Beyond Identity Resource Servers API

A resource server represents an API server that hosts a set of protected resources and is capable of accepting and responding to protected resource requests using access tokens. Clients can enable these APIs to be consumed from authorized applications.

Operations 5

POST /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers Create a New Resource Server #
GET /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers List Resource Servers For a Realm #
GET /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers/{resource_server_id} Retrieve an Existing Resource Server #
PATCH /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers/{resource_server_id} Patch a Resource Server #
DELETE /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers/{resource_server_id} Delete a Resource Server #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/beyond-identity-resource-servers-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

beyond-identity-resource-servers-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Beyond Identity Secure Access Resource Servers API
  version: 1.7.0
  contact:
    email: support@beyondidentity.com
  description: '# Introduction


    **NOTE:** To determine if you are accessing the Secure Access Platform, check the URL of your Admin Console.'
servers:
- url: https://api-us.beyondidentity.com
  description: US region API base URL
- url: https://api-eu.beyondidentity.com
  description: EU region API base URL
- url: https://api.us1.beyondidentity-gov.com/
  description: US FedRAMP API base URL
security:
- BearerAuth: []
tags:
- name: Resource Servers
  description: A resource server represents an API server that hosts a set of protected resources and is capable of accepting and responding to protected resource requests using access tokens. Clients can enable these APIs to be consumed from authorized applications.
paths:
  /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers:
    post:
      operationId: CreateResourceServer
      tags:
      - Resource Servers
      summary: Create a New Resource Server
      description: To create a resource server, send a POST request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/resource-servers`. Values in the request body for read-only fields will be ignored.
      security:
      - BearerAuth:
        - resource-servers:create
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      requestBody:
        content:
          application/json:
            schema:
              title: Create Resource Server Request
              description: Request for CreateResourceServer.
              type: object
              properties:
                resource_server:
                  $ref: '#/components/schemas/ResourceServer'
              required:
              - resource_server
            examples:
              Create Resource Server:
                value:
                  resource_server:
                    display_name: Pet API
                    identifier: https://api.mypetapp.com
                    scopes:
                    - pets:read
                    - pets:write
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with a resource server.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceServer'
              examples:
                Success:
                  value:
                    id: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
                    realm_id: caf2ff640497591a
                    tenant_id: 00011f1183c67b69
                    display_name: Pet API
                    is_managed: false
                    identifier: https://api.mypetapp.com
                    scopes:
                    - pets:read
                    - pets:write
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Malformed Request:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/patch/responses/400/content/application~1json/examples/Malformed%20Request'
                Invalid Parameters:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/400/content/application~1json/examples/Invalid%20Parameters'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Realm Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
    get:
      operationId: ListResourceServers
      tags:
      - Resource Servers
      summary: List Resource Servers For a Realm
      description: 'To list all resource servers for a realm, send a GET request to

        `/v1/tenants/$TENANT_ID/realms/$REALM_ID/resource-servers`.


        The response will contain at most 100 items and may contain a page token to

        query the remaining items. If page size is not specified, the response will

        contain 100 items. There is no defined ordering of the list of resource

        servers in the response. Note that the maximum and default page sizes are

        subject to change.


        When paginating, the page size is maintained by the page token but may be

        overridden on subsequent requests. The skip is not maintained by the page

        token and must be specified on each subsequent request.


        Page tokens expire after one week. Requests which specify an expired page

        token will result in undefined behavior.'
      security:
      - BearerAuth:
        - resource-servers:read
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/page_size'
      - $ref: '#/components/parameters/page_token'
      responses:
        '200':
          description: 'The response will be a JSON object with a keys for `resource_servers` and `total_size`. `resource_servers` will be set to an array of resource server objects, each of which contains the standard resource server attributes. `total_size` will be set to the total number of items matched by the list request. If there are more items to be returned by the requested query, the response will also contain a key called `next_page_token`.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListResourceServersResponse'
              examples:
                Success:
                  value:
                    resource_servers:
                    - id: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
                      realm_id: caf2ff640497591a
                      tenant_id: 00011f1183c67b69
                      display_name: Pet API
                      is_managed: false
                      identifier: https://api.mypetapp.com
                      scopes:
                      - pets:read
                      - pets:write
                    total_size: 1
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Invalid Parameters:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/400/content/application~1json/examples/Invalid%20Parameters'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Realm Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
  /v1/tenants/{tenant_id}/realms/{realm_id}/resource-servers/{resource_server_id}:
    get:
      operationId: GetResourceServer
      tags:
      - Resource Servers
      summary: Retrieve an Existing Resource Server
      description: To retrieve an existing resource server, send a GET request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/resource-servers/$RESOURCE_SERVER_ID`.
      security:
      - BearerAuth:
        - resource-servers:read
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/resource_server_id'
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with a resource server.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceServer'
              examples:
                Success:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1resource-servers/post/responses/200/content/application~1json/examples/Success'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Resource Server Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
    patch:
      operationId: UpdateResourceServer
      tags:
      - Resource Servers
      summary: Patch a Resource Server
      description: 'To update only specific attributes of an existing resource server, send a a

        PATCH request to

        `/v1/tenants/$TENANT_ID/realms/$REALM_ID/resource-servers/$RESOURCE_SERVER_ID`.

        Values in the request body for immutable or read-only fields will be

        ignored. Fields that are omitted from the request body will be left

        unchanged.


        Scopes that are removed from a resource server will be asynchronously

        removed from all roles associated with the resource server.'
      security:
      - BearerAuth:
        - resource-servers:update
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/resource_server_id'
      requestBody:
        content:
          application/json:
            schema:
              title: Update Resource Server Request
              description: Request for UpdateResourceServer.
              type: object
              properties:
                resource_server:
                  $ref: '#/components/schemas/ResourceServer'
              required:
              - resource_server
            examples:
              Update Display Name:
                value:
                  resource_server:
                    display_name: Pet API
      responses:
        '200':
          description: 'The response will be a JSON object containing the standard attributes associated with a resource server.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResourceServer'
              examples:
                Success:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1resource-servers/post/responses/200/content/application~1json/examples/Success'
        '400':
          description: Bad request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Malformed Request:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/patch/responses/400/content/application~1json/examples/Malformed%20Request'
                Invalid Parameters:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/400/content/application~1json/examples/Invalid%20Parameters'
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Resource Server Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
    delete:
      operationId: DeleteResourceServer
      tags:
      - Resource Servers
      summary: Delete a Resource Server
      description: 'To delete a resource server, send a DELETE request to `/v1/tenants/$TENANT_ID/realms/$REALM_ID/resource-servers/$RESOURCE_SERVER_ID`.

        A successful request will receive a 200 status code with no body in the response. This indicates that the request was processed successfully.'
      security:
      - BearerAuth:
        - resource-servers:delete
      parameters:
      - $ref: '#/components/parameters/tenant_id'
      - $ref: '#/components/parameters/realm_id'
      - $ref: '#/components/parameters/resource_server_id'
      responses:
        '200':
          description: The action was successful and the response body is empty.
        '401':
          description: Unauthorized.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Missing Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/401/content/application~1json/examples/Missing%20Authorization'
        '403':
          description: Forbidden.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Insufficient Authorization:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/403/content/application~1json/examples/Insufficient%20Authorization'
        '404':
          description: The resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Resource Server Not Found:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D~1realms~1%7Brealm_id%7D~1applications/get/responses/404/content/application~1json/examples/Realm%20Not%20Found'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              examples:
                Internal Error:
                  $ref: '#/paths/~1v1~1tenants~1%7Btenant_id%7D/get/responses/500/content/application~1json/examples/Internal%20Error'
components:
  schemas:
    ResourceServer:
      title: Resource Server
      type: object
      description: 'A resource server represents an API server that hosts a set of protected resources and is capable of accepting and responding to protected resource requests using access tokens. Clients can enable these APIs to be consumed from authorized applications.

        '
      properties:
        id:
          type: string
          description: 'A unique identifier for a resource server. This is automatically generated on creation. This field is immutable and read-only. This field is unique within the realm.

            '
          readOnly: true
          example: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
        realm_id:
          type: string
          description: 'A unique identifier for the resource server''s realm. This is automatically set on creation. This field is immutable and read-only.

            '
          readOnly: true
          example: caf2ff640497591a
        tenant_id:
          type: string
          description: 'A unique identifier for the resource server''s tenant. This is automatically set on creation. This field is immutable and read-only.

            '
          readOnly: true
          example: 00011f1183c67b69
        display_name:
          type: string
          description: 'A human-readable name for the resource server. This name is used for display purposes.

            '
          example: Pet API
        is_managed:
          type: boolean
          description: 'A boolean indicating whether the resource server is managed by Beyond Identity. Managed resource servers may not be modified by the user. This is automatically set on creation. This field is immutable and read-only.

            '
          readOnly: true
          example: false
        identifier:
          type: string
          description: 'The identifier of this resource server entity. This value should be unique per realm and is often presented as a URI, as it should be a unique identifier for an API to which access is being gated. This identifier will be returned in the `audience` claim of all tokens minted that provide access to scopes owned by this resource server. The client is responsible for validating tokens are intended for them via this `audience` claim. Tokens minted for the Beyond Identity Management API will use the audience `beyondidentity`, which is reserved and may not be used for any other resource servers.

            '
          example: https://api.mypetapp.com
        scopes:
          type: array
          items:
            type: string
            example: pets:read
          description: 'The list of scopes supported by this resource server. For the Beyond Identity Management API, this will include scopes for all publicly available endpoints.  Note that applications may not provide access to scopes that are not defined on a resource server that they reference; this is the superset of all allowable application scopes in a given realm.

            '
    Error:
      type: object
      properties:
        code:
          type: string
          description: 'Human-readable HTTP status code name, stylized as lower snake case (e.g. bad_request).

            '
        message:
          type: string
          description: 'Human-readable message describing the error.

            '
        details:
          type: array
          items:
            $ref: '#/components/schemas/ErrorDetail'
      required:
      - code
      - message
    ListResourceServersResponse:
      title: List Resource Servers Response
      description: Response for ListResourceServers.
      type: object
      properties:
        resource_servers:
          type: array
          items:
            $ref: '#/components/schemas/ResourceServer'
          maxItems: 100
          description: 'An unordered array of resource servers corresponding to the request.

            '
        total_size:
          type: integer
          format: uint32
          description: 'Total number of results returned by the operation. This value may be larger than the number of resources returned, such as when returning a single page where multiple pages are available.

            '
          example: 1000
        next_page_token:
          type: string
          description: 'Token used to fetch the next set of results. If this field is omitted, there are no subsequent pages.

            '
      required:
      - resource_servers
      - total_size
    ErrorDetail:
      title: Error Detail
      description: 'Additional details for errors designed to support client applications.

        '
      type: object
      discriminator:
        propertyName: type
      properties:
        type:
          type: string
          description: Type of the error detail.
      required:
      - type
  parameters:
    page_size:
      name: page_size
      in: query
      description: 'Number of items returned per page. The response will include at most this many results but may include fewer. If this value is omitted, the response will return the default number of results allowed by the method.

        '
      schema:
        type: integer
        format: uint32
        minimum: 0
    realm_id:
      name: realm_id
      in: path
      description: A unique identifier for a realm.
      required: true
      schema:
        type: string
        example: 19a95130480dfa79
    tenant_id:
      name: tenant_id
      in: path
      description: A unique identifier for a tenant.
      required: true
      schema:
        type: string
        example: 000176d94fd7b4d1
    page_token:
      name: page_token
      in: query
      description: 'Token to retrieve the subsequent page of the previous request. All other parameters to the list endpoint should match the original request that provided this token unless otherwise specified.

        '
      schema:
        type: string
    resource_server_id:
      name: resource_server_id
      in: path
      description: A unique identifier for a resource server.
      required: true
      schema:
        type: string
        example: 84db69f5-48a8-4c11-8cda-1bae3a73f07e
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'See the [Authentication](#section/Authentication) section for details.

        '