Entur Security Policy API

The security-policy API from Entur — 4 operation(s) for security-policy.

Operations 6

GET /security-policy Retrieves all security policies #
POST /security-policy Create a SecurityPolicy #
GET /security-policy/defaults Retrieves default security policies #
GET /security-policy/{id} Retrieves a security policy by id. #
GET /security-policy/{id}/{version} Retrieves security policy for id and version #
PUT /security-policy/{id}/{version} Updates an existing SecurityPolicy #

Specifications

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-partner-dataset-rpt-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-partner-dataset-download-job-dto-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-partner-settlement-import-dto-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-partner-settlement-import-response-dto-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-given-consent-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-consent-crm-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-consent-base-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-given-consent-bulk-update-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-given-consent-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-consent-base-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-customer-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-temporary-customer-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-customer-post-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-customer-put-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-ecard-ownership-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-temporary-customer-post-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-result-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-quota-request-v1-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-quota-configuration-response-v1-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-quota-response-v1-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reservation-response-v1-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-quota-configuration-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-multi-stock-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-search-geo-location-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-search-authority-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-search-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-search-trip-pattern-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-collection-info-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-customer-input-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-search-offer-input-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-subscriber-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-extend-expiry-time-input-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-update-traveller-input-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-note-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-note-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-page-of-order-note-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-line-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-fee-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-create-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-line-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-payment-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-transaction-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-credit-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-transaction-import-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-transaction-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-terminal-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-program-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-transaction-by-order-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-current-level-summary-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-current-level-summary-query-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-point-period-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-customer-membership-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-employee-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-imported-employee-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-imported-employee-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-contract-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-imported-employee-merge-patch-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-entitlement-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-zonal-stop-place-distance-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-fare-zone-distance-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-fare-zone-distance-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-coordinate-distance-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-distance-calculation-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-fare-table-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-fare-table-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-version-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-version-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-purchase-window-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-purchase-window-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-purchase-window-list-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-supplement-product-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-supplement-product-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-sales-offer-package-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-sales-offer-package-publication-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-sales-offer-package-assignment-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-supplement-product-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-generic-parameter-assignment-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-exchanging-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-amount-of-price-unit-product-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-capped-discount-right-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-sale-discount-right-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-netex-import-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-send-receipt-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-user-receipt-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-receipt-type-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-refund-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-refund-option-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-dry-run-refund-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-compensation-operation-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-refund-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-compensation-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-change-order-lines-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-order-line-ids-and-reservation-ids-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reserve-offers-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-add-supplement-products-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reserve-third-party-products-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reserve-third-party-products-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-seating-offer-debug-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-rebooked-reservation-response-v1-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-rebooked-reservation-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reservation-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-seating-offer-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reservation-line-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-reserve-specific-seats-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-map-string-string-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-seq-cancel-seat-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-seq-companion-for-seat-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-seq-journey-query-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-seq-product-attribute-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-asset-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-booking-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-support-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-one-stop-booking-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-one-stop-booking-event-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-notification-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-post-skoleskyss-request-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-post-skoleskyss-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/entur/refs/heads/main/json-schema/entur-delete-skoleskyss-response-schema.json

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/entur:entur-security-policy-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

entur-security-policy-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Entur Security Policy API
  version: 2026.10.0
  description: 'Operations tagged security-policy across 2 of this provider''s published API definitions: entur-products-openapi.json, entur-products-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.entur.io/products
  description: Production environment
- url: https://api.staging.entur.io/products
  description: Staging environment
- url: https://api.dev.entur.io/products
  description: Development environment
security:
- jwt: []
tags:
- name: security policy
paths:
  /security-policy:
    parameters:
    - $ref: '#/components/parameters/ET-Client-Name'
    - $ref: '#/components/parameters/X-Correlation-Id'
    get:
      tags:
      - security policy
      summary: Retrieves all security policies
      operationId: security-policy_getAll
      parameters:
      - name: orgId
        in: query
        description: The unique id to identify an organisation
        required: false
        style: form
        explode: true
        schema:
          type: string
      - name: fareFrameId
        in: query
        description: The unique id to identify a dataset to an organisation
        required: false
        style: form
        explode: true
        schema:
          type: string
      - name: minimizeDataLoad
        in: query
        required: false
        style: form
        explode: true
        schema:
          type: boolean
      - name: statusFilter
        in: query
        description: 'Filter by status. Allowed values: DRAFT, PROPOSED, VERSIONED, DEPRECATED, ALL. Defaults to ALL if not specified. Mutually exclusive with validOnDate.'
        required: false
        style: form
        explode: true
        schema:
          type: array
          items:
            type: string
        examples:
          default:
            value:
            - DRAFT
            - PROPOSED
      - name: validOnDate
        in: query
        description: 'Return the SecurityPolicies valid on this date, example: 2024-06-01T00:00:00Z. Note that, if called in the production environment, only VERSIONED SecurityPolicies are returned. And in the staging environment, PROPOSED SecurityPolicies are preferred to VERSIONED ones. Mutually exclusive with statusFilter.'
        required: false
        style: form
        explode: true
        schema:
          type: string
      - name: If-None-Match
        in: header
        description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource.
        required: false
        style: simple
        explode: false
        schema:
          type: string
      responses:
        '200':
          description: Returns the info
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/SecurityPolicy'
        '304':
          description: Not Modified
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                type: string
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                type: string
        '403':
          description: Authorization failed
          content:
            application/problem+json:
              schema:
                type: string
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                type: string
        '500':
          description: Internal server error
          content:
            application/problem+json:
              schema:
                type: string
      security:
      - basic_auth: []
      x-entur-permissions:
        value: product-api-access:les
    post:
      tags:
      - security policy
      summary: Create a SecurityPolicy
      operationId: security-policy_create
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SecurityPolicy'
        required: true
      responses:
        '204':
          description: Entity created successfully
        '400':
          description: Validation errors
          content:
            application/problem+json:
              schema:
                type: string
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                type: string
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                type: string
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                type: string
        '409':
          description: Already registered
          content:
            application/problem+json:
              schema:
                type: string
        '500':
          description: Internal server error
          content:
            application/problem+json:
              schema:
                type: string
      security:
      - basic_auth: []
      x-entur-permissions:
        value: product-api-access:endre
    servers:
    - url: https://api.entur.io/products
      description: Production environment
    - url: https://api.staging.entur.io/products
      description: Staging environment
    - url: https://api.dev.entur.io/products
      description: Development environment
  /security-policy/defaults:
    parameters:
    - $ref: '#/components/parameters/ET-Client-Name'
    - $ref: '#/components/parameters/X-Correlation-Id'
    get:
      tags:
      - security policy
      summary: Retrieves default security policies
      operationId: security-policy_getDefaults
      parameters:
      - name: If-None-Match
        in: header
        description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource.
        required: false
        style: simple
        explode: false
        schema:
          type: string
      responses:
        '200':
          description: Returns the info
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/SecurityPolicy'
        '304':
          description: Not Modified
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                type: string
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                type: string
        '403':
          description: Authorization failed
          content:
            application/problem+json:
              schema:
                type: string
        '404':
          description: Resource not found
          content:
            application/problem+json:
              schema:
                type: string
        '500':
          description: Internal server error
          content:
            application/problem+json:
              schema:
                type: string
      security:
      - basic_auth: []
      x-entur-permissions:
        value: product-api-access:les
    servers:
    - url: https://api.entur.io/products
      description: Production environment
    - url: https://api.staging.entur.io/products
      description: Staging environment
    - url: https://api.dev.entur.io/products
      description: Development environment
  /security-policy/{id}:
    parameters:
    - $ref: '#/components/parameters/ET-Client-Name'
    - $ref: '#/components/parameters/X-Correlation-Id'
    get:
      tags:
      - security policy
      summary: Retrieves a security policy by id.
      description: Optional validOnDate query parameter (defaults to now). In prod returns the VERSIONED element; in staging/dev PROPOSED is preferred over VERSIONED.
      operationId: security-policy_getByIdAndValidOnDate
      parameters:
      - name: id
        in: path
        description: The id to identify a SecurityPolicy
        required: true
        style: simple
        explode: false
        schema:
          type: string
      - name: validOnDate
        in: query
        description: Return the version valid on the given date (ISO-8601). Defaults to now.
        required: false
        style: form
        explode: true
        schema:
          type: string
          format: date-time
      - name: If-None-Match
        in: header
        description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource.
        required: false
        style: simple
        explode: false
        schema:
          type: string
      responses:
        '200':
          description: Returns the info
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityPolicy'
        '304':
          description: Not Modified
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                type: string
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                type: string
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                type: string
        '404':
          description: Resource not found
          content:
            application/problem+json:
              schema:
                type: string
        '500':
          description: Internal server error
          content:
            application/problem+json:
              schema:
                type: string
      security:
      - basic_auth: []
      x-entur-permissions:
        value: product-api-access:les
    servers:
    - url: https://api.entur.io/products
      description: Production environment
    - url: https://api.staging.entur.io/products
      description: Staging environment
    - url: https://api.dev.entur.io/products
      description: Development environment
  /security-policy/{id}/{version}:
    parameters:
    - $ref: '#/components/parameters/ET-Client-Name'
    - $ref: '#/components/parameters/X-Correlation-Id'
    get:
      tags:
      - security policy
      summary: Retrieves security policy for id and version
      operationId: security-policy_getById
      parameters:
      - name: id
        in: path
        description: The id to identify a SecurityPolicy
        required: true
        style: simple
        explode: false
        schema:
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
      - name: version
        in: path
        description: The id for the version of the SecurityPolicy
        required: true
        style: simple
        explode: false
        schema:
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
      - name: If-None-Match
        in: header
        description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource.
        required: false
        style: simple
        explode: false
        schema:
          type: string
      responses:
        '200':
          description: Returns the info
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityPolicy'
        '304':
          description: Not Modified
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                type: string
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                type: string
        '403':
          description: Authorization failed
          content:
            application/problem+json:
              schema:
                type: string
        '404':
          description: Resource not found
          content:
            application/problem+json:
              schema:
                type: string
        '500':
          description: Internal server error
          content:
            application/problem+json:
              schema:
                type: string
      security:
      - basic_auth: []
      x-entur-permissions:
        value: product-api-access:les
    put:
      tags:
      - security policy
      summary: Updates an existing SecurityPolicy
      operationId: security-policy_update
      parameters:
      - name: id
        in: path
        description: The id to identify a SecurityPolicy
        required: true
        style: simple
        explode: false
        schema:
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
      - name: version
        in: path
        description: The id for the version of the SecurityPolicy
        required: true
        style: simple
        explode: false
        schema:
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SecurityPolicy'
        required: true
      responses:
        '204':
          description: Entity updated successfully
        '400':
          description: Validation errors
          content:
            application/problem+json:
              schema:
                type: string
        '401':
          description: Missing Authorization
          content:
            application/problem+json:
              schema:
                type: string
        '403':
          description: Authorization failed
          content:
            application/problem+json:
              schema:
                type: string
        '404':
          description: Resource not found
          content:
            application/problem+json:
              schema:
                type: string
        '409':
          description: Conflict
          content:
            application/problem+json:
              schema:
                type: string
        '500':
          description: Internal server error
          content:
            application/problem+json:
              schema:
                type: string
      security:
      - basic_auth: []
      x-entur-permissions:
        value: product-api-access:endre
    servers:
    - url: https://api.entur.io/products
      description: Production environment
    - url: https://api.staging.entur.io/products
      description: Staging environment
    - url: https://api.dev.entur.io/products
      description: Development environment
components:
  schemas:
    VersionOfObjectRef:
      required:
      - nameOfClass
      - ref
      - version
      type: object
      properties:
        nameOfClass:
          minLength: 1
          type: string
          description: Name of class.
        ref:
          minLength: 1
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
          description: The netex id reference to the object.
        version:
          type: string
          description: Version.
      description: Fare frame ref.
    TextInLanguage:
      required:
      - lang
      - value
      type: object
      properties:
        lang:
          minLength: 1
          type: string
          description: Language code.
          examples:
          - nob
        value:
          minLength: 1
          type: string
          description: The text.
      description: Text in a specific language.
    SecurityPolicy:
      required:
      - changed
      - created
      - id
      - minimumAccountSecurityLevel
      - modification
      - nameOfClass
      - status
      - version
      type: object
      properties:
        changed:
          type: string
          description: Changed
          readOnly: true
        created:
          type: string
          description: Created
          readOnly: true
        description:
          type: array
          description: Description.
          items:
            $ref: '#/components/schemas/TextInLanguage'
        fareFrameRef:
          $ref: '#/components/schemas/VersionOfObjectRef'
        id:
          minLength: 1
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
          description: Id
          examples:
          - NSB:SecurityPolicy:HighValueProduct
        minimumAccountSecurityLevel:
          type: integer
          description: 'Required (minimum) sequrity level of a product. The value is specified as a negative number, 0 is the highest level of security (most secure). In Entur we use three default levels: -50, -120 and -200. We have default implementations of SecurityPolicies for these three levels, and these can be retrieved from the security-policy/defaults endpoint.'
          format: int32
        modification:
          type: string
          description: Modification status.
          readOnly: true
          enum:
          - NEW
          - REVISE
          - DELETE
          examples:
          - NEW
        name:
          type: array
          description: Name.
          items:
            $ref: '#/components/schemas/TextInLanguage'
        nameOfClass:
          type: string
          description: NameOfClass
          readOnly: true
          examples:
          - SecurityPolicy
        status:
          type: string
          description: Status
          readOnly: true
          enum:
          - DRAFT
          - PROPOSED
          - VERSIONED
          - DEPRECATED
          examples:
          - DRAFT
        version:
          minLength: 1
          pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$
          type: string
          description: Version
          examples:
          - NSB:Version:V1
  parameters:
    X-Correlation-Id:
      name: X-Correlation-Id
      in: header
      description: Correlation id
      required: false
      style: simple
      explode: false
      schema:
        type: string
    ET-Client-Name:
      name: ET-Client-Name
      in: header
      description: 'Entur Client Header.

        It is required that all consumers identify themselves by using this header.

        Entur will deploy strict rate-limiting policies on API-consumers who do not identify with a header and reserves the right to block unidentified consumers.

        The structure of ET-Client-Name should be: `<company>-<application>`.'
      required: false
      style: simple
      explode: false
      schema:
        type: string
  securitySchemes:
    jwt:
      type: http
      scheme: bearer
      bearerFormat: JWT
x-refined-from:
- entur-products-openapi.json
- entur-products-openapi.yml