Cubist MFA API
The MFA API from Cubist — 5 operation(s) for mfa.
The MFA API from Cubist — 5 operation(s) for mfa.
openapi: 3.0.3
info:
title: CubeSigner Account MFA API
description: The CubeSigner management and signing service.
contact:
name: Cubist Inc.
email: hello@cubist.dev
version: v0.1.0
servers:
- url: https://gamma.signer.cubist.dev
description: Testing and staging environment
- url: https://prod.signer.cubist.dev
description: Production environment
security:
- Cognito: []
tags:
- name: MFA
paths:
/v0/org/{org_id}/mfa:
get:
tags:
- MFA
summary: List Pending MFA Requests
description: 'List Pending MFA Requests
Retrieves and returns all pending MFA requests that are accessible to the current session,
i.e., those created by the current session identity plus those in which the current user
is listed as an approver
NOTE that if pagination is used and a page limit is set, the returned result
set may contain either FEWER or MORE elements than the requested page limit.'
operationId: mfaList
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: page.size
in: query
description: 'Max number of items to return per page.
If the actual number of returned items may be less that this, even if there exist more
data in the result set. To reliably determine if more data is left in the result set,
inspect the [UnencryptedLastEvalKey] value in the response object.'
required: false
schema:
type: integer
format: int32
default: 1000
maximum: 10001
minimum: 1
style: form
- name: page.start
in: query
description: 'The start of the page. Omit to start from the beginning; otherwise, only specify a
the exact value previously returned as ''last_evaluated_key'' from the same endpoint.'
required: false
schema:
type: string
nullable: true
style: form
responses:
'200':
$ref: '#/components/responses/PaginatedListMfaResponse'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:list
/v0/org/{org_id}/mfa/{mfa_id}:
get:
tags:
- MFA
summary: Get Pending MFA Request
description: 'Get Pending MFA Request
Retrieves and returns a pending MFA request by its id.'
operationId: mfaGet
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
responses:
'200':
$ref: '#/components/responses/MfaRequestInfo'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth: []
patch:
tags:
- MFA
summary: Approve or Reject MFA Request
description: 'Approve or Reject MFA Request
Approve or reject request after logging in with CubeSigner.
If approving, adds the currently-logged user as an approver
of a pending MFA request of the [Status::RequiredApprovers] kind. If the required number of
approvers is reached, the MFA request is approved; the confirmation receipt can be used to
resume the original HTTP request.
If rejecting, immediately deletes the pending MFA request.'
operationId: mfaVoteCs
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_vote
in: query
required: false
schema:
allOf:
- $ref: '#/components/schemas/MfaVote'
nullable: true
style: form
responses:
'200':
$ref: '#/components/responses/MfaRequestInfo'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:vote:cs
/v0/org/{org_id}/mfa/{mfa_id}/email:
post:
tags:
- MFA
summary: Initiate an Email OTP MFA Approval/Rejection
description: 'Initiate an Email OTP MFA Approval/Rejection
Initiates the approval/rejection process of an MFA Request using Email OTP.'
operationId: mfaEmailInit
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_vote
in: query
required: false
schema:
allOf:
- $ref: '#/components/schemas/MfaVote'
nullable: true
style: form
responses:
'200':
$ref: '#/components/responses/EmailOtpResponse'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:vote:email
patch:
tags:
- MFA
summary: Finalize a Email OTP MFA Approval/Rejection.
description: 'Finalize a Email OTP MFA Approval/Rejection.
The request should contain the full JWT obtained by concatenating the
partial token returned by the `mfa_email_init` endpoint and the signature
emailed to the user issuing the request.
If approving, adds an approver to a pending MFA request.
If the required number of approvers is reached, the MFA request is approved;
the confirmation receipt can be used to resume the original HTTP request.
If rejecting, immediately deletes the pending MFA request.'
operationId: mfaVoteEmailComplete
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/EmailOtpAnswer'
required: true
responses:
'200':
$ref: '#/components/responses/MfaRequestInfo'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:vote:email
/v0/org/{org_id}/mfa/{mfa_id}/fido:
post:
tags:
- MFA
summary: Initiate a FIDO MFA Approval/Rejection
description: 'Initiate a FIDO MFA Approval/Rejection
Initiates the approval/rejection process of an MFA Request using FIDO.'
operationId: mfaFidoInit
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
responses:
'200':
$ref: '#/components/responses/FidoAssertChallenge'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:vote:fido
patch:
tags:
- MFA
summary: Finalize a FIDO MFA Approval/Rejection
description: 'Finalize a FIDO MFA Approval/Rejection
If approving, adds an approver to a pending MFA request.
If the required number of approvers is reached, the MFA request is approved;
the confirmation receipt can be used to resume the original HTTP request.
If rejecting, immediately deletes the pending MFA request.'
operationId: mfaVoteFidoComplete
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_vote
in: query
required: false
schema:
allOf:
- $ref: '#/components/schemas/MfaVote'
nullable: true
style: form
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/FidoAssertAnswer'
required: true
responses:
'200':
$ref: '#/components/responses/MfaRequestInfo'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:vote:fido
/v0/org/{org_id}/mfa/{mfa_id}/totp:
patch:
tags:
- MFA
summary: Approve/Reject a TOTP MFA Request
description: 'Approve/Reject a TOTP MFA Request
If approving, adds the current user as approver to a pending MFA request by
providing TOTP code. If the required number of approvers is reached, the MFA request is
approved; the confirmation receipt can be used to resume the original HTTP request.
If rejecting, immediately deletes the pending MFA request.'
operationId: mfaVoteTotp
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_id
in: path
description: Name or ID of the desired MfaRequest
required: true
schema:
type: string
example: MfaRequest#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: mfa_vote
in: query
required: false
schema:
allOf:
- $ref: '#/components/schemas/MfaVote'
nullable: true
style: form
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/TotpApproveRequest'
required: true
responses:
'200':
$ref: '#/components/responses/MfaRequestInfo'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:mfa:vote:totp
components:
schemas:
EpochDateTime:
type: integer
format: int64
description: 'DateTime measured in seconds since unix epoch.
A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`]
representing the number of seconds since [`SystemTime::UNIX_EPOCH`].'
minimum: 0
UserVerificationRequirement:
type: string
description: 'A WebAuthn Relying Party may require user verification for some of its
operations but not for others, and may use this type to express its needs.
https://www.w3.org/TR/webauthn-2/#enum-userVerificationRequirement'
enum:
- required
- discouraged
- preferred
MfaRequiredArgs:
type: object
required:
- id
- ids
- org_id
properties:
id:
type: string
description: Always set to first MFA id from `Self::ids`
ids:
type: array
items:
type: string
minLength: 1
description: Non-empty MFA request IDs
org_id:
type: string
description: Organization id
policy_eval_tree:
description: Optional policy evaluation tree (included in signer responses, when requested)
nullable: true
session:
allOf:
- $ref: '#/components/schemas/NewSessionResponse'
nullable: true
B32:
type: string
description: Wrapper around a zeroizing 32-byte fixed-size array
PublicKeyCredential:
type: object
description: 'This type represents a wire-encodable form of the PublicKeyCredential interface
Clients may need to manually encode into this format to communicate with the server
The PublicKeyCredential interface inherits from Credential
[CREDENTIAL-MANAGEMENT-1], and contains the attributes that are returned to
the caller when a new credential is created, or a new assertion is
requested.
https://www.w3.org/TR/webauthn-2/#iface-pkcredential'
required:
- id
- response
properties:
clientExtensionResults:
type: object
description: 'This internal slot contains the results of processing client extensions
requested by the Relying Party upon the Relying Party''s invocation of
either navigator.credentials.create() or navigator.credentials.get().
https://www.w3.org/TR/webauthn-2/#dom-publickeycredential-clientextensionsresults-slot
IMPLEMENTATION NOTE: The type for this field comes from the type of getClientExtensionResults() which as the following doc:
This operation returns the value of [[clientExtensionsResults]], which is a map containing extension identifier → client extension output entries produced by the extension’s client extension processing.
https://www.w3.org/TR/webauthn-2/#ref-for-dom-publickeycredential-getclientextensionresults
'
nullable: true
id:
type: string
description: 'This internal slot contains the credential ID, chosen by the
authenticator. The credential ID is used to look up credentials for use,
and is therefore expected to be globally unique with high probability
across all credentials of the same type, across all authenticators.
https://www.w3.org/TR/webauthn-2/#dom-publickeycredential-identifier-slot'
response:
oneOf:
- $ref: '#/components/schemas/AuthenticatorAttestationResponse'
- $ref: '#/components/schemas/AuthenticatorAssertionResponse'
description: Authenticators respond to Relying Party requests by returning an object derived from the AuthenticatorResponse interface
EmailOtpAnswer:
type: object
description: An answer to the challenge returned by the `mfa_email_init` endpoint.
required:
- token
properties:
token:
type: string
description: 'Full JWT token, constructed by concatenating the "partial token"
(i.e., `{header}.{payload}.`) returned by the `mail_email_init` endpoint
and the signature sent to the user''s email.'
AcceptedValue:
oneOf:
- type: object
required:
- SignDryRun
properties:
SignDryRun:
$ref: '#/components/schemas/SignDryRunArgs'
- type: object
required:
- BinanceDryRun
properties:
BinanceDryRun:
$ref: '#/components/schemas/BinanceDryRunArgs'
- type: object
required:
- BybitDryRun
properties:
BybitDryRun:
$ref: '#/components/schemas/BybitDryRunArgs'
- type: object
required:
- CoinbaseDryRun
properties:
CoinbaseDryRun:
$ref: '#/components/schemas/CoinbaseDryRunArgs'
- type: object
required:
- MfaRequired
properties:
MfaRequired:
$ref: '#/components/schemas/MfaRequiredArgs'
description: Different responses we return for success status codes.
NotFoundErrorCode:
type: string
enum:
- UriSegmentMissing
- UriSegmentInvalid
- TotpNotConfigured
- FidoKeyNotFound
- FidoChallengeNotFound
- TotpChallengeNotFound
- UserExportRequestNotFound
- UserExportCiphertextNotFound
- OrgExportCiphertextNotFound
- UploadObjectNotFound
- PolicySecretNotFound
- BucketMetaNotFound
- TimestreamDisabled
- CustomChainNotFound
- InvitationNotFound
- TransactionNotFound
- EmailConfigNotFound
HttpRequestCmp:
oneOf:
- type: string
description: The requests must match exactly. Any given MFA receipt can be used at most once.
enum:
- Eq
- type: object
required:
- EvmTx
properties:
EvmTx:
$ref: '#/components/schemas/EvmTxCmp'
- type: object
required:
- SolanaTx
properties:
SolanaTx:
$ref: '#/components/schemas/SolanaTxCmp'
description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request])
AuthenticatorAssertionResponse:
type: object
description: 'Represents the assertion response used by clients when attempting to log in with a known credential
https://www.w3.org/TR/webauthn-2/#authenticatorassertionresponse'
required:
- clientDataJSON
- authenticatorData
- signature
properties:
authenticatorData:
type: string
description: 'Contains the standard CTAP2 authenticator data. Must be a valid [`AuthenticatorData`].
This contains information about how key was invoked.
https://www.w3.org/TR/webauthn-2/#dom-authenticatorassertionresponse-authenticatordata'
clientDataJSON:
type: string
description: 'Contains UTF8 encoded JSON which must be a valid [`ClientData`]
This data is combined with `authenticator_data` to produce the signature
meaning the client attests to the correctness of this data.
https://www.w3.org/TR/webauthn-2/#dom-authenticatorresponse-clientdatajson'
signature:
type: string
description: 'The signature of the concatenated `authenticatorData || hash` where
`hash` is the SHA256 hash of the `clientDataJSON` buffer:
Field Definition: https://www.w3.org/TR/webauthn-2/#dom-authenticatorassertionresponse-signature
Step 11 of `getAssertion` specifies the concatenation: https://www.w3.org/TR/webauthn-2/#sctn-op-get-assertion
Requirement for SHA-256: https://www.w3.org/TR/webauthn-2/#collectedclientdata-hash-of-the-serialized-client-data'
userHandle:
type: string
description: 'Allows the authenticator to optionally declare the credential identifier they used.
https://www.w3.org/TR/webauthn-2/#dom-authenticatorassertionresponse-userhandle'
nullable: true
SolanaTxCmp:
type: object
properties:
ignore_blockhash:
type: boolean
description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different.
ChallengePieces:
type: object
description: Describes how to derive a WebAuthn challenge value.
required:
- preimage
- random_seed
properties:
preimage:
type: string
description: 'A base64url encoding of UTF8 JSON. The data in that JSON is endpoint specific, and describes what this FIDO challenge will be used for.
Clients can use `preimage` along with `random_seed` to reconstruct the challenge like so:
`challenge = HMAC-SHA256(key=random_seed, message=preimage)`'
random_seed:
type: string
description: A random seed that prevents replay attacks
BadGatewayErrorCode:
type: string
enum:
- Generic
- CustomChainRpcError
- EsploraApiError
- SentryApiError
- CallWebhookError
- OAuthProviderError
- OidcDisoveryFailed
- OidcIssuerJwkEndpointUnavailable
- SmtpServerUnavailable
InternalErrorCode:
type: string
enum:
- NoMaterialId
- InvalidAuditLogEntry
- UnexpectedCheckerRule
- UnresolvedPolicyReference
- UnexpectedAclAction
- FidoKeyAssociatedWithMultipleUsers
- ClaimsParseError
- InvalidThrottleId
- InvalidEmailAddress
- EmailTemplateRender
- OidcIdentityHeaderMissing
- OidcIdentityParseError
- SystemTimeError
- PasswordHashParseError
- SendMailError
- ReqwestError
- EmailConstructionError
- TsWriteError
- TsQueryError
- DbQueryError
- DbGetError
- DbDeleteError
- DbPutError
- DbUpdateError
- SerdeError
- TestAndSetError
- DbGetItemsError
- DbWriteError
- CubistSignerError
- CwListMetricsError
- CwPutMetricDataError
- GetAwsSecretError
- SecretNotFound
- KmsGenerateRandomError
- MalformedTotpBytes
- KmsGenerateRandomNoResponseError
- CreateKeyError
- ParseDerivationPathError
- SplitSignerError
- CreateImportKeyError
- CreateEotsNoncesError
- EotsSignError
- BabylonCovSignError
- CognitoDeleteUserError
- CognitoListUsersError
- CognitoGetUserError
- MissingUserEmail
- CognitoResendUserInvitation
- CognitoSetUserPasswordError
- GenericInternalError
- AssumeRoleWithoutEvidence
- OidcAuthWithoutOrg
- MissingKeyMetadata
- KmsEnableKeyError
- KmsDisableKeyError
- LambdaInvokeError
- LambdaNoResponseError
- LambdaFailure
- LambdaUnparsableResponse
- SerializeEncryptedExportKeyError
- DeserializeEncryptedExportKeyError
- ReEncryptUserExport
- S3UploadError
- S3DownloadError
- S3CopyError
- S3ListObjectsError
- S3DeleteObjectsError
- S3BuildError
- S3PresignedUrlError
- ManagedStateMissing
- InternalHeaderMissing
- InvalidInternalHeaderValue
- RequestLocalStateAlreadySet
- OidcOrgMismatch
- OidcIssuerInvalidJwk
- InvalidPkForMaterialId
- SegwitTweakFailed
- UncheckedOrg
- SessionOrgIdMissing
- AvaSignCredsMissing
- AvaSignSignatureMissing
- ExpectedRoleSession
- InvalidThirdPartyIdentity
- CognitoGetUser
- SnsSubscribeError
- SnsUnsubscribeError
- SnsGetSubscriptionAttributesError
- SnsSubscriptionAttributesMissing
- SnsSetSubscriptionAttributesError
- SnsPublishBatchError
- InconsistentMultiValueTestAndSet
- MaterialIdError
- InvalidBtcAddress
- HistoricalTxBodyMissing
- InvalidOperation
- ParentOrgNotFound
- OrgParentLoop
- ResolvedParentOrgWithNoScopeCeiling
- InvalidUploadObjectId
- PolicyEngineNotFound
- PolicyEngineError
- PolicySecretsEncryptionError
- CreatePolicyImportKeyError
- InvalidAlias
- EmptyUpdateModifiedObject
- EmptyUpdateModifiedActions
- DbContactAddressesInvalid
- InvalidEvmSigedRlp
- InvalidErc20Data
- InvalidRpcUrl
SignerErrorCode:
oneOf:
- $ref: '#/components/schemas/SignerErrorOwnCodes'
- $ref: '#/components/schemas/AcceptedValueCode'
- $ref: '#/components/schemas/BadRequestErrorCode'
- $ref: '#/components/schemas/BadGatewayErrorCode'
- $ref: '#/components/schemas/NotFoundErrorCode'
- $ref: '#/components/schemas/ForbiddenErrorCode'
- $ref: '#/components/schemas/UnauthorizedErrorCode'
- $ref: '#/components/schemas/PreconditionErrorCode'
- $ref: '#/components/schemas/TimeoutErrorCode'
- $ref: '#/components/schemas/ConflictErrorCode'
- $ref: '#/components/schemas/InternalErrorCode'
EvmTxDepositErrorCode:
type: string
enum:
- EvmTxDepositReceiverMismatch
- EvmTxDepositEmptyData
- EvmTxDepositEmptyChainId
- EvmTxDepositEmptyReceiver
- EvmTxDepositUnexpectedValue
- EvmTxDepositUnexpectedDataLength
- EvmTxDepositNoAbi
- EvmTxDepositNoDepositFunction
- EvmTxDepositUnexpectedFunctionName
- EvmTxDepositUnexpectedValidatorKey
- EvmTxDepositInvalidValidatorKey
- EvmTxDepositMissingDepositArg
- EvmTxDepositWrongDepositArgType
- EvmTxDepositValidatorKeyNotInRole
- EvmTxDepositUnexpectedWithdrawalCredentials
- EvmTxDepositUnresolvedRole
- EvmTxDepositInvalidDepositEncoding
PublicKeyCredentialDescriptor:
type: object
description: 'This dictionary contains the attributes that are specified by a caller when
referring to a public key credential as an input parameter to the create()
or get() methods. It mirrors the fields of the PublicKeyCredential object
returned by the latter methods.
https://www.w3.org/TR/webauthn-2/#dictionary-credential-descriptor'
required:
- type
- id
properties:
id:
type: string
description: 'This member contains the credential ID of the public key credential the caller is referring to.
https://www.w3.org/TR/webauthn-2/#dom-publickeycredentialdescriptor-id'
transports:
type: array
items:
$ref: '#/components/schemas/AuthenticatorTransport'
description: 'This OPTIONAL member contains a hint as to how the client might
communicate with the managing authenticator of the public key credential
the caller is referring to. The values SHOULD be members of
AuthenticatorTransport but client platforms MUST ignore unknown values.
The getTransports() operation can provide suitable values for this
member. When registering a new credential, the Relying Party SHOULD
store the value returned from getTransports(). When creating a
PublicKeyCredentialDescriptor for that credential, the Relying Party
SHOULD retrieve that stored value and set it as the value of the
transports member.'
nullable: true
type:
$ref: '#/components/schemas/PublicKeyCredentialType'
AuthenticatorAttestationResponse:
type: object
description: 'The AuthenticatorAttestationResponse interface represents the authenticator''s
response to a client’s request for the creation of a new public key
credential. It contains information about the new credential that can be
used to identify it for later use, and metadata that can be used by the
WebAuthn Relying Party to assess the characteristics of the credential
during registration.
https://www.w3.org/TR/webauthn-2/#iface-authenticatorattestationresponse'
required:
- clientDataJSON
- attestationObject
properties:
attestationObject:
type: string
description: 'This attribute contains an attestation object, which is opaque to, and
cryptographically protected against tampering by, the client. The
attestation object contains both authenticator data and an attestation
statement. The former contains the AAGUID, a unique credential ID, and
the credential public key. The contents of the attestation statement are
determined by the attestation statement format used by the
authenticator. It also contains any additional information that the
Relying Party''s server requires to validate the attestation statement,
as well as to decode and validate the authenticator data along with the
JSON-compatible serialization of client data. For more details, see
§ 6.5 Attestation, § 6.5.4 Generating an Attestation Object, and Figure
6.'
clientDataJSON:
type: string
description: 'This attribute, inherited from AuthenticatorResponse, contains the
JSON-compatible serialization of client data (see § 6.5 Attestation)
passed to the authenticator by the client in order to generate this
credential. The exact JSON serialization MUST be preserved, as the hash
of the serialized client data has been computed over it.'
ErrorResponse:
type: object
description: The structure of ErrorResponse must match the response template that AWS uses
required:
- message
- error_code
properties:
accepted:
allOf:
- $ref: '#/components/schemas/AcceptedValue'
nullable: true
error_code:
$ref: '#/components/schemas/SignerErrorCode'
message:
type: string
description: Error message
policy_eval_tree:
description: Optional policy evaluation tree (included in signer responses, when requested)
nullable: true
request_id:
type: string
description: Optional request identifier
PreconditionErrorOwnCodes:
type: string
enum:
- FailOnMfaRequired
- KeyRegionLocked
- KeyRegionChangedRecently
- MfaRegionLocked
- Eth2ProposerSlotTooLow
- Eth2AttestationSourceEpochTooLow
- Eth2AttestationTargetEpochTooLow
- Eth2ConcurrentBlockSigning
- Eth2ConcurrentAttestationSigning
- Eth2MultiDepositToNonGeneratedKey
- Eth2MultiDepositUnknownInitialDeposit
- Eth2MultiDepositWithdrawalAddressMismatch
- ConcurrentSigningWhenTimeLimitPolicyIsDefined
- BabylonEotsConcurrentSigning
- TendermintStateError
- TendermintConcurrentSigning
- MfaApprovalsNotYetValid
ClientSessionInfo:
type: object
description: 'Session information sent to the client.
This struct works in tandem with its server-side counterpart [`SessionData`].'
required:
- session_id
- auth_token
- refresh_token
- epoch
- epoch_token
- auth_token_exp
- refresh_token_exp
properties:
auth_token:
type: string
description: Token to use for authorization.
auth_token_exp:
$ref: '#/components/schemas/EpochDateTime'
epoch:
type: integer
format: int32
description: Epoch at which the token was last refreshed
minimum: 0
epoch_token:
$ref: '#/components/schemas/B32'
refresh_token:
type: string
description: Token to use for refreshing the `(auth, refresh)` token pair
refresh_token_exp:
$ref: '#/components/schemas/EpochDateTime'
session_id:
type: string
description: Session ID
PolicyErrorOwnCodes:
type: string
enum:
- Inapplicable
- SuiTxReceiversDisall
# --- truncated at 32 KB (63 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cubist/refs/heads/main/openapi/cubist-mfa-api-openapi.yml