openapi: 3.1.2 info: description: "You're looking at the current **stable** documentation of the OpenProject APIv3. If you're interested in the current\ndevelopment version, please go to [github.com/opf](https://github.com/opf/openproject/tree/dev/docs/api/apiv3).\n\n## Introduction\n\nThe documentation for the APIv3 is written according to the [OpenAPI 3.1 Specification](https://swagger.io/specification/).\nYou can either view the static version of this documentation on the [website](https://www.openproject.org/docs/api/introduction/)\nor the interactive version, rendered with [OpenAPI Explorer](https://github.com/Rhosys/openapi-explorer/blob/main/README.md),\nin your OpenProject installation under `/api/docs`.\nIn the latter you can try out the various API endpoints directly interacting with our OpenProject data.\nMoreover you can access the specification source itself under `/api/v3/spec.json` and `/api/v3/spec.yml`\n(e.g. [here](https://community.openproject.org/api/v3/spec.yml)).\n\nThe APIv3 is a hypermedia REST API, a shorthand for \"Hypermedia As The Engine Of Application State\" (HATEOAS).\nThis means that each endpoint of this API will have links to other resources or actions defined in the resulting body.\n\nThese related resources and actions for any given resource will be context sensitive. For example, only actions that the\nauthenticated user can take are being rendered. This can be used to dynamically identify actions that the user might take for any\ngiven response.\n\nAs an example, if you fetch a work package through the [Work Package endpoint](https://www.openproject.org/docs/api/endpoints/work-packages/), the `update` link will only\nbe present when the user you authenticated has been granted a permission to update the work package in the assigned project.\n\n## HAL+JSON\n\nHAL is a simple format that gives a consistent and easy way to hyperlink between resources in your API.\nRead more in the following specification: [https://tools.ietf.org/html/draft-kelly-json-hal-08](https://tools.ietf.org/html/draft-kelly-json-hal-08)\n\n**OpenProject API implementation of HAL+JSON format** enriches JSON and introduces a few meta properties:\n\n- `_type` - specifies the type of the resource (e.g.: WorkPackage, Project)\n- `_links` - contains all related resource and action links available for the resource\n- `_embedded` - contains all embedded objects\n\nHAL does not guarantee that embedded resources are embedded in their full representation, they might as well be\npartially represented (e.g. some properties can be left out).\nHowever in this API you have the guarantee that whenever a resource is **embedded**, it is embedded in its **full representation**.\n\n## API response structure\n\nAll API responses contain a single HAL+JSON object, even collections of objects are technically represented by\na single HAL+JSON object that itself contains its members. More details on collections can be found\nin the [Collections Section](https://www.openproject.org/docs/api/collections/).\n\n## Authentication\n\nThe API supports the following authentication schemes:\n\n* Session-based authentication\n* API tokens\n * passed as Bearer token\n * passed via Basic auth\n* OAuth 2.0\n * using built-in authorization server\n * using an external authorization server (RFC 9068)\n\nDepending on the settings of the OpenProject instance many resources can be accessed without being authenticated.\nIn case the instance requires authentication on all requests the client will receive an **HTTP 401** status code\nin response to any request.\n\nOtherwise unauthenticated clients have all the permissions of the anonymous user.\n\n### Session-based authentication\n\nThis means you have to login to OpenProject via the Web-Interface to be authenticated in the API.\nThis method is well-suited for clients acting within the browser, like the Angular-Client built into OpenProject.\n\nIn this case, you always need to pass the HTTP header `X-Requested-With \"XMLHttpRequest\"` for authentication.\n\n### API token as bearer token\n\nUsers can authenticate towards the API v3 using an API token as a bearer token.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42\n```\n\nUsers can generate API tokens on their account page.\n\n### API token through Basic Auth\n\nAPI tokens can also be used with basic auth, using the user name `apikey` (NOT your login) and the API token as the password.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -u apikey:$API_KEY https://community.openproject.org/api/v3/users/42\n```\n\n### OAuth 2.0 authentication\n\nOpenProject allows authentication and authorization with OAuth2 with *Authorization code flow*, as well as *Client credentials* operation modes.\n\nTo get started, you first need to register an application in the OpenProject OAuth administration section of your installation.\nThis will save an entry for your application with a client unique identifier (`client_id`) and an accompanying secret key (`client_secret`).\n\nYou can then use one the following guides to perform the supported OAuth 2.0 flows:\n\n- [Authorization code flow](https://oauth.net/2/grant-types/authorization-code)\n\n- [Authorization code flow with PKCE](https://doorkeeper.gitbook.io/guides/ruby-on-rails/pkce-flow), recommended for clients unable to keep the client_secret confidential\n\n- [Client credentials](https://oauth.net/2/grant-types/client-credentials/) - Requires an application to be bound to an impersonating user for non-public access\n\n### OAuth 2.0 using an external authorization server\n\nThere is a possibility to use JSON Web Tokens (JWT) generated by an OIDC provider configured in OpenProject as a bearer token to do authenticated requests against the API.\nThe following requirements must be met:\n\n- OIDC provider must be configured in OpenProject with **jwks_uri**\n- JWT must be signed using RSA algorithm\n- JWT **iss** claim must be equal to OIDC provider **issuer**\n- JWT **aud** claim must contain the OpenProject **client ID** used at the OIDC provider\n- JWT **scope** claim must include a valid scope to access the desired API (e.g. `api_v3` for APIv3)\n- JWT must be actual (neither expired or too early to be used)\n- JWT must be passed in Authorization header like: `Authorization: Bearer {jwt}`\n- User from **sub** claim must be linked to OpenProject before (e.g. by logging in), otherwise it will be not authenticated\n\nIn more general terms, OpenProject should be compliant to [RFC 9068](https://www.rfc-editor.org/rfc/rfc9068) when validating access tokens.\n\n### Why not username and password?\n\nThe simplest way to do basic auth would be to use a user's username and password naturally.\nHowever, OpenProject already has supported API keys in the past for the API v2, though not through basic auth.\n\nUsing **username and password** directly would have some advantages:\n\n* It is intuitive for the user who then just has to provide those just as they would when logging into OpenProject.\n\n* No extra logic for token management necessary.\n\nOn the other hand using **API keys** has some advantages too, which is why we went for that:\n\n* If compromised while saved on an insecure client the user only has to regenerate the API key instead of changing their password, too.\n\n* They are naturally long and random which makes them invulnerable to dictionary attacks and harder to crack in general.\n\nMost importantly users may not actually have a password to begin with. Specifically when they have registered\nthrough an OpenID Connect provider.\n\n## Cross-Origin Resource Sharing (CORS)\n\nBy default, the OpenProject API is _not_ responding with any CORS headers.\nIf you want to allow cross-domain AJAX calls against your OpenProject instance, you need to enable CORS headers being returned.\n\nPlease see [our API settings documentation](https://www.openproject.org/docs/system-admin-guide/api-and-webhooks/) on\nhow to selectively enable CORS.\n\n## Allowed HTTP methods\n\n- `GET` - Get a single resource or collection of resources\n\n- `POST` - Create a new resource or perform\n\n- `PATCH` - Update a resource\n\n- `DELETE` - Delete a resource\n\n## Compression\n\nResponses are compressed if requested by the client. Currently [gzip](https://www.gzip.org/) and [deflate](https://tools.ietf.org/html/rfc1951)\nare supported. The client signals the desired compression by setting the [`Accept-Encoding` header](https://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.3).\nIf no `Accept-Encoding` header is send, `Accept-Encoding: identity` is assumed which will result in the API responding uncompressed." title: OpenProject API V3 (Stable) Actions & Capabilities Portfolios API version: '3' servers: - url: https://qa.openproject-edge.com description: Edge QA instance - url: https://qa.openproject-stage.com description: Staging instance - url: https://community.openproject.org description: Community instance security: - BasicAuth: [] tags: - description: "Portfolios are one of the types of [workspaces](https://www.openproject.org/docs/api/endpoints/workspaces) in OpenProject structuring the information (e.g. work packages, wikis) into smaller sets. They are typically used to group, structure and manage sub-portfolios, programs and projects that\ntarget similar strategic goals of the organization. \n\nAs containers, they also control behaviour of the elements within them. One of the most important aspects of this is that portfolios limit permissions by having members with a certain permission set (roles) assigned to them.\n\n## Actions\n\n| Link | Description | Condition |\n|:--------------------------: |----------------------------------------------------------------------| --------------------------------- |\n| update | Form endpoint that aids in updating this portfolio | **Permission**: edit workspace |\n| updateImmediately | Directly update this portfolio | **Permission**: edit workspace |\n| delete | Delete this portfolio | **Permission**: admin |\n| favor | Mark this portfolio as favorited by the current user | **Permission**: none but login is required, only present if the portfolio is not yet favorited |\n| disfavor | Mark this portfolio as no longer favorited by the current user | **Permission**: none but login is required, only present if the portfolio is favorited |\n| createWorkPackage | Form endpoint that aids in preparing and creating a work package | **Permission**: add work packages |\n| createWorkPackageImmediately | Directly creates a work package in the portfolio | **Permission**: add work packages |\n\n## Linked Properties\n\n| Link | Description | Type | Constraints | Supported operations |Condition |\n| :----------: | ------------- | ---- | ----------- | -------------------- |----------------------------------------- |\n| self | This portfolio | Portfolio | not null | READ | |\n| ancestors | Array of all ancestors of the portfolio, down from the root node (first element) to the parent (last element). | Collection | not null | READ | **Permission** view portfolio on the ancestor portfolio. Non visible portfolios will be omitted |\n| categories | Categories available in this portfolio | Collection | not null | READ | |\n| types | Types available in this portfolio | Collection | not null | READ | **Permission**: view work packages or manage types |\n| versions | Versions available in this portfolio | Collection | not null | READ | **Permission**: view work packages or manage versions |\n| memberships | Memberships in the portfolio | Collection | not null | READ | **Permission**: view members |\n| workPackages | Work Packages of this portfolio | Collection | not null | READ | |\n| parent | Parent portfolio of the portfolio | Portfolio | | READ/WRITE | **Permission** edit workspace |\n| status | Denotes the status of the portfolio, so whether the portfolio is on track, at risk or is having trouble. | PortfolioStatus | | READ/WRITE | **Permission** edit workspace |\n\nDepending on custom fields defined for portfolios, additional links might exist.\n\nNote, that the parent and ancestor links may contain the \"undisclosed uri\" `urn:openportfolio-org:api:v3:undisclosed` in case an\nancestor portfolio is defined but the client lacks permission to see it. See the\n[general introduction into links' properties](https://www.openportfolio.org/docs/api/basic-objects/#local-properties) for more information.\n\n## Local Properties\n\n| Property | Description | Type | Constraints | Supported operations |\n| :---------------------:| ------------- | ---- | ----------- | -------------------- |\n| id | Portfolios' id | Integer | x > 0 | READ/WRITE |\n| identifier | | String | | READ/WRITE |\n| name | | String | | READ/WRITE |\n| active | Indicates whether the portfolio is currently active or already archived | Boolean | | READ/WRITE |\n| favorited | Indicates whether the portfolio is favorited by the current user | Boolean | | READ |\n| statusExplanation | A text detailing and explaining why the portfolio has the reported status | Formattable | | READ/WRITE |\n| public | Indicates whether the portfolio is accessible for everybody | Boolean | | READ/WRITE |\n| description | | Formattable | | READ/WRITE |\n| createdAt | Time of creation | DateTime | | READ |\n| updatedAt | Time of the most recent change to the portfolio | DateTime | | READ |\n\nDepending on custom fields defined for portfolios, additional properties might exist." name: Portfolios paths: /api/v3/portfolios: get: summary: List portfolios operationId: list_portfolios tags: - Portfolios description: Returns a collection of portfolios. The collection can be filtered via query parameters similar to how work packages are filtered. In addition to the provided filter, the result set is always limited to only contain portfolios the client is allowed to see. parameters: - name: filters schema: type: string in: query required: false description: 'JSON specifying filter conditions. Accepts the same format as returned by the [queries](https://www.openportfolio.org/docs/api/endpoints/queries/) endpoint. Currently supported filters are: + active: based on the active property of the portfolio + ancestor: filters portfolios by their ancestor. A portfolio is not considered to be its own ancestor. + available_project_attributes: filters portfolios based on the activated project attributes. + created_at: based on the time the portfolio was created + favorited: based on the favorited property of the portfolio + id: based on portfolios'' id. + latest_activity_at: based on the time the last activity was registered on a portfolio. + name_and_identifier: based on both the name and the identifier. + parent_id: filters portfolios by their parent. + principal: based on members of the portfolio. + project_phase_any: based on the project phases active in a portfolio. + project_status_code: based on status code of the portfolio + storage_id: filters portfolios by linked storages + storage_url: filters portfolios by linked storages identified by the host url + type_id: based on the types active in a portfolio. + user_action: based on the actions the current user has in the portfolio. + visible: based on the visibility for the user (id) provided as the filter value. This filter is useful for admins to identify the portfolios visible to a user. There might also be additional filters based on the custom fields that have been configured. Each defined lifecycle step will also define a filter in this list endpoint. Given that the elements are not static but rather dynamically created on each OpenProject instance, a list cannot be provided. Those filters follow the schema: + project_start_gate_[id]: a filter on a project phase''s start gate active in a portfolio. The id is the id of the phase the gate belongs to. + project_finish_gate_[id]: a filter on a project phase''s finish gate active in a portfolio. The id is the id of the phase the gate belongs to. + project_phase_[id]: a filter on a project phase active in a portfolio. The id is the id of the phase queried for.' example: '[{ "ancestor": { "operator": "=", "values": ["1"] }" }]' - name: sortBy schema: type: string in: query required: false description: 'JSON specifying sort criteria. Currently supported orders are: + id + name + typeahead (sorting by hierarchy and name) + created_at + public + latest_activity_at + required_disk_space There might also be additional orders based on the custom fields that have been configured.' example: '[["id", "asc"]]' - name: select schema: type: string in: query required: false description: Comma separated list of properties to include. example: total,elements/identifier,elements/name responses: '200': description: OK content: application/hal+json: schema: $ref: '#/components/schemas/PortfolioCollectionModel' examples: simple portfolio collection: $ref: '#/components/examples/PortfolioCollection' '400': description: Returned if the client sends invalid request parameters e.g. filters content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' example: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:InvalidQuery message: Filters Invalid filter does not exist. /api/v3/portfolios/{id}: get: parameters: - description: Portfolio id example: '1' in: path name: id required: true schema: type: integer responses: '200': content: application/hal+json: schema: $ref: '#/components/schemas/PortfolioModel' description: OK headers: {} '404': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:NotFound message: The requested resource could not be found. description: 'Returned if the portfolio does not exist or the client does not have sufficient permissions to see it. **Required permission:** any permission in the portfolio *Note: A client without sufficient permissions shall not be able to test for the existence of a portfolio. That''s why a 404 is returned here, even if a 403 might be more appropriate.*' headers: {} tags: - Portfolios description: '' operationId: View_portfolio summary: View portfolio patch: parameters: - description: Portfolio id example: '1' in: path name: id required: true schema: type: integer requestBody: content: application/json: schema: $ref: '#/components/schemas/PortfolioModel' examples: with custom fields: $ref: '#/components/examples/PortfolioBody' responses: '200': content: application/hal+json: schema: $ref: '#/components/schemas/PortfolioModel' examples: with custom fields: $ref: '#/components/examples/Portfolio' description: OK headers: {} '400': $ref: '#/components/responses/InvalidRequestBody' '403': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission message: You are not authorized to access this resource. description: 'Returned if the client does not have sufficient permissions. **Required permission:** edit project for the portfolio to be altered' headers: {} '404': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:NotFound message: The requested resource could not be found. description: 'Returned if the portfolio does not exist or the client does not have sufficient permissions to see it. **Required permission:** view project *Note: A client without sufficient permissions shall not be able to test for the existence of a version. That''s why a 404 is returned here, even if a 403 might be more appropriate.*' headers: {} '406': $ref: '#/components/responses/MissingContentType' '415': $ref: '#/components/responses/UnsupportedMediaType' '422': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _embedded: details: attribute: name _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation message: Name can't be blank. description: 'Returned if: * a constraint for a property was violated (`PropertyConstraintViolation`)' headers: {} tags: - Portfolios description: Updates the given portfolio by applying the attributes provided in the body. operationId: Update_Portfolio summary: Update Portfolio delete: parameters: - description: Portfolio id example: '1' in: path name: id required: true schema: type: integer responses: '204': description: 'Returned if the portfolio was successfully deleted. There is currently no endpoint to query for the actual deletion status. Such an endpoint _might_ be added in the future.' headers: {} '403': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission message: You are not authorized to access this resource. description: 'Returned if the client does not have sufficient permissions. **Required permission:** admin' headers: {} '404': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:NotFound message: The requested resource could not be found. description: 'Returned if the portfolio does not exist or the client does not have sufficient permissions to see it. **Required permission:** any permission in the portfolio *Note: A client without sufficient permissions shall not be able to test for the existence of a version. That''s why a 404 is returned here, even if a 403 might be more appropriate.*' headers: {} '406': $ref: '#/components/responses/MissingContentType' '415': $ref: '#/components/responses/UnsupportedMediaType' '422': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _embedded: details: attribute: base _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation message: Work packages in non descendant projects reference versions of the portfolio or its descendants. description: 'Returned if the portfolio cannot be deleted. This can happen when there are still references to the portfolio in other workspaces that need to be severed at first.' headers: {} tags: - Portfolios description: 'Deletes the portfolio permanently. As this is a lengthy process, the actual deletion is carried out asynchronously. So the portfolio might exist well after the request has returned successfully. To prevent unwanted changes to the portfolio scheduled for deletion, it is archived at once.' operationId: Delete_Portfolio summary: Delete Portfolio /api/v3/portfolios/{id}/form: post: parameters: - description: Portfolio id example: '1' in: path name: id required: true schema: type: integer requestBody: content: application/json: schema: type: object examples: with custom fields: $ref: '#/components/examples/PortfolioBody' empty: description: Empty request to get the form initially in order to start the guided update of a portfolio value: {} responses: '200': description: OK headers: {} '400': $ref: '#/components/responses/InvalidRequestBody' '403': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission message: You are not authorized to access this resource. description: 'Returned if the client does not have sufficient permissions. **Required permission:** edit workspace in the portfolio' headers: {} '406': $ref: '#/components/responses/MissingContentType' '415': $ref: '#/components/responses/UnsupportedMediaType' tags: - Portfolios description: '' operationId: Portfolio_update_form summary: Portfolio update form components: examples: PortfolioBody: value: name: Portfolio example statusExplanation: raw: Everything **fine** description: raw: Lorem **ipsum** dolor sit amet customField123: 123 customComment123: Because it is 123! _links: parent: href: /api/v3/portfolios/123 customField456: href: /api/v3/portfolios/315 Portfolio: value: _type: Portfolio _links: self: href: /api/v3/portfolios/1 title: Lorem createWorkPackage: href: /api/v3/portfolios/1/work_packages/form method: post createWorkPackageImmediate: href: /api/v3/portfolios/1/work_packages method: post categories: href: /api/v3/portfolios/1/categories types: href: /api/v3/portfolios/1/types versions: href: /api/v3/portfolios/1/versions workPackages: href: /api/v3/portfolios/1/work_packages memberships: href: /api/v3/memberships?filters=[{"project":{"operator":"=","values":["1"]}}] customField456: href: /api/v3/users/315 title: A user parent: href: /api/v3/portfolios/123 title: Parent portfolio ancestors: - href: /api/v3/portfolios/2 title: Root portfolio - href: /api/v3/portfolios/12 title: Grandparent portfolio - href: /api/v3/portfolios/123 title: Parent portfolio status: href: /api/v3/project_statuses/on_track title: On track id: 1 identifier: connect2025 name: Digital Connect 2030 active: true public: false statusExplanation: format: markdown raw: Everything **fine** html:
Everything fine
description: format: markdown raw: This collection showcases a diverse selection of projects that highlight our commitment to excellence and our passion for design. From innovative web applications to stunning graphic designs, each piece reflects our unique approach and dedication to delivering impactful solutions. Discover the journey of our work and see how we bring ideas to life. html:This collection showcases a diverse selection of projects that highlight our commitment to excellence and our passion for design. From innovative web applications to stunning graphic designs, each piece reflects our unique approach and dedication to delivering impactful solutions. Discover the journey of our work and see how we bring ideas to life.
createdAt: '2014-05-21T08:51:20.396Z' updatedAt: '2014-05-21T08:51:20.396Z' customField123: 123 customComment123: Why is the value 123? PortfolioCollection: value: _type: Collection count: 2 total: 2 pageSize: 20 offset: 1 _embedded: elements: - _hint: Portfolio resource shortened for brevity id: 1 identifier: connect2030 name: Digital Connect 2030 active: true public: true - _hint: Portfolio resource shortened for brevity id: 2 identifier: future2050 name: Digital Future 2050 active: true public: false _links: self: href: /api/v3/portfolios?filters=%5B%5D&offset=1&pageSize=20 jumpTo: href: /api/v3/portfolios?filters=%5B%5D&offset=%7Boffset%7D&pageSize=20 templated: true changeSize: href: /api/v3/portfolios?filters=%5B%5D&offset=1&pageSize=%7Bsize%7D templated: true representations: - href: /portfolios.csv?filters=%5B%5D&offset=1&pageSize=20 identifier: csv type: text/csv title: CSV - href: /portfolios.xls?filters=%5B%5D&offset=1&pageSize=20 identifier: xls type: application/vnd.ms-excel title: XLS schemas: CollectionModel: type: object required: - _type - total - count - _links properties: _type: type: string enum: - Collection total: type: integer description: The total amount of elements available in the collection. minimum: 0 count: type: integer description: Actual amount of elements in this response. minimum: 0 _links: $ref: '#/components/schemas/CollectionLinks' ErrorResponse: type: object required: - _type - errorIdentifier - message properties: _embedded: type: object properties: details: type: object properties: attribute: type: string example: project _type: type: string enum: - Error errorIdentifier: type: string example: urn:openproject-org:api:v3:errors:PropertyConstraintViolation message: type: string example: Project can't be blank. CollectionLinks: type: object required: - self properties: self: allOf: - $ref: '#/components/schemas/Link' - description: 'This collection resource. **Resource**: Collection' Formattable: type: object required: - format properties: format: type: string enum: - plain - markdown - custom readOnly: true description: Indicates the formatting language of the raw text example: markdown raw: type: string description: The raw text, as entered by the user example: I **am** formatted! html: type: string readOnly: true description: The text converted to HTML according to the format example: I am formatted! example: format: markdown raw: I am formatted! html: I am formatted! Link: type: object required: - href properties: href: type: - string - 'null' description: URL to the referenced resource (might be relative) title: type: string description: Representative label for the resource templated: type: boolean default: false description: If true the href contains parts that need to be replaced by the client method: type: string default: GET description: The HTTP verb to use when requesting the resource payload: type: object description: The payload to send in the request to achieve the desired result identifier: type: string description: An optional unique identifier to the link object type: type: string description: The MIME-Type of the returned resource. example: href: /api/v3/work_packages method: POST OffsetPaginatedCollectionModel: allOf: - $ref: '#/components/schemas/CollectionModel' - type: object required: - pageSize - offset - _links properties: pageSize: type: integer description: 'The amount of elements per page. If not set by the request this value defaults to the server''s system settings.' minimum: 0 offset: type: integer description: The page offset indicating on which page the element collection starts. minimum: 0 _links: $ref: '#/components/schemas/OffsetPaginatedCollectionLinks' CustomCommentProperties: type: object patternProperties: ^customComment\d+$: type: - 'null' - string description: 'A plain-text comment associated with a project custom field that has comments enabled. The property is only present when the corresponding `customField{N}` has `has_comment` set to `true`.' PortfolioModel: allOf: - $ref: '#/components/schemas/CustomFieldProperties' - $ref: '#/components/schemas/CustomCommentProperties' - type: object properties: _type: type: string enum: - Portfolio id: type: integer description: Portfolios' id minimum: 1 identifier: type: string name: type: string active: type: boolean description: Indicates whether the portfolio is currently active or already archived favorited: type: boolean description: Indicates whether the portfolio is favorited by the current user statusExplanation: allOf: - $ref: '#/components/schemas/Formattable' - description: A text detailing and explaining why the portfolio has the reported status public: type: boolean description: Indicates whether the portfolio is accessible for everybody description: $ref: '#/components/schemas/Formattable' createdAt: type: string format: date-time description: Time of creation. Can be writable by admins with the `apiv3_write_readonly_attributes` setting enabled. updatedAt: type: string format: date-time description: Time of the most recent change to the portfolio _links: type: object required: - self - categories properties: update: allOf: - $ref: '#/components/schemas/Link' - description: 'Form endpoint that aids in updating this portfolio # Conditions **Permission**: edit workspace' updateImmediately: allOf: - $ref: '#/components/schemas/Link' - description: 'Directly update this portfolio # Conditions **Permission**: edit workspace' delete: allOf: - $ref: '#/components/schemas/Link' - description: 'Delete this portfolio # Conditions **Permission**: admin' favor: allOf: - $ref: '#/components/schemas/Link' - description: 'Mark this portfolio as favorited by the current user # Conditions Only present if the portfolio is not yet favorited Permission**: none but login is required' disfavor: allOf: - $ref: '#/components/schemas/Link' - description: 'Mark this portfolio as not favorited by the current user # Conditions Only present if the portfolio is favorited by the current user Permission**: none but login is required' createWorkPackage: allOf: - $ref: '#/components/schemas/Link' - description: 'Form endpoint that aids in preparing and creating a work package # Conditions **Permission**: add work packages' createWorkPackageImmediately: allOf: - $ref: '#/components/schemas/Link' - description: 'Directly creates a work package in the portfolio # Conditions **Permission**: add work packages' self: allOf: - $ref: '#/components/schemas/Link' - description: 'This portfolio **Resource**: Portfolio' categories: allOf: - $ref: '#/components/schemas/Link' - description: 'Categories available in this portfolio **Resource**: Collection' types: allOf: - $ref: '#/components/schemas/Link' - description: 'Types available in this portfolio **Resource**: Collection # Conditions **Permission**: view work packages or manage types' versions: allOf: - $ref: '#/components/schemas/Link' - description: 'Versions available in this portfolio **Resource**: Collection # Conditions **Permission**: view work packages or manage versions' memberships: allOf: - $ref: '#/components/schemas/Link' - description: 'Memberships in the portfolio **Resource**: Collection # Conditions **Permission**: view members' workPackages: allOf: - $ref: '#/components/schemas/Link' - description: 'Work Packages of this portfolio **Resource**: Collection' parent: allOf: - $ref: '#/components/schemas/Link' - description: 'Parent of the portfolio **Resource**: Portfolio # Conditions **Permission** edit workspace' status: allOf: - $ref: '#/components/schemas/Link' - description: 'Denotes the status of the portfolio, so whether the portfolio is on track, at risk or is having trouble. **Resource**: ProjectStatus # Conditions **Permission** edit workspace' storages: type: array items: allOf: - $ref: '#/components/schemas/Link' - description: 'The link to a storage that is active for this portfolio. **Resource**: Storage # Conditions **Permission**: view_file_links' projectStorages: allOf: - $ref: '#/components/schemas/Link' - description: 'The project storage collection of this portfolio. **Resource**: Collection # Conditions **Permission**: view_file_links' ancestors: type: array items: allOf: - $ref: '#/components/schemas/Link' - description: 'A collection of links to the ancestor portfolios. **Resource**: Portfolio' PortfolioCollectionModel: allOf: - $ref: '#/components/schemas/OffsetPaginatedCollectionModel' - type: object required: - _links - _embedded properties: _links: allOf: - $ref: '#/components/schemas/OffsetPaginatedCollectionLinks' - type: object properties: representations: type: array items: allOf: - $ref: '#/components/schemas/Link' - description: A portfolio collection representation in a specific file format. _embedded: type: object required: - elements properties: elements: type: array items: $ref: '#/components/schemas/PortfolioModel' OffsetPaginatedCollectionLinks: allOf: - $ref: '#/components/schemas/CollectionLinks' - type: object required: - jumpTo - changeSize properties: jumpTo: allOf: - $ref: '#/components/schemas/Link' - description: A templated link to jump to a given offset. changeSize: allOf: - $ref: '#/components/schemas/Link' - description: A templated link to change the current page size. previousByOffset: allOf: - $ref: '#/components/schemas/Link' - description: 'A link to the previous page of the collection. # Conditions - The collection is not on the first page.' nextByOffset: allOf: - $ref: '#/components/schemas/Link' - description: 'A link to the next page of the collection. # Conditions - The collection is not on the last page.' CustomFieldProperties: type: object patternProperties: ^customField\d+$: type: - 'null' - number - boolean - string - object description: 'A custom field value, that belongs to a custom field of a simple type: - Boolean - Date - Float - Integer - Link (URL) - Text - Long text' responses: MissingContentType: description: Occurs when the client did not send a Content-Type header content: text/plain: schema: type: string example: Missing content-type header InvalidRequestBody: description: Occurs when the client did not send a valid JSON object in the request body. content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' example: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:InvalidRequestBody message: The request body was not a single JSON object. UnsupportedMediaType: description: Occurs when the client sends an unsupported Content-Type header. content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' example: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:TypeNotSupported message: Expected CONTENT-TYPE to be (expected value) but got (actual value). securitySchemes: BasicAuth: type: http scheme: basic