Cubist Identity API
The Identity API from Cubist — 4 operation(s) for identity.
The Identity API from Cubist — 4 operation(s) for identity.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/cubist-identity-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: CubeSigner Account Identity API
description: The CubeSigner management and signing service.
contact:
name: Cubist Inc.
email: hello@cubist.dev
version: v0.1.0
servers:
- url: https://gamma.signer.cubist.dev
description: Testing and staging environment
- url: https://prod.signer.cubist.dev
description: Production environment
security:
- Cognito: []
tags:
- name: Identity
paths:
/v0/org/{org_id}/identity:
get:
tags:
- Identity
summary: List associated OIDC identities with the current user.
description: 'List associated OIDC identities with the current user.
'
operationId: listOidcIdentities
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
responses:
'200':
$ref: '#/components/responses/ListIdentitiesResponse'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:identity:list
post:
tags:
- Identity
summary: Associate an OIDC identity with the current user in org <session.org>.
description: 'Associate an OIDC identity with the current user in org <session.org>.
Alien users are allowed to call this endpoint, but for them MFA is required
(unless they are registering an email-otp identity matching their current email);
additionally, limits may apply to how many identities that may register.
'
operationId: addOidcIdentity
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/AddIdentityRequest'
required: true
responses:
'200':
$ref: '#/components/responses/EmptyImpl'
'202':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/AcceptedResponse'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:identity:add
delete:
tags:
- Identity
summary: Remove an OIDC identity from the current user's account in org <session.org>.
description: 'Remove an OIDC identity from the current user''s account in org <session.org>.
'
operationId: removeOidcIdentity
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/OidcIdentity'
required: true
responses:
'200':
$ref: '#/components/responses/EmptyImpl'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:identity:remove
/v0/org/{org_id}/identity/prove:
post:
tags:
- Identity
summary: Create [IdentityProof] from CubeSigner user session
description: 'Create [IdentityProof] from CubeSigner user session
This route can be used to prove to another party that a user has a
valid CubeSigner session.
Clients are intended to call this route and pass the returned evidence
to another service which will verify it by making a request to `/v0/org/<org_id>/identity/verify`.'
operationId: createProofCubeSigner
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
responses:
'200':
$ref: '#/components/responses/IdentityProof'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth: []
/v0/org/{org_id}/identity/prove/oidc:
post:
tags:
- Identity
summary: Create [IdentityProof] from OIDC token
description: 'Create [IdentityProof] from OIDC token
Exchange an OIDC ID token (passed via the `Authorization` header) for a proof of authentication.
This route can be used to prove to another party that a user has met the
authentication requirements (allowed issuers & audiences) for CubeSigner
without leaking their credentials.
Clients are intended to call this route and pass the returned evidence to another service
which will verify it by making a request to `/v0/org/<org_id>/identity/verify`.'
operationId: createProofOidc
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
responses:
'200':
$ref: '#/components/responses/IdentityProof'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- Oidc: []
/v0/org/{org_id}/identity/verify:
post:
tags:
- Identity
summary: Verify identity proof
description: 'Verify identity proof
Allows a third-party to validate proof of authentication.
When a third-party is provided an [IdentityProof] object, they must check its
veracity by calling this endpoint'
operationId: verifyProof
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/IdentityProof'
required: true
responses: {}
security:
- SignerAuth:
- manage:identity:verify
components:
schemas:
OidcIdentity:
type: object
description: 'Represents a globally unique OIDC-authorized user by expressing the full "path" to a user. That is:
(iss) (sub)
Issuer -> Subresource'
required:
- iss
- sub
properties:
iss:
type: string
description: 'The root-level issuer who administrates this user. From the OIDC spec:
Issuer Identifier for the Issuer of the response. The iss
value is a case sensitive URL using the https scheme that contains
scheme, host, and optionally, port number and path components and
no query or fragment components.'
example: https://accounts.google.com
sub:
type: string
description: 'From the OIDC spec:
A locally unique and never reassigned identifier within the Issuer for
the End-User, which is intended to be consumed by the Client, e.g.,
24400320 or AItOawmwtWwcT0k51BayewNvutrJUqsvl6qs7A4. It MUST NOT exceed
255 ASCII characters in length. The sub value is a case sensitive
string.'
example: '10769150350006150715113082367'
PreconditionErrorOwnCodes:
type: string
enum:
- FailOnMfaRequired
- KeyRegionLocked
- KeyRegionChangedRecently
- MfaRegionLocked
- Eth2ProposerSlotTooLow
- Eth2AttestationSourceEpochTooLow
- Eth2AttestationTargetEpochTooLow
- Eth2ConcurrentBlockSigning
- Eth2ConcurrentAttestationSigning
- Eth2MultiDepositToNonGeneratedKey
- Eth2MultiDepositUnknownInitialDeposit
- Eth2MultiDepositWithdrawalAddressMismatch
- ConcurrentSigningWhenTimeLimitPolicyIsDefined
- BabylonEotsConcurrentSigning
- TendermintStateError
- TendermintConcurrentSigning
- MfaApprovalsNotYetValid
BadRequestErrorCode:
type: string
enum:
- GenericBadRequest
- DisallowedAllowRuleReference
- InvalidPaginationToken
- InvalidEmail
- InvalidEmailTemplate
- QueryMetricsError
- InvalidTelegramData
- ValidationError
- WebhookPolicyTimeoutOutOfBounds
- WebhookPolicyDisallowedUrlScheme
- WebhookPolicyDisallowedUrlHost
- WebhookPolicyDisallowedHeaders
- ReservedName
- UserEmailNotConfigured
- EmailPasswordNotFound
- PasswordAuthNotAllowedByInvitation
- OneTimeCodeExpired
- InvalidBody
- InvalidJwt
- InvitationNoLongerValid
- TokenRequestError
- InvalidMfaReceipt
- InvalidMfaPolicyCount
- InvalidMfaPolicyNumAuthFactors
- InvalidMfaPolicyNumAllowedApprovers
- InvalidMfaPolicyGracePeriodTooLong
- InvalidBabylonStakingPolicyParams
- InvalidSuiTxReceiversEmptyAllowlist
- InvalidBtcTxReceiversEmptyAllowlist
- InvalidRequireRoleSessionAllowlist
- InvalidCreateKeyCount
- InvalidDiffieHellmanCount
- OrgInviteExistingUser
- OrgUserAlreadyExists
- OrgNameTaken
- KwkNotFoundInRegion
- OrgIsNotOrgExport
- RoleNameTaken
- PolicyNameTaken
- NameTaken
- ContactNameInvalid
- ContactAddressesInvalid
- ContactLabelInvalid
- ContactModified
- PolicyNotFound
- PolicyVersionNotFound
- PolicyRuleDisallowedByType
- PolicyTypeDisallowed
- PolicyDuplicateError
- PolicyStillAttached
- PolicyModified
- PolicyNotAttached
- AddKeyToRoleCountTooHigh
- InvalidKeyId
- InvalidTimeLockAlreadyInThePast
- InvalidRestrictedScopes
- InvalidUpdate
- InvalidMetadataLength
- InvalidLength
- InvalidKeyMaterialId
- KeyNotFound
- SiweChallengeNotFound
- SiweInvalidRequest
- SiwsChallengeNotFound
- SiwsInvalidRequest
- UserExportDerivedKey
- UserExportPublicKeyInvalid
- NistP256PublicKeyInvalid
- UnableToAccessSmtpRelay
- UserExportInProgress
- RoleNotFound
- InvalidRoleNameOrId
- InvalidMfaReceiptOrgIdMissing
- InvalidMfaReceiptInvalidOrgId
- MfaRequestNotFound
- InvalidKeyType
- InvalidPropertiesForKeyType
- MismatchedKeyPropertiesPatch
- MissingBinanceApiKey
- MissingBybitApiKey
- MissingCoinbaseApiKey
- BinanceKeyMasterMismatch
- BybitAccountMismatch
- InvalidKeyMaterial
- InvalidHexValue
- InvalidBase32Value
- InvalidBase58Value
- InvalidBase64Value
- InvalidSs58Value
- InvalidForkVersionLength
- InvalidEthAddress
- InvalidStellarAddress
- InvalidOrgNameOrId
- InvalidUpdateOrgRequestDisallowedMfaType
- InvalidUpdateOrgRequestEmptyAllowedMfaTypes
- EmailOtpDelayTooShortForRegisterMfa
- InvalidStakeDeposit
- InvalidBlobSignRequest
- InvalidDiffieHellmanRequest
- InvalidSolanaSignRequest
- InvalidEip712SignRequest
- InvalidEip7702SignRequest
- OnlySpecifyOne
- IncompatibleParams
- NoOidcDataInProof
- InvalidEvmSignRequest
- InvalidEth2SignRequest
- InvalidDeriveKeyRequest
- InvalidStakingAmount
- CustomStakingAmountNotAllowedForWrapperContract
- InvalidUnstakeRequest
- InvalidCreateUserRequest
- UserAlreadyExists
- IdpUserAlreadyExists
- CognitoUserAlreadyOrgMember
- UserNotFound
- UserWithEmailNotFound
- PolicyKeyMismatch
- EmptyScopes
- InvalidScopesForRoleSession
- InvalidLifetime
- NoSingleKeyForUser
- InvalidOrgPolicyRule
- SourceIpAllowlistEmpty
- LimitWindowTooLong
- Erc20ContractDisallowed
- EmptyRuleError
- PolicyFieldValidationError
- OptionalListEmpty
- MultipleExclusiveFieldsProvided
- DuplicateFieldEntry
- InvalidRange
- InvalidOrgPolicyRepeatedRule
- InvalidSuiTransaction
- SuiSenderMismatch
- AvaSignHashError
- AvaSignError
- BtcSegwitHashError
- BtcTaprootHashError
- BtcSignError
- TaprootSignError
- Eip712SignError
- InvalidMemberRoleInUserAdd
- InvalidMemberRoleInRecipientAdd
- ThirdPartyUserAlreadyExists
- OidcIdentityAlreadyExists
- UserAlreadyHasIdentity
- ThirdPartyUserNotFound
- DeleteOidcUserError
- DeleteUserError
- SessionRoleMismatch
- InvalidOidcToken
- InvalidOidcIdentity
- OidcIssuerUnsupported
- OidcIssuerNotAllowed
- OidcIssuerNoApplicableJwk
- FidoKeyAlreadyRegistered
- FidoKeySignCountTooLow
- FidoVerificationFailed
- FidoChallengeMfaMismatch
- UnsupportedLegacyCognitoSession
- InvalidIdentityProof
- PaginationDataExpired
- ExistingKeysViolateExclusiveKeyAccess
- ExportDelayTooShort
- ExportWindowTooLong
- InvalidTotpFailureLimit
- InvalidEip191SignRequest
- CannotResendUserInvitation
- InvalidNotificationEndpointCount
- CannotDeletePendingSubscription
- InvalidNotificationUrlProtocol
- EmptyOneOfOrgEventFilter
- EmptyAllExceptOrgEventFilter
- InvalidTapNodeHash
- InvalidOneTimeCode
- MessageNotFound
- MessageAlreadySigned
- MessageRejected
- MessageReplaced
- InvalidMessageType
- EmptyAddress
- InvalidEth2SigningPolicySlotRange
- InvalidEth2SigningPolicyEpochRange
- InvalidEth2SigningPolicyTimestampRange
- InvalidEth2SigningPolicyOverlappingRule
- RpcUrlMissing
- MmiChainIdMissing
- EthersInvalidRpcUrl
- EthersGetTransactionCountError
- InvalidPassword
- BabylonStakingFeePlusDustOverflow
- BabylonStaking
- BabylonStakingIncorrectKey
- BabylonStakingSegwitNonDeposit
- BabylonStakingRegistrationRequiresTaproot
- PsbtSigning
- TooManyResets
- TooManyRequests
- TooManyFailedLogins
- BadBtcMessageSignP2shFlag
- InvalidTendermintRequest
- PolicyVersionMaxReached
- PolicyVersionInvalid
- PolicySecretLimitReached
- PolicySecretTooLarge
- InvalidImportKey
- AlienOwnerInvalid
- EmptyUpdateRequest
- InvalidPolicyReference
- PolicyEngineDisabled
- InvalidWasmPolicy
- CelProgramTooLarge
- InvalidPolicy
- RedundantDerivationPath
- ImportKeyMissing
- InvalidAbiMethods
- BabylonCovSign
- InvalidPolicyLogsRequest
- UserProfileMigrationMultipleEntries
- UserProfileMigrationTooManyItems
- InputTooShort
- InvalidTweakLength
- InvalidCustomChains
- InvalidRpcRequest
MfaRequiredArgs:
type: object
required:
- id
- ids
- org_id
properties:
id:
type: string
description: Always set to first MFA id from `Self::ids`
ids:
type: array
items:
type: string
minLength: 1
description: Non-empty MFA request IDs
org_id:
type: string
description: Organization id
policy_eval_tree:
description: Optional policy evaluation tree (included in signer responses, when requested)
session:
allOf:
- $ref: '#/components/schemas/NewSessionResponse'
IdentityProof:
allOf:
- type: object
description: 'Evidence is used in non-custodial deployments to prove to a third-party that
a user has indeed authenticated with CubeSigner.
This evidence can be obtained by either logging in with an OIDC token or with
a CubeSigner session token. In the latter case, no [Proof::aud] is set.'
required:
- exp_epoch
properties:
aud:
allOf:
- $ref: '#/components/schemas/Aud'
email:
type:
- string
- 'null'
description: The email associated with the user
example: user@email.com
exp_epoch:
$ref: '#/components/schemas/EpochDateTime'
identity:
allOf:
- $ref: '#/components/schemas/OidcIdentity'
preferred_username:
type:
- string
- 'null'
description: The username (if any) associated with the user
example: cubistdev
user_info:
allOf:
- $ref: '#/components/schemas/CubeSignerUserInfo'
- type: object
required:
- id
properties:
id:
type: string
description: An opaque identifier for the proof
description: 'Proof that an end-user provided CubeSigner with a valid auth token
(either an OIDC token or a CubeSigner session token)'
PreconditionErrorCode:
oneOf:
- $ref: '#/components/schemas/PreconditionErrorOwnCodes'
- $ref: '#/components/schemas/PolicyErrorCode'
AcceptedValueCode:
type: string
enum:
- SignDryRun
- BinanceDryRun
- BybitDryRun
- CoinbaseDryRun
- MfaRequired
PolicyErrorOwnCodes:
type: string
enum:
- Inapplicable
- SuiTxReceiversDisallowedTransactionKind
- SuiTxReceiversDisallowedTransferAddress
- SuiTxReceiversDisallowedCommand
- BtcTxDisallowedOutputs
- BtcSignatureExceededValue
- BtcValueOverflow
- BtcSighashTypeDisallowed
- Eip7702AddressMismatch
- EvmTxReceiverMismatch
- EvmTxChainIdMismatch
- EvmTxSenderMismatch
- EvmTxExceededValue
- EvmTxExceededGasCost
- EvmTxGasCostUndefined
- EvmDataDisallowed
- Erc20DataInvalid
- EvmContractAddressUndefined
- EvmContractChainIdUndefined
- EvmDataNotDefined
- EvmDataInvalid
- EvmContractNotInAllowlist
- Erc20ExceededTransferLimit
- Erc20ReceiverMismatch
- Erc20ExceededApproveLimit
- Erc20SpenderMismatch
- EvmFunctionNotInAllowlist
- EvmFunctionCallInvalid
- EvmFunctionCallDisallowedArg
- PolicyDisjunctionError
- PolicyNegationError
- Eth2ExceededMaxUnstake
- Eth2ConcurrentUnstaking
- NotInIpv4Allowlist
- NotInOriginAllowlist
- NotInOperationAllowlist
- InvalidSourceIp
- RawSigningNotAllowed
- DiffieHellmanExchangeNotAllowed
- Eip712SigningNotAllowed
- OidcSourceNotAllowed
- NoOidcAuthSourcesDefined
- AddKeyToRoleDisallowed
- KeysAlreadyInRole
- KeyInMultipleRoles
- KeyAccessError
- RequireRoleSessionKeyAccessError
- BtcMessageSigningNotAllowed
- Eip191SigningNotAllowed
- Eip7702SigningNotAllowed
- TaprootSigningDisallowed
- SegwitSigningDisallowed
- PsbtSigningDisallowed
- BabylonStakingDisallowed
- TimeLocked
- CelPolicyDenied
- BabylonStakingNetwork
- BabylonStakingParamsVersion
- BabylonStakingExplicitParams
- BabylonStakingStakerPk
- BabylonStakingFinalityProviderPk
- BabylonStakingLockTime
- BabylonStakingValue
- BabylonStakingChangeAddress
- BabylonStakingFee
- BabylonStakingWithdrawalAddress
- BabylonStakingBbnAddress
- SolanaInstructionCountLow
- SolanaInstructionCountHigh
- SolanaNotInInstructionAllowlist
- SolanaInstructionMismatch
- WasmPoliciesDisabled
- WasmPolicyDenied
- WasmPolicyFailed
- WebhookPoliciesDisabled
- DeniedByWebhook
- ExplicitlyDenied
IdentityInfo:
allOf:
- $ref: '#/components/schemas/OidcIdentity'
- $ref: '#/components/schemas/OidcUserInfo'
- type: object
description: 'Information about a linked OIDC identity including unique identifiers and user info
(e.g., email)'
AcceptedValue:
oneOf:
- type: object
required:
- SignDryRun
properties:
SignDryRun:
$ref: '#/components/schemas/SignDryRunArgs'
- type: object
required:
- BinanceDryRun
properties:
BinanceDryRun:
$ref: '#/components/schemas/BinanceDryRunArgs'
- type: object
required:
- BybitDryRun
properties:
BybitDryRun:
$ref: '#/components/schemas/BybitDryRunArgs'
- type: object
required:
- CoinbaseDryRun
properties:
CoinbaseDryRun:
$ref: '#/components/schemas/CoinbaseDryRunArgs'
- type: object
required:
- MfaRequired
properties:
MfaRequired:
$ref: '#/components/schemas/MfaRequiredArgs'
description: Different responses we return for success status codes.
Id:
type: string
ForbiddenErrorCode:
type: string
enum:
- AlienKeyCreate
- CannotAssumeIdentity
- SentryDisallowed
- PasskeyLoginDisabled
- PasskeyNotRegistered
- CannotCreateOrg
- WrongMfaEmailOtpJwt
- OrgFlagNotSet
- FidoRequiredToRemoveTotp
- OidcIdentityLimitReached
- OidcScopeCeilingMissing
- OidcIssuerNotAllowedForMemberRole
- OidcNoMemberRolesAllowed
- EmailOtpNotConfigured
- MfaChallengeExpired
- ChainIdNotAllowed
- InvalidOrg
- OrgIdMismatch
- SessionForWrongOrg
- SelfDelete
- SelfDisable
- SelfMfaReset
- InvalidOrgMembershipRoleChange
- UserDisabled
- OrgDisabled
- OrgNotFound
- OrgWithoutOwner
- OrphanedUser
- OidcUserNotFound
- UserNotInOrg
- UserNotOrgOwner
- UserNotKeyOwner
- InvalidRole
- DisabledRole
- KeyDisabled
- KeyNotInRole
- ContactNotInOrg
- UserExportRequestNotInOrg
- UserExportRequestInvalid
- UserExportDisabled
- UserNotOriginalKeyOwner
- UserNotInRole
- MustBeFullMember
- SessionExpired
- SessionChanged
- SessionRevoked
- ExpectedUserSession
- SessionRoleChanged
- ScopedNameNotFound
- SessionInvalidEpochToken
- SessionInvalidRefreshToken
- SessionRefreshTokenExpired
- InvalidAuthHeader
- SessionNotFound
- InvalidArn
- SessionInvalidAuthToken
- SessionAuthTokenExpired
- SessionPossiblyStolenToken
- MfaDisallowedIdentity
- MfaDisallowedApprover
- MfaTypeNotAllowed
- MfaNotApprovedYet
- MfaConfirmationCodeMismatch
- MfaHttpRequestMismatch
- MfaRemoveBelowMin
- MfaOrgRequirementNotMet
- MfaRegistrationDisallowed
- TotpAlreadyConfigured
- TotpConfigurationChanged
- MfaTotpBadConfiguration
- MfaTotpBadCode
- MfaTotpRateLimit
- ImproperSessionScope
- FullSessionRequired
- SessionWithoutAnyScopeUnder
- UserRoleUnprivileged
- MemberRoleForbidden
- MfaNotConfigured
- RemoveLastOidcIdentity
- OperationNotAllowed
- OrgExportRetrievalDisabled
- ChangingKeyExportRequirementIsDisabled
- AutoAddBlsKeyToProtectedRole
- UserNotPolicyOwner
- UserNotContactOwner
- UserNotBucketOwner
- LegacySessionCannotHaveScopeCeiling
- RoleInParentOrgNotAllowed
- RemoveKeyFromRoleUserNotAllowed
- SiweChallengeExpired
- SiweMessageNotValid
- SiweMessageInvalidSignature
- SiwsChallengeExpired
- SiwsDomain
- SiwsMessageInvalid
- Acl
UnauthorizedErrorCode:
type: string
enum:
- AuthorizationHeaderMissing
- EndpointRequiresUserSession
- RefreshTokenMissing
SignerErrorOwnCodes:
type: string
enum:
- PreComputed
- StatusCodeWithMessage
- JrpcError
- UnhandledError
- ProxyStartError
- EnclaveError
- PolicyErrorWithEvalTree
- RpcApi
AddIdentityRequest:
type: object
description: Request to add OIDC identity to an existing user account
required:
- oidc_token
properties:
oidc_token:
type: string
user_id:
allOf:
- $ref: '#/components/schemas/Id'
SignDryRunArgs:
type: object
required:
- mfa_requests
properties:
mfa_requests:
type: array
items:
$ref: '#/components/schemas/MfaRequestInfo'
description: Whether MFA is required
policy_eval_tree:
description: Optional policy evaluation tree, if requested
AcceptedResponse:
allOf:
- $ref: '#/components/schemas/ErrorResponse'
- type: object
EpochDateTime:
type: integer
format: int64
description: 'DateTime measured in seconds since unix epoch.
A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`]
representing the number of seconds since [`SystemTime::UNIX_EPOCH`].'
minimum: 0
B32:
type: string
description: Wrapper around a zeroizing 32-byte fixed-size array
CoinbaseDryRunArgs:
type: object
required:
- method
- url
properties:
method:
type: string
description: The Coinbase API method that would have been used
url:
type: string
description: The Coinbase API url method that would have been called
ErrorResponse:
type: object
description: The structure of ErrorResponse must match the response template that AWS uses
required:
- message
- error_code
properties:
accepted:
allOf:
- $ref: '#/components/schemas/AcceptedValue'
error_code:
$ref: '#/components/schemas/SignerErrorCode'
message:
type: string
description: Error message
policy_eval_tree:
description: Optional policy evaluation tree (included in signer responses, when requested)
request_id:
type: string
description: Optional request identifier
NotFoundErrorCode:
type: string
enum:
- UriSegmentMissing
- UriSegmentInvalid
- TotpNotConfigured
- FidoKeyNotFound
- FidoChallengeNotFound
- TotpChallengeNotFound
- UserExportRequestNotFound
- UserExportCiphertextNotFound
- OrgExportCiphertextNotFound
- UploadObjectNotFound
- PolicySecretNotFound
- BucketMetaNotFound
- TimestreamDisabled
- CustomChainNotFound
- InvitationNotFound
- TransactionNotFound
- EmailConfigNotFound
ConflictErrorCode:
type: string
enum:
- ConcurrentRequestDisallowed
- ConcurrentLockCreation
SignerErrorCode:
oneOf:
- $ref: '#/components/schemas/SignerErrorOwnCodes'
- $ref: '#/components/schemas/AcceptedValueCode'
- $ref: '#/components/schemas/BadRequestErrorCode'
- $ref: '#/components/schemas/BadGatewayErrorCode'
- $ref: '#/components/schemas/NotFoundErrorCode'
- $ref: '#/components/schemas/ForbiddenErrorCode'
- $ref: '#/components/schemas/UnauthorizedErrorCode'
- $ref: '#/components/schemas/PreconditionErrorCode'
- $ref: '#/components/schemas/TimeoutErrorCode'
- $ref: '#/components/schemas/ConflictErrorCode'
- $ref: '#/components/schemas/InternalErrorCode'
BybitDryRunArgs:
type: object
required:
- method
- url
- payload
properties:
method:
type: string
description: The Bybit API method that would have been used
payload:
type: string
description: The request body (for POST endpoints) or query string (for GET endpoints).
url:
type: string
description: The Bybit API url that would have been called
PolicyErrorCode:
oneOf:
- $ref: '#/components/schemas/PolicyErrorOwnCodes'
- $ref: '#/components/schemas/EvmTxDepositErrorCode'
MfaType:
type: string
format: '''CubeSigner'' | ''Fido'' | `FidoKey#${string}` | ''Totp'' | ''EmailOtp'' | `EmailOtp#${number}`'
description: Different types that can be used to approve an MFA request
pattern: ^(CubeSigner|Totp|EmailOtp|EmailOtp#\d+|Fido|FidoKey#[^#\s]+)$
Aud:
oneOf:
- type: string
- type: array
items:
type: string
description: 'Audience(s) that this ID Token is intended for. It MUST contain the
OAuth 2.0 client_id of the Relying Party as an audience value. It MAY also contain
identifiers for other audiences. In the general case, the aud value is an array of
case-sensitive strings. In the common special case when there is one audience,
the aud value MAY be a single case-sensitive string.'
SolanaTxCmp:
type: object
properties:
ignore_blockhash:
type: boolean
description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different.
TimeoutErrorCode:
type: string
enum:
- PolicyEngineTimeout
- WasmPolicyExecutionTimeout
HttpRequest:
type: object
description: 'Information about the request.
Captures all the relevant info (including the request body) about requests that require MFA.
We use this to verify that when a request is resumed (after obtaining necessary MFA approvals)
it is exactly the same as it originally was.'
required:
- method
- path
properties:
body:
type:
- object
- 'null'
description: HTTP request body
method:
type: string
description: HTTP method of the request
path:
type: string
description: HTTP path of the request, excluding the host
HttpRequestCmp:
oneOf:
- type: string
description: The requests must match exactly. Any given MFA receipt can be used at most once.
enum:
- Eq
- type: object
required:
- EvmTx
properties:
EvmTx:
$ref: '#/components/schemas/EvmTxCmp'
- type: object
required:
- SolanaTx
properties:
SolanaTx:
$ref: '#/components/schemas/SolanaTxCmp'
description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request])
EvmTxCmp:
type: object
properties:
grace:
type:
- integer
- 'null'
format: int64
description: 'To prevent replay attacks, any given MFA receipt is normally allowed to be used only once.
In this case, however, because EVM transactions already have a replay prevention mechanism
(namely the ''nonce'' property), we allow the user to specify a grace period (in seconds) to
indicate how long an MFA receipt should remain valid after its first use.
Note that we allow both ''grace'' and ''ignore_nonce'' to be set because once an MFA request
enters its grace period we unconditionally set its ''ignore_nonce'' property to ''false'' to
ensure that any subsequent requests that claim the same receipt must sign for the same
nonce as the request we signed originally with that receipt.
Also note that the grace period cannot extend the lifetime of an MFA request beyond its
original expiration date.
The grace period must not be greater than 30 days.'
minimum: 0
ignore_gas:
type: boolean
descri
# --- truncated at 32 KB (47 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cubist/refs/heads/main/openapi/cubist-identity-api-openapi.yml