openapi: 3.0.3 info: title: Samsung SmartThings Apps Capabilities API description: 'The SmartThings API is the RESTful core of the SmartThings smart-home IoT platform. It is used to control devices, read device status, manage Locations, Rooms, and Modes, build Automations with Rules and Scenes, inspect Capabilities, and build SmartApps (Apps and Installed Apps) that subscribe to events and run Schedules. Requests are authenticated with a Personal Access Token (PAT) for testing or an OAuth 2.0 access token for production integrations, passed as `Authorization: Bearer {token}`. This document is grounded in the official SmartThings Swagger definition (https://swagger.api.smartthings.com/public/st-api.yml); some less-common endpoints (Apps, History, Virtual Devices, individual Subscription operations) are modeled from the public docs and SDK where a full path was not directly confirmed.' version: '1.0' contact: name: SmartThings Developers url: https://developer.smartthings.com servers: - url: https://api.smartthings.com/v1 description: SmartThings Cloud API security: - bearerAuth: [] - oauth2: [] tags: - name: Capabilities description: Standard and custom capability definitions. paths: /capabilities: get: operationId: listCapabilities tags: - Capabilities summary: List Capabilities responses: '200': description: A list of standard capabilities. content: application/json: schema: type: object properties: items: type: array items: $ref: '#/components/schemas/Capability' '401': $ref: '#/components/responses/Unauthorized' /capabilities/{capabilityId}/{capabilityVersion}: parameters: - name: capabilityId in: path required: true schema: type: string - name: capabilityVersion in: path required: true schema: type: integer get: operationId: getCapability tags: - Capabilities summary: Get a Capability responses: '200': description: The capability definition, including attributes and commands. content: application/json: schema: $ref: '#/components/schemas/Capability' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' components: schemas: Capability: type: object properties: id: type: string version: type: integer status: type: string name: type: string attributes: type: object additionalProperties: true commands: type: object additionalProperties: true Error: type: object properties: requestId: type: string error: type: object properties: code: type: string message: type: string details: type: array items: type: object additionalProperties: true responses: NotFound: description: The requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/Error' Unauthorized: description: Missing or invalid access token. content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: bearerAuth: type: http scheme: bearer description: 'A Personal Access Token (PAT) from https://account.smartthings.com/tokens or an OAuth 2.0 access token, passed as `Authorization: Bearer {token}`.' oauth2: type: oauth2 description: OAuth 2.0 authorization code flow for production integrations. flows: authorizationCode: authorizationUrl: https://api.smartthings.com/oauth/authorize tokenUrl: https://api.smartthings.com/oauth/token scopes: r:devices:*: Read devices x:devices:*: Control devices r:locations:*: Read locations w:locations:*: Manage locations r:scenes:*: Read scenes x:scenes:*: Execute scenes r:rules:*: Read rules w:rules:*: Manage rules