openapi: 3.1.2 info: description: "You're looking at the current **stable** documentation of the OpenProject APIv3. If you're interested in the current\ndevelopment version, please go to [github.com/opf](https://github.com/opf/openproject/tree/dev/docs/api/apiv3).\n\n## Introduction\n\nThe documentation for the APIv3 is written according to the [OpenAPI 3.1 Specification](https://swagger.io/specification/).\nYou can either view the static version of this documentation on the [website](https://www.openproject.org/docs/api/introduction/)\nor the interactive version, rendered with [OpenAPI Explorer](https://github.com/Rhosys/openapi-explorer/blob/main/README.md),\nin your OpenProject installation under `/api/docs`.\nIn the latter you can try out the various API endpoints directly interacting with our OpenProject data.\nMoreover you can access the specification source itself under `/api/v3/spec.json` and `/api/v3/spec.yml`\n(e.g. [here](https://community.openproject.org/api/v3/spec.yml)).\n\nThe APIv3 is a hypermedia REST API, a shorthand for \"Hypermedia As The Engine Of Application State\" (HATEOAS).\nThis means that each endpoint of this API will have links to other resources or actions defined in the resulting body.\n\nThese related resources and actions for any given resource will be context sensitive. For example, only actions that the\nauthenticated user can take are being rendered. This can be used to dynamically identify actions that the user might take for any\ngiven response.\n\nAs an example, if you fetch a work package through the [Work Package endpoint](https://www.openproject.org/docs/api/endpoints/work-packages/), the `update` link will only\nbe present when the user you authenticated has been granted a permission to update the work package in the assigned project.\n\n## HAL+JSON\n\nHAL is a simple format that gives a consistent and easy way to hyperlink between resources in your API.\nRead more in the following specification: [https://tools.ietf.org/html/draft-kelly-json-hal-08](https://tools.ietf.org/html/draft-kelly-json-hal-08)\n\n**OpenProject API implementation of HAL+JSON format** enriches JSON and introduces a few meta properties:\n\n- `_type` - specifies the type of the resource (e.g.: WorkPackage, Project)\n- `_links` - contains all related resource and action links available for the resource\n- `_embedded` - contains all embedded objects\n\nHAL does not guarantee that embedded resources are embedded in their full representation, they might as well be\npartially represented (e.g. some properties can be left out).\nHowever in this API you have the guarantee that whenever a resource is **embedded**, it is embedded in its **full representation**.\n\n## API response structure\n\nAll API responses contain a single HAL+JSON object, even collections of objects are technically represented by\na single HAL+JSON object that itself contains its members. More details on collections can be found\nin the [Collections Section](https://www.openproject.org/docs/api/collections/).\n\n## Authentication\n\nThe API supports the following authentication schemes:\n\n* Session-based authentication\n* API tokens\n * passed as Bearer token\n * passed via Basic auth\n* OAuth 2.0\n * using built-in authorization server\n * using an external authorization server (RFC 9068)\n\nDepending on the settings of the OpenProject instance many resources can be accessed without being authenticated.\nIn case the instance requires authentication on all requests the client will receive an **HTTP 401** status code\nin response to any request.\n\nOtherwise unauthenticated clients have all the permissions of the anonymous user.\n\n### Session-based authentication\n\nThis means you have to login to OpenProject via the Web-Interface to be authenticated in the API.\nThis method is well-suited for clients acting within the browser, like the Angular-Client built into OpenProject.\n\nIn this case, you always need to pass the HTTP header `X-Requested-With \"XMLHttpRequest\"` for authentication.\n\n### API token as bearer token\n\nUsers can authenticate towards the API v3 using an API token as a bearer token.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42\n```\n\nUsers can generate API tokens on their account page.\n\n### API token through Basic Auth\n\nAPI tokens can also be used with basic auth, using the user name `apikey` (NOT your login) and the API token as the password.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -u apikey:$API_KEY https://community.openproject.org/api/v3/users/42\n```\n\n### OAuth 2.0 authentication\n\nOpenProject allows authentication and authorization with OAuth2 with *Authorization code flow*, as well as *Client credentials* operation modes.\n\nTo get started, you first need to register an application in the OpenProject OAuth administration section of your installation.\nThis will save an entry for your application with a client unique identifier (`client_id`) and an accompanying secret key (`client_secret`).\n\nYou can then use one the following guides to perform the supported OAuth 2.0 flows:\n\n- [Authorization code flow](https://oauth.net/2/grant-types/authorization-code)\n\n- [Authorization code flow with PKCE](https://doorkeeper.gitbook.io/guides/ruby-on-rails/pkce-flow), recommended for clients unable to keep the client_secret confidential\n\n- [Client credentials](https://oauth.net/2/grant-types/client-credentials/) - Requires an application to be bound to an impersonating user for non-public access\n\n### OAuth 2.0 using an external authorization server\n\nThere is a possibility to use JSON Web Tokens (JWT) generated by an OIDC provider configured in OpenProject as a bearer token to do authenticated requests against the API.\nThe following requirements must be met:\n\n- OIDC provider must be configured in OpenProject with **jwks_uri**\n- JWT must be signed using RSA algorithm\n- JWT **iss** claim must be equal to OIDC provider **issuer**\n- JWT **aud** claim must contain the OpenProject **client ID** used at the OIDC provider\n- JWT **scope** claim must include a valid scope to access the desired API (e.g. `api_v3` for APIv3)\n- JWT must be actual (neither expired or too early to be used)\n- JWT must be passed in Authorization header like: `Authorization: Bearer {jwt}`\n- User from **sub** claim must be linked to OpenProject before (e.g. by logging in), otherwise it will be not authenticated\n\nIn more general terms, OpenProject should be compliant to [RFC 9068](https://www.rfc-editor.org/rfc/rfc9068) when validating access tokens.\n\n### Why not username and password?\n\nThe simplest way to do basic auth would be to use a user's username and password naturally.\nHowever, OpenProject already has supported API keys in the past for the API v2, though not through basic auth.\n\nUsing **username and password** directly would have some advantages:\n\n* It is intuitive for the user who then just has to provide those just as they would when logging into OpenProject.\n\n* No extra logic for token management necessary.\n\nOn the other hand using **API keys** has some advantages too, which is why we went for that:\n\n* If compromised while saved on an insecure client the user only has to regenerate the API key instead of changing their password, too.\n\n* They are naturally long and random which makes them invulnerable to dictionary attacks and harder to crack in general.\n\nMost importantly users may not actually have a password to begin with. Specifically when they have registered\nthrough an OpenID Connect provider.\n\n## Cross-Origin Resource Sharing (CORS)\n\nBy default, the OpenProject API is _not_ responding with any CORS headers.\nIf you want to allow cross-domain AJAX calls against your OpenProject instance, you need to enable CORS headers being returned.\n\nPlease see [our API settings documentation](https://www.openproject.org/docs/system-admin-guide/api-and-webhooks/) on\nhow to selectively enable CORS.\n\n## Allowed HTTP methods\n\n- `GET` - Get a single resource or collection of resources\n\n- `POST` - Create a new resource or perform\n\n- `PATCH` - Update a resource\n\n- `DELETE` - Delete a resource\n\n## Compression\n\nResponses are compressed if requested by the client. Currently [gzip](https://www.gzip.org/) and [deflate](https://tools.ietf.org/html/rfc1951)\nare supported. The client signals the desired compression by setting the [`Accept-Encoding` header](https://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.3).\nIf no `Accept-Encoding` header is send, `Accept-Encoding: identity` is assumed which will result in the API responding uncompressed." title: OpenProject API V3 (Stable) Actions & Capabilities Workspaces API version: '3' servers: - url: https://qa.openproject-edge.com description: Edge QA instance - url: https://qa.openproject-stage.com description: Staging instance - url: https://community.openproject.org description: Community instance security: - BasicAuth: [] tags: - name: Workspaces description: "Workspaces are containers for resources to be worked on and people with sets of permissions that work on the former. There is no actual workspace resource\nin OpenProject. Rather, it is the generic term describing:\n* [Portfolio](https://www.openproject.org/docs/api/endpoints/portfolios)\n* [Program](https://www.openproject.org/docs/api/endpoints/programs)\n* [Project](https://www.openproject.org/docs/api/endpoints/projects)\n\nA lot of resources reference the workspaces they are valid in, e.g. [Work package](https://www.openproject.org/docs/api/endpoints/work-packages/#linked-properties) and\n[Memberships](https://www.openproject.org/docs/api/endpoints/memberships/#linked-properties).\n\nBefore OP 17.0 only projects existed. At that point, the API v3 was already established. That is the reason why quite a number of\nresource have links called \"project\" or similar when they are in fact contained in a different type of workspace. To not break the API, the name of the link was kept. \nBut those links can contain the other types of workspaces as well. It can thus be possible for a work package to have the following:\n\n```\n {\n \"_links\": {\n \"project\": {\n \"href\": \"/api/v3/portfolios/48\",\n \"title: \"A portfolio\"\n },\n ...\n },\n ...\n }\n```\n\nAccordingly, to set the workspace a resource is in, sending any workspace link to the link property will be accepted by the API.\n\nThe concept of workspaces is planned to be extended to include further types." paths: /api/v3/workspaces/{id}/favorite: delete: parameters: - description: Workspace id example: '1' in: path name: id required: true schema: type: integer responses: '204': description: Returned if the workspace was successfully removed from favorites. '404': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:NotFound message: The requested resource could not be found. description: 'Returned if the workspace does not exist or the client does not have sufficient permissions to see it. **Required permission:** view workspace' '403': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission message: You are not authorized to access this resource. description: 'Returned if the client does not have sufficient permissions. **Required permission:** logged in' tags: - Workspaces description: Removes the workspace from the current user's favorites. operationId: Unfavorite_Workspace summary: Unfavorite Workspace post: parameters: - description: Workspace id example: '1' in: path name: id required: true schema: type: integer responses: '204': description: Returned if the workspace was successfully added to favorites. '404': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:NotFound message: The requested resource could not be found. description: 'Returned if the workspace does not exist or the client does not have sufficient permissions to see it. **Required permission:** view workspace' '403': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission message: You are not authorized to access this resource. description: 'Returned if the client does not have sufficient permissions. **Required permission:** logged in' tags: - Workspaces description: Adds the workspace to the current user's favorites. operationId: Favorite_Workspace summary: Favorite Workspace /api/v3/workspaces/{id}/types: get: parameters: - description: ID of the workspace whose types will be listed example: '1' in: path name: id required: true schema: type: integer responses: '200': content: application/hal+json: examples: response: value: _embedded: elements: - _links: self: href: /api/v3/types/1 _type: Type color: '#ff0000' createdAt: '2014-05-21T08:51:20.396Z' id: 1 isDefault: true isMilestone: false name: Bug position: 1 updatedAt: '2014-05-21T08:51:20.396Z' - _links: self: href: /api/v3/types/2 _type: Type color: '#888' createdAt: '2014-05-21T08:51:20.396Z' id: 2 isDefault: false isMilestone: false name: Feature position: 2 updatedAt: '2014-05-21T08:51:20.396Z' _links: self: href: /api/v3/workspaces/11/types _type: Collection count: 2 total: 2 schema: $ref: '#/components/schemas/Types_by_WorkspaceModel' description: OK headers: {} '404': content: application/hal+json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: _type: Error errorIdentifier: urn:openproject-org:api:v3:errors:NotFound message: The specified workspace does not exist. description: 'Returned if the workspace does not exist or the client does not have sufficient permissions to see it. **Required permission:** view work packages **or** manage types (on given workspace) *Note: A client without sufficient permissions shall not be able to test for the existence of a workspace. That''s why a 404 is returned here, even if a 403 might be more appropriate.*' headers: {} tags: - Workspaces description: This endpoint lists the types that are *available* in a given workspace. operationId: List_types_available_in_a_workspace summary: List types available in a workspace /api/v3/workspaces/schema: get: responses: '200': content: application/hal+json: examples: response: value: _dependencies: [] _attributeGroups: - _type: ProjectFormCustomFieldSection name: Workspace Details attributes: - customField30 - customField34 - _type: ProjectFormCustomFieldSection name: Budget Information attributes: - customField31 - customField32 - customField35 _links: self: href: /api/v3/workspaces/schema _type: Schema active: hasDefault: true name: Active required: true type: Boolean writable: true createdAt: hasDefault: false name: Created on required: true type: DateTime writable: false customField30: hasDefault: false name: Integer workspace custom field required: false type: Integer visibility: default writable: true customField31: _links: {} hasDefault: false location: _links name: List workspace custom field required: false type: CustomOption visibility: default writable: true customField32: _links: {} hasDefault: false location: _links name: Version workspace custom field required: false type: Version visibility: default writable: true customField34: hasDefault: false name: Boolean workspace custom field required: false type: Boolean visibility: default writable: true customField35: hasDefault: false name: Text workspace custom field required: true type: String visibility: default writable: true description: hasDefault: false name: Description required: false type: Formattable writable: true id: hasDefault: false name: ID required: true type: Integer writable: false identifier: hasDefault: false maxLength: 100 minLength: 1 name: Identifier required: true type: String writable: true name: hasDefault: false maxLength: 255 minLength: 1 name: Name required: true type: String writable: true parent: _links: {} hasDefault: false location: _links name: Subproject of required: false type: Workspace visibility: default writable: true public: hasDefault: false name: Public required: true type: Boolean writable: true status: _links: allowedValues: - href: /api/v3/project_statuses/on_track title: On track - href: /api/v3/project_statuses/at_risk title: At risk - href: /api/v3/project_statuses/off_track title: Off track hasDefault: true name: Status required: false type: ProjectStatus writable: true statusExplanation: hasDefault: false name: Status explanation required: false type: Formattable writable: true updatedAt: hasDefault: false name: Updated on required: true type: DateTime writable: false schema: $ref: '#/components/schemas/Workspaces_schemaModel' description: OK headers: {} tags: - Workspaces description: '' operationId: View_workspace_schema summary: View workspace schema components: schemas: TypeModel: type: object required: - id - name - color - position - isDefault - isMilestone - createdAt - updatedAt properties: id: type: integer description: Type id readOnly: true exclusiveMinimum: 0 name: type: string description: Type name readOnly: true color: type: - string - 'null' description: The color used to represent this type readOnly: true position: type: integer description: Sort index of the type readOnly: true isDefault: type: boolean description: Is this type active by default in new projects? readOnly: true isMilestone: type: boolean description: Do work packages of this type represent a milestone? readOnly: true createdAt: type: string format: date-time description: Time of creation readOnly: true updatedAt: type: string format: date-time description: Time of the most recent change to the user _links: type: object required: - self properties: self: allOf: - $ref: '#/components/schemas/Link' - description: 'This type **Resource**: Type' readOnly: true example: _links: self: href: /api/v3/types/1 _type: Type id: 1 name: Bug color: '#ff0000' position: 1 isDefault: true isMilestone: false createdAt: '2014-05-21T08:51:20.624Z' updatedAt: '2014-05-21T08:51:20.624Z' CollectionModel: type: object required: - _type - total - count - _links properties: _type: type: string enum: - Collection total: type: integer description: The total amount of elements available in the collection. minimum: 0 count: type: integer description: Actual amount of elements in this response. minimum: 0 _links: $ref: '#/components/schemas/CollectionLinks' Workspaces_schemaModel: type: object description: A schema for a workspace. This schema defines the attributes of a workspace. properties: _type: type: string enum: - Schema description: The type identifier for this resource _dependencies: type: array description: Schema dependencies (currently empty for workspaces) _attributeGroups: type: array items: type: object properties: _type: type: string enum: - ProjectFormCustomFieldSection description: The type identifier for this resource id: type: integer description: The unique identifier of the custom field section name: type: string description: The human-readable name of the custom field section attributes: type: array items: type: string description: 'Array of camelCase custom field attribute names belonging to this section. Only includes custom fields visible to the current user.' description: "Defines the organizational structure of project custom fields into sections for UI rendering.\n\nEach attribute group represents a project attribute section containing related project attributes.\nThe sections determine how project attributes are visually organized and grouped in forms.\n\n**Key behaviors:**\n- Admin-only project attributes appear only for users with admin privileges\n- Empty sections (with no accessible project attributes) are omitted from the response\n- The order reflects the configured section positioning in admin settings\n- Each section contains only project attributes assigned to that specific section\n\n**Example structure:**\n```json\n[\n {\n \"_type\": \"ProjectFormCustomFieldSection\",\n \"name\": \"Project Details\",\n \"attributes\": [\"customField1\", \"customField3\"]\n },\n {\n \"_type\": \"ProjectFormCustomFieldSection\",\n \"name\": \"Budget Information\",\n \"attributes\": [\"customField2\", \"customField4\"]\n }\n]\n```" id: $ref: '#/components/schemas/SchemaPropertyModel' name: $ref: '#/components/schemas/SchemaPropertyModel' identifier: $ref: '#/components/schemas/SchemaPropertyModel' description: $ref: '#/components/schemas/SchemaPropertyModel' public: $ref: '#/components/schemas/SchemaPropertyModel' active: $ref: '#/components/schemas/SchemaPropertyModel' status: $ref: '#/components/schemas/SchemaPropertyModel' statusExplanation: $ref: '#/components/schemas/SchemaPropertyModel' parent: $ref: '#/components/schemas/SchemaPropertyModel' createdAt: $ref: '#/components/schemas/SchemaPropertyModel' updatedAt: $ref: '#/components/schemas/SchemaPropertyModel' _links: type: object description: Links related to this resource properties: self: type: object properties: href: type: string example: /api/v3/workspaces/schema patternProperties: ^customField\d+$: $ref: '#/components/schemas/SchemaPropertyModel' ^customComment\d+$: $ref: '#/components/schemas/SchemaPropertyModel' example: _type: Schema _dependencies: [] _attributeGroups: - _type: ProjectFormCustomFieldSection name: Project Details attributes: - customField30 - customField34 - _type: ProjectFormCustomFieldSection name: Budget Information attributes: - customField31 - customField32 - customField35 id: type: Integer name: ID required: true hasDefault: false writable: false name: type: String name: Name required: true hasDefault: false writable: true minLength: 1 maxLength: 255 identifier: type: String name: Identifier required: true hasDefault: false writable: true minLength: 1 maxLength: 100 description: type: Formattable name: Description required: false hasDefault: false writable: true public: type: Boolean name: Public required: true hasDefault: false writable: true active: type: Boolean name: Active required: true hasDefault: true writable: true status: type: ProjectStatus name: Status required: false hasDefault: true writable: true _links: allowedValues: - href: /api/v3/project_statuses/on_track title: On track - href: /api/v3/project_statuses/at_risk title: At risk - href: /api/v3/project_statuses/off_track title: Off track statusExplanation: type: Formattable name: Status explanation required: false hasDefault: false writable: true parent: type: Workspace name: Subproject of required: false hasDefault: false writable: true location: _links visibility: default _links: {} createdAt: type: DateTime name: Created on required: true hasDefault: false writable: false updatedAt: type: DateTime name: Updated on required: true hasDefault: false writable: false customField30: type: Integer name: Integer project custom field required: false hasDefault: false writable: true visibility: default customField31: type: CustomOption name: List project custom field required: false hasDefault: false writable: true location: _links visibility: default _links: {} customField32: type: Version name: Version project custom field required: false hasDefault: false writable: true location: _links visibility: default _links: {} customField34: type: Boolean name: Boolean project custom field required: false hasDefault: false writable: true visibility: default customField35: type: String name: Text project custom field required: true hasDefault: false writable: true visibility: default customComment35: type: String name: Text project custom field comment required: false hasDefault: false writable: true _links: self: href: /api/v3/workspaces/schema CollectionLinks: type: object required: - self properties: self: allOf: - $ref: '#/components/schemas/Link' - description: 'This collection resource. **Resource**: Collection' Link: type: object required: - href properties: href: type: - string - 'null' description: URL to the referenced resource (might be relative) title: type: string description: Representative label for the resource templated: type: boolean default: false description: If true the href contains parts that need to be replaced by the client method: type: string default: GET description: The HTTP verb to use when requesting the resource payload: type: object description: The payload to send in the request to achieve the desired result identifier: type: string description: An optional unique identifier to the link object type: type: string description: The MIME-Type of the returned resource. example: href: /api/v3/work_packages method: POST Types_by_WorkspaceModel: allOf: - $ref: '#/components/schemas/CollectionModel' - type: object required: - _links - _embedded properties: _links: type: object required: - self properties: self: allOf: - $ref: '#/components/schemas/Link' - description: 'The types collection **Resource**: TypesCollection' readOnly: true _embedded: type: object properties: elements: type: array readOnly: true items: allOf: - $ref: '#/components/schemas/TypeModel' - description: Collection of Types ErrorResponse: type: object required: - _type - errorIdentifier - message properties: _embedded: type: object properties: details: type: object properties: attribute: type: string example: project _type: type: string enum: - Error errorIdentifier: type: string example: urn:openproject-org:api:v3:errors:PropertyConstraintViolation message: type: string example: Project can't be blank. SchemaPropertyModel: type: object required: - type - name - required - hasDefault - writable properties: type: type: string description: The resource type for this property. name: type: string description: The name of the property. required: type: boolean description: Indicates, if the property is required for submitting a request of this schema. hasDefault: type: boolean description: Indicates, if the property has a default. writable: type: boolean description: Indicates, if the property is writable when sending a request of this schema. options: type: object description: Additional options for the property. location: type: string description: Defines the json path where the property is located in the payload. default: '' placeholder: type: string description: A placeholder for the property to display if the property has no value. _links: type: object description: Useful links for this property (e.g. an endpoint to fetch allowed values) securitySchemes: BasicAuth: type: http scheme: basic