openapi: 3.0.3 info: title: SAP Crystal Reports RESTful Web Services Authentication API description: RESTful web services API for SAP Crystal Reports, providing access to report viewing, exporting, data retrieval via OData, and repository navigation through the SAP BusinessObjects BI Platform. version: 4.3.0 contact: name: SAP url: https://www.sap.com license: name: Proprietary url: https://www.sap.com/about/legal/copyright.html x-generated-from: documentation x-source-url: https://help.sap.com/doc/sapcrystalreportsrestfulwebservices/4.3/en-US/crrest_api_42SP2.pdf servers: - url: http://{host}:{port}/biprws description: SAP BusinessObjects BI Platform REST API server variables: host: default: localhost description: Hostname of the SAP BusinessObjects server port: default: '6405' description: Port number for the RESTful web services security: - sapLogonToken: [] tags: - name: Authentication description: Logon and session management paths: /logon/long: get: operationId: getLogonForm summary: Crystal Reports Get Logon Form Template description: Returns a JSON or XML template for the logon request body, showing the required fields for authentication. tags: - Authentication security: [] parameters: - $ref: '#/components/parameters/Accept' responses: '200': description: Logon form template returned successfully content: application/json: schema: $ref: '#/components/schemas/LogonRequest' application/xml: schema: $ref: '#/components/schemas/LogonRequest' x-microcks-operation: delay: 100 post: operationId: logon summary: Crystal Reports Authenticate with Username and Password description: Authenticates a user against the SAP BusinessObjects BI Platform and returns an X-SAP-LogonToken header for subsequent requests. tags: - Authentication security: [] parameters: - $ref: '#/components/parameters/Accept' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LogonRequest' application/xml: schema: $ref: '#/components/schemas/LogonRequest' responses: '200': description: Authentication successful headers: X-SAP-LogonToken: description: Session logon token enclosed in quotes schema: type: string example: '"COMMANDCOM-LCM:6400@{3&2=5697,U3&p=40623.9596541551,Y7&4F&68&z=_3P05,UP&66&UF=02twEaVJw0H1xh3KHPg3S7x.mhc0RWgGLQo1jW.aQbs5Q&42&0F=Ax3kVubd7nkS0DmUxkxGr5J"' content: application/json: schema: $ref: '#/components/schemas/LogonResponse' application/xml: schema: $ref: '#/components/schemas/LogonResponse' '401': description: Authentication failed content: application/json: schema: $ref: '#/components/schemas/Error' x-microcks-operation: delay: 200 components: schemas: Error: type: object description: Error response from the API properties: error_code: type: integer description: Numeric error code example: 401 message: type: string description: Human-readable error message example: Authentication token is missing or expired LogonResponse: type: object description: Response containing the logon token after successful authentication properties: logonToken: type: string description: Session token for subsequent API calls (include in X-SAP-LogonToken header with quotes) example: COMMANDCOM-LCM:6400@{3&2=5697,U3&p=40623.9596541551,Y7&4F&68&z=_3P05,UP&66&UF=02twEaVJw0H1xh3KHPg3S7x.mhc0RWgGLQo1jW.aQbs5Q&42&0F=Ax3kVubd7nkS0DmUxkxGr5J LogonRequest: type: object description: Logon credentials for authenticating against the BI Platform properties: userName: type: string description: Username for authentication example: Administrator password: type: string description: Password for the user account example: P@ssw0rd auth: type: string description: Authentication type to use enum: - secEnterprise - secLDAP - secWinAD - secSAPR3 example: secEnterprise required: - userName - password - auth parameters: Accept: name: Accept in: header required: false description: Desired response format schema: type: string enum: - application/json - application/xml default: application/json example: application/json securitySchemes: sapLogonToken: type: apiKey name: X-SAP-LogonToken in: header description: SAP logon token obtained from the /logon/long endpoint. The token value must be enclosed in double quotes when sent in the header. basicAuth: type: http scheme: basic description: HTTP Basic authentication as an alternative to token-based auth