Passbolt Groups API
Organize users in logical groups to make it easier to share resources with them.
Organize users in logical groups to make it easier to share resources with them.
openapi: 3.1.0
info:
contact:
email: contact@passbolt.com
description: This is a low-level overview of the API and its endpoints, if you need higher-level guides for interacting with the endpoints, use the Developer guide.
license:
name: AGPL-3.0
url: https://www.gnu.org/licenses/agpl-3.0.html
termsOfService: https://www.passbolt.com/terms
title: Passbolt Authentication (GPGAuth) Authentication (GPGAuth) Groups API
version: 5.0.0
servers:
- url: https://passbolt.local
description: API Passbolt
tags:
- name: Groups
description: 'Organize users in logical groups to make it easier to share resources with them.
'
paths:
/groups.json:
get:
summary: Get multiple groups.
operationId: indexGroups
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request GET \\\n --url {{API_BASE_URL}}/groups.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups.json';\nconst options = {method: 'GET', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
parameters:
- $ref: '#/components/parameters/containModifier'
- $ref: '#/components/parameters/containModifierProfile'
- $ref: '#/components/parameters/containMyGroupUser'
- $ref: '#/components/parameters/containGroupsUsers'
- $ref: '#/components/parameters/containGroupsUsersUser'
- $ref: '#/components/parameters/containGroupsUsersUserProfile'
- $ref: '#/components/parameters/containGroupsUsersUserGpgkey'
- $ref: '#/components/parameters/filterHasUsers'
- $ref: '#/components/parameters/filterHasManagers'
responses:
'200':
$ref: '#/components/responses/groups_index'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
post:
summary: Create a group.
description: Please note that only users with Admin role can create a group.
operationId: addGroup
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request POST \\\n --url {{API_BASE_URL}}/groups.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n --header 'Content-Type: application/json' \\\n --data '{\n \"name\": \"Groupe B\",\n \"groups_users\": [\n {\n \"user_id\": \"8bb80df5-700c-48ce-b568-85a60fc3c8f2\",\n \"is_admin\": true\n }]\n }'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups.json';\nconst options = {\n method: 'POST',\n headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n body: '{\"name\":\"Groupe B\",\"groups_users\":[{\"user_id\":\"8bb80df5-700c-48ce-b568-85a60fc3c8f2\",\"is_admin\":true}]}'\n};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"POST\",\n CURLOPT_POSTFIELDS => json_encode([\n 'name' => 'Groupe B',\n 'groups_users' => [\n [\n 'user_id' => '8bb80df5-700c-48ce-b568-85a60fc3c8f2',\n 'is_admin' => true\n ]\n ]\n ]),\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
responses:
'200':
$ref: '#/components/responses/addAndUpdate'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
requestBody:
$ref: '#/components/requestBodies/groupAdd'
/groups/{groupId}.json:
get:
summary: Get a group.
operationId: viewGroup
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request GET \\\n --url {{API_BASE_URL}}/groups/8a3c5c4e-e931-4e6b-854a-9b2e9afcd3bc.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups/8a3c5c4e-e931-4e6b-854a-9b2e9afcd3bc.json';\nconst options = {method: 'GET', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups/8a3c5c4e-e931-4e6b-854a-9b2e9afcd3bc.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
parameters:
- $ref: '#/components/parameters/groupId'
- $ref: '#/components/parameters/containModifier'
- $ref: '#/components/parameters/containModifierProfile'
- $ref: '#/components/parameters/containUsers'
- $ref: '#/components/parameters/containMyGroupUser'
- $ref: '#/components/parameters/containGroupsUsers'
- $ref: '#/components/parameters/containGroupsUsersUser'
- $ref: '#/components/parameters/containGroupsUsersUserProfile'
- $ref: '#/components/parameters/containGroupsUsersUserGpgkey'
responses:
'200':
$ref: '#/components/responses/groups_view'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
put:
summary: Update a group.
operationId: updateGroup
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request PUT \\\n--url {{API_BASE_URL}}/groups/8fa37ef6-f167-4342-8e1c-3488439cf7d1.json \\\n--header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n--header 'Content-Type: application/json' \\\n--data '{\n \"name\": \"WRC\",\n \"groups_users\": [\n {\n \"user_id\": \"8bb80df5-700c-48ce-b568-85a60fc3c8f2\",\n \"is_admin\": true\n },\n {\n \"id\": \"3b9b9757-1ccb-444a-a3cf-4090364fac4f\",\n \"is_admin\": false\n },\n {\n \"id\": \"1a2b3c4d-5e6f-7g8h-9i0j-k1l2m3n4o5p6\",\n \"delete\": true\n }\n ]\n}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups/8fa37ef6-f167-4342-8e1c-3488439cf7d1.json';\nconst options = {\n method: 'PUT',\n headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n body: '{\"name\":\"WRC\",\"groups_users\":[{\"user_id\":\"8bb80df5-700c-48ce-b568-85a60fc3c8f2\",\"is_admin\":true},{\"id\":\"3b9b9757-1ccb-444a-a3cf-4090364fac4f\",\"is_admin\":false},{\"id\":\"1a2b3c4d-5e6f-7g8h-9i0j-k1l2m3n4o5p6\",\"delete\":true}]}'\n};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups/8fa37ef6-f167-4342-8e1c-3488439cf7d1.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"PUT\",\n CURLOPT_POSTFIELDS => json_encode([\n 'name' => 'WRC',\n 'groups_users' => [\n [\n 'user_id' => '8bb80df5-700c-48ce-b568-85a60fc3c8f2',\n 'is_admin' => true\n ],\n [\n 'id' => '3b9b9757-1ccb-444a-a3cf-4090364fac4f',\n 'is_admin' => false\n ],\n [\n 'id' => '1a2b3c4d-5e6f-7g8h-9i0j-k1l2m3n4o5p6',\n 'delete' => true\n ]\n ]\n ]),\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
parameters:
- $ref: '#/components/parameters/groupId'
responses:
'200':
$ref: '#/components/responses/addAndUpdate'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
requestBody:
$ref: '#/components/requestBodies/groupUpdate'
delete:
summary: Delete a group.
description: 'Only a group manager or a user with administrator role can delete a group. A group cannot be deleted as long as it is the sole owner of a shared resource or folder.
'
operationId: deleteGroup
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request DELETE \\\n --url {{API_BASE_URL}}/groups/164d51b8-d6ce-4d59-b8a0-43869919407e.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups/164d51b8-d6ce-4d59-b8a0-43869919407e.json';\nconst options = {method: 'DELETE', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups/164d51b8-d6ce-4d59-b8a0-43869919407e.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"DELETE\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
parameters:
- $ref: '#/components/parameters/groupId'
responses:
'200':
$ref: '#/components/responses/nullBody'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
/groups/{groupId}/dry-run.json:
put:
summary: Dry run a group update.
operationId: dryRunUpdateGroup
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request PUT \\\n--url {{API_BASE_URL}}/groups/8fa37ef6-f167-4342-8e1c-3488439cf7d1/dry-run.json \\\n--header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n--header 'Content-Type: application/json' \\\n--data '{\n \"name\": \"WRC\",\n \"groups_users\": [\n {\n \"user_id\": \"8bb80df5-700c-48ce-b568-85a60fc3c8f2\",\n \"is_admin\": true\n }\n ]\n}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups/8fa37ef6-f167-4342-8e1c-3488439cf7d1/dry-run.json';\nconst options = {\n method: 'PUT',\n headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n body: '{\"name\":\"WRC\",\"groups_users\":[{\"user_id\":\"8bb80df5-700c-48ce-b568-85a60fc3c8f2\",\"is_admin\":true}]}'\n};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups/8fa37ef6-f167-4342-8e1c-3488439cf7d1/dry-run.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"PUT\",\n CURLOPT_POSTFIELDS => json_encode([\n 'name' => 'WRC',\n 'groups_users' => [\n [\n 'user_id' => '8bb80df5-700c-48ce-b568-85a60fc3c8f2',\n 'is_admin' => true\n ]\n ]\n ]),\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
parameters:
- $ref: '#/components/parameters/groupId'
responses:
'200':
$ref: '#/components/responses/updateDryRunSuccess'
'400':
$ref: '#/components/responses/updateDryRunError'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
requestBody:
$ref: '#/components/requestBodies/groupUpdate'
delete:
summary: Dry run a group deletion.
operationId: dryRunDeleteGroup
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request DELETE \\\n --url {{API_BASE_URL}}/groups/164d51b8-d6ce-4d59-b8a0-43869919407e/dry-run.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/groups/164d51b8-d6ce-4d59-b8a0-43869919407e/dry-run.json';\nconst options = {method: 'DELETE', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/groups/164d51b8-d6ce-4d59-b8a0-43869919407e/dry-run.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"DELETE\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Groups
parameters:
- $ref: '#/components/parameters/groupId'
responses:
'200':
$ref: '#/components/responses/emptyArrayBody'
'400':
$ref: '#/components/responses/deleteDryRun'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
components:
schemas:
e2eeMetadataBasedId:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBased'
- type: object
required:
- id
properties:
id:
type: string
format: uuid
folderV5IndexAndView:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBasedCommon'
- type: object
properties:
children_resources:
type: array
items:
anyOf:
- $ref: '#/components/schemas/resourceV4IndexAndView'
- $ref: '#/components/schemas/resourceV5IndexAndView'
children_folders:
type: array
items:
anyOf:
- $ref: '#/components/schemas/folderV4IndexAndView'
- $ref: '#/components/schemas/folderV5IndexAndView'
resourceV5IndexAndView:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBasedCommon'
- type: object
required:
- resource_type_id
- expired
properties:
resource_type_id:
type: string
format: uuid
expired:
type: string
format: date-time
x-nullable: true
favorite:
$ref: '#/components/schemas/favorite'
secrets:
type: array
items:
type: string
resource_type:
$ref: '#/components/schemas/resourceType'
groupsUsersIndexAndView:
type: object
required:
- id
- group_id
- user_id
- is_admin
- created
properties:
id:
type: string
format: uuid
group_id:
type: string
format: uuid
user_id:
type: string
format: uuid
is_admin:
type: boolean
created:
type: string
format: date-time
user:
$ref: '#/components/schemas/userIndexAndView'
groupUpdateDryRun:
type: object
required:
- dry-run
properties:
dry-run:
type: object
required:
- SecretsNeeded
- Secrets
properties:
SecretsNeeded:
type: array
items:
type: object
required:
- Secret
properties:
Secret:
type: object
required:
- resource_id
- user_id
properties:
resource_id:
type: string
format: uuid
user_id:
type: string
format: uuid
Secrets:
type: array
items:
type: object
required:
- Secret
properties:
Secret:
type: object
required:
- id
- resource_id
- user_id
- data
properties:
id:
type: string
format: uuid
resource_id:
type: string
format: uuid
user_id:
type: string
format: uuid
data:
type: string
e2eeMetadataBased:
type: object
required:
- metadata
- metadata_key_id
- metadata_key_type
properties:
metadata:
type: string
metadata_key_id:
type: string
format: uuid
metadata_key_type:
type: string
enum:
- user_key
- shared_key
groupDeleteDryRunError:
type: object
properties:
resources:
type: object
properties:
sole_owner:
type: array
items:
anyOf:
- $ref: '#/components/schemas/resourceV4IndexAndView'
- $ref: '#/components/schemas/resourceV5IndexAndView'
folders:
type: object
properties:
sole_owner:
type: array
items:
anyOf:
- $ref: '#/components/schemas/folderV4IndexAndView'
- $ref: '#/components/schemas/folderV5IndexAndView'
groupAdd:
type: object
required:
- name
- groups_users
properties:
name:
type: string
groups_users:
type: array
items:
type: object
required:
- user_id
- is_admin
properties:
user_id:
type: string
format: uuid
is_admin:
type: boolean
secretIndex:
type: object
required:
- id
- user_id
- resource_id
- data
- created
- modified
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
resource_id:
type: string
format: uuid
data:
type: string
created:
type: string
format: date-time
modified:
type: string
format: date-time
userIndexAndView:
type: object
required:
- id
- role_id
- username
- active
- deleted
- created
- modified
- disabled
properties:
is_mfa_enabled:
type: boolean
id:
type: string
format: uuid
role_id:
type: string
format: uuid
username:
type: string
active:
type: boolean
deleted:
type: boolean
created:
type: string
format: date-time
modified:
type: string
format: date-time
disabled:
type: string
format: date-time
x-nullable: true
profile:
type: object
required:
- id
- user_id
- first_name
- last_name
- created
- modified
- avatar
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
first_name:
type: string
last_name:
type: string
created:
type: string
format: date-time
modified:
type: string
format: date-time
avatar:
type: object
required:
- url
properties:
id:
type: string
format: uuid
profile_id:
type: string
format: uuid
created:
type: string
format: date-time
modified:
type: string
format: date-time
url:
type: object
required:
- medium
- small
properties:
medium:
type: string
format: url
small:
type: string
format: url
groups_users:
$ref: '#/components/schemas/groupsUsersIndexAndView'
gpgkey:
$ref: '#/components/schemas/gpgkey'
x-nullable: true
role:
$ref: '#/components/schemas/role'
missing_metadata_key_ids:
type: array
items:
type: string
format: uuid
last_logged_in:
type: string
format: date-time
x-nullable: true
groupIndexAndView:
type: object
required:
- id
- name
- deleted
- created
- modified
- created_by
- modified_by
properties:
id:
type: string
format: uuid
name:
type: string
deleted:
type: boolean
created:
type: string
format: date-time
modified:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
my_group_user:
$ref: '#/components/schemas/groupsUsersIndexAndView'
groups_users:
type: array
items:
$ref: '#/components/schemas/groupsUsersIndexAndView'
user_count:
type: integer
e2eeMetadataBasedCommon:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBasedId'
- type: object
required:
- created
- modified
- created_by
- modified_by
- personal
- folder_parent_id
properties:
created:
type: string
format: date-time
modified:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
personal:
type: boolean
folder_parent_id:
type: string
format: uuid
x-nullable: true
modifier:
$ref: '#/components/schemas/userIndexAndView'
creator:
$ref: '#/components/schemas/userIndexAndView'
permission:
$ref: '#/components/schemas/permissionIndexAndView'
permissions:
type: array
items:
$ref: '#/components/schemas/permissionIndexAndView'
resourceV4IndexAndView:
type: object
required:
- id
- name
- username
- uri
- description
- deleted
- created
- created_by
- modified_by
- resource_type_id
- expired
- folder_parent_id
- personal
properties:
id:
type: string
format: uuid
name:
type: string
username:
type: string
uri:
type: string
description:
type: string
deleted:
type: boolean
created:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
resource_type_id:
type: string
format: uuid
expired:
type: string
format: date-time
x-nullable: true
folder_parent_id:
type: string
format: uuid
x-nullable: true
personal:
type: boolean
favorite:
$ref: '#/components/schemas/favorite'
modifier:
$ref: '#/components/schemas/userIndexAndView'
creator:
$ref: '#/components/schemas/userIndexAndView'
secrets:
type: array
items:
$ref: '#/components/schemas/secretIndex'
resource_type:
$ref: '#/components/schemas/resourceType'
permission:
$ref: '#/components/schemas/permissionIndexAndView'
permissions:
type: array
items:
$ref: '#/components/schemas/permissionIndexAndView'
gpgkey:
type: object
required:
- id
- user_id
- armored_key
- bits
- uid
- key_id
- fingerprint
- type
- expires
- key_created
- deleted
- created
- modified
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
armored_key:
type: string
bits:
type: integer
uid:
type: string
key_id:
type: string
fingerprint:
type: string
type:
type: string
enum:
- RSA
- ECC
expires:
type: string
format: date-time
x-nullable: true
deleted:
type: boolean
created:
type: string
format: date-time
modified:
type: string
format: date-time
permissionIndexAndView:
type: object
required:
- id
- aco
- aco_foreign_key
- aro
- aro_foreign_key
- type
- created
- modified
properties:
id:
type: string
format: uuid
aco:
type: string
enum:
- Resource
- Folder
aco_foreign_key:
type: string
format: uuid
aro:
type: string
enum:
- User
- Group
aro_foreign_key:
type: string
format: uuid
type:
$ref: '#/components/schemas/permissionLevel'
created:
type: string
format: date-time
modified:
type: string
format: date-time
user:
$ref: '#/components/schemas/userIndexAndView'
x-nullable: true
group:
$ref: '#/components/schemas/groupIndexAndView'
x-nullable: true
permissionLevel:
description: '* `1` - Read
* `7` - Update
* `15` - Owner
'
type: integer
enum:
- 1
- 7
- 15
groupUpdate:
type: object
required:
- name
- groups_users
properties:
name:
type: string
groups_users:
type: array
items:
type: object
properties:
id:
type: string
format: uuid
description: GroupUser relationship ID (required for updating existing users or marking for deletion)
user_id:
type: string
format: uuid
description: User ID (required for adding new users to the group)
is_admin:
type: boolean
description: Whether the user is a group administrator
delete:
type: boolean
description: Whether to remove the user from the group
secrets:
type: array
items:
type: object
required:
- resource_id
- user_id
- data
properties:
resource_id:
type: string
format: uuid
user_id:
type: string
format: uuid
data:
type: string
resourceType:
type: object
required:
- id
- slug
- name
- description
- definition
- deleted
- created
- modified
properties:
id:
type: string
format: uuid
slug:
type: string
description: '* `password-string` - The original passbolt resource type, where the secret is a non empty string.
* `password-and-description` - A resource with the password and the description encrypted.
* `totp` - A resource with standalone TOTP fields.
* `password-description-totp` - A resource with encrypted password, description and TOTP fields.
* `v5-default-with-totp` - The new default resource type with a TOTP introduced with v5.
* `v5-password-string (Deprecated)` - The original passbolt resource type, kept for backward compatibility reasons.
* `v5-totp-standalone` - The new standalone TOTP resource type introduced with v5.
* `v5-default` - The new default resource type introduced with v5.
'
enum:
- password-string
- password-and-description
- totp
- password-description-totp
# --- truncated at 32 KB (56 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/passbolt/refs/heads/main/openapi/passbolt-groups-api-openapi.yml