openapi: 3.0.3 info: title: 'Boxflow External API Documentation' description: 'External API for integrating with Boxflow. Access tenant data, messages, and attachments programmatically.' version: 1.0.0 servers: - url: 'https://boxflow.be' tags: - name: Endpoints description: '' components: securitySchemes: default: type: http scheme: bearer description: 'You can generate an API token from your user profile in Boxflow. Go to your profile settings and create a new API token.' security: - default: [] paths: /api/external/tenants: get: summary: '' operationId: getApiExternalTenants description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints requestBody: required: false content: application/json: schema: type: object properties: tenant_ids: type: array description: 'Must be at least 1.' example: - 16 items: type: integer page: type: integer description: 'Must be at least 1.' example: 22 per_page: type: integer description: 'Must be at least 1. Must not be greater than 100.' example: 7 includeUsage: type: boolean description: '' example: true includeCompanies: type: boolean description: '' example: true /api/external/subscriptions: get: summary: '' operationId: getApiExternalSubscriptions description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints requestBody: required: false content: application/json: schema: type: object properties: tenant_ids: type: array description: 'Must be at least 1.' example: - 16 items: type: integer plan_ids: type: array description: 'Must be at least 1.' example: - 22 items: type: integer status: type: string description: '' example: inactive enum: - active - inactive - pending - canceled - past_due page: type: integer description: 'Must be at least 1.' example: 67 per_page: type: integer description: 'Must be at least 1. Must not be greater than 100.' example: 16 /api/external/transactions: post: summary: '' operationId: postApiExternalTransactions description: '' parameters: [] responses: {} tags: - Endpoints requestBody: required: true content: application/json: schema: type: object properties: subscription_id: type: integer description: 'Must match an existing stored value.' example: 16 amount: type: integer description: 'Must be at least 1.' example: 22 total_tax: type: integer description: 'Must be at least 0.' example: 84 total_discount: type: integer description: 'Must be at least 0.' example: 12 total_fees: type: integer description: 'Must be at least 0.' example: 77 description: type: string description: 'Must not be greater than 500 characters.' example: 'Et fugiat sunt nihil accusantium.' transaction_date: type: string description: 'Must be a valid date.' example: '2026-09-11T13:51:20' required: - subscription_id - amount '/api/external/subscriptions/{subscriptionId}/mrr-override': patch: summary: '' operationId: patchApiExternalSubscriptionsSubscriptionIdMrrOverride description: '' parameters: [] responses: {} tags: - Endpoints requestBody: required: false content: application/json: schema: type: object properties: mrr_override: type: integer description: 'Must be at least 0.' example: 27 nullable: true parameters: - in: path name: subscriptionId description: '' example: architecto required: true schema: type: string '/api/external/subscriptions/{subscriptionId}/enterprise-billing': patch: summary: '' operationId: patchApiExternalSubscriptionsSubscriptionIdEnterpriseBilling description: '' parameters: [] responses: {} tags: - Endpoints requestBody: required: false content: application/json: schema: type: object properties: enterprise_amount_per_company: type: integer description: 'Must be at least 0.' example: 27 nullable: true enterprise_minimum_companies: type: integer description: 'Must be at least 0.' example: 39 nullable: true parameters: - in: path name: subscriptionId description: '' example: architecto required: true schema: type: string '/api/external/tenants/{tenant}/users': get: summary: 'List users for a specific tenant' operationId: listUsersForASpecificTenant description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints requestBody: required: false content: application/json: schema: type: object properties: page: type: integer description: 'Must be at least 1.' example: 16 per_page: type: integer description: 'Must be at least 1. Must not be greater than 100.' example: 22 search: type: string description: 'Must not be greater than 255 characters.' example: g parameters: - in: path name: tenant description: 'The tenant.' example: architecto required: true schema: type: string '/api/external/tenants/{tenant}/messages': get: summary: 'List messages for a specific tenant' operationId: listMessagesForASpecificTenant description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints requestBody: required: false content: application/json: schema: type: object properties: status_id: type: integer description: 'Must be at least 1.' example: 16 service_id: type: integer description: 'Must be at least 1.' example: 22 company_id: type: integer description: 'Must be at least 1.' example: 67 sender_id: type: integer description: 'Must be at least 1.' example: 66 from_date: type: string description: 'Must be a valid date.' example: '2026-09-11T13:51:20' to_date: type: string description: 'Must be a valid date.' example: '2026-09-11T13:51:20' search: type: string description: 'Must not be greater than 255 characters.' example: m page: type: integer description: 'Must be at least 1.' example: 35 per_page: type: integer description: 'Must be at least 1. Must not be greater than 100.' example: 8 parameters: - in: path name: tenant description: 'The tenant.' example: architecto required: true schema: type: string '/api/external/tenants/{tenant}/messages/{id}': get: summary: 'Get a specific message with all details' operationId: getASpecificMessageWithAllDetails description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints parameters: - in: path name: tenant description: 'The tenant.' example: architecto required: true schema: type: string - in: path name: id description: 'The ID of the message.' example: 1 required: true schema: type: integer '/api/external/tenants/{tenant}/messages/{message_id}/attachments': get: summary: 'List attachments for a specific message' operationId: listAttachmentsForASpecificMessage description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints parameters: - in: path name: tenant description: 'The tenant.' example: architecto required: true schema: type: string - in: path name: message_id description: 'The ID of the message.' example: 1 required: true schema: type: integer '/api/external/tenants/{tenant}/messages/{message}/attachments/{attachment}': get: summary: 'Download a specific attachment (decrypted from local storage or live service)' operationId: downloadASpecificAttachmentdecryptedFromLocalStorageOrLiveService description: '' parameters: [] responses: 401: description: '' content: application/json: schema: type: object example: message: Unauthenticated. properties: message: type: string example: Unauthenticated. tags: - Endpoints parameters: - in: path name: tenant description: 'The tenant.' example: architecto required: true schema: type: string - in: path name: message description: 'The message.' example: 1 required: true schema: type: integer - in: path name: attachment description: 'The attachment.' example: architecto required: true schema: type: string