Indykite AuthZEN API
Authorization API implemented according to [AuthZEN specification](https://openid.net/wg/authzen/specifications/).
Authorization API implemented according to [AuthZEN specification](https://openid.net/wg/authzen/specifications/).
openapi: 3.2.0
info:
contact: {}
description: Config API supports CRUD operations on config objects.
title: Config REST Application Agent Credentials AuthZEN API
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0
version: '1'
servers:
- url: https://eu.api.indykite.com/configs/v1
- url: https://us.api.indykite.com/configs/v1
security:
- BearerToken: []
tags:
- description: Authorization API implemented according to [AuthZEN specification](https://openid.net/wg/authzen/specifications/).
name: AuthZEN
x-displayName: AuthZEN
paths:
/access/v1/evaluation:
post:
summary: AuthZEN specified Evaluation endpoint
description: Evaluate the authorization request and return decision in response.
tags:
- AuthZEN
operationId: createAccessV1Evaluation
security:
- APIKey: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.EvaluationRequest'
description: Evaluation request
required: true
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.EvaluationResponse'
'400':
description: Bad request
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/restapi.DetailedError'
- properties:
errors:
items:
type: string
type: array
message:
type: string
type: object
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/restapi.ErrorResponse'
- properties:
message:
type: string
type: object
x-codegen-request-body-name: request
/access/v1/evaluations:
post:
operationId: createAccessV1Evaluations
summary: AuthZEN specified Evaluations endpoint
security:
- APIKey: []
description: Evaluate multiple authorization requests at once and return decisions in response.
tags:
- AuthZEN
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.EvaluationsRequest'
description: Evaluation request
required: true
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.EvaluationsResponse'
'400':
description: Bad request
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/restapi.DetailedError'
- properties:
errors:
items:
type: string
type: array
message:
type: string
type: object
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
x-codegen-request-body-name: request
/access/v1/search/action:
post:
operationId: createAccessV1SearchAction
summary: AuthZEN specified Action Search API
security:
- APIKey: []
description: Search for actions allowed to be done by the specified subject on the specified resource.
tags:
- AuthZEN
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.SearchActionRequest'
description: Action Search request
required: true
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.SearchActionResponse'
'400':
description: Bad request
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/restapi.DetailedError'
- properties:
errors:
items:
type: string
type: array
message:
type: string
type: object
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
x-codegen-request-body-name: request
/access/v1/search/resource:
post:
operationId: createAccessV1SearchResource
summary: AuthZEN specified Resource Search API
security:
- APIKey: []
description: Search for resources that the specified subject is allowed to do the specified action on.
tags:
- AuthZEN
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.SearchResourceRequest'
description: Resource Search request
required: true
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.SearchResourceResponse'
'400':
description: Bad request
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/restapi.DetailedError'
- properties:
errors:
items:
type: string
type: array
message:
type: string
type: object
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
x-codegen-request-body-name: request
/access/v1/search/subject:
post:
operationId: createAccessV1SearchSubject
summary: AuthZEN specified Subject Search API
security:
- APIKey: []
description: Search for subjects allowed to do the specified action on the specified resource.
tags:
- AuthZEN
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.SearchSubjectRequest'
description: Subject Search request
required: true
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.SearchSubjectResponse'
'400':
description: Bad request
content:
application/json:
schema:
allOf:
- $ref: '#/components/schemas/restapi.DetailedError'
- properties:
errors:
items:
type: string
type: array
message:
type: string
type: object
'422':
description: Unprocessable Entity
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.DetailedError'
'500':
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/restapi.ErrorResponse'
x-codegen-request-body-name: request
components:
schemas:
restapi.Node:
type: object
required:
- id
- type
properties:
id:
type: string
description: ID is a node external_id.
examples:
- IdSpecifyingTheNode
type:
type: string
description: Type is a node label.
examples:
- NodeType
examples:
- id: IdSpecifyingTheNode
type: NodeType
restapi.Context:
type: object
properties:
input_params:
type: object
additionalProperties: {}
description: 'InputParams map specifies the values of input parameters used within the policies.
If a policy uses input parameters and is used for making the decision,
they must be sent with the request, otherwise an error is returned.'
examples:
- additionalProp1: {}
additionalProp2: {}
policy_tags:
type: array
description: PolicyTags array limits the policies used to only the policies with the specified tags.
items:
type: string
uniqueItems: true
examples:
- - tag1
- tag2
examples:
- input_params:
additionalProp1: {}
additionalProp2: {}
policy_tags:
- Tag1
- Tag2
restapi.respContext:
type: object
properties:
advice:
type: array
items:
type: object
additionalProperties:
type: string
reason:
type: string
examples:
- advice:
- error: insufficient_user_authentication
error_description: A different authentication level is required
acr_values: whatever
restapi.EvaluationResponse:
type: object
properties:
context:
$ref: '#/components/schemas/restapi.respContext'
decision:
type: boolean
examples:
- true
examples:
- context:
advice:
- error: insufficient_user_authentication
error_description: A different authentication level is required
acr_values: whatever
decision: true
restapi.SearchSubjectRequest:
type: object
required:
- action
- resource
- subject
properties:
action:
$ref: '#/components/schemas/restapi.Action'
context:
$ref: '#/components/schemas/restapi.Context'
resource:
$ref: '#/components/schemas/restapi.Node'
subject:
$ref: '#/components/schemas/restapi.NodeType'
restapi.OptionalFields:
type: object
properties:
action:
$ref: '#/components/schemas/restapi.Action'
context:
$ref: '#/components/schemas/restapi.Context'
resource:
$ref: '#/components/schemas/restapi.Node'
subject:
$ref: '#/components/schemas/restapi.Node'
restapi.NodeType:
type: object
required:
- type
properties:
type:
type: string
examples:
- NodeType
restapi.SearchActionRequest:
type: object
required:
- resource
- subject
properties:
context:
$ref: '#/components/schemas/restapi.Context'
resource:
$ref: '#/components/schemas/restapi.Node'
subject:
$ref: '#/components/schemas/restapi.Node'
restapi.EvaluationsResponse:
type: object
properties:
evaluations:
type: array
items:
$ref: '#/components/schemas/restapi.EvaluationResponse'
restapi.SearchActionResponse:
type: object
properties:
results:
type: array
items:
$ref: '#/components/schemas/restapi.Action'
restapi.DetailedError:
type: object
properties:
errors:
type: array
description: Errors are optional and may contain additional details.
items:
type: string
examples:
- - missing bearer token
message:
type: string
description: Message describes the error.
examples:
- unauthorized request
restapi.SearchResourceResponse:
type: object
properties:
results:
type: array
items:
$ref: '#/components/schemas/restapi.Node'
restapi.SearchResourceRequest:
type: object
required:
- action
- resource
- subject
properties:
action:
$ref: '#/components/schemas/restapi.Action'
context:
$ref: '#/components/schemas/restapi.Context'
resource:
$ref: '#/components/schemas/restapi.NodeType'
subject:
$ref: '#/components/schemas/restapi.Node'
restapi.ErrorResponse:
type: object
properties:
message:
type: string
examples:
- Internal Server Error
restapi.SearchSubjectResponse:
type: object
properties:
results:
type: array
items:
$ref: '#/components/schemas/restapi.Node'
restapi.EvaluationsRequest:
type: object
required:
- evaluations
properties:
action:
$ref: '#/components/schemas/restapi.Action'
context:
$ref: '#/components/schemas/restapi.Context'
evaluations:
type: array
items:
$ref: '#/components/schemas/restapi.OptionalFields'
resource:
$ref: '#/components/schemas/restapi.Node'
subject:
$ref: '#/components/schemas/restapi.Node'
restapi.Action:
type: object
required:
- name
properties:
name:
type: string
description: Name specifies the action.
examples:
- CAN_READ
examples:
- name: CAN_READ
restapi.EvaluationRequest:
type: object
required:
- action
- resource
- subject
properties:
action:
$ref: '#/components/schemas/restapi.Action'
context:
$ref: '#/components/schemas/restapi.Context'
resource:
$ref: '#/components/schemas/restapi.Node'
subject:
$ref: '#/components/schemas/restapi.Node'
examples:
- action:
name: CAN_READ
context:
input_params:
additionalProp1: {}
additionalProp2: {}
policy_tags:
- Tag1
- Tag2
resource:
id: IdSpecifyingTheNode
type: NodeType
subject:
id: IdSpecifyingTheNode
type: NodeType
securitySchemes:
BearerToken:
type: http
scheme: bearer
bearerFormat: JWT
description: Bearer token generated from Service Account credentials.
x-original-swagger-version: '2.0'