openapi: 3.2.0 info: version: 2.0.0 title: Opal Services API license: name: Opal API License url: https://www.workwithopal.com/api-license description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Other API Versions\n\nThe [v3 API](/api/documentation/v3) is less complete than the v2 API, and is still a work in progress. Currently, if a resource has endpoints in both the v2 API and the v3 API you **SHOULD** use the v2 API endpoints. At some point in the future we will recommend the v3 API instead.\n\n# Documentation Organization\n\nv2 API endpoints are categorized by stability:\n\n1. JSON:API\n2. Other\n3. Unstable\n4. Proposed\n\nv2 API endpoints in the “JSON:API”, “Unstable”, and “Proposed” categories are [JSON:API](https://jsonapi.org)-compliant ([specification](https://jsonapi.org/format/)) and can be used with any [JSON:API-compliant client](https://jsonapi.org/implementations/).\n\n\n\n“Other” endpoints are stable, but do not follow the JSON:API specification. (Some “Other” endpoints have data that resembles the JSON:API structure, but **MUST** be parsed as generic JSON.) Your requests **MUST** set the `Accept` HTTP header to `application/json`, and the response’s `Content-Type` HTTP header will be `application/json`.\n\n## Unstable Endpoints\n\n*Note:* This generally refers resources in the “Unstable” category, but includes endpoints with a summary that’s prefixed by `[UNSTABLE]`. These `[UNSTABLE]` endpoints may be part of a “Stable” resource.\n\nThe data structure and behavior of “Unstable” endpoints are not guaranteed, and we **MAY** change them at any time. You **MUST NOT** use these endpoints for production features, but **MAY** use them as a preview of upcoming features, and we welcome feedback.\n\n## Proposed Endpoints\n\n“Proposed” endpoints **MUST NOT** be used (they’re not yet implemented), and we **MAY** change or remove them at any time. We publish them at our discretion to share our plans and encourage internal feedback. We also welcome your feedback.\n\n# Design Principles\n\n## Breaking Changes\n\nWe **MAY** expand the data for “JSON:API” and “Other” resources, but will not change or remove existing attributes or relationships for these resources. These expansions should not require any changes to your code.\n\nWe provide no guarantees for “Unstable” and “Proposed” endpoints.\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Roles\n#### Client\nThe 3rd-party application accessing the API on behalf of the User.\n\n#### API\nAPI endpoints used to interact with a User's resources in Opal.\n\n#### User\nThe person authorizing the Client to access to their Opal account.\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n - public\n- Application secret\n - keep this private\n - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n \"access_token\":\"ABC123\",\n \"token_type\":\"bearer\",\n \"expires_in\":3600,\n \"refresh_token\":\"DEF456\",\n \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n GET /resource HTTP/1.1\n Host: server.example.com\n Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n" servers: - url: https://login.ouropal.com tags: - name: Services paths: /services/v2: get: tags: - Services summary: Returns a list of Services operationId: ReadServicesV2 security: - oauth2: - offline_access - api_key: - Session-Token parameters: - name: include in: query required: false description: A comma separated list of related objects to include schema: type: array items: type: string enum: - accounts - asset_reference - post_types style: form explode: false - name: filter in: query description: 'Filters for limiting the results. ' required: false schema: type: object properties: brand_id: type: array description: 'The IDs of the workspaces to which results should be filtered. "Workspace ID" and "Brand ID" are synonymous. Comma separated list of IDs. If included, will only fetch resources associated with these brands. If not included, will return resources associated with all brands that the user belongs to. For example, `filter[brand_id]=1` will fetch all resources associated with brand 1, while `filter[brand_id]=1,2,3` will fetch any resources associated with brands 1, 2, or 3. Note that "standard" services common to all brands such as Facebook or Twitter will have a `null` brand_id and can be filtered as such. For example `filter[brand_id]=null` will return only standard services, and `filter[brand_id]=null,1,2` will return all standard services, plus any custom services for brands 1 and 2. ' items: oneOf: - type: string - type: integer style: deepObject explode: true - name: sort in: query description: 'A comma separated value specifying how a collection in the response body should be sorted, where each value is an attribute of the story. When specifying multiple values, each value in the sequence determines the ordering precedence. Each service in the collection will appear in ascending order, unless any of the enumerated values are prefixed with a minus "-" sign, in which case each story will appear in descending order for the specified values. If no sort parameter is provided, services will be default sorted by created_at, ascending. ' required: false schema: type: string enum: - created_at - updated_at - name: page description: Specify an offset and limit for pagination in: query required: false schema: type: object properties: limit: type: integer default: 50 offset: type: integer style: deepObject explode: true responses: '200': description: An array of services content: application/json: schema: type: object required: - data additionalProperties: false properties: data: type: array items: title: service type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - service attributes: type: object required: - color - content_name - icon_name - name - system_name - uuid - web_modules_channel additionalProperties: false properties: color: type: string description: A hex color value with leading hash symbol intact content_name: type: string description: The default name of content for this service created_at: type: string format: date-time description: An ISO8601 date-time indicating when the service was created. readOnly: true has_placements: type: - boolean - 'null' description: Indicates if the service supports placements capability icon_name: type: - string - 'null' icon_path: type: - string - 'null' is_active: type: boolean description: Indicates active status of the service is_visible: type: boolean description: Indicates visibility of the service name: type: string system_name: type: string updated_at: type: string format: date-time description: An ISO8601 date-time indicating when the service was last updated. readOnly: true uuid: type: string format: uuid web_modules_channel: type: - boolean - 'null' description: Indicates if the service is of the category "web modules" relationships: type: object required: - accounts - asset_reference - brand - post_types additionalProperties: false properties: accounts: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - account asset_reference: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - asset_reference brand: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - brand post_types: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - post_type included: type: array items: oneOf: - title: account type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - account attributes: type: object required: - name - uuid additionalProperties: false properties: name: type: string uuid: type: string format: uuid relationships: type: object required: - service - brand - dispatch_provider_account - placements additionalProperties: false properties: service: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - service brand: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - brand dispatch_provider_account: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - dispatch_provider_account placements: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - placement - title: asset_reference type: object required: - id - attributes - type - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - asset_reference attributes: type: object required: - asset_type - asset_uuid - content_type - format - filename - escaped_filename - filesize - full_url - meta_data - original_url - preview_url - public_id - width - height - uuid additionalProperties: false properties: asset_type: type: - string - 'null' description: 'This field is semi-open ended but should be set to `image`, `audio`, or `video` for those respective types of media and `file` for most other types of media. ' asset_source: type: - string - 'null' description: 'Asset Sources are pre-existing records indicating the origin of an asset reference. You can''t set this field to arbitrary values. If you know of an Asset Source and you''d like to indicate a new asset reference originated with that source, this field should contain that source''s name. ' asset_uuid: type: - string - 'null' description: 'The `id` of an `asset` resource this asset reference will surface within the Asset Library. ' content_type: type: - string - 'null' description: 'This field was used by some legacy systems. It is exposed for historical reasons. If set, setting it to the same value as `asset_type` is generally a good idea. It is not a MIME type. ' description: type: - string - 'null' format: type: - string - 'null' description: 'Used differently by some legacy systems but any new asset reference should use the `format` field to store its filetype extension (ex. `png`, `mp4`, `gif`, `mov`, etc.). ' filename: type: - string - 'null' escaped_filename: type: string readOnly: true filesize: type: - integer - 'null' description: Size of file in bytes. full_url: type: - string - 'null' description: 'When associating an asset with an asset reference, this field should be set to the `url` property of the asset. ' meta_data: type: - object - 'null' description: Can contain arbitrary key-value pairs related to the asset. properties: duration: type: string description: Parsed from video assets. page_count: type: string description: Parsed from PDF assets. processed_height: type: string description: Parsed from video assets. processed_width: type: string description: Parsed from video assets. additionalProperties: type: string original_url: type: - string - 'null' preview_url: type: - string - 'null' readOnly: true public_id: type: - string - 'null' width: type: - integer - 'null' description: 'When associating an asset with an asset reference, this field should be set to the `width` of the asset. ' height: type: - integer - 'null' description: 'When associating an asset with an asset reference, this field should be set to the `height` of the asset. ' uuid: type: string readOnly: true description: 'Use this ID when referring to the same asset reference from one of Opal''s v3 APIs. ' relationships: type: object additionalProperties: false properties: brand: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - brand stories: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - story cover_asset_reference: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - asset_reference labels: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - label asset_reference_options: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - asset_reference_option options: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - option - title: post_type type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string pattern: ^[0-9]+$ type: type: string enum: - post_type attributes: type: object required: - created_at additionalProperties: false properties: created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true is_supported: type: boolean description: Whether or not a Post Type is standard for all Opals. name: type: string description: The name of the Post Type system_name: type: string description: The unique name used to look up a Post Type updated_at: type: - string - 'null' format: date-time description: An ISO8601 date-time. readOnly: true relationships: type: object additionalProperties: false required: - brand - opal properties: brand: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - brand opal: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - opal meta: type: object required: - resource_type - total properties: resource_type: type: string total: type: integer example: data: - id: '1' type: service attributes: color: '#5CA539' content_name: Digital Advertising created_at: '2020-06-03T13:20:20.960-07:00' has_placements: true icon_name: display-ad icon_path: null is_active: true is_visible: true name: Digital Advertising system_name: digital_advertising updated_at: '2020-06-03T13:20:22.033-07:00' uuid: f649cebe-3dce-441a-8335-86707303c388 web_modules_channel: false relationships: accounts: data: - id: '1' type: account asset_reference: data: null brand: data: id: '1' type: brand post_types: data: - id: '1' type: post_type - id: '3' type: service attributes: color: '#3B5998' content_name: Facebook Post created_at: '2020-06-03T13:20:26.882-07:00' has_placements: true icon_name: facebook icon_path: M8 19v-8H6V8h2V4.706C8 2.276 8.636 1 11.338 1H14v3h-2c-1.052 0-1 1.223-1 2v2h2.762l-.456 3H11v8H8z is_active: true is_visible: true name: Facebook system_name: facebook updated_at: '2020-06-03T13:20:38.752-07:00' uuid: f649cebe-3dce-441a-8335-86707303c388 web_modules_channel: false relationships: accounts: data: [] asset_reference: data: null brand: data: null post_types: data: [] meta: total: 2 resource_type: service components: securitySchemes: oauth2: type: oauth2 description: This API uses OAuth 2.0 with the authorization code grant flow. You can find more detailed authentication instructions in the [Authentication Strategies](/api/documentation#section/Authentication-Strategies/OAuth-2.0) section. flows: authorizationCode: authorizationUrl: /oauth2/auth tokenUrl: /oauth2/token scopes: offline_access: Include this scope if you wish to receive a refresh token api_key: type: apiKey description: (Deprecated) This API also supports authentication via an API or session token set in the request headers. in: header name: Session-Token x-tagGroups: - name: JSON:API tags: - Accounts - Activities - Annotations - Asset Reference Options - Asset Reference Usage Rights Options - Asset References - Assets - Brand Settings - Brands - Checkpoints - Content - Delivery Records - Label Sets - Labels - Messages - Moments - Phase Items - Placements - Post Types - Privacy - Reactions - Rich Texts - Services - Stamps - Stories - Url Uploads - User Domain Views - Users - Workflows - name: Other tags: - Budgets - URL Previews - Search - Stories V1 - name: ⚠️ Unstable tags: [] - name: Additional Resources tags: - secondary_resources