OpenProject Meetings API
The Meetings API from OpenProject — 2 operation(s) for meetings.
The Meetings API from OpenProject — 2 operation(s) for meetings.
openapi: 3.1.2
info:
description: "You're looking at the current **stable** documentation of the OpenProject APIv3. If you're interested in the current\ndevelopment version, please go to [github.com/opf](https://github.com/opf/openproject/tree/dev/docs/api/apiv3).\n\n## Introduction\n\nThe documentation for the APIv3 is written according to the [OpenAPI 3.1 Specification](https://swagger.io/specification/).\nYou can either view the static version of this documentation on the [website](https://www.openproject.org/docs/api/introduction/)\nor the interactive version, rendered with [OpenAPI Explorer](https://github.com/Rhosys/openapi-explorer/blob/main/README.md),\nin your OpenProject installation under `/api/docs`.\nIn the latter you can try out the various API endpoints directly interacting with our OpenProject data.\nMoreover you can access the specification source itself under `/api/v3/spec.json` and `/api/v3/spec.yml`\n(e.g. [here](https://community.openproject.org/api/v3/spec.yml)).\n\nThe APIv3 is a hypermedia REST API, a shorthand for \"Hypermedia As The Engine Of Application State\" (HATEOAS).\nThis means that each endpoint of this API will have links to other resources or actions defined in the resulting body.\n\nThese related resources and actions for any given resource will be context sensitive. For example, only actions that the\nauthenticated user can take are being rendered. This can be used to dynamically identify actions that the user might take for any\ngiven response.\n\nAs an example, if you fetch a work package through the [Work Package endpoint](https://www.openproject.org/docs/api/endpoints/work-packages/), the `update` link will only\nbe present when the user you authenticated has been granted a permission to update the work package in the assigned project.\n\n## HAL+JSON\n\nHAL is a simple format that gives a consistent and easy way to hyperlink between resources in your API.\nRead more in the following specification: [https://tools.ietf.org/html/draft-kelly-json-hal-08](https://tools.ietf.org/html/draft-kelly-json-hal-08)\n\n**OpenProject API implementation of HAL+JSON format** enriches JSON and introduces a few meta properties:\n\n- `_type` - specifies the type of the resource (e.g.: WorkPackage, Project)\n- `_links` - contains all related resource and action links available for the resource\n- `_embedded` - contains all embedded objects\n\nHAL does not guarantee that embedded resources are embedded in their full representation, they might as well be\npartially represented (e.g. some properties can be left out).\nHowever in this API you have the guarantee that whenever a resource is **embedded**, it is embedded in its **full representation**.\n\n## API response structure\n\nAll API responses contain a single HAL+JSON object, even collections of objects are technically represented by\na single HAL+JSON object that itself contains its members. More details on collections can be found\nin the [Collections Section](https://www.openproject.org/docs/api/collections/).\n\n## Authentication\n\nThe API supports the following authentication schemes:\n\n* Session-based authentication\n* API tokens\n * passed as Bearer token\n * passed via Basic auth\n* OAuth 2.0\n * using built-in authorization server\n * using an external authorization server (RFC 9068)\n\nDepending on the settings of the OpenProject instance many resources can be accessed without being authenticated.\nIn case the instance requires authentication on all requests the client will receive an **HTTP 401** status code\nin response to any request.\n\nOtherwise unauthenticated clients have all the permissions of the anonymous user.\n\n### Session-based authentication\n\nThis means you have to login to OpenProject via the Web-Interface to be authenticated in the API.\nThis method is well-suited for clients acting within the browser, like the Angular-Client built into OpenProject.\n\nIn this case, you always need to pass the HTTP header `X-Requested-With \"XMLHttpRequest\"` for authentication.\n\n### API token as bearer token\n\nUsers can authenticate towards the API v3 using an API token as a bearer token.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42\n```\n\nUsers can generate API tokens on their account page.\n\n### API token through Basic Auth\n\nAPI tokens can also be used with basic auth, using the user name `apikey` (NOT your login) and the API token as the password.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -u apikey:$API_KEY https://community.openproject.org/api/v3/users/42\n```\n\n### OAuth 2.0 authentication\n\nOpenProject allows authentication and authorization with OAuth2 with *Authorization code flow*, as well as *Client credentials* operation modes.\n\nTo get started, you first need to register an application in the OpenProject OAuth administration section of your installation.\nThis will save an entry for your application with a client unique identifier (`client_id`) and an accompanying secret key (`client_secret`).\n\nYou can then use one the following guides to perform the supported OAuth 2.0 flows:\n\n- [Authorization code flow](https://oauth.net/2/grant-types/authorization-code)\n\n- [Authorization code flow with PKCE](https://doorkeeper.gitbook.io/guides/ruby-on-rails/pkce-flow), recommended for clients unable to keep the client_secret confidential\n\n- [Client credentials](https://oauth.net/2/grant-types/client-credentials/) - Requires an application to be bound to an impersonating user for non-public access\n\n### OAuth 2.0 using an external authorization server\n\nThere is a possibility to use JSON Web Tokens (JWT) generated by an OIDC provider configured in OpenProject as a bearer token to do authenticated requests against the API.\nThe following requirements must be met:\n\n- OIDC provider must be configured in OpenProject with **jwks_uri**\n- JWT must be signed using RSA algorithm\n- JWT **iss** claim must be equal to OIDC provider **issuer**\n- JWT **aud** claim must contain the OpenProject **client ID** used at the OIDC provider\n- JWT **scope** claim must include a valid scope to access the desired API (e.g. `api_v3` for APIv3)\n- JWT must be actual (neither expired or too early to be used)\n- JWT must be passed in Authorization header like: `Authorization: Bearer {jwt}`\n- User from **sub** claim must be linked to OpenProject before (e.g. by logging in), otherwise it will be not authenticated\n\nIn more general terms, OpenProject should be compliant to [RFC 9068](https://www.rfc-editor.org/rfc/rfc9068) when validating access tokens.\n\n### Why not username and password?\n\nThe simplest way to do basic auth would be to use a user's username and password naturally.\nHowever, OpenProject already has supported API keys in the past for the API v2, though not through basic auth.\n\nUsing **username and password** directly would have some advantages:\n\n* It is intuitive for the user who then just has to provide those just as they would when logging into OpenProject.\n\n* No extra logic for token management necessary.\n\nOn the other hand using **API keys** has some advantages too, which is why we went for that:\n\n* If compromised while saved on an insecure client the user only has to regenerate the API key instead of changing their password, too.\n\n* They are naturally long and random which makes them invulnerable to dictionary attacks and harder to crack in general.\n\nMost importantly users may not actually have a password to begin with. Specifically when they have registered\nthrough an OpenID Connect provider.\n\n## Cross-Origin Resource Sharing (CORS)\n\nBy default, the OpenProject API is _not_ responding with any CORS headers.\nIf you want to allow cross-domain AJAX calls against your OpenProject instance, you need to enable CORS headers being returned.\n\nPlease see [our API settings documentation](https://www.openproject.org/docs/system-admin-guide/api-and-webhooks/) on\nhow to selectively enable CORS.\n\n## Allowed HTTP methods\n\n- `GET` - Get a single resource or collection of resources\n\n- `POST` - Create a new resource or perform\n\n- `PATCH` - Update a resource\n\n- `DELETE` - Delete a resource\n\n## Compression\n\nResponses are compressed if requested by the client. Currently [gzip](https://www.gzip.org/) and [deflate](https://tools.ietf.org/html/rfc1951)\nare supported. The client signals the desired compression by setting the [`Accept-Encoding` header](https://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.3).\nIf no `Accept-Encoding` header is send, `Accept-Encoding: identity` is assumed which will result in the API responding uncompressed."
title: OpenProject API V3 (Stable) Actions & Capabilities Meetings API
version: '3'
servers:
- url: https://qa.openproject-edge.com
description: Edge QA instance
- url: https://qa.openproject-stage.com
description: Staging instance
- url: https://community.openproject.org
description: Community instance
security:
- BasicAuth: []
tags:
- name: Meetings
paths:
/api/v3/meetings:
get:
summary: List all visible meetings
operationId: list_meetings
tags:
- Meetings
description: Retrieve a paginated collection of meetings visible to the authenticated user.
responses:
'200':
description: OK
content:
application/hal+json:
examples:
response:
$ref: '#/components/examples/MeetingCollectionSimpleResponse'
schema:
$ref: '#/components/schemas/MeetingCollectionModel'
/api/v3/meetings/{id}:
get:
summary: Get a meeting
operationId: get_meeting
tags:
- Meetings
description: Retrieve an individual meeting as identified by the id parameter
parameters:
- description: Meeting identifier
example: 1
in: path
name: id
required: true
schema:
type: integer
responses:
'200':
description: OK
content:
application/hal+json:
examples:
response:
$ref: '#/components/examples/MeetingSimpleResponse'
schema:
$ref: '#/components/schemas/MeetingModel'
'404':
content:
application/hal+json:
schema:
$ref: '#/components/schemas/ErrorResponse'
examples:
response:
value:
_type: Error
errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
message: The requested resource could not be found.
description: 'Returned if the meeting does not exist or the client does not have sufficient permissions to see it.
**Required permission:** view meetings in the page''s project'
components:
schemas:
CollectionModel:
type: object
required:
- _type
- total
- count
- _links
properties:
_type:
type: string
enum:
- Collection
total:
type: integer
description: The total amount of elements available in the collection.
minimum: 0
count:
type: integer
description: Actual amount of elements in this response.
minimum: 0
_links:
$ref: '#/components/schemas/CollectionLinks'
AttachmentModel:
type: object
required:
- fileName
- description
- status
- contentType
- digest
- createdAt
properties:
id:
type: integer
description: Attachment's id
minimum: 1
fileName:
type: string
description: The name of the uploaded file
fileSize:
type: integer
description: The size of the uploaded file in Bytes
minimum: 0
description:
allOf:
- $ref: '#/components/schemas/Formattable'
- description: A user provided description of the file
status:
type: string
enum:
- uploaded
- prepared
- scanned
- quarantined
- rescan
contentType:
type: string
description: The files MIME-Type as determined by the server
digest:
type: object
description: A checksum for the files content
required:
- algorithm
- hash
properties:
algorithm:
type: string
description: The algorithm used to generate the digest.
hash:
type: string
description: The hexadecimal representation of the digested hash value.
createdAt:
type: string
format: date-time
description: Time of creation
_links:
type: object
required:
- self
- container
- author
- downloadLocation
properties:
delete:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Deletes this attachment
# Conditions
**Permission**: edit on attachment container or being the author for attachments without container'
self:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'This attachment
**Resource**: Attachment'
container:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The object (e.g. WorkPackage) housing the attachment
**Resource**: Anything'
author:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The user who uploaded the attachment
**Resource**: User'
downloadLocation:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Direct download link to the attachment
**Resource**: -'
example:
_type: Attachment
_links:
self:
href: /api/v3/attachments/1
container:
href: /api/v3/work_packages/1
author:
href: /api/v3/users/1
staticDownloadLocation:
href: /api/v3/attachments/1/content
downloadLocation:
href: /some/remote/aws/url/image.png
id: 1
fileName: cat.png
filesize: 24
status: uploaded
description:
format: plain
raw: A picture of a cute cat
html: <p>A picture of a cute cat</p>
contentType: image/png
digest:
algorithm: md5
hash: 64c26a8403cd796ea4cf913cda2ee4a9
createdAt: '2014-05-21T08:51:20.396Z'
CollectionLinks:
type: object
required:
- self
properties:
self:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'This collection resource.
**Resource**: Collection'
Formattable:
type: object
required:
- format
properties:
format:
type: string
enum:
- plain
- markdown
- custom
readOnly: true
description: Indicates the formatting language of the raw text
example: markdown
raw:
type: string
description: The raw text, as entered by the user
example: I **am** formatted!
html:
type: string
readOnly: true
description: The text converted to HTML according to the format
example: I <strong>am</strong> formatted!
example:
format: markdown
raw: I am formatted!
html: I am formatted!
Link:
type: object
required:
- href
properties:
href:
type:
- string
- 'null'
description: URL to the referenced resource (might be relative)
title:
type: string
description: Representative label for the resource
templated:
type: boolean
default: false
description: If true the href contains parts that need to be replaced by the client
method:
type: string
default: GET
description: The HTTP verb to use when requesting the resource
payload:
type: object
description: The payload to send in the request to achieve the desired result
identifier:
type: string
description: An optional unique identifier to the link object
type:
type: string
description: The MIME-Type of the returned resource.
example:
href: /api/v3/work_packages
method: POST
UserModel:
allOf:
- $ref: '#/components/schemas/PrincipalModel'
- $ref: '#/components/schemas/CustomFieldProperties'
- type: object
required:
- _type
- avatar
properties:
_type:
type: string
enum:
- User
avatar:
type:
- string
- 'null'
format: uri
description: URL to user's avatar
login:
type: string
description: 'The user''s login name
# Conditions
- User is self, or `create_user` or `manage_user` permission globally'
maxLength: 256
firstName:
type: string
description: 'The user''s first name
# Conditions
- User is self, or `create_user` or `manage_user` permission globally'
maxLength: 30
lastName:
type: string
description: 'The user''s last name
# Conditions
- User is self, or `create_user` or `manage_user` permission globally'
maxLength: 30
email:
type: string
description: 'The user''s email address
# Conditions
- E-Mail address not hidden
- User is not a new record
- User is self, or `create_user` or `manage_user` permission globally'
maxLength: 60
admin:
type: boolean
description: 'Flag indicating whether or not the user is an admin
# Conditions
- `admin`'
status:
type: string
description: 'The current activation status of the user.
# Conditions
- User is self, or `create_user` or `manage_user` permission globally'
language:
type: string
description: 'User''s language | ISO 639-1 format
# Conditions
- User is self, or `create_user` or `manage_user` permission globally'
identityUrl:
type:
- string
- 'null'
description: 'User''s identity_url for OmniAuth authentication.
**Deprecated:** It will be removed in the near future.
# Conditions
- User is self, or `create_user` or `manage_user` permission globally'
deprecated: true
createdAt:
type: string
format: date-time
description: Time of creation
updatedAt:
type: string
format: date-time
description: Time of the most recent change to the user
_links:
type: object
properties:
showUser:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'A relative path to show the user in the web application.
# Condition
- User is not a new record
- User is not `locked`'
updateImmediately:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'A link to update the user resource.
# Conditions
- `admin`'
lock:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Restrict the user from logging in and performing any actions.
# Conditions
- User is not locked
- `admin`'
unlock:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Allow a locked user to login and act again.
# Conditions
- User is not locked
- `admin`'
delete:
allOf:
- $ref: '#/components/schemas/Link'
- description: "Permanently remove a user from the instance\n\n# Conditions\n\neither:\n - `admin`\n - Setting `users_deletable_by_admin` is set\nor:\n - User is self\n - Setting `users_deletable_by_self` is set"
authSource:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Permanently remove a user from the instance
# Conditions
- LDAP authentication configured
- `admin`'
Attachments_Model:
allOf:
- $ref: '#/components/schemas/CollectionModel'
- type: object
required:
- _links
- _embedded
properties:
_links:
type: object
required:
- self
properties:
self:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The attachments collection
**Resource**: AttachmentsCollection'
readOnly: true
_embedded:
type: object
properties:
elements:
type: array
readOnly: true
items:
allOf:
- $ref: '#/components/schemas/AttachmentModel'
- description: Collection of Attachments
MeetingCollectionModel:
allOf:
- $ref: '#/components/schemas/PaginatedCollectionModel'
- type: object
required:
- _embedded
- _links
properties:
_embedded:
type: object
required:
- elements
properties:
elements:
type: array
items:
$ref: '#/components/schemas/MeetingModel'
_links:
type: object
required:
- self
properties:
self:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The link to this meeting collection resource
**Resource**: MeetingCollection'
MeetingModel:
type: object
required:
- _type
- id
- lockVersion
- title
- startTime
- endTime
- duration
- createdAt
- updatedAt
properties:
_type:
type: string
enum:
- Meeting
id:
type: integer
description: Identifier of this meeting
minimum: 1
title:
type: string
description: The meeting's title
location:
type: string
description: The meeting's location
lockVersion:
type: integer
description: The version of the item as used for optimistic locking
startTime:
type: string
format: date-time
description: The scheduled meeting start time.
endTime:
type: string
format: date-time
description: The scheduled meeting start time.
duration:
type: number
description: The meeting duration in hours.
createdAt:
type: string
format: date-time
description: Time of creation. Can be writable by admins with the `apiv3_write_readonly_attributes` setting enabled.
updatedAt:
type: string
format: date-time
description: Time of the most recent change to the meeting.
_embedded:
type: object
required:
- attachments
- author
properties:
attachments:
$ref: '#/components/schemas/Attachments_Model'
author:
$ref: '#/components/schemas/UserModel'
project:
$ref: '#/components/schemas/ProjectModel'
_links:
type: object
properties:
self:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'This meeting
**Resource**: Meeting'
author:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The user having created the meeting
**Resource**: User'
project:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The project the meeting is in
**Resource**: Project'
attachments:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'The attachment collection of this grid.
**Resource**: AttachmentCollection'
addAttachment:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Attach a file to the meeting
# Conditions
**Permission**: edit meeting'
ErrorResponse:
type: object
required:
- _type
- errorIdentifier
- message
properties:
_embedded:
type: object
properties:
details:
type: object
properties:
attribute:
type: string
example: project
_type:
type: string
enum:
- Error
errorIdentifier:
type: string
example: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
message:
type: string
example: Project can't be blank.
ProjectModel:
allOf:
- $ref: '#/components/schemas/CustomFieldProperties'
- $ref: '#/components/schemas/CustomCommentProperties'
- type: object
properties:
_type:
type: string
enum:
- Project
id:
type: integer
description: Projects' id
minimum: 1
identifier:
type: string
name:
type: string
active:
type: boolean
description: Indicates whether the project is currently active or already archived
favorited:
type: boolean
description: Indicates whether the project is favorited by the current user
statusExplanation:
allOf:
- $ref: '#/components/schemas/Formattable'
- description: A text detailing and explaining why the project has the reported status
public:
type: boolean
description: Indicates whether the project is accessible for everybody
description:
$ref: '#/components/schemas/Formattable'
createdAt:
type: string
format: date-time
description: Time of creation. Can be writable by admins with the `apiv3_write_readonly_attributes` setting enabled.
updatedAt:
type: string
format: date-time
description: Time of the most recent change to the project
_links:
type: object
required:
- self
- categories
properties:
update:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Form endpoint that aids in updating this project
# Conditions
**Permission**: edit workspace'
updateImmediately:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Directly update this project
# Conditions
**Permission**: edit workspace'
delete:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Delete this project
# Conditions
**Permission**: admin'
favor:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Mark this project as favorited by the current user
# Conditions
Only present if the project is not yet favorited
Permission**: none but login is required'
disfavor:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Mark this project as not favorited by the current user
# Conditions
Only present if the project is favorited by the current user
Permission**: none but login is required'
createWorkPackage:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Form endpoint that aids in preparing and creating a work package
# Conditions
**Permission**: add work packages'
createWorkPackageImmediately:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Directly creates a work package in the project
# Conditions
**Permission**: add work packages'
self:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'This project
**Resource**: Project'
categories:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Categories available in this project
**Resource**: Collection'
types:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Types available in this project
**Resource**: Collection
# Conditions
**Permission**: view work packages or manage types'
versions:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Versions available in this project
**Resource**: Collection
# Conditions
**Permission**: view work packages or manage versions'
memberships:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Memberships in the project
**Resource**: Collection
# Conditions
**Permission**: view members'
workPackages:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Work Packages of this project
**Resource**: Collection'
parent:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Parent of the project
**Resource**: Workspace
# Conditions
**Permission** edit workspace'
status:
allOf:
- $ref: '#/components/schemas/Link'
- description: 'Denotes the status of the project, so whether the project is on track, at risk or is having trouble.
**Resource**: ProjectStatus
# Conditions
**Permission** edit workspace'
# --- truncated at 32 KB (38 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/openproject/refs/heads/main/openapi/openproject-meetings-api-openapi.yml