Indykite Authorization Policies API
KBAC and ContX IQ Policies CRUD operations
KBAC and ContX IQ Policies CRUD operations
openapi: 3.2.0
info:
contact: {}
description: Config API supports CRUD operations on config objects.
title: Config REST Application Agent Credentials Authorization Policies API
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0
version: '1'
servers:
- url: https://eu.api.indykite.com/configs/v1
- url: https://us.api.indykite.com/configs/v1
security:
- BearerToken: []
tags:
- name: Authorization Policies
description: KBAC and ContX IQ Policies CRUD operations
x-displayName: Authorization Policies
paths:
/authorization-policies:
get:
tags:
- Authorization Policies
operationId: listAuthorizationPolicies
summary: List Authorization Policies
description: List Authorization Policies in provided Project with optional filtering.
parameters:
- description: Project ID where to search for Authorization Policies.
in: query
name: project_id
required: true
style: form
explode: true
schema:
type: string
- description: Full fetch of all data. If not provided, only metadata is returned.
in: query
name: full_fetch
required: false
style: form
explode: true
schema:
type: boolean
- description: List only objects, that contains given search query in name, display name or description
in: query
name: search
required: false
style: form
explode: true
schema:
type: string
- description: Type of policy to filter by, can be 'kbac' or 'ciq'.
in: query
name: type
required: false
style: form
explode: true
schema:
type: string
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.listConfigResponse-httpproxy_readAuthorizationPolicyResponse'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
'401':
description: Invalid ServiceAccount JWT in Authorization header
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'403':
description: Forbidden
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'404':
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
security:
- BearerToken: []
post:
tags:
- Authorization Policies
operationId: createAuthorizationPolicy
summary: Create Authorization Policy
description: Create Authorization Policy in provided Project.
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.createAuthorizationPolicyRequest'
description: Create Authorization Policy request
required: true
responses:
'201':
description: Created
headers:
etag:
description: Multiversion concurrency control version - etag
style: simple
explode: false
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.createConfigResponse'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
'401':
description: Invalid ServiceAccount JWT in Authorization header
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'403':
description: Forbidden
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'404':
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
x-codegen-request-body-name: request
security:
- BearerToken: []
/authorization-policies/{id}:
delete:
tags:
- Authorization Policies
operationId: deleteAuthorizationPolicy
summary: Delete Authorization Policy
description: Delete Authorization Policy by provided ID. You can optionally can specify etag in If-Match header.
parameters:
- description: Authorization Policy ID
in: path
name: id
required: true
style: simple
explode: false
schema:
type: string
- description: Multiversion concurrency control version - etag
in: header
name: If-Match
required: false
style: simple
explode: false
schema:
type: string
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.deleteConfigResponse'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
'401':
description: Invalid ServiceAccount JWT in Authorization header
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'403':
description: Forbidden
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'404':
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
security:
- BearerToken: []
get:
tags:
- Authorization Policies
operationId: getAuthorizationPolicy
summary: Read Authorization Policy
description: Read Authorization Policy identified by provided ID.
parameters:
- description: Authorization Policy ID or name
in: path
name: id
required: true
style: simple
explode: false
schema:
type: string
- description: Version of configuration to read. If not provided, latest version is returned.
in: query
name: version
required: false
style: form
explode: true
schema:
type: integer
- description: Parent project ID. Required when querying by name
in: query
name: location
required: false
style: form
explode: true
schema:
type: string
responses:
'200':
description: OK
headers:
etag:
description: Multiversion concurrency control version - etag
style: simple
explode: false
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.readAuthorizationPolicyResponse'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
'401':
description: Invalid ServiceAccount JWT in Authorization header
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'403':
description: Forbidden
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'404':
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
security:
- BearerToken: []
put:
tags:
- Authorization Policies
operationId: updateAuthorizationPolicy
summary: Update Authorization Policy
description: Update Authorization Policy identified by provided ID and optionally etag in If-Match header.
parameters:
- description: Authorization Policy ID
in: path
name: id
required: true
style: simple
explode: false
schema:
type: string
- description: Multiversion concurrency control version - etag.
in: header
name: If-Match
required: false
style: simple
explode: false
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.updateAuthorizationPolicyRequest'
description: Update Authorization Policy request.
required: true
responses:
'200':
description: OK
headers:
etag:
description: Multiversion concurrency control version - etag
style: simple
explode: false
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/httpproxy.updateConfigResponse'
'400':
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
'401':
description: Invalid ServiceAccount JWT in Authorization header
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'403':
description: Forbidden
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'404':
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
x-codegen-request-body-name: request
security:
- BearerToken: []
components:
schemas:
httpproxy.createAuthorizationPolicyRequest:
properties:
description:
description: Description is optional description of configuration.
maxLength: 65000
minLength: 2
type: string
display_name:
description: DisplayName is optional human readable name of configuration.
maxLength: 254
minLength: 2
type: string
name:
description: 'Name is URL friendly identifier of configuration, must be unique in scope of parent entity.
Also is immutable and cannot be changed later.'
type: string
policy:
description: Policy is required to be valid JSON format of policy. Format differs based on policy type.
maxLength: 512000
type: string
project_id:
description: 'ProjectID is identifier of Project, formerly known as Application space,
where to place this new configuration object. Must be in GID format.'
type: string
status:
description: Status of policy specify whenever it is active or not. If status is DRAFT, it is possible to save invalid policy.
enum:
- ACTIVE
- INACTIVE
- DRAFT
type: string
tags:
items:
type: string
type: array
required:
- name
- policy
- project_id
- status
type: object
httpproxy.updateConfigResponse:
properties:
create_time:
description: CreateTime specify when configuration was created.
type: string
created_by:
description: CreatedBy specify who created configuration.
type: string
id:
description: ID of configuration to update.
type: string
update_time:
description: UpdateTime specify when configuration was last time updated.
type: string
updated_by:
description: UpdatedBy specify who last time updated configuration.
type: string
type: object
httpproxy.updateAuthorizationPolicyRequest:
properties:
description:
description: 'Description is optional description of configuration. When kept null, it is not changed.
But when set to empty string, it will be removed.'
maxLength: 65000
type: string
display_name:
description: 'DisplayName is optional human readable name of configuration. When kept null, it is not changed.
But when set to empty string, it will be removed.'
maxLength: 254
type: string
policy:
description: Policy is required to be valid JSON format of policy. Format differs based on policy type.
maxLength: 512000
type: string
status:
description: Status of policy specify whenever it is active or not. If status is DRAFT, it is possible to save invalid policy.
enum:
- ACTIVE
- INACTIVE
- DRAFT
type: string
tags:
items:
type: string
type: array
required:
- policy
- status
type: object
httpproxy.listConfigResponse-httpproxy_readAuthorizationPolicyResponse:
properties:
data:
items:
$ref: '#/components/schemas/httpproxy.readAuthorizationPolicyResponse'
type: array
type: object
httpproxy.deleteConfigResponse:
properties:
id:
description: ID of deleted configuration.
type: string
type: object
restapi.DetailedError:
properties:
errors:
items:
type: string
type: array
message:
type: string
type: object
restapi.ErrorResponse:
properties:
message:
example: Internal Server Error
type: string
type: object
httpproxy.createConfigResponse:
properties:
create_time:
description: CreateTime specify when configuration was created.
type: string
created_by:
description: CreatedBy specify who created configuration.
type: string
id:
description: ID is globally unique identifier of created configuration.
type: string
update_time:
description: UpdateTime specify when configuration was last time updated.
type: string
updated_by:
description: UpdatedBy specify who last time updated configuration.
type: string
type: object
httpproxy.readAuthorizationPolicyResponse:
properties:
create_time:
description: CreateTime specify when configuration was created.
type: string
created_by:
description: CreatedBy specify who created configuration.
type: string
description:
description: Description is optional description of configuration.
type: string
display_name:
description: DisplayName is optional human readable name of configuration. Is equal to Name if not set.
type: string
id:
description: ID is globally unique identifier of configuration.
type: string
name:
description: Name is URL friendly identifier of configuration.
type: string
organization_id:
description: 'OrganizationID is globally unique identifier of organization, formerly known as customer,
under which configuration was created.'
type: string
policy:
type: string
project_id:
description: 'ProjectID is globally unique identifier of project, formerly known as application space,
under which configuration was created.
Might be empty, if configuration is created directly under organization.'
type: string
status:
type: string
tags:
items:
type: string
type: array
update_time:
description: UpdateTime specify when configuration was last time updated.
type: string
updated_by:
description: UpdatedBy specify who last time updated configuration.
type: string
type: object
securitySchemes:
BearerToken:
type: http
scheme: bearer
bearerFormat: JWT
description: Bearer token generated from Service Account credentials.
x-original-swagger-version: '2.0'