Passbolt Users API
User are entities with the ability to interact with the application.
User are entities with the ability to interact with the application.
openapi: 3.1.0
info:
contact:
email: contact@passbolt.com
description: This is a low-level overview of the API and its endpoints, if you need higher-level guides for interacting with the endpoints, use the Developer guide.
license:
name: AGPL-3.0
url: https://www.gnu.org/licenses/agpl-3.0.html
termsOfService: https://www.passbolt.com/terms
title: Passbolt Authentication (GPGAuth) Authentication (GPGAuth) Users API
version: 5.0.0
servers:
- url: https://passbolt.local
description: API Passbolt
tags:
- name: Users
description: 'User are entities with the ability to interact with the application.
'
paths:
/users.json:
get:
summary: Get multiple users.
operationId: indexUsers
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request GET \\\n --url {{API_BASE_URL}}/users.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/users.json';\nconst options = {method: 'GET', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/users.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Users
parameters:
- $ref: '#/components/parameters/containLastLoggedIn'
- $ref: '#/components/parameters/containGroupsUsers'
- $ref: '#/components/parameters/containGpgkey'
- $ref: '#/components/parameters/containProfile'
- $ref: '#/components/parameters/containRole'
- $ref: '#/components/parameters/containMissingMetadataKeyIds'
- $ref: '#/components/parameters/filterSearch'
- $ref: '#/components/parameters/filterHasGroups'
- $ref: '#/components/parameters/filterHasAccess'
- $ref: '#/components/parameters/filterIsAdmin'
- $ref: '#/components/parameters/filterIsActive'
responses:
'200':
$ref: '#/components/responses/users_index'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
'403':
$ref: '#/components/responses/accessRestrictedToAdministrators'
post:
summary: Create a user.
operationId: addUser
description: 'Only users with `admin` role can create other users.
'
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request POST \\\n --url {{API_BASE_URL}}/users.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n --header 'Content-Type: application/json' \\\n --data '{\n \"username\": \"ada@passbolt.com\",\n \"profile\": {\n \"first_name\": \"Ada\",\n \"last_name\": \"Lovelace\"\n }\n }'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/users.json';\nconst options = {\n method: 'POST',\n headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n body: '{\"username\":\"ada@passbolt.com\",\"profile\":{\"first_name\":\"Ada\",\"last_name\":\"Lovelace\"}}'\n};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/users.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"POST\",\n CURLOPT_POSTFIELDS => json_encode([\n 'username' => 'ada@passbolt.com',\n 'profile' => [\n 'first_name' => 'Ada',\n 'last_name' => 'Lovelace'\n ]\n ]),\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Users
requestBody:
$ref: '#/components/requestBodies/userAdd'
responses:
'200':
$ref: '#/components/responses/users_add'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
/users/{userId}.json:
get:
summary: Get a user.
operationId: viewUser
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request GET \\\n --url {{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json';\nconst options = {method: 'GET', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Users
parameters:
- $ref: '#/components/parameters/userId'
- $ref: '#/components/parameters/containMissingMetadataKeyIds'
responses:
'200':
$ref: '#/components/responses/users_view'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
'403':
$ref: '#/components/responses/accessRestrictedToAdministrators'
'404':
$ref: '#/components/responses/notFound'
put:
summary: Update a user.
operationId: updateUser
description: 'Neither the email or the username field which can be updated, and only administrators can update a user''s role.
'
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request PUT \\\n --url {{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}' \\\n --header 'Content-Type: application/json' \\\n --data '{\n \"profile\": {\n \"first_name\": \"Freddy\",\n \"last_name\": \"Mercury\"\n }\n }'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json';\nconst options = {\n method: 'PUT',\n headers: {Authorization: 'Bearer {{JWT_TOKEN}}'},\n body: '{\"profile\":{\"first_name\":\"Freddy\",\"last_name\":\"Mercury\"}}'\n};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"PUT\",\n CURLOPT_POSTFIELDS => json_encode([\n 'profile' => [\n 'first_name' => 'Freddy',\n 'last_name' => 'Mercury'\n ]\n ]),\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Users
parameters:
- $ref: '#/components/parameters/userId'
responses:
'200':
$ref: '#/components/responses/users_update'
'400':
$ref: '#/components/responses/badRequest'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
requestBody:
$ref: '#/components/requestBodies/userUpdate'
delete:
summary: Delete a user.
operationId: deleteUser
description: 'Only a user with an administrator role can delete users. A `user` can not be deleted as long as:
- They are the sole owner of a shared resource.
- They are a manager of a non empty group.
In this case you will need to transfer the ownership of the shared resources and appoint a new manager to the group in order to proceed.
'
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request DELETE \\\n --url {{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json';\nconst options = {method: 'DELETE', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"DELETE\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Users
parameters:
- $ref: '#/components/parameters/userId'
responses:
'200':
$ref: '#/components/responses/nullBody'
'400':
$ref: '#/components/responses/delete'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
/users/{userId}/dry-run.json:
delete:
summary: Dry run a user deletion.
operationId: dryRunDeleteUser
security:
- bearerHttpAuthentication: []
x-codeSamples:
- lang: cURL
source: "curl --request DELETE \\\n --url {{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831/dry-run.json \\\n --header 'Authorization: Bearer {{JWT_TOKEN}}'\n"
- lang: JavaScript
source: "const url = '{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831/dry-run.json';\nconst options = {method: 'DELETE', headers: {Authorization: 'Bearer {{JWT_TOKEN}}'}};\n\ntry {\n const response = await fetch(url, options);\n const data = await response.json();\n console.log(data);\n} catch (error) {\n console.error(error);\n}\n"
- lang: PHP
source: "<?php\n$curl = curl_init();\n\ncurl_setopt_array($curl, [\n CURLOPT_URL => \"{{API_BASE_URL}}/users/8c640fd5-268c-4ae0-9e35-2f120cf1a831/dry-run.json\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"DELETE\",\n CURLOPT_HTTPHEADER => [\n \"Authorization: Bearer {{JWT_TOKEN}}\"\n ],\n]);\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}\n"
tags:
- Users
parameters:
- $ref: '#/components/parameters/userId'
responses:
'200':
$ref: '#/components/responses/nullBody'
'400':
$ref: '#/components/responses/users_deleteDryRun'
'401':
$ref: '#/components/responses/authenticationRequired'
'404':
$ref: '#/components/responses/notFound'
components:
schemas:
e2eeMetadataBasedId:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBased'
- type: object
required:
- id
properties:
id:
type: string
format: uuid
folderV5IndexAndView:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBasedCommon'
- type: object
properties:
children_resources:
type: array
items:
anyOf:
- $ref: '#/components/schemas/resourceV4IndexAndView'
- $ref: '#/components/schemas/resourceV5IndexAndView'
children_folders:
type: array
items:
anyOf:
- $ref: '#/components/schemas/folderV4IndexAndView'
- $ref: '#/components/schemas/folderV5IndexAndView'
resourceV5IndexAndView:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBasedCommon'
- type: object
required:
- resource_type_id
- expired
properties:
resource_type_id:
type: string
format: uuid
expired:
type: string
format: date-time
x-nullable: true
favorite:
$ref: '#/components/schemas/favorite'
secrets:
type: array
items:
type: string
resource_type:
$ref: '#/components/schemas/resourceType'
groupsUsersIndexAndView:
type: object
required:
- id
- group_id
- user_id
- is_admin
- created
properties:
id:
type: string
format: uuid
group_id:
type: string
format: uuid
user_id:
type: string
format: uuid
is_admin:
type: boolean
created:
type: string
format: date-time
user:
$ref: '#/components/schemas/userIndexAndView'
userDelete:
type: object
properties:
errors:
type: object
properties:
resources:
type: object
properties:
sole_owner:
type: array
items:
anyOf:
- $ref: '#/components/schemas/resourceV4IndexAndView'
- $ref: '#/components/schemas/resourceV5IndexAndView'
userDeleteDryRun:
type: object
properties:
errors:
type: object
properties:
groups:
type: object
properties:
sole_manager:
type: array
items:
$ref: '#/components/schemas/groupIndexAndView'
folders:
type: object
properties:
sole_owner:
type: array
items:
$ref: '#/components/schemas/folderV5IndexAndView'
resources:
type: object
properties:
sole_owner:
type: array
items:
anyOf:
- $ref: '#/components/schemas/resourceV4IndexAndView'
- $ref: '#/components/schemas/resourceV5IndexAndView'
groups_to_delete:
type: array
items:
$ref: '#/components/schemas/groupIndexAndView'
e2eeMetadataBased:
type: object
required:
- metadata
- metadata_key_id
- metadata_key_type
properties:
metadata:
type: string
metadata_key_id:
type: string
format: uuid
metadata_key_type:
type: string
enum:
- user_key
- shared_key
folderV4IndexAndView:
type: object
required:
- id
- name
- created
- modified
- created_by
- modified_by
- folder_parent_id
- personal
properties:
id:
type: string
format: uuid
name:
type: string
created:
type: string
format: date-time
modified:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
folder_parent_id:
type: string
format: uuid
x-nullable: true
personal:
type: boolean
modifier:
$ref: '#/components/schemas/userIndexAndView'
creator:
$ref: '#/components/schemas/userIndexAndView'
permission:
$ref: '#/components/schemas/permissionIndexAndView'
permissions:
type: array
items:
$ref: '#/components/schemas/permissionIndexAndView'
children_resources:
type: array
items:
anyOf:
- $ref: '#/components/schemas/resourceV4IndexAndView'
- $ref: '#/components/schemas/resourceV5IndexAndView'
children_folders:
type: array
items:
anyOf:
- $ref: '#/components/schemas/folderV4IndexAndView'
- $ref: '#/components/schemas/folderV5IndexAndView'
secretIndex:
type: object
required:
- id
- user_id
- resource_id
- data
- created
- modified
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
resource_id:
type: string
format: uuid
data:
type: string
created:
type: string
format: date-time
modified:
type: string
format: date-time
userIndexAndView:
type: object
required:
- id
- role_id
- username
- active
- deleted
- created
- modified
- disabled
properties:
is_mfa_enabled:
type: boolean
id:
type: string
format: uuid
role_id:
type: string
format: uuid
username:
type: string
active:
type: boolean
deleted:
type: boolean
created:
type: string
format: date-time
modified:
type: string
format: date-time
disabled:
type: string
format: date-time
x-nullable: true
profile:
type: object
required:
- id
- user_id
- first_name
- last_name
- created
- modified
- avatar
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
first_name:
type: string
last_name:
type: string
created:
type: string
format: date-time
modified:
type: string
format: date-time
avatar:
type: object
required:
- url
properties:
id:
type: string
format: uuid
profile_id:
type: string
format: uuid
created:
type: string
format: date-time
modified:
type: string
format: date-time
url:
type: object
required:
- medium
- small
properties:
medium:
type: string
format: url
small:
type: string
format: url
groups_users:
$ref: '#/components/schemas/groupsUsersIndexAndView'
gpgkey:
$ref: '#/components/schemas/gpgkey'
x-nullable: true
role:
$ref: '#/components/schemas/role'
missing_metadata_key_ids:
type: array
items:
type: string
format: uuid
last_logged_in:
type: string
format: date-time
x-nullable: true
userAdd:
type: object
required:
- username
- profile
properties:
username:
type: string
format: email
role_id:
type: string
format: uuid
profile:
type: object
required:
- first_name
- last_name
properties:
first_name:
type: string
last_name:
type: string
groupIndexAndView:
type: object
required:
- id
- name
- deleted
- created
- modified
- created_by
- modified_by
properties:
id:
type: string
format: uuid
name:
type: string
deleted:
type: boolean
created:
type: string
format: date-time
modified:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
my_group_user:
$ref: '#/components/schemas/groupsUsersIndexAndView'
groups_users:
type: array
items:
$ref: '#/components/schemas/groupsUsersIndexAndView'
user_count:
type: integer
e2eeMetadataBasedCommon:
allOf:
- $ref: '#/components/schemas/e2eeMetadataBasedId'
- type: object
required:
- created
- modified
- created_by
- modified_by
- personal
- folder_parent_id
properties:
created:
type: string
format: date-time
modified:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
personal:
type: boolean
folder_parent_id:
type: string
format: uuid
x-nullable: true
modifier:
$ref: '#/components/schemas/userIndexAndView'
creator:
$ref: '#/components/schemas/userIndexAndView'
permission:
$ref: '#/components/schemas/permissionIndexAndView'
permissions:
type: array
items:
$ref: '#/components/schemas/permissionIndexAndView'
userUpdate:
type: object
properties:
role_id:
type: string
format: uuid
disabled:
type: boolean
profile:
type: object
properties:
first_name:
type: string
last_name:
type: string
avatar:
type: object
required:
- file
properties:
file:
type: string
description: Image file in binary format.
headerWithPagination:
type: object
required:
- id
- status
- servertime
- action
- message
- url
- code
- pagination
properties:
id:
type: string
format: uuid
status:
type: string
enum:
- success
- error
servertime:
type: integer
example: 1720702619
action:
type: string
format: uuid
message:
type: string
example: The operation was successful.
url:
type: string
format: uri
example: /auth/verify.json
code:
type: integer
example: 200
pagination:
type: object
required:
- count
- page
- limit
properties:
count:
type: integer
page:
type: integer
limit:
type: integer
x-nullable: true
resourceV4IndexAndView:
type: object
required:
- id
- name
- username
- uri
- description
- deleted
- created
- created_by
- modified_by
- resource_type_id
- expired
- folder_parent_id
- personal
properties:
id:
type: string
format: uuid
name:
type: string
username:
type: string
uri:
type: string
description:
type: string
deleted:
type: boolean
created:
type: string
format: date-time
created_by:
type: string
format: uuid
modified_by:
type: string
format: uuid
resource_type_id:
type: string
format: uuid
expired:
type: string
format: date-time
x-nullable: true
folder_parent_id:
type: string
format: uuid
x-nullable: true
personal:
type: boolean
favorite:
$ref: '#/components/schemas/favorite'
modifier:
$ref: '#/components/schemas/userIndexAndView'
creator:
$ref: '#/components/schemas/userIndexAndView'
secrets:
type: array
items:
$ref: '#/components/schemas/secretIndex'
resource_type:
$ref: '#/components/schemas/resourceType'
permission:
$ref: '#/components/schemas/permissionIndexAndView'
permissions:
type: array
items:
$ref: '#/components/schemas/permissionIndexAndView'
gpgkey:
type: object
required:
- id
- user_id
- armored_key
- bits
- uid
- key_id
- fingerprint
- type
- expires
- key_created
- deleted
- created
- modified
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
armored_key:
type: string
bits:
type: integer
uid:
type: string
key_id:
type: string
fingerprint:
type: string
type:
type: string
enum:
- RSA
- ECC
expires:
type: string
format: date-time
x-nullable: true
deleted:
type: boolean
created:
type: string
format: date-time
modified:
type: string
format: date-time
permissionIndexAndView:
type: object
required:
- id
- aco
- aco_foreign_key
- aro
- aro_foreign_key
- type
- created
- modified
properties:
id:
type: string
format: uuid
aco:
type: string
enum:
- Resource
- Folder
aco_foreign_key:
type: string
format: uuid
aro:
type: string
enum:
- User
- Group
aro_foreign_key:
type: string
format: uuid
type:
$ref: '#/components/schemas/permissionLevel'
created:
type: string
format: date-time
modified:
type: string
format: date-time
user:
$ref: '#/components/schemas/userIndexAndView'
x-nullable: true
group:
$ref: '#/components/schemas/groupIndexAndView'
x-nullable: true
permissionLevel:
description: '* `1` - Read
* `7` - Update
* `15` - Owner
'
type: integer
enum:
- 1
- 7
- 15
resourceType:
type: object
required:
- id
- slug
- name
- description
- definition
- deleted
- created
- modified
properties:
id:
type: string
format: uuid
slug:
type: string
description: '* `password-string` - The original passbolt resource type, where the secret is a non empty string.
* `password-and-description` - A resource with the password and the description encrypted.
* `totp` - A resource with standalone TOTP fields.
* `password-description-totp` - A resource with encrypted password, description and TOTP fields.
* `v5-default-with-totp` - The new default resource type with a TOTP introduced with v5.
* `v5-password-string (Deprecated)` - The original passbolt resource type, kept for backward compatibility reasons.
* `v5-totp-standalone` - The new standalone TOTP resource type introduced with v5.
* `v5-default` - The new default resource type introduced with v5.
'
enum:
- password-string
- password-and-description
- totp
- password-description-totp
- v5-default-with-totp
- v5-password-string (Deprecated)
- v5-totp-standalone
- v5-default
name:
type: string
description:
type: string
definition:
type: object
description: Schema for the expected data for this kind of resources.
deleted:
type: string
x-nullable: true
created:
type: string
format: date-time
modified:
type: string
format: date-time
role:
type: object
required:
- id
- name
- description
- created
- modified
properties:
id:
type: string
format: uuid
name:
type: string
enum:
- admin
- guest
- user
description:
type: string
created:
type: string
format: date-time
modified:
type: string
format: date-time
favorite:
type: object
required:
- id
- user_id
- foreign_key
- foreign_model
- created
- modified
properties:
id:
type: string
format: uuid
user_id:
type: string
format: uuid
foreign_key:
type: string
format: uuid
foreign_model:
type: string
enum:
- Resource
created:
type: string
format: date-time
modified:
type: string
format: date-time
header:
type: object
required:
- id
- status
- servertime
- action
- message
- url
- code
properties:
id:
type: string
format: uuid
status:
type: string
enum:
- success
- error
servertime:
type: integer
example: 1720702619
ac
# --- truncated at 32 KB (60 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/passbolt/refs/heads/main/openapi/passbolt-users-api-openapi.yml