openapi: 3.2.0 info: version: 2.0.0 title: Opal Labels API license: name: Opal API License url: https://www.workwithopal.com/api-license description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Other API Versions\n\nThe [v3 API](/api/documentation/v3) is less complete than the v2 API, and is still a work in progress. Currently, if a resource has endpoints in both the v2 API and the v3 API you **SHOULD** use the v2 API endpoints. At some point in the future we will recommend the v3 API instead.\n\n# Documentation Organization\n\nv2 API endpoints are categorized by stability:\n\n1. JSON:API\n2. Other\n3. Unstable\n4. Proposed\n\nv2 API endpoints in the “JSON:API”, “Unstable”, and “Proposed” categories are [JSON:API](https://jsonapi.org)-compliant ([specification](https://jsonapi.org/format/)) and can be used with any [JSON:API-compliant client](https://jsonapi.org/implementations/).\n\n\n\n“Other” endpoints are stable, but do not follow the JSON:API specification. (Some “Other” endpoints have data that resembles the JSON:API structure, but **MUST** be parsed as generic JSON.) Your requests **MUST** set the `Accept` HTTP header to `application/json`, and the response’s `Content-Type` HTTP header will be `application/json`.\n\n## Unstable Endpoints\n\n*Note:* This generally refers resources in the “Unstable” category, but includes endpoints with a summary that’s prefixed by `[UNSTABLE]`. These `[UNSTABLE]` endpoints may be part of a “Stable” resource.\n\nThe data structure and behavior of “Unstable” endpoints are not guaranteed, and we **MAY** change them at any time. You **MUST NOT** use these endpoints for production features, but **MAY** use them as a preview of upcoming features, and we welcome feedback.\n\n## Proposed Endpoints\n\n“Proposed” endpoints **MUST NOT** be used (they’re not yet implemented), and we **MAY** change or remove them at any time. We publish them at our discretion to share our plans and encourage internal feedback. We also welcome your feedback.\n\n# Design Principles\n\n## Breaking Changes\n\nWe **MAY** expand the data for “JSON:API” and “Other” resources, but will not change or remove existing attributes or relationships for these resources. These expansions should not require any changes to your code.\n\nWe provide no guarantees for “Unstable” and “Proposed” endpoints.\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Roles\n#### Client\nThe 3rd-party application accessing the API on behalf of the User.\n\n#### API\nAPI endpoints used to interact with a User's resources in Opal.\n\n#### User\nThe person authorizing the Client to access to their Opal account.\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n - public\n- Application secret\n - keep this private\n - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n \"access_token\":\"ABC123\",\n \"token_type\":\"bearer\",\n \"expires_in\":3600,\n \"refresh_token\":\"DEF456\",\n \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n GET /resource HTTP/1.1\n Host: server.example.com\n Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n" servers: - url: https://login.ouropal.com tags: - name: Labels description: '## Labels Overview In Opal, Labels are a useful way of categorizing resources to be filtered or grouped. ### Label Inheritance Labels follow StoryFirst inheritance rules. This means that **Content** inherits labels from **Moment** which inherits labels from **Story**. **Content** also inherits labels from the selected **Account**. If a **Moment** belongs to more than one **Story**, labels are inherited from all related stories (i.e. the labels inherited comprise the union of the labels for each story). For example: ![Label Inheritance](/api/documentation/static/svg/label_inheritance) Inheritance is "broken" when one or more labels is explicitly set directly on a resource. For example, if you set the labels _x_ and _y_ for a piece of **Content**, that content will then only be considered to have exactly the labels _x_ and _y_ and no longer the labels of its parent **Moment** or **Story** (or associated **Account**). The default behavior of the Opal Web frontend is actually such that when **Content** gets explicit direct labels, it takes on all existing inherited labels _and_ the new direct labels, but it does not gain new inherited labels going forward. This behavior is achieved by requesting all of the current labels for that **Content** and then explicitly setting the new labels to all existing inherited labels plus the new labels. ![Broken Label Inheritance at Content](/api/documentation/static/svg/label_inheritance_broken) Inheritance can also be broken by explicitly setting labels on a **Moment**. Using our _x_ and _y_ labels again: ![Broken Label Inheritance at Moment](/api/documentation/static/svg/label_inheritance_broken_at_moment) Notice that **Content** still inherits from **Moment** and **Account** even when **Moment** stops inheriting from **Story**. ' paths: /labels/v2: get: tags: - Labels operationId: ReadLabelsV2 summary: Find labels for a Workspace. description: 'Note that this endpoint supports both a deprecated and new representation of pagination in the query parameters of requests. Going forward, you should use the `page[offset]` and `page[limit]` query parameters to indicate what "page" of results you would like. ' security: - oauth2: - offline_access - api_key: - Session-Token parameters: - name: brand_id in: query required: true description: The ID of the workspace/brand. schema: type: string - name: label_set_id in: query required: false description: Filter labels by label set ID. schema: type: string - name: page in: query required: false description: 'Request a particular page using `offset` and `limit`. When not specified, the `offset` defaults to 0 and the `limit` defaults to 150. **Deprecated** usage (as a string value): The page number being requested. This should should be used in conjunction with per_page. For example, if there are 50 records, a user can request all of them in two requests by requesting `?page=1&per_page=25` and `?page=2&per_page=25`. ' schema: oneOf: - type: string title: page number (deprecated) - type: object title: offset & limit properties: offset: type: integer minimum: 0 limit: type: integer minimum: 0 maximum: 800 style: deepObject explode: true - name: per_page in: query required: false deprecated: true description: The number of results being requested per page. schema: type: string - name: include in: query required: false description: A comma separated list of related objects to include schema: type: array items: type: string enum: - label_set style: form explode: false responses: '200': description: A collection of labels. content: application/json: schema: type: object required: - data properties: data: type: array items: title: label type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label attributes: type: object required: - name - color - is_active - uuid additionalProperties: false properties: name: type: string description: The label's name. This value must be unique within the label's label set. uuid: type: string format: uuid description: A unique identifier for the label. color: type: string description: The label's color. A hex color code without the '#' prefix. The color is settable on any non-shared label set, but today it is only rendered by the Opal platform when the label belongs to the workspace's primary label set. Broader rendering across non-primary label sets is upcoming. is_active: type: boolean description: Enable or disable this label. Note that this is different than deleting and it is probably generally advisable to set is_active to false rather than deleting a label because deactivating can be undone via the API. position: type: integer description: By default, the label position is not used and labels are sorted by creation date from oldest to newest. By request, Opal employees can set the sort order of labels within any label set to be `manual` which causes the labels to be sorted by their `position` instead. relationships: type: object additionalProperties: false properties: label_set: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label_set included: type: array items: oneOf: - title: label_set type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label_set attributes: type: object required: - name - label_sort_method - is_active - is_shared - uuid additionalProperties: false properties: name: type: string uuid: type: string format: uuid description: A unique identifier for the label set. is_active: type: boolean description: 'Determines whether the label set will be available to use in the Opal platform. Note that inactive label sets are only even exposed via API when specifically filtered for. ' is_shared: type: boolean description: 'True when the label set is shared across workspaces. ' label_sort_method: type: string default: oldest_first enum: - alphabetical - newest_first - oldest_first - manual relationships: type: object required: - labels - paired_custom_field - parent_label additionalProperties: false properties: labels: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label paired_custom_field: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - custom_field parent_label: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label meta: type: object required: - total - page - resource_type properties: resource_type: type: string total: type: integer page: type: object required: - limit - offset properties: limit: type: integer offset: type: integer example: data: - id: '593363174' type: label attributes: uuid: dc68d20c-3dd9-48f0-a8c5-8dd7b170ba99 id: 593363174 is_active: true name: Rock color: b2cb19 relationships: label_set: data: id: '593363174' type: label_set meta: total: 1 resource_type: label page: offset: 0 limit: 100 '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status post: tags: - Labels operationId: CreateLabelV2 summary: Create a new label. security: - oauth2: - offline_access - api_key: - Session-Token requestBody: content: application/json: schema: type: object required: - data properties: data: type: object required: - type - attributes - relationships properties: type: type: string enum: - label attributes: type: object required: - name properties: name: type: string description: The label's name. This value must be unique within the label's label set. minLength: 1 maxLength: 50 color: type: string description: The label's color. A hex color code without the '#' prefix. This color is only used by the Opal platform if the label is in its workspace's primary label set. If you omit a color when creating a label in the primary label set, a color will be selected by Opal. position: type: integer description: By default, the label position is not used and labels are sorted by creation date from oldest to newest. By request, Opal employees can set the sort order of labels within any label set to be `manual` which causes the labels to be sorted by their `position` instead. relationships: type: object required: - label_set properties: label_set: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label_set responses: '201': description: A newly created label resource. content: application/json: schema: type: object required: - data properties: data: title: label type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label attributes: type: object required: - name - color - is_active - uuid additionalProperties: false properties: name: type: string description: The label's name. This value must be unique within the label's label set. uuid: type: string format: uuid description: A unique identifier for the label. color: type: string description: The label's color. A hex color code without the '#' prefix. The color is settable on any non-shared label set, but today it is only rendered by the Opal platform when the label belongs to the workspace's primary label set. Broader rendering across non-primary label sets is upcoming. is_active: type: boolean description: Enable or disable this label. Note that this is different than deleting and it is probably generally advisable to set is_active to false rather than deleting a label because deactivating can be undone via the API. position: type: integer description: By default, the label position is not used and labels are sorted by creation date from oldest to newest. By request, Opal employees can set the sort order of labels within any label set to be `manual` which causes the labels to be sorted by their `position` instead. relationships: type: object additionalProperties: false properties: label_set: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label_set included: type: array items: oneOf: - title: label_set type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label_set attributes: type: object required: - name - label_sort_method - is_active - is_shared - uuid additionalProperties: false properties: name: type: string uuid: type: string format: uuid description: A unique identifier for the label set. is_active: type: boolean description: 'Determines whether the label set will be available to use in the Opal platform. Note that inactive label sets are only even exposed via API when specifically filtered for. ' is_shared: type: boolean description: 'True when the label set is shared across workspaces. ' label_sort_method: type: string default: oldest_first enum: - alphabetical - newest_first - oldest_first - manual relationships: type: object required: - labels - paired_custom_field - parent_label additionalProperties: false properties: labels: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label paired_custom_field: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - custom_field parent_label: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '409': description: Conflict content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status /labels/v2/{label_id}: patch: tags: - Labels operationId: UpdateLabelV2 summary: Update a label. description: This action can only be performed by admin users. security: - oauth2: - offline_access - api_key: - Session-Token parameters: - name: label_id in: path required: true description: The ID of the label. schema: type: string requestBody: content: application/json: schema: type: object required: - data properties: data: type: object required: - id - type - attributes - relationships properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label attributes: type: object properties: name: type: string description: The label's name. This value must be unique within the label's label set. minLength: 1 maxLength: 50 color: type: string description: The label's color. A hex color code without the '#' prefix. This color is only used by the Opal platform if the label is in its workspace's primary label set. is_active: type: boolean description: Enable or disable this label. Note that this is different than deleting and it is probably generally advisable to set is_active to false rather than deleting a label because deactivating can be undone via the API. position: type: integer description: By default, the label position is not used and labels are sorted by creation date from oldest to newest. By request, Opal employees can set the sort order of labels within any label set to be `manual` which causes the labels to be sorted by their `position` instead. relationships: type: object required: - label_set properties: label_set: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label_set responses: '201': description: A newly created label resource. content: application/json: schema: type: object required: - data properties: data: title: label type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label attributes: type: object required: - name - color - is_active - uuid additionalProperties: false properties: name: type: string description: The label's name. This value must be unique within the label's label set. uuid: type: string format: uuid description: A unique identifier for the label. color: type: string description: The label's color. A hex color code without the '#' prefix. The color is settable on any non-shared label set, but today it is only rendered by the Opal platform when the label belongs to the workspace's primary label set. Broader rendering across non-primary label sets is upcoming. is_active: type: boolean description: Enable or disable this label. Note that this is different than deleting and it is probably generally advisable to set is_active to false rather than deleting a label because deactivating can be undone via the API. position: type: integer description: By default, the label position is not used and labels are sorted by creation date from oldest to newest. By request, Opal employees can set the sort order of labels within any label set to be `manual` which causes the labels to be sorted by their `position` instead. relationships: type: object additionalProperties: false properties: label_set: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label_set included: type: array items: oneOf: - title: label_set type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - label_set attributes: type: object required: - name - label_sort_method - is_active - is_shared - uuid additionalProperties: false properties: name: type: string uuid: type: string format: uuid description: A unique identifier for the label set. is_active: type: boolean description: 'Determines whether the label set will be available to use in the Opal platform. Note that inactive label sets are only even exposed via API when specifically filtered for. ' is_shared: type: boolean description: 'True when the label set is shared across workspaces. ' label_sort_method: type: string default: oldest_first enum: - alphabetical - newest_first - oldest_first - manual relationships: type: object required: - labels - paired_custom_field - parent_label additionalProperties: false properties: labels: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label paired_custom_field: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - custom_field parent_label: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '409': description: Conflict content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status delete: tags: - Labels operationId: DeleteLabelV2 summary: Delete a label. description: 'This action can only be performed by an admin user, and cannot be undone via the API. It is generally preferable to deactivate a label by sending a `PATCH` request that sets the label''s `is_active` field to `false`. ' security: - oauth2: - offline_access - api_key: - Session-Token parameters: - name: label_id in: path required: true description: The ID of the label. schema: type: string responses: '204': description: The label was successfully deleted. '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string title: type: string detail: type: string required: - status components: securitySchemes: oauth2: type: oauth2 description: This API uses OAuth 2.0 with the authorization code grant flow. You can find more detailed authentication instructions in the [Authentication Strategies](/api/documentation#section/Authentication-Strategies/OAuth-2.0) section. flows: authorizationCode: authorizationUrl: /oauth2/auth tokenUrl: /oauth2/token scopes: offline_access: Include this scope if you wish to receive a refresh token api_key: type: apiKey description: (Deprecated) This API also supports authentication via an API or session token set in the request headers. in: header name: Session-Token x-tagGroups: - name: JSON:API tags: - Accounts - Activities - Annotations - Asset Reference Options - Asset Reference Usage Rights Options - Asset References - Assets - Brand Settings - Brands - Checkpoints - Content - Delivery Records - Label Sets - Labels - Messages - Moments - Phase Items - Placements - Post Types - Privacy - Reactions - Rich Texts - Services - Stamps - Stories - Url Uploads - User Domain Views - Users - Workflows - name: Other tags: - Budgets - URL Previews - Search - Stories V1 - name: ⚠️ Unstable tags: [] - name: Additional Resources tags: - secondary_resources