Passbolt Folders API

Organize your passwords and share them in bulk using folders.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/passbolt-folders-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

passbolt-folders-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: contact@passbolt.com
  description: This is a low-level overview of the API and its endpoints, if you need higher-level guides for interacting with the endpoints, use the Developer guide.
  license:
    name: AGPL-3.0
    url: https://www.gnu.org/licenses/agpl-3.0.html
  termsOfService: https://www.passbolt.com/terms
  title: Passbolt Authentication (GPGAuth) Authentication (GPGAuth) Folders API
  version: 5.0.0
servers:
- url: https://passbolt.local
  description: API Passbolt
tags:
- name: Folders
  description: Organize your passwords and share them in bulk using folders.
paths:
  /folders.json:
    get:
      summary: Get multiple folders.
      operationId: indexFolders
      security:
      - bearerHttpAuthentication: []
      x-codeSamples:
      - lang: cURL
        source: "curl --request GET \\\n  --url {{API_BASE_URL}}/folders.json \\\n  --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
      - lang: JavaScript
        source: "const url = '{{API_BASE_URL}}/folders.json';\nconst options = {method: 'GET', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n  const response = await fetch(url, options);\n  const data = await response.json();\n  console.log(data);\n} catch (error) {\n  console.error(error);\n}\n"
      - lang: PHP
        source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n  CURLOPT_URL => \"{{API_BASE_URL}}/folders.json\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => [\n    \"Authorization: Bearer {{JWT_TOKEN}}\"\n  ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}\n"
      tags:
      - Folders
      parameters:
      - $ref: '#/components/parameters/containChildrenResources'
      - $ref: '#/components/parameters/containChildrenFolders'
      - $ref: '#/components/parameters/containCreator'
      - $ref: '#/components/parameters/containCreatorProfile'
      - $ref: '#/components/parameters/containModifier'
      - $ref: '#/components/parameters/containModifierProfile'
      - $ref: '#/components/parameters/containPermission'
      - $ref: '#/components/parameters/containPermissions'
      - $ref: '#/components/parameters/containPermissionsUserProfile'
      - $ref: '#/components/parameters/containPermissionsGroup'
      - $ref: '#/components/parameters/filterHasId'
      - $ref: '#/components/parameters/filterHasParent'
      - $ref: '#/components/parameters/filterSearch'
      responses:
        '200':
          $ref: '#/components/responses/folders_index'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/authenticationRequired'
    post:
      summary: Create a folder.
      description: '> *Encrypted metadata for this item is not supported on all clients.*

        '
      operationId: addFolder
      security:
      - bearerHttpAuthentication: []
      x-codeSamples:
      - lang: cURL
        source: "curl --request POST \\\n  --url {{API_BASE_URL}}/folders.json \\\n  --header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\n    \"metadata\": \"-----BEGIN PGP MESSAGE-----\",\n    \"metadata_key_id\": \"e3dabc04-cfbd-45c1-9f7d-827c61603e20\",\n    \"metadata_key_type\": \"shared_key\"\n  }'\n"
      - lang: JavaScript
        source: "const url = '{{API_BASE_URL}}/folders.json';\nconst options = {\n  method: 'POST',\n  headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n  body: '{\"metadata\": \"-----BEGIN PGP MESSAGE-----\", \"metadata_key_id\": \"e3dabc04-cfbd-45c1-9f7d-827c61603e20\", \"metadata_key_type\": \"shared_key\"}'\n};\n\ntry {\n  const response = await fetch(url, options);\n  const data = await response.json();\n  console.log(data);\n} catch (error) {\n  console.error(error);\n}\n"
      - lang: PHP
        source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n  CURLOPT_URL => \"{{API_BASE_URL}}/folders.json\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"POST\",\n  CURLOPT_POSTFIELDS => json_encode([\n    'metadata' => '-----BEGIN PGP MESSAGE-----',\n    'metadata_key_id' => 'e3dabc04-cfbd-45c1-9f7d-827c61603e20',\n    'metadata_key_type' => 'shared_key'\n  ]),\n  CURLOPT_HTTPHEADER => [\n    \"Authorization: Bearer {{JWT_TOKEN}}\"\n  ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}\n"
      tags:
      - Folders
      requestBody:
        $ref: '#/components/requestBodies/folderAdd'
      parameters:
      - $ref: '#/components/parameters/containChildrenResources'
      - $ref: '#/components/parameters/containChildrenFolders'
      - $ref: '#/components/parameters/containCreator'
      - $ref: '#/components/parameters/containModifier'
      - $ref: '#/components/parameters/containPermission'
      - $ref: '#/components/parameters/containPermissions'
      - $ref: '#/components/parameters/containPermissionsUserProfile'
      - $ref: '#/components/parameters/containPermissionsGroup'
      responses:
        '200':
          $ref: '#/components/responses/folders_add'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/authenticationRequired'
  /folders/{folderId}.json:
    get:
      summary: Get a folder.
      operationId: viewFolder
      security:
      - bearerHttpAuthentication: []
      x-codeSamples:
      - lang: cURL
        source: "curl --request GET \\\n  --url {{API_BASE_URL}}/folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json \\\n  --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
      - lang: JavaScript
        source: "const url = '{{API_BASE_URL}}/folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json';\nconst options = {method: 'GET', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n  const response = await fetch(url, options);\n  const data = await response.json();\n  console.log(data);\n} catch (error) {\n  console.error(error);\n}\n"
      - lang: PHP
        source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n  CURLOPT_URL => \"{{API_BASE_URL}}/folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => [\n    \"Authorization: Bearer {{JWT_TOKEN}}\"\n  ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}\n"
      tags:
      - Folders
      parameters:
      - $ref: '#/components/parameters/folderId'
      - $ref: '#/components/parameters/containChildrenResources'
      - $ref: '#/components/parameters/containChildrenFolders'
      - $ref: '#/components/parameters/containCreator'
      - $ref: '#/components/parameters/containCreatorProfile'
      - $ref: '#/components/parameters/containModifier'
      - $ref: '#/components/parameters/containModifierProfile'
      - $ref: '#/components/parameters/containPermission'
      - $ref: '#/components/parameters/containPermissions'
      - $ref: '#/components/parameters/containPermissionsUserProfile'
      - $ref: '#/components/parameters/containPermissionsGroup'
      - $ref: '#/components/parameters/filterHasId'
      responses:
        '200':
          $ref: '#/components/responses/folders_view'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/authenticationRequired'
        '404':
          $ref: '#/components/responses/notFound'
    put:
      summary: Update a folder.
      description: '> *Encrypted metadata for this item is not supported on all clients.*


        The current user must have the “update” or “owner” permission on the folder.

        '
      operationId: updateFolder
      x-codeSamples:
      - lang: cURL
        source: "curl --request PUT \\\n  --url {{API_BASE_URL}}/folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json \\\n  --header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\n    \"metadata\": \"-----BEGIN PGP MESSAGE-----\",\n    \"metadata_key_id\": \"9d9a6672-35d6-4d0f-a807-b90edf25c275\",\n    \"metadata_key_type\": \"shared_key\",\n    }'\n"
      - lang: JavaScript
        source: "const url = '{{API_BASE_URL}}/folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json';\nconst options = {\n  method: 'PUT',\n  headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n  body: '{\"metadata\":\"-----BEGIN PGP MESSAGE-----\",\"metadata_key_id\":\"9d9a6672-35d6-4d0f-a807-b90edf25c275\",\"metadata_key_type\":\"shared_key\"}'\n};\n\ntry {\n  const response = await fetch(url, options);\n  const data = await response.json();\n  console.log(data);\n} catch (error) {\n  console.error(error);\n}\n"
      - lang: PHP
        source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n  CURLOPT_URL => \"{{API_BASE_URL}}/folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"PUT\",\n  CURLOPT_POSTFIELDS => json_encode([\n    'metadata' => '-----BEGIN PGP MESSAGE-----',\n    'metadata_key_id' => '9d9a6672-35d6-4d0f-a807-b90edf25c275',\n    'metadata_key_type' => 'shared_key',\n  ]),\n  CURLOPT_HTTPHEADER => [\n    \"Authorization: Bearer {{JWT_TOKEN}}\"\n  ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}\n"
      security:
      - bearerHttpAuthentication: []
      parameters:
      - $ref: '#/components/parameters/folderId'
      - $ref: '#/components/parameters/containChildrenResources'
      - $ref: '#/components/parameters/containChildrenFolders'
      - $ref: '#/components/parameters/containCreator'
      - $ref: '#/components/parameters/containModifier'
      - $ref: '#/components/parameters/containPermission'
      - $ref: '#/components/parameters/containPermissions'
      - $ref: '#/components/parameters/containPermissionsUserProfile'
      - $ref: '#/components/parameters/containPermissionsGroup'
      tags:
      - Folders
      requestBody:
        $ref: '#/components/requestBodies/folderUpdate'
      responses:
        '200':
          $ref: '#/components/responses/folders_update'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/authenticationRequired'
        '404':
          $ref: '#/components/responses/notFound'
    delete:
      summary: Delete a folder.
      operationId: deleteFolder
      x-codeSamples:
      - lang: cURL
        source: "curl --request DELETE \\\n  --url {{API_BASE_URL}}/folders/b2a72cb2-508c-43ad-b96f-697f7ad21635.json \\\n  --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
      - lang: JavaScript
        source: "const url = '{{API_BASE_URL}}/folders/b2a72cb2-508c-43ad-b96f-697f7ad21635.json';\nconst options = {method: 'DELETE', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n  const response = await fetch(url, options);\n  const data = await response.json();\n  console.log(data);\n} catch (error) {\n  console.error(error);\n}\n"
      - lang: PHP
        source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n  CURLOPT_URL => \"{{API_BASE_URL}}/folders/b2a72cb2-508c-43ad-b96f-697f7ad21635.json\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"DELETE\",\n  CURLOPT_HTTPHEADER => [\n    \"Authorization: Bearer {{JWT_TOKEN}}\"\n  ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}\n"
      security:
      - bearerHttpAuthentication: []
      parameters:
      - $ref: '#/components/parameters/folderId'
      - $ref: '#/components/parameters/cascade'
      tags:
      - Folders
      responses:
        '200':
          $ref: '#/components/responses/nullBody'
        '400':
          $ref: '#/components/responses/badRequest'
        '401':
          $ref: '#/components/responses/authenticationRequired'
        '404':
          $ref: '#/components/responses/notFound'
components:
  schemas:
    e2eeMetadataBasedId:
      allOf:
      - $ref: '#/components/schemas/e2eeMetadataBased'
      - type: object
        required:
        - id
        properties:
          id:
            type: string
            format: uuid
    folderV5IndexAndView:
      allOf:
      - $ref: '#/components/schemas/e2eeMetadataBasedCommon'
      - type: object
        properties:
          children_resources:
            type: array
            items:
              anyOf:
              - $ref: '#/components/schemas/resourceV4IndexAndView'
              - $ref: '#/components/schemas/resourceV5IndexAndView'
          children_folders:
            type: array
            items:
              anyOf:
              - $ref: '#/components/schemas/folderV4IndexAndView'
              - $ref: '#/components/schemas/folderV5IndexAndView'
    resourceV5IndexAndView:
      allOf:
      - $ref: '#/components/schemas/e2eeMetadataBasedCommon'
      - type: object
        required:
        - resource_type_id
        - expired
        properties:
          resource_type_id:
            type: string
            format: uuid
          expired:
            type: string
            format: date-time
            x-nullable: true
          favorite:
            $ref: '#/components/schemas/favorite'
          secrets:
            type: array
            items:
              type: string
          resource_type:
            $ref: '#/components/schemas/resourceType'
    groupsUsersIndexAndView:
      type: object
      required:
      - id
      - group_id
      - user_id
      - is_admin
      - created
      properties:
        id:
          type: string
          format: uuid
        group_id:
          type: string
          format: uuid
        user_id:
          type: string
          format: uuid
        is_admin:
          type: boolean
        created:
          type: string
          format: date-time
        user:
          $ref: '#/components/schemas/userIndexAndView'
    e2eeMetadataBased:
      type: object
      required:
      - metadata
      - metadata_key_id
      - metadata_key_type
      properties:
        metadata:
          type: string
        metadata_key_id:
          type: string
          format: uuid
        metadata_key_type:
          type: string
          enum:
          - user_key
          - shared_key
    secretIndex:
      type: object
      required:
      - id
      - user_id
      - resource_id
      - data
      - created
      - modified
      properties:
        id:
          type: string
          format: uuid
        user_id:
          type: string
          format: uuid
        resource_id:
          type: string
          format: uuid
        data:
          type: string
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
    userIndexAndView:
      type: object
      required:
      - id
      - role_id
      - username
      - active
      - deleted
      - created
      - modified
      - disabled
      properties:
        is_mfa_enabled:
          type: boolean
        id:
          type: string
          format: uuid
        role_id:
          type: string
          format: uuid
        username:
          type: string
        active:
          type: boolean
        deleted:
          type: boolean
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
        disabled:
          type: string
          format: date-time
          x-nullable: true
        profile:
          type: object
          required:
          - id
          - user_id
          - first_name
          - last_name
          - created
          - modified
          - avatar
          properties:
            id:
              type: string
              format: uuid
            user_id:
              type: string
              format: uuid
            first_name:
              type: string
            last_name:
              type: string
            created:
              type: string
              format: date-time
            modified:
              type: string
              format: date-time
            avatar:
              type: object
              required:
              - url
              properties:
                id:
                  type: string
                  format: uuid
                profile_id:
                  type: string
                  format: uuid
                created:
                  type: string
                  format: date-time
                modified:
                  type: string
                  format: date-time
                url:
                  type: object
                  required:
                  - medium
                  - small
                  properties:
                    medium:
                      type: string
                      format: url
                    small:
                      type: string
                      format: url
        groups_users:
          $ref: '#/components/schemas/groupsUsersIndexAndView'
        gpgkey:
          $ref: '#/components/schemas/gpgkey'
          x-nullable: true
        role:
          $ref: '#/components/schemas/role'
        missing_metadata_key_ids:
          type: array
          items:
            type: string
            format: uuid
        last_logged_in:
          type: string
          format: date-time
          x-nullable: true
    groupIndexAndView:
      type: object
      required:
      - id
      - name
      - deleted
      - created
      - modified
      - created_by
      - modified_by
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        deleted:
          type: boolean
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
        created_by:
          type: string
          format: uuid
        modified_by:
          type: string
          format: uuid
        my_group_user:
          $ref: '#/components/schemas/groupsUsersIndexAndView'
        groups_users:
          type: array
          items:
            $ref: '#/components/schemas/groupsUsersIndexAndView'
        user_count:
          type: integer
    e2eeMetadataBasedCommon:
      allOf:
      - $ref: '#/components/schemas/e2eeMetadataBasedId'
      - type: object
        required:
        - created
        - modified
        - created_by
        - modified_by
        - personal
        - folder_parent_id
        properties:
          created:
            type: string
            format: date-time
          modified:
            type: string
            format: date-time
          created_by:
            type: string
            format: uuid
          modified_by:
            type: string
            format: uuid
          personal:
            type: boolean
          folder_parent_id:
            type: string
            format: uuid
            x-nullable: true
          modifier:
            $ref: '#/components/schemas/userIndexAndView'
          creator:
            $ref: '#/components/schemas/userIndexAndView'
          permission:
            $ref: '#/components/schemas/permissionIndexAndView'
          permissions:
            type: array
            items:
              $ref: '#/components/schemas/permissionIndexAndView'
    headerWithPagination:
      type: object
      required:
      - id
      - status
      - servertime
      - action
      - message
      - url
      - code
      - pagination
      properties:
        id:
          type: string
          format: uuid
        status:
          type: string
          enum:
          - success
          - error
        servertime:
          type: integer
          example: 1720702619
        action:
          type: string
          format: uuid
        message:
          type: string
          example: The operation was successful.
        url:
          type: string
          format: uri
          example: /auth/verify.json
        code:
          type: integer
          example: 200
        pagination:
          type: object
          required:
          - count
          - page
          - limit
          properties:
            count:
              type: integer
            page:
              type: integer
            limit:
              type: integer
              x-nullable: true
    resourceV4IndexAndView:
      type: object
      required:
      - id
      - name
      - username
      - uri
      - description
      - deleted
      - created
      - created_by
      - modified_by
      - resource_type_id
      - expired
      - folder_parent_id
      - personal
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        username:
          type: string
        uri:
          type: string
        description:
          type: string
        deleted:
          type: boolean
        created:
          type: string
          format: date-time
        created_by:
          type: string
          format: uuid
        modified_by:
          type: string
          format: uuid
        resource_type_id:
          type: string
          format: uuid
        expired:
          type: string
          format: date-time
          x-nullable: true
        folder_parent_id:
          type: string
          format: uuid
          x-nullable: true
        personal:
          type: boolean
        favorite:
          $ref: '#/components/schemas/favorite'
        modifier:
          $ref: '#/components/schemas/userIndexAndView'
        creator:
          $ref: '#/components/schemas/userIndexAndView'
        secrets:
          type: array
          items:
            $ref: '#/components/schemas/secretIndex'
        resource_type:
          $ref: '#/components/schemas/resourceType'
        permission:
          $ref: '#/components/schemas/permissionIndexAndView'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/permissionIndexAndView'
    gpgkey:
      type: object
      required:
      - id
      - user_id
      - armored_key
      - bits
      - uid
      - key_id
      - fingerprint
      - type
      - expires
      - key_created
      - deleted
      - created
      - modified
      properties:
        id:
          type: string
          format: uuid
        user_id:
          type: string
          format: uuid
        armored_key:
          type: string
        bits:
          type: integer
        uid:
          type: string
        key_id:
          type: string
        fingerprint:
          type: string
        type:
          type: string
          enum:
          - RSA
          - ECC
        expires:
          type: string
          format: date-time
          x-nullable: true
        deleted:
          type: boolean
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
    permissionIndexAndView:
      type: object
      required:
      - id
      - aco
      - aco_foreign_key
      - aro
      - aro_foreign_key
      - type
      - created
      - modified
      properties:
        id:
          type: string
          format: uuid
        aco:
          type: string
          enum:
          - Resource
          - Folder
        aco_foreign_key:
          type: string
          format: uuid
        aro:
          type: string
          enum:
          - User
          - Group
        aro_foreign_key:
          type: string
          format: uuid
        type:
          $ref: '#/components/schemas/permissionLevel'
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
        user:
          $ref: '#/components/schemas/userIndexAndView'
          x-nullable: true
        group:
          $ref: '#/components/schemas/groupIndexAndView'
          x-nullable: true
    permissionLevel:
      description: '* `1` - Read

        * `7` - Update

        * `15` - Owner

        '
      type: integer
      enum:
      - 1
      - 7
      - 15
    resourceType:
      type: object
      required:
      - id
      - slug
      - name
      - description
      - definition
      - deleted
      - created
      - modified
      properties:
        id:
          type: string
          format: uuid
        slug:
          type: string
          description: '* `password-string` - The original passbolt resource type, where the secret is a non empty string.

            * `password-and-description` - A resource with the password and the description encrypted.

            * `totp` - A resource with standalone TOTP fields.

            * `password-description-totp` - A resource with encrypted password, description and TOTP fields.

            * `v5-default-with-totp` - The new default resource type with a TOTP introduced with v5.

            * `v5-password-string (Deprecated)` - The original passbolt resource type, kept for backward compatibility reasons.

            * `v5-totp-standalone` - The new standalone TOTP resource type introduced with v5.

            * `v5-default` - The new default resource type introduced with v5.

            '
          enum:
          - password-string
          - password-and-description
          - totp
          - password-description-totp
          - v5-default-with-totp
          - v5-password-string (Deprecated)
          - v5-totp-standalone
          - v5-default
        name:
          type: string
        description:
          type: string
        definition:
          type: object
          description: Schema for the expected data for this kind of resources.
        deleted:
          type: string
          x-nullable: true
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
    role:
      type: object
      required:
      - id
      - name
      - description
      - created
      - modified
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
          enum:
          - admin
          - guest
          - user
        description:
          type: string
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
    favorite:
      type: object
      required:
      - id
      - user_id
      - foreign_key
      - foreign_model
      - created
      - modified
      properties:
        id:
          type: string
          format: uuid
        user_id:
          type: string
          format: uuid
        foreign_key:
          type: string
          format: uuid
        foreign_model:
          type: string
          enum:
          - Resource
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
    header:
      type: object
      required:
      - id
      - status
      - servertime
      - action
      - message
      - url
      - code
      properties:
        id:
          type: string
          format: uuid
        status:
          type: string
          enum:
          - success
          - error
        servertime:
          type: integer
          example: 1720702619
        action:
          type: string
          format: uuid
        message:
          type: string
          example: The operation was successful.
        url:
          type: string
          format: uri
          example: /auth/verify.json
        code:
          type: integer
          example: 200
    folderV4IndexAndView:
      type: object
      required:
      - id
      - name
      - created
      - modified
      - created_by
      - modified_by
      - folder_parent_id
      - personal
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        created:
          type: string
          format: date-time
        modified:
          type: string
          format: date-time
        created_by:
          type: string
          format: uuid
        modified_by:
          type: string
          format: uuid
        folder_parent_id:
          type: string
          format: uuid
          x-nullable: true
        personal:
          type: boolean
        modifier:
          $ref: '#/components/schemas/userIndexAndView'
        creator:
          $ref: '#/components/schemas/userIndexAndView'
        permission:
          $ref: '#/components/schemas/permissionIndexAndView'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/permissionIndexAndView'
        children_resources:
          type: array
          items:
            anyOf:
            - $ref: '#/components/schemas/resourceV4IndexAndView'
            - $ref: '#/components/schemas/resourceV5IndexAndView'
        children_folders:
          type: array
          items:
            anyOf:
            - $ref: '#/components/schemas/folderV4IndexAndView'
            - $ref: '#/components/schemas/folderV5IndexAndView'
  responses:
    folders_update:
      description: Operation is successful
      content:
        application/json:
          schema:
            type: object
            required:
            - header
            - body
            properties:
              header:
                $ref: '#/components/schemas/header'
              body:
                $ref: '#/components/schemas/folderV5IndexAndView'
          examples:
            index:
              value:
                header:
                  id: 7ff2828c-1092-4897-8e0a-1dc64ada889f
                  status: success
                  servertime: 1721207029
                  action: 4d0c0996-ce30-4bce-9918-9062ab35c542
                  message: The operation was successful.
                  url: /folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json
                  code: 200
                body:
                  id: 27605bac-8aa8-4fe4-a80b-486d8b76c748
                  metadata: '-----BEGIN PGP MESSAGE-----'
                  metadata_key_id: dd1f723d-0d1e-513f-8218-4055dc0530d0
                  metadata_key_type: shared_key
                  created: '2025-02-19T13:50:53+00:00'
                  modified: '2025-02-19T13:50:53+00:00'
                  created_by: ae48ed02-54ea-4be4-9ae8-229bf8c04739
                  modified_by: ae48ed02-54ea-4be4-9ae8-229bf8c04739
                  folder_parent_id: null
                  personal: true
    folders_view:
      description: Operation is successful
      content:
        application/json:
          schema:
            type: object
            required:
            - header
            - body
            properties:
              header:
                $ref: '#/components/schemas/header'
              body:
                anyOf:
                - $ref: '#/components/schemas/folderV4IndexAndView'
                - $ref: '#/components/schemas/folderV5IndexAndView'
          examples:
            index:
              value:
                header:
                  id: 7ff2828c-1092-4897-8e0a-1dc64ada889f
                  status: success
                  servertime: 1721207029
                  action: 4d0c0996-ce30-4bce-9918-9062ab35c542
                  message: The operation was successful.
                  url: /folders/27605bac-8aa8-4fe4-a80b-486d8b76c748.json
       

# --- truncated at 32 KB (43 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/passbolt/refs/heads/main/openapi/passbolt-folders-api-openapi.yml