OpenProject Groups API

Groups are collections of users. They support assigning/unassigning multiple users to/from a project in one operation. This resource does not yet have the form and schema endpoints. But as all properties are static, clients should still be able to work with this resource. ## Actions ## Actions | Link | Description | Condition | |:-------------------:| -------------------------------------------------------------------- | ---------------------------------------------------------------- | | delete | Deletes the group. | **Permission**: Administrator | | updateImmediately | Updates the group's attributes. | **Permission**: Administrator | ## Linked Properties | Link | Description | Type | Constraints | Supported operations | Condition | |:-----------: |-------------------------------------------------------------- | ------------- | --------------------- | -------------------- | ----------------------------------------- | | self | This group | Group | not null | READ | | | memberships | Link to collection of all the group's memberships. The list will only include the memberships in projects in which the requesting user has the necessary permissions. | MemberCollection | | READ | **Permission**: view members or manage members in any project | | members | The list all all the users that are members of the group | UserCollection | | READ/WRITE | **Permission**: manage members in any project to read & admin to write | Depending on custom fields defined for versions, additional linked properties might exist. ## Local Properties | Property | Description | Type | Constraints | Supported operations | Condition | | :----------: | --------------------------------------------------------- | -------- | ---------------------------------------------------- | -------------------- | ----------------------------------------------------------- | | id | Group's id | Integer | x > 0 | READ | | | name | Group's full name, formatting depends on instance settings | String | | READ/WRITE | Admin to write | | createdAt | Time of creation | DateTime | | READ | Only visible by admins | | updatedAt | Time of the most recent change to the user | DateTime | | READ | Only visible by admins | Depending on custom fields defined for versions, additional properties might exist.

Operations 5

GET /api/v3/groups List groups #
POST /api/v3/groups Create group #
DELETE /api/v3/groups/{id} Delete group #
GET /api/v3/groups/{id} Get group #
PATCH /api/v3/groups/{id} Update group #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/openproject-groups-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

openproject-groups-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: You're looking at the current **stable** documentation of the OpenProject APIv3.
  title: OpenProject API V3 (Stable) Groups API
  version: '3'
servers:
- url: https://qa.openproject-edge.com
  description: Edge QA instance
- url: https://qa.openproject-stage.com
  description: Staging instance
- url: https://community.openproject.org
  description: Community instance
security:
- BasicAuth: []
tags:
- description: Groups are collections of users.
  name: Groups
paths:
  /api/v3/groups:
    get:
      summary: List groups
      operationId: list_groups
      tags:
      - Groups
      description: 'Returns a collection of groups. The client can choose to filter the

        groups similar to how work packages are filtered. In addition to the provided

        filters, the server will reduce the result set to only contain groups, for which

        the requesting client has sufficient permissions (*view_members*, *manage_members*).'
      parameters:
      - name: sortBy
        description: 'JSON specifying sort criteria.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/) endpoint. Currently supported sorts are:


          + id: Sort by primary key


          + created_at: Sort by group creation datetime


          + updated_at: Sort by the time the group was updated last'
        in: query
        required: false
        example: '[["id", "asc"]]'
        schema:
          default: '[["id", "asc"]]'
          type: string
      - name: select
        description: Comma separated list of properties to include.
        in: query
        required: false
        example: total,elements/name,elements/self,self
        schema:
          type: string
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/GroupCollectionModel'
        '403':
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** View members or manage members in any project'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not authorized to access this resource.
    post:
      summary: Create group
      operationId: create_group
      tags:
      - Groups
      description: Creates a new group applying the attributes provided in the body.
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GroupWriteModel'
      responses:
        '201':
          description: Created
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/GroupModel'
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrator'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not authorized to access this resource.
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '422':
          description: 'Returned if:


            * a constraint for a property was violated (`PropertyConstraintViolation`)'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _embedded:
                  details:
                    attribute: name
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                message: Name can't be blank.
  /api/v3/groups/{id}:
    delete:
      summary: Delete group
      operationId: delete_group
      tags:
      - Groups
      description: Deletes the group.
      parameters:
      - name: id
        description: Group id
        example: 1
        in: path
        required: true
        schema:
          type: integer
      responses:
        '202':
          description: 'Returned if the group was marked for deletion.


            Note that the response body is empty as of now. In future versions of the API a body

            *might* be returned, indicating the progress of deletion.'
        '403':
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrator'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not authorized to access this resource.
        '404':
          description: 'Returned if the group does not exist or the client does not have sufficient permissions

            to see it.


            **Required permission:** Administrator


            *Note: A client without sufficient permissions shall not be able to test for the existence of

            a version. That''s why a 404 is returned here, even if a 403 might be more appropriate.*'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    _type: Error
                    errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                    message: The requested resource could not be found.
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
    get:
      summary: Get group
      operationId: get_group
      tags:
      - Groups
      description: Fetches a group resource.
      parameters:
      - name: id
        description: Group id
        example: 1
        in: path
        required: true
        schema:
          type: integer
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/GroupModel'
              examples:
                group response:
                  $ref: '#/components/examples/GroupResponse'
        '404':
          description: 'Returned if the group does not exist or if the API user does not have permission to view them.


            **Required permission** If the user has the *manage members* permission in at least one project the user will be able to query all groups. If not, the user

            will be able to query all groups which are members in projects, he has the *view members* permission in.'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
    patch:
      summary: Update group
      operationId: update_group
      tags:
      - Groups
      description: 'Updates the given group by applying the attributes provided in the body.


        Please note that the `members` array provided will override the existing set of members (similar to a PUT). A

        client thus has to provide the complete list of members the group is to have after the PATCH even if only one

        member is to be added.'
      parameters:
      - name: id
        description: Group id
        example: 1
        in: path
        required: true
        schema:
          type: integer
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GroupWriteModel'
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/GroupModel'
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrator'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not authorized to access this resource.
        '404':
          description: 'Returned if the group does not exist or the client does not have sufficient permissions

            to see it.


            **Required permission** If the user has the *manage members* permission in at least one project the user will be able to query all groups. If not, the user

            will be able to query all groups which are members in projects, he has the *view members* permission in.


            *Note: A client without sufficient permissions shall not be able to test for the existence of

            a version. That''s why a 404 is returned here, even if a 403 might be more appropriate.*'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '422':
          description: 'Returned if:


            * a constraint for a property was violated (`PropertyConstraintViolation`)'
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _embedded:
                  details:
                    attribute: members
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                message: Member is already taken.
components:
  schemas:
    CollectionLinks:
      type: object
      required:
      - self
      properties:
        self:
          allOf:
          - $ref: '#/components/schemas/Link'
          - description: 'This collection resource.


              **Resource**: Collection'
    CustomFieldProperties:
      type: object
      patternProperties:
        ^customField\d+$:
          type:
          - 'null'
          - number
          - boolean
          - string
          - object
          description: 'A custom field value, that belongs to a custom field of a simple type:


            - Boolean

            - Date

            - Float

            - Integer

            - Link (URL)

            - Text

            - Long text'
    Link:
      type: object
      required:
      - href
      properties:
        href:
          type:
          - string
          - 'null'
          description: URL to the referenced resource (might be relative)
        title:
          type: string
          description: Representative label for the resource
        templated:
          type: boolean
          default: false
          description: If true the href contains parts that need to be replaced by the client
        method:
          type: string
          default: GET
          description: The HTTP verb to use when requesting the resource
        payload:
          type: object
          description: The payload to send in the request to achieve the desired result
        identifier:
          type: string
          description: An optional unique identifier to the link object
        type:
          type: string
          description: The MIME-Type of the returned resource.
      example:
        href: /api/v3/work_packages
        method: POST
    GroupModel:
      allOf:
      - $ref: '#/components/schemas/PrincipalModel'
      - $ref: '#/components/schemas/CustomFieldProperties'
      - type: object
        required:
        - _type
        - _embedded
        properties:
          _type:
            type: string
            enum:
            - Group
          _embedded:
            type: object
            properties:
              members:
                type: array
                description: Embedded list of members.
                items:
                  $ref: '#/components/schemas/UserModel'
          _links:
            type: object
            properties:
              self:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'This group resource


                    **Resource**: Group'
              members:
                type: array
                items:
                  allOf:
                  - $ref: '#/components/schemas/Link'
                  - description: 'A member of the group


                      # Conditions:


                      - user has permission `manage_members` in any project


                      **Resource**: User'
              memberships:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'An collection of all memberships of the group.


                    **Resource**: MembershipCollection'
              delete:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'An href to delete the group.


                    # Conditions:


                    - `admin`'
              updateImmediately:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'An href to update the group.


                    # Conditions:


                    - `admin`


                    **Resource**: Group'
    PrincipalModel:
      type: object
      required:
      - _type
      - id
      - name
      - _links
      properties:
        _type:
          type: string
          enum:
          - User
          - Group
          - PlaceholderUser
        id:
          type: integer
          description: The principal's unique identifier.
          minimum: 1
        name:
          type: string
          description: The principal's display name, layout depends on instance settings.
        createdAt:
          type: string
          format: date-time
          description: Time of creation
        updatedAt:
          type: string
          format: date-time
          description: Time of the most recent change to the principal
        _links:
          type: object
          required:
          - self
          properties:
            self:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'This principal resource.


                  **Resource**: User|Group|PlaceholderUser'
            memberships:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'An href to the collection of the principal''s memberships.


                  # Conditions:


                  - user has permission `view_members` or `manage_members` in any project


                  **Resource**: Collection'
    GroupWriteModel:
      type: object
      properties:
        name:
          type: string
          description: The new group name.
        _links:
          type: object
          properties:
            members:
              type: array
              items:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'A new member for the group.


                    **Resource**: User'
      example:
        name: Emperor's guard
        _links:
          members:
          - href: /api/v3/users/42
          - href: /api/v3/users/43
          - href: /api/v3/users/44
    UserModel:
      allOf:
      - $ref: '#/components/schemas/PrincipalModel'
      - $ref: '#/components/schemas/CustomFieldProperties'
      - type: object
        required:
        - _type
        - avatar
        properties:
          _type:
            type: string
            enum:
            - User
          avatar:
            type:
            - string
            - 'null'
            format: uri
            description: URL to user's avatar
          login:
            type: string
            description: 'The user''s login name


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 256
          firstName:
            type: string
            description: 'The user''s first name


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 30
          lastName:
            type: string
            description: 'The user''s last name


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 30
          email:
            type: string
            description: 'The user''s email address


              # Conditions


              - E-Mail address not hidden

              - User is not a new record

              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 60
          admin:
            type: boolean
            description: 'Flag indicating whether or not the user is an admin


              # Conditions


              - `admin`'
          status:
            type: string
            description: 'The current activation status of the user.


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
          language:
            type: string
            description: 'User''s language | ISO 639-1 format


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
          identityUrl:
            type:
            - string
            - 'null'
            description: 'User''s identity_url for OmniAuth authentication.

              **Deprecated:** It will be removed in the near future.


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            deprecated: true
          createdAt:
            type: string
            format: date-time
            description: Time of creation
          updatedAt:
            type: string
            format: date-time
            description: Time of the most recent change to the user
          _links:
            type: object
            properties:
              showUser:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'A relative path to show the user in the web application.


                    # Condition


                    - User is not a new record

                    - User is not `locked`'
              updateImmediately:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'A link to update the user resource.


                    # Conditions


                    - `admin`'
              lock:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'Restrict the user from logging in and performing any actions.


                    # Conditions


                    - User is not locked

                    - `admin`'
              unlock:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'Allow a locked user to login and act again.


                    # Conditions


                    - User is not locked

                    - `admin`'
              delete:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: "Permanently remove a user from the instance\n\n# Conditions\n\neither:\n  - `admin`\n  - Setting `users_deletable_by_admin` is set\nor:\n  - User is self\n  - Setting `users_deletable_by_self` is set"
              authSource:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'Permanently remove a user from the instance


                    # Conditions


                    - LDAP authentication configured

                    - `admin`'
    GroupCollectionModel:
      allOf:
      - $ref: '#/components/schemas/CollectionModel'
      - type: object
        required:
        - _links
        - _embedded
        properties:
          _links:
            type: object
            required:
            - self
            properties:
              self:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'This group collection


                    **Resource**: Collection'
          _embedded:
            type: object
            required:
            - elements
            properties:
              elements:
                type: array
                items:
                  $ref: '#/components/schemas/GroupModel'
      example:
        _type: Collection
        total: 2
        count: 2
        _links:
          self:
            href: /api/v3/groups
        _embedded:
          elements:
          - _type: Group
            id: 1337
            name: Stormtroopers
            createdAt: '2022-09-23T11:06:36.300Z'
            updatedAt: '2022-09-23T11:06:36.300Z'
            _links:
              self:
                href: /api/v3/groups/9
                title: Stormtroopers
              delete:
                href: /api/v3/group/9
                method: delete
              memberships:
                href: /api/v3/memberships?filters=[{"principal":{"operator":"=","values":["9"]}}]
                title: Memberships
              updateImmediately:
                href: /api/v3/group/9
                method: patch
              members:
              - href: /api/v3/users/363
                title: ST-097E
              - href: /api/v3/users/60
                title: ST-C-334
          - _abbreviated: Group resource shortened for brevity
            id: 1338
    ErrorResponse:
      type: object
      required:
      - _type
      - errorIdentifier
      - message
      properties:
        _embedded:
          type: object
          properties:
            details:
              type: object
              properties:
                attribute:
                  type: string
                  example: project
        _type:
          type: string
          enum:
          - Error
        errorIdentifier:
          type: string
          example: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
        message:
          type: string
          example: Project can't be blank.
    CollectionModel:
      type: object
      required:
      - _type
      - total
      - count
      - _links
      properties:
        _type:
          type: string
          enum:
          - Collection
        total:
          type: integer
          description: The total amount of elements available in the collection.
          minimum: 0
        count:
          type: integer
          description: Actual amount of elements in this response.
          minimum: 0
        _links:
          $ref: '#/components/schemas/CollectionLinks'
  examples:
    GroupResponse:
      value:
        _type: Group
        id: 26
        name: Force Users
        createdAt: '2024-01-11T15:54:16.542Z'
        updatedAt: '2024-01-11T15:58:02.237Z'
        _embedded:
          members:
          - _type: User
            id: 23
            name: Grogu Jarin
            _abbreviated: Principal resource shortened for brevity
          - _type: User
            id: 14
            name: Mara Jade
            _abbreviated: Principal resource shortened for brevity
          - _type: User
            id: 3
            name: Darth Vader
            _abbreviated: Principal resource shortened for brevity
        _links:
          self:
            href: /api/v3/groups/26
            title: Force Users
          memberships:
            href: /api/v3/memberships?filters=%5B%7B%22principal%22%3A%7B%22operator%22%3A%22%3D%22%2C%22values%22%3A%5B%2226%22%5D%7D%7D%5D
            title: Memberships
          delete:
            href: /api/v3/groups/26
            method: delete
          updateImmediately:
            href: /api/v3/groups/26
            method: patch
          members:
          - href: /api/v3/users/23
            title: Grogu Jarin
          - href: /api/v3/users/14
            title: Mara Jade
          - href: /api/v3/users/3
            title: Darth Vader
  responses:
    MissingContentType:
      description: Occurs when the client did not send a Content-Type header
      content:
        text/plain:
          schema:
            type: string
          example: Missing content-type header
    InvalidRequestBody:
      description: Occurs when the client did not send a valid JSON object in the request body.
      content:
        application/hal+json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            _type: Error
            errorIdentifier: urn:openproject-org:api:v3:errors:InvalidRequestBody
            message: The request body was not a single JSON object.
    UnsupportedMediaType:
      description: Occurs when the client sends an unsupported Content-Type header.
      content:
        application/hal+json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            _type: Error
            errorIdentifier: urn:openproject-org:api:v3:errors:TypeNotSupported
            message: Expected CONTENT-TYPE to be (expected value) but got (actual value).
  securitySchemes:
    BasicAuth:
      type: http
      scheme: basic