Cubist MFA API

The MFA API from Cubist — 5 operation(s) for mfa.

OpenAPI Specification

cubist-mfa-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: CubeSigner Account MFA API
  description: The CubeSigner management and signing service.
  contact:
    name: Cubist Inc.
    email: hello@cubist.dev
  version: v0.1.0
servers:
- url: https://gamma.signer.cubist.dev
  description: Testing and staging environment
- url: https://prod.signer.cubist.dev
  description: Production environment
security:
- Cognito: []
tags:
- name: MFA
paths:
  /v0/org/{org_id}/mfa:
    get:
      tags:
      - MFA
      summary: List Pending MFA Requests
      description: 'List Pending MFA Requests


        Retrieves and returns all pending MFA requests that are accessible to the current session,

        i.e., those created by the current session identity plus those in which the current user

        is listed as an approver


        NOTE that if pagination is used and a page limit is set, the returned result

        set may contain either FEWER or MORE elements than the requested page limit.'
      operationId: mfaList
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: page.size
        in: query
        description: 'Max number of items to return per page.


          If the actual number of returned items may be less that this, even if there exist more

          data in the result set. To reliably determine if more data is left in the result set,

          inspect the [UnencryptedLastEvalKey] value in the response object.'
        required: false
        schema:
          type: integer
          format: int32
          default: 1000
          maximum: 10001
          minimum: 1
        style: form
      - name: page.start
        in: query
        description: 'The start of the page.  Omit to start from the beginning; otherwise, only specify a

          the exact value previously returned as ''last_evaluated_key'' from the same endpoint.'
        required: false
        schema:
          type: string
          nullable: true
        style: form
      responses:
        '200':
          $ref: '#/components/responses/PaginatedListMfaResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:list
  /v0/org/{org_id}/mfa/{mfa_id}:
    get:
      tags:
      - MFA
      summary: Get Pending MFA Request
      description: 'Get Pending MFA Request


        Retrieves and returns a pending MFA request by its id.'
      operationId: mfaGet
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      responses:
        '200':
          $ref: '#/components/responses/MfaRequestInfo'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth: []
    patch:
      tags:
      - MFA
      summary: Approve or Reject MFA Request
      description: 'Approve or Reject MFA Request


        Approve or reject request after logging in with CubeSigner.


        If approving, adds the currently-logged user as an approver

        of a pending MFA request of the [Status::RequiredApprovers] kind. If the required number of

        approvers is reached, the MFA request is approved; the confirmation receipt can be used to

        resume the original HTTP request.


        If rejecting, immediately deletes the pending MFA request.'
      operationId: mfaVoteCs
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_vote
        in: query
        required: false
        schema:
          allOf:
          - $ref: '#/components/schemas/MfaVote'
          nullable: true
        style: form
      responses:
        '200':
          $ref: '#/components/responses/MfaRequestInfo'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:vote:cs
  /v0/org/{org_id}/mfa/{mfa_id}/email:
    post:
      tags:
      - MFA
      summary: Initiate an Email OTP MFA Approval/Rejection
      description: 'Initiate an Email OTP MFA Approval/Rejection


        Initiates the approval/rejection process of an MFA Request using Email OTP.'
      operationId: mfaEmailInit
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_vote
        in: query
        required: false
        schema:
          allOf:
          - $ref: '#/components/schemas/MfaVote'
          nullable: true
        style: form
      responses:
        '200':
          $ref: '#/components/responses/EmailOtpResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:vote:email
    patch:
      tags:
      - MFA
      summary: Finalize a Email OTP MFA Approval/Rejection.
      description: 'Finalize a Email OTP MFA Approval/Rejection.


        The request should contain the full JWT obtained by concatenating the

        partial token returned by the `mfa_email_init` endpoint and the signature

        emailed to the user issuing the request.


        If approving, adds an approver to a pending MFA request.

        If the required number of approvers is reached, the MFA request is approved;

        the confirmation receipt can be used to resume the original HTTP request.


        If rejecting, immediately deletes the pending MFA request.'
      operationId: mfaVoteEmailComplete
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EmailOtpAnswer'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/MfaRequestInfo'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:vote:email
  /v0/org/{org_id}/mfa/{mfa_id}/fido:
    post:
      tags:
      - MFA
      summary: Initiate a FIDO MFA Approval/Rejection
      description: 'Initiate a FIDO MFA Approval/Rejection


        Initiates the approval/rejection process of an MFA Request using FIDO.'
      operationId: mfaFidoInit
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      responses:
        '200':
          $ref: '#/components/responses/FidoAssertChallenge'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:vote:fido
    patch:
      tags:
      - MFA
      summary: Finalize a FIDO MFA Approval/Rejection
      description: 'Finalize a FIDO MFA Approval/Rejection


        If approving, adds an approver to a pending MFA request.

        If the required number of approvers is reached, the MFA request is approved;

        the confirmation receipt can be used to resume the original HTTP request.


        If rejecting, immediately deletes the pending MFA request.'
      operationId: mfaVoteFidoComplete
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_vote
        in: query
        required: false
        schema:
          allOf:
          - $ref: '#/components/schemas/MfaVote'
          nullable: true
        style: form
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/FidoAssertAnswer'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/MfaRequestInfo'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:vote:fido
  /v0/org/{org_id}/mfa/{mfa_id}/totp:
    patch:
      tags:
      - MFA
      summary: Approve/Reject a TOTP MFA Request
      description: 'Approve/Reject a TOTP MFA Request


        If approving, adds the current user as approver to a pending MFA request by

        providing TOTP code. If the required number of approvers is reached, the MFA request is

        approved; the confirmation receipt can be used to resume the original HTTP request.


        If rejecting, immediately deletes the pending MFA request.'
      operationId: mfaVoteTotp
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_id
        in: path
        description: Name or ID of the desired MfaRequest
        required: true
        schema:
          type: string
        example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: mfa_vote
        in: query
        required: false
        schema:
          allOf:
          - $ref: '#/components/schemas/MfaVote'
          nullable: true
        style: form
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TotpApproveRequest'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/MfaRequestInfo'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:mfa:vote:totp
components:
  schemas:
    EpochDateTime:
      type: integer
      format: int64
      description: 'DateTime measured in seconds since unix epoch.

        A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`]

        representing the number of seconds since [`SystemTime::UNIX_EPOCH`].'
      minimum: 0
    UserVerificationRequirement:
      type: string
      description: 'A WebAuthn Relying Party may require user verification for some of its

        operations but not for others, and may use this type to express its needs.


        https://www.w3.org/TR/webauthn-2/#enum-userVerificationRequirement'
      enum:
      - required
      - discouraged
      - preferred
    MfaRequiredArgs:
      type: object
      required:
      - id
      - ids
      - org_id
      properties:
        id:
          type: string
          description: Always set to first MFA id from `Self::ids`
        ids:
          type: array
          items:
            type: string
            minLength: 1
          description: Non-empty MFA request IDs
        org_id:
          type: string
          description: Organization id
        policy_eval_tree:
          description: Optional policy evaluation tree (included in signer responses, when requested)
          nullable: true
        session:
          allOf:
          - $ref: '#/components/schemas/NewSessionResponse'
          nullable: true
    B32:
      type: string
      description: Wrapper around a zeroizing 32-byte fixed-size array
    PublicKeyCredential:
      type: object
      description: 'This type represents a wire-encodable form of the PublicKeyCredential interface

        Clients may need to manually encode into this format to communicate with the server


        The PublicKeyCredential interface inherits from Credential

        [CREDENTIAL-MANAGEMENT-1], and contains the attributes that are returned to

        the caller when a new credential is created, or a new assertion is

        requested.


        https://www.w3.org/TR/webauthn-2/#iface-pkcredential'
      required:
      - id
      - response
      properties:
        clientExtensionResults:
          type: object
          description: 'This internal slot contains the results of processing client extensions

            requested by the Relying Party upon the Relying Party''s invocation of

            either navigator.credentials.create() or navigator.credentials.get().


            https://www.w3.org/TR/webauthn-2/#dom-publickeycredential-clientextensionsresults-slot


            IMPLEMENTATION NOTE: The type for this field comes from the type of getClientExtensionResults() which as the following doc:


            This operation returns the value of [[clientExtensionsResults]], which is a map containing extension identifier → client extension output entries produced by the extension’s client extension processing.

            https://www.w3.org/TR/webauthn-2/#ref-for-dom-publickeycredential-getclientextensionresults


            '
          nullable: true
        id:
          type: string
          description: 'This internal slot contains the credential ID, chosen by the

            authenticator. The credential ID is used to look up credentials for use,

            and is therefore expected to be globally unique with high probability

            across all credentials of the same type, across all authenticators.


            https://www.w3.org/TR/webauthn-2/#dom-publickeycredential-identifier-slot'
        response:
          oneOf:
          - $ref: '#/components/schemas/AuthenticatorAttestationResponse'
          - $ref: '#/components/schemas/AuthenticatorAssertionResponse'
          description: Authenticators respond to Relying Party requests by returning an object derived from the AuthenticatorResponse interface
    EmailOtpAnswer:
      type: object
      description: An answer to the challenge returned by the `mfa_email_init` endpoint.
      required:
      - token
      properties:
        token:
          type: string
          description: 'Full JWT token, constructed by concatenating the "partial token"

            (i.e., `{header}.{payload}.`) returned by the `mail_email_init` endpoint

            and the signature sent to the user''s email.'
    AcceptedValue:
      oneOf:
      - type: object
        required:
        - SignDryRun
        properties:
          SignDryRun:
            $ref: '#/components/schemas/SignDryRunArgs'
      - type: object
        required:
        - BinanceDryRun
        properties:
          BinanceDryRun:
            $ref: '#/components/schemas/BinanceDryRunArgs'
      - type: object
        required:
        - BybitDryRun
        properties:
          BybitDryRun:
            $ref: '#/components/schemas/BybitDryRunArgs'
      - type: object
        required:
        - CoinbaseDryRun
        properties:
          CoinbaseDryRun:
            $ref: '#/components/schemas/CoinbaseDryRunArgs'
      - type: object
        required:
        - MfaRequired
        properties:
          MfaRequired:
            $ref: '#/components/schemas/MfaRequiredArgs'
      description: Different responses we return for success status codes.
    NotFoundErrorCode:
      type: string
      enum:
      - UriSegmentMissing
      - UriSegmentInvalid
      - TotpNotConfigured
      - FidoKeyNotFound
      - FidoChallengeNotFound
      - TotpChallengeNotFound
      - UserExportRequestNotFound
      - UserExportCiphertextNotFound
      - OrgExportCiphertextNotFound
      - UploadObjectNotFound
      - PolicySecretNotFound
      - BucketMetaNotFound
      - TimestreamDisabled
      - CustomChainNotFound
      - InvitationNotFound
      - TransactionNotFound
      - EmailConfigNotFound
    HttpRequestCmp:
      oneOf:
      - type: string
        description: The requests must match exactly. Any given MFA receipt can be used at most once.
        enum:
        - Eq
      - type: object
        required:
        - EvmTx
        properties:
          EvmTx:
            $ref: '#/components/schemas/EvmTxCmp'
      - type: object
        required:
        - SolanaTx
        properties:
          SolanaTx:
            $ref: '#/components/schemas/SolanaTxCmp'
      description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request])
    AuthenticatorAssertionResponse:
      type: object
      description: 'Represents the assertion response used by clients when attempting to log in with a known credential

        https://www.w3.org/TR/webauthn-2/#authenticatorassertionresponse'
      required:
      - clientDataJSON
      - authenticatorData
      - signature
      properties:
        authenticatorData:
          type: string
          description: 'Contains the standard CTAP2 authenticator data. Must be a valid [`AuthenticatorData`].

            This contains information about how key was invoked.

            https://www.w3.org/TR/webauthn-2/#dom-authenticatorassertionresponse-authenticatordata'
        clientDataJSON:
          type: string
          description: 'Contains UTF8 encoded JSON which must be a valid [`ClientData`]

            This data is combined with `authenticator_data` to produce the signature

            meaning the client attests to the correctness of this data.

            https://www.w3.org/TR/webauthn-2/#dom-authenticatorresponse-clientdatajson'
        signature:
          type: string
          description: 'The signature of the concatenated `authenticatorData || hash` where

            `hash` is the SHA256 hash of the `clientDataJSON` buffer:


            Field Definition: https://www.w3.org/TR/webauthn-2/#dom-authenticatorassertionresponse-signature

            Step 11 of `getAssertion` specifies the concatenation: https://www.w3.org/TR/webauthn-2/#sctn-op-get-assertion

            Requirement for SHA-256: https://www.w3.org/TR/webauthn-2/#collectedclientdata-hash-of-the-serialized-client-data'
        userHandle:
          type: string
          description: 'Allows the authenticator to optionally declare the credential identifier they used.

            https://www.w3.org/TR/webauthn-2/#dom-authenticatorassertionresponse-userhandle'
          nullable: true
    SolanaTxCmp:
      type: object
      properties:
        ignore_blockhash:
          type: boolean
          description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different.
    ChallengePieces:
      type: object
      description: Describes how to derive a WebAuthn challenge value.
      required:
      - preimage
      - random_seed
      properties:
        preimage:
          type: string
          description: 'A base64url encoding of UTF8 JSON. The data in that JSON is endpoint specific, and describes what this FIDO challenge will be used for.


            Clients can use `preimage` along with `random_seed` to reconstruct the challenge like so:


            `challenge = HMAC-SHA256(key=random_seed, message=preimage)`'
        random_seed:
          type: string
          description: A random seed that prevents replay attacks
    BadGatewayErrorCode:
      type: string
      enum:
      - Generic
      - CustomChainRpcError
      - EsploraApiError
      - SentryApiError
      - CallWebhookError
      - OAuthProviderError
      - OidcDisoveryFailed
      - OidcIssuerJwkEndpointUnavailable
      - SmtpServerUnavailable
    InternalErrorCode:
      type: string
      enum:
      - NoMaterialId
      - InvalidAuditLogEntry
      - UnexpectedCheckerRule
      - UnresolvedPolicyReference
      - UnexpectedAclAction
      - FidoKeyAssociatedWithMultipleUsers
      - ClaimsParseError
      - InvalidThrottleId
      - InvalidEmailAddress
      - EmailTemplateRender
      - OidcIdentityHeaderMissing
      - OidcIdentityParseError
      - SystemTimeError
      - PasswordHashParseError
      - SendMailError
      - ReqwestError
      - EmailConstructionError
      - TsWriteError
      - TsQueryError
      - DbQueryError
      - DbGetError
      - DbDeleteError
      - DbPutError
      - DbUpdateError
      - SerdeError
      - TestAndSetError
      - DbGetItemsError
      - DbWriteError
      - CubistSignerError
      - CwListMetricsError
      - CwPutMetricDataError
      - GetAwsSecretError
      - SecretNotFound
      - KmsGenerateRandomError
      - MalformedTotpBytes
      - KmsGenerateRandomNoResponseError
      - CreateKeyError
      - ParseDerivationPathError
      - SplitSignerError
      - CreateImportKeyError
      - CreateEotsNoncesError
      - EotsSignError
      - BabylonCovSignError
      - CognitoDeleteUserError
      - CognitoListUsersError
      - CognitoGetUserError
      - MissingUserEmail
      - CognitoResendUserInvitation
      - CognitoSetUserPasswordError
      - GenericInternalError
      - AssumeRoleWithoutEvidence
      - OidcAuthWithoutOrg
      - MissingKeyMetadata
      - KmsEnableKeyError
      - KmsDisableKeyError
      - LambdaInvokeError
      - LambdaNoResponseError
      - LambdaFailure
      - LambdaUnparsableResponse
      - SerializeEncryptedExportKeyError
      - DeserializeEncryptedExportKeyError
      - ReEncryptUserExport
      - S3UploadError
      - S3DownloadError
      - S3CopyError
      - S3ListObjectsError
      - S3DeleteObjectsError
      - S3BuildError
      - S3PresignedUrlError
      - ManagedStateMissing
      - InternalHeaderMissing
      - InvalidInternalHeaderValue
      - RequestLocalStateAlreadySet
      - OidcOrgMismatch
      - OidcIssuerInvalidJwk
      - InvalidPkForMaterialId
      - SegwitTweakFailed
      - UncheckedOrg
      - SessionOrgIdMissing
      - AvaSignCredsMissing
      - AvaSignSignatureMissing
      - ExpectedRoleSession
      - InvalidThirdPartyIdentity
      - CognitoGetUser
      - SnsSubscribeError
      - SnsUnsubscribeError
      - SnsGetSubscriptionAttributesError
      - SnsSubscriptionAttributesMissing
      - SnsSetSubscriptionAttributesError
      - SnsPublishBatchError
      - InconsistentMultiValueTestAndSet
      - MaterialIdError
      - InvalidBtcAddress
      - HistoricalTxBodyMissing
      - InvalidOperation
      - ParentOrgNotFound
      - OrgParentLoop
      - ResolvedParentOrgWithNoScopeCeiling
      - InvalidUploadObjectId
      - PolicyEngineNotFound
      - PolicyEngineError
      - PolicySecretsEncryptionError
      - CreatePolicyImportKeyError
      - InvalidAlias
      - EmptyUpdateModifiedObject
      - EmptyUpdateModifiedActions
      - DbContactAddressesInvalid
      - InvalidEvmSigedRlp
      - InvalidErc20Data
      - InvalidRpcUrl
    SignerErrorCode:
      oneOf:
      - $ref: '#/components/schemas/SignerErrorOwnCodes'
      - $ref: '#/components/schemas/AcceptedValueCode'
      - $ref: '#/components/schemas/BadRequestErrorCode'
      - $ref: '#/components/schemas/BadGatewayErrorCode'
      - $ref: '#/components/schemas/NotFoundErrorCode'
      - $ref: '#/components/schemas/ForbiddenErrorCode'
      - $ref: '#/components/schemas/UnauthorizedErrorCode'
      - $ref: '#/components/schemas/PreconditionErrorCode'
      - $ref: '#/components/schemas/TimeoutErrorCode'
      - $ref: '#/components/schemas/ConflictErrorCode'
      - $ref: '#/components/schemas/InternalErrorCode'
    EvmTxDepositErrorCode:
      type: string
      enum:
      - EvmTxDepositReceiverMismatch
      - EvmTxDepositEmptyData
      - EvmTxDepositEmptyChainId
      - EvmTxDepositEmptyReceiver
      - EvmTxDepositUnexpectedValue
      - EvmTxDepositUnexpectedDataLength
      - EvmTxDepositNoAbi
      - EvmTxDepositNoDepositFunction
      - EvmTxDepositUnexpectedFunctionName
      - EvmTxDepositUnexpectedValidatorKey
      - EvmTxDepositInvalidValidatorKey
      - EvmTxDepositMissingDepositArg
      - EvmTxDepositWrongDepositArgType
      - EvmTxDepositValidatorKeyNotInRole
      - EvmTxDepositUnexpectedWithdrawalCredentials
      - EvmTxDepositUnresolvedRole
      - EvmTxDepositInvalidDepositEncoding
    PublicKeyCredentialDescriptor:
      type: object
      description: 'This dictionary contains the attributes that are specified by a caller when

        referring to a public key credential as an input parameter to the create()

        or get() methods. It mirrors the fields of the PublicKeyCredential object

        returned by the latter methods.


        https://www.w3.org/TR/webauthn-2/#dictionary-credential-descriptor'
      required:
      - type
      - id
      properties:
        id:
          type: string
          description: 'This member contains the credential ID of the public key credential the caller is referring to.


            https://www.w3.org/TR/webauthn-2/#dom-publickeycredentialdescriptor-id'
        transports:
          type: array
          items:
            $ref: '#/components/schemas/AuthenticatorTransport'
          description: 'This OPTIONAL member contains a hint as to how the client might

            communicate with the managing authenticator of the public key credential

            the caller is referring to. The values SHOULD be members of

            AuthenticatorTransport but client platforms MUST ignore unknown values.


            The getTransports() operation can provide suitable values for this

            member. When registering a new credential, the Relying Party SHOULD

            store the value returned from getTransports(). When creating a

            PublicKeyCredentialDescriptor for that credential, the Relying Party

            SHOULD retrieve that stored value and set it as the value of the

            transports member.'
          nullable: true
        type:
          $ref: '#/components/schemas/PublicKeyCredentialType'
    AuthenticatorAttestationResponse:
      type: object
      description: 'The AuthenticatorAttestationResponse interface represents the authenticator''s

        response to a client’s request for the creation of a new public key

        credential. It contains information about the new credential that can be

        used to identify it for later use, and metadata that can be used by the

        WebAuthn Relying Party to assess the characteristics of the credential

        during registration.


        https://www.w3.org/TR/webauthn-2/#iface-authenticatorattestationresponse'
      required:
      - clientDataJSON
      - attestationObject
      properties:
        attestationObject:
          type: string
          description: 'This attribute contains an attestation object, which is opaque to, and

            cryptographically protected against tampering by, the client. The

            attestation object contains both authenticator data and an attestation

            statement. The former contains the AAGUID, a unique credential ID, and

            the credential public key. The contents of the attestation statement are

            determined by the attestation statement format used by the

            authenticator. It also contains any additional information that the

            Relying Party''s server requires to validate the attestation statement,

            as well as to decode and validate the authenticator data along with the

            JSON-compatible serialization of client data. For more details, see

            § 6.5 Attestation, § 6.5.4 Generating an Attestation Object, and Figure

            6.'
        clientDataJSON:
          type: string
          description: 'This attribute, inherited from AuthenticatorResponse, contains the

            JSON-compatible serialization of client data (see § 6.5 Attestation)

            passed to the authenticator by the client in order to generate this

            credential. The exact JSON serialization MUST be preserved, as the hash

            of the serialized client data has been computed over it.'
    ErrorResponse:
      type: object
      description: The structure of ErrorResponse must match the response template that AWS uses
      required:
      - message
      - error_code
      properties:
        accepted:
          allOf:
          - $ref: '#/components/schemas/AcceptedValue'
          nullable: true
        error_code:
          $ref: '#/components/schemas/SignerErrorCode'
        message:
          type: string
          description: Error message
        policy_eval_tree:
          description: Optional policy evaluation tree (included in signer responses, when requested)
          nullable: true
        request_id:
          type: string
          description: Optional request identifier
    PreconditionErrorOwnCodes:
      type: string
      enum:
      - FailOnMfaRequired
      - KeyRegionLocked
      - KeyRegionChangedRecently
      - MfaRegionLocked
      - Eth2ProposerSlotTooLow
      - Eth2AttestationSourceEpochTooLow
      - Eth2AttestationTargetEpochTooLow
      - Eth2ConcurrentBlockSigning
      - Eth2ConcurrentAttestationSigning
      - Eth2MultiDepositToNonGeneratedKey
      - Eth2MultiDepositUnknownInitialDeposit
      - Eth2MultiDepositWithdrawalAddressMismatch
      - ConcurrentSigningWhenTimeLimitPolicyIsDefined
      - BabylonEotsConcurrentSigning
      - TendermintStateError
      - TendermintConcurrentSigning
      - MfaApprovalsNotYetValid
    ClientSessionInfo:
      type: object
      description: 'Session information sent to the client.

        This struct works in tandem with its server-side counterpart [`SessionData`].'
      required:
      - session_id
      - auth_token
      - refresh_token
      - epoch
      - epoch_token
      - auth_token_exp
      - refresh_token_exp
      properties:
        auth_token:
          type: string
          description: Token to use for authorization.
        auth_token_exp:
          $ref: '#/components/schemas/EpochDateTime'
        epoch:
          type: integer
          format: int32
          description: Epoch at which the token was last refreshed
          minimum: 0
        epoch_token:
          $ref: '#/components/schemas/B32'
        refresh_token:
          type: string
          description: Token to use for refreshing the `(auth, refresh)` token pair
        refresh_token_exp:
          $ref: '#/components/schemas/EpochDateTime'
        session_id:
          type: string
          description: Session ID
    PolicyErrorOwnCodes:
      type: string
      enum:
      - Inapplicable
      - SuiTxReceiversDisall

# --- truncated at 32 KB (63 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cubist/refs/heads/main/openapi/cubist-mfa-api-openapi.yml