openapi: 3.2.0 info: title: Confluence Cloud REST API v2 Operation API description: This document describes Confluence's v2 APIs. This is intended to be an iteration on the existing Confluence Cloud REST API with improvements in both endpoint definitions and performance. termsOfService: https://developer.atlassian.com/platform/marketplace/atlassian-developer-terms/ version: 2.0.0 servers: - url: https://{your-domain}/wiki/api/v2 variables: your-domain: default: no-default description: Specific domain of the Confluence site being used. Must be provided. tags: - name: Operation description: '' paths: /attachments/{id}/operations: get: tags: - Operation operationId: getAttachmentOperations summary: Get permitted operations for attachment description: 'Returns the permitted operations on specific attachment. **Permissions required**: Permission to view the parent content of the attachment and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the attachment for which operations should be returned. schema: type: string pattern: (att)?[0-9]+ responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the parent content of the requested attachment or the attachment was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:attachment:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:attachment:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /blogposts/{id}/operations: get: tags: - Operation operationId: getBlogPostOperations summary: Get permitted operations for blog post description: 'Returns the permitted operations on specific blog post. **Permissions required**: Permission to view the parent content of the blog post and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the blog post for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the parent content of the requested blog post or the blog post was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:page:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:page:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /custom-content/{id}/operations: get: tags: - Operation operationId: getCustomContentOperations summary: Get permitted operations for custom content description: 'Returns the permitted operations on specific custom content. **Permissions required**: Permission to view the parent content of the custom content and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the custom content for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the parent content of the requested custom content or the custom content was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:custom-content:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:custom-content:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /pages/{id}/operations: get: tags: - Operation operationId: getPageOperations summary: Get permitted operations for page description: 'Returns the permitted operations on specific page. **Permissions required**: Permission to view the parent content of the page and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the page for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the parent content of the requested page or the page was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:page:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:page:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /whiteboards/{id}/operations: get: tags: - Operation operationId: getWhiteboardOperations summary: Get permitted operations for a whiteboard description: 'Returns the permitted operations on specific whiteboard. **Permissions required**: Permission to view the whiteboard and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the whiteboard for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the requested whiteboard or the whiteboard was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:whiteboard:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:whiteboard:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /databases/{id}/operations: get: tags: - Operation operationId: getDatabaseOperations summary: Get permitted operations for a database description: 'Returns the permitted operations on specific database. **Permissions required**: Permission to view the database and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the database for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the requested database or the database was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:database:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:database:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /embeds/{id}/operations: get: tags: - Operation operationId: getSmartLinkOperations summary: Get permitted operations for a Smart Link in the content tree description: 'Returns the permitted operations on specific Smart Link in the content tree. **Permissions required**: Permission to view the Smart Link in the content tree and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the Smart Link in the content tree for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the requested Smart Link in the content tree or the Smart Link was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:embed:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:embed:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /folders/{id}/operations: get: tags: - Operation operationId: getFolderOperations summary: Get permitted operations for a folder description: 'Returns the permitted operations on specific folder. **Permissions required**: Permission to view the folder and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the folder for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the requested folder or the folder was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:folder:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:folder:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /spaces/{id}/operations: get: tags: - Operation operationId: getSpaceOperations summary: Get permitted operations for space description: 'Returns the permitted operations on specific space. **Permissions required**: Permission to view the corresponding space.' parameters: - name: id in: path required: true description: The ID of the space for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the space or the space was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:space:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:space:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: true /footer-comments/{id}/operations: get: tags: - Operation operationId: getFooterCommentOperations summary: Get permitted operations for footer comment description: 'Returns the permitted operations on specific footer comment. **Permissions required**: Permission to view the parent content of the footer comment and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the footer comment for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the parent content of the requested footer comment or the footer comment was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:comment:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:comment:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false /inline-comments/{id}/operations: get: tags: - Operation operationId: getInlineCommentOperations summary: Get permitted operations for inline comment description: 'Returns the permitted operations on specific inline comment. **Permissions required**: Permission to view the parent content of the inline comment and its corresponding space.' parameters: - name: id in: path required: true description: The ID of the inline comment for which operations should be returned. schema: format: int64 type: integer responses: '200': description: Returned if the requested operations are returned. content: application/json: schema: $ref: '#/components/schemas/PermittedOperationsResponse' '400': description: Returned if an invalid request is provided. content: {} '401': description: 'Returned if the authentication credentials are incorrect or missing from the request.' content: {} '404': description: 'Returned if the calling user does not have permission to view the parent content of the requested inline comment or the inline comment was not found.' content: {} security: - basicAuth: [] - oAuthDefinitions: - read:comment:confluence x-atlassian-oauth2-scopes: - scheme: oAuthDefinitions state: Current scopes: - read:comment:confluence x-atlassian-connect-scope: READ x-atlassian-data-security-policy: - app-access-rule-exempt: false components: schemas: PermittedOperationsResponse: description: The list of operations permitted on entity. type: object properties: operations: type: array items: $ref: '#/components/schemas/Operation' Operation: type: object properties: operation: description: The type of operation. type: string targetType: description: The type of entity the operation type targets. type: string securitySchemes: basicAuth: type: http description: You can access this resource via basic auth. scheme: basic oAuthDefinitions: type: oauth2 description: This API uses OAuth 2 with the authorizationCode grant flow. flows: authorizationCode: authorizationUrl: https://auth.atlassian.com/authorize tokenUrl: https://auth.atlassian.com/oauth/token scopes: read:page:confluence: View pages and blogposts and their properties. read:space:confluence: View spaces and their properties. read:attachment:confluence: View attachments and their properties. read:comment:confluence: View comments and their properties. read:custom-content:confluence: View custom content and their properties. read:task:confluence: View tasks. read:whiteboard:confluence: View whiteboards and their properties. read:database:confluence: View databases and their properties. read:embed:confluence: View Smart Links in the content tree and their properties. read:folder:confluence: View folders and their properties. read:hierarchical-content:confluence: View children and descendants in the content tree. write:space:confluence: Create and update spaces and their properties. write:page:confluence: Create and update pages and blog posts and their properties. write:comment:confluence: Create and update comments and their properties. write:custom-content:confluence: Create and update custom content and their properties. write:whiteboard:confluence: Create and update whiteboards and their properties. write:database:confluence: Create and update databases and their properties. write:embed:confluence: Create and update Smart Links in the content tree and their properties. write:folder:confluence: Create and update folders and their properties. write:app-data:confluence: Create, update and delete app properties. delete:custom-content:confluence: Delete custom content. delete:page:confluence: Delete pages and blog posts. delete:comment:confluence: Delete comments. delete:whiteboard:confluence: Delete whiteboards. delete:database:confluence: Delete databases. delete:embed:confluence: Delete Smart Links in the content tree. delete:folder:confluence: Delete folders. externalDocs: description: The online and complete version of the Confluence Cloud REST API docs. url: https://developer.atlassian.com/cloud/confluence/rest/v2 x-atlassian-narrative: documents: - title: About anchor: about body: This is the reference for the Confluence Cloud REST API v2, with definitions and performance intended to be an improvement over v1. You can click on the meatball menu in the upper right to download the spec or Postman collection. - title: Authentication and authorization anchor: auth body: '**Authentication:** If you are building a Cloud app, authentication is implemented via JWT or Oauth 2.0, depending on what you''re building (see [Authentication for apps](https://developer.atlassian.com/cloud/confluence/authentication-for-apps/)). Otherwise, if you are authenticating directly against the REST API, the REST API supports basic auth (see [Basic auth for REST APIs](https://developer.atlassian.com/cloud/confluence/basic-auth-for-rest-apis/)). **Authorization:** If you are building a Cloud app, authorization can be implemented by [scopes](https://developer.atlassian.com/cloud/confluence/scopes/) or by [OAuth 2.0 user impersonation](https://developer.atlassian.com/cloud/confluence/oauth-2-jwt-bearer-tokens-for-apps). Otherwise, if you are making calls directly against the REST API, authorization is based on the user used in the authentication process. See [Security overview](https://developer.atlassian.com/cloud/confluence/security-overview/) for more details on authentication and authorization.' - title: Using the REST API anchor: using body: "**Pagination:** The Confluence REST API v2 uses cursor-based pagination: a method that returns a response with multiple objects can only return a limited number at one time. This limits the size of responses and conserves server resources.\n\nUse the 'limit' and 'cursor' parameters on endpoints that return multiple objects to work with pagination. First, make a request with your desired limit in the 'limit' parameter, then observe the `Link` header in the response. If there are additional entities to be retrieved, the `next` URL in the `Link` header will allow you to retrieve the next set of results. This relative URL will also be available under the `_links.next` property of paginated responses. \n\nFor example, the following request will return 5 page objects (if there are 5 present in the target site).\n```\nGET /wiki/api/v2/pages?limit=5\n```\n\nIf there are additional pages available, the `Link` header will look like:\n```\n>; rel=\"next\"\n```\nThe URL within the `Link` header will allow you to access the next 5 pages, while the `rel=\"next\"` denotes that the URL refers to the \"next\" set of pages. Relations for a single URL are separated by semicolons (;) and URLs are separated by commas (,)\nIf there are no related URLs, the `Link` header will not be present in the response and neither will the `next` property for `_links` in the response body."