OpenProject O Auth2 API

TBD

Business capability
Developer Identity & Credential Management BC-4270.40

Operations 2

GET /api/v3/oauth_applications/{id} Get the oauth application #
GET /api/v3/oauth_client_credentials/{id} Get the oauth client credentials object #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/openproject-oauth2-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

openproject-oauth2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: You're looking at the current **stable** documentation of the OpenProject APIv3.
  title: OpenProject API V3 (Stable) OAuth 2 API
  version: '3'
servers:
- url: https://qa.openproject-edge.com
  description: Edge QA instance
- url: https://qa.openproject-stage.com
  description: Staging instance
- url: https://community.openproject.org
  description: Community instance
security:
- BasicAuth: []
tags:
- description: TBD
  name: OAuth2
paths:
  /api/v3/oauth_applications/{id}:
    get:
      summary: Get the oauth application
      operationId: get_oauth_application
      tags:
      - OAuth2
      description: 'Retrieves the OAuth 2 provider application for the given identifier. The secret will not be part of the response,

        instead a `confidential` flag is indicating, whether there is a secret or not.'
      parameters:
      - name: id
        description: OAuth application id
        in: path
        required: true
        schema:
          type: integer
        example: 1337
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/OAuthApplicationReadModel'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    _type: Error
                    errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                    message: You are not authorized to access this resource.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** admin'
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
          description: Returned if the application does not exist.
  /api/v3/oauth_client_credentials/{id}:
    get:
      summary: Get the oauth client credentials object
      operationId: get_oauth_client_credentials
      tags:
      - OAuth2
      description: 'Retrieves the OAuth 2 client credentials for the given identifier. The secret will not be part of the response,

        instead a `confidential` flag is indicating, whether there is a secret or not.'
      parameters:
      - name: id
        description: OAuth Client Credentials id
        in: path
        required: true
        schema:
          type: integer
        example: 1337
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/OAuthClientCredentialsReadModel'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                response:
                  value:
                    _type: Error
                    errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                    message: You are not authorized to access this resource.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** admin'
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The requested resource could not be found.
          description: Returned if the object does not exist.
components:
  schemas:
    OAuthClientCredentialsReadModel:
      type: object
      required:
      - id
      - _type
      - clientId
      - confidential
      - _links
      properties:
        id:
          type: integer
          minimum: 1
        _type:
          type: string
          enum:
          - OAuthClientCredentials
        clientId:
          type: string
          description: OAuth 2 client id
        confidential:
          type: boolean
          description: true, if OAuth 2 credentials are confidential, false, if no secret is stored
        createdAt:
          type: string
          format: date-time
          description: The time the OAuth client credentials were created at
        updatedAt:
          type: string
          format: date-time
          description: The time the OAuth client credentials were last updated
        _links:
          type: object
          required:
          - self
          - integration
          properties:
            self:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'This OAuth Client Credentials object


                  **Resource**: OAuthClientCredentials'
            integration:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'The resource that integrates this OAuth client credentials. Currently, only `Storage` resources are

                  able to contain OAuth client credentials.


                  **Resource**: Storage'
      example:
        id: 1337
        _type: OAuthClientCredentials
        clientId: O5h6WObhMg1Z8IcLHRE3_LMh4jJYmmca2V6OTFSv8DA
        confidential: true
        createdAt: '2022-12-07T12:56:42.836Z'
        updatedAt: '2022-12-07T12:56:42.836Z'
        _links:
          self:
            href: /api/v3/oauth_client_credentials/1337
          integration:
            href: /api/v3/storages/42
            title: Death Star Cloud
    Link:
      type: object
      required:
      - href
      properties:
        href:
          type:
          - string
          - 'null'
          description: URL to the referenced resource (might be relative)
        title:
          type: string
          description: Representative label for the resource
        templated:
          type: boolean
          default: false
          description: If true the href contains parts that need to be replaced by the client
        method:
          type: string
          default: GET
          description: The HTTP verb to use when requesting the resource
        payload:
          type: object
          description: The payload to send in the request to achieve the desired result
        identifier:
          type: string
          description: An optional unique identifier to the link object
        type:
          type: string
          description: The MIME-Type of the returned resource.
      example:
        href: /api/v3/work_packages
        method: POST
    OAuthApplicationReadModel:
      type: object
      required:
      - id
      - _type
      - name
      - clientId
      - confidential
      - _links
      properties:
        id:
          type: integer
          minimum: 1
        _type:
          type: string
          enum:
          - OAuthApplication
        name:
          type: string
          description: The name of the OAuth 2 application
        clientId:
          type: string
          description: OAuth 2 client id
        clientSecret:
          type: string
          description: OAuth 2 client secret. This is only returned when creating a new OAuth application.
        confidential:
          type: boolean
          description: true, if OAuth 2 credentials are confidential, false, if no secret is stored
        createdAt:
          type: string
          format: date-time
          description: The time the OAuth 2 Application was created at
        updatedAt:
          type: string
          format: date-time
          description: The time the OAuth 2 Application was last updated
        scopes:
          type: array
          description: An array of the scopes of the OAuth 2 Application
          items:
            type: string
        _links:
          type: object
          required:
          - self
          - owner
          - redirectUri
          properties:
            self:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'This OAuth application


                  **Resource**: OAuthApplication'
            owner:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'The user that created the OAuth application.


                  **Resource**: User'
            integration:
              allOf:
              - $ref: '#/components/schemas/Link'
              - description: 'The resource that integrates this OAuth application into itself. Currently, only `Storage` resources are

                  able to create and maintain own OAuth application.


                  **Resource**: Storage'
            redirectUri:
              type: array
              items:
                allOf:
                - $ref: '#/components/schemas/Link'
                - description: 'A redirect URI of the OAuth application


                    **Resource**: N/A'
      example:
        id: 1337
        _type: OAuthApplication
        name: Vader's secure OAuth app
        clientId: O5h6WObhMg1Z8IcLHRE3_LMh4jJYmmca2V6OTFSv8DA
        confidential: true
        createdAt: '2022-12-07T12:56:42.626Z'
        updatedAt: '2022-12-07T12:56:42.626Z'
        scopes:
        - api_v3
        _links:
          self:
            href: /api/v3/oauth_applications/1337
          owner:
            href: /api/v3/users/13
            title: Darth Vader
          integration:
            href: /api/v3/storages/42
            title: Death Star Cloud
          redirectUri:
          - href: https://death-star.cloud.tools/index.php/apps/integration_openproject/oauth-redirect
    ErrorResponse:
      type: object
      required:
      - _type
      - errorIdentifier
      - message
      properties:
        _embedded:
          type: object
          properties:
            details:
              type: object
              properties:
                attribute:
                  type: string
                  example: project
        _type:
          type: string
          enum:
          - Error
        errorIdentifier:
          type: string
          example: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
        message:
          type: string
          example: Project can't be blank.
  securitySchemes:
    BasicAuth:
      type: http
      scheme: basic