Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/opal-category-types-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no email required.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 3.0.0
title: Opal API (⚠️ WIP) Category Types API
license:
name: Opal API License
url: https://www.workwithopal.com/api-license
description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Other API Versions\n\nThe [v2 API](/api/documentation/v2) is more complete than the v3 API. Currently, if a resource has endpoints in both the v2 API and the v3 API you **SHOULD** use the v2 API endpoints. At some point in the future we will recommend the v3 API instead.\n\n*Note:* Endpoints will be added to the v3 API as needed, and we will continue to support all v2 API endpoints in the “JSON:API” and “Other” categories, even if we add an equivalent v3 API endpoint.\n\n# Key differences between v2 and v3 APIs\n\n## Resource Identifiers\n\nThe v3 API uses a different format for primary resource identifiers than the v2 API. Responses from v3 API endpoints include the resource’s v2 API id in the `attributes.legacy_id` field, in case you need to use both API versions. (v2 API resource identifiers are generally integers, but v2 API endpoints **MAY** use a different format.)\n\n*Note:* These are opaque strings, and you **MUST NOT** rely on the structure. Currently newly-created resources have a UUIDv4 identifier, but this behavior **MAY** change at any time. Existing identifiers will not be affected.\n\n# Documentation Organization\n\nv3 API endpoints are categorized by stability:\n\n1. Stable\n2. Unstable\n3. Proposed\n4. Experimental\n\nAll v3 API endpoints are [JSON:API](https://jsonapi.org)-compliant ([specification](https://jsonapi.org/format/)) and can be used with any [JSON:API-compliant client](https://jsonapi.org/implementations/).\n\nYour requests **MUST** set the `Accept` HTTP header to `application/vnd.api+json`. The server response’s `Content-Type` HTTP header will also be `application/vnd.api+json`.\n\n## Unstable Endpoints\n\n*Note:* This generally refers resources in the “Unstable” category, but includes endpoints with a summary that’s prefixed by `[UNSTABLE]`. These `[UNSTABLE]` endpoints may be part of a “Stable” resource.\n\nThe data structure and behavior of “Unstable” endpoints are not guaranteed, and we **MAY** change them at any time. You **MUST NOT** use these endpoints for production features, but **MAY** use them as a preview of upcoming features, and we welcome feedback.\n\n## Proposed Endpoints\n\n“Proposed” endpoints **MUST NOT** be used (they’re not yet implemented), and we **MAY** change or remove them at any time. We publish them at our discretion to share our plans and encourage internal feedback. We also welcome your feedback.\n\n# Design Principles\n\n## Breaking Changes\n\nWe **MAY** expand the data for “Stable” resources, but will not change or remove existing attributes or relationships for these resources. These expansions should not require any changes to your code.\n\nWe provide no guarantees for “Unstable,” \"Experimental,\" or “Proposed” endpoints.\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Roles\n#### Client\nThe 3rd-party application accessing the API on behalf of the User.\n\n#### API\nAPI endpoints used to interact with a User's resources in Opal.\n\n#### User\nThe person authorizing the Client to access to their Opal account.\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n - public\n- Application secret\n - keep this private\n - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n \"access_token\":\"ABC123\",\n \"token_type\":\"bearer\",\n \"expires_in\":3600,\n \"refresh_token\":\"DEF456\",\n \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n GET /resource HTTP/1.1\n Host: server.example.com\n Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n"
servers:
- url: https://login.ouropal.com
tags:
- name: Category Types
paths:
/loupe/v3/category_types:
get:
tags:
- Category Types
operationId: ReadCategoryTypesV3
summary: Get Category Types available to the authenticated user.
security:
- oauth2:
- offline_access
- api_key: []
parameters:
- name: filter
in: query
description: 'Filters for limiting the results.
'
required: true
schema:
type: object
required:
- workspace_id
properties:
only_active:
description: Don't return Category Types with a non-null deactivated_at.
type: boolean
workspace_id:
description: Only return Category Types for the given workspace.
type: string
format: uuid
id:
description: A comma separated list of Category Type `id`s to filter by.
type: array
items:
type: string
format: uuid
style: deepObject
explode: true
- name: include
in: query
required: false
description: A comma separated value of related objects to include.
schema:
type: array
items:
type: string
enum:
- custom_fields
- default_child_type
style: form
explode: false
- name: page
description: Specify an offset and limit for pagination
in: query
required: false
schema:
type: object
properties:
limit:
type: integer
default: 50
offset:
type: integer
style: deepObject
explode: true
responses:
'200':
description: A collection of Category Types.
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
type: array
items:
title: category_type
type: object
required:
- id
- type
- attributes
- relationships
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- category_type
attributes:
type: object
required:
- created_at
- name
- supported_paired_type
additionalProperties: false
properties:
name:
type: string
description: The name that will be displayed in the Opal application UI.
description:
type:
- string
- 'null'
description: A description of the record.
supported_paired_type:
type:
- string
- 'null'
default: null
enum:
- moment
- null
description: Whether blocks of this type will have resources of the given type paired with them. Moment pairing allows teams to work with the same resources from the Plan (via blocks) or from a Board or Calendar (via Moments). Once set to 'moment', this property cannot be set back to null. Blocks created with a type that supports moment pairing will always have paired moments. Conversely, blocks created with types that do not support moment pairing will not have paired moments (unless moment pairing support is added to the type later).
created_at:
type: string
format: date-time
description: An ISO 8601-formatted datetime indicating when the resource was created.
readOnly: true
updated_at:
type: string
format: date-time
description: An ISO 8601-formatted datetime indicating when the resource was last updated.
readOnly: true
deactivated_at:
type:
- string
- 'null'
format: date-time
description: An RFC 3339 date-time. If present, indicates the record has been deactivated (but not deleted).
has_explicit_custom_field_order:
type: boolean
default: false
description: 'If true, the category type uses its own saved order for `custom_fields`.
If false, ordering falls back to the global custom field order (e.g., `custom_fields.created_at`).
'
relationships:
type: object
required:
- creator
- workspace
- in_support_of_category_types
additionalProperties: false
properties:
creator:
title: User
type: object
required:
- data
additionalProperties: false
properties:
data:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- user
workspace:
type: object
required:
- data
additionalProperties: false
properties:
data:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- workspace
custom_fields:
type: object
required:
- data
additionalProperties: false
properties:
data:
type: array
items:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- custom_field
default_child_type:
type: object
required:
- data
additionalProperties: false
properties:
data:
type:
- object
- 'null'
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- category_type
in_support_of_category_types:
description: 'A list of category_types that this type is configured to support.
'
type: object
required:
- data
additionalProperties: false
properties:
data:
type: array
items:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- category_type
included:
type: array
items:
oneOf:
- title: block
type: object
required:
- id
- type
- attributes
- relationships
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- block
meta:
type:
- object
- 'null'
description: 'Optionally calculated block metadata which are not part of responses by default.
'
additionalProperties: false
properties:
effective_category_type:
type:
- object
- 'null'
description: The Block resource's most immediate ancestor's Category Type. See documentation for Category Type for additional details.
additionalProperties: false
properties:
id:
type: string
description: The Category Type's ID
name:
type: string
description: The Category Type's display name
description:
type:
- string
- 'null'
description: Optional additional descriptive text.
deactivated_at:
type:
- string
- 'null'
format: date-time
description: A flag indicating whether the category type is deactivated.
effective_privacy:
type: string
enum:
- whole_workspace
- some_but_not_all
description: 'The effective privacy of a resource is calculated based on all direct and
inherited access. If a resource or any of its parents that it inherits
access from are accessible to the entire workspace, the effective privacy
is `whole_workspace`. Otherwise, the effective privacy is
`some_but_not_all`.
'
custom_fields:
type: array
description: "This metadata is available when requesting block resources from the\n`loupe/v3/blocks/{block_id}` `GET` endpoint.\n\nYou request that this metadata be included in responses with the `expose` query \nparameter like: `loupe/v3/blocks/{block_id}?expose[block][meta][custom_fields]`.\n\nEffective custom fields include both **directly assigned** and **inherited** fields from \nthe associated category type. Inherited fields may, or may not, have explicit \n`block_custom_field_value`s.\n\nThe result is a list of effective custom fields for the block. Can be empty or\ncontain multiple instances of any custom field type.\n\nOrdering:\n- Inherited custom fields appear first, ordered by the associated\n Category Type’s saved custom field order.\n- Directly assigned custom fields (via block_custom_field_values)\n follow, preserving their relative order as returned by the service.\n"
items:
type: object
required:
- id
- display_name
- type
- options
- deactivated_options
- association_type
- data
additionalProperties: false
properties:
id:
type: string
format: uuid
description: The ID of the custom field.
display_name:
type: string
description: The display name for this custom field.
type:
type: string
enum:
- textarea
- singleSelect
- multiSelect
- date
- url
- usersSelect
description: The type of custom field.
association_type:
type: string
description: Indicates whether the field is `direct` (explicitly assigned to the block) or `inherited` (comes from the category type).
enum:
- direct
- inherited
options:
type: array
description: Active options for this custom field (for select types). Empty array for non-select types.
items:
type: object
required:
- id
- display_name
- position
properties:
id:
type: string
format: uuid
display_name:
type: string
position:
type: integer
deactivated_options:
type: array
description: Deactivated options for this custom field (for select types). Empty array for non-select types.
items:
type: object
required:
- id
- display_name
- position
properties:
id:
type: string
format: uuid
display_name:
type: string
position:
type: integer
data:
description: The value for this custom field. Can be null for fields that have no value set.
oneOf:
- title: Field Value
type: object
required:
- id
- value
properties:
id:
type: string
format: uuid
description: The ID of the custom field value.
value:
oneOf:
- title: Textarea Value
type: object
required:
- value
properties:
value:
type:
- string
- 'null'
description: The text content.
- title: Multi Select Value
type: object
required:
- ids
properties:
ids:
type: array
description: List of selected option IDs.
items:
type: string
format: uuid
- title: Single Select Value
type: object
required:
- id
properties:
id:
type:
- string
- 'null'
format: uuid
description: The selected option ID.
- title: Date Value
type: object
required:
- value
properties:
value:
type:
# --- truncated at 32 KB (395 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/opal/refs/heads/main/openapi/opal-category-types-api-openapi.yml