OpenProject Notifications API

Notifications are created through notifiable actions in OpenProject. Notifications are triggered by actions carried out in the system by users, e.g. editing a work package, but can also be send out because of time passing e.g. when a user is notified of a work package that is overdue. This endpoint only returns in-app notifications. ## Actions | Link | Description | Condition | |:-------------------:| -------------------------------------------------------------------- | --------------------------- | | read_ian | Marks the notification as read | notification is unread | | unread_ian | Marks the notification as unread | notification is read | ## Linked Properties | Link | Description | Type | Constraints | Supported operations | Condition | | :-----------: | ---------------------------------------- | -------------- | --------------------- | -------------------- | ----------------------------------------- | | self | This notification | Notification | not null | READ | | | project | The project containing the resource | Project | not null | READ | | | actor | The user that caused the notification | User | | READ | optional | | resource | The resource the notification belongs to | Polymorphic | not null | READ | | | activity | The journal the notification belongs to | Polymorphic | | READ | optional | | details | A list of objects including detailed information | Polymorphic | | READ | optional | ## Local Properties | Property | Description | Type | Constraints | Supported operations | Condition | | :----------: | --------------------------------------------------------- | -------- | ---------------------------------------------------- | -------------------- | ----------------------------------------------------------- | | id | Primary key | Integer | | READ | | | subject | The subject of the notification | String | | READ | | | reason | The reason causing the notification | String | | READ | | | readIAN | Whether the notification is read | Boolean | | READ | |

Operations 7

GET /api/v3/notifications Get notification collection #
POST /api/v3/notifications/read_ian Read all notifications #
POST /api/v3/notifications/unread_ian Unread all notifications #
GET /api/v3/notifications/{id} Get the notification #
GET /api/v3/notifications/{notification_id}/details/{id} Get a notification detail #
POST /api/v3/notifications/{id}/read_ian Read notification #
POST /api/v3/notifications/{id}/unread_ian Unread notification #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/openproject-notifications-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

openproject-notifications-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: "You're looking at the current **stable** documentation of the OpenProject APIv3. If you're interested in the current\ndevelopment version, please go to [github.com/opf](https://github.com/opf/openproject/tree/dev/docs/api/apiv3).\n\n## Introduction\n\nThe documentation for the APIv3 is written according to the [OpenAPI 3.1 Specification](https://swagger.io/specification/).\nYou can either view the static version of this documentation on the [website](https://www.openproject.org/docs/api/introduction/)\nor the interactive version, rendered with [OpenAPI Explorer](https://github.com/Rhosys/openapi-explorer/blob/main/README.md),\nin your OpenProject installation under `/api/docs`.\nIn the latter you can try out the various API endpoints directly interacting with our OpenProject data.\nMoreover you can access the specification source itself under `/api/v3/spec.json` and `/api/v3/spec.yml`\n(e.g. [here](https://community.openproject.org/api/v3/spec.yml)).\n\nThe APIv3 is a hypermedia REST API, a shorthand for \"Hypermedia As The Engine Of Application State\" (HATEOAS).\nThis means that each endpoint of this API will have links to other resources or actions defined in the resulting body.\n\nThese related resources and actions for any given resource will be context sensitive. For example, only actions that the\nauthenticated user can take are being rendered. This can be used to dynamically identify actions that the user might take for any\ngiven response.\n\nAs an example, if you fetch a work package through the [Work Package endpoint](https://www.openproject.org/docs/api/endpoints/work-packages/), the `update` link will only\nbe present when the user you authenticated has been granted a permission to update the work package in the assigned project.\n\n## HAL+JSON\n\nHAL is a simple format that gives a consistent and easy way to hyperlink between resources in your API.\nRead more in the following specification: [https://tools.ietf.org/html/draft-kelly-json-hal-08](https://tools.ietf.org/html/draft-kelly-json-hal-08)\n\n**OpenProject API implementation of HAL+JSON format** enriches JSON and introduces a few meta properties:\n\n- `_type` - specifies the type of the resource (e.g.: WorkPackage, Project)\n- `_links` - contains all related resource and action links available for the resource\n- `_embedded` - contains all embedded objects\n\nHAL does not guarantee that embedded resources are embedded in their full representation, they might as well be\npartially represented (e.g. some properties can be left out).\nHowever in this API you have the guarantee that whenever a resource is **embedded**, it is embedded in its **full representation**.\n\n## API response structure\n\nAll API responses contain a single HAL+JSON object, even collections of objects are technically represented by\na single HAL+JSON object that itself contains its members. More details on collections can be found\nin the [Collections Section](https://www.openproject.org/docs/api/collections/).\n\n## Authentication\n\nThe API supports the following authentication schemes:\n\n* Session-based authentication\n* API tokens\n    * passed as Bearer token\n    * passed via Basic auth\n* OAuth 2.0\n    * using built-in authorization server\n    * using an external authorization server (RFC 9068)\n\nDepending on the settings of the OpenProject instance many resources can be accessed without being authenticated.\nIn case the instance requires authentication on all requests the client will receive an **HTTP 401** status code\nin response to any request.\n\nOtherwise unauthenticated clients have all the permissions of the anonymous user.\n\n### Session-based authentication\n\nThis means you have to login to OpenProject via the Web-Interface to be authenticated in the API.\nThis method is well-suited for clients acting within the browser, like the Angular-Client built into OpenProject.\n\nIn this case, you always need to pass the HTTP header `X-Requested-With \"XMLHttpRequest\"` for authentication.\n\n### API token as bearer token\n\nUsers can authenticate towards the API v3 using an API token as a bearer token.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42\n```\n\nUsers can generate API tokens on their account page.\n\n### API token through Basic Auth\n\nAPI tokens can also be used with basic auth, using the user name `apikey` (NOT your login) and the API token as the password.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -u apikey:$API_KEY https://community.openproject.org/api/v3/users/42\n```\n\n### OAuth 2.0 authentication\n\nOpenProject allows authentication and authorization with OAuth2 with *Authorization code flow*, as well as *Client credentials* operation modes.\n\nTo get started, you first need to register an application in the OpenProject OAuth administration section of your installation.\nThis will save an entry for your application with a client unique identifier (`client_id`) and an accompanying secret key (`client_secret`).\n\nYou can then use one the following guides to perform the supported OAuth 2.0 flows:\n\n- [Authorization code flow](https://oauth.net/2/grant-types/authorization-code)\n\n- [Authorization code flow with PKCE](https://doorkeeper.gitbook.io/guides/ruby-on-rails/pkce-flow), recommended for clients unable to keep the client_secret confidential\n\n- [Client credentials](https://oauth.net/2/grant-types/client-credentials/) - Requires an application to be bound to an impersonating user for non-public access\n\n### OAuth 2.0 using an external authorization server\n\nThere is a possibility to use JSON Web Tokens (JWT) generated by an OIDC provider configured in OpenProject as a bearer token to do authenticated requests against the API.\nThe following requirements must be met:\n\n- OIDC provider must be configured in OpenProject with **jwks_uri**\n- JWT must be signed using RSA algorithm\n- JWT **iss** claim must be equal to OIDC provider **issuer**\n- JWT **aud** claim must contain the OpenProject **client ID** used at the OIDC provider\n- JWT **scope** claim must include a valid scope to access the desired API (e.g. `api_v3` for APIv3)\n- JWT must be actual (neither expired or too early to be used)\n- JWT must be passed in Authorization header like: `Authorization: Bearer {jwt}`\n- User from **sub** claim must be linked to OpenProject before (e.g. by logging in), otherwise it will be not authenticated\n\nIn more general terms, OpenProject should be compliant to [RFC 9068](https://www.rfc-editor.org/rfc/rfc9068) when validating access tokens.\n\n### Why not username and password?\n\nThe simplest way to do basic auth would be to use a user's username and password naturally.\nHowever, OpenProject already has supported API keys in the past for the API v2, though not through basic auth.\n\nUsing **username and password** directly would have some advantages:\n\n* It is intuitive for the user who then just has to provide those just as they would when logging into OpenProject.\n\n* No extra logic for token management necessary.\n\nOn the other hand using **API keys** has some advantages too, which is why we went for that:\n\n* If compromised while saved on an insecure client the user only has to regenerate the API key instead of changing their password, too.\n\n* They are naturally long and random which makes them invulnerable to dictionary attacks and harder to crack in general.\n\nMost importantly users may not actually have a password to begin with. Specifically when they have registered\nthrough an OpenID Connect provider.\n\n## Cross-Origin Resource Sharing (CORS)\n\nBy default, the OpenProject API is _not_ responding with any CORS headers.\nIf you want to allow cross-domain AJAX calls against your OpenProject instance, you need to enable CORS headers being returned.\n\nPlease see [our API settings documentation](https://www.openproject.org/docs/system-admin-guide/api-and-webhooks/) on\nhow to selectively enable CORS.\n\n## Allowed HTTP methods\n\n- `GET` - Get a single resource or collection of resources\n\n- `POST` - Create a new resource or perform\n\n- `PATCH` - Update a resource\n\n- `DELETE` - Delete a resource\n\n## Compression\n\nResponses are compressed if requested by the client. Currently [gzip](https://www.gzip.org/) and [deflate](https://tools.ietf.org/html/rfc1951)\nare supported. The client signals the desired compression by setting the [`Accept-Encoding` header](https://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.3).\nIf no `Accept-Encoding` header is send, `Accept-Encoding: identity` is assumed which will result in the API responding uncompressed."
  title: OpenProject API V3 (Stable) Actions & Capabilities Notifications API
  version: '3'
servers:
- url: https://qa.openproject-edge.com
  description: Edge QA instance
- url: https://qa.openproject-stage.com
  description: Staging instance
- url: https://community.openproject.org
  description: Community instance
security:
- BasicAuth: []
tags:
- description: 'Notifications are created through notifiable actions in OpenProject.

    Notifications are triggered by actions carried out in the system by users, e.g. editing a work package, but can also be send out because

    of time passing e.g. when a user is notified of a work package that is overdue.


    This endpoint only returns in-app notifications.


    ## Actions


    | Link                | Description                                                          | Condition                   |

    |:-------------------:| -------------------------------------------------------------------- | --------------------------- |

    | read_ian            | Marks the notification as read                                       | notification is unread      |

    | unread_ian          | Marks the notification as unread                                     | notification is read        |


    ## Linked Properties


    | Link          | Description                                       | Type            | Constraints           | Supported operations | Condition                                 |

    | :-----------: | ----------------------------------------          | --------------  | --------------------- | -------------------- | ----------------------------------------- |

    | self          | This notification                                 | Notification    | not null              | READ                 |                                           |

    | project       | The project containing the resource               | Project         | not null              | READ                 |                                           |

    | actor         | The user that caused the notification             | User            |                       | READ                 | optional                                  |

    | resource      | The resource the notification belongs to          | Polymorphic     | not null              | READ                 |                                           |

    | activity      | The journal the notification belongs to           | Polymorphic     |                       | READ                 | optional                                  |

    | details       | A list of objects including detailed information  | Polymorphic     |                       | READ                 | optional                                  |


    ## Local Properties


    | Property     | Description                                               | Type          | Constraints                                          | Supported operations | Condition                                                   |

    | :----------: | --------------------------------------------------------- | --------      | ---------------------------------------------------- | -------------------- | ----------------------------------------------------------- |

    | id           | Primary key                                               | Integer       |                                                      | READ                 |                                                             |

    | subject      | The subject of the notification                           | String        |                                                      | READ                 |                                                             |

    | reason       | The reason causing the notification                       | String        |                                                      | READ                 |                                                             |

    | readIAN      | Whether the notification is read                          | Boolean       |                                                      | READ                 |                                                             |'
  name: Notifications
paths:
  /api/v3/notifications:
    get:
      summary: Get notification collection
      operationId: list_notifications
      tags:
      - Notifications
      description: 'Returns the collection of available in-app notifications. The notifications returned depend on the provided

        parameters and also on the requesting user''s permissions.


        Contrary to most collections, this one also links to and embeds schemas for the `details` properties of the notifications returned.

        This is an optimization. Clients will receive the information necessary to display the various types of details that a notification

        can carry.'
      parameters:
      - name: offset
        description: Page number inside the requested collection.
        in: query
        example: 25
        required: false
        schema:
          default: 1
          type: integer
      - name: pageSize
        description: Number of elements to display per page.
        in: query
        example: 25
        required: false
        schema:
          default: 20
          type: integer
      - name: sortBy
        in: query
        description: 'JSON specifying sort criteria.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/) endpoint. Currently supported sorts are:


          + id: Sort by primary key


          + reason: Sort by notification reason


          + readIAN: Sort by read status'
        example: '[["reason", "asc"]]'
        required: false
        schema:
          type: string
      - name: groupBy
        in: query
        description: 'string specifying group_by criteria.


          + reason: Group by notification reason


          + project: Sort by associated project'
        example: reason
        required: false
        schema:
          type: string
      - name: filters
        in: query
        description: 'JSON specifying filter conditions.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/) endpoint. Currently supported filters are:


          + id: Filter by primary key


          + project: Filter by the project the notification was created in


          + readIAN: Filter by read status


          + reason: Filter by the reason, e.g. ''mentioned'' or ''assigned'' the notification was created because of


          + resourceId: Filter by the id of the resource the notification was created for. Ideally used together with the `resourceType` filter.


          + resourceType: Filter by the type of the resource the notification was created for. Ideally used together with the `resourceId` filter.'
        example: '[{ "readIAN": { "operator": "=", "values": ["t"] } }]'
        required: false
        schema:
          type: string
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/NotificationCollectionModel'
              examples:
                Collection of notifications:
                  $ref: '#/components/examples/NotificationCollection'
          description: OK
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not authorized to view this resource.
          description: Returned if the client is not logged in and login is required.
        '422':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:InvalidQuery
                message: Filters Invalid filter does not exist.
          description: Returned if the client sends invalid request parameters e.g. filters
  /api/v3/notifications/read_ian:
    post:
      summary: Read all notifications
      operationId: read_notifications
      tags:
      - Notifications
      description: 'Marks the whole notification collection as read. The collection contains only elements the authenticated user can

        see, and can be further reduced with filters.'
      parameters:
      - name: filters
        in: query
        description: "JSON specifying filter conditions.\nAccepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/)\nendpoint. Currently supported filters are:\n\n+ id: Filter by primary key\n\n+ project: Filter by the project the notification was created in\n\n+ reason: Filter by the reason, e.g. 'mentioned' or 'assigned' the notification was created because of\n\n+ resourceId: Filter by the id of the resource the notification was created for. Ideally used together with the\n  `resourceType` filter.\n\n+ resourceType: Filter by the type of the resource the notification was created for. Ideally used together with\n  the `resourceId` filter."
        example: '[{ "reason": { "operator": "=", "values": ["mentioned"] } }]'
        required: false
        schema:
          type: string
      responses:
        '204':
          description: OK
        '400':
          description: Returned if the request is not properly formatted.
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:InvalidQuery
                message:
                - Filters Invalid filter does not exist.
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
  /api/v3/notifications/unread_ian:
    post:
      summary: Unread all notifications
      operationId: unread_notifications
      tags:
      - Notifications
      description: 'Marks the whole notification collection as unread. The collection contains only elements the authenticated user can

        see, and can be further reduced with filters.'
      parameters:
      - name: filters
        in: query
        description: "JSON specifying filter conditions.\nAccepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/)\nendpoint. Currently supported filters are:\n\n+ id: Filter by primary key\n\n+ project: Filter by the project the notification was created in\n\n+ reason: Filter by the reason, e.g. 'mentioned' or 'assigned' the notification was created because of\n\n+ resourceId: Filter by the id of the resource the notification was created for. Ideally used together with the\n  `resourceType` filter.\n\n+ resourceType: Filter by the type of the resource the notification was created for. Ideally used together with\n  the `resourceId` filter."
        example: '[{ "reason": { "operator": "=", "values": ["mentioned"] } }]'
        required: false
        schema:
          type: string
      responses:
        '204':
          description: OK
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
  /api/v3/notifications/{id}:
    get:
      summary: Get the notification
      operationId: view_notification
      tags:
      - Notifications
      description: Returns the notification identified by the notification id.
      parameters:
      - name: id
        in: path
        description: notification id
        example: 1
        required: true
        schema:
          type: integer
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/NotificationModel'
              examples:
                Date alert notification:
                  $ref: '#/components/examples/DateAlertNotification'
                Mentioned notification:
                  $ref: '#/components/examples/MentionedNotification'
          description: OK
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
          description: 'Returned if the notification does not exist or if the user does not have permission to view it.


            **Required permission** being recipient of the notification'
  /api/v3/notifications/{notification_id}/details/{id}:
    get:
      summary: Get a notification detail
      operationId: view_notification_detail
      tags:
      - Notifications
      description: Returns an individual detail of a notification identified by the notification id and the id of the detail.
      parameters:
      - name: notification_id
        in: path
        description: notification id
        example: 1
        required: true
        schema:
          type: integer
      - name: id
        in: path
        description: detail id
        example: 0
        required: true
        schema:
          type: integer
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ValuesPropertyModel'
              examples:
                Start date notification detail:
                  $ref: '#/components/examples/ValuesPropertyStartDate'
                Due date notification detail:
                  $ref: '#/components/examples/ValuesPropertyDueDate'
                Date notification detail for milestone work package:
                  $ref: '#/components/examples/ValuesPropertyDate'
          description: OK
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
          description: 'Returned if the notification or the detail of it does not exist or if the user does not have permission to view it.


            **Required permission** being recipient of the notification'
  /api/v3/notifications/{id}/read_ian:
    post:
      summary: Read notification
      operationId: read_notification
      tags:
      - Notifications
      description: Marks the given notification as read.
      parameters:
      - name: id
        in: path
        description: notification id
        example: '1'
        required: true
        schema:
          type: integer
      responses:
        '204':
          description: OK
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
          description: 'Returned if the notification does not exist or if the user does not have permission to view it.


            **Required permission** being recipient of the notification'
  /api/v3/notifications/{id}/unread_ian:
    post:
      summary: Unread notification
      operationId: unread_notification
      tags:
      - Notifications
      description: Marks the given notification as unread.
      parameters:
      - name: id
        in: path
        description: notification id
        example: 1
        required: true
        schema:
          type: integer
      responses:
        '204':
          description: OK
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
          description: 'Returned if the notification does not exist or if the user does not have permission to view it.


            **Required permission** being recipient of the notification'
components:
  schemas:
    UserModel:
      allOf:
      - $ref: '#/components/schemas/PrincipalModel'
      - $ref: '#/components/schemas/CustomFieldProperties'
      - type: object
        required:
        - _type
        - avatar
        properties:
          _type:
            type: string
            enum:
            - User
          avatar:
            type:
            - string
            - 'null'
            format: uri
            description: URL to user's avatar
          login:
            type: string
            description: 'The user''s login name


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 256
          firstName:
            type: string
            description: 'The user''s first name


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 30
          lastName:
            type: string
            description: 'The user''s last name


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 30
          email:
            type: string
            description: 'The user''s email address


              # Conditions


              - E-Mail address not hidden

              - User is not a new record

              - User is self, or `create_user` or `manage_user` permission globally'
            maxLength: 60
          admin:
            type: boolean
            description: 'Flag indicating whether or not the user is an admin


              # Conditions


              - `admin`'
          status:
            type: string
            description: 'The current activation status of the user.


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
          language:
            type: string
            description: 'User''s language | ISO 639-1 format


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
          identityUrl:
            type:
            - string
            - 'null'
            description: 'User''s identity_url for OmniAuth authentication.

              **Deprecated:** It will be removed in the near future.


              # Conditions


              - User is self, or `create_user` or `manage_user` permission globally'
            deprecated: true
          createdAt:
            type: string
            format: date-time
            description: Time of creation
          updatedAt:
            type: string
            format: date-time
            description: Time of the most recent change to the user
          _links:
            type: object
            properties:
              showUser:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'A relative path to show the user in the web application.


                    # Condition


                    - User is not a new record

                    - User is not `locked`'
              updateImmediately:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'A link to update the user resource.


                    # Conditions


                    - `admin`'
              lock:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'Restrict the user from logging in and performing any actions.


                    # Conditions


                    - User is not locked

                    - `admin`'
              unlock:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'Allow a locked user to login and act again.


                    # Conditions


                    - User is not locked

                    - `admin`'
              delete:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: "Permanently remove a user from the instance\n\n# Conditions\n\neither:\n  - `admin`\n  - Setting `users_deletable_by_admin` is set\nor:\n  - User is self\n  - Setting `users_deletable_by_self` is set"
              authSource:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'Permanently remove a user from the instance


                    # Conditions


                    - LDAP authentication configured

                    - `admin`'
    PrincipalModel:
      type: object
      required:
      - _type
      - id
      - name
      - _links
      properties:
        _type:
          type: string
          enum:
          - User
          - Group
          - PlaceholderUser
        id:
          type: integer
          description: The principal's unique identifier.
          minimum: 1
        name:
          type: string
          description: The principal's display name, layout depends on instance settings.
        createdAt:
          type: string
          format: date-time
          description: Time of creation
        updatedAt:
          type: string
          format: date-time
          description: Time of the most recent change to the principal
        _links:
          type: object
          required:
          - self
          properties:
            self:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'This principal resource.


                  **Resource**: User|Group|PlaceholderUser'
            memberships:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'An href to the collection of the principal''s memberships.


                  # Conditions:


                  - user has permission `view_members` or `manage_members` in any project


                  **Resource**: Collection'
    AttachmentModel:
      type: object
      required:
      - fileName
      - description
      - status
      - contentType
      - digest
      - createdAt
      properties:
        id:
          type: integer
          description: Attachment's id
          minimum: 1
        fileName:
          type: string
          description: The name of the uploaded file
        fileSize:
          type: integer
          description: The size of the uploaded file in Bytes
          minimum: 0
        description:
          allOf:
          - $ref: '#/components/schemas/Formattable'
          - description: A user provided description of the file
        status:
          type: string
          enum:
          - uploaded
          - prepared
          - scanned
          - quarantined
          - rescan
        contentType:
          type: string
          description: The files MIME-Type as determined by the server
        digest:
          type: object
          description: A checksum for the files content
          required:
          - algorith

# --- truncated at 32 KB (106 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/openproject/refs/heads/main/openapi/openproject-notifications-api-openapi.yml