Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
title: Basware APIs for Purchase-to-Pay and Master Data import…
description: The Basware APIs documented here are for Purchase-to-Pay use cases and for importing Master Data to Basware services.
version: v1
servers:
- url: ''
security:
- Bearer: []
- oauth2authentication: []
tags:
- name: AdvancedPermissions
paths:
/v1/advancedPermissions:
get:
tags:
- AdvancedPermissions
summary: Returns advanced user rights -records posted to Basware API
description: ''
parameters:
- name: pageSize
in: query
description: "A limit for the number of items to be returned for one request. Li\n items."
schema:
type: integer
format: int32
default: 500
- name: companyCode
in: query
description: Company filter. Returns items for specific company.
schema:
type: string
default: ''
- name: lastUpdated
in: query
description: Date Filter. Returns items that have been updated after specified date.
schema:
type: string
format: date-time
- name: x-amz-meta-continuationtoken
in: header
description: Used to get next page of results when item count indicated by 'pageSize' is exceeded. A token is returned in header (not body) parameter 'X-amz-meta-continuationToken' of the response whenever there are more records to fetch. Post the received value here in a new HEADER parameter on the next GET request to receive the next page of results. When getting the next page of results, you must include the same query parameters that were used when getting the first page.
schema:
type: string
example: 2701ea15-a2c9-43b1-a48b-3a840c78b668
responses:
'200':
description: Success
content:
text/plain:
schema:
$ref: '#/components/schemas/AdvancedPermissionResponse'
application/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionResponse'
text/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionResponse'
'401':
description: Unauthorized
'404':
description: Not found. Request was successful and no records were found.
'500':
description: Unexpected error
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
operationId: getV1AdvancedPermissions
x-operation-id-source: derived
post:
tags:
- AdvancedPermissions
summary: Creates new advanced user rights -record(s), fully overwrites previous record…
parameters:
- name: Content-Type
in: header
description: Specifies the media type of the resource. Value application/json is supported.
schema:
type: string
example: application/json
requestBody:
content:
application/json-patch+json:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
text/json:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/*+json:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
responses:
'200':
description: Success
content:
text/plain:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
text/json:
schema:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
'400':
description: Bad request
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
'401':
description: Unauthorized
'409':
description: Conflict
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
'500':
description: Unexpected error
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
operationId: postV1AdvancedPermissions
x-operation-id-source: derived
delete:
tags:
- AdvancedPermissions
summary: Deletes data from Basware API. For manual one-time operations
description: 'For manual one-time operations only, such as a manual clean-up to remove test data generated during API integration development. Only removes records from API layer.
Deletion in target systems needs to be done separately using the data deletion mechanisms available in each of the target system in addition to deleting the data in Basware API.'
requestBody:
description: "Contains the body of the request.\n Either externalCode or lastUpdated -field is required. If both values are provided, externalCode will have the priority."
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/DeleteRequest'
application/json:
schema:
$ref: '#/components/schemas/DeleteRequest'
text/json:
schema:
$ref: '#/components/schemas/DeleteRequest'
application/*+json:
schema:
$ref: '#/components/schemas/DeleteRequest'
responses:
'200':
description: Success
content:
text/plain:
schema:
$ref: '#/components/schemas/DeleteResponse'
application/json:
schema:
$ref: '#/components/schemas/DeleteResponse'
text/json:
schema:
$ref: '#/components/schemas/DeleteResponse'
'202':
description: RequestAccepted
content:
text/plain:
schema:
$ref: '#/components/schemas/DeleteResponse'
application/json:
schema:
$ref: '#/components/schemas/DeleteResponse'
text/json:
schema:
$ref: '#/components/schemas/DeleteResponse'
'400':
description: BadRequest
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
'401':
description: Unauthorized
'500':
description: Unexpected error
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
operationId: deleteV1AdvancedPermissions
x-operation-id-source: derived
/v1/advancedPermissions/{externalCode}:
get:
tags:
- AdvancedPermissions
summary: Returns single advanced user rights -record by externalCode -identifier
description: ''
parameters:
- name: externalCode
in: path
description: The ExternalCode of the entity to be fetched
required: true
schema:
type: string
responses:
'200':
description: Success
content:
text/plain:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
text/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
'401':
description: Unauthorized
'404':
description: Not found. Request was successful and no records were found.
'500':
description: Unexpected error
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
operationId: getV1AdvancedPermissionsByExternalCode
x-operation-id-source: derived
patch:
tags:
- AdvancedPermissions
summary: Updates fields on specified advanced user rights -record.
description: 'Note: Basware API considers ''null'' value in field(s) equivalent to the field(s) not being sent. For this reason patch method does not support setting field values to ''null''.'
parameters:
- name: externalCode
in: path
description: The ExternalCode of the AdvancedPermission to be updated
required: true
schema:
type: string
requestBody:
description: Entity to be updated
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
text/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/*+json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
responses:
'200':
description: Success
content:
text/plain:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
application/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
text/json:
schema:
$ref: '#/components/schemas/AdvancedPermissionEntity'
'400':
description: Bad request
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
'401':
description: Unauthorized
'404':
description: Not found. Record to update not found.
'500':
description: Unexpected error
content:
text/plain:
schema:
$ref: '#/components/schemas/ResponseEntityList'
application/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
text/json:
schema:
$ref: '#/components/schemas/ResponseEntityList'
operationId: patchV1AdvancedPermissionsByExternalCode
x-operation-id-source: derived
components:
schemas:
AdvancedPermissionCompanyEntity:
required:
- active
- companyCode
type: object
properties:
companyCode:
maxLength: 32
minLength: 1
type: string
description: Defines a company code that is attached to the advanced user right.
example: BW01
active:
type: boolean
description: This flag will enable the data to be visible on UI, provided if the value is true, not visible in case of value is false. It will be also used for soft delete.
additionalProperties: false
ErrorEntity:
type: object
properties:
externalCode:
type:
- string
- 'null'
description: External code of record on which error occurred (when available).
example: 4847-31231212-212121-1212
type:
enum:
- BUSINESS
- VALIDATION
- TECHNICAL
- SECURITY
type: string
description: Error type.
example: ''
code:
enum:
- EXTERNAL_CODE_MISMATCH
- SCHEMA_VALIDATION_ERROR
- CONFLICT_IN_POST
- DATA_ORIGIN_VALIDATION_ERROR
- ACCESS_TOKEN_VALIDATION_ERROR
- CREDENTIAL_VALIDATION_ERROR
- PARAMETER_VALIDATION_ERROR
- UNEXPECTED_ERROR
- METHOD_NOT_ALLOWED
- ENTITY_NOT_FOUND
- DATA_VALIDATION_FAILED
- SNS_PUBLISH_ERROR
- SQS_PUBLISH_ERROR
type: string
description: Error code.
example: ''
message:
type:
- string
- 'null'
description: Specific error message.
example: ''
info:
type:
- string
- 'null'
description: Information about type of the error.
example: ''
additionalProperties: false
DeleteRequest:
type: object
properties:
lastUpdated:
type:
- string
- 'null'
description: 'To delete records updated after specific time, use lastUpdated -field. This will delete all items that have been updated after the specified date. In response, user will get the taskStatus api link where the task status can be checked. Note: ''0001-01-01'' can be used to delete all records.'
format: date-time
externalCode:
maxLength: 36
minLength: 0
type:
- string
- 'null'
description: Single item can be deleted using externalCode and final status is returned immediately.
additionalProperties: false
DeleteResponse:
type: object
properties:
statusApiLink:
type:
- string
- 'null'
taskName:
type:
- string
- 'null'
taskStatus:
type:
- string
- 'null'
additionalProperties: false
ResponseEntityList:
type: object
properties:
requestId:
type:
- string
- 'null'
description: ID of the request on which error occurred (generated by Basware API).
example: fbc082a2-65a4-469c-b230-d84a252f18fc
hasErrors:
type: boolean
description: Specifies whether the request has errors.
errors:
type:
- array
- 'null'
items:
$ref: '#/components/schemas/ErrorEntity'
additionalProperties: false
description: Errors returned here are returned synchronously from Basware API middle layer. Additional errors coming from target system(s) may be returned through errorFeedbacks API.
AdvancedPermissionResponse:
type: object
properties:
advancedPermissions:
type:
- array
- 'null'
items:
$ref: '#/components/schemas/AdvancedPermissionEntity'
additionalProperties: false
AdvancedPermissionEntity:
required:
- companies
- externalCode
- limit
- loginAccount
- priorityIndex
type: object
properties:
loginAccount:
maxLength: 100
minLength: 1
type: string
description: Specifies the user's login name
example: jyrki@basware.com
rowApproveIterationCount:
maximum: 2147483647
minimum: 0
type:
- integer
- 'null'
description: This field is used to define if the user is shown in a picker in row approval.
format: int32
example: 0
permissionCode1:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: '6210'
permissionCode2:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: 6210,6211
permissionCode3:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: 6209-6230
permissionCode4:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: '*'
permissionCode5:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: ''
permissionCode6:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: ''
permissionCode7:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
example: ''
limit:
maximum: 1000000000
minimum: 0
type: number
description: Defines the user's coding line approval limit.
format: double
example: 0
priorityIndex:
maximum: 2147483647
minimum: 0
type: integer
description: If there is more than one approver in the user picker, the priority index defines the order of the approvers in the picker.
format: int32
example: 0
module:
maxLength: 28
minLength: 0
type:
- string
- 'null'
description: 'This field defines the P2P module. Available values: "IA" (Invoice Automation), "Purchase" (P2P Purchase), "Both" (both Invoice Administration and Purchase).'
example: Purchase
excludedValue:
maxLength: 1000
minLength: 0
type:
- string
- 'null'
description: This column is used to exclude a user from a process for coding rows requiring approval. When a user is excluded, the user will not receive an invoice for approval. The value can be anything, for example numeric (123, 23,45 - comma separated values), alphanumeric, special characters except single quote ('). The field can also be left empty. This field is based on tenant settings.
example: ExcludedValue1
companies:
type: array
items:
$ref: '#/components/schemas/AdvancedPermissionCompanyEntity'
description: List of company units to associate advanced permission to P2P organization hierarchy.
externalCode:
maxLength: 36
minLength: 1
type: string
description: External identifier that is used as a key in API.
example: 4847-31231212-212121-1212
lastUpdated:
type: string
description: Timestamp when the record was last sent to API. Set automatically.
format: date-time
additionalProperties: false
securitySchemes:
Bearer:
type: http
description: Please insert basic authentication credentials into fields
scheme: basic
oauth2authentication:
type: oauth2
description: Oauth2 client credentials flow.
flows:
clientCredentials:
tokenUrl: https://api.basware.com/v1/tokens
scopes:
accountingDocuments.read: GET accountingDocuments
accountingDocuments.write: POST/PATCH accountingDocuments
accountingDocuments.delete: DELETE accountingDocuments
accounts.read: GET accounts
accounts.write: POST/PATCH accounts
accounts.delete: DELETE accounts
advancedPermissions.read: GET advancedPermissions
advancedPermissions.write: POST/PATCH advancedPermissions
advancedPermissions.delete: DELETE advancedPermissions
advancedValidations.read: GET advancedValidations
advancedValidations.write: POST/PATCH advancedValidations
advancedValidations.delete: DELETE advancedValidations
applicationGroups.read: GET applicationGroups
applicationGroups.write: POST/PATCH applicationGroups
companies.read: GET companies
companies.write: POST/PATCH companies
contracts.delete: DELETE contracts
contracts.read: GET contracts
contracts.write: POST/PATCH contracts
costCenters.read: GET costCenters
costCenters.write: POST/PATCH costCenters
costCenters.delete: DELETE costCenters
errorFeedbacks.read: GET errorFeedbacks
errorFeedbacks.write: POST/PATCH errorFeedbacks
errorFeedbacks.delete: DELETE errorFeedbacks
exchangeRates.read: GET exchangeRates
exchangeRates.write: POST/PATCH exchangeRates
exchangeRates.delete: DELETE exchangeRates
exportedContracts.read: GET exportedContracts
exportedContracts.write: POST/PATCH exportedContracts
exportedContracts.delete: DELETE exportedContracts
exportedContractSpends.read: GET exportedContractSpends
exportedContractSpends.write: POST/PATCH exportedContractSpends
exportedContractSpends.delete: DELETE exportedContractSpends
exportedPurchaseOrders.read: GET exportedPurchaseOrders
exportedPurchaseOrders.write: POST/PATCH exportedPurchaseOrders
exportedPurchaseOrders.delete: DELETE exportedPurchaseOrders
exportedPurchaseRequisitions.read: GET exportedPurchaseRequisitions
exportedPurchaseRequisitions.write: POST/PATCH exportedPurchaseRequisitions
exportedPurchaseRequisitions.delete: DELETE exportedPurchaseRequisitions
lists.read: GET lists
lists.write: POST/PATCH lists
lists.delete: DELETE lists
matchingOrders.read: GET matchingOrders
matchingOrders.write: POST/PATCH matchingOrders
matchingOrders.delete: DELETE matchingOrders
matchingOrderLines.read: GET matchingOrderLines
matchingOrderLines.write: POST/PATCH matchingOrderLines
matchingOrderLines.delete: DELETE matchingOrderLines
paymentTerms.read: GET paymentTerms
paymentTerms.write: POST/PATCH paymentTerms
paymentTerms.delete: DELETE paymentTerms
projects.read: GET projects
projects.write: POST/PATCH projects
projects.delete: DELETE projects
purchaseOrders.read: GET purchaseOrders
purchaseOrders.write: POST/PATCH purchaseOrders
purchaseOrders.delete: DELETE purchaseOrders
purchaseRequisitions.read: GET purchaseRequisitions
purchaseRequisitions.write: POST/PATCH purchaseRequisitions
purchaseRequisitions.delete: DELETE purchaseRequisitions
purchaseGoodsReceipts.read: GET purchaseGoodsReceipts
purchaseGoodsReceipts.write: POST/PATCH purchaseGoodsReceipts
purchaseGoodsReceipts.delete: DELETE purchaseGoodsReceipts
requestStatus.read: GET requestStatus
requestStatus.write: POST/PATCH requestStatus
subscriptions.read: GET subscriptions
subscriptions.write: POST/PATCH subscriptions
subscriptions.delete: DELETE subscriptions
tasks.read: GET tasks
taskStatus.read: GET taskStatus
taxCodes.read: GET taxCodes
taxCodes.write: POST/PATCH taxCodes
taxCodes.delete: DELETE taxCodes
users.read: GET users
users.write: POST/PATCH users
users.delete: DELETE users
vendors.read: GET vendors
vendors.write: POST/PATCH vendors
vendors.delete: DELETE vendors