Inductive Automation config-security-properties API
Security properties configuration
Security properties configuration
openapi: 3.0.3
info:
title: Ignition Gateway REST access-control config-security-properties API
description: The Ignition Gateway REST API (Ignition 8.3+) provides an OpenAPI-compliant HTTP interface to Gateway configuration resources including tags, projects, modules, device connections, historian data, user management (SCIM), alarm notification, OPC connections, and more. The specification is dynamically generated based on installed modules. Authentication uses API keys exchanged for time-limited tokens via the X-Ignition-API-Token header. Mutative requests are audit-logged. Supports Kubernetes and Helm-based cloud-native deployments.
version: 8.3.0
contact:
name: Inductive Automation Support
url: https://support.inductiveautomation.com/
license:
name: Commercial
url: https://inductiveautomation.com/pricing/
x-postman-collection: https://raw.githubusercontent.com/inductiveautomation/83-api/main/postman/8.3.postman_collection_v2.json
servers:
- url: http://{gateway-host}:{port}
description: Ignition Gateway (HTTP)
variables:
gateway-host:
default: localhost
description: Hostname or IP address of the Ignition Gateway
port:
default: '8088'
description: Gateway HTTP port (default 8088; HTTPS default 8043)
- url: https://{gateway-host}:{port}
description: Ignition Gateway (HTTPS)
variables:
gateway-host:
default: localhost
description: Hostname or IP address of the Ignition Gateway
port:
default: '8043'
description: Gateway HTTPS port
security:
- apiKeyAuth: []
tags:
- name: config-security-properties
description: Security properties configuration
paths:
/data/api/v1/resources/ignition/security-properties:
put:
summary: Modify Security Properties
operationId: modify-security-properties-put
tags:
- config-security-properties
description: Modify one or more Security Properties resources
parameters:
- name: allowInvalidReferences
in: query
required: false
schema:
type: string
description: If true, invalid references will be allowed. Default is false.
requestBody:
content:
application/json:
schema:
type: object
example:
- signature: <string>
collection: <string>
enabled: <boolean>
description: <string>
config:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
backupConfig:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
- signature: <string>
collection: <string>
enabled: <boolean>
description: <string>
config:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
backupConfig:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
post:
summary: Create Security Properties
operationId: create-security-properties-post
tags:
- config-security-properties
description: Create the Security Properties resource
parameters:
- name: allowInvalidReferences
in: query
required: false
schema:
type: string
description: If true, invalid references will be allowed. Default is false.
requestBody:
content:
application/json:
schema:
type: object
example:
- collection: <string>
enabled: <boolean>
description: <string>
config:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
backupConfig:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
- collection: <string>
enabled: <boolean>
description: <string>
config:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
backupConfig:
systemAuthProfile: <string>
systemIdentityProvider: <string>
forceIdpAuth: true
designerAuthStrategy: CLASSIC
designerAuthTokenInactivityTimeout: 10
designerAuthTokenTimeToLive: 0
designerRoleName: Administrator
createProjectRoleName: <string>
accessPermissions:
type: AllOf
securityLevels: []
readPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
writePermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
designerPermissions:
type: AnyOf
securityLevels:
- name: Authenticated
children:
- name: Roles
children:
- name: Administrator
children: []
createProjectPermissions:
type: AllOf
securityLevels: []
userInactivityTimeout: 10
allowUserAdmin: false
allowDesignerSSO: false
gatewayAuditProfile: <string>
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
/data/api/v1/resources/ignition/security-properties/{signature}:
delete:
summary: Delete Security Properties
operationId: delete-security-properties-delete
tags:
- config-security-properties
description: Delete the Security Properties resource.
parameters:
- name: signature
in: path
required: true
schema:
type: string
- name: collection
in: query
required: false
schema:
type: string
description: The configuration collection to delete the resource from
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
/data/api/v1/resources/singleton/ignition/security-properties:
get:
summary: Get Security Properties Config
operationId: get-security-properties-config-get
tags:
- config-security-properties
description: Retrieve configuration details about the Security Properties resource
parameters:
- name: defaultIfUndefined
in: query
required: false
schema:
type: string
description: If true, return the default configuration if the resource is not defined. Otherwise, return 404. Default is false.
- name: collection
in: query
required: false
schema:
type: string
description: The configuration collection to read the resource from
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
/data/api/v1/resources/type/ignition/security-properties:
get:
summary: Describe 'Security Properties' Resource Type
operationId: describe-'security-properties'-resource-type-get
tags:
- config-security-properties
description: Describe the Security Properties resource type
responses:
'200':
description: Successful response
content:
application/json:
schema:
type: object
'400':
description: Bad request
'401':
description: Unauthorized
'404':
description: Not found
components:
securitySchemes:
apiKeyAuth:
type: apiKey
in: header
name: X-Ignition-API-Token
description: Time-limited API token. Obtain by posting credentials to the token endpoint. See /data/api/v1/token for details.
externalDocs:
description: Ignition 8.3 Gateway REST API Documentation
url: https://www.docs.inductiveautomation.com/docs/8.3/platform/gateway/openapi