Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
version: 2.0.0
title: Opal Phase Items API
license:
name: Opal API License
url: https://www.workwithopal.com/api-license
description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Other API Versions\n\nThe [v3 API](/api/documentation/v3) is less complete than the v2 API, and is still a work in progress. Currently, if a resource has endpoints in both the v2 API and the v3 API you **SHOULD** use the v2 API endpoints. At some point in the future we will recommend the v3 API instead.\n\n# Documentation Organization\n\nv2 API endpoints are categorized by stability:\n\n1. JSON:API\n2. Other\n3. Unstable\n4. Proposed\n\nv2 API endpoints in the “JSON:API”, “Unstable”, and “Proposed” categories are [JSON:API](https://jsonapi.org)-compliant ([specification](https://jsonapi.org/format/)) and can be used with any [JSON:API-compliant client](https://jsonapi.org/implementations/).\n\n<aside>\n\nTo strictly comply with the JSON:API specification your requests for endpoints in the “JSON:API”, “Unstable”, and “Proposed” categories **MUST** set the `Accept` HTTP header to `application/vnd.api+json`. The server response’s `Content-Type` HTTP header will also be `application/vnd.api+json`.\n\nYou **SHOULD** use `application/vnd.api+json` for maximum stability, but v2 API endpoints **MAY** allow the `Accept` HTTP header to be `application/json`; if so, the response’s `Content-Type` HTTP header will be `application/json`. This support for `application/json` **MAY** disappear from a given endpoint at any time, and is not available on all endpoints.\n</aside>\n\n“Other” endpoints are stable, but do not follow the JSON:API specification. (Some “Other” endpoints have data that resembles the JSON:API structure, but **MUST** be parsed as generic JSON.) Your requests **MUST** set the `Accept` HTTP header to `application/json`, and the response’s `Content-Type` HTTP header will be `application/json`.\n\n## Unstable Endpoints\n\n*Note:* This generally refers resources in the “Unstable” category, but includes endpoints with a summary that’s prefixed by `[UNSTABLE]`. These `[UNSTABLE]` endpoints may be part of a “Stable” resource.\n\nThe data structure and behavior of “Unstable” endpoints are not guaranteed, and we **MAY** change them at any time. You **MUST NOT** use these endpoints for production features, but **MAY** use them as a preview of upcoming features, and we welcome feedback.\n\n## Proposed Endpoints\n\n“Proposed” endpoints **MUST NOT** be used (they’re not yet implemented), and we **MAY** change or remove them at any time. We publish them at our discretion to share our plans and encourage internal feedback. We also welcome your feedback.\n\n# Design Principles\n\n## Breaking Changes\n\nWe **MAY** expand the data for “JSON:API” and “Other” resources, but will not change or remove existing attributes or relationships for these resources. These expansions should not require any changes to your code.\n\nWe provide no guarantees for “Unstable” and “Proposed” endpoints.\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Roles\n#### Client\nThe 3rd-party application accessing the API on behalf of the User.\n\n#### API\nAPI endpoints used to interact with a User's resources in Opal.\n\n#### User\nThe person authorizing the Client to access to their Opal account.\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n - public\n- Application secret\n - keep this private\n - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n \"access_token\":\"ABC123\",\n \"token_type\":\"bearer\",\n \"expires_in\":3600,\n \"refresh_token\":\"DEF456\",\n \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n https://login.ouropal.com/oauth2/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n GET /resource HTTP/1.1\n Host: server.example.com\n Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n"
servers:
- url: https://login.ouropal.com
tags:
- name: Phase Items
paths:
/phase_items/v2:
get:
tags:
- Phase Items
operationId: ReadPhaseItemsV2
summary: Return all phase items available to the authenticated user.
security:
- oauth2:
- offline_access
- api_key:
- Session-Token
parameters:
- name: fields
in: query
description: 'An object where each key is a CSV of phase item attributes to include in the response.
Omit this parameter entirely to retrieve all available fields.
'
required: false
schema:
type: object
properties:
approvable:
type: string
created_at:
type: string
from_user:
type: string
is_starred:
type: string
phase:
type: string
proxy_user:
type: string
response:
type: string
request:
type: string
to_user:
type: string
type:
type: string
updated_at:
type: string
style: deepObject
explode: true
- name: filter
in: query
description: Filters for limiting the results.
required: false
schema:
type: object
properties:
active:
type: boolean
description: 'Boolean true returns phase items where an action may be taken while boolean false returns phase items where no action may be taken.
'
brand_id:
type: array
description: 'The IDs of the workspaces to which results should be filtered.
"Workspace ID" and "Brand ID" are synonymous.
Comma separated list of IDs. If included, will only fetch resources associated with these brands. If not included, will return resources associated with all brands that the user belongs to. For example, `filter[brand_id]=1` will fetch all resources associated with brand 1, while `filter[brand_id]=1,2,3` will fetch any resources associated with brands 1, 2, or 3.
'
items:
type: integer
content_id:
type: array
description: Retrieve phase items associated with one or more content IDs.
items:
type: integer
created_at:
allOf:
- type: object
properties:
eq:
type: string
description: 'Equal to filter. If no other filter is specified, `eq` will be assumed.
'
gt:
type: string
description: Greater than filter
gteq:
type: string
description: Greater than or equal to filter
lt:
type: string
description: Less than filter
lteq:
type: string
description: Less than or equal to filter
- format: date-time
- description: 'Filter phase items by created_at time. Uses syntax `filter[created_at][gt]=2020-01-01` Timestamps use iso8601 formatting, such as `YYYY-MM-DD` or `YYYY-MM-DDThh:mmTZD`. If no operator is specified, `eq` will be assumed. For example, `filter[created_at]=2020-01-01` is equivalent to `filter[created_at][eq]=2020-01-01`
'
current:
type: boolean
description: 'Boolean true returns phase items in the current phase while boolean false excludes phase items in the current phase.
'
due_date:
allOf:
- type: object
properties:
eq:
type: string
description: 'Equal to filter. If no other filter is specified, `eq` will be assumed.
'
gt:
type: string
description: Greater than filter
gteq:
type: string
description: Greater than or equal to filter
lt:
type: string
description: Less than filter
lteq:
type: string
description: Less than or equal to filter
- format: date-time
- description: 'Filter by the due date of the phase. Uses syntax `filter[due_date][gt]=2020-01-01` Timestamps use iso8601 formatting, such as `YYYY-MM-DD` or `YYYY-MM-DDThh:mmTZD`. If no operator is specified, `eq` will be assumed. For example, `filter[due_date]=2020-01-01` is equivalent to `filter[due_date][eq]=2020-01-01`
'
from_days_prior:
type: integer
description: 'Limit the number of past-due items up to a number of days. Note that using this in conjunction with the overdue filter will result in an error.
'
overdue:
type: boolean
description: 'Boolean true to get overdue phase items only, false to get current and future phase items, or unspecified to get both. Note that using this in conjunction with the from_days_prior filter will result in an error.
'
pending:
type: boolean
description: 'Boolean true returns tasks that are not yet complete and approvals that are not yet approved. Boolean false return completed tasks and approvals that are approved.
'
scheduled_at:
allOf:
- type: object
properties:
eq:
type: string
description: 'Equal to filter. If no other filter is specified, `eq` will be assumed.
'
gt:
type: string
description: Greater than filter
gteq:
type: string
description: Greater than or equal to filter
lt:
type: string
description: Less than filter
lteq:
type: string
description: Less than or equal to filter
- format: date-time
- description: 'Filter by the content scheduled time. Uses syntax `filter[scheduled_at][gt]=2020-01-01` Timestamps use iso8601 formatting, such as `YYYY-MM-DD` or `YYYY-MM-DDThh:mmTZD`. If no operator is specified, `eq` will be assumed. For example, `filter[scheduled_at]=2020-01-01` is equivalent to `filter[scheduled_at][eq]=2020-01-01`
'
to_me:
type: boolean
description: 'Boolean true to get phase items assigned to the current user and boolean false to exclude phase items assigned to the current user. Note that using this filter in conjunction with the to_user_ids filter will result in an error.
'
to_user_ids:
deprecated: true
description: 'See the `to_user_id` parameter which offers the same functionality (filtering to one or more comma-separated ids _or_ `null`).
'
oneOf:
- type: string
description: Retrieve unassigned items.
enum:
- 'null'
- type: array
description: Retrieve assigned items by user IDs.
items:
type: integer
to_user_id:
description: A CSV of user IDs, or null to retrieve unassigned items.
oneOf:
- type: string
description: Retrieve unassigned items.
enum:
- 'null'
- type: array
description: Retrieve assigned items by user IDs.
items:
type: integer
example: filter[to_user_id]=1,50,22
type:
type: string
description: 'Filtering by task will return phase items of type task, filtering by approval will return phase items of type approval.
'
enum:
- task
- approval
updated_at:
allOf:
- type: object
properties:
eq:
type: string
description: 'Equal to filter. If no other filter is specified, `eq` will be assumed.
'
gt:
type: string
description: Greater than filter
gteq:
type: string
description: Greater than or equal to filter
lt:
type: string
description: Less than filter
lteq:
type: string
description: Less than or equal to filter
- format: date-time
- description: 'Filter by the phase item updated_at time. Uses syntax `filter[updated_at][gt]=2020-01-01`. Timestamps use iso8601 formatting, such as `YYYY-MM-DD` or `YYYY-MM-DDThh:mmTZD`. If no operator is specified, `eq` will be assumed. For example, `filter[updated_at]=2020-01-01` is equivalent to `filter[updated_at][eq]=2020-01-01`
'
style: deepObject
explode: true
- name: include
in: query
required: false
description: 'A comma separated value of related resource objects on the phase item to include. These need to be specified when attributes on a relationship are required by the client.
'
schema:
type: array
items:
type: string
enum:
- approvable
- brand
- from_user
- phase
- proxy_user
- to_user
style: form
explode: false
- name: sort
in: query
required: false
description: 'A comma separated value specifying how a collection in the response body should be sorted, where each value is an attribute of the phase item. When specifying multiple values, each value in the sequence determines the ordering precedence. Lastly, each phase item in the collection will appear in ascending order, unless any of the enumerated values are prefixed with a minus "-" sign, in which case each phase item will appear in descending order for the specified values.
'
schema:
type: array
items:
type: string
enum:
- created_at
- due_date
- full_name
- request
- scheduled_at
- updated_at
- name: expose
in: query
required: false
description: Expose response data that is only provided by request.
schema:
type: object
properties:
unscheduled_posts:
type: boolean
description: '**[INTERNAL-ONLY] [Unstable]** 🏴☠️👻🚷💣 This parameter can be used to expose Unscheduled Posts to the V2 Phase Items GET API. Opal developers are using this parameter as a migration tool. If you need Phase Items for content that is Unscheduled, please see the V3 APIs that offer native support.
This parameter should be considered [Unstable] and may be removed at any time without notice of deprecation. Using this parameter will also cause the Phase Items V2 GET response to deviate from the documented schema.
'
responses:
'200':
description: An array of phase items.
content:
application/json:
schema:
type: object
required:
- data
- meta
properties:
data:
type: array
items:
title: phase item
type: object
required:
- id
- type
- attributes
additionalProperties: false
properties:
id:
type: string
pattern: ^[0-9]+$
type:
type: string
enum:
- phase_item
attributes:
type: object
required:
- created_at
- request
- status
- phase_item_type
- updated_at
additionalProperties: false
properties:
created_at:
type: string
format: date-time
description: An ISO8601 date-time.
readOnly: true
is_starred:
type: boolean
description: Indicates the phase item is starred/pinned.
request:
type:
- string
- 'null'
description: A description of the request being made.
response:
type:
- string
- 'null'
description: A comment to be left by the approver.
status:
type: string
description: The status of the phase item.
enum:
- complete
- incomplete
- rejected
type:
type: string
deprecated: true
description: Deprecated. See `phase_item_type`.
enum:
- Moments::Approval
- Moments::Task
phase_item_type:
type: string
description: The specific type of phase item.
enum:
- Moments::Approval
- Moments::Task
updated_at:
type: string
format: date-time
description: An ISO8601 date-time.
readOnly: true
relationships:
type: object
additionalProperties: false
properties:
approvable:
type: object
required:
- data
additionalProperties: false
properties:
data:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- content
brand:
type: object
required:
- data
additionalProperties: false
properties:
data:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- brand
from_user:
type: object
required:
- data
additionalProperties: false
properties:
data:
type:
- object
- 'null'
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- user
phase:
type: object
required:
- data
additionalProperties: false
properties:
data:
type: object
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- phase
proxy_user:
type: object
required:
- data
additionalProperties: false
properties:
data:
type:
- object
- 'null'
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- user
to_user:
type: object
required:
- data
additionalProperties: false
properties:
data:
type:
- object
- 'null'
required:
- id
- type
additionalProperties: false
properties:
id:
type: string
type:
type: string
enum:
- user
included:
type: array
items:
oneOf:
- title: brand
type: object
required:
- id
- type
- attributes
- relationships
additionalProperties: false
properties:
id:
type: string
pattern: ^[0-9]+$
type:
type: string
enum:
- brand
meta:
type:
- object
- 'null'
description: Metadata around the Brand object
properties:
user_is_member:
type: boolean
description: Boolean that represents whether the requesting user is a member of the brand.
attributes:
type: object
required:
- slug
- name
- uuid
- start_of_week
- timezone
additionalProperties: false
properties:
# --- truncated at 32 KB (132 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/opal/refs/heads/main/openapi/opal-phase-items-api-openapi.yml