Infisical SPIFFE Auth API

The SPIFFE Auth API from Infisical — 3 operation(s) for spiffe auth.

Operations 6

POST /api/v1/auth/spiffe-auth/login #
POST /api/v1/auth/spiffe-auth/identities/{identityId} #
PATCH /api/v1/auth/spiffe-auth/identities/{identityId} #
GET /api/v1/auth/spiffe-auth/identities/{identityId} #
DELETE /api/v1/auth/spiffe-auth/identities/{identityId} #
POST /api/v1/auth/spiffe-auth/identities/{identityId}/refresh-bundle #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/infisical-spiffe-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

infisical-spiffe-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Infisical Admin SPIFFE Auth API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
- url: https://us.infisical.com
  description: Production server (US)
- url: https://eu.infisical.com
  description: Production server (EU)
- url: http://localhost:8080
  description: Local server
tags:
- name: SPIFFE Auth
paths:
  /api/v1/auth/spiffe-auth/login:
    post:
      operationId: loginWithSpiffeAuth
      tags:
      - SPIFFE Auth
      description: Login with SPIFFE Auth (JWT-SVID) for machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                identityId:
                  type: string
                  description: The ID of the machine identity to login.
                jwt:
                  type: string
                  description: The JWT-SVID token to authenticate with.
                organizationSlug:
                  type: string
                  minLength: 1
                  maxLength: 64
                  description: When set, this will scope the login session to the specified organization the machine identity has access to. If omitted, the session defaults to the organization where the machine identity was created in.
              required:
              - identityId
              - jwt
              additionalProperties: false
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  accessToken:
                    type: string
                  expiresIn:
                    type: number
                  accessTokenMaxTTL:
                    type: number
                  tokenType:
                    type: string
                    enum:
                    - Bearer
                required:
                - accessToken
                - expiresIn
                - accessTokenMaxTTL
                - tokenType
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
  /api/v1/auth/spiffe-auth/identities/{identityId}:
    post:
      operationId: attachSpiffeAuth
      tags:
      - SPIFFE Auth
      description: Attach SPIFFE Auth configuration onto machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                trustDomain:
                  type: string
                  minLength: 1
                  description: The SPIFFE trust domain (e.g. prod.example.com).
                allowedSpiffeIds:
                  type: string
                  minLength: 1
                  description: Comma-separated list of allowed SPIFFE ID patterns. Supports picomatch glob patterns (e.g. spiffe://prod.example.com/**).
                allowedAudiences:
                  type: string
                  minLength: 1
                  description: Comma-separated list of allowed audiences for JWT-SVID validation.
                trustBundleDistribution:
                  anyOf:
                  - type: object
                    properties:
                      profile:
                        type: string
                        enum:
                        - static
                        description: 'The trust bundle distribution profile. Must be one of: ''static'' (admin uploads JWKS), ''https_web_bundle'' (auto-refresh from HTTPS endpoint).'
                      bundle:
                        type: string
                        minLength: 1
                        description: The JWKS JSON containing public keys for JWT-SVID verification. Required when profile is 'static'.
                    required:
                    - profile
                    - bundle
                    additionalProperties: false
                  - type: object
                    properties:
                      profile:
                        type: string
                        enum:
                        - https_web_bundle
                        description: 'The trust bundle distribution profile. Must be one of: ''static'' (admin uploads JWKS), ''https_web_bundle'' (auto-refresh from HTTPS endpoint).'
                      endpointUrl:
                        type: string
                        format: uri
                        description: The SPIRE bundle endpoint URL for automatic trust bundle retrieval. Required when profile is 'https_web_bundle'.
                      caCert:
                        type: string
                        description: Optional PEM-encoded root CA certificate for verifying the bundle endpoint TLS connection. Defaults to system root CAs when not provided.
                      refreshHintSeconds:
                        type: integer
                        minimum: 0
                        default: 3600
                        description: The interval in seconds between bundle refresh attempts. Defaults to 3600.
                    required:
                    - profile
                    - endpointUrl
                    additionalProperties: false
                accessTokenTrustedIps:
                  type: array
                  items:
                    type: object
                    properties:
                      ipAddress:
                        type: string
                    required:
                    - ipAddress
                    additionalProperties: false
                  minItems: 1
                  default:
                  - ipAddress: 0.0.0.0/0
                  - ipAddress: ::/0
                  description: The IPs or CIDR ranges that access tokens can be used from.
                accessTokenTTL:
                  type: integer
                  minimum: 0
                  maximum: 315360000
                  default: 2592000
                  description: The lifetime for an access token in seconds.
                accessTokenMaxTTL:
                  type: integer
                  minimum: 0
                  maximum: 315360000
                  default: 2592000
                  description: The maximum lifetime for an access token in seconds.
                accessTokenNumUsesLimit:
                  type: integer
                  minimum: 0
                  default: 0
                  description: The maximum number of times that an access token can be used.
              required:
              - trustDomain
              - allowedSpiffeIds
              - allowedAudiences
              - trustBundleDistribution
              additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to attach the configuration onto.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identitySpiffeAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      identityId:
                        type: string
                        format: uuid
                      trustDomain:
                        type: string
                      allowedSpiffeIds:
                        type: string
                      allowedAudiences:
                        type: string
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      trustBundleDistribution:
                        anyOf:
                        - type: object
                          properties:
                            profile:
                              type: string
                              enum:
                              - static
                            bundle:
                              type: string
                          required:
                          - profile
                          - bundle
                          additionalProperties: false
                        - type: object
                          properties:
                            profile:
                              type: string
                              enum:
                              - https_web_bundle
                            endpointUrl:
                              type: string
                            caCert:
                              type: string
                            refreshHintSeconds:
                              type: number
                            cachedBundleLastRefreshedAt:
                              type:
                              - string
                              - 'null'
                              format: date-time
                          required:
                          - profile
                          - endpointUrl
                          - caCert
                          - refreshHintSeconds
                          additionalProperties: false
                    required:
                    - id
                    - identityId
                    - trustDomain
                    - allowedSpiffeIds
                    - allowedAudiences
                    - createdAt
                    - updatedAt
                    - trustBundleDistribution
                    additionalProperties: false
                required:
                - identitySpiffeAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    patch:
      operationId: updateSpiffeAuth
      tags:
      - SPIFFE Auth
      description: Update SPIFFE Auth configuration on machine identity
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                trustDomain:
                  type: string
                  minLength: 1
                  description: The SPIFFE trust domain (e.g. prod.example.com).
                allowedSpiffeIds:
                  type: string
                  minLength: 1
                  description: Comma-separated list of allowed SPIFFE ID patterns. Supports picomatch glob patterns (e.g. spiffe://prod.example.com/**).
                allowedAudiences:
                  type: string
                  minLength: 1
                  description: Comma-separated list of allowed audiences for JWT-SVID validation.
                trustBundleDistribution:
                  anyOf:
                  - type: object
                    properties:
                      profile:
                        type: string
                        enum:
                        - static
                        description: 'The trust bundle distribution profile. Must be one of: ''static'' (admin uploads JWKS), ''https_web_bundle'' (auto-refresh from HTTPS endpoint).'
                      bundle:
                        type: string
                        minLength: 1
                        description: The JWKS JSON containing public keys for JWT-SVID verification. Required when profile is 'static'.
                    required:
                    - profile
                    - bundle
                    additionalProperties: false
                  - type: object
                    properties:
                      profile:
                        type: string
                        enum:
                        - https_web_bundle
                        description: 'The trust bundle distribution profile. Must be one of: ''static'' (admin uploads JWKS), ''https_web_bundle'' (auto-refresh from HTTPS endpoint).'
                      endpointUrl:
                        type: string
                        format: uri
                        description: The SPIRE bundle endpoint URL for automatic trust bundle retrieval. Required when profile is 'https_web_bundle'.
                      caCert:
                        type: string
                        description: Optional PEM-encoded root CA certificate for verifying the bundle endpoint TLS connection. Defaults to system root CAs when not provided.
                      refreshHintSeconds:
                        type: integer
                        minimum: 0
                        default: 3600
                        description: The interval in seconds between bundle refresh attempts. Defaults to 3600.
                    required:
                    - profile
                    - endpointUrl
                    additionalProperties: false
                accessTokenTrustedIps:
                  type: array
                  items:
                    type: object
                    properties:
                      ipAddress:
                        type: string
                    required:
                    - ipAddress
                    additionalProperties: false
                  minItems: 1
                  default:
                  - ipAddress: 0.0.0.0/0
                  - ipAddress: ::/0
                  description: The IPs or CIDR ranges that access tokens can be used from.
                accessTokenTTL:
                  type: integer
                  minimum: 0
                  maximum: 315360000
                  default: 2592000
                  description: The lifetime for an access token in seconds.
                accessTokenMaxTTL:
                  type: integer
                  minimum: 0
                  maximum: 315360000
                  default: 2592000
                  description: The maximum lifetime for an access token in seconds.
                accessTokenNumUsesLimit:
                  type: integer
                  minimum: 0
                  default: 0
                  description: The maximum number of times that an access token can be used.
              additionalProperties: false
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to update the auth method for.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identitySpiffeAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      identityId:
                        type: string
                        format: uuid
                      trustDomain:
                        type: string
                      allowedSpiffeIds:
                        type: string
                      allowedAudiences:
                        type: string
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      trustBundleDistribution:
                        anyOf:
                        - type: object
                          properties:
                            profile:
                              type: string
                              enum:
                              - static
                            bundle:
                              type: string
                          required:
                          - profile
                          - bundle
                          additionalProperties: false
                        - type: object
                          properties:
                            profile:
                              type: string
                              enum:
                              - https_web_bundle
                            endpointUrl:
                              type: string
                            caCert:
                              type: string
                            refreshHintSeconds:
                              type: number
                            cachedBundleLastRefreshedAt:
                              type:
                              - string
                              - 'null'
                              format: date-time
                          required:
                          - profile
                          - endpointUrl
                          - caCert
                          - refreshHintSeconds
                          additionalProperties: false
                    required:
                    - id
                    - identityId
                    - trustDomain
                    - allowedSpiffeIds
                    - allowedAudiences
                    - createdAt
                    - updatedAt
                    - trustBundleDistribution
                    additionalProperties: false
                required:
                - identitySpiffeAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 422
                  message: {}
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                    - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                - reqId
                - statusCode
                - message
                - error
                additionalProperties: false
    get:
      operationId: getSpiffeAuth
      tags:
      - SPIFFE Auth
      description: Retrieve SPIFFE Auth configuration on machine identity
      parameters:
      - schema:
          type: string
        in: path
        name: identityId
        required: true
        description: The ID of the machine identity to retrieve the auth method for.
      security:
      - bearerAuth: []
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identitySpiffeAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      identityId:
                        type: string
                        format: uuid
                      trustDomain:
                        type: string
                      allowedSpiffeIds:
                        type: string
                      allowedAudiences:
                        type: string
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      trustBundleDistribution:
                        anyOf:
                        - type: object
                          properties:
                            profile:
                              type: string
                              enum:
                              - static
                            bundle:
                              type: string
                          required:
                          - profile
                          - bundle
                          additionalProperties: false
                        - type: object
                          properties:
                            profile:
                              type: string
                              enum:
                              - https_web_bundle
                            endpointUrl:
                              type: string
                            caCert:
                              type: string
                            refreshHintSeconds:
                              type: number
                            cachedBun

# --- truncated at 32 KB (51 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/infisical/refs/heads/main/openapi/infisical-spiffe-auth-api-openapi.yml