Operations 2
Documentation
APIReference
https://api-documentation.ofelia.com/latest/
Documentation
https://documentation.ofelia.com/bonita/latest/api/api-index
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/bonitasoft-authentication-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
license:
name: GPL-v2.0
url: http://www.gnu.org/licenses/gpl-2.0.txt
version: 1.0.9
title: Bonita Authentication API
description: 'Download OpenAPI specification
Download Postman collection
The REST API lets you access the data with HTTP requests; it is useful when implementing rich web forms / pages for a good user experience.'
x-logo:
url: images/ofelia-logo.svg
backgroundColor: '#19465f'
altText: Bonita API
href: /
servers:
- url: http://localhost:8080/bonita
description: Sample url for a local development server.
security:
- bonita_auth: []
bonita_token: []
- bearer_auth: []
tags:
- name: Authentication
x-displayName: Authentication
description: Authentication
paths:
/loginservice:
post:
tags:
- Authentication
operationId: login
security: []
summary: Login
description: 'A call to the `/loginservice` will generates a set-cookie header in the response.
The `JSESSIONID` cookie must be transfered with each subsequent calls. (If the REST API is used in an application running in a web browser, this is handled automatically by the web browser just like any cookies).
Additional protection agains CSRF attacks is enabled by default for all fresh installations This security relies on `X-Bonita-API-Token` information.
The `X-Bonita-API-Token` value can be found in the cookie named: `X-Bonita-API-Token`.
All the subsequence REST API calls performing changes in the system using DELETE, POST, or PUT HTTP methods must contain the **HTTP header** below:
``` X-Bonita-API-Token: example-dummy-not-be-used-value ```'
requestBody:
content:
application/x-www-form-urlencoded:
schema:
$ref: '#/components/schemas/LoginRequest'
x-codeSamples:
- lang: Shell
label: Curl
source: "# Generate cookie file\ncurl -v -c saved_cookies.txt \\\n--url 'http://localhost:8080/bonita/loginservice' \\\n--header 'Content-Type: application/x-www-form-urlencoded'\n --data-urlencode 'username=install' \\\n --data-urlencode 'password=install' \\\n --data-urlencode 'redirect=false' \\\n --data-urlencode 'redirectURL='\n \n # Reuse the cookie file and set the `X-Bonita-API-Token` header\n curl -b saved_cookies.txt -X GET \\\n-- header 'X-Bonita-API-Token: <token>' \\\n--url 'http://localhost:8080/bonita/API/bpm/process?c=100&p=0'\n"
responses:
'204':
description: Login success
headers:
Set-Cookie:
description: Session cookie
schema:
type: string
example: JSESSIONID=C5385BFEE2969D9E46F0160C1952B0F1; Path=/bonita; HttpOnly; SameSite=Lax
X-Bonita-API-Token:
description: X-Bonita-API-Token - CSRF token (also present in the cookie response)
schema:
type: string
example: ed27cbeb-9953-4d77-b5a2-1f62a6c2e0bb
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
5XX:
$ref: '#/components/responses/ServerError'
/logoutservice:
get:
tags:
- Authentication
summary: Logout the current user
description: Logout the current user from the system
operationId: logout
parameters:
- description: Setting the redirect parameter to false indicates that the service should not redirect to the login page after logging out.
explode: true
in: query
name: redirect
required: false
schema:
type: string
maxLength: 5
pattern: ^(?:tru|fals)e$
style: form
example:
redirect: 'false'
redirectURL: null
x-codeSamples:
- lang: Shell
label: Curl
source: 'curl -b saved_cookies.txt -X GET --url ''http://localhost:8080/bonita/logoutservice?redirect=false''
'
responses:
'200':
description: 'Success '
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
5XX:
$ref: '#/components/responses/ServerError'
components:
responses:
Unauthorized:
description: Authorization information is missing or invalid.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
message: Unauthorized
BadRequest:
description: Bad request.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
message: Bad request
Forbidden:
description: Forbidden, The request contained valid data and was understood by the server, but the server is refusing action.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
message: Forbidden, The request contained valid data and was understood by the server, but the server is refusing action.
ServerError:
description: Unexpected error.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
message: An unexpected error occured.
schemas:
LoginRequest:
type: object
required:
- username
- password
properties:
username:
type: string
description: the username
password:
type: string
format: password
description: the password
redirect:
type: string
default: 'false'
description: '"true" or "false". "false" indicates that the service should not redirect to Bonita Portal (after a successful login) or to the login page (after a login failure).'
redirectURL:
type:
- string
- 'null'
default: ''
description: the URL of the page to be displayed after login
example:
username: install
password: install
redirect: 'false'
redirectURL: null
Error:
type: object
additionalProperties: true
properties:
message:
type: string
description: The error message
exception:
type: string
description: The exception type
explanations:
description: Further details on the error
type: array
items:
type: string
securitySchemes:
bonita_auth:
name: JSESSIONID
description: 'To call the REST API, you must first log on with a user registered in the Engine database. Please refer to the __[Login API](#operation/login)__ operations section.
'
type: apiKey
in: cookie
bonita_token:
name: X-Bonita-API-Token
description: 'To call the REST API, you must first log on with a user registered in the Engine database. Please refer to the __[Login API](#operation/login)__ operations section.
'
type: apiKey
in: header
bearer_auth:
description: '
When Bonita runtime is configured for SSO with openID Connect it is possible To call the REST API directly with a Bearer Authorization header containing the access token.
'
type: http
scheme: bearer
x-tagGroups:
- name: Authentication
tags:
- Authentication
- PlatformAuthentication
- name: Application
tags:
- Application
- ApplicationMenu
- ApplicationPage
- FormMapping
- name: BDM
tags:
- BDM
- BusinessDataQuery
- Business Data Operations
- BDMAccessControl
- DataRetention
- name: BPM
tags:
- Activity
- ArchivedActivity
- HumanTask
- ManualTask
- Task
- UserTask
- ArchivedHumanTask
- ArchivedManualTask
- ArchivedTask
- ArchivedUserTask
- ActivityVariable
- ArchivedActivityVariable
- ProcessInstanceVariable
- ArchivedProcessInstanceVariable
- ProcessInstanceDocument
- ArchivedProcessInstanceDocument
- Actor
- ActorMember
- ProcessInstance
- ArchivedProcessInstance
- ProcessInstanceInfo
- ProcessInstanceComment
- ArchivedProcessInstanceComment
- Process
- Diagram
- ProcessInfo
- ProcessParameter
- ProcessResolutionProblem
- ProcessSupervisor
- ProcessConnectorDependency
- ConnectorFailure
- ConnectorInstance
- ArchivedConnectorInstance
- FlowNode
- ArchivedFlowNode
- Failure
- ArchivedFailure
- TimerEventTrigger
- Message
- Signal
- Delegation
- name: Custom user info
tags:
- CustomUserDefinition
- CustomUserValue
- CustomUser
- name: Identity
tags:
- ProfessionalContactData
- Group
- Membership
- Role
- User
- Authentication
- name: Platform
tags:
- PlatformAuthentication
- Platform
- License
- Information
- name: Portal
tags:
- Page
- Profile
- ProfileEntry
- ProfileMember
- Theme
- Upload
- name: System
tags:
- I18nlocale
- I18ntranslation
- Log
- Session
- Maintenance
- name: Other
tags:
- RestAPIextensions
- name: Upload
tags:
- FormFileUpload