Beyond Identity Credential Binding Jobs API

A credential binding job defines the state of binding a new credential to an identity. The state includes creation of the credential binding job to delivery of the credential binding method to completion of the credential binding.

OpenAPI Specification

beyond-identity-credential-binding-jobs-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Beyond Identity Secure Access Applications Credential Binding Jobs API
  version: 1.7.0
  contact:
    email: support@beyondidentity.com
  description: "# Introduction\n\n**NOTE:** To determine if you are accessing the Secure Access Platform, check the URL of your Admin Console.\nIf it looks like one of the following, you are using the Secure Access Platform:\n- `https://console.beyondidentity.com` (Localized to your region)\n- `https://console-us.beyondidentity.com` (US region)\n- `https://console-eu.beyondidentity.com` (EU region)\n- `https://console.us1.beyondidentity-gov.com` (US FedRAMP)\n\nIf your Admin Console URL does not look like one of the above, you are using the Secure Workforce Platform. Please refer to the [Secure Workforce API documentation](https://docs.beyondidentity.com/api/v0). <br /><br />\n\nThe Beyond Identity Secure Access API defines methods for managing resources in the Beyond Identity Secure Access platform.<br /><br />\n\nAll of the functionality available in the Beyond Identity Admin Console is\nalso available through the API. <br /><br />\n\nThis API is currently in the early-access stage and is under active\ndevelopment. Feedback and suggestions are encouraged and should be directed\nto the\n[Beyond Identity Developer Slack Channel](https://join.slack.com/t/byndid/shared_invite/zt-1anns8n83-NQX4JvW7coi9dksADxgeBQ).\n\n# Base API URLs\n\nThe base API URLs is determined by the region your tenant is hosted in OR if you are a FedRAMP customer. <br><br>\n\n### US Region\n\nIf you are a US region customer, your base API URLs will be:\n- `https://api-us.beyondidentity.com`\n- `https://auth-us.beyondidentity.com`\n\n### EU Region\n\nIf you are a EU region customer, your base API URLs will be:\n- `https://api-eu.beyondidentity.com`\n- `https://auth-eu.beyondidentity.com`\n\n### US FedRAMP\n\n**NOTE**: The FedRAMP version of Secure Access is released approximately *two weeks* after the commercial version, so some API endpoints may not be available immediately. <br><br>\n\nIf you are a FedRAMP customer in the US region, your base API URLs will be:\n- `https://api.us1.beyondidentity-gov.com`\n- `https://auth.us1.beyondidentity-gov.com`\n\nFor all the examples in this document, we will use the US region API base URL. You can always replace `https://api-us.beyondidentity.com`\nand `https://auth-us.beyondidentity.com` in the examples to use the proper base URL for your tenant.\n\n# Authentication\n\nAll Beyond Identity API endpoints require authentication using an access\ntoken. The access token is generated through OAuth 2.0 or OIDC, using the\nauthorization code flow or the client credentials flow. <br /><br />\n\nThe simplest way to acquire an access token is through the Beyond Identity Admin Console. Under the \"Applications\" tab, select the \"Beyond Identity Management API\" application, navigate to the \"API Tokens\" tab, and then click on \"Create token\". <br /><br />\n\nAlternatively, an access token may also be generated directly via the API by\nrequesting a token for the \"Beyond Identity Management API\" Application. <br><br>\n\n```\ncurl https://auth-us.beyondidentity.com/v1/tenants/$TENANT_ID/realms/$REALM_ID/applications/$APPLICATION_ID/token \\\n  -X POST \\\n  -u \"$CLIENT_ID:$CLIENT_SECRET\" --basic \\\n  -H \"Content-Type: application/x-www-form-urlencoded\" \\\n  -d \"grant_type=client_credentials&scope=$SCOPES\"\n```\n\nThis will work for any application that you have configured to provide\naccess to the Beyond Identity Management API Resource Server. The \"Beyond\nIdentity Management API\" application is provided by default as part of the\ntenant onboarding process.\n\nThe access token must be provided in the `Authorization` header of the\nAPI request. <br><br>\n\n```\ncurl https://api-us.beyondidentity.com/v1/... \\\n  -X $HTTP_METHOD -H \"Authorization: Bearer $TOKEN\"\n```\n\n## Requests and Responses\n\nTo interact with the Beyond Identity API, all requests should be made over\nHTTPS. <br /><br />\n\nThe Beyond Identity API is generally structured as a resource-oriented API.\nResources are represented as JSON objects and are used as both inputs to\nand outputs from API methods. <br /><br />\n\nResource fields may be described as read-only and immutable. A read-only\nfield is only provided on the response. An immutable field is only assigned\nonce and may not be changed after. For example, system-generated IDs are\ndescribed as both read-only and immutable. <br /><br />\n\nTo create a new resource, requests should use the `POST` method. Create\nrequests include all of the necessary attributes to create a new resource.\nCreate operations return the created resource in the response. <br /><br />\n\nTo retrieve a single resource or a collection of resources, requests should\nuse the `GET` method. When retrieving a collection of resources, the\nresponse will include an array of JSON objects keyed on the plural name of\nthe requested resource. <br /><br />\n\nTo update an resource, requests should use the `PATCH` method. Update\noperations support partial updating so requests may specify only the\nattributes which should be updated. Update operations return the updated\nresource in the response. <br /><br />\n\nTo delete a resource, requests should use the `DELETE` method. Note that\ndelete operations return an empty response instead of returning the\nresource in the response. <br /><br />\n\n### Example Response for a Realm\n\n```\n{\n  \"id\": \"a448fe493e02fa9f\",\n  \"tenant_id\": \"000168dc50bdce49\",\n  \"display_name\": \"Test Realm\",\n  \"create_time\": \"2022-06-22T21:46:08.930278Z\",\n  \"update_time\": \"2022-06-22T21:46:08.930278Z\"\n}\n```\n\n### Example Response for a Collection of Realms\n\n```\n{\n  \"realms\": [\n    {\n      \"id\": \"a448fe493e02fa9f\",\n      \"tenant_id\": \"000168dc50bdce49\",\n      \"display_name\": \"Test Realm\",\n      \"create_time\": \"2022-06-22T21:46:08.930278Z\",\n      \"update_time\": \"2022-06-22T21:46:08.930278Z\"\n    }\n  ],\n  \"total_size\": 1\n}\n```\n\n## HTTP Statuses\n\nThe API returns standard HTTP statuses and error codes.\n\nStatuses in the 200 range indicate that the request was successfully\nfulfilled and there were no errors. <br><br>\n\nStatuses in the 400 range indicate that there was an issue with the request\nthat may be addressed by the client. For example, client errors may\nindicate that the request was missing proper authorization or that the\nrequest was malformed. <br><br>\n\nStatuses in the 500 range indicate that the server encountered an internal\nissue and was unable to fulfill the request. <br><br>\n\nAll error responses include a JSON object with a `code` field and a\n`message` field. `code` contains a human-readable name for the HTTP status\ncode and `message` contains a high-level description of the error. The\nerror object may also contain additional error details which may be used by\nthe client to determine the exact cause of the error. Refer to each API\nmethod's examples to determine the specific error detail types supported\nfor that method. <br><br>\n\n### Invalid Access Token Example\n\nIf the provided access token is invalid, you will receive a 401 error.\nThis error indicates that the token is not recognized and was not generated\nby Beyond Identity. <br><br>\n\n```\nHTTP/1.1 401 Unauthorized\n{\n  \"code\": \"unauthorized\",\n  \"message\": \"unauthorized\"\n}\n```\n\n### Permission Denied Example\n\nIf the provided access token does not have access to the requested resource,\nyou will receive a 403 error. Access tokens are scoped at a minimum to your\ntenant. Any request for resources outside of your tenant will result in this\nerror. <br><br>\n\n```\nHTTP/1.1 403 Forbidden\n{\n  \"code\": \"forbidden\",\n  \"message\": \"forbidden\"\n}\n```\n\n### Missing Resource Example\n\nIf the requested resource does not exist, you will receive a 404 error. The\nspecific API method may return additional details about the missing\nresource. <br><br>\n\n```\nHTTP/1.1 404 Not Found\n{\n  \"code\": \"not_found\",\n  \"message\": \"group not found\"\n  \"details\": [\n    {\n      \"type\": \"ResourceInfo\",\n      \"resource_type\": \"Group\",\n      \"id\": \"4822738be6b7f658\",\n      \"description\": \"group not found\"\n    }\n  ],\n}\n```\n\n### Invalid Parameters Example\n\nIf the request body contains invalid parameters, you will receive a 400\nerror. The specific API method may return additional details about the\ninvalid parameter. <br><br>\n\n```\nHTTP/1.1 400 Bad Request\n{\n  \"code\": \"bad_request\",\n  \"message\": \"invalid parameters\"\n  \"details\": [\n    {\n      \"type\": \"FieldViolations\"\n      \"field_violations\": [\n        {\n          \"description\": \"missing\",\n          \"field\": \"group.display_name\"\n        }\n      ],\n    }\n  ],\n}\n```\n"
servers:
- url: https://api-us.beyondidentity.com
  description: US region API base URL
- url: https://api-eu.beyondidentity.com
  description: EU region API base URL
- url: https://api.us1.beyondidentity-gov.com/
  description: US FedRAMP API base URL
security:
- BearerAuth: []
tags:
- name: Credential Binding Jobs
  description: 'A credential binding job defines the state of binding a new credential to an identity. The state includes creation of the credential binding job to delivery of the credential binding method to completion of the credential binding.

    '
paths:
  /v1/tenants/{tenant_id}/realms/{realm_id}/identities/{identity_id}/credential-binding-jobs:
    post:
      tags:
      - Credential Binding Jobs
      operationId: CreateCredentialBindingJob
      summary: Create a New Credential Binding Job
      description: 'To create an identity, send a POST request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/identities/$IDENTITY_ID/credential-binding-jobs`. Values in the request body for read-only fields will be ignored.

        '
      security:
      - BearerAuth:
        - credential-binding-jobs:create
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/identity_id'
      requestBody:
        description: Credential binding job to be created.
        content:
          application/json:
            schema:
              title: Create credential binding job request
              description: Request for CreateCredentialBindingJob.
              type: object
              properties:
                job:
                  $ref: '#/components/schemas/CredentialBindingJob'
              required:
              - job
            examples:
              Create Credential Binding Job:
                value:
                  job:
                    delivery_method: RETURN
                    post_binding_redirect_uri: http://example.com/callback
                    authenticator_config_id: 67bb0acf12e5c899
      responses:
        '200':
          description: 'The response will be a JSON object with a key called `credential_binding_job`. The value of this will be an object containing the standard attributes associated with a credential binding job. If the `delivery_method` of the credential binding job is `RETURN`, the response will also contain a key called `credential_binding_link` that contains a link to facilitate the credential binding process.

            '
          content:
            application/json:
              schema:
                title: Create Credential Binding Job Response
                description: Response for CreateCredentialBindingJob.
                type: object
                properties:
                  credential_binding_job:
                    $ref: '#/components/schemas/CredentialBindingJob'
                  credential_binding_link:
                    type: string
                    description: 'A unique URL to be delivered to an identity to facilitate the credential binding process.  This field is only present if the credential binding job''s `delivery_method` is `RETURN`.

                      '
                required:
                - credential_binding_job
              examples:
                Delivery Method Return:
                  value:
                    credential_binding_job:
                      id: c4fc2d753ca22b14
                      realm_id: cdf4862dc4d49791
                      tenant_id: 000183a77dd50fa9
                      identity_id: 87fabad6956c6d4b
                      delivery_method: RETURN
                      state: LINK_SENT
                      post_binding_redirect_uri: http://example.com/callback
                      authenticator_config_id: 67bb0acf12e5c899
                      expire_time: '2022-03-21T03:42:52.905657Z'
                      create_time: '2022-03-14T03:42:52.905657Z'
                      update_time: '2022-03-15T05:55:23.823187Z'
                    credential_binding_link: http://example.com/v1/tenants/000183a77dd50fa9/realms/cdf4862dc4d49791/identities/87fabad6956c6d4b/credential-binding-jobs/c4fc2d753ca22b14:invokeAuthenticator?token=1St9IKIIrYyQ8sOSeuk5UkbLKnBJhuD4I7nWIqt-BNANDEFS-XVuOHxB7TFdZcRm
                Delivery Method Email:
                  value:
                    credential_binding_job:
                      id: c4fc2d753ca22b14
                      realm_id: cdf4862dc4d49791
                      tenant_id: 000183a77dd50fa9
                      identity_id: 87fabad6956c6d4b
                      delivery_method: EMAIL
                      state: LINK_SENT
                      post_binding_redirect_uri: http://example.com/callback
                      authenticator_config_id: 67bb0acf12e5c899
                      expire_time: '2022-03-21T03:42:52.905657Z'
                      create_time: '2022-03-14T03:42:52.905657Z'
                      update_time: '2022-03-15T05:55:23.823187Z'
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Malformed Request:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/patch/responses/400/content/application~1json/examples/Malformed%20Request'
                Invalid Parameters:
                  value:
                    code: bad_request
                    message: invalid parameters
                    details:
                    - type: FieldViolations
                      field_violations:
                      - field: job.authenticator_config_id
                        description: empty string
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceInfo'
              examples:
                Identity Not Found:
                  value:
                    code: not_found
                    message: identity not found
                    details:
                    - type: ResourceInfo
                      resource_type: Identity
                      id: 51c3c2d2907d6b40
                      description: identity not found
        '422':
          description: Unprocessable entity.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Identity Missing Email Address:
                  value:
                    code: unprocessable_entity
                    message: Identity missing email address
                    details:
                    - type: ResourceInfo
                      resource_type: Identity
                      id: 69f4d38f840c13ab
                      description: Identity missing email address
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
        '503':
          description: Service unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
    get:
      tags:
      - Credential Binding Jobs
      operationId: ListCredentialBindingJobs
      summary: List Credential Binding Jobs for an Identity
      description: 'To list all credential binding jobs for an identity, send a GET request to

        `/v1/tenants/$TENANT_ID/realms/$REALM_ID/identities/$IDENTITY_ID/credential-binding-jobs`.

        `$IDENTITY_ID` may be a wildcard (`-`) to request all credential binding

        jobs across all identities within the realm.


        The response will contain at most 200 items and may contain a page token to

        query the remaining items. If page size is not specified, the response will

        contain 20 items. There is no defined ordering of the list of credential

        binding jobs in the response. Note that the maximum and default page sizes

        are subject to change.


        When paginating, the page size is maintained by the page token but may be

        overridden on subsequent requests. The skip is not maintained by the page

        token and must be specified on each subsequent request.


        Page tokens expire after one week. Requests which specify an expired page

        token will result in undefined behavior.

        '
      security:
      - BearerAuth:
        - credential-binding-jobs:read
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/identity_id'
      - $ref: '#/components/parameters/page_size'
      - $ref: '#/components/parameters/page_token'
      - $ref: '#/components/parameters/skip'
      responses:
        '200':
          description: 'The response will be a JSON object with keys for `credential_binding_jobs` and `total_size`. `credential_binding_jobs` will be set to an array of credential binding job objects, each of which contains the standard credential binding job attributes. `total_size` will be set to the total number of items matched by the list request. If there are more items to be returned by the requested query, the response will also contain a key called `next_page_token`.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListCredentialBindingJobsResponse'
              examples:
                Success:
                  value:
                    credential_binding_jobs:
                    - id: 81490afab171aef0
                      identity_id: e85de356dc78843a
                      realm_id: 7df92e4a38ba0993
                      tenant_id: 0001b42d80372976
                      credential_id: 9802966246819b35
                      delivery_method: EMAIL
                      state: COMPLETE
                      post_binding_redirect_uri: http://example.com/callback
                      authenticator_config_id: 67bb0acf12e5c899
                      expire_time: '2022-03-21T03:42:52.905657Z'
                      create_time: '2022-03-14T03:42:52.905657Z'
                      update_time: '2022-03-15T05:55:23.823187Z'
                    total_size: 1
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Invalid Parameters:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms/get/responses/400/content/application~1json/examples/Invalid%20Parameters'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
  /v1/tenants/{tenant_id}/realms/{realm_id}/identities/{identity_id}/credential-binding-jobs/{credential_binding_job_id}:
    get:
      tags:
      - Credential Binding Jobs
      operationId: GetCredentialBindingJob
      summary: Retrieve an Existing Credential Binding Job
      description: 'To retrieve an existing credential binding job, send a GET request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/identities/$IDENTITY_ID/credential-binding-jobs/$CREDENTIAL_BINDING_JOB_ID`.

        '
      security:
      - BearerAuth:
        - credential-binding-jobs:read
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/identity_id'
      - $ref: '#/components/parameters/credential_binding_job_id'
      - name: filter
        in: query
        description: 'Filter to constrain the response. The response will only include resources matching this filter. Filters follow the SCIM grammar from [RFC-7644 Section 3.4.2.2](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2). Supported filters attributes:

          `state`: the state of the credential binding job.

          `delivery_method`: the delivery method used for the credential binding job.

          '
        schema:
          type: string
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with a credential binding job.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CredentialBindingJob'
              examples:
                Success:
                  value:
                    id: 81490afab171aef0
                    identity_id: e85de356dc78843a
                    realm_id: 7df92e4a38ba0993
                    tenant_id: 0001b42d80372976
                    credential_id: 9802966246819b35
                    delivery_method: EMAIL
                    state: COMPLETE
                    post_binding_redirect_uri: http://example.com/callback
                    authenticator_config_id: 67bb0acf12e5c899
                    expire_time: '2022-03-21T03:42:52.905657Z'
                    create_time: '2022-03-14T03:42:52.905657Z'
                    update_time: '2022-03-15T05:55:23.823187Z'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Credential Binding Job Not Found:
                  value:
                    code: not_found
                    message: credential binding job not found
                    details:
                    - type: ResourceInfo
                      resource_type: CredentialBindingJob
                      id: 3103ba9a652b755e
                      description: credential binding job not found
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
  ? /v1/tenants/{tenant_id}/realms/{realm_id}/identities/{identity_id}/credential-binding-jobs/{credential_binding_job_id}:revoke
  : post:
      tags:
      - Credential Binding Jobs
      operationId: SetCredentialBindingJobRevoked
      summary: Revocation of an active credential binding job.
      description: 'To revoke an active credential binding job, send a POST request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/identities/$IDENTITY_ID/credential-binding-jobs/$CREDENTIAL_BINDING_JOB_ID:revoke`.

        This endpoint invalidates a pending credential binding job, preventing a credential from being enrolled for the associated identity. If the specified job has already been completed, the revocation attempt will fail.

        '
      security:
      - CredentialAuth:
        - credential-binding-jobs:revoke
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/identity_id'
      - $ref: '#/components/parameters/credential_binding_job_id'
      requestBody:
        content:
          application/json:
            schema:
              title: Bind Credential Request
              description: 'Request for `SetCredentialBindingJobRevoked`. This request body is empty.

                '
              type: object
      responses:
        '200':
          description: Credential binding job was successfully revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CredentialBindingJob'
        '400':
          description: 'Bad request. If the request failed due to invalid fields, the error details will include a FieldViolations.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: 'Permission denied. The error details will include a ResourceInfo describing the authorization failure.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: 'Not found. The error details will include a ResourceInfo describing the required resource that was not found.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: 'Conflict. The error details will include a ResourceInfo describing the required resource that is conflicting.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /v1/tenants/{tenant_id}/realms/{realm_id}/batch-credential-binding-jobs:
    post:
      tags:
      - Credential Binding Jobs
      operationId: CreateBatchCredentialBindingJob
      summary: Create a New Batch Credential Binding Job
      description: 'To create a new batch credential binding job, send a POST request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/batch-credential-binding-jobs`.

        Values in the request body for read-only fields will be ignored.

        A maximum of 1000 credential binding jobs can be created in a single batch.

        Each realm can have up to 1000 credential binding jobs in the batch queue at any given time.

        '
      security:
      - BearerAuth:
        - credential-binding-jobs:create
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      requestBody:
        description: Batch credential binding job to be created.
        content:
          application/json:
            schema:
              title: Create Batch Credential Binding Job Request
              description: Request for CreateBatchCredentialBindingJob.
              type: object
              properties:
                batch_credential_binding_job:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1batch-credential-binding-jobs/post/responses/200/content/application~1json/schema'
              required:
              - batch_credential_binding_job
            examples:
              Create Batch Credential Binding Job:
                value:
                  batch_credential_binding_job:
                    identity_ids:
                    - 3d227b0d5949969d
                    - a3f28b7c9e6d1234
                    - 5c90d2af18e47b0e
                    job_template:
                      authenticator_config_id: 67bb0acf12e5c899
                      post_binding_redirect_uri: http://example.com/callback
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with a credential binding job.

            '
          content:
            application/json:
              schema:
                title: BatchCredentialBindingJob
                description: 'A batch credential binding job manages the binding of credentials for multiple identities in a batch operation.

                  '
                type: object
                required:
                - identity_ids
                - job_template
                properties:
                  id:
                    type: string
                    description: 'ID of the batch credential binding job. This is automatically generated on creation. This field is immutable and output-only.

                      '
                    readOnly: true
                  tenant_id:
                    type: string
                    description: 'ID of the tenant associated with the batch credential binding job. This is automatically set on creation. This field is immutable and output-only.

                      '
                    minLength: 1
                    readOnly: true
                  realm_id:
                    type: string
                    description: 'ID of the realm associated with the batch credential binding job. This is automatically set on creation. This field is immutable and output-only.

                      '
                    minLength: 1
                    readOnly: true
                  identity_ids:
                    type: array
                    description: 'The list of identities associated with the batch credential binding job.

                      '
                    items:
                      type: string
                      m

# --- truncated at 32 KB (73 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/beyond-identity/refs/heads/main/openapi/beyond-identity-credential-binding-jobs-api-openapi.yml