Infisical LDAP Auth API

The LDAP Auth API from Infisical — 3 operation(s) for ldap auth.

Operations 6

POST /api/v1/auth/ldap-auth/login #
POST /api/v1/auth/ldap-auth/identities/{identityId} #
PATCH /api/v1/auth/ldap-auth/identities/{identityId} #
GET /api/v1/auth/ldap-auth/identities/{identityId} #
DELETE /api/v1/auth/ldap-auth/identities/{identityId} #
POST /api/v1/auth/ldap-auth/identities/{identityId}/clear-lockouts #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/infisical-ldap-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

infisical-ldap-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Infisical Admin LDAP Auth API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
- url: https://us.infisical.com
  description: Production server (US)
- url: https://eu.infisical.com
  description: Production server (EU)
- url: http://localhost:8080
  description: Local server
tags:
- name: LDAP Auth
paths:
  /api/v1/auth/ldap-auth/login:
    post:
      operationId: loginWithLdapAuth
      tags:
      - LDAP Auth
      description: Login with LDAP Auth for machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                identityId:
                  type: string
                  format: uuid
                  description: The ID of the machine identity to login.
                username:
                  type: string
                  minLength: 1
                  description: The username of the LDAP user to login.
                password:
                  type: string
                  minLength: 1
                  description: The password of the LDAP user to login.
                organizationSlug:
                  type: string
                  minLength: 1
                  maxLength: 64
                  description: When set, this will scope the login session to the specified organization the machine identity has access to. If omitted, the session defaults to the organization where the machine identity was created in.
              required:
              - identityId
              - username
              - password
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  accessToken:
                    type: string
                  expiresIn:
                    type: number
                  accessTokenMaxTTL:
                    type: number
                  tokenType:
                    type: string
                    enum:
                    - Bearer
                required:
                - accessToken
                - expiresIn
                - accessTokenMaxTTL
                - tokenType
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v1/auth/ldap-auth/identities/{identityId}:
    post:
      operationId: attachLdapAuth
      tags:
      - LDAP Auth
      description: Attach LDAP Auth configuration onto machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              anyOf:
              - type: object
                properties:
                  templateId:
                    type: string
                    description: The ID of the identity auth template to attach the configuration onto.
                  searchFilter:
                    type: string
                    minLength: 1
                    default: (uid={{username}})
                    description: The filter to use to search for the LDAP user.
                  allowedFields:
                    type: array
                    items:
                      type: object
                      properties:
                        key:
                          type: string
                        value:
                          type: string
                      required:
                      - key
                      - value
                      additionalProperties: false
                    description: The comma-separated array of key/value pairs of required fields that the LDAP entry must have in order to authenticate.
                  ldapCaCertificate:
                    type: string
                    description: The PEM-encoded CA certificate for the LDAP server.
                  accessTokenTrustedIps:
                    type: array
                    items:
                      type: object
                      properties:
                        ipAddress:
                          type: string
                      required:
                      - ipAddress
                      additionalProperties: false
                    minItems: 1
                    default:
                    - ipAddress: 0.0.0.0/0
                    - ipAddress: ::/0
                    description: The IPs or CIDR ranges that access tokens can be used from.
                  accessTokenTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The lifetime for an access token in seconds.
                  accessTokenMaxTTL:
                    type: integer
                    minimum: 1
                    maximum: 315360000
                    default: 2592000
                    description: The maximum lifetime for an access token in seconds.
                  accessTokenNumUsesLimit:
                    type: integer
                    minimum: 0
                    default: 0
                    description: The maximum number of times that an access token can be used.
                  lockoutEnabled:
                    type: boolean
                    default: true
                    description: Whether the lockout feature is enabled.
                  lockoutThreshold:
                    type: number
                    minimum: 1
                    maximum: 30
                    default: 3
                    description: The amount of times login must fail before locking the identity auth method.
                  lockoutDurationSeconds:
                    type: number
                    minimum: 30
                    maximum: 86400
                    default: 300
                    description: How long an identity auth method lockout lasts.
                  lockoutCounterResetSeconds:
                    type: number
                    minimum: 5
                    maximum: 3600
                    default: 30
                    description: How long to wait from the most recent failed login until resetting the lockout counter.
                required:
                - templateId
                additionalProperties: false
              - type: object
                properties:
                  url:
                    type: string
                    description: The URL of the LDAP server.
                  bindDN:
                    type: string
                    description: The DN of the user to bind to the LDAP server.
                  bindPass:
                    type: string
                    description: The password of the user to bind to the LDAP server.
                  searchBase:
                    type: string
                    description: The base DN to search for the LDAP user.
                  searchFilter:
                    type: string
                    minLength: 1
                    default: (uid={{username}})
                    description: The filter to use to search for the LDAP user.
                  allowedFields:
                    type: array
                    items:
                      type: object
                      properties:
                        key:
                          type: string
                        value:
                          type: string
                      required:
                      - key
                      - value
                      additionalProperties: false
                    description: The comma-separated array of key/value pairs of required fields that the LDAP entry must have in order to authenticate.
                  ldapCaCertificate:
                    type: string
                    description: The PEM-encoded CA certificate for the LDAP server.
                  accessTokenTrustedIps:
                    type: array
                    items:
                      type: object
                      properties:
                        ipAddress:
                          type: string
                      required:
                      - ipAddress
                      additionalProperties: false
                    minItems: 1
                    default:
                    - ipAddress: 0.0.0.0/0
                    - ipAddress: ::/0
                    description: The IPs or CIDR ranges that access tokens can be used from.
                  accessTokenTTL:
                    type: integer
                    minimum: 0
                    maximum: 315360000
                    default: 2592000
                    description: The lifetime for an access token in seconds.
                  accessTokenMaxTTL:
                    type: integer
                    minimum: 1
                    maximum: 315360000
                    default: 2592000
                    description: The maximum lifetime for an access token in seconds.
                  accessTokenNumUsesLimit:
                    type: integer
                    minimum: 0
                    default: 0
                    description: The maximum number of times that an access token can be used.
                  lockoutEnabled:
                    type: boolean
                    default: true
                    description: Whether the lockout feature is enabled.
                  lockoutThreshold:
                    type: number
                    minimum: 1
                    maximum: 30
                    default: 3
                    description: The amount of times login must fail before locking the identity auth method.
                  lockoutDurationSeconds:
                    type: number
                    minimum: 30
                    maximum: 86400
                    default: 300
                    description: How long an identity auth method lockout lasts.
                  lockoutCounterResetSeconds:
                    type: number
                    minimum: 5
                    maximum: 3600
                    default: 30
                    description: How long to wait from the most recent failed login until resetting the lockout counter.
                required:
                - url
                - bindDN
                - bindPass
                - searchBase
                additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to attach the configuration onto.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identityLdapAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      identityId:
                        type: string
                        format: uuid
                      url:
                        type: string
                      searchBase:
                        type: string
                      searchFilter:
                        type: string
                      allowedFields: {}
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      accessTokenPeriod:
                        type: number
                        default: 0
                      templateId:
                        type:
                        - string
                        - 'null'
                        format: uuid
                      lockoutEnabled:
                        type: boolean
                        default: true
                      lockoutThreshold:
                        type: number
                        default: 3
                      lockoutDurationSeconds:
                        type: number
                        default: 300
                      lockoutCounterResetSeconds:
                        type: number
                        default: 30
                    required:
                    - id
                    - identityId
                    - url
                    - searchBase
                    - searchFilter
                    - createdAt
                    - updatedAt
                    additionalProperties: false
                required:
                - identityLdapAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    patch:
      operationId: updateLdapAuth
      tags:
      - LDAP Auth
      description: Update LDAP Auth configuration on machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                url:
                  type: string
                  minLength: 1
                  description: The new URL of the LDAP server.
                bindDN:
                  type: string
                  minLength: 1
                  description: The new DN of the user to bind to the LDAP server.
                bindPass:
                  type: string
                  minLength: 1
                  description: The new password of the user to bind to the LDAP server.
                searchBase:
                  type: string
                  minLength: 1
                  description: The new base DN to search for the LDAP user.
                templateId:
                  type: string
                  description: The ID of the identity auth template to update the configuration to.
                searchFilter:
                  type: string
                  minLength: 1
                  description: The new filter to use to search for the LDAP user.
                allowedFields:
                  type: array
                  items:
                    type: object
                    properties:
                      key:
                        type: string
                      value:
                        type: string
                    required:
                    - key
                    - value
                    additionalProperties: false
                  description: The comma-separated list of allowed fields to return from the LDAP user.
                accessTokenTrustedIps:
                  type: array
                  items:
                    type: object
                    properties:
                      ipAddress:
                        type: string
                    required:
                    - ipAddress
                    additionalProperties: false
                  minItems: 1
                  description: The new IPs or CIDR ranges that access tokens can be used from.
                accessTokenTTL:
                  type: integer
                  minimum: 0
                  maximum: 315360000
                  description: The new lifetime for an access token in seconds.
                accessTokenNumUsesLimit:
                  type: integer
                  minimum: 0
                  description: The new maximum number of times that an access token can be used.
                accessTokenMaxTTL:
                  type: integer
                  maximum: 315360000
                  minimum: 0
                  description: The new maximum lifetime for an access token in seconds.
                lockoutEnabled:
                  type: boolean
                  description: Whether the lockout feature is enabled.
                lockoutThreshold:
                  type: number
                  minimum: 1
                  maximum: 30
                  description: The amount of times login must fail before locking the identity auth method.
                lockoutDurationSeconds:
                  type: number
                  minimum: 30
                  maximum: 86400
                  description: How long an identity auth method lockout lasts.
                lockoutCounterResetSeconds:
                  type: number
                  minimum: 5
                  maximum: 3600
                  description: How long to wait from the most recent failed login until resetting the lockout counter.
              additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to update the configuration for.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identityLdapAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      identityId:
                        type: string
                        format: uuid
                      url:
                        type: string
                      searchBase:
                        type: string
                      searchFilter:
                        type: string
                      allowedFields: {}
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      accessTokenPeriod:
                        type: number
                        default: 0
                      templateId:
                        type:
                        - string
                        - 'null'
                        format: uuid
                      lockoutEnabled:
                        type: boolean
                        default: true
                      lockoutThreshold:
                        type: number
                        default: 3
                      lockoutDurationSeconds:
                        type: number
                        default: 300
                      lockoutCounterResetSeconds:
                        type: number
                        default: 30
                    required:
                    - id
                    - identityId
                    - url
                    - searchBase
                    - searchFilter
                    - createdAt
                    - updatedAt
                    additionalProperties: false
                required:
                - identityLdapAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    get:
      operationId: getLdapAuth
      tags:
      - LDAP Auth
      description: Retrieve LDAP Auth configuration on machine identity
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to retrieve the configuration for.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identityLdapAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      identityId:
                        type: string
                        format: uuid
                      url:
        

# --- truncated at 32 KB (48 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-ldap-auth-api-openapi.yml