Beyond Identity Applications API

An application represents a client application that uses Beyond Identity for authentication. This could be a native app, a single-page application, regular web application, or machine-to-machine application credentials.

OpenAPI Specification

beyond-identity-applications-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Beyond Identity Secure Access Applications API
  version: 1.7.0
  contact:
    email: support@beyondidentity.com
  description: "# Introduction\n\n**NOTE:** To determine if you are accessing the Secure Access Platform, check the URL of your Admin Console.\nIf it looks like one of the following, you are using the Secure Access Platform:\n- `https://console.beyondidentity.com` (Localized to your region)\n- `https://console-us.beyondidentity.com` (US region)\n- `https://console-eu.beyondidentity.com` (EU region)\n- `https://console.us1.beyondidentity-gov.com` (US FedRAMP)\n\nIf your Admin Console URL does not look like one of the above, you are using the Secure Workforce Platform. Please refer to the [Secure Workforce API documentation](https://docs.beyondidentity.com/api/v0). <br /><br />\n\nThe Beyond Identity Secure Access API defines methods for managing resources in the Beyond Identity Secure Access platform.<br /><br />\n\nAll of the functionality available in the Beyond Identity Admin Console is\nalso available through the API. <br /><br />\n\nThis API is currently in the early-access stage and is under active\ndevelopment. Feedback and suggestions are encouraged and should be directed\nto the\n[Beyond Identity Developer Slack Channel](https://join.slack.com/t/byndid/shared_invite/zt-1anns8n83-NQX4JvW7coi9dksADxgeBQ).\n\n# Base API URLs\n\nThe base API URLs is determined by the region your tenant is hosted in OR if you are a FedRAMP customer. <br><br>\n\n### US Region\n\nIf you are a US region customer, your base API URLs will be:\n- `https://api-us.beyondidentity.com`\n- `https://auth-us.beyondidentity.com`\n\n### EU Region\n\nIf you are a EU region customer, your base API URLs will be:\n- `https://api-eu.beyondidentity.com`\n- `https://auth-eu.beyondidentity.com`\n\n### US FedRAMP\n\n**NOTE**: The FedRAMP version of Secure Access is released approximately *two weeks* after the commercial version, so some API endpoints may not be available immediately. <br><br>\n\nIf you are a FedRAMP customer in the US region, your base API URLs will be:\n- `https://api.us1.beyondidentity-gov.com`\n- `https://auth.us1.beyondidentity-gov.com`\n\nFor all the examples in this document, we will use the US region API base URL. You can always replace `https://api-us.beyondidentity.com`\nand `https://auth-us.beyondidentity.com` in the examples to use the proper base URL for your tenant.\n\n# Authentication\n\nAll Beyond Identity API endpoints require authentication using an access\ntoken. The access token is generated through OAuth 2.0 or OIDC, using the\nauthorization code flow or the client credentials flow. <br /><br />\n\nThe simplest way to acquire an access token is through the Beyond Identity Admin Console. Under the \"Applications\" tab, select the \"Beyond Identity Management API\" application, navigate to the \"API Tokens\" tab, and then click on \"Create token\". <br /><br />\n\nAlternatively, an access token may also be generated directly via the API by\nrequesting a token for the \"Beyond Identity Management API\" Application. <br><br>\n\n```\ncurl https://auth-us.beyondidentity.com/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications/$APPLICATION_ID/token \\\n  -X POST \\\n  -u \"$CLIENT_ID:$CLIENT_SECRET\" --basic \\\n  -H \"Content-Type: application/x-www-form-urlencoded\" \\\n  -d \"grant_type=client_credentials&scope=$SCOPES\"\n```\n\nThis will work for any application that you have configured to provide\naccess to the Beyond Identity Management API Resource Server. The \"Beyond\nIdentity Management API\" application is provided by default as part of the\ntenant onboarding process.\n\nThe access token must be provided in the `Authorization` header of the\nAPI request. <br><br>\n\n```\ncurl https://api-us.beyondidentity.com/v1/... \\\n  -X $HTTP_METHOD -H \"Authorization: Bearer $TOKEN\"\n```\n\n## Requests and Responses\n\nTo interact with the Beyond Identity API, all requests should be made over\nHTTPS. <br /><br />\n\nThe Beyond Identity API is generally structured as a resource-oriented API.\nResources are represented as JSON objects and are used as both inputs to\nand outputs from API methods. <br /><br />\n\nResource fields may be described as read-only and immutable. A read-only\nfield is only provided on the response. An immutable field is only assigned\nonce and may not be changed after. For example, system-generated IDs are\ndescribed as both read-only and immutable. <br /><br />\n\nTo create a new resource, requests should use the `POST` method. Create\nrequests include all of the necessary attributes to create a new resource.\nCreate operations return the created resource in the response. <br /><br />\n\nTo retrieve a single resource or a collection of resources, requests should\nuse the `GET` method. When retrieving a collection of resources, the\nresponse will include an array of JSON objects keyed on the plural name of\nthe requested resource. <br /><br />\n\nTo update an resource, requests should use the `PATCH` method. Update\noperations support partial updating so requests may specify only the\nattributes which should be updated. Update operations return the updated\nresource in the response. <br /><br />\n\nTo delete a resource, requests should use the `DELETE` method. Note that\ndelete operations return an empty response instead of returning the\nresource in the response. <br /><br />\n\n### Example Response for a Realm\n\n```\n{\n  \"id\": \"a448fe493e02fa9f\",\n  \"tenant_id\": \"000168dc50bdce49\",\n  \"display_name\": \"Test Realm\",\n  \"create_time\": \"2022-06-22T21:46:08.930278Z\",\n  \"update_time\": \"2022-06-22T21:46:08.930278Z\"\n}\n```\n\n### Example Response for a Collection of Realms\n\n```\n{\n  \"realms\": [\n    {\n      \"id\": \"a448fe493e02fa9f\",\n      \"tenant_id\": \"000168dc50bdce49\",\n      \"display_name\": \"Test Realm\",\n      \"create_time\": \"2022-06-22T21:46:08.930278Z\",\n      \"update_time\": \"2022-06-22T21:46:08.930278Z\"\n    }\n  ],\n  \"total_size\": 1\n}\n```\n\n## HTTP Statuses\n\nThe API returns standard HTTP statuses and error codes.\n\nStatuses in the 200 range indicate that the request was successfully\nfulfilled and there were no errors. <br><br>\n\nStatuses in the 400 range indicate that there was an issue with the request\nthat may be addressed by the client. For example, client errors may\nindicate that the request was missing proper authorization or that the\nrequest was malformed. <br><br>\n\nStatuses in the 500 range indicate that the server encountered an internal\nissue and was unable to fulfill the request. <br><br>\n\nAll error responses include a JSON object with a `code` field and a\n`message` field. `code` contains a human-readable name for the HTTP status\ncode and `message` contains a high-level description of the error. The\nerror object may also contain additional error details which may be used by\nthe client to determine the exact cause of the error. Refer to each API\nmethod's examples to determine the specific error detail types supported\nfor that method. <br><br>\n\n### Invalid Access Token Example\n\nIf the provided access token is invalid, you will receive a 401 error.\nThis error indicates that the token is not recognized and was not generated\nby Beyond Identity. <br><br>\n\n```\nHTTP/1.1 401 Unauthorized\n{\n  \"code\": \"unauthorized\",\n  \"message\": \"unauthorized\"\n}\n```\n\n### Permission Denied Example\n\nIf the provided access token does not have access to the requested resource,\nyou will receive a 403 error. Access tokens are scoped at a minimum to your\ntenant. Any request for resources outside of your tenant will result in this\nerror. <br><br>\n\n```\nHTTP/1.1 403 Forbidden\n{\n  \"code\": \"forbidden\",\n  \"message\": \"forbidden\"\n}\n```\n\n### Missing Resource Example\n\nIf the requested resource does not exist, you will receive a 404 error. The\nspecific API method may return additional details about the missing\nresource. <br><br>\n\n```\nHTTP/1.1 404 Not Found\n{\n  \"code\": \"not_found\",\n  \"message\": \"group not found\"\n  \"details\": [\n    {\n      \"type\": \"ResourceInfo\",\n      \"resource_type\": \"Group\",\n      \"id\": \"4822738be6b7f658\",\n      \"description\": \"group not found\"\n    }\n  ],\n}\n```\n\n### Invalid Parameters Example\n\nIf the request body contains invalid parameters, you will receive a 400\nerror. The specific API method may return additional details about the\ninvalid parameter. <br><br>\n\n```\nHTTP/1.1 400 Bad Request\n{\n  \"code\": \"bad_request\",\n  \"message\": \"invalid parameters\"\n  \"details\": [\n    {\n      \"type\": \"FieldViolations\"\n      \"field_violations\": [\n        {\n          \"description\": \"missing\",\n          \"field\": \"group.display_name\"\n        }\n      ],\n    }\n  ],\n}\n```\n"
servers:
- url: https://api-us.beyondidentity.com
  description: US region API base URL
- url: https://api-eu.beyondidentity.com
  description: EU region API base URL
- url: https://api.us1.beyondidentity-gov.com/
  description: US FedRAMP API base URL
security:
- BearerAuth: []
tags:
- name: Applications
  description: 'An application represents a client application that uses Beyond Identity for authentication. This could be a native app, a single-page application, regular web application, or machine-to-machine application credentials.

    '
paths:
  /v1/tenants/{tenant_id}/realms/{realm_id}/applications:
    post:
      operationId: CreateApplication
      tags:
      - Applications
      summary: Create a New Application
      description: 'To create an application, send a POST request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications`. Values in the request body for read-only fields will be ignored.

        At present, there are only two supported protocol types for applications, `oauth2` and `oidc`.

        '
      security:
      - BearerAuth:
        - applications:create
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      requestBody:
        content:
          application/json:
            schema:
              title: Create Application Request
              description: Request for CreateApplication.
              type: object
              properties:
                application:
                  $ref: '#/components/schemas/Application'
              required:
              - application
            examples:
              Create Application:
                value:
                  application:
                    display_name: Pet Application
                    resource_server_id: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
                    protocol_config:
                      type: oidc
                      allowed_scopes:
                      - pets:read
                      - pets:write
                      confidentiality: confidential
                      token_endpoint_auth_method: client_secret_post
                      grant_type:
                      - authorization_code
                      redirect_uris:
                      - https://auth.mypetapp.com/callback
                      token_configuration:
                        subject_field: id
                        expires_after: 86400
                        token_signing_algorithm: RS256
                      pkce: disabled
                      token_format: self_contained
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with an application.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Application'
              examples:
                Success:
                  value:
                    id: 38833c36-6f47-4992-9329-ea0a00915137
                    realm_id: caf2ff640497591a
                    tenant_id: 00011f1183c67b69
                    resource_server_id: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
                    display_name: Pet Application
                    is_managed: false
                    protocol_config:
                      type: oidc
                      allowed_scopes:
                      - pets:read
                      - pets:write
                      client_id: AYYNcuOSpfqIf33JeegCzDIT
                      client_secret: wWD4mPzdsjms1LPekQSo0v9scOHLWy5wmMtKAR2JNhJPAKXv
                      confidentiality: confidential
                      token_endpoint_auth_method: client_secret_post
                      grant_type:
                      - authorization_code
                      redirect_uris:
                      - https://auth.mypetapp.com/callback
                      token_configuration:
                        subject_field: id
                        expires_after: 86400
                        token_signing_algorithm: RS256
                      pkce: disabled
                      token_format: self_contained
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Malformed Request:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/patch/responses/400/content/application~1json/examples/Malformed%20Request'
                Invalid Parameters:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/400/content/application~1json/examples/Invalid%20Parameters'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Realm Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
    get:
      operationId: ListApplications
      tags:
      - Applications
      summary: List Applications for a Realm
      description: 'To list all applications for a realm, send a GET request to

        `/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications`.


        The response will contain at most 100 items and may contain a page token to

        query the remaining items. If page size is not specified, the response will

        contain 100 items. There is no defined ordering of the list of applications

        in the response.  Note that the maximum and default page sizes are subject

        to change.


        When paginating, the page size is maintained by the page token but may be

        overridden on subsequent requests. The skip is not maintained by the page

        token and must be specified on each subsequent request.


        Page tokens expire after one week. Requests which specify an expired page

        token will result in undefined behavior.

        '
      security:
      - BearerAuth:
        - applications:read
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/page_size'
      - $ref: '#/components/parameters/page_token'
      responses:
        '200':
          description: 'The response will be a JSON object with keys for `applications` and `total_size`. `applications` will be set to an array of application objects, each of which contains the standard application attributes. `total_size` will be set to the total number of items matched by the list request. If there are more items to be returned by the requested query, the response will also contain a key called `next_page_token`.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListApplicationsResponse'
              examples:
                Success:
                  value:
                    applications:
                    - id: 38833c36-6f47-4992-9329-ea0a00915137
                      realm_id: caf2ff640497591a
                      tenant_id: 00011f1183c67b69
                      resource_server_id: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
                      display_name: Pet Application
                      is_managed: false
                      protocol_config:
                        type: oidc
                        allowed_scopes:
                        - pets:read
                        - pets:write
                        client_id: AYYNcuOSpfqIf33JeegCzDIT
                        client_secret: wWD4mPzdsjms1LPekQSo0v9scOHLWy5wmMtKAR2JNhJPAKXv
                        confidentiality: confidential
                        token_endpoint_auth_method: client_secret_post
                        grant_type:
                        - authorization_code
                        redirect_uris:
                        - https://auth.mypetapp.com/callback
                        token_configuration:
                          subject_field: id
                          expires_after: 86400
                          token_signing_algorithm: RS256
                        pkce: disabled
                        token_format: self_contained
                    total_size: 1
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Invalid Parameters:
                  value:
                    code: bad_request
                    message: invalid parameters
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Realm Not Found:
                  value:
                    code: not_found
                    message: The requested resource was not found.
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
  /v1/tenants/{tenant_id}/realms/{realm_id}/applications/{application_id}:
    get:
      operationId: GetApplication
      tags:
      - Applications
      summary: Retrieve an Existing Application
      description: 'To retrieve an existing application, send a GET request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications/$APPLICATION_ID`.

        '
      security:
      - BearerAuth:
        - applications:read
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/application_id'
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with an application.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Application'
              examples:
                Success:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/post/responses/200/content/application~1json/examples/Success'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Application Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
    patch:
      operationId: UpdateApplication
      tags:
      - Applications
      summary: Patch an Application
      description: 'To update only specific attributes of an existing application, send a PATCH request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications/$APPLICATION_ID`. Values in the request body for immutable or read-only fields will be ignored. Fields that are omitted from the request body will be left unchanged.

        '
      security:
      - BearerAuth:
        - applications:update
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/application_id'
      requestBody:
        content:
          application/json:
            schema:
              title: Update Application Request
              description: Request for UpdateApplication.
              type: object
              properties:
                application:
                  $ref: '#/components/schemas/Application'
              required:
              - application
            examples:
              Update Display Name:
                value:
                  application:
                    display_name: Pet Application
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with an application.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Application'
              examples:
                Success:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/post/responses/200/content/application~1json/examples/Success'
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Malformed Request:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/patch/responses/400/content/application~1json/examples/Malformed%20Request'
                Invalid Parameters:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/400/content/application~1json/examples/Invalid%20Parameters'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Application Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
    delete:
      operationId: DeleteApplication
      tags:
      - Applications
      summary: Delete an Application
      description: 'To delete an application, send a DELETE request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications/$APPLICATION_ID`.

        A successful request will receive a 200 status code with no body in the response. This indicates that the request was processed successfully.

        '
      security:
      - BearerAuth:
        - applications:delete
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/application_id'
      responses:
        '200':
          description: The action was successful and the response body is empty.
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Application Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
components:
  schemas:
    SsoConfigPayload:
      oneOf:
      - $ref: '#/components/schemas/SsoConfigBookmark'
      - $ref: '#/components/schemas/SsoConfigEntraIdExternalAuthMethod'
      - $ref: '#/components/schemas/SsoConfigGenericOidc'
      - $ref: '#/components/schemas/SsoConfigOidcIdp'
      - type: object
        required:
        - type
        - acs_url
        - override_recipient_and_destination
        - audience_url
        - default_relay_state
        - name_format
        - authentication_context
        - subject_user_name_attribute
        - sign_envelope
        - sign_assertions
        - signature_algorithm
        - digest_algorithm
        - encrypt_assertions
        - assertion_validity_duration_seconds
        - sp_signature_certificates
        - enable_single_log_out
        - validate_signed_requests
        - additional_user_attributes
        - single_logout_sign_request_and_response
        properties:
          type:
            type: string
            enum:
            - saml
          acs_url:
            description: 'Location where the SAML Response is sent via HTTP-POST. Often referred to as the SAML Assertion Consumer Service (ACS) URL.

              '
            type: string
            example: https://example.com/saml/acs
          override_recipient_and_destination:
            description: 'When this is true, the `recipient_url` and the `destination_url` are used for SAML Response.

              When this is false, both the `recipient_url` and the `destination_url` are omitted and the `acs_url` is used instead.

              '
            type: boolean
            example: true
          recipient_url:
            description: 'If `override_recipient_and_destination` is set to `true`, this field is utilized for the SAML Response. If it is `false`, this field is unused.

              The location where the application may present the SAML assertion. This is usually the same location as the Single Sign-On URL.

              '
            type: string
            example: https://example.com/saml/recipient
          destination_url:
            description: 'If `override_recipient_and_destination` is set to `true`, this field is utilized for the SAML Response. If it is `false`, this field is unused.

              Identifies the location where the SAML response is intended to be sent inside of the SAML assertion.

              '
            type: string
            example: https://example.com/saml/destination
          audience_url:
            description: 'The intended audience of the SAML assertion. Often referred to as the service provider Entity ID.

              '
            type: string
            example: https://example.com/saml/audience
          default_relay_state:
            description: 'Identifies a specific application resource in an IDP initiated Single Sign-On scenario. In most instances this is blank.

              '
            type: string
            example: defaultRelayState
          name_format:
            description: 'Name format of the assertion''s subject statement. Processing rules and constraints can be applied based on selection. Default value is "unspecified" unless SP explicitly requires differently.

              '
            type: string
            enum:
            - unspecified
            - email_address
            - x509_subject_name
            - persistent
            - transient
            - entity
            - kerberos
            - windows_domain_qualifie

# --- truncated at 32 KB (70 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/beyond-identity/refs/heads/main/openapi/beyond-identity-applications-api-openapi.yml