Basware Contracts API

The Contracts API from Basware — 2 operation(s) for contracts.

Business capability
Procurement Contract Management BC-500.20

Operations 5

GET /v1/contracts Returns contract entities #
POST /v1/contracts Creates new contract entity, overwrites previous if exists #
DELETE /v1/contracts Deletes data from Basware API. For manual one-time operations #
GET /v1/contracts/{externalCode} Returns single contract entity by ID #
PATCH /v1/contracts/{externalCode} Updates contract entity. #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/basware-contracts-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

basware-contracts-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Basware APIs for Purchase-to-Pay and Master Data import…
  description: The Basware APIs documented here are for Purchase-to-Pay use cases and for importing Master Data to Basware services.
  version: v1
servers:
- url: ''
security:
- Bearer: []
- oauth2authentication: []
tags:
- name: Contracts
paths:
  /v1/contracts:
    get:
      tags:
      - Contracts
      summary: Returns contract entities
      description: ''
      parameters:
      - name: pageSize
        in: query
        description: A limit for the number of items to be returned for one request. Limit can range between 1 and 500 items.
        schema:
          type: integer
          format: int32
          default: 500
      - name: companyCode
        in: query
        description: Company filter. Returns items for specific company.
        schema:
          type: string
          default: ''
      - name: lastUpdated
        in: query
        description: Date Filter. Returns items that have been updated after specified date.
        schema:
          type: string
          format: date-time
      - name: x-amz-meta-continuationtoken
        in: header
        description: Used to get next page of results when item count indicated by 'pageSize' is exceeded. A token is returned in header (not body) parameter 'X-amz-meta-continuationToken' of the response whenever there are more records to fetch. Post the received value here in a new HEADER parameter on the next GET request to receive the next page of results. When getting the next page of results, you must include the same query parameters that were used when getting the first page.
        schema:
          type: string
        example: 20577767-3fd9-4dda-9667-a7d7ee00ac95
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ContractResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/ContractResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/ContractResponse'
        '401':
          description: Unauthorized
        '404':
          description: Not found. Request was successful and no records were found.
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
      operationId: getV1Contracts
      x-operation-id-source: derived
    post:
      tags:
      - Contracts
      summary: Creates new contract entity, overwrites previous if exists
      description: 'Notes:

        1. The supplier and company code used need to exist in P2P.

        2. P2P needs to know the exchange rate from contract currency to company currency (if there are different).'
      parameters:
      - name: Content-Type
        in: header
        description: Specifies the media type of the resource. Value application/json is supported.
        schema:
          type: string
        example: application/json
      requestBody:
        content:
          application/json-patch+json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/ContractEntity'
          application/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/ContractEntity'
          text/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/ContractEntity'
          application/*+json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/ContractEntity'
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ContractEntity'
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ContractEntity'
            text/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ContractEntity'
        '400':
          description: Bad request
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '401':
          description: Unauthorized
        '409':
          description: Conflict
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
      operationId: postV1Contracts
      x-operation-id-source: derived
    delete:
      tags:
      - Contracts
      summary: Deletes data from Basware API. For manual one-time operations
      description: 'For manual one-time operations only, such as a manual clean-up to remove test data generated during API integration development. Only removes records from API layer.

        Deletion in target systems needs to be done separately using the data deletion mechanisms available in each of the target system in addition to deleting the data in Basware API.'
      requestBody:
        description: "Contains the body of the request.\n            Either externalCode or lastUpdated -field is required. If both values are provided, externalCode will have the priority."
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
          application/json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
          text/json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
          application/*+json:
            schema:
              $ref: '#/components/schemas/DeleteRequest'
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
        '202':
          description: RequestAccepted
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
            text/json:
              schema:
                $ref: '#/components/schemas/DeleteResponse'
        '400':
          description: BadRequest
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '401':
          description: Unauthorized
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
      operationId: deleteV1Contracts
      x-operation-id-source: derived
  /v1/contracts/{externalCode}:
    get:
      tags:
      - Contracts
      summary: Returns single contract entity by ID
      description: ''
      parameters:
      - name: externalCode
        in: path
        description: The ExternalCode of the contract to be fetched
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ContractEntity'
            application/json:
              schema:
                $ref: '#/components/schemas/ContractEntity'
            text/json:
              schema:
                $ref: '#/components/schemas/ContractEntity'
        '401':
          description: Unauthorized
        '404':
          description: Not found. Request was successful and no records were found.
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
      operationId: getV1ContractsByExternalCode
      x-operation-id-source: derived
    patch:
      tags:
      - Contracts
      summary: Updates contract entity.
      description: 'Note: Contract currency can no longer be changed if spend has been collected for the contract.'
      parameters:
      - name: externalCode
        in: path
        description: The ExternalCode of the contract to be updated
        required: true
        schema:
          type: string
      requestBody:
        description: Entity to be updated
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/ContractEntity'
          application/json:
            schema:
              $ref: '#/components/schemas/ContractEntity'
          text/json:
            schema:
              $ref: '#/components/schemas/ContractEntity'
          application/*+json:
            schema:
              $ref: '#/components/schemas/ContractEntity'
      responses:
        '200':
          description: Success
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ContractEntity'
            application/json:
              schema:
                $ref: '#/components/schemas/ContractEntity'
            text/json:
              schema:
                $ref: '#/components/schemas/ContractEntity'
        '400':
          description: Bad request
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
        '401':
          description: Unauthorized
        '404':
          description: Not found. Record to update not found.
        '500':
          description: Unexpected error
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            application/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
            text/json:
              schema:
                $ref: '#/components/schemas/ResponseEntityList'
      operationId: patchV1ContractsByExternalCode
      x-operation-id-source: derived
components:
  schemas:
    ContractSuppliers:
      required:
      - supplierCode
      type: object
      properties:
        supplierCode:
          maxLength: 25
          minLength: 1
          type: string
          description: Code of the supplier on the contract. This supplier needs to exist in P2P and be available on the selected company.
          example: '32789'
        supplierName:
          maxLength: 250
          minLength: 0
          type:
          - string
          - 'null'
          description: Name of the supplier on the contract. Informative field, P2P will take supplier name from it's supplier registry.
          example: Acme Motor Leasing inc.
      additionalProperties: false
    ErrorEntity:
      type: object
      properties:
        externalCode:
          type:
          - string
          - 'null'
          description: External code of record on which error occurred (when available).
          example: 4847-31231212-212121-1212
        type:
          enum:
          - BUSINESS
          - VALIDATION
          - TECHNICAL
          - SECURITY
          type: string
          description: Error type.
          example: ''
        code:
          enum:
          - EXTERNAL_CODE_MISMATCH
          - SCHEMA_VALIDATION_ERROR
          - CONFLICT_IN_POST
          - DATA_ORIGIN_VALIDATION_ERROR
          - ACCESS_TOKEN_VALIDATION_ERROR
          - CREDENTIAL_VALIDATION_ERROR
          - PARAMETER_VALIDATION_ERROR
          - UNEXPECTED_ERROR
          - METHOD_NOT_ALLOWED
          - ENTITY_NOT_FOUND
          - DATA_VALIDATION_FAILED
          - SNS_PUBLISH_ERROR
          - SQS_PUBLISH_ERROR
          type: string
          description: Error code.
          example: ''
        message:
          type:
          - string
          - 'null'
          description: Specific error message.
          example: ''
        info:
          type:
          - string
          - 'null'
          description: Information about type of the error.
          example: ''
      additionalProperties: false
    DeleteResponse:
      type: object
      properties:
        statusApiLink:
          type:
          - string
          - 'null'
        taskName:
          type:
          - string
          - 'null'
        taskStatus:
          type:
          - string
          - 'null'
      additionalProperties: false
    ContractExternalLinks:
      required:
      - externalLinkName
      type: object
      properties:
        externalLinkName:
          maxLength: 512
          minLength: 1
          type: string
          description: Name shown in UI for external link
          example: Acme motor leasing
        externalLinkURL:
          maxLength: 2000
          minLength: 1
          type:
          - string
          - 'null'
          description: URL used when selecting external link
          example: https://www.acmemotorsinc.com
      additionalProperties: false
      description: Contract external links
    ContractResponse:
      required:
      - contracts
      type: object
      properties:
        contracts:
          type: array
          items:
            $ref: '#/components/schemas/ContractEntity'
      additionalProperties: false
    DeleteRequest:
      type: object
      properties:
        lastUpdated:
          type:
          - string
          - 'null'
          description: 'To delete records updated after specific time, use lastUpdated -field. This will delete all items that have been updated after the specified date. In response, user will get the taskStatus api link where the task status can be checked. Note: ''0001-01-01'' can be used to delete all records.'
          format: date-time
        externalCode:
          maxLength: 36
          minLength: 0
          type:
          - string
          - 'null'
          description: Single item can be deleted using externalCode and final status is returned immediately.
      additionalProperties: false
    ResponseEntityList:
      type: object
      properties:
        requestId:
          type:
          - string
          - 'null'
          description: ID of the request on which error occurred (generated by Basware API).
          example: fbc082a2-65a4-469c-b230-d84a252f18fc
        hasErrors:
          type: boolean
          description: Specifies whether the request has errors.
        errors:
          type:
          - array
          - 'null'
          items:
            $ref: '#/components/schemas/ErrorEntity'
      additionalProperties: false
      description: Errors returned here are returned synchronously from Basware API middle layer. Additional errors coming from target system(s) may be returned through errorFeedbacks API.
    ContractEntity:
      required:
      - active
      - companyCode
      - currencyCode
      - externalCode
      - owner
      - referenceCode
      - suppliers
      - title
      - total
      - validFrom
      - validTo
      type: object
      properties:
        referenceCode:
          maxLength: 255
          minLength: 1
          type: string
          description: FreeText reference shown in contracts view (Contract Number). Same company and vendor -combination(s) must not use same reference code (contract number) multiple times.
          example: '12197627'
        companyCode:
          maxLength: 32
          minLength: 1
          type: string
          description: Buyer Company Code. This company needs to exist in P2P before importing the contract.
          example: '200'
        title:
          maxLength: 250
          minLength: 1
          type: string
          description: A short name generally used to identify the contract in reporting.
          example: Car leasing
        description:
          maxLength: 2000
          minLength: 0
          type:
          - string
          - 'null'
          description: General information on contract.
          example: This contract is for car leasing for Acme Motor leasing inc.
        type:
          maxLength: 100
          minLength: 1
          type:
          - string
          - 'null'
          description: Determined by the contract management system. Types are displayed only for informational purposes.
          example: Leasing
        validFrom:
          type: string
          description: The date on which the contract legally came in to force.
          format: date-time
          example: '2021-01-01'
        validTo:
          type: string
          description: The date on which the contract will naturally end if not active decisions are made to extend or terminate early.
          format: date-time
          example: '2025-01-01'
        total:
          maximum: 9999999999999
          minimum: 0
          type: number
          description: Total expected expenditure under this contract between the Start and End Dates specified above.
          format: double
          example: 10000
        amountType:
          enum:
          - Net
          - Gross
          type:
          - string
          - 'null'
          description: 'Net or Gross. Default value: Net.'
          example: net
        currencyCode:
          maxLength: 3
          minLength: 2
          type: string
          description: 'Currency used in the contract. Note: 1) P2P needs to have an exhange rate configured from contract curency currency of the company used on contract (if they are different). 2) Contract currency cannot be changed if spend has been collected for the contract.'
          example: EUR
        paymentTermCode:
          maxLength: 250
          minLength: 0
          type:
          - string
          - 'null'
          description: Payment term for this contract.
          example: NET30
        owner:
          maxLength: 100
          minLength: 1
          type: string
          description: The person owning the contract.
          example: Liz Black
        contactPerson:
          maxLength: 100
          minLength: 0
          type:
          - string
          - 'null'
          description: The person to contact on contract matters.
          example: Liz Black
        active:
          type: boolean
          description: States if the contract can be used or not.
          example: true
        suppliers:
          type: array
          items:
            $ref: '#/components/schemas/ContractSuppliers'
          description: Supplier(s) for contract.
        externalLinks:
          type:
          - array
          - 'null'
          items:
            $ref: '#/components/schemas/ContractExternalLinks'
          description: ExternalLinks for contract.
        orderSpend:
          type:
          - boolean
          - 'null'
          description: States if spend of orders using this contract is collected for spend reporting.
          example: true
        spendPlanSpend:
          type:
          - boolean
          - 'null'
          description: Field reserved for future use (to state if spend of spend plans using this contract is collected for spend reporting).
          example: false
        invoiceSpend:
          type:
          - boolean
          - 'null'
          description: Field reserved for future use (to state if spend of invoices linked to this contract is collected for spend reporting).
          example: false
        externalCode:
          maxLength: 36
          minLength: 1
          type: string
          description: External identifier that is used as a key in API.
          example: 4847-31231212-212121-1212
        lastUpdated:
          type: string
          description: Timestamp when the record was last sent to API. Set automatically.
          format: date-time
      additionalProperties: false
      description: ''
  securitySchemes:
    Bearer:
      type: http
      description: Please insert basic authentication credentials into fields
      scheme: basic
    oauth2authentication:
      type: oauth2
      description: Oauth2 client credentials flow.
      flows:
        clientCredentials:
          tokenUrl: https://api.basware.com/v1/tokens
          scopes:
            accountingDocuments.read: GET accountingDocuments
            accountingDocuments.write: POST/PATCH accountingDocuments
            accountingDocuments.delete: DELETE accountingDocuments
            accounts.read: GET accounts
            accounts.write: POST/PATCH accounts
            accounts.delete: DELETE accounts
            advancedPermissions.read: GET advancedPermissions
            advancedPermissions.write: POST/PATCH advancedPermissions
            advancedPermissions.delete: DELETE advancedPermissions
            advancedValidations.read: GET advancedValidations
            advancedValidations.write: POST/PATCH advancedValidations
            advancedValidations.delete: DELETE advancedValidations
            applicationGroups.read: GET applicationGroups
            applicationGroups.write: POST/PATCH applicationGroups
            companies.read: GET companies
            companies.write: POST/PATCH companies
            contracts.delete: DELETE contracts
            contracts.read: GET contracts
            contracts.write: POST/PATCH contracts
            costCenters.read: GET costCenters
            costCenters.write: POST/PATCH costCenters
            costCenters.delete: DELETE costCenters
            errorFeedbacks.read: GET errorFeedbacks
            errorFeedbacks.write: POST/PATCH errorFeedbacks
            errorFeedbacks.delete: DELETE errorFeedbacks
            exchangeRates.read: GET exchangeRates
            exchangeRates.write: POST/PATCH exchangeRates
            exchangeRates.delete: DELETE exchangeRates
            exportedContracts.read: GET exportedContracts
            exportedContracts.write: POST/PATCH exportedContracts
            exportedContracts.delete: DELETE exportedContracts
            exportedContractSpends.read: GET exportedContractSpends
            exportedContractSpends.write: POST/PATCH exportedContractSpends
            exportedContractSpends.delete: DELETE exportedContractSpends
            exportedPurchaseOrders.read: GET exportedPurchaseOrders
            exportedPurchaseOrders.write: POST/PATCH exportedPurchaseOrders
            exportedPurchaseOrders.delete: DELETE exportedPurchaseOrders
            exportedPurchaseRequisitions.read: GET exportedPurchaseRequisitions
            exportedPurchaseRequisitions.write: POST/PATCH exportedPurchaseRequisitions
            exportedPurchaseRequisitions.delete: DELETE exportedPurchaseRequisitions
            lists.read: GET lists
            lists.write: POST/PATCH lists
            lists.delete: DELETE lists
            matchingOrders.read: GET matchingOrders
            matchingOrders.write: POST/PATCH matchingOrders
            matchingOrders.delete: DELETE matchingOrders
            matchingOrderLines.read: GET matchingOrderLines
            matchingOrderLines.write: POST/PATCH matchingOrderLines
            matchingOrderLines.delete: DELETE matchingOrderLines
            paymentTerms.read: GET paymentTerms
            paymentTerms.write: POST/PATCH paymentTerms
            paymentTerms.delete: DELETE paymentTerms
            projects.read: GET projects
            projects.write: POST/PATCH projects
            projects.delete: DELETE projects
            purchaseOrders.read: GET purchaseOrders
            purchaseOrders.write: POST/PATCH purchaseOrders
            purchaseOrders.delete: DELETE purchaseOrders
            purchaseRequisitions.read: GET purchaseRequisitions
            purchaseRequisitions.write: POST/PATCH purchaseRequisitions
            purchaseRequisitions.delete: DELETE purchaseRequisitions
            purchaseGoodsReceipts.read: GET purchaseGoodsReceipts
            purchaseGoodsReceipts.write: POST/PATCH purchaseGoodsReceipts
            purchaseGoodsReceipts.delete: DELETE purchaseGoodsReceipts
            requestStatus.read: GET requestStatus
            requestStatus.write: POST/PATCH requestStatus
            subscriptions.read: GET subscriptions
            subscriptions.write: POST/PATCH subscriptions
            subscriptions.delete: DELETE subscriptions
            tasks.read: GET tasks
            taskStatus.read: GET taskStatus
            taxCodes.read: GET taxCodes
            taxCodes.write: POST/PATCH taxCodes
            taxCodes.delete: DELETE taxCodes
            users.read: GET users
            users.write: POST/PATCH users
            users.delete: DELETE users
            vendors.read: GET vendors
            vendors.write: POST/PATCH vendors
            vendors.delete: DELETE vendors