Basware AdvancedPermissions API

The AdvancedPermissions API from Basware — 2 operation(s) for advancedpermissions.

Operations 5

GET /v1/advancedPermissions Returns advanced user rights -records posted to Basware API.
POST /v1/advancedPermissions Creates new advanced user rights -record(s), fully overwrites previous record if exists.
DELETE /v1/advancedPermissions Deletes data from Basware API. For manual one-time operations.
GET /v1/advancedPermissions/{externalCode} Returns single advanced user rights -record by externalCode -identifier.
PATCH /v1/advancedPermissions/{externalCode} Updates fields on specified advanced user rights -record. Preserves existing values in fields, which were not updated.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/basware-advancedpermissions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

basware-advancedpermissions-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Basware OAUTH2 authentication APIs AccountingDocuments Advanced Permissions API
  description: "**Using OAUTH2.0 authentication:**\n\nGet API access token from api.basware.com/tokens\n1. Using client id and client secret, which you can obtain from Basware. \n2. Specify which APIs can be accessed by using the token e.g. Read only access to vendors API only (these are called scopes). Available scopes are listed at <https://developer.basware.com/api/p2p/manual#AccessRights>. \n3. Each token has an expiration time, until which it can be used to call APIs.\n\nWhen using OAUTH2 authentication, you need to pass the OAUTH2 authentication token when calling Basware API endpoints. Available Basware API operations are documented at <https://api.basware.com/swagger>. \n\nSee the Basware API developer site at <https://developer.basware.com/api/p2p/manual#Authentication> for more details on API authentication."
  version: 1.0.0
  x-logo:
    url: https://fastapi.tiangolo.com/img/logo-margin/logo-teal.png
servers:
- url: https://api.basware.com
  description: Base URL declared by the provider in apis.yml (roadmap#122).
tags:
- name: AdvancedPermissions
paths:
  /v1/advancedPermissions:
    get:
      tags:
      - AdvancedPermissions
      summary: Returns advanced user rights -records posted to Basware API.
      description: ''
      parameters:
      - name: pageSize
        in: query
        description: "A limit for the number of items to be returned for one request. Li\n            items."
        schema:
          type: integer
          format: int32
          default: 500
      - name: companyCode
        in: query
        description: Company filter. Returns items for specific company.
        schema:
          type: string
          default: ''
      - name: lastUpdated
        in: query
        description: Date Filter. Returns items that have been updated after specified date.
        schema:
          type: string
          format: date-time
      - name: x-amz-meta-continuationtoken
        in: header
        description: Used to get next page of results when item count indicated by 'pageSize' is exceeded. A token is returned in header (not body) parameter 'X-amz-meta-continuationToken' of the response whenever there are more records to fetch. Post the received value here in a new HEADER parameter on the next GET request to receive the next page of results. When getting the next page of results, you must include the same query parameters that were used when getting the first page.
        schema:
          type: string
        example: 2701ea15-a2c9-43b1-a48b-3a840c78b668
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionResponse'
        '401':
          description: Unauthorized
        '404':
          description: Not found. Request was successful and no records were found.
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
    post:
      tags:
      - AdvancedPermissions
      summary: Creates new advanced user rights -record(s), fully overwrites previous record if exists.
      parameters:
      - name: Content-Type
        in: header
        description: Specifies the media type of the resource. Value application/json is supported.
        schema:
          type: string
        example: application/json
      requestBody:
        content:
          application/json-patch+json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
          application/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
          text/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
          application/*+json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/AdvancedPermissionEntity'
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/AdvancedPermissionEntity'
            text/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/AdvancedPermissionEntity'
        '400':
          description: Bad request
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '401':
          description: Unauthorized
        '409':
          description: Conflict
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
    delete:
      tags:
      - AdvancedPermissions
      summary: Deletes data from Basware API. For manual one-time operations.
      description: "For manual one-time operations only, such as a manual clean-up to remove test data generated during API integration development. Only removes records from API layer. \nDeletion in target systems needs to be done separately using the data deletion mechanisms available in each of the target system in addition to deleting the data in Basware API."
      requestBody:
        description: "Contains the body of the request.\n            Either externalCode or lastUpdated -field is required. If both values are provided, externalCode will have the priority."
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
          application/json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
          text/json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
          application/*+json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
        '202':
          description: RequestAccepted
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
        '400':
          description: BadRequest
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '401':
          description: Unauthorized
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
  /v1/advancedPermissions/{externalCode}:
    get:
      tags:
      - AdvancedPermissions
      summary: Returns single advanced user rights -record by externalCode -identifier.
      description: ''
      parameters:
      - name: externalCode
        in: path
        description: The ExternalCode of the entity to be fetched
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
            application/json:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
            text/json:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
        '401':
          description: Unauthorized
        '404':
          description: Not found. Request was successful and no records were found.
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
    patch:
      tags:
      - AdvancedPermissions
      summary: Updates fields on specified advanced user rights -record. Preserves existing values in fields, which were not updated.
      description: 'Note: Basware API considers ''null'' value in field(s) equivalent to the field(s) not being sent. For this reason patch method does not support setting field values to ''null''.'
      parameters:
      - name: externalCode
        in: path
        description: The ExternalCode of the AdvancedPermission to be updated
        required: true
        schema:
          type: string
      requestBody:
        description: Entity to be updated
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/AdvancedPermissionEntity'
          application/json:
            schema:
              $ref: '#/components/schemas/AdvancedPermissionEntity'
          text/json:
            schema:
              $ref: '#/components/schemas/AdvancedPermissionEntity'
          application/*+json:
            schema:
              $ref: '#/components/schemas/AdvancedPermissionEntity'
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
            application/json:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
            text/json:
              schema:
                $ref: '#/components/schemas/AdvancedPermissionEntity'
        '400':
          description: Bad request
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '401':
          description: Unauthorized
        '404':
          description: Not found. Record to update not found.
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
components:
  schemas:
    AdvancedPermissionEntity:
      required:
      - companies
      - externalCode
      - limit
      - loginAccount
      - priorityIndex
      type: object
      properties:
        loginAccount:
          maxLength: 100
          minLength: 1
          type: string
          description: Specifies the user's login name
          example: jyrki@basware.com
        rowApproveIterationCount:
          maximum: 2147483647
          minimum: 0
          type:
          - integer
          - 'null'
          description: This field is used to define if the user is shown in a picker in row approval.
          format: int32
          example: 0
        permissionCode1:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: '6210'
        permissionCode2:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: 6210,6211
        permissionCode3:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: 6209-6230
        permissionCode4:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: '*'
        permissionCode5:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: ''
        permissionCode6:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: ''
        permissionCode7:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: 'Allows user to approve coding lines based on dimension values (cost center, account, etc) when row approval and advanced permissions are in use. Dimensions are mapped to permission codes in P2P. The value of each individual field can be one of the following: 1) "*" (asterisk, meaning "all"), 2) list of comma separated values such as: "123, 23, 45, A18", 3) single range of values such as: "10-100". If a combination of these is required, multiple records can be posted for the same user. The field can also be left empty.'
          example: ''
        limit:
          maximum: 1000000000
          minimum: 0
          type: number
          description: Defines the user's coding line approval limit.
          format: double
          example: 0
        priorityIndex:
          maximum: 2147483647
          minimum: 0
          type: integer
          description: If there is more than one approver in the user picker, the priority index defines the order of the approvers in the picker.
          format: int32
          example: 0
        module:
          maxLength: 28
          minLength: 0
          type:
          - string
          - 'null'
          description: 'This field defines the P2P module. Available values: "IA" (Invoice Automation), "Purchase" (P2P Purchase), "Both" (both Invoice Administration and Purchase).'
          example: Purchase
        excludedValue:
          maxLength: 1000
          minLength: 0
          type:
          - string
          - 'null'
          description: This column is used to exclude a user from a process for coding rows requiring approval. When a user is excluded, the user will not receive an invoice for approval. The value can be anything, for example numeric (123, 23,45 - comma separated values), alphanumeric, special characters except single quote ('). The field can also be left empty. This field is based on tenant settings.
          example: ExcludedValue1
        companies:
          type: array
          items:
            $ref: '#/components/schemas/AdvancedPermissionCompanyEntity'
          description: List of company units to associate advanced permission to P2P organization hierarchy.
        externalCode:
          maxLength: 36
          minLength: 1
          type: string
          description: External identifier that is used as a key in API.
          example: 4847-31231212-212121-1212
        lastUpdated:
          type: string
          description: Timestamp when the record was last sent to API. Set automatically.
          format: date-time
      additionalProperties: false
    AdvancedPermissionResponse:
      type: object
      properties:
        advancedPermissions:
          type:
          - array
          - 'null'
          items:
            $ref: '#/components/schemas/AdvancedPermissionEntity'
      additionalProperties: false
    DeleteRequest:
      type: object
      properties:
        lastUpdated:
          type:
          - string
          - 'null'
          description: 'To delete records updated after specific time, use lastUpdated -field. This will delete all items that have been updated after the specified date. In response, user will get the taskStatus api link where the task status can be checked. Note: ''0001-01-01'' can be used to delete all records.'
          format: date-time
        externalCode:
          maxLength: 36
          minLength: 0
          type:
          - string
          - 'null'
          description: Single item can be deleted using externalCode and final status is returned immediately.
      additionalProperties: false
    AdvancedPermissionCompanyEntity:
      required:
      - active
      - companyCode
      type: object
      properties:
        companyCode:
          maxLength: 32
          minLength: 1
          type: string
          description: Defines a company code that is attached to the advanced user right.
          example: BW01
        active:
          type: boolean
          description: This flag will enable the data to be visible on UI, provided if the value is true, not visible in case of value is false. It will be also used for soft delete.
      additionalProperties: false
    ErrorEntity:
      type: object
      properties:
        externalCode:
          type:
          - string
          - 'null'
          description: External code of record on which error occurred (when available).
          example: 4847-31231212-212121-1212
        type:
          enum:
          - BUSINESS
          - VALIDATION
          - TECHNICAL
          - SECURITY
          type: string
          description: Error type.
          example: ''
        code:
          enum:
          - EXTERNAL_CODE_MISMATCH
          - SCHEMA_VALIDATION_ERROR
          - CONFLICT_IN_POST
          - DATA_ORIGIN_VALIDATION_ERROR
          - ACCESS_TOKEN_VALIDATION_ERROR
          - CREDENTIAL_VALIDATION_ERROR
          - PARAMETER_VALIDATION_ERROR
          - UNEXPECTED_ERROR
          - METHOD_NOT_ALLOWED
          - ENTITY_NOT_FOUND
          - DATA_VALIDATION_FAILED
          - SNS_PUBLISH_ERROR
          - SQS_PUBLISH_ERROR
          type: string
          description: Error code.
          example: ''
        message:
          type:
          - string
          - 'null'
          description: Specific error message.
          example: ''
        info:
          type:
          - string
          - 'null'
          description: Information about type of the error.
          example: ''
      additionalProperties: false
    DeleteResponse:
      type: object
      properties:
        statusApiLink:
          type:
          - string
          - 'null'
        taskName:
          type:
          - string
          - 'null'
        taskStatus:
          type:
          - string
          - 'null'
      additionalProperties: false
    ResponseEntityList:
      type: object
      properties:
        requestId:
          type:
          - string
          - 'null'
          description: ID of the request on which error occurred (generated by Basware API).
          example: fbc082a2-65a4-469c-b230-d84a252f18fc
        hasErrors:
          type: boolean
          description: Specifies whether the request has errors.
        errors:
          type:
          - array
          - 'null'
          items:
            $ref: '#/components/schemas/ErrorEntity'
      additionalProperties: false
      description: Errors returned here are returned synchronously from Basware API middle layer. Additional errors coming from target system(s) may be returned through errorFeedbacks API.
  securitySchemes:
    HTTPBasic:
      type: http
      scheme: basic