Bonitasoft Authentication API

Authentication

Operations 2

POST /loginservice Login #
GET /logoutservice Logout the current user #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/bonitasoft-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

bonitasoft-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  license:
    name: GPL-v2.0
    url: http://www.gnu.org/licenses/gpl-2.0.txt
  version: 1.0.9
  title: Bonita Authentication API
  description: 'Download OpenAPI specification

    Download Postman collection


    The REST API lets you access the data with HTTP requests; it is useful when implementing rich web forms / pages for a good user experience.'
  x-logo:
    url: images/ofelia-logo.svg
    backgroundColor: '#19465f'
    altText: Bonita API
    href: /
servers:
- url: http://localhost:8080/bonita
  description: Sample url for a local development server.
security:
- bonita_auth: []
  bonita_token: []
- bearer_auth: []
tags:
- name: Authentication
  x-displayName: Authentication
  description: Authentication
paths:
  /loginservice:
    post:
      tags:
      - Authentication
      operationId: login
      security: []
      summary: Login
      description: 'A call to the `/loginservice` will generates a set-cookie header in the response.


        The `JSESSIONID` cookie must be transfered with each subsequent calls. (If the REST API is used in an application running in a web browser, this is handled automatically by the web browser just like any cookies).


        Additional protection agains CSRF attacks is enabled by default for all fresh installations This security relies on `X-Bonita-API-Token` information.

        The `X-Bonita-API-Token` value can be found in the cookie named: `X-Bonita-API-Token`.


        All the subsequence REST API calls performing changes in the system using DELETE, POST, or PUT HTTP methods must contain the **HTTP header** below:


        ``` X-Bonita-API-Token: example-dummy-not-be-used-value ```'
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/LoginRequest'
      x-codeSamples:
      - lang: Shell
        label: Curl
        source: "# Generate cookie file\ncurl -v -c saved_cookies.txt \\\n--url 'http://localhost:8080/bonita/loginservice' \\\n--header 'Content-Type: application/x-www-form-urlencoded'\n  --data-urlencode 'username=install' \\\n  --data-urlencode 'password=install' \\\n  --data-urlencode 'redirect=false' \\\n  --data-urlencode 'redirectURL='\n  \n  # Reuse the cookie file and set the `X-Bonita-API-Token` header\n  curl -b saved_cookies.txt -X GET \\\n-- header 'X-Bonita-API-Token: <token>' \\\n--url 'http://localhost:8080/bonita/API/bpm/process?c=100&p=0'\n"
      responses:
        '204':
          description: Login success
          headers:
            Set-Cookie:
              description: Session cookie
              schema:
                type: string
                example: JSESSIONID=C5385BFEE2969D9E46F0160C1952B0F1; Path=/bonita; HttpOnly; SameSite=Lax
            X-Bonita-API-Token:
              description: X-Bonita-API-Token - CSRF token (also present in the cookie response)
              schema:
                type: string
              example: ed27cbeb-9953-4d77-b5a2-1f62a6c2e0bb
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        5XX:
          $ref: '#/components/responses/ServerError'
  /logoutservice:
    get:
      tags:
      - Authentication
      summary: Logout the current user
      description: Logout the current user from the system
      operationId: logout
      parameters:
      - description: Setting the redirect parameter to false indicates that the service should not redirect to the login page after logging out.
        explode: true
        in: query
        name: redirect
        required: false
        schema:
          type: string
          maxLength: 5
          pattern: ^(?:tru|fals)e$
        style: form
        example:
          redirect: 'false'
          redirectURL: null
      x-codeSamples:
      - lang: Shell
        label: Curl
        source: 'curl -b saved_cookies.txt -X GET --url ''http://localhost:8080/bonita/logoutservice?redirect=false''

          '
      responses:
        '200':
          description: 'Success '
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        5XX:
          $ref: '#/components/responses/ServerError'
components:
  responses:
    Unauthorized:
      description: Authorization information is missing or invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Unauthorized
    BadRequest:
      description: Bad request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Bad request
    Forbidden:
      description: Forbidden, The request contained valid data and was understood by the server, but the server is refusing action.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Forbidden, The request contained valid data and was understood by the server, but the server is refusing action.
    ServerError:
      description: Unexpected error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: An unexpected error occured.
  schemas:
    LoginRequest:
      type: object
      required:
      - username
      - password
      properties:
        username:
          type: string
          description: the username
        password:
          type: string
          format: password
          description: the password
        redirect:
          type: string
          default: 'false'
          description: '"true" or "false". "false" indicates that the service should not redirect to Bonita Portal (after a successful login) or to the login page (after a login failure).'
        redirectURL:
          type:
          - string
          - 'null'
          default: ''
          description: the URL of the page to be displayed after login
      example:
        username: install
        password: install
        redirect: 'false'
        redirectURL: null
    Error:
      type: object
      additionalProperties: true
      properties:
        message:
          type: string
          description: The error message
        exception:
          type: string
          description: The exception type
        explanations:
          description: Further details on the error
          type: array
          items:
            type: string
  securitySchemes:
    bonita_auth:
      name: JSESSIONID
      description: 'To call the REST API, you must first log on with a user registered in the Engine database. Please refer to the __[Login API](#operation/login)__ operations section.

        '
      type: apiKey
      in: cookie
    bonita_token:
      name: X-Bonita-API-Token
      description: 'To call the REST API, you must first log on with a user registered in the Engine database. Please refer to the __[Login API](#operation/login)__ operations section.

        '
      type: apiKey
      in: header
    bearer_auth:
      description: '![edition](https://img.shields.io/badge/edition-entreprise-blue)


        When Bonita runtime is configured for SSO with openID Connect it is possible To call the REST API directly with a Bearer Authorization header containing the access token.

        '
      type: http
      scheme: bearer
x-tagGroups:
- name: Authentication
  tags:
  - Authentication
  - PlatformAuthentication
- name: Application
  tags:
  - Application
  - ApplicationMenu
  - ApplicationPage
  - FormMapping
- name: BDM
  tags:
  - BDM
  - BusinessDataQuery
  - Business Data Operations
  - BDMAccessControl
  - DataRetention
- name: BPM
  tags:
  - Activity
  - ArchivedActivity
  - HumanTask
  - ManualTask
  - Task
  - UserTask
  - ArchivedHumanTask
  - ArchivedManualTask
  - ArchivedTask
  - ArchivedUserTask
  - ActivityVariable
  - ArchivedActivityVariable
  - ProcessInstanceVariable
  - ArchivedProcessInstanceVariable
  - ProcessInstanceDocument
  - ArchivedProcessInstanceDocument
  - Actor
  - ActorMember
  - ProcessInstance
  - ArchivedProcessInstance
  - ProcessInstanceInfo
  - ProcessInstanceComment
  - ArchivedProcessInstanceComment
  - Process
  - Diagram
  - ProcessInfo
  - ProcessParameter
  - ProcessResolutionProblem
  - ProcessSupervisor
  - ProcessConnectorDependency
  - ConnectorFailure
  - ConnectorInstance
  - ArchivedConnectorInstance
  - FlowNode
  - ArchivedFlowNode
  - Failure
  - ArchivedFailure
  - TimerEventTrigger
  - Message
  - Signal
  - Delegation
- name: Custom user info
  tags:
  - CustomUserDefinition
  - CustomUserValue
  - CustomUser
- name: Identity
  tags:
  - ProfessionalContactData
  - Group
  - Membership
  - Role
  - User
  - Authentication
- name: Platform
  tags:
  - PlatformAuthentication
  - Platform
  - License
  - Information
- name: Portal
  tags:
  - Page
  - Profile
  - ProfileEntry
  - ProfileMember
  - Theme
  - Upload
- name: System
  tags:
  - I18nlocale
  - I18ntranslation
  - Log
  - Session
  - Maintenance
- name: Other
  tags:
  - RestAPIextensions
- name: Upload
  tags:
  - FormFileUpload