Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
version: 3.0.0
title: Opal API (⚠️ WIP) Onboarding API
license:
name: Opal API License
url: https://www.workwithopal.com/api-license
description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Other API Versions\n\nThe [v2 API](/api/documentation/v2) is more complete than the v3 API. Currently, if a resource has endpoints in both the v2 API and the v3 API you **SHOULD** use the v2 API endpoints. At some point in the future we will recommend the v3 API instead.\n\n*Note:* Endpoints will be added to the v3 API as needed, and we will continue to support all v2 API endpoints in the “JSON:API” and “Other” categories, even if we add an equivalent v3 API endpoint.\n\n# Key differences between v2 and v3 APIs\n\n## Resource Identifiers\n\nThe v3 API uses a different format for primary resource identifiers than the v2 API. Responses from v3 API endpoints include the resource’s v2 API id in the `attributes.legacy_id` field, in case you need to use both API versions. (v2 API resource identifiers are generally integers, but v2 API endpoints **MAY** use a different format.)\n\n*Note:* These are opaque strings, and you **MUST NOT** rely on the structure. Currently newly-created resources have a UUIDv4 identifier, but this behavior **MAY** change at any time. Existing identifiers will not be affected.\n\n# Documentation Organization\n\nv3 API endpoints are categorized by stability:\n\n1. Stable\n2. Unstable\n3. Proposed\n4. Experimental\n\nAll v3 API endpoints are [JSON:API](https://jsonapi.org)-compliant ([specification](https://jsonapi.org/format/)) and can be used with any [JSON:API-compliant client](https://jsonapi.org/implementations/).\n\nYour requests **MUST** set the `Accept` HTTP header to `application/vnd.api+json`. The server response’s `Content-Type` HTTP header will also be `application/vnd.api+json`.\n\n## Unstable Endpoints\n\n*Note:* This generally refers resources in the “Unstable” category, but includes endpoints with a summary that’s prefixed by `[UNSTABLE]`. These `[UNSTABLE]` endpoints may be part of a “Stable” resource.\n\nThe data structure and behavior of “Unstable” endpoints are not guaranteed, and we **MAY** change them at any time. You **MUST NOT** use these endpoints for production features, but **MAY** use them as a preview of upcoming features, and we welcome feedback.\n\n## Proposed Endpoints\n\n“Proposed” endpoints **MUST NOT** be used (they’re not yet implemented), and we **MAY** change or remove them at any time. We publish them at our discretion to share our plans and encourage internal feedback. We also welcome your feedback.\n\n# Design Principles\n\n## Breaking Changes\n\nWe **MAY** expand the data for “Stable” resources, but will not change or remove existing attributes or relationships for these resources. These expansions should not require any changes to your code.\n\nWe provide no guarantees for “Unstable,” \"Experimental,\" or “Proposed” endpoints.\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Roles\n#### Client\nThe 3rd-party application accessing the API on behalf of the User.\n\n#### API\nAPI endpoints used to interact with a User's resources in Opal.\n\n#### User\nThe person authorizing the Client to access to their Opal account.\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n - public\n- Application secret\n - keep this private\n - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n \"access_token\":\"ABC123\",\n \"token_type\":\"bearer\",\n \"expires_in\":3600,\n \"refresh_token\":\"DEF456\",\n \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n GET /resource HTTP/1.1\n Host: server.example.com\n Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n"
servers:
- url: https://login.ouropal.com
tags:
- name: Onboarding
description: "## Onboarding Overview\nUnlike many other Opal endpoints, the Onboarding endpoints are only accessible via a special OAuth scope that is not currently offered to Opal customers (i.e. it is internal-use only).\n\nThe `trial_invites` `POST` endpoint is JSON:API compliant, but the `trial_invites/do/accept` endpoint is capable of serving up either a JSON RPC response or redirecting to a user onboarding web page depending on whether HTML or JSON is specified in the request's `Accept` header.\n\nThe process of requesting an invitation and accepting it is always two steps:\n1. A `POST` request to `onboarding/v3/trial_invites` creates a trial invite and produces an `accept` link that is included in the response body.\n2. A user follows the `accept` link in a browser and is redirected into the user setup process OR a client makes an RPC request to the `accept` link and receives a `user_setup` link a user can follow to begin profile setup in a JSON response body.\n\nThere is optionally a third step. If the `user_setup` link in the `accept` request's response is not used to get the user into their setup flow, a `GET` request to `onboarding/v3/trial_invites/status` can be sent in order to retrieve a `trial_invite` record that surfaces the `user_setup` link as well.\n\n### Setting up a new integration\nThe internal-only process of creating a new onboarding integration starts with creating a new onboarding client. From Opal's Hydra admin CLI, choose the \"create onboarding client\" option. Fill out the required information and take note of the Client Secret produced near the end of the process. This is the only time that client secret will be accessible. This secret should be saved in Opal's shared Engineering vault in 1Password.\n\nNext, a third party integration that creates new Opal trials can be set up with the newly created Hydra client in one of two ways. Either it can make a Client Credentials OAuth 2.0 token request using the client secret and then make authenticated requests with the token it receives in response, or you can set the third party integration up to use Opal's `trial_invites` endpoint as a webhook (see below).\n\n#### Webhook usage\nIf you want to create a token and treat it like an API key while using the `trial_invites` endpoint as a webhook, you should request an OAuth token by hand and use that token in the third party integration as a long-lived API key.\n\nFrom the Hydra admin CLI, select the onboarding client you created for the purposes of this integration. Next choose the \"Show sample auth URL and curl commands\" option. You will get a CURL command like the following:\n```shell\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d \"client_secret=<SECRET>&client_id=onboarding1--742d8aff84759a6c&grant_type=client_credentials&scope=write:onboarding\"\n```\n\nReplace `<SECRET>` with this client's secret, replace `https://login.ouropal.com` with whichever Opal domain you are working against, and make the request from a shell on your laptop (just needs internet access and `cURL` installed). This will produce JSON similar to the following:\n```json\n{\n \"access_token\": \"dRGg4JW0F9QIHBnZpkLHWJ7j748AsALcL4_UfmjI0-4.VYbLrAiQzqgrmgXClQhmICP2_7BBEp9OMgKO9lpyUjU\",\n \"expires_in\": <a long time>,\n \"scope\": \"write:onboarding\",\n \"token_type\": \"bearer\"\n}\n```\n\nNow take your `access_token` and plug it into an Authorization header for whatever webhook request to `onboarding/v3/trial_invites` your new integration is going to make:\n```\nContent-Type: application/json\nAccept: application/json\nAuthorization: Bearer dRGg4JW0F9QIHBnZpkLHWJ7j748AsALcL4_UfmjI0-4.VYbLrAiQzqgrmgXClQhmICP2_7BBEp9OMgKO9lpyUjU\n```\n"
paths:
/onboarding/v3/trial_invites:
post:
tags:
- Onboarding
summary: Request a trial invite
operationId: CreateTrialInviteV3
description: 'Create a trial invitation record that can be accepted by following the one-time URL populated into the response''s `accept` `link` property.
Note that although the OAuth Client Credentials Flow for authorization is not stateless, you _can_ use this API endpoint as a webhook by requesting an access token once (which will not expire for the `write:onboarding` scope) and configuring an Authorization Bearer header (per the OAuth standard) using this token within a third party platform.'
security:
- anonymous_oauth:
- write:onboarding
requestBody:
content:
application/json:
schema:
type: object
required:
- data
properties:
data:
type: object
required:
- type
- attributes
properties:
type:
type: string
enum:
- trial_invite
attributes:
type: object
required:
- user_email
- user_first_name
- user_last_name
- company
additionalProperties: false
properties:
user_email:
type: string
description: The email address to which a trial invite should be sent.
user_first_name:
type: string
description: The first name of an initial user to invite to the new Opal.
user_last_name:
type: string
description: The last name of an initial user to invite to the new Opal.
company:
type: string
description: The Company name to associated with the new Opal.
team_types:
type: array
description: The types of teams expected to join the trial.
items:
type: string
enum:
- agency
- brand marketing
- content marketing
- creatives
- email marketing
- external comms
- geographies
- influencer marketing
- internal comms
- paid advertising
- retail in-store
- social marketing
- web marketing
- other
responses:
'201':
description: A trial invite has been created.
content:
application/json:
schema:
type: object
required:
- data
properties:
data:
title: trial_invite
type: object
required:
- id
- type
- attributes
- links
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- trial_invite
links:
type: object
required:
- accept
- user_setup
properties:
accept:
type: string
format: uri
description: 'A URL that should be followed by the user to accept the trial invitation.
Once accepted, this link is moot. Following it a second time will produce the error that the invitation has already been used to create a Trial Opal.'
user_setup:
type:
- string
- 'null'
format: uri
description: A URL that won't be populated until the accept link has been followed. Once a trial has been accepted, this link will take the user who requested the trial to a user setup flow and then into their new Opal.
attributes:
type: object
required:
- created_at
- expires_at
- used_at
- single_use_hash
- user_email
- user_first_name
- user_last_name
- company
additionalProperties: false
properties:
created_at:
type: string
format: date-time
description: An ISO8601 date-time.
readOnly: true
expires_at:
type: string
format: date-time
description: An ISO8601 date-time.
used_at:
type:
- string
- 'null'
format: date-time
description: An ISO8601 date-time.
single_use_hash:
type: string
description: 'A one-time hash for accepting the invite.
See the `links` `accept` property for a full URL that can be followed to accept the invite.
'
user_email:
type: string
format: email
description: The email address of the user requesting a trial.
user_first_name:
type: string
description: The first name of an initial user to invite to the new Opal.
user_last_name:
type: string
description: The last name of an initial user to invite to the new Opal.
company:
type: string
description: The Company name to associated with the new Opal.
team_types:
type:
- array
- 'null'
description: The types of teams expected to join the trial. If null, then the user creating the trial did not specify team types.
items:
type: string
enum:
- agency
- brand marketing
- content marketing
- creatives
- email marketing
- external comms
- geographies
- influencer marketing
- internal comms
- paid advertising
- retail in-store
- social marketing
- web marketing
- other
relationships:
type: object
required:
- opal
- plan
additionalProperties: false
properties:
opal:
type: object
required:
- data
additionalProperties: false
properties:
data:
type:
- object
- 'null'
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- opal
plan:
type: object
required:
- data
additionalProperties: false
properties:
data:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- plan
'400':
description: Bad request
content:
application/json:
schema:
type: object
required:
- errors
properties:
errors:
type: array
items:
type: object
properties:
status:
type: string
description: The http status code of the error response.
title:
type: string
description: A short, human-readable summary of the error.
detail:
type: string
description: A human-readable explanation of the error.
code:
type: string
description: 'An system-readable error code to provide additional specificity for
the error.
'
required:
- status
'401':
description: Unauthorized
content:
application/json:
schema:
type: object
required:
- errors
properties:
errors:
type: array
items:
type: object
properties:
status:
type: string
description: The http status code of the error response.
title:
type: string
description: A short, human-readable summary of the error.
detail:
type: string
description: A human-readable explanation of the error.
code:
type: string
description: 'An system-readable error code to provide additional specificity for
the error.
'
required:
- status
/onboarding/v3/trial_invites/status:
get:
tags:
- Onboarding
summary: Get a trial invite
operationId: GetTrialInviteV3
description: 'Retrieve a trial invite. This route is designed to be used by a page that waits for a requested trial to be created and then allows the requesting user to proceed. It therefore is not authenticated but it does require _very_ specific knowledge of the trial in order to retrieve its record.
Most of the parameter values must exactly match those used to create the trial invitation.
Of particular note in the response payload is the `user_setup` link. This link will only be populated if the trial has been created & accepted. The user who requested the trial can be sent to this URL to finish setting up their user and begin using the new trial Opal.'
parameters:
- name: approximate_created_at
in: query
required: true
description: An ISO8601 datetime that is within 10 minutes of when the trial invitation was created.
schema:
type: string
format: date-time
- name: company
in: query
required: true
description: The name for the Company the trial is being requested on behalf of.
schema:
type: string
- name: user_email
in: query
required: true
description: The email of the user requesting a trial.
schema:
type: string
format: email
- name: user_first_name
in: query
required: true
description: The first name of the user requesting a trial.
schema:
type: string
- name: user_last_name
in: query
required: true
description: The last name of the user requesting a trial.
schema:
type: string
responses:
'200':
description: The trial invite was found.
content:
application/json:
schema:
type: object
required:
- data
properties:
data:
title: trial_invite
type: object
required:
- id
- type
- attributes
- links
additionalProperties: false
properties:
id:
type: string
format: uuid
type:
type: string
enum:
- trial_invite
links:
type: object
required:
- accept
- user_setup
properties:
accept:
type: string
format: uri
description: 'A URL that should be followed by the user to accept the trial invitation.
Once accepted, this link is moot. Following it a second time will produce the error that the invitation has already been used to create a Trial Opal.'
user_setup:
type:
- string
- 'null'
format: uri
description: A URL that won't be populated until the accept link has been followed. Once a trial has been accepted, this link will take the user who requested the trial to a user setup flow and then into their new Opal.
attributes:
type: object
required:
- created_at
- expires_at
- used_at
- single_use_hash
- user_email
- user_first_name
- user_last_name
- company
additionalProperties: false
properties:
created_at:
type: string
format: date-time
description: An ISO8601 date-time.
readOnly: true
expires_at:
type: string
format: date-time
description: An ISO8601 date-time.
used_at:
type:
- string
- 'null'
format: date-time
description: An ISO8601 date-time.
single_use_hash:
type: string
description: 'A one-time hash for accepting the invite.
See the `links` `accept` property for a full URL that can be followed to accept the invite.
'
user_email:
type: string
format: email
description: The email address of the user requesting a trial.
user_first_name:
type: string
description: The first name of an initial user to invite to the new Opal.
user_last_name:
type: string
description: The last name of an initial user to invite to the new Opal.
company:
type: string
description: The Company name to associated with the new Opal.
team_types:
type:
- array
- 'null'
# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/opal/refs/heads/main/openapi/opal-onboarding-api-openapi.yml