Opal Plans API

The Plans API from Opal — 1 operation(s) for plans.

Operations 1

GET /{workspace_id}/plans Get multiple Plans. #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/opal-plans-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

opal-plans-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 3.0.0
  title: Asgard BFF Plans API
  license:
    name: Opal API License
    url: https://www.workwithopal.com/api-license
  description: "The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “NOT RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in [BCP 14](https://tools.ietf.org/html/bcp14) [[RFC2119](https://tools.ietf.org/html/rfc2119)] [[RFC8174](https://tools.ietf.org/html/rfc8174)] when, and only when, they appear in all capitals, as shown here.\n\n# Design Principles\n\n## Firehose Rule\n\nBy default endpoints include all the relevant data that’s accessible to the authenticated user. Clients **MAY** specify filters, ordering, pagination, sparse fields, and other limiting mechanisms to pare down the desired data.\n\n*Note:* Existing endpoints **MAY NOT** follow this maximalist approach, but new endpoints will, and we **MAY** enhance existing endpoints.\n\n## Obscurity\n\nIn order to provide customers with as much privacy as possible, many API calls that fail authorization will return `404 Not Found` rather than `403 Forbidden`. Do not design frontends around the expectation that a `404 Not Found` status code means a resource would not be returned given different authentication credentials.\n\n# Authentication Strategies\n## OAuth 2.0\nOpal uses OAuth 2.0 (https://oauth.net/2) to authenticate users and grant access to protected resources. After registering your application as an OAuth client, you must get permission from each user before accessing their account.\n\nThe main steps are:\n\n1. Register your application\n2. Direct the user to Opal, to authorize your application\n3. Opal confirm's user identity, and asks the user to grant your application permissions\n4. Opal issues tokens your application can use to access the user's Opal resources\n5. Your application can begin making requests to the Opal API on behalf of the user\n\n### Registering your application\nApplication registration is currently a manual process.\n\nTo begin, you will need to provide the following information to the Opal integrations team:\n\n- Application name\n- Logo URI\n- Redirect URI\n\nIn return, expect to receive:\n\n- Client ID\n  - public\n- Application secret\n  - keep this private\n  - keep this written down someplace safe. Opal cannot retrieve this for you if it is lost.\n\n### Authorization\nFor a Client to make API requests on behalf of Users, the User must first give consent.\nHere is an overview of the consent flow:\n\n1. Direct the User to grant access in Opal\n\n```\nhttps://login.ouropal.com/oauth2/auth?grant_type=authorization_code&scope=offline_access&response_type=code&client_id={client_id}&state={state}&redirect_uri={url_encoded_redirect}\n```\n\nParameters:\n- `client_id`: Provided by Opal.\n- `grant_type`: Set the value to authorization_code to receive a code string that can be exchanged for an access token.\n- `redirect_uri`: Defined by Client. After authentication, the user will be directed to this location.\n- `response_type`: The value code should be set for refresh tokens to be issued.\n- `scope`: The value offline_access must be present if you wish to use refresh tokens.\n- `state`: Defined by the Client. A unique value used to validate the response.\n\n\n2. If logged out, User is directed to log in to Opal\n\n3. User is redirected to consent page (if the User has not already given consent)\n\n```\nhttps://login.ouropal.com/oauth2/consent?consent_challenge=abc123\n```\n\n4. If the User grants permission, User is sent to the specified `redirect_uri`\n\n```\nhttps://example.com/defined-by-client?code=Mu9z2DndN7TfXSLaf99O8ReqqXqMabXhSqP5e0jlx_Q.naLKbko-GyfPJRGYcWyclxU0sBGwygPy05OSFww0XZ8&scope=offline_access&state={state}\n```\n\nParameters:\n- `code`: The Client may use this to get an access token.\n- `scope`: API permissions granted to the Client by the User.\n- `state`: The validation string provided by the Client in step 1.\n\nIf the User declines the consent prompt, User will be sent to the same `redirect_uri`, but with an error parameter :\n\n```\nhttps://example.com/defined-by-client?error=consent+request+denied&state={state}\n```\n\nParameters:\n- `error`: A brief description of the issue.\n- `state`: The validation string provided by the Client in step 1.\n\n### Retrieving Access Token\nYou must make a POST request to the token endpoint to get an access token, before the code expires:\n\n```\ncurl -X POST \\\n  https://login.ouropal.com/oauth2/token \\\n  -H 'Content-Type: application/x-www-form-urlencoded' \\\n  -d 'code={code}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={client_secret}&grant_type=authorization_code'\n```\n\nParameters:\n- `code`\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to authorization_code .\n- `redirect_uri`: Optional.\n\nIf successful, a JSON-formatted response body will contain the access_token and refresh_token:\n\n```json\n{\n  \"access_token\":\"ABC123\",\n  \"token_type\":\"bearer\",\n  \"expires_in\":3600,\n  \"refresh_token\":\"DEF456\",\n  \"scope\":\"offline_access\"\n}\n```\n\n### Refreshing an Access Token\nOnce the access_token expires, you may generate a new one at the same token endpoint, but with different parameters.\nNote that in this request, a \"refresh_token\" parameter is used instead of \"code\", and the \"grant_type\" value is now \"refresh_token\" instead of \"authorization_code\".\n\n```\ncurl -X POST \\\n  https://login.ouropal.com/oauth2/token \\\n  -H 'Content-Type: application/x-www-form-urlencoded' \\\n  -d 'refresh_token={refresh_token}&client_id={client_id}&redirect_uri={url_encoded_redirect}&client_secret={secret}&grant_type=refresh_token'\n```\n\nParameters:\n- `client_id`: Client ID provided by Opal.\n- `client_secret`: Client secret provided by Opal.\n- `grant_type`: Set value to refresh_token .\n- `redirect_uri`: Optional.\n- `refresh_token`: Refresh token value\n\n### Making Authenticated Requests\n\nSet an authorization header in your requests, specifying your access token as documented here: https://tools.ietf.org/html/rfc6750#section-2.1.\n\n**NOTE** that the `Authorization` header supercedes the `Session-Token` header described in the documentation for many endpoints. Specifying an `Authorization` header means you do not need to specify a `Session-Token` header.\n\n```\nAuthorization: Bearer ACCESS_TOKEN\n```\n\nFor example:\n```\n     GET /resource HTTP/1.1\n     Host: server.example.com\n     Authorization: Bearer mF_9.B5f-4.1JqM\n```\n\n### Client Revoke/Rolling OAuth secrets\nClient secrets must be kept secret and not exposed outside of the token retrieval requests. If a secret has been potentially compromised, please notify Opal as soon as possible and let us know the OAuth client id associated with the secret. We will roll/update the secret, which will invalidate all existing access and refresh tokens. Invalidating tokens will cause users to need to reauthenticate, but consent should be remembered.\n"
servers:
- url: https://login.ouropal.com
tags:
- name: Plans
paths:
  /{workspace_id}/plans:
    get:
      tags:
      - Plans
      operationId: ReadPlansBFFV1
      summary: Get multiple Plans.
      security:
      - oauth2:
        - offline_access
      - api_key:
        - Session-Token
      parameters:
      - name: workspace_id
        in: path
        required: true
        description: The ID of the Plan's workspace.
        schema:
          type: string
          format: uuid
      - name: filter
        in: query
        description: 'Filters for limiting the results.

          '
        required: false
        schema:
          type: object
          properties:
            is_nested:
              type: boolean
              description: 'Boolean true returns nested plans, while boolean false returns top-level plans. Omission will return all plans.

                '
        style: deepObject
        explode: true
      responses:
        '200':
          description: The requested Plans
          content:
            application/json:
              schema:
                type: object
                required:
                - data
                properties:
                  data:
                    type: array
                    items:
                      type: object
                      required:
                      - id
                      - kind
                      - default_timescale
                      - description
                      - end_at
                      - owner
                      - start_at
                      - title
                      - parent_block
                      - created_at
                      - updated_at
                      - supportive_category_id
                      additionalProperties: false
                      properties:
                        id:
                          type: string
                          format: uuid
                        kind:
                          type: string
                          enum:
                          - plan
                          description: Describes the type of view this object is.
                        default_timescale:
                          type: string
                          enum:
                          - day
                          - week
                          - month
                          - quarter
                          description: Describes the default fidelity of the plan's layout.
                        description:
                          type: string
                          description: Description of the plan.
                        end_at:
                          type: string
                          format: date
                          description: An ISO8601 date describing the end of the plan.
                        owner:
                          description: Minimal information about the user who 'owns' the plan.
                          title: user
                          type: object
                          required:
                          - id
                          - full_name
                          - avatar_url
                          - legacy_id
                          additionalProperties: false
                          properties:
                            id:
                              type: string
                              format: uuid
                            full_name:
                              type: string
                            avatar_url:
                              type:
                              - string
                              - 'null'
                              description: URL for the user's avatar.
                            legacy_id:
                              type: string
                              description: The ID to be used with v2 APIs.
                        start_at:
                          type: string
                          format: date
                          description: An ISO8601 date describing the start of the plan.
                        title:
                          type: string
                        parent_block:
                          type: object
                          description: This is the containing parent block.
                          required:
                          - id
                          - color
                          - description
                          - end_at
                          - duration
                          - owner
                          - plan
                          - start_at
                          - title
                          - created_at
                          additionalProperties: false
                          properties:
                            id:
                              type: string
                              format: uuid
                            color:
                              type:
                              - string
                              - 'null'
                            description:
                              type: string
                              description: Description of the block.
                            duration:
                              type:
                              - string
                              - 'null'
                              description: ISO 8601 duration string (e.g. P10D, P5W, P3M). Clients compute end date as start_at + duration.
                            end_at:
                              type: string
                              format: date
                              deprecated: true
                              description: 'DEPRECATED: migrate to `duration`.'
                            owner:
                              description: Minimal information about the user who 'owns' the block.
                              title: user
                              type: object
                              required:
                              - id
                              - full_name
                              - avatar_url
                              - legacy_id
                              additionalProperties: false
                              properties:
                                id:
                                  type: string
                                  format: uuid
                                full_name:
                                  type: string
                                avatar_url:
                                  type:
                                  - string
                                  - 'null'
                                  description: URL for the user's avatar.
                                legacy_id:
                                  type: string
                                  description: The ID to be used with v2 APIs.
                            plan:
                              type:
                              - object
                              - 'null'
                              description: This is the containing grandparent plan.
                              required:
                              - id
                              - kind
                              - default_timescale
                              - description
                              - end_at
                              - owner
                              - start_at
                              - title
                              - created_at
                              - updated_at
                              additionalProperties: false
                              properties:
                                id:
                                  type: string
                                  format: uuid
                                kind:
                                  type: string
                                  enum:
                                  - plan
                                  description: Describes the type of view this object is.
                                default_timescale:
                                  type: string
                                  enum:
                                  - day
                                  - week
                                  - month
                                  - quarter
                                  description: Describes the default fidelity of the plan's layout.
                                description:
                                  type: string
                                  description: Description of the plan.
                                end_at:
                                  type: string
                                  format: date
                                  description: An ISO8601 date describing the end of the plan.
                                owner:
                                  description: Minimal information about the user who 'owns' the plan.
                                  title: user
                                  type: object
                                  required:
                                  - id
                                  - full_name
                                  - avatar_url
                                  - legacy_id
                                  additionalProperties: false
                                  properties:
                                    id:
                                      type: string
                                      format: uuid
                                    full_name:
                                      type: string
                                    avatar_url:
                                      type:
                                      - string
                                      - 'null'
                                      description: URL for the user's avatar.
                                    legacy_id:
                                      type: string
                                      description: The ID to be used with v2 APIs.
                                start_at:
                                  type: string
                                  format: date
                                  description: An ISO8601 date describing the start of the plan.
                                title:
                                  type: string
                                created_at:
                                  type: string
                                  format: date-time
                                  description: The timestamp when the plan was created.
                                updated_at:
                                  type: string
                                  format: date-time
                                  description: The timestamp when the plan was last updated.
                            start_at:
                              type: string
                              format: date
                              description: An ISO8601 date describing the start of the block.
                            title:
                              type: string
                            created_at:
                              type: string
                              format: date-time
                              description: The timestamp when the block was created.
                        created_at:
                          type: string
                          format: date-time
                          description: The timestamp when the plan was created.
                        updated_at:
                          type: string
                          format: date-time
                          description: The timestamp when the plan was last updated.
                        supportive_category_id:
                          type: string
                          format: uuid
                          description: 'The identifier of the plan''s supportive category. Placing blocks

                            into this category via a block_connector designates the block

                            "in support of" this plan.

                            '
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                type: object
                required:
                - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      properties:
                        status:
                          type: string
                        title:
                          type: string
                        detail:
                          type: string
                      required:
                      - status
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                type: object
                required:
                - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      properties:
                        status:
                          type: string
                        title:
                          type: string
                        detail:
                          type: string
                      required:
                      - status
        '404':
          description: Not found
          content:
            application/json:
              schema:
                type: object
                required:
                - errors
                properties:
                  errors:
                    type: array
                    items:
                      type: object
                      properties:
                        status:
                          type: string
                        title:
                          type: string
                        detail:
                          type: string
                      required:
                      - status
components:
  securitySchemes:
    api_key:
      type: apiKey
      description: (Deprecated) This API also supports authentication via an API or session token set in the request headers.
      in: header
      name: Session-Token
x-tagGroups:
- name: ⚠️  Unstable
  tags:
  - Plans
  - Blocks
  - Custom Fields
- name: ℹ️ Proposed
  tags:
  - Moments
  - Smart Blocks
  - In Market
- name: 🔮 Experimental
  tags:
  - Experimental