Bonitasoft User API

User

Operations 6

GET /API/identity/user Finds Users #
POST /API/identity/user Create the User #
GET /API/identity/user/{id} Finds the User by ID #
PUT /API/identity/user/{id} Update the User by ID #
DELETE /API/identity/user/{id} Delete the User by ID #
GET /API/identity/userSummary Finds User summaries #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/bonitasoft-user-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

bonitasoft-user-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  license:
    name: GPL-v2.0
    url: http://www.gnu.org/licenses/gpl-2.0.txt
  version: 1.0.9
  title: Bonita User API
  description: 'Download OpenAPI specification

    Download Postman collection


    The REST API lets you access the data with HTTP requests; it is useful when implementing rich web forms / pages for a good user experience.'
  x-logo:
    url: images/ofelia-logo.svg
    backgroundColor: '#19465f'
    altText: Bonita API
    href: /
servers:
- url: http://localhost:8080/bonita
  description: Sample url for a local development server.
security:
- bonita_auth: []
  bonita_token: []
- bearer_auth: []
tags:
- name: User
  x-displayName: User
  description: User
paths:
  /API/identity/user:
    get:
      tags:
      - User
      summary: Finds Users
      description: 'Finds Users with pagination params and filters


        - can order on `id`

        - can search on `displayName`

        - can filter on `displayName`'
      operationId: searchUsers
      parameters:
      - $ref: '#/components/parameters/pageIndex'
      - $ref: '#/components/parameters/pageCount'
      - $ref: '#/components/parameters/pageFilter'
      - $ref: '#/components/parameters/pageOrder'
      - $ref: '#/components/parameters/pageSearch'
      responses:
        '200':
          description: 'Success '
          headers:
            Content-Range:
              schema:
                type: integer
                format: int64
              description: The total number of matching items
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/User'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        5XX:
          $ref: '#/components/responses/ServerError'
    post:
      tags:
      - User
      summary: Create the User
      operationId: createUser
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserCreateRequest'
        description: Partial User description
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
          description: 'Success '
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        5XX:
          $ref: '#/components/responses/ServerError'
      x-codegen-request-body-name: body
  /API/identity/user/{id}:
    get:
      tags:
      - User
      summary: Finds the User by ID
      description: Returns the single User for the given ID
      operationId: getUserById
      parameters:
      - description: ID of the User to return
        in: path
        name: id
        required: true
        schema:
          type: string
          maxLength: 250
          pattern: ^[A-Za-z0-9\_\-\.]{0,250}$
      responses:
        '200':
          description: 'Success '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        5XX:
          $ref: '#/components/responses/ServerError'
    put:
      tags:
      - User
      summary: Update the User by ID
      description: Update the User for the given ID
      operationId: updateUserById
      parameters:
      - description: ID of the User to return
        in: path
        name: id
        required: true
        schema:
          type: string
          maxLength: 250
          pattern: ^[A-Za-z0-9\_\-\.]{0,250}$
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserUpdateRequest'
        description: Partial User description
        required: true
      responses:
        '200':
          $ref: '#/components/responses/OK'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        5XX:
          $ref: '#/components/responses/ServerError'
    delete:
      tags:
      - User
      summary: Delete the User by ID
      description: 'Delete the single User for the given ID.


        **Use this method with caution**: some artifacts like applications, process instances or users may present display problems in the Bonita Portal if the referenced user was deleted.

        Note that you can disable a user instead of deleting it. To do so, use the UPDATE method and set the attribute ''enabled'' to false'
      operationId: deleteUserById
      parameters:
      - description: ID of the User to delete
        in: path
        name: id
        required: true
        schema:
          type: string
          maxLength: 250
          pattern: ^[A-Za-z0-9\_\-\.]{0,250}$
      responses:
        '200':
          $ref: '#/components/responses/OK'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        5XX:
          $ref: '#/components/responses/ServerError'
  /API/identity/userSummary:
    get:
      tags:
      - User
      summary: Finds User summaries
      description: 'Finds a paginated, lightweight projection of users (`id`, `userName`, `firstname`, `lastname`, `job_title`),

        intended for user pickers and similar listings without exposing the full `identity/user` payload.


        - `p` / `c`: pagination params (page index and page size)

        - can search (`s`) on a free-text term matched by the engine across user attributes

        - can order (`o`) on `username` (default `username ASC`), `firstname` or `lastname`. One or more

        comma-separated sort clauses are applied in order (e.g. `lastname,firstname`). An optional `ASC` or

        `DESC` direction may follow each field. Unknown fields or malformed clauses return `400`.

        - can filter (`f`) only on `enabled` with a boolean value (e.g. `enabled=true`). Any other filter key

        or a non-boolean value returns `400`. `enabled` is filter-only and is not part of the returned projection.'
      operationId: searchUserSummaries
      parameters:
      - $ref: '#/components/parameters/pageIndex'
      - $ref: '#/components/parameters/pageCount'
      - $ref: '#/components/parameters/pageFilter'
      - $ref: '#/components/parameters/pageOrder'
      - $ref: '#/components/parameters/pageSearch'
      responses:
        '200':
          description: 'Success '
          headers:
            Content-Range:
              schema:
                type: integer
                format: int64
              description: The total number of matching items
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/UserSummary'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        5XX:
          $ref: '#/components/responses/ServerError'
components:
  parameters:
    pageOrder:
      description: can order on attributes
      explode: true
      in: query
      name: o
      required: false
      schema:
        type: string
        maxLength: 250
        pattern: ^[A-Za-z0-9%]{0,250}$
      style: form
      example: myProp%20ASC
    pageCount:
      description: maximum number of elements to retrieve
      explode: true
      in: query
      name: c
      example: '10'
      required: true
      schema:
        type: integer
        minimum: 1
        default: 20
        format: int32
      style: form
    pageIndex:
      description: index of the page to display
      explode: true
      in: query
      name: p
      example: '0'
      required: true
      schema:
        type: integer
        minimum: 0
        default: 0
        format: int32
      style: form
    pageFilter:
      description: can filter on attributes with the format f={filter\_name}={filter\_value} with the name/value pair as url encoded string.
      explode: true
      in: query
      name: f
      required: false
      schema:
        type: array
        items:
          type: string
          maxLength: 250
          pattern: ^[A-Za-z0-9%]{0,250}$
      style: form
      example: abc%3d123
    pageSearch:
      description: can search on attributes
      explode: true
      in: query
      name: s
      required: false
      schema:
        type: string
        maxLength: 250
        pattern: ^[A-Za-z0-9%]{0,250}$
      style: form
  responses:
    Unauthorized:
      description: Authorization information is missing or invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Unauthorized
    OK:
      description: OK
    BadRequest:
      description: Bad request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Bad request
    NotFound:
      description: The resource for the specified ID was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Resource not found.
    Forbidden:
      description: Forbidden, The request contained valid data and was understood by the server, but the server is refusing action.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: Forbidden, The request contained valid data and was understood by the server, but the server is refusing action.
    ServerError:
      description: Unexpected error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            message: An unexpected error occured.
  schemas:
    UserUpdateRequest:
      type: object
      properties:
        enabled:
          description: if "true", user will be activated.
          type: string
        userName:
          description: user name
          type: string
        firstname:
          description: user last name
          type: string
        lastname:
          description: user last name
          type: string
        password:
          description: user password
          format: password
          type: string
        icon:
          description: ' bonita icon path (ie. /default/icon_user.png)'
          type: string
        title:
          description: user title
          type: string
        job_title:
          description: user job title
          type: string
        manager_id:
          description: user manager id
          type: string
    Error:
      type: object
      additionalProperties: true
      properties:
        message:
          type: string
          description: The error message
        exception:
          type: string
          description: The exception type
        explanations:
          description: Further details on the error
          type: array
          items:
            type: string
    UserSummary:
      type: object
      description: 'Lightweight projection of a User returned by the `identity/userSummary` resource:

        only the id, user name, first name, last name and job title.


        Attribute names are kept consistent with the `identity/user` resource.

        '
      properties:
        id:
          description: user id
          type: string
        userName:
          description: user name
          type: string
        firstname:
          description: user first name
          type: string
        lastname:
          description: user last name
          type: string
        job_title:
          description: user job title. Optional on a user, `null` when unset.
          type:
          - string
          - 'null'
      required:
      - id
      - userName
      - firstname
      - lastname
    User:
      type: object
      properties:
        id:
          description: user id
          type: string
        enabled:
          description: if "true", user is active.
          type: string
        userName:
          description: user name
          type: string
        firstname:
          description: user last name
          type: string
        lastname:
          description: user last name
          type: string
        password:
          description: user password
          format: password
          type: string
        icon:
          description: ' bonita icon path (ie. /default/icon_user.png)'
          type: string
        title:
          description: user title
          type: string
        job_title:
          description: user job title
          type: string
        manager_id:
          description: user manager id
          type: string
        last_connection:
          description: last connection date
          type: string
        created_by_user_id:
          description: created by
          type: string
        creation_date:
          description: creation date
          type: string
        last_update_date:
          description: user last update date
          type: string
    UserCreateRequest:
      type: object
      required:
      - userName
      - password
      - password_confirm
      - firstname
      - lastname
      - enabled
      properties:
        userName:
          description: user name
          type: string
        firstname:
          description: user last name
          type: string
        lastname:
          description: user last name
          type: string
        password:
          description: user password
          format: password
          type: string
        password_confirm:
          description: user password confirmation
          format: password
          type: string
        icon:
          description: ' bonita icon path (ie. /default/icon_user.png)'
          type: string
        title:
          description: user title
          type: string
        job_title:
          description: user job title
          type: string
        manager_id:
          description: user manager id
          type: string
        enabled:
          description: true|false if the user is enabled or not
          type: string
      example:
        userName: New.User
        password: bpm
        password_confirm: bpm
        icon: ''
        firstname: New
        lastname: User
        title: Mr
        job_title: Human resources benefits
        manager_id: '3'
        enabled: 'true'
  securitySchemes:
    bonita_auth:
      name: JSESSIONID
      description: 'To call the REST API, you must first log on with a user registered in the Engine database. Please refer to the __[Login API](#operation/login)__ operations section.

        '
      type: apiKey
      in: cookie
    bonita_token:
      name: X-Bonita-API-Token
      description: 'To call the REST API, you must first log on with a user registered in the Engine database. Please refer to the __[Login API](#operation/login)__ operations section.

        '
      type: apiKey
      in: header
    bearer_auth:
      description: '![edition](https://img.shields.io/badge/edition-entreprise-blue)


        When Bonita runtime is configured for SSO with openID Connect it is possible To call the REST API directly with a Bearer Authorization header containing the access token.

        '
      type: http
      scheme: bearer
x-tagGroups:
- name: Authentication
  tags:
  - Authentication
  - PlatformAuthentication
- name: Application
  tags:
  - Application
  - ApplicationMenu
  - ApplicationPage
  - FormMapping
- name: BDM
  tags:
  - BDM
  - BusinessDataQuery
  - Business Data Operations
  - BDMAccessControl
  - DataRetention
- name: BPM
  tags:
  - Activity
  - ArchivedActivity
  - HumanTask
  - ManualTask
  - Task
  - UserTask
  - ArchivedHumanTask
  - ArchivedManualTask
  - ArchivedTask
  - ArchivedUserTask
  - ActivityVariable
  - ArchivedActivityVariable
  - ProcessInstanceVariable
  - ArchivedProcessInstanceVariable
  - ProcessInstanceDocument
  - ArchivedProcessInstanceDocument
  - Actor
  - ActorMember
  - ProcessInstance
  - ArchivedProcessInstance
  - ProcessInstanceInfo
  - ProcessInstanceComment
  - ArchivedProcessInstanceComment
  - Process
  - Diagram
  - ProcessInfo
  - ProcessParameter
  - ProcessResolutionProblem
  - ProcessSupervisor
  - ProcessConnectorDependency
  - ConnectorFailure
  - ConnectorInstance
  - ArchivedConnectorInstance
  - FlowNode
  - ArchivedFlowNode
  - Failure
  - ArchivedFailure
  - TimerEventTrigger
  - Message
  - Signal
  - Delegation
- name: Custom user info
  tags:
  - CustomUserDefinition
  - CustomUserValue
  - CustomUser
- name: Identity
  tags:
  - ProfessionalContactData
  - Group
  - Membership
  - Role
  - User
  - Authentication
- name: Platform
  tags:
  - PlatformAuthentication
  - Platform
  - License
  - Information
- name: Portal
  tags:
  - Page
  - Profile
  - ProfileEntry
  - ProfileMember
  - Theme
  - Upload
- name: System
  tags:
  - I18nlocale
  - I18ntranslation
  - Log
  - Session
  - Maintenance
- name: Other
  tags:
  - RestAPIextensions
- name: Upload
  tags:
  - FormFileUpload