{"activeVersionTag":"latest","latestAvailableVersionTag":"latest","collection":{"info":{"_postman_id":"18f73ef3-6576-4155-a960-8b7b51c7ad40","name":"MMS-API v1","description":"<img src=\"https://content.pstmn.io/15cfc291-fabb-4f39-a90d-1af5f9a4295d/bG9nb19wb3N0bWFuLnBuZw==\" alt=\"\">\n\n## Authentication\n\nEvery request needs an API token, passed either as a `Bearer` token in the `Authorization` header (the collection is pre-configured for this via the `{{token}}` variable) or as an `X-TOKEN` header. Tokens are issued per API application in the MMS portal.\n\nA token may act **on behalf of** a portal user by sending the `X-On-Behalf-Of: <user-uuid>` header. All permission checks and row-level scoping then apply to that user; the effective permission is always the intersection of the token's own ceiling and the impersonated user's rights. `GET /context` describes the resulting identity, capabilities and project scope in a single call.\n\n## Identifiers\n\nUUIDs are the canonical identifiers everywhere: single entities are retrieved via `/<resource>/<uuid>`, foreign keys are read and written through `*Uuid` fields (e.g. `projectUuid`), and `$filter` expressions reference them the same way. Responses may additionally contain legacy integer id fields for one internal client — they are **not part of the contract**. Send the `X-Hide-Deprecated: 1` header to receive clean uuid-only payloads (all examples in this documentation were recorded that way).\n\n## Creating / updating / deleting\n\n`POST /<resource>` is an **upsert by uuid**: without a `uuid` in the body the server creates the entity and assigns one; with a known `uuid` it updates that entity (only sent fields are changed); with an unknown, client-generated `uuid` it creates the entity under exactly that uuid. The update-via-upsert exists for idempotent offline/sync flows and for clients that cannot send PATCH — **for plain updates prefer `PATCH /<resource>/<uuid>`**.\n\n`PATCH /<resource>/<uuid>` is the **preferred update**: a strict, partial update of one existing entity — only sent fields are changed, and an unknown uuid is a `404`; this form never creates, so a typo cannot silently mint a new entity. A `uuid` in the body must be absent or equal to the path uuid (`400` otherwise).\n\nA few resources are **create-only** (e.g. `comments` — the conversation trail cannot be rewritten): their POST says so, updating an existing entry is refused with `403`, and they have no update form under `/<resource>/<uuid>`.\n\n**Client-generated uuids make creates idempotent** — recommended for offline-capable and syncing clients: if an HTTP request is interrupted after the server stored the record, simply re-sending the same payload can never produce a duplicate. Regular request/response clients can ignore this and let the server assign uuids.\n\nDelete via `DELETE /<resource>/<uuid>`. All dates are ISO 8601 with time zone. Write and delete operations require the acting user to hold the resource's `Api_<resource>_write` / `Api_<resource>_delete` right; some resources are read-only through the API.\n\n**Import mode:** system-written data (a ticket's workflow status, protocol entries, e-post letters) can be written directly during migrations/imports by sending the `X-Import: 1` header. Import mode is restricted to superadmins — any other caller receives `403`.\n\n## Filtering and paging\n\n`$filter` supports conjunctions of equality terms:\n`$filter=projectUuid eq '<uuid>' and open eq 1`\n\n**Every collection request documents its supported filter fields on the `$filter` parameter itself — open the request's Params tab.** Paging via `$top` and `$skip`. **`$top` is capped at 500** — a larger value, or an unpaged query whose result would exceed 500 rows, is rejected with `400` and a hint to paginate. Fields marked `readOnly` in the schema are computed or embedded values (e.g. the `user` object on a comment); they are silently ignored on write. Requests may also be rate-limited (`429`).\n\n## Terms and definitions\n\n*   ticket: a defect (\"Mangel\") or, more generally, any tracked issue/measure in a project\n*   status: workflow status of a ticket (e.g. new, deadline running, done) — changed only through ticket transitions\n*   workflow: the ticket lifecycle definition (historically \"Projekt-Typ\")\n*   comment: a comment on a ticket\n*   email: e-mails belong to a project and are usually assigned to tickets\n*   media: an image or document, stored in collections (folders) that hang below tickets, e-mails, the building structure or the project\n*   ticket protocol: dated protocol entries on a ticket (actions, remarks — the ticket's activity log)\n*   project: a building complex / property (\"Objekt\")\n*   part: a building (\"Bauteil\") within a project\n*   floor: a storey (\"Etage\") within a part\n*   section: an area (\"Bereich\") within a floor — rental unit or common space\n*   trade: a craft/trade (\"Gewerk\"); sub-trades refine a trade\n*   company: a contractor company assigned to trades within a project\n*   contract: the assignment of a company to a project (\"Firma-Projekt\")\n*   warranty: warranty periods per contract and trade (\"Gewährleistung\")\n*   guarantee: a bond/surety (\"Bürgschaft/Aval\") securing projects or contracts\n*   budget: a money pot within a project; transactions book against it\n*   limitation avoidance: measures avoiding the statute of limitations (\"Verjährungshemmung\")\n*   equipment: maintainable technical equipment (\"Anlagen\") located in the building structure\n*   maintenance interval: a recurrence rule that spawns maintenance tickets from a template\n*   todo: a task, usually attached to a ticket","schema":"https://schema.getpostman.com/json/collection/v2.0.0/collection.json","isPublicCollection":false,"owner":"14159217","team":1501422,"collectionId":"18f73ef3-6576-4155-a960-8b7b51c7ad40","publishedId":"2sBYArUCqV","public":true,"publicUrl":"https://docs.mms-portal.eu","privateUrl":"https://go.postman.co/documentation/14159217-18f73ef3-6576-4155-a960-8b7b51c7ad40","customColor":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"FF6C37"},"documentationLayout":"classic-double-column","customisation":{"metaTags":[{"name":"description","value":""},{"name":"title","value":""}],"appearance":{"default":"light","themes":[{"name":"dark","logo":null,"colors":{"top-bar":"212121","right-sidebar":"303030","highlight":"FF6C37"}},{"name":"light","logo":null,"colors":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"FF6C37"}}]}},"version":"8.12.3","publishDate":"2026-08-20T09:46:40.000Z","activeVersionTag":"latest","documentationTheme":"light","metaTags":{"title":"","description":""},"logos":{"logoLight":null,"logoDark":null}},"statusCode":200},"environments":[{"name":"Demo","id":"24a892a3-f2a6-404d-bd59-36941261dc5e","owner":"14159217","values":[{"key":"url","value":"https://demo.mms-portal.eu/index.php/MmsApi/v1","enabled":true,"type":"default"},{"key":"token","value":"","enabled":true,"type":"default"},{"key":"user","value":"","enabled":true,"type":"default"},{"key":"password","value":"","enabled":true,"type":"default"},{"key":"tenant","value":"demo","enabled":true,"type":"default"},{"key":"baseUrl","value":"https://demo.mms-portal.eu/index.php/MmsApi/v1","enabled":true,"type":"default"}],"published":true}],"user":{"authenticated":false,"permissions":{"publish":false}},"run":{"button":{"js":"https://run.pstmn.io/button.js","css":"https://run.pstmn.io/button.css"}},"web":"https://www.getpostman.com/","team":{"logo":"https://res.cloudinary.com/postman/image/upload/t_team_logo_pubdoc/v1/team/eac65aba9dc726eb76b1e531e204f54c10ffc00e57b8d91b75c3eec361849307","favicon":"https://mms-portal.eu/favicon.ico"},"isEnvFetchError":false,"languages":"[{\"key\":\"csharp\",\"label\":\"C#\",\"variant\":\"HttpClient\"},{\"key\":\"csharp\",\"label\":\"C#\",\"variant\":\"RestSharp\"},{\"key\":\"curl\",\"label\":\"cURL\",\"variant\":\"cURL\"},{\"key\":\"dart\",\"label\":\"Dart\",\"variant\":\"http\"},{\"key\":\"go\",\"label\":\"Go\",\"variant\":\"Native\"},{\"key\":\"http\",\"label\":\"HTTP\",\"variant\":\"HTTP\"},{\"key\":\"java\",\"label\":\"Java\",\"variant\":\"OkHttp\"},{\"key\":\"java\",\"label\":\"Java\",\"variant\":\"Unirest\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"Fetch\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"jQuery\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"XHR\"},{\"key\":\"c\",\"label\":\"C\",\"variant\":\"libcurl\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Axios\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Native\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Request\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Unirest\"},{\"key\":\"objective-c\",\"label\":\"Objective-C\",\"variant\":\"NSURLSession\"},{\"key\":\"ocaml\",\"label\":\"OCaml\",\"variant\":\"Cohttp\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"cURL\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"Guzzle\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"HTTP_Request2\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"pecl_http\"},{\"key\":\"powershell\",\"label\":\"PowerShell\",\"variant\":\"RestMethod\"},{\"key\":\"python\",\"label\":\"Python\",\"variant\":\"http.client\"},{\"key\":\"python\",\"label\":\"Python\",\"variant\":\"Requests\"},{\"key\":\"r\",\"label\":\"R\",\"variant\":\"httr\"},{\"key\":\"r\",\"label\":\"R\",\"variant\":\"RCurl\"},{\"key\":\"ruby\",\"label\":\"Ruby\",\"variant\":\"Net::HTTP\"},{\"key\":\"shell\",\"label\":\"Shell\",\"variant\":\"Httpie\"},{\"key\":\"shell\",\"label\":\"Shell\",\"variant\":\"wget\"},{\"key\":\"swift\",\"label\":\"Swift\",\"variant\":\"URLSession\"}]","languageSettings":[{"key":"csharp","label":"C#","variant":"HttpClient"},{"key":"csharp","label":"C#","variant":"RestSharp"},{"key":"curl","label":"cURL","variant":"cURL"},{"key":"dart","label":"Dart","variant":"http"},{"key":"go","label":"Go","variant":"Native"},{"key":"http","label":"HTTP","variant":"HTTP"},{"key":"java","label":"Java","variant":"OkHttp"},{"key":"java","label":"Java","variant":"Unirest"},{"key":"javascript","label":"JavaScript","variant":"Fetch"},{"key":"javascript","label":"JavaScript","variant":"jQuery"},{"key":"javascript","label":"JavaScript","variant":"XHR"},{"key":"c","label":"C","variant":"libcurl"},{"key":"nodejs","label":"NodeJs","variant":"Axios"},{"key":"nodejs","label":"NodeJs","variant":"Native"},{"key":"nodejs","label":"NodeJs","variant":"Request"},{"key":"nodejs","label":"NodeJs","variant":"Unirest"},{"key":"objective-c","label":"Objective-C","variant":"NSURLSession"},{"key":"ocaml","label":"OCaml","variant":"Cohttp"},{"key":"php","label":"PHP","variant":"cURL"},{"key":"php","label":"PHP","variant":"Guzzle"},{"key":"php","label":"PHP","variant":"HTTP_Request2"},{"key":"php","label":"PHP","variant":"pecl_http"},{"key":"powershell","label":"PowerShell","variant":"RestMethod"},{"key":"python","label":"Python","variant":"http.client"},{"key":"python","label":"Python","variant":"Requests"},{"key":"r","label":"R","variant":"httr"},{"key":"r","label":"R","variant":"RCurl"},{"key":"ruby","label":"Ruby","variant":"Net::HTTP"},{"key":"shell","label":"Shell","variant":"Httpie"},{"key":"shell","label":"Shell","variant":"wget"},{"key":"swift","label":"Swift","variant":"URLSession"}],"languageOptions":[{"label":"C# - HttpClient","value":"csharp - HttpClient - C#"},{"label":"C# - RestSharp","value":"csharp - RestSharp - C#"},{"label":"cURL - cURL","value":"curl - cURL - cURL"},{"label":"Dart - http","value":"dart - http - Dart"},{"label":"Go - Native","value":"go - Native - Go"},{"label":"HTTP - HTTP","value":"http - HTTP - HTTP"},{"label":"Java - OkHttp","value":"java - OkHttp - Java"},{"label":"Java - Unirest","value":"java - Unirest - Java"},{"label":"JavaScript - Fetch","value":"javascript - Fetch - JavaScript"},{"label":"JavaScript - jQuery","value":"javascript - jQuery - JavaScript"},{"label":"JavaScript - XHR","value":"javascript - XHR - JavaScript"},{"label":"C - libcurl","value":"c - libcurl - C"},{"label":"NodeJs - Axios","value":"nodejs - Axios - NodeJs"},{"label":"NodeJs - Native","value":"nodejs - Native - NodeJs"},{"label":"NodeJs - Request","value":"nodejs - Request - NodeJs"},{"label":"NodeJs - Unirest","value":"nodejs - Unirest - NodeJs"},{"label":"Objective-C - NSURLSession","value":"objective-c - NSURLSession - Objective-C"},{"label":"OCaml - Cohttp","value":"ocaml - Cohttp - OCaml"},{"label":"PHP - cURL","value":"php - cURL - PHP"},{"label":"PHP - Guzzle","value":"php - Guzzle - PHP"},{"label":"PHP - HTTP_Request2","value":"php - HTTP_Request2 - PHP"},{"label":"PHP - pecl_http","value":"php - pecl_http - PHP"},{"label":"PowerShell - RestMethod","value":"powershell - RestMethod - PowerShell"},{"label":"Python - http.client","value":"python - http.client - Python"},{"label":"Python - Requests","value":"python - Requests - Python"},{"label":"R - httr","value":"r - httr - R"},{"label":"R - RCurl","value":"r - RCurl - R"},{"label":"Ruby - Net::HTTP","value":"ruby - Net::HTTP - Ruby"},{"label":"Shell - Httpie","value":"shell - Httpie - Shell"},{"label":"Shell - wget","value":"shell - wget - Shell"},{"label":"Swift - URLSession","value":"swift - URLSession - Swift"}],"layoutOptions":[{"value":"classic-single-column","label":"Single Column"},{"value":"classic-double-column","label":"Double Column"}],"versionOptions":[],"environmentOptions":[{"value":"0","label":"No Environment"},{"label":"Demo","value":"14159217-24a892a3-f2a6-404d-bd59-36941261dc5e"}],"canonicalUrl":"https://docs.mms-portal.eu/view/metadata/2sBYArUCqV"}