publiq Permissions API

The Permissions API from publiq — 2 operation(s) for permissions.

Operations 3

GET /permissions Get permissions #
GET /permissions/{clientId} Get permissions for a client #
PUT /permissions/{clientId} Update permissions for a client #

Documentation

Specifications

Schemas & Data

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/publiq:publiq-permissions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

publiq-permissions-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Publiq Permissions API
  version: '4.0'
  contact:
    name: publiq helpdesk
    email: technical-support@publiq.be
    url: https://docs.publiq.be
  x-refined-note:
  - x-source differs across the merged source definitions and was not carried
  description: 'Operations tagged Permissions across 2 of this provider''s published API definitions: uitpas-uitpas.json, publiq-uitpas-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api-test.uitpas.be
  description: Testing
- url: https://api.uitpas.be
  description: Production
tags:
- name: Permissions
paths:
  /permissions:
    parameters: []
    get:
      summary: Get permissions
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/OrganizerPermissions'
              examples:
                Example with multiple organizers:
                  value:
                  - organizer:
                      id: c097fa2e-d9be-42e6-b41a-ec3d4d4cbad1
                      name: CC De Werf
                      address:
                        postalCode: '9300'
                        city: Aalst
                      linkedLocationId: db18c985-c6a3-4454-9875-b28f74a9b823
                    permissions:
                    - TARIFFS_READ
                    - TICKETSALES_SEARCH
                    permissionDetails:
                    - id: TARIFFS_READ
                      label:
                        nl: Tarieven opvragen
                      cardSystemIds:
                      - 1
                    - id: TICKETSALES_SEARCH
                      label:
                        nl: Ticketsales zoeken
                      cardSystemIds:
                      - 1
                    linkedOrganizers:
                    - organizer:
                        id: 347e6177-4add-4fa8-a7fe-6e60127bfb12
                        name: Sportdienst
                        address:
                          postalCode: '9300'
                          city: Aalst
                        linkedLocationId: db18c985-c6a3-4454-9875-b28f74a9b823
                      permissionDetails:
                      - id: CHECKINS_WRITE
                        label:
                          nl: Punten sparen
                        cardSystemIds:
                        - 1
                  - organizer:
                      id: fd7e6177-4add-4fa8-a7fe-6e60127bfb35
                      name: CC De Schakel
                      address:
                        postalCode: '9300'
                        city: Aalst
                      linkedLocationId: fb18c985-c6a3-4454-9875-b28f74a9b809
                    permissions:
                    - ORGANIZERS_SEARCH
                    permissionDetails:
                    - id: ORGANIZERS_SEARCH
                      label:
                        nl: Organisators zoeken
                      cardSystemIds:
                      - 1
                Example with one organizer:
                  value:
                  - organizer:
                      id: c097fa2e-d9be-42e6-b41a-ec3d4d4cbad1
                      name: CC De Werf
                      address:
                        postalCode: '9300'
                        city: Aalst
                      linkedLocationId: fb18c985-c6a3-4454-9875-b28f74a9b809
                    permissions:
                    - TARIFFS_READ
                    - TICKETSALES_SEARCH
                    permissionDetails:
                    - id: TARIFFS_READ
                      label:
                        nl: Tarieven opvragen
                      cardSystemIds:
                      - 1
                    - id: TICKETSALES_SEARCH
                      label:
                        nl: Ticketsales zoeken
                      cardSystemIds:
                      - 1
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      operationId: get-permissions
      description: 'Lists the organizers that the current user or client (depending on the token) has access to including a list of its permissions.


        The OrganizerPermission response object can also contain `linkedOrganizers` for which admins of this organizer also have access to.


        Use this endpoint if you obtained a user or client access token and need to know its organizer permissions. Use GET /permissions/clientID to manage permissions for any client.'
      security:
      - USER_ACCESS_TOKEN: []
      - CLIENT_ACCESS_TOKEN: []
      tags:
      - Permissions
    servers:
    - url: https://api-test.uitpas.be
      description: Testing
    - url: https://api.uitpas.be
      description: Production
  /permissions/{clientId}:
    parameters:
    - schema:
        type: string
      name: clientId
      in: path
      required: true
      description: ID of the client
    get:
      summary: Get permissions for a client
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/OrganizerPermissions'
              examples:
                Example:
                  value:
                  - organizer:
                      id: c097fa2e-d9be-42e6-b41a-ec3d4d4cbad1
                      name: CC De Werf
                      address:
                        postalCode: '9300'
                        city: Aalst
                      linkedLocationId: fb18c985-c6a3-4454-9875-b28f74a9b809
                    permissionDetails:
                    - id: TARIFFS_READ
                      label:
                        nl: Tarieven opvragen
                      cardSystemIds:
                      - 1
                    - id: TICKETSALES_SEARCH
                      label:
                        nl: Ticketsales zoeken
                      cardSystemIds:
                      - 1
                  - organizer:
                      id: fd7e6177-4add-4fa8-a7fe-6e60127bfb35
                      name: CC De Schakel
                      address:
                        postalCode: '9300'
                        city: Aalst
                      linkedLocationId: fb18c985-c6a3-4454-9875-b28f74a9b809
                    permissionDetails:
                    - id: ORGANIZERS_SEARCH
                      label:
                        nl: Organisators zoeken
                      cardSystemIds:
                      - 1
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: 'Not found. Possible error types:


            * https://api.publiq.be/probs/uitpas/client-not-found


            The detail property might include more information for the client developer.'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Error'
      operationId: get-permissions-clientId
      description: 'Lists the organizer permissions of the given client ID.


        Use this endpoint to manage permissions for any client. Use GET /permissions to retrieve permissions for your token (current client or user).


        The caller of this request must have `PERMISSIONS_READ` permission.'
      security:
      - CLIENT_ACCESS_TOKEN: []
      tags:
      - Permissions
    put:
      summary: Update permissions for a client
      operationId: put-permissions-clientId
      responses:
        '204':
          description: Permissions Updated. No Content
        '400':
          description: 'Bad Request. Possible error types:


            * https://api.publiq.be/probs/body/missing

            * https://api.publiq.be/probs/body/invalid-syntax

            * https://api.publiq.be/probs/body/invalid-data'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: 'Not found. Possible error types:


            * https://api.publiq.be/probs/uitpas/client-not-found


            The detail property might include more information for the client developer.'
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Error'
      description: 'Update the organizer permissions of the given client ID.


        The caller of this request must have `PERMISSIONS_WRITE` permission.'
      security:
      - CLIENT_ACCESS_TOKEN: []
      requestBody:
        content:
          application/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/OrganizerPermissions'
            examples:
              Example:
                value:
                - organizer:
                    id: c097fa2e-d9be-42e6-b41a-ec3d4d4cbad1
                  permissionDetails:
                  - id: TARIFFS_READ
                  - id: TICKETSALES_SEARCH
                - organizer:
                    id: fd7e6177-4add-4fa8-a7fe-6e60127bfb35
                  permissionDetails:
                  - id: ORGANIZERS_SEARCH
        description: Full set of organizer permissions for the client
      tags:
      - Permissions
    servers:
    - url: https://api-test.uitpas.be
      description: Testing
    - url: https://api.uitpas.be
      description: Production
components:
  responses:
    Unauthorized:
      description: 'Unauthorized. Your request is missing the required credentials to authenticate. See the Authentication documentation for more info.


        * type: https://api.publiq.be/probs/auth/unauthorized

        * detail: might contain a developer-readable explanation of the reason'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
          x-examples:
            Unauthorized:
              value:
                type: https://api.publiq.be/probs/auth/unauthorized
                title: Unauthorized
                status: 401
    Forbidden:
      description: 'Forbidden. Your request was successfully authenticated but you do not have permission to perform this particular request.


        * type: https://api.publiq.be/probs/auth/forbidden

        * detail: might contain a developer-readable explanation of the reason'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Error'
          x-examples:
            Forbidden:
              value:
                type: https://api.publiq.be/probs/auth/forbidden
                title: Forbidden
                status: 403
                detail: user must be admin of organiser abcd1234
  schemas:
    PermissionDetail:
      type: object
      title: PermissionDetail
      description: Permission details
      properties:
        id:
          $ref: '#/components/schemas/Permission'
        label:
          type: object
          description: Human-readable label of the permission
          properties:
            nl:
              type: string
              description: Human-readable label of the permission in Dutch
            en:
              type: string
              description: Human-readable label of the permission in English
          required:
          - nl
        cardSystemIds:
          type: array
          description: IDs of the card systems to which this permission applies
          items:
            type: integer
            readOnly: true
      required:
      - id
    Error:
      $ref: https://raw.githubusercontent.com/cultuurnet/apidocs/main/projects/errors/models/Error.json
    City:
      title: City
      type: object
      x-tags:
      - Models
      example:
        postalCode: '9300'
        name: Aalst
      properties:
        postalCode:
          type: string
          description: Postalcode of the city
        name:
          type: string
          description: Name of the city
      required:
      - postalCode
      - name
    Permission:
      title: Permission
      type: string
      x-tags:
      - Models
      enum:
      - TARIFFS_READ
      - TICKETSALES_SEARCH
      - TICKETSALES_REGISTER
      - EVENTS_UPDATE
      - EVENTS_READ
      - EVENT_SETTINGS_READ
      - EVENT_SETTINGS_UPDATE
      - EVENTS_UPDATE_ALL
      - EVENTS_READ_ALL
      - EVENT_SETTINGS_READ_ALL
      - EVENT_SETTINGS_UPDATE_ALL
      - EVENTS_QR_CHECKINCODE
      - CHECKINS_READ
      - CHECKINS_WRITE
      - ORGANIZERS_SEARCH
      - ORGANIZERS_REPORTS
      - ORGANIZERS_ADMINS_READ
      - ORGANIZERS_ADMINS_WRITE
      - PASSHOLDERS_PICTURE_READ
      - PASSHOLDERS_PICTURE_WRITE
      - PASSHOLDERS_PRIVATE_READ
      - PASSHOLDERS_PRIVATE_WRITE
      - PASSHOLDERS_SEARCH
      - PASSHOLDERS_SEARCH_ALL
      - PASSHOLDERS_SEARCH_BY_ID
      - GROUPPASSES_SEARCH
      - PASSHOLDERS_WRITE
      - PASSHOLDERS_WRITE_SOCIALTARIFF_FULL_CARDSYSTEM
      - PASSHOLDERS_WRITE_FOREIGN_COUNTRY
      - PASSHOLDERS_WRITE_SOCIALTARIFF
      - PASSHOLDERS_UPDATE
      - PASSHOLDERS_DELETE
      - PASSHOLDER_COUPONS_READ
      - GROUPPASS_COUPONS_READ
      - MEMBERSHIP_PRICES_READ
      - PASSES_READ
      - PASSES_INSZNUMBERS_READ
      - PASSES_CHIPNUMBERS_READ
      - REWARDS_WRITE
      - REWARDS_READ
      - REWARDS_REDEEM
      - REWARDS_PASSHOLDERS_READ
      - PASSHOLDERS_SELF_REGISTRATION
      - PASSHOLDERS_SELF_CHECKIN
      - PASSHOLDERS_SELF_READ
      - PASSHOLDERS_REGISTER_UITID
      - PASSHOLDERS_TRANSACTION_HISTORY
      - PASSHOLDERS_FAMILY_MEMBERS
      - ORDERS_READ
      - ORDERS_CREATE
      - PERMISSIONS_READ
      - PERMISSIONS_WRITE
      - CARDS_READ
      - ASSOCIATIONS
      - SOCIALTARIFF_EXPORT
      - KIOSKS_READ
      - KIOSKS_WRITE
      description: ID of the permission
    OrganizerPermissions:
      title: OrganizerPermissions
      type: object
      x-tags:
      - Models
      description: Combination of organizer and its permissions
      properties:
        organizer:
          $ref: '#/components/schemas/Organizer'
        permissions:
          type: array
          description: Permissions of the calling client for this organizer. This field is deprecated. Please use `permissionDetails`, which includes a user-readable label, instead.
          deprecated: true
          items:
            $ref: '#/components/schemas/Permission'
        permissionDetails:
          description: Permissions of the calling client for this organizer.
          type: array
          items:
            $ref: '#/components/schemas/PermissionDetail'
        linkedOrganizers:
          type: array
          description: Organizers linked to this organizer.
          items:
            $ref: '#/components/schemas/LinkedOrganizerPermissions'
      required:
      - organizer
    Organizer:
      title: Organizer
      type: object
      description: An organisation that partners with UiTPAS to provide discounts and/or rewards, and/or allows points to be collected at their events.
      x-tags:
      - Models
      properties:
        id:
          type: string
          description: Unique ID of an UiTPAS organizer. (Same as its ID in UiTdatabank)
        name:
          type: string
          description: Human-readable name of an UiTPAS organizer.
        cardSystems:
          type: array
          description: Card systems linked to this organizer
          items:
            $ref: '#/components/schemas/CardSystem'
        linkedLocationId:
          type: string
          description: ID of the location linked to this organizer.
          readOnly: true
        address:
          type: object
          description: Address of this organizer. This property is alway available in responses.
          required:
          - city
          properties:
            street:
              type: string
              description: Street address of this organizer
            postalCode:
              type: string
              description: Postal code of this organizer
            city:
              type: string
              description: City of this organizer
          readOnly: true
      required:
      - id
    CardSystem:
      title: CardSystem
      description: A region, usually one or multiple municipalities in Belgium, that uses UiTPAS and provides discounts and/or rewards. For example "Paspartoe" (Brussels), UiTPAS Leuven, UiTPAS Hasselt, UiTPAS Gent, and so on.
      type: object
      x-tags:
      - Models
      example:
        id: 1
        name: UiTPAS Dender
        branding:
          logo: https://www.uitpas.be/_nuxt/img/1351557.svg
          primaryColor: rgba(0,0,0,1.0)
          secondaryColor: rgba(97,166,14,1.0)
        links:
          website: https://www.uitpas.be
        cities:
        - postalCode: '9300'
          name: Aalst
        - postalCode: '9400'
          name: Ninove
        permanent: true
      properties:
        id:
          type: integer
          description: ID of the card system
        name:
          type: string
          description: Name of the card system. This field is always available in responses.
        branding:
          type: object
          description: Branding information of the card system
          properties:
            logo:
              type: string
              description: URL to the logo of the card system
            primaryColor:
              type: string
              description: Color code of the primary branding color.
            secondaryColor:
              type: string
              description: Color code of the secondary branding color.
        links:
          type: object
          description: Links of the card system
          properties:
            website:
              type: string
              description: URL of the website of the card system
        cities:
          type: array
          description: List of cities that are part of this card system
          items:
            $ref: '#/components/schemas/City'
        permanent:
          type: boolean
          description: Indicates whether this is a permanent card system
        allowsCardlessRegistration:
          type: boolean
          description: Indicates if cardless registration is enabled
        cardlessRegistrationType:
          type: string
          description: Indicates the types of online cardless registrations this cardsystem supports.
          enum:
          - ALL
          - REGULAR
          - SOCIALTARIFF
          - NONE
        socialTariffInfo:
          type: string
          description: Optional information about social tariff entitlement in this card system.
      required:
      - id
    LinkedOrganizerPermissions:
      title: LinkedOrganizerPermissions
      type: object
      x-tags:
      - Models
      properties:
        organizer:
          $ref: '#/components/schemas/Organizer'
        permissionDetails:
          description: Permissions of the calling client for this organizer.
          type: array
          items:
            $ref: '#/components/schemas/PermissionDetail'
      required:
      - organizer
      description: Combination of organizer and its permissions, specifically targetted to be used when linked to another organizer.
    Error_2:
      title: Error
      type: object
      description: RFC7807 error model for all publiq APIs.
      properties:
        type:
          type: string
          description: A URI reference that identifies the problem type. Can be used to recognize specific errors in your application code by comparing the complete URI.
        title:
          type: string
          description: A short, human-readable summary of the problem type (for developers).
        status:
          type: integer
          description: The HTTP status code.
        detail:
          type: string
          description: 'A human-readable explanation specific to this occurrence of the problem (for developers). '
        endUserMessage:
          type: object
          description: A human-readable explanation of the problem, specifically for end-users, in one or more languages. Typically available for domain errors, but not for errors caused by a technical issue in the integration (for example invalid JSON syntax in a request body). An `nl` value is always provided, other languages may be provided depending on the API and its intended audience. When this property is included, it is strongly encouraged to show this to the end-user.
          properties:
            nl:
              type: string
              description: A human-readable explanation of the problem, specifically for end-users, localized in Dutch.
            fr:
              type: string
              description: A human-readable explanation of the problem, specifically for end-users, localized in French.
            de:
              type: string
              description: A human-readable explanation of the problem, specifically for end-users, localized in German.
            en:
              type: string
              description: A human-readable explanation of the problem, specifically for end-users, localized in English.
          required:
          - nl
        schemaErrors:
          type: array
          description: A list of one or more schema validation errors (usually used for error type https://api.publiq.be/probs/body/invalid-data).
          items:
            type: object
            properties:
              jsonPointer:
                type: string
                format: json-pointer
                description: RFC6901 compliant pointer that indicates what property/value was invalid.
              error:
                type: string
                description: A human-readable (but often technical) reason why the property was invalid.
            required:
            - jsonPointer
            - error
      required:
      - type
      - title
      - status
      x-internal: false
  securitySchemes:
    USER_ACCESS_TOKEN:
      type: oauth2
      flows: {}
      description: A user access token, obtained by redirecting the end user to publiq's authorization server to login using the **Authorization Code OAuth Flow**. See the [authentication docs about user access tokens](https://docs.publiq.be/docs/authentication/methods/user-access-token) for more info.
    CLIENT_ACCESS_TOKEN:
      type: oauth2
      flows: {}
      description: A client access token, obtained by exchanging your client id and client secret for a token via an HTTP request to publiq's authorization server using the **Client Credentials OAuth Flow**. See the [authentication docs about client access tokens](https://docs.publiq.be/docs/authentication/methods/client-access-token) for more info.
    CLIENT_IDENTIFICATION:
      name: x-client-id
      type: apiKey
      in: header
    CUSTOM_TOKEN:
      name: x-custom-token
      type: apiKey
      in: header
x-refined-from:
- uitpas-uitpas.json
- publiq-uitpas-openapi.yml