Amazon IoT Device Defender Authorizer API
The Authorizer API from Amazon IoT Device Defender — 2 operation(s) for authorizer.
The Authorizer API from Amazon IoT Device Defender — 2 operation(s) for authorizer.
openapi: 3.0.0
info:
version: 2015-05-28
x-release: v4
title: AWS IoT Accept Certificate Transfer Authorizer API
description: '<fullname>IoT</fullname> <p>IoT provides secure, bi-directional communication between Internet-connected devices (such as sensors, actuators, embedded devices, or smart appliances) and the Amazon Web Services cloud. You can discover your custom IoT-Data endpoint to communicate with, configure rules for data processing and integration with other services, organize resources associated with each device (Registry), configure logging, and create and manage policies and credentials to authenticate devices.</p> <p>The service endpoints that expose this API are listed in <a href="https://docs.aws.amazon.com/general/latest/gr/iot-core.html">Amazon Web Services IoT Core Endpoints and Quotas</a>. You must use the endpoint for the region that has the resources you want to access.</p> <p>The service name used by <a href="https://docs.aws.amazon.com/general/latest/gr/signature-version-4.html">Amazon Web Services Signature Version 4</a> to sign the request is: <i>execute-api</i>.</p> <p>For more information about how IoT works, see the <a href="https://docs.aws.amazon.com/iot/latest/developerguide/aws-iot-how-it-works.html">Developer Guide</a>.</p> <p>For information about how to use the credentials provider for IoT, see <a href="https://docs.aws.amazon.com/iot/latest/developerguide/authorizing-direct-aws.html">Authorizing Direct Calls to Amazon Web Services Services</a>.</p>'
x-logo:
url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
backgroundColor: '#FFFFFF'
termsOfService: https://aws.amazon.com/service-terms/
contact:
name: Mike Ralphson
email: mike.ralphson@gmail.com
url: https://github.com/mermade/aws2openapi
x-twitter: PermittedSoc
license:
name: Apache 2.0 License
url: http://www.apache.org/licenses/
x-providerName: amazonaws.com
x-serviceName: iot
x-aws-signingName: iot
x-origin:
- contentType: application/json
url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/iot-2015-05-28.normal.json
converter:
url: https://github.com/mermade/aws2openapi
version: 1.0.0
x-apisguru-driver: external
x-apiClientRegistration:
url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
x-apisguru-categories:
- cloud
x-preferred: true
servers:
- url: http://iot.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The AWS IoT multi-region endpoint
- url: https://iot.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The AWS IoT multi-region endpoint
- url: http://iot.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The AWS IoT endpoint for China (Beijing) and China (Ningxia)
- url: https://iot.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The AWS IoT endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: Authorizer
paths:
/authorizer/{authorizerName}:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
post:
operationId: CreateAuthorizer
description: <p>Creates an authorizer.</p> <p>Requires permission to access the <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiot.html#awsiot-actions-as-permissions">CreateAuthorizer</a> action.</p>
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/CreateAuthorizerResponse'
'480':
description: ResourceAlreadyExistsException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceAlreadyExistsException'
'481':
description: InvalidRequestException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidRequestException'
'482':
description: LimitExceededException
content:
application/json:
schema:
$ref: '#/components/schemas/LimitExceededException'
'483':
description: ThrottlingException
content:
application/json:
schema:
$ref: '#/components/schemas/ThrottlingException'
'484':
description: UnauthorizedException
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedException'
'485':
description: ServiceUnavailableException
content:
application/json:
schema:
$ref: '#/components/schemas/ServiceUnavailableException'
'486':
description: InternalFailureException
content:
application/json:
schema:
$ref: '#/components/schemas/InternalFailureException'
parameters:
- name: authorizerName
in: path
required: true
description: The authorizer name.
schema:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- authorizerFunctionArn
properties:
authorizerFunctionArn:
description: The ARN of the authorizer's Lambda function.
type: string
pattern: '[\s\S]*'
maxLength: 2048
tokenKeyName:
description: The name of the token key used to extract the token from the HTTP headers.
type: string
pattern: '[a-zA-Z0-9_-]+'
minLength: 1
maxLength: 128
tokenSigningPublicKeys:
description: The public keys used to verify the digital signature returned by your custom authentication service.
type: object
additionalProperties:
$ref: '#/components/schemas/KeyValue'
status:
description: The status of the create authorizer request.
type: string
enum:
- ACTIVE
- INACTIVE
tags:
description: '<p>Metadata which can be used to manage the custom authorizer.</p> <note> <p>For URI Request parameters use format: ...key1=value1&key2=value2...</p> <p>For the CLI command-line parameter use format: &&tags "key1=value1&key2=value2..."</p> <p>For the cli-input-json file use format: "tags": "key1=value1&key2=value2..."</p> </note>'
type: array
items:
$ref: '#/components/schemas/Tag'
signingDisabled:
description: Specifies whether IoT validates the token signature in an authorization request.
type: boolean
enableCachingForHttp:
description: <p>When <code>true</code>, the result from the authorizer’s Lambda function is cached for clients that use persistent HTTP connections. The results are cached for the time specified by the Lambda function in <code>refreshAfterInSeconds</code>. This value does not affect authorization of clients that use MQTT connections.</p> <p>The default value is <code>false</code>.</p>
type: boolean
summary: Amazon IoT Device Defender Create Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
delete:
operationId: DeleteAuthorizer
description: <p>Deletes an authorizer.</p> <p>Requires permission to access the <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiot.html#awsiot-actions-as-permissions">DeleteAuthorizer</a> action.</p>
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/DeleteAuthorizerResponse'
'480':
description: DeleteConflictException
content:
application/json:
schema:
$ref: '#/components/schemas/DeleteConflictException'
'481':
description: ResourceNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceNotFoundException'
'482':
description: InvalidRequestException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidRequestException'
'483':
description: ThrottlingException
content:
application/json:
schema:
$ref: '#/components/schemas/ThrottlingException'
'484':
description: UnauthorizedException
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedException'
'485':
description: ServiceUnavailableException
content:
application/json:
schema:
$ref: '#/components/schemas/ServiceUnavailableException'
'486':
description: InternalFailureException
content:
application/json:
schema:
$ref: '#/components/schemas/InternalFailureException'
parameters:
- name: authorizerName
in: path
required: true
description: The name of the authorizer to delete.
schema:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
summary: Amazon IoT Device Defender Delete Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
get:
operationId: DescribeAuthorizer
description: <p>Describes an authorizer.</p> <p>Requires permission to access the <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiot.html#awsiot-actions-as-permissions">DescribeAuthorizer</a> action.</p>
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/DescribeAuthorizerResponse'
'480':
description: ResourceNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceNotFoundException'
'481':
description: InvalidRequestException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidRequestException'
'482':
description: ThrottlingException
content:
application/json:
schema:
$ref: '#/components/schemas/ThrottlingException'
'483':
description: UnauthorizedException
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedException'
'484':
description: ServiceUnavailableException
content:
application/json:
schema:
$ref: '#/components/schemas/ServiceUnavailableException'
'485':
description: InternalFailureException
content:
application/json:
schema:
$ref: '#/components/schemas/InternalFailureException'
parameters:
- name: authorizerName
in: path
required: true
description: The name of the authorizer to describe.
schema:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
summary: Amazon IoT Device Defender Describe Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
put:
operationId: UpdateAuthorizer
description: <p>Updates an authorizer.</p> <p>Requires permission to access the <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiot.html#awsiot-actions-as-permissions">UpdateAuthorizer</a> action.</p>
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateAuthorizerResponse'
'480':
description: ResourceNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceNotFoundException'
'481':
description: InvalidRequestException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidRequestException'
'482':
description: LimitExceededException
content:
application/json:
schema:
$ref: '#/components/schemas/LimitExceededException'
'483':
description: ThrottlingException
content:
application/json:
schema:
$ref: '#/components/schemas/ThrottlingException'
'484':
description: UnauthorizedException
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedException'
'485':
description: ServiceUnavailableException
content:
application/json:
schema:
$ref: '#/components/schemas/ServiceUnavailableException'
'486':
description: InternalFailureException
content:
application/json:
schema:
$ref: '#/components/schemas/InternalFailureException'
parameters:
- name: authorizerName
in: path
required: true
description: The authorizer name.
schema:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
authorizerFunctionArn:
description: The ARN of the authorizer's Lambda function.
type: string
pattern: '[\s\S]*'
maxLength: 2048
tokenKeyName:
description: 'The key used to extract the token from the HTTP headers. '
type: string
pattern: '[a-zA-Z0-9_-]+'
minLength: 1
maxLength: 128
tokenSigningPublicKeys:
description: The public keys used to verify the token signature.
type: object
additionalProperties:
$ref: '#/components/schemas/KeyValue'
status:
description: The status of the update authorizer request.
type: string
enum:
- ACTIVE
- INACTIVE
enableCachingForHttp:
description: When <code>true</code>, the result from the authorizer’s Lambda function is cached for the time specified in <code>refreshAfterInSeconds</code>. The cached result is used while the device reuses the same HTTP connection.
type: boolean
summary: Amazon IoT Device Defender Update Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
/authorizer/{authorizerName}/test:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
post:
operationId: TestInvokeAuthorizer
description: <p>Tests a custom authorization behavior by invoking a specified custom authorizer. Use this to test and debug the custom authorization behavior of devices that connect to the IoT device gateway.</p> <p>Requires permission to access the <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiot.html#awsiot-actions-as-permissions">TestInvokeAuthorizer</a> action.</p>
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/TestInvokeAuthorizerResponse'
'480':
description: ResourceNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceNotFoundException'
'481':
description: InvalidRequestException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidRequestException'
'482':
description: ThrottlingException
content:
application/json:
schema:
$ref: '#/components/schemas/ThrottlingException'
'483':
description: UnauthorizedException
content:
application/json:
schema:
$ref: '#/components/schemas/UnauthorizedException'
'484':
description: ServiceUnavailableException
content:
application/json:
schema:
$ref: '#/components/schemas/ServiceUnavailableException'
'485':
description: InternalFailureException
content:
application/json:
schema:
$ref: '#/components/schemas/InternalFailureException'
'486':
description: InvalidResponseException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidResponseException'
parameters:
- name: authorizerName
in: path
required: true
description: The custom authorizer name.
schema:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
token:
description: The token returned by your custom authentication service.
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 6144
tokenSignature:
description: The signature made with the token and your custom authentication service's private key. This value must be Base-64-encoded.
type: string
pattern: '[A-Za-z0-9+/]+={0,2}'
minLength: 1
maxLength: 2560
httpContext:
description: Specifies the HTTP context to use for the test authorizer request.
type: object
properties:
headers:
allOf:
- $ref: '#/components/schemas/HttpHeaders'
- description: The header keys and values in an HTTP authorization request.
queryString:
allOf:
- $ref: '#/components/schemas/HttpQueryString'
- description: The query string keys and values in an HTTP authorization request.
mqttContext:
description: Specifies the MQTT context to use for the test authorizer request
type: object
properties:
username:
allOf:
- $ref: '#/components/schemas/MqttUsername'
- description: The value of the <code>username</code> key in an MQTT authorization request.
password:
allOf:
- $ref: '#/components/schemas/MqttPassword'
- description: The value of the <code>password</code> key in an MQTT authorization request.
clientId:
allOf:
- $ref: '#/components/schemas/MqttClientId'
- description: The value of the <code>clientId</code> key in an MQTT authorization request.
tlsContext:
description: Specifies the TLS context to use for the test authorizer request.
type: object
properties:
serverName:
allOf:
- $ref: '#/components/schemas/ServerName'
- description: The value of the <code>serverName</code> key in a TLS authorization request.
summary: Amazon IoT Device Defender Test Invoke Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
components:
parameters:
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
schemas:
ResourceNotFoundException: {}
HttpHeaderValue:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 8192
DateType:
type: string
format: date-time
InternalFailureException: {}
DeleteConflictException: {}
IsAuthenticated:
type: boolean
PolicyDocuments:
type: array
items:
$ref: '#/components/schemas/PolicyDocument'
UpdateAuthorizerResponse:
type: object
properties:
authorizerName:
allOf:
- $ref: '#/components/schemas/AuthorizerName'
- description: The authorizer name.
authorizerArn:
allOf:
- $ref: '#/components/schemas/AuthorizerArn'
- description: The authorizer ARN.
DeleteAuthorizerResponse:
type: object
properties: {}
HttpQueryString:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 4096
AuthorizerArn:
type: string
maxLength: 2048
KeyValue:
type: string
pattern: '[\s\S]*'
maxLength: 5120
PolicyDocument:
type: string
pattern: '[\s\S]*'
minLength: 0
maxLength: 404600
MqttUsername:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 65535
AuthorizerFunctionArn:
type: string
pattern: '[\s\S]*'
maxLength: 2048
Seconds:
type: integer
MqttClientId:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 65535
ServiceUnavailableException: {}
PublicKeyMap:
type: object
additionalProperties:
$ref: '#/components/schemas/KeyValue'
ResourceAlreadyExistsException: {}
PrincipalId:
type: string
pattern: '[a-zA-Z0-9]+'
minLength: 1
maxLength: 128
BooleanKey:
type: boolean
UnauthorizedException: {}
EnableCachingForHttp:
type: boolean
Tag:
type: object
required:
- Key
properties:
Key:
allOf:
- $ref: '#/components/schemas/TagKey'
- description: The tag's key.
Value:
allOf:
- $ref: '#/components/schemas/TagValue'
- description: The tag's value.
description: A set of key/value pairs that are used to manage the resource.
TagKey:
type: string
pattern: ^([\p{L}\p{Z}\p{N}_.:/=+\-@]*)$
minLength: 1
maxLength: 128
MqttPassword:
type: string
minLength: 1
maxLength: 65535
TagValue:
type: string
minLength: 0
maxLength: 256
DescribeAuthorizerResponse:
type: object
properties:
authorizerDescription:
allOf:
- $ref: '#/components/schemas/AuthorizerDescription'
- description: The authorizer description.
ThrottlingException: {}
AuthorizerStatus:
type: string
enum:
- ACTIVE
- INACTIVE
InvalidRequestException: {}
CreateAuthorizerResponse:
type: object
properties:
authorizerName:
allOf:
- $ref: '#/components/schemas/AuthorizerName'
- description: The authorizer's name.
authorizerArn:
allOf:
- $ref: '#/components/schemas/AuthorizerArn'
- description: The authorizer ARN.
AuthorizerDescription:
type: object
properties:
authorizerName:
allOf:
- $ref: '#/components/schemas/AuthorizerName'
- description: The authorizer name.
authorizerArn:
allOf:
- $ref: '#/components/schemas/AuthorizerArn'
- description: The authorizer ARN.
authorizerFunctionArn:
allOf:
- $ref: '#/components/schemas/AuthorizerFunctionArn'
- description: The authorizer's Lambda function ARN.
tokenKeyName:
allOf:
- $ref: '#/components/schemas/TokenKeyName'
- description: The key used to extract the token from the HTTP headers.
tokenSigningPublicKeys:
allOf:
- $ref: '#/components/schemas/PublicKeyMap'
- description: The public keys used to validate the token signature returned by your custom authentication service.
status:
allOf:
- $ref: '#/components/schemas/AuthorizerStatus'
- description: The status of the authorizer.
creationDate:
allOf:
- $ref: '#/components/schemas/DateType'
- description: The UNIX timestamp of when the authorizer was created.
lastModifiedDate:
allOf:
- $ref: '#/components/schemas/DateType'
- description: The UNIX timestamp of when the authorizer was last updated.
signingDisabled:
allOf:
- $ref: '#/components/schemas/BooleanKey'
- description: Specifies whether IoT validates the token signature in an authorization request.
enableCachingForHttp:
allOf:
- $ref: '#/components/schemas/EnableCachingForHttp'
- description: When <code>true</code>, the result from the authorizer’s Lambda function is cached for the time specified in <code>refreshAfterInSeconds</code>. The cached result is used while the device reuses the same HTTP connection.
description: The authorizer description.
TokenKeyName:
type: string
pattern: '[a-zA-Z0-9_-]+'
minLength: 1
maxLength: 128
ServerName:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 253
AuthorizerName:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
InvalidResponseException: {}
LimitExceededException: {}
HttpHeaders:
type: object
additionalProperties:
$ref: '#/components/schemas/HttpHeaderValue'
TestInvokeAuthorizerResponse:
type: object
properties:
isAuthenticated:
allOf:
- $ref: '#/components/schemas/IsAuthenticated'
- description: True if the token is authenticated, otherwise false.
principalId:
allOf:
- $ref: '#/components/schemas/PrincipalId'
- description: The principal ID.
policyDocuments:
allOf:
- $ref: '#/components/schemas/PolicyDocuments'
- description: IAM policy documents.
refreshAfterInSeconds:
allOf:
- $ref: '#/components/schemas/Seconds'
- description: The number of seconds after which the temporary credentials are refreshed.
disconnectAfterInSeconds:
allOf:
- $ref: '#/components/schemas/Seconds'
- description: The number of seconds after which the connection is terminated.
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/iot/
x-hasEquivalentPaths: true