FINOS CertificateAuthentication API

The CertificateAuthentication API from FINOS — 2 operation(s) for certificateauthentication.

OpenAPI Specification

finos-certificateauthentication-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Agent Admin CertificateAuthentication API
  description: 'This document refers to Symphony API calls to send and receive messages

    and content. They need the on-premise Agent installed to perform

    decryption/encryption of content.


    - sessionToken and keyManagerToken can be obtained by calling the

    authenticationAPI on the symphony back end and the key manager

    respectively. Refer to the methods described in authenticatorAPI.yaml.

    - Actions are defined to be atomic, ie will succeed in their entirety

    or fail and have changed nothing.

    - If it returns a 40X status then it will have sent no message to any

    stream even if a request to some subset of the requested streams

    would have succeeded.

    - If this contract cannot be met for any reason then this is an error

    and the response code will be 50X.

    - MessageML is a markup language for messages. See reference here:

    https://rest-api.symphony.com/docs/messagemlv2

    - **Real Time Events**: The following events are returned when reading

    from a real time messages and events stream ("datafeed"). These

    events will be returned for datafeeds created with the v5 endpoints.

    To know more about the endpoints, refer to Create Messages/Events

    Stream and Read Messages/Events Stream. Unless otherwise specified,

    all events were added in 1.46.

    '
  version: 25.8.1
servers:
- url: youragentURL.symphony.com/agent
tags:
- name: CertificateAuthentication
paths:
  /v1/authenticate:
    post:
      summary: Authenticate.
      description: 'Based on the SSL client certificate presented by the TLS layer, authenticate

        the API caller and return a session token.

        '
      produces:
      - application/json
      tags:
      - CertificateAuthentication
      responses:
        '200':
          description: OK.
          schema:
            $ref: '#/definitions/Token'
        '400':
          description: Client error.
          schema:
            $ref: '#/definitions/Error'
        '403':
          description: 'Forbidden: Certificate authentication is not allowed for the requested user.'
          schema:
            $ref: '#/definitions/Error'
        '500':
          description: Server error, see response body for further details.
          schema:
            $ref: '#/definitions/Error'
  /v1/logout:
    post:
      summary: Logout.
      description: 'Logout a users session.

        '
      parameters:
      - name: sessionToken
        description: the session token to logout.
        in: header
        required: true
        type: string
      produces:
      - application/json
      tags:
      - CertificateAuthentication
      responses:
        '200':
          description: OK.
          schema:
            $ref: '#/definitions/SuccessResponse'
        '400':
          description: Client error.
          schema:
            $ref: '#/definitions/Error'
        '403':
          description: 'Forbidden: Certificate authentication is not allowed for the requested user.'
          schema:
            $ref: '#/definitions/Error'
        '500':
          description: Server error, see response body for further details.
          schema:
            $ref: '#/definitions/Error'
definitions:
  Token:
    type: object
    properties:
      name:
        description: 'The name of the header in which the token should be presented on subsequent API calls.

          '
        type: string
      token:
        type: string
        description: 'Authentication token that should be passed as header in each API rest calls.

          This should be considered opaque data by the client. It is not intended to contain any data interpretable by the

          client. The format is secret and subject to change without notice.

          '
      authorizationToken:
        type: string
        description: "(Beta) Short lived access token built from a user session. This field is still on Beta, please continue using \nthe returned \"token\" instead.\n"
  SuccessResponse:
    type: object
    properties:
      message:
        type: string
  Error:
    type: object
    properties:
      code:
        type: integer
        format: int32
      message:
        type: string