Canonical Auth Groups API

The auth_groups API from Canonical — 3 operation(s) for auth_groups.

Operations 8

GET /1.0/auth/groups Get the groups #
POST /1.0/auth/groups Create a new authorization group #
DELETE /1.0/auth/groups/{groupName} Delete the authorization group #
GET /1.0/auth/groups/{groupName} Get the authorization group #
PATCH /1.0/auth/groups/{groupName} Partially update the authorization group #
POST /1.0/auth/groups/{groupName} Rename the authorization group #
PUT /1.0/auth/groups/{groupName} Update the authorization group #
GET /1.0/auth/groups?recursion=1 Get the groups #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/canonical-auth-groups-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

canonical-auth-groups-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: lxd@lists.canonical.com
    name: LXD upstream
    url: https://github.com/canonical/lxd
  description: 'This is the REST API used by all LXD clients.

    Internal endpoints aren''t included in this documentation.


    The LXD API is available over both a local unix+http and remote https API.

    Authentication for local users relies on group membership and access to the unix socket.

    For remote users, the default authentication method is TLS client.'
  license:
    name: AGPL-3.0-only
    url: https://www.gnu.org/licenses/agpl-3.0.en.html
  title: LXD external REST Auth Groups API
  version: '1.0'
tags:
- name: Auth Groups
paths:
  /1.0/auth/groups:
    get:
      description: Returns a list of authorization groups (URLs).
      operationId: auth_groups_get
      responses:
        '200':
          description: API endpoints
          content:
            application/json:
              schema:
                description: Sync response
                properties:
                  metadata:
                    description: List of endpoints
                    example: "[\n  \"/1.0/auth/groups/foo\",\n  \"/1.0/auth/groups/bar\"\n]"
                    items:
                      type: string
                    type: array
                  status:
                    description: Status description
                    example: Success
                    type: string
                  status_code:
                    description: Status code
                    example: 200
                    type: integer
                  type:
                    description: Response type
                    example: sync
                    type: string
                type: object
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the groups
      tags:
      - Auth Groups
    post:
      description: Creates a new authorization group.
      operationId: auth_groups_post
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Create a new authorization group
      tags:
      - Auth Groups
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthGroupsPost'
        description: Group request
        required: true
  /1.0/auth/groups/{groupName}:
    delete:
      description: Deletes the authorization group
      operationId: auth_group_delete
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Delete the authorization group
      tags:
      - Auth Groups
    get:
      description: Gets a specific authorization group.
      operationId: auth_group_get
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                description: Sync response
                properties:
                  metadata:
                    $ref: '#/components/schemas/AuthGroup'
                  status:
                    description: Status description
                    example: Success
                    type: string
                  status_code:
                    description: Status code
                    example: 200
                    type: integer
                  type:
                    description: Response type
                    example: sync
                    type: string
                type: object
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the authorization group
      tags:
      - Auth Groups
    patch:
      description: Updates the editable fields of an authorization group
      operationId: auth_group_patch
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Partially update the authorization group
      tags:
      - Auth Groups
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthGroupPut'
        description: Update request
    post:
      description: Renames the authorization group
      operationId: auth_group_post
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Rename the authorization group
      tags:
      - Auth Groups
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthGroupPost'
        description: Update request
    put:
      description: Replaces the editable fields of an authorization group
      operationId: auth_group_put
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Update the authorization group
      tags:
      - Auth Groups
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthGroupPut'
        description: Update request
  /1.0/auth/groups?recursion=1:
    get:
      description: Returns a list of authorization groups.
      operationId: auth_groups_get_recursion1
      responses:
        '200':
          description: API endpoints
          content:
            application/json:
              schema:
                description: Sync response
                properties:
                  metadata:
                    description: List of auth groups
                    items:
                      $ref: '#/components/schemas/AuthGroup'
                    type: array
                  status:
                    description: Status description
                    example: Success
                    type: string
                  status_code:
                    description: Status code
                    example: 200
                    type: integer
                  type:
                    description: Response type
                    example: sync
                    type: string
                type: object
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the groups
      tags:
      - Auth Groups
components:
  schemas:
    Permission:
      properties:
        entitlement:
          description: Entitlement is the entitlement define for the entity type.
          example: can_view
          type: string
          x-go-name: Entitlement
        entity_type:
          description: EntityType is the string representation of the entity type.
          example: instance
          type: string
          x-go-name: EntityType
        url:
          description: EntityReference is the URL of the entity that the permission applies to.
          example: /1.0/instances/c1?project=default
          type: string
          x-go-name: EntityReference
      title: Permission represents a permission that may be granted to a group.
      type: object
      x-go-package: github.com/canonical/lxd/shared/api
    AuthGroupPost:
      properties:
        name:
          description: Name is the name of the group.
          example: default-c1-viewers
          type: string
          x-go-name: Name
      title: AuthGroupPost is used for renaming a group.
      type: object
      x-go-package: github.com/canonical/lxd/shared/api
    AuthGroup:
      properties:
        access_entitlements:
          description: AccessEntitlements represents the entitlements that are granted to the requesting user on the attached entity.
          example:
          - can_view
          - can_edit
          items:
            type: string
          type: array
          x-go-name: AccessEntitlements
        description:
          description: Description is a short description of the group.
          example: Viewers of instance c1 in the default project
          type: string
          x-go-name: Description
        identities:
          additionalProperties:
            items:
              type: string
            type: array
          description: Identities is a map of authentication method to slice of identity identifiers.
          type: object
          x-go-name: Identities
        identity_provider_groups:
          description: 'IdentityProviderGroups are a list of groups from the IdP whose mapping

            includes this group.'
          example:
          - sales
          - operations
          items:
            type: string
          type: array
          x-go-name: IdentityProviderGroups
        name:
          description: Name is the name of the group.
          example: default-c1-viewers
          type: string
          x-go-name: Name
        permissions:
          description: Permissions are a list of permissions.
          items:
            $ref: '#/components/schemas/Permission'
          type: array
          x-go-name: Permissions
      title: AuthGroup is the type for a LXD group.
      type: object
      x-go-package: github.com/canonical/lxd/shared/api
    AuthGroupsPost:
      properties:
        description:
          description: Description is a short description of the group.
          example: Viewers of instance c1 in the default project
          type: string
          x-go-name: Description
        name:
          description: Name is the name of the group.
          example: default-c1-viewers
          type: string
          x-go-name: Name
        permissions:
          description: Permissions are a list of permissions.
          items:
            $ref: '#/components/schemas/Permission'
          type: array
          x-go-name: Permissions
      title: AuthGroupsPost is used for creating a new group.
      type: object
      x-go-package: github.com/canonical/lxd/shared/api
    AuthGroupPut:
      properties:
        description:
          description: Description is a short description of the group.
          example: Viewers of instance c1 in the default project
          type: string
          x-go-name: Description
        permissions:
          description: Permissions are a list of permissions.
          items:
            $ref: '#/components/schemas/Permission'
          type: array
          x-go-name: Permissions
      title: AuthGroupPut contains the editable fields of a group.
      type: object
      x-go-package: github.com/canonical/lxd/shared/api
  responses:
    BadRequest:
      description: Bad Request
      content:
        application/json:
          schema:
            properties:
              error:
                example: bad request
                type: string
                x-go-name: Error
              error_code:
                example: 400
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object
    EmptySyncResponse:
      description: Empty sync response
      content:
        application/json:
          schema:
            properties:
              status:
                example: Success
                type: string
                x-go-name: Status
              status_code:
                example: 200
                format: int64
                type: integer
                x-go-name: StatusCode
              type:
                example: sync
                type: string
                x-go-name: Type
            type: object
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            properties:
              error:
                example: not authorized
                type: string
                x-go-name: Error
              error_code:
                example: 403
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object
    InternalServerError:
      description: Internal Server Error
      content:
        application/json:
          schema:
            properties:
              error:
                example: internal server error
                type: string
                x-go-name: Error
              error_code:
                example: 500
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object