openapi: 3.2.0 info: version: 3.0.0 title: Opal API (⚠️ WIP) User Groups API license: name: Opal API License url: https://www.workwithopal.com/api-license description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Other API Versions\n\nThe [v2 API](/api/documentation/v2) is more complete than the v3 API. Currently, if a resource has endpoints in both the v2 API and the v3 API you **SHOULD** use the v2 API endpoints. At some point in the future we will recommend the v3 API instead.\n\n*Note:* Endpoints will be added to the v3 API as needed, and we will continue to support all v2 API endpoints in the “JSON:API” and “Other” categories, even if we add an equivalent v3 API endpoint.\n\n# Key differences between v2 and v3 APIs\n\n## Resource Identifiers\n\nThe v3 API uses a different format for primary resource identifiers than the v2 API. Responses from v3 API endpoints include the resource’s v2 API id in the `attributes.legacy_id` field, in case you need to use both API versions. (v2 API resource identifiers are generally integers, but v2 API endpoints **MAY** use a different format.)\n\n*Note:* These are opaque strings, and you **MUST NOT** rely on the structure. Currently newly-created resources have a UUIDv4 identifier, but this behavior **MAY** change at any time. Existing identifiers will not be affected.\n\n# Documentation Organization\n\nv3 API endpoints are categorized by stability:\n\n1. Stable\n2. Unstable\n3. Proposed\n4. Experimental\n\nAll v3 API endpoints are [JSON:API](https://jsonapi.org)-compliant ([specification](https://jsonapi.org/format/)) and can be used with any [JSON:API-compliant client](https://jsonapi.org/implementations/).\n\nYour requests **MUST** set the `Accept` HTTP header to `application/vnd.api+json`. The server response’s `Content-Type` HTTP header will also be `application/vnd.api+json`.\n\n## Unstable Endpoints\n\n*Note:* This generally refers resources in the “Unstable” category, but includes endpoints with a summary that’s prefixed by `[UNSTABLE]`. These `[UNSTABLE]` endpoints may be part of a “Stable” resource.\n\nThe data structure and behavior of “Unstable” endpoints are not guaranteed, and we **MAY** change them at any time. You **MUST NOT** use these endpoints for production features, but **MAY** use them as a preview of upcoming features, and we welcome feedback.\n\n## Proposed Endpoints\n\n“Proposed” endpoints **MUST NOT** be used (they’re not yet implemented), and we **MAY** change or remove them at any time. We publish them at our discretion to share our plans and encourage internal feedback. We also welcome your feedback.\n\n# Design Principles\n\n## Breaking Changes\n\nWe **MAY** expand the data for “Stable” resources, but will not change or remove existing attributes or relationships for these resources. These expansions should not require any changes to your code.\n\nWe provide no guarantees for “Unstable,” \"Experimental,\" or “Proposed” endpoints.\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Roles\n#### Client\nThe 3rd-party application accessing the API on behalf of the User.\n\n#### API\nAPI endpoints used to interact with a User's resources in Opal.\n\n#### User\nThe person authorizing the Client to access to their Opal account.\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n - public\n- Application secret\n - keep this private\n - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n \"access_token\":\"ABC123\",\n \"token_type\":\"bearer\",\n \"expires_in\":3600,\n \"refresh_token\":\"DEF456\",\n \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n GET /resource HTTP/1.1\n Host: server.example.com\n Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n" servers: - url: https://login.ouropal.com tags: - name: User Groups paths: /user_groups/v3/user_groups: get: tags: - User Groups operationId: ReadUserGroupsV3 summary: Get User Groups available to the authenticated user. security: - oauth2: - offline_access - api_key: [] parameters: - name: filter in: query description: Filters for limiting the results. required: false schema: type: object properties: id: type: array items: type: string format: uuid description: Comma-separated list of User Group IDs. Limits results to user groups whose IDs are in the provided list. opal_id: type: string format: uuid description: If specified, this parameter must match the v3 ID of the Opal that the authenticated user belongs to. name: type: string description: Limits results to user groups whose name contains a substring of the provided term. members: type: object properties: workspace_id: type: array items: type: string format: uuid description: 'Comma-separated list of workspace IDs. Filters group members to those that belong to the specified workspaces. Uses syntax `filter[members][workspace_id]=798ac6d9-b3fc-4155-88ee-237f43f3404b,d79e513e-9246-454e-80bf-8268bc39cd6e`. ' system_generated: type: boolean description: '(internal-use only) Optionally exclude system-generated user groups by setting this to `false`. ' is_archived: type: boolean description: 'Filter user groups by archived status. Set to `false` to exclude archived groups, or `true` to include only archived groups. ' external_resource: type: object description: '(internal-use only) Filters results to system-generated groups which represent the type and/or ID(s) of these external resources. ' required: - type properties: id: type: array items: type: string format: uuid type: type: string style: deepObject explode: true - name: include in: query required: false description: A comma separated value of related objects to include. schema: type: array items: type: string enum: - asset - members - created_by - inherited_groups style: form explode: false - name: expose in: query required: false description: 'Optionally calculated user groups metadata which are not part of responses by default. You request that metadata be included in responses with the `expose` query parameter like: `?expose[user_group][meta]` or more granularly `?expose[user_group][meta][effective_member_users]`. ' style: deepObject explode: true schema: type: object additionalProperties: false properties: user_group: type: object additionalProperties: false properties: meta: type: object properties: effective_member_users: type: - string - 'null' description: 'Expose the effective member users of the group. This includes direct membership on the group as well as membership to any groups that are inherited from recursively. Use this parameter as: `?expose[user_group][meta][effective_member_users]` ' responses: '200': description: A collection of User Groups. content: application/json: schema: type: object required: - data properties: data: type: array items: title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group included: type: array items: oneOf: - title: asset type: object required: - id - type - attributes - links - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset attributes: type: object required: - bytes - created_at - download_url_override - duration - file_extension - file_name - height - mime_type - updated_at - url - width additionalProperties: false properties: url: type: string download_url_override: type: - string - 'null' description: 'An alternative download URL for the file. If set, downloading the asset will result in a redirect to the overridden location instead of downloading the asset data directly. When not present, `url` should be used. ' width: type: - integer - 'null' description: When applicable, the width in pixels of an image or video. height: type: - integer - 'null' description: When applicable, the height in pixels of an image or video. duration: type: - integer - 'null' description: When applicable, the play time of a video in seconds. pages: type: - integer - 'null' description: When applicable, the number of pages in a PDF document. mime_type: type: string description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types/Common_types) that corresponds to the uploaded file. file_name: type: string file_extension: type: string bytes: type: integer description: The size of the file in bytes. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri relationships: required: - opal type: object additionalProperties: false properties: opal: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - opal - title: user type: object required: - id - type - attributes - relationships - links additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user meta: type: - object - 'null' description: Metadata around the User object properties: workspace_approval_counts: type: object description: Object representing the user's unseen approval counts per Workspace Id. attributes: type: object required: - created_at - email - first_name - full_name - is_active - last_name - title - transliterated_full_name - updated_at - legacy_id additionalProperties: false properties: created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true email: type: string first_name: type: string full_name: type: string is_active: type: - boolean - 'null' last_name: type: string role_name: type: string title: type: - string - 'null' transliterated_full_name: type: string feature_flags: type: object additionalProperties: type: boolean description: 'A named feature flag and `true` or `false` depending on whether the feature is enabled for the user or not. ' description: 'List of Feature Flags for this user, only available for the currently authenticated User. ' updated_at: type: string format: date-time description: An ISO8601 date-time indicating when the user was last updated. readOnly: true legacy_id: type: string description: An ID that can be used with `v2` APIs. relationships: type: object required: - profile - workspaces additionalProperties: false properties: profile: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_profile workspaces: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - workspace links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri - title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group example: data: - id: d76701b0-8e7f-4d71-aede-13b486468ff4 type: user_group attributes: name: foo description: bar is_archived: false external_resource_type: null created_at: '2020-09-11T15:27:01.881-08:00' updated_at: '2020-09-11T15:27:01.881-08:00' relationships: members: data: - id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user asset: data: id: 31d040a3-c4e1-4580-ba28-1251167ee95a type: asset created_by_user: data: id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user external_resource: data: null inherited_groups: data: [] '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status post: tags: - User Groups operationId: CreateUserGroupV3 summary: Create a new User Group. security: - oauth2: - offline_access - api_key: [] requestBody: content: application/json: schema: type: object required: - data properties: data: type: object required: - type - attributes - relationships properties: type: type: string enum: - user_group attributes: type: object required: - name properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_system_generated: type: boolean description: 'Writing this attribute is only allowed for internal Opal clients. ' external_resource_type: type: - string - 'null' description: 'Writing this attribute is only allowed for internal Opal clients, and furthermore is only permitted for system-generated groups. When creating a system-generated group, this attribute must be set to the name of the resource it represents, along with the `external_resource` relationship. ' relationships: type: object properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset opal: description: 'For internal use only; attempting to set this relationship will result in a `forbidden` error. ' type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - opal created_by_user: description: 'For internal use only; attempting to set this relationship will result in a `forbidden` error. ' title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user external_resource: allOf: - description: 'Writing this relationship is only allowed for internal Opal clients, and furthermore is only permitted for system-generated groups. When creating a system-generated group, this relationship must be set to the ID of the resource it represents, along with the `external_resource_type` attribute. ' - type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group responses: '201': description: A newly created User Group resource. content: application/json: schema: type: object required: - data properties: data: title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group included: type: array items: oneOf: - title: asset type: object required: - id - type - attributes - links - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset attributes: type: object required: - bytes - created_at - download_url_override - duration - file_extension - file_name - height - mime_type - updated_at - url - width additionalProperties: false properties: url: type: string download_url_override: type: - string - 'null' description: 'An alternative download URL for the file. If set, downloading the asset will result in a redirect to the overridden location instead of downloading the asset data directly. When not present, `url` should be used. ' width: type: - integer - 'null' description: When applicable, the width in pixels of an image or video. height: type: - integer - 'null' description: When applicable, the height in pixels of an image or video. duration: type: - integer - 'null' description: When applicable, the play time of a video in seconds. pages: type: - integer - 'null' description: When applicable, the number of pages in a PDF document. mime_type: type: string description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types/Common_types) that corresponds to the uploaded file. file_name: type: string file_extension: type: string bytes: type: integer description: The size of the file in bytes. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri relationships: required: - opal type: object additionalProperties: false properties: opal: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - opal - title: user type: object required: - id - type - attributes - relationships - links additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user meta: type: - object - 'null' description: Metadata around the User object properties: workspace_approval_counts: type: object description: Object representing the user's unseen approval counts per Workspace Id. attributes: type: object required: - created_at - email - first_name - full_name - is_active - last_name - title - transliterated_full_name - updated_at - legacy_id additionalProperties: false properties: created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true email: type: string first_name: type: string full_name: type: string is_active: type: - boolean - 'null' last_name: type: string role_name: type: string title: type: - string - 'null' transliterated_full_name: type: string feature_flags: type: object additionalProperties: type: boolean description: 'A named feature flag and `true` or `false` depending on whether the feature is enabled for the user or not. ' description: 'List of Feature Flags for this user, only available for the currently authenticated User. ' updated_at: type: string format: date-time description: An ISO8601 date-time indicating when the user was last updated. readOnly: true legacy_id: type: string description: An ID that can be used with `v2` APIs. relationships: type: object required: - profile - workspaces additionalProperties: false properties: profile: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_profile workspaces: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - workspace links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri - title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group example: data: id: d76701b0-8e7f-4d71-aede-13b486468ff4 type: user_group attributes: name: foo description: bar is_archived: false external_resource_type: null created_at: '2020-09-11T15:27:01.881-08:00' updated_at: '2020-09-11T15:27:01.881-08:00' relationships: members: data: - id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user asset: data: id: 31d040a3-c4e1-4580-ba28-1251167ee95a type: asset created_by_user: data: id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user external_resource: data: null inherited_groups: data: [] '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: 'May also contain a `code` indicating additional context: - "member_no_access": one or more of the members being associated with the group in the request cannot access the user group. - "group_unmodifiable": the group cannot be modified by the client. - "no_edit_permission": the user lacks sufficient permissions to edit the user group. ' '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '409': description: Conflict content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status /user_groups/v3/user_groups/{user_group_id}: get: tags: - User Groups operationId: ReadUserGroupV3 summary: Get a User Group security: - oauth2: - offline_access - api_key: [] parameters: - name: user_group_id in: path required: true description: The ID of the User Group. schema: type: string format: uuid - name: filter in: query description: Filters for limiting the results. required: false schema: type: object properties: external_resource: type: object description: '(internal-use only) Filters results to system-generated groups which represent the type of these external resources. ' required: - type properties: id: type: string type: type: string members: type: object properties: workspace_id: type: array items: type: string format: uuid description: 'Comma-separated list of workspace IDs. Filters group members to those that belong to the specified workspaces. Uses syntax `filter[members][workspace_id]=798ac6d9-b3fc-4155-88ee-237f43f3404b,d79e513e-9246-454e-80bf-8268bc39cd6e`. ' style: deepObject explode: true - name: include in: query required: false description: A comma separated value of related objects to include. schema: type: array items: type: string enum: - asset - members - created_by - inherited_groups style: form explode: false - name: expose in: query required: false description: 'Optionally calculated user groups metadata which are not part of responses by default. You request that metadata be included in responses with the `expose` query parameter like: `?expose[user_group][meta]` or more granularly `?expose[user_group][meta][effective_member_users]`. ' style: deepObject explode: true schema: type: object additionalProperties: false properties: user_group: type: object additionalProperties: false properties: meta: type: object properties: effective_member_users: type: - string - 'null' description: 'Expose the effective member users of the group. This includes direct membership on the group as well as membership to any groups that are inherited from recursively. Use this parameter as: `?expose[user_group][meta][effective_member_users]` ' responses: '200': description: A single User Group content: application/json: schema: type: object required: - data properties: data: title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group included: type: array items: oneOf: - title: asset type: object required: - id - type - attributes - links - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset attributes: type: object required: - bytes - created_at - download_url_override - duration - file_extension - file_name - height - mime_type - updated_at - url - width additionalProperties: false properties: url: type: string download_url_override: type: - string - 'null' description: 'An alternative download URL for the file. If set, downloading the asset will result in a redirect to the overridden location instead of downloading the asset data directly. When not present, `url` should be used. ' width: type: - integer - 'null' description: When applicable, the width in pixels of an image or video. height: type: - integer - 'null' description: When applicable, the height in pixels of an image or video. duration: type: - integer - 'null' description: When applicable, the play time of a video in seconds. pages: type: - integer - 'null' description: When applicable, the number of pages in a PDF document. mime_type: type: string description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types/Common_types) that corresponds to the uploaded file. file_name: type: string file_extension: type: string bytes: type: integer description: The size of the file in bytes. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri relationships: required: - opal type: object additionalProperties: false properties: opal: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - opal - title: user type: object required: - id - type - attributes - relationships - links additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user meta: type: - object - 'null' description: Metadata around the User object properties: workspace_approval_counts: type: object description: Object representing the user's unseen approval counts per Workspace Id. attributes: type: object required: - created_at - email - first_name - full_name - is_active - last_name - title - transliterated_full_name - updated_at - legacy_id additionalProperties: false properties: created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true email: type: string first_name: type: string full_name: type: string is_active: type: - boolean - 'null' last_name: type: string role_name: type: string title: type: - string - 'null' transliterated_full_name: type: string feature_flags: type: object additionalProperties: type: boolean description: 'A named feature flag and `true` or `false` depending on whether the feature is enabled for the user or not. ' description: 'List of Feature Flags for this user, only available for the currently authenticated User. ' updated_at: type: string format: date-time description: An ISO8601 date-time indicating when the user was last updated. readOnly: true legacy_id: type: string description: An ID that can be used with `v2` APIs. relationships: type: object required: - profile - workspaces additionalProperties: false properties: profile: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_profile workspaces: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - workspace links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri - title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group example: data: id: d76701b0-8e7f-4d71-aede-13b486468ff4 type: user_group attributes: name: foo description: bar is_archived: false external_resource_type: null created_at: '2020-09-11T15:27:01.881-08:00' updated_at: '2020-09-11T15:27:01.881-08:00' relationships: members: data: - id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user asset: data: id: 31d040a3-c4e1-4580-ba28-1251167ee95a type: asset created_by_user: data: id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user external_resource: data: null inherited_groups: data: [] '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: Forbidden content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status patch: tags: - User Groups operationId: UpdateUserGroupV3 summary: Update an existing User Group. security: - oauth2: - offline_access - api_key: [] parameters: - name: user_group_id in: path required: true description: The ID of the User Group. schema: type: string format: uuid requestBody: content: application/json: schema: type: object required: - data properties: data: type: object required: - id - type - attributes - relationships properties: id: type: string format: uuid type: type: string enum: - user_group attributes: type: object properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' relationships: type: object properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group responses: '200': description: An updated user group resource. content: application/json: schema: type: object required: - data properties: data: title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group included: type: array items: oneOf: - title: asset type: object required: - id - type - attributes - links - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset attributes: type: object required: - bytes - created_at - download_url_override - duration - file_extension - file_name - height - mime_type - updated_at - url - width additionalProperties: false properties: url: type: string download_url_override: type: - string - 'null' description: 'An alternative download URL for the file. If set, downloading the asset will result in a redirect to the overridden location instead of downloading the asset data directly. When not present, `url` should be used. ' width: type: - integer - 'null' description: When applicable, the width in pixels of an image or video. height: type: - integer - 'null' description: When applicable, the height in pixels of an image or video. duration: type: - integer - 'null' description: When applicable, the play time of a video in seconds. pages: type: - integer - 'null' description: When applicable, the number of pages in a PDF document. mime_type: type: string description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types/Common_types) that corresponds to the uploaded file. file_name: type: string file_extension: type: string bytes: type: integer description: The size of the file in bytes. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri relationships: required: - opal type: object additionalProperties: false properties: opal: type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - opal - title: user type: object required: - id - type - attributes - relationships - links additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user meta: type: - object - 'null' description: Metadata around the User object properties: workspace_approval_counts: type: object description: Object representing the user's unseen approval counts per Workspace Id. attributes: type: object required: - created_at - email - first_name - full_name - is_active - last_name - title - transliterated_full_name - updated_at - legacy_id additionalProperties: false properties: created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true email: type: string first_name: type: string full_name: type: string is_active: type: - boolean - 'null' last_name: type: string role_name: type: string title: type: - string - 'null' transliterated_full_name: type: string feature_flags: type: object additionalProperties: type: boolean description: 'A named feature flag and `true` or `false` depending on whether the feature is enabled for the user or not. ' description: 'List of Feature Flags for this user, only available for the currently authenticated User. ' updated_at: type: string format: date-time description: An ISO8601 date-time indicating when the user was last updated. readOnly: true legacy_id: type: string description: An ID that can be used with `v2` APIs. relationships: type: object required: - profile - workspaces additionalProperties: false properties: profile: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_profile workspaces: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - workspace links: type: object additionalProperties: false required: - v2_request properties: v2_request: type: string format: uri - title: user_group type: object required: - id - type - attributes - relationships additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group meta: type: - object - 'null' description: 'Optionally calculated user_group metadata that is not part of responses by default. ' additionalProperties: false properties: effective_member_users: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user attributes: type: object required: - name - created_at - updated_at additionalProperties: false properties: name: type: string description: The display name which will appear in the Opal application UI where used. description: type: - string - 'null' description: A plain text description of the user group. is_archived: type: boolean description: 'A true/false value indicating whether this user group is available for use within the Opal application. Note that this is separate from deleting the user group. ' external_resource_type: type: - string - 'null' description: (internal-use only) For system-generated groups, the type of the resource that it represents. created_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true updated_at: type: string format: date-time description: An ISO8601 date-time. readOnly: true relationships: required: - created_by_user - members - inherited_groups type: object additionalProperties: false properties: asset: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - asset external_resource: type: object required: - data additionalProperties: false properties: data: type: - object - 'null' required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - external_resource members: type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user created_by_user: title: User type: object required: - data additionalProperties: false properties: data: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user inherited_groups: allOf: - description: "These are groups whose members should be considered part of this group.\n\nIMPORTANT: This relationship cannot be set by third party clients yet. It \nis currently used internally and is safe to reason about, but editing will\nproduce a bad request error.\n" - type: object required: - data additionalProperties: false properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string format: uuid type: type: string enum: - user_group example: data: id: d76701b0-8e7f-4d71-aede-13b486468ff4 type: user_group attributes: name: foo description: bar is_archived: false external_resource_type: null created_at: '2020-09-11T15:27:01.881-08:00' updated_at: '2020-09-11T15:27:01.881-08:00' relationships: members: data: - id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user asset: data: id: 31d040a3-c4e1-4580-ba28-1251167ee95a type: asset created_by_user: data: id: 4eea039c-3f5d-4f2d-baa3-126b2933a024 type: user external_resource: data: null inherited_groups: data: [] '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: 'May also contain a `code` indicating additional context: - "member_no_access": one or more of the members being associated with the group in the request cannot access the user group. - "group_unmodifiable": the group cannot be modified by the client. - "no_edit_permission": the user lacks sufficient permissions to edit the user group. ' content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '409': description: Conflict content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status delete: tags: - User Groups operationId: DeleteUserGroupV3 summary: Delete a User Group description: 'Default behavior is **soft-delete**: sets `deleted_at` and tears down SpiceDB `member` and `inherited_group` relations so downstream resources stop inheriting access through it. The Postgres row, group members, and the `opal` SpiceDB relation are preserved for potential restoration. Pass `destroy=true` (internal-only, privileged clients only) to hard-delete the row entirely. Used by transactional-rollback paths where the resource that owned the group failed to create and a soft-deleted orphan would block retries via uniqueness constraints. ' security: - oauth2: - offline_access - api_key: [] parameters: - name: user_group_id in: path required: true description: The ID of the User Group. schema: type: string format: uuid - name: destroy in: query required: false description: 'When `true`, hard-deletes the row instead of soft-deleting. Internal rollback use only. ' schema: type: boolean default: false responses: '204': description: 'The User Group was successfully deleted. Soft-delete by default; hard-delete when `destroy=true` and the client is privileged. ' '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: 'Returned when `destroy=true` is passed by a non-internal client. The hard-delete branch is reserved for internal clients (Loupe, Monolith) performing transactional rollback; admins are restricted to the default soft-delete behavior. ' content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '404': description: Not found content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status /user_groups/v3/user_groups/all/relationships/members: delete: tags: - User Groups operationId: DeleteUserGroupMembersV3 summary: Delete all User Group Members for User description: '[Internal Only] Deletes the given user from all groups. ' security: - oauth2: - offline_access - api_key: [] requestBody: content: application/json: schema: type: object required: - data properties: data: type: array items: type: object required: - id - type additionalProperties: false properties: id: type: string type: type: string enum: - user responses: '204': description: All Members were successfully deleted. '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: Forbidden content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status /user_groups/v3/user_groups/do/get_intersections: post: tags: - User Groups operationId: UserGroupIntersectionsByMemberV3 summary: Filter a list of groups to those intersecting given lists of users and groups description: Filters `candidate_group_ids` to those which - contain (at any nesting level) at least one of the source users - are, or have as a child, one of the source groups security: - oauth2: - offline_access - api_key: [] requestBody: required: true content: application/json: x-not-json-api: true schema: type: object additionalProperties: false required: - source - candidate_group_ids properties: source: type: object description: The users and/or groups to filter against. Both properties MUST be present but MAY be empty. additionalProperties: false required: - user_ids - group_ids properties: user_ids: type: array items: type: string format: uuid group_ids: type: array items: type: string format: uuid candidate_group_ids: type: array description: User Group ids to filter using `source` items: type: string format: uuid opal_id: type: string format: uuid description: Opal that contains the groups. Required for OAuth-scoped requests; optional for user-authenticated requests (because it can be derived from the user). example: source: user_ids: - aa29f22c-c711-4aee-aa90-4ddb6c4625de - ef7f29ee-4d32-4933-b163-29657a46b012 group_ids: - aaaaaaaa-0000-4000-8000-000000000001 candidate_group_ids: - aaaaaaaa-0000-4000-8000-000000000003 - aaaaaaaa-0000-4000-8000-000000000002 - aaaaaaaa-0000-4000-8000-000000000001 - aaaaaaaa-0000-4000-8000-000000000004 responses: '200': description: The candidate groups that intersect the given sources content: application/json: schema: type: object required: - data properties: data: type: array items: type: object additionalProperties: false required: - id - type properties: id: type: string format: uuid type: type: string enum: - user_group example: data: - id: aaaaaaaa-0000-4000-8000-000000000003 type: user_group - id: aaaaaaaa-0000-4000-8000-000000000002 type: user_group - id: aaaaaaaa-0000-4000-8000-000000000001 type: user_group '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: Forbidden content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status /user_groups/v3/user_groups/{user_group_id}/do/get_intersections: post: tags: - User Groups operationId: UserGroupIntersectionsByGroupV3 summary: Filter a list of groups to those intersecting a source group description: Convenience layer over `UserGroupIntersectionsByMemberV3` that uses a group as its starting point. security: - oauth2: - offline_access - api_key: [] parameters: - name: user_group_id in: path required: true description: The ID of the User Group. schema: type: string format: uuid requestBody: required: true content: application/json: x-not-json-api: true schema: type: object additionalProperties: false required: - candidate_group_ids properties: candidate_group_ids: type: array description: User Group ids to filter using the group given in the request path items: type: string format: uuid opal_id: type: string format: uuid description: Opal that contains the groups. Required for OAuth-scoped requests; optional for user-authenticated requests (because it can be derived from the user). example: candidate_group_ids: - aaaaaaaa-0000-4000-8000-000000000003 - aaaaaaaa-0000-4000-8000-000000000002 - aaaaaaaa-0000-4000-8000-000000000001 - aaaaaaaa-0000-4000-8000-000000000004 responses: '200': description: The candidate groups that intersect the source group content: application/json: schema: type: object required: - data properties: data: type: array items: type: object additionalProperties: false required: - id - type properties: id: type: string format: uuid type: type: string enum: - user_group example: data: - id: aaaaaaaa-0000-4000-8000-000000000003 type: user_group - id: aaaaaaaa-0000-4000-8000-000000000002 type: user_group - id: aaaaaaaa-0000-4000-8000-000000000001 type: user_group '400': description: Bad request content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '401': description: Unauthorized content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '403': description: Forbidden content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '404': description: The source user group does not exist or has been deleted. content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status '422': description: Unprocessable entity content: application/json: schema: type: object required: - errors properties: errors: type: array items: type: object properties: status: type: string description: The http status code of the error response. title: type: string description: A short, human-readable summary of the error. detail: type: string description: A human-readable explanation of the error. code: type: string description: 'An system-readable error code to provide additional specificity for the error. ' required: - status components: securitySchemes: oauth2: type: oauth2 description: 'This API uses OAuth 2.0 with the authorization code grant flow. You can find more detailed authentication instructions in the [Authentication Strategies](/api/documentation#section/Authentication-Strategies/OAuth-2.0) section. ' flows: authorizationCode: authorizationUrl: /oauth2/auth tokenUrl: /oauth2/token scopes: offline_access: Include this scope if you wish to receive a refresh token anonymous_oauth: type: oauth2 description: 'The OAuth 2.0 client credentials flow is used for secure server-server requests when Opal does not need to associate a request with a particular Opal user. These anonymous requests are instead authorized based on the OAuth scope. ' flows: clientCredentials: tokenUrl: /oauth/token scopes: write:onboarding: Include this scope if you wish to make API requests to onboard new Opals. api_key: type: apiKey description: '(Deprecated) This API also supports authentication via an API or session token set in the request headers. ' in: header name: Session-Token presentation_share_cookie: type: apiKey description: 'A cookie set and read by the Monolith service that authorizes a non-opal user to view a presentation and the resources within it. Other services can rely on this cookie by asking Monolith to authenticate it. ' in: cookie name: share_token x-tagGroups: - name: Stable tags: - Board Collaborators - Board Objects - Boards - Content Schedules - Moment Schedules - Moments - Onboarding - name: ⚠️ Unstable tags: - Block Connectors - Board Columns - Board Duplication - Board Standard Columns - Channels - Custom Field Options - Custom Field Types - Custom Fields - Moment Assignees - Moment Custom Fields - Planning Status - Rich Text Documents - User Groups - Users - Workspaces - name: ℹ️ Proposed tags: - Bulk Operations - Gem Chats - Gem Files - Moment Duplication - Presentation Themes - Workflows - Workflow Contexts - Workflow Stages - Workflow Assignments - Workflow Responses - name: ⚛️ Experimental tags: - Blocks - Block Custom Field Values - Block Duplication - Board User Settings - Categories - Category Types - Charts - Content - Custom Field Colors - Filter Sets - Key Dates - View Columns - View Standard Columns - Views - View Colors - Stories - name: Additional Resources tags: - secondary_resources