confluence entities, like pages and blog posts, spaces, users, groups, and more.' - title: Authentication and authorization anchor: auth body: '**Authentication:** If you are building a Cloud app, authentication is implemented via JWT or OAuth 2.0, depending on what you are building (see [Security overview](https://developer.atlassian.com/cloud/confluence/security-overview/)). Otherwise, if you are authenticating directly against the REST API, the REST API supports basic auth (see [Basic auth for REST APIs](https://developer.atlassian.com/cloud/confluence/basic-auth-for-rest-apis/)). **Authorization:** If you are building a Cloud app, authorization can be implemented by [scopes](https://developer.atlassian.com/cloud/confluence/scopes/) or by [OAuth 2.0 user impersonation](https://developer.atlassian.com/cloud/confluence/oauth-2-jwt-bearer-tokens-for-apps). Otherwise, if you are making calls directly against the REST API, authorization is based on the user used in the authentication process. See [Security overview](https://developer.atlassian.com/cloud/confluence/security-overview/) for more details on authentication and authorization.' - title: Status codes anchor: status-code body: "The Confluence REST API uses the [standard HTTP status codes](https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html).\n\nResponses that return an error status code will also return a response body, similar to the following:\n```json\n{\n \"statusCode\": 404,\n \"data\": {\n \"authorized\": false,\n \"valid\": false,\n \"errors\": [\n {\n \"message\": {\n \"translation\": \"This is an example error message.\",\n \"args\": []\n }\n }\n ],\n \"successful\": false\n },\n \"message\": \"This is an example error message.\"\n}\n```" - title: Using the REST API anchor: using body: '**Expansion:** The Confluence REST API uses resource expansion: some parts of a resource are not returned unless explicitly specified. This simplifies responses and minimizes network traffic. To expand part of a resource in a request, use the `expand` query parameter and specify the entities to be expanded. If you need to expand nested entities, use the `.` dot notation. For example, the following request will expand information about the requested content''s space and labels: ``` GET /wiki/rest/api/content/{id}?expand=space,metadata.labels ``` For bulk endpoints, when using the expand query parameter to request `body.export_view` and/or `body.styled_view` content representations, the response will be limited to a maximum of 25 results. If you require more than 25 results, use pagination to retrieve additional results. **Pagination:** The Confluence REST API uses pagination: a method that returns a response with multiple objects can only return a limited number at one time. This limits the size of responses and conserves server resources. Use the ''limit'' and ''start'' query parameters to specify pagination: - `limit` is the number of objects to return per page. This may be restricted by system limits. - `start` is the index of the first item returned in the page of results. The base index is 0. For example, the following request will return ten content objects, starting from the fifth object. ``` GET /wiki/rest/api/content?start=4&limit=10 ``` **Special headers:** - `X-Atlassian-Token: no-check` request header must be specified for methods that are protected from Cross Site Request Forgery (XSRF/CSRF) attacks. This is stated in the method description, if required. For more information, see this [KB article](https://confluence.atlassian.com/cloudkb/xsrf-check-failed-when-calling-cloud-apis-826874382.html).' - title: Capabilities anchor: capabilities body: '**Webhooks:** A webhook is a user-defined callback over HTTP. You can use Confluence webhooks to notify your app or web application when certain events occur in Confluence. For example, when a page is created or updated. To learn more, see [Webhooks](https://developer.atlassian.com/cloud/confluence/modules/webhook/). **Content properties:** Content properties are a key-value storage associated with a piece of Confluence content. If you are building an app, this is one form of persistence that you can use. You can use the Confluence REST API to get, update, and delete content properties. To learn more, see [Content properties in the REST API](https://developer.atlassian.com/cloud/confluence/content-properties/). **CQL:** The Confluence Query Language (CQL) allows you to perform complex searches for content using an SQL-like syntax in the `search` resource. To learn more, see [Advanced searching using CQL](https://developer.atlassian.com/cloud/confluence/advanced-searching-using-cql/).'