InfluxDB Legacy Authorizations API

The Legacy Authorizations API from InfluxDB — 3 operation(s) for legacy authorizations.

OpenAPI Specification

influxdb-legacy-authorizations-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  title: Complete InfluxDB Cloud Authorizations (API tokens) Authorizations (API tokens) Legacy Authorizations API
  description: 'Create and manage authorizations (API tokens).


    An _authorization_ contains a list of `read` and `write`

    permissions for organization resources and provides an API token for authentication.

    An authorization belongs to an organization and only contains permissions for that organization.


    We recommend the following for managing your tokens:


    - Create a generic user to create and manage tokens for writing data.

    - Store your tokens in a secure password vault for future access.


    ### User sessions with authorizations


    Optionally, when creating an authorization, you can scope it to a specific user.

    If the user signs in with username and password, creating a _user session_,

    the session carries the permissions granted by all the user''s authorizations.

    For more information, see [how to assign a token to a specific user](https://docs.influxdata.com/influxdb/cloud/security/tokens/create-token/).

    To create a user session, use the [`POST /api/v2/signin` endpoint](#operation/PostSignin).


    ### Related endpoints


    - [Signin](#tag/Signin)

    - [Signout](#tag/Signout)


    ### Related guides


    - [Authorize API requests](https://docs.influxdata.com/influxdb/cloud/api-guide/api_intro/#authentication)

    - [Manage API tokens](https://docs.influxdata.com/influxdb/cloud/security/tokens/)

    - [Assign a token to a specific user](https://docs.influxdata.com/influxdb/cloud/security/tokens/create-token/)

    '
servers:
- url: ''
security:
- TokenAuthentication: []
tags:
- name: Legacy Authorizations
paths:
  /legacy/authorizations:
    servers:
    - url: /private
    get:
      operationId: GetLegacyAuthorizations
      parameters:
      - $ref: '#/components/parameters/TraceSpan'
      - description: 'A user ID.

          Only returns legacy authorizations scoped to the specified [user]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#user).

          '
        in: query
        name: userID
        schema:
          type: string
      - description: 'A user name.

          Only returns legacy authorizations scoped to the specified [user]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#user).

          '
        in: query
        name: user
        schema:
          type: string
      - description: 'An organization ID.

          Only returns legacy authorizations that belong to the specified [organization]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#organization).

          '
        in: query
        name: orgID
        schema:
          type: string
      - description: 'An organization name.

          Only returns legacy authorizations that belong to the specified [organization]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#organization).

          '
        in: query
        name: org
        schema:
          type: string
      - description: 'An authorization name token.

          Only returns legacy authorizations with the specified name.

          '
        in: query
        name: token
        schema:
          type: string
      - description: 'An authorization ID.

          Returns the specified legacy authorization.

          '
        in: query
        name: authID
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  authorizations:
                    items:
                      $ref: '#/components/schemas/Authorization'
                    type: array
                  links:
                    $ref: '#/components/schemas/Links'
                    readOnly: true
                type: object
          description: Success. The response body contains a list of legacy `authorizations`.
        default:
          $ref: '#/components/responses/ServerError'
          description: Unexpected error
      summary: List all legacy authorizations
      tags:
      - Legacy Authorizations
    post:
      description: 'Creates a legacy authorization and returns the legacy authorization.


        #### Required permissions


        - `write-users USER_ID` if you pass the `userID` property in the request body.


        *`USER_ID`* is the ID of the user that you want to scope the authorization to.

        '
      operationId: PostLegacyAuthorizations
      parameters:
      - $ref: '#/components/parameters/TraceSpan'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LegacyAuthorizationPostRequest'
        description: The legacy authorization to create.
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Authorization'
          description: 'Created. The legacy authorization is created.

            The response body contains the newly created legacy authorization.

            '
        '400':
          $ref: '#/components/responses/ServerError'
          description: Invalid request
        '401':
          content:
            application/json:
              examples:
                unauthorizedWriteUsers:
                  summary: The token doesn't have the write:user permission
                  value:
                    code: unauthorized
                    message: write:users/08028e90933bf000 is unauthorized
              schema:
                properties:
                  code:
                    description: 'The HTTP status code description. Default is `unauthorized`.

                      '
                    enum:
                    - unauthorized
                    readOnly: true
                    type: string
                  message:
                    description: A human-readable message that may contain detail about the error.
                    readOnly: true
                    type: string
          description: 'Unauthorized.

            The API token passed doesn''t have the permissions necessary for the

            request.

            '
        default:
          $ref: '#/components/responses/ServerError'
          description: Unexpected error
      summary: Create a legacy authorization
      tags:
      - Legacy Authorizations
  /legacy/authorizations/{authID}:
    servers:
    - url: /private
    delete:
      operationId: DeleteLegacyAuthorizationsID
      parameters:
      - $ref: '#/components/parameters/TraceSpan'
      - description: The ID of the legacy authorization to delete.
        in: path
        name: authID
        required: true
        schema:
          type: string
      responses:
        '204':
          description: Legacy authorization deleted
        default:
          $ref: '#/components/responses/ServerError'
          description: Unexpected error
      summary: Delete a legacy authorization
      tags:
      - Legacy Authorizations
    get:
      operationId: GetLegacyAuthorizationsID
      parameters:
      - $ref: '#/components/parameters/TraceSpan'
      - description: The ID of the legacy authorization to get.
        in: path
        name: authID
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Authorization'
          description: Legacy authorization details
        default:
          $ref: '#/components/responses/ServerError'
          description: Unexpected error
      summary: Retrieve a legacy authorization
      tags:
      - Legacy Authorizations
    patch:
      operationId: PatchLegacyAuthorizationsID
      parameters:
      - $ref: '#/components/parameters/TraceSpan'
      - description: The ID of the legacy authorization to update.
        in: path
        name: authID
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthorizationUpdateRequest'
        description: Legacy authorization to update
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Authorization'
          description: The active or inactive legacy authorization
        default:
          $ref: '#/components/responses/ServerError'
          description: Unexpected error
      summary: Update a legacy authorization to be active or inactive
      tags:
      - Legacy Authorizations
  /legacy/authorizations/{authID}/password:
    servers:
    - url: /private
    post:
      operationId: PostLegacyAuthorizationsIDPassword
      parameters:
      - $ref: '#/components/parameters/TraceSpan'
      - description: The ID of the legacy authorization to update.
        in: path
        name: authID
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              properties:
                password:
                  type: string
              required:
              - password
        description: New password
        required: true
      responses:
        '204':
          description: Legacy authorization password set
        default:
          $ref: '#/components/responses/ServerError'
          description: Unexpected error
      summary: Set a legacy authorization password
      tags:
      - Legacy Authorizations
components:
  schemas:
    Permission:
      properties:
        action:
          enum:
          - read
          - write
          type: string
        resource:
          $ref: '#/components/schemas/Resource'
          properties:
            id:
              description: 'A resource ID.

                Identifies a specific resource.

                '
              type: string
            name:
              description: 'The name of the resource.

                _Note: not all resource types have a `name` property_.

                '
              type: string
            org:
              description: 'An organization name.

                The organization that owns the resource.

                '
              type: string
            orgID:
              description: 'An organization ID.

                Identifies the organization that owns the resource.

                '
              type: string
            type:
              description: 'A resource type.

                Identifies the API resource''s type (or _kind_).

                '
              enum:
              - authorizations
              - buckets
              - dashboards
              - orgs
              - tasks
              - telegrafs
              - users
              - variables
              - secrets
              - labels
              - views
              - documents
              - notificationRules
              - notificationEndpoints
              - checks
              - dbrp
              - annotations
              - sources
              - scrapers
              - notebooks
              - remotes
              - replications
              - instance
              - flows
              - functions
              - subscriptions
              type: string
          required:
          - type
          type: object
      required:
      - action
      - resource
    Links:
      description: 'URI pointers for additional paged results.

        '
      properties:
        next:
          $ref: '#/components/schemas/Link'
        prev:
          $ref: '#/components/schemas/Link'
        self:
          $ref: '#/components/schemas/Link'
      required:
      - self
      type: object
    Resource:
      properties:
        id:
          description: 'A resource ID.

            Identifies a specific resource.

            '
          type: string
        name:
          description: 'The name of the resource.

            _Note: not all resource types have a `name` property_.

            '
          type: string
        org:
          description: 'An organization name.

            The organization that owns the resource.

            '
          type: string
        orgID:
          description: 'An organization ID.

            Identifies the organization that owns the resource.

            '
          type: string
        type:
          description: 'A resource type.

            Identifies the API resource''s type (or _kind_).

            '
          enum:
          - authorizations
          - buckets
          - dashboards
          - orgs
          - tasks
          - telegrafs
          - users
          - variables
          - secrets
          - labels
          - views
          - documents
          - notificationRules
          - notificationEndpoints
          - checks
          - dbrp
          - annotations
          - sources
          - scrapers
          - notebooks
          - remotes
          - replications
          - instance
          - flows
          - functions
          - subscriptions
          type: string
      required:
      - type
      type: object
    Authorization:
      allOf:
      - $ref: '#/components/schemas/AuthorizationUpdateRequest'
      - properties:
          createdAt:
            format: date-time
            readOnly: true
            type: string
          id:
            description: The authorization ID.
            readOnly: true
            type: string
          links:
            example:
              self: /api/v2/authorizations/1
              user: /api/v2/users/12
            properties:
              self:
                $ref: '#/components/schemas/Link'
                readOnly: true
              user:
                $ref: '#/components/schemas/Link'
                readOnly: true
            readOnly: true
            type: object
          org:
            description: 'The organization name.

              Specifies the [organization]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#organization)

              that the token is scoped to.

              '
            readOnly: true
            type: string
          orgID:
            description: 'The organization ID.

              Specifies the [organization]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#organization) that the authorization is scoped to.

              '
            type: string
          permissions:
            description: 'The list of permissions.

              An authorization must have at least one permission.

              '
            items:
              $ref: '#/components/schemas/Permission'
            minItems: 1
            type: array
          token:
            description: 'The API token.

              The token value is unique to the authorization.

              [API tokens]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#token) are

              used to authenticate and authorize InfluxDB API requests and `influx`

              CLI commands--after receiving the request, InfluxDB checks that the

              token is valid and that the `permissions` allow the requested action(s).

              '
            readOnly: true
            type: string
          updatedAt:
            format: date-time
            readOnly: true
            type: string
          user:
            description: 'The user name.

              Specifies the [user]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#user) that owns the authorization.

              If the authorization is _scoped_ to a user, the user;

              otherwise, the creator of the authorization.

              '
            readOnly: true
            type: string
          userID:
            description: The user ID. Specifies the [user]({{% INFLUXDB_DOCS_URL %}}/reference/glossary/#user) that owns the authorization. If _scoped_, the user that the authorization is scoped to; otherwise, the creator of the authorization.
            readOnly: true
            type: string
        type: object
      required:
      - orgID
      - permissions
    Link:
      description: URI of resource.
      format: uri
      readOnly: true
      type: string
    LegacyAuthorizationPostRequest:
      allOf:
      - $ref: '#/components/schemas/AuthorizationUpdateRequest'
      - properties:
          orgID:
            description: The organization ID. Identifies the organization that the authorization is scoped to.
            type: string
          permissions:
            description: 'The list of permissions that provide `read` and `write` access to organization resources.

              An authorization must contain at least one permission.

              '
            items:
              $ref: '#/components/schemas/Permission'
            minItems: 1
            type: array
          token:
            description: The name that you provide for the authorization.
            type: string
          userID:
            description: The user ID. Identifies the user that the authorization is scoped to.
            type: string
        type: object
      required:
      - orgID
      - permissions
    ErrorCode:
      description: code is the machine-readable error code.
      enum:
      - internal error
      - not implemented
      - not found
      - conflict
      - invalid
      - unprocessable entity
      - empty value
      - unavailable
      - forbidden
      - too many requests
      - unauthorized
      - method not allowed
      - request too large
      - unsupported media type
      readOnly: true
      type: string
    AuthorizationUpdateRequest:
      properties:
        description:
          description: A description of the token.
          type: string
        status:
          default: active
          description: Status of the token. If `inactive`, InfluxDB rejects requests that use the token.
          enum:
          - active
          - inactive
          type: string
    Error:
      properties:
        code:
          $ref: '#/components/schemas/ErrorCode'
          description: code is the machine-readable error code.
          enum:
          - internal error
          - not implemented
          - not found
          - conflict
          - invalid
          - unprocessable entity
          - empty value
          - unavailable
          - forbidden
          - too many requests
          - unauthorized
          - method not allowed
          - request too large
          - unsupported media type
          readOnly: true
          type: string
        err:
          description: Stack of errors that occurred during processing of the request. Useful for debugging.
          readOnly: true
          type: string
        message:
          description: Human-readable message.
          readOnly: true
          type: string
        op:
          description: Describes the logical code operation when the error occurred. Useful for debugging.
          readOnly: true
          type: string
      required:
      - code
  responses:
    ServerError:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Non 2XX error response from server.
  parameters:
    TraceSpan:
      description: OpenTracing span context
      example:
        baggage:
          key: value
        span_id: '1'
        trace_id: '1'
      in: header
      name: Zap-Trace-Span
      required: false
      schema:
        type: string
  securitySchemes:
    BasicAuthentication:
      description: "### Basic authentication scheme\n\nUse the HTTP Basic authentication scheme for InfluxDB `/api/v2` API operations that support it:\n\n### Syntax\n\n`Authorization: Basic BASE64_ENCODED_CREDENTIALS`\n\nTo construct the `BASE64_ENCODED_CREDENTIALS`, combine the username and\nthe password with a colon (`USERNAME:PASSWORD`), and then encode the\nresulting string in [base64](https://developer.mozilla.org/en-US/docs/Glossary/Base64).\nMany HTTP clients encode the credentials for you before sending the\nrequest.\n\n_**Warning**: Base64-encoding can easily be reversed to obtain the original\nusername and password. It is used to keep the data intact and does not provide\nsecurity. You should always use HTTPS when authenticating or sending a request with\nsensitive information._\n\n### Examples\n\nIn the examples, replace the following:\n\n- **`EMAIL_ADDRESS`**: InfluxDB Cloud username (the email address the user signed up with)\n- **`PASSWORD`**: InfluxDB Cloud [API token](https://docs.influxdata.com/influxdb/cloud/reference/glossary/#token)\n- **`INFLUX_URL`**: your InfluxDB Cloud URL\n\n#### Encode credentials with cURL\n\nThe following example shows how to use cURL to send an API request that uses Basic authentication.\nWith the `--user` option, cURL encodes the credentials and passes them\nin the `Authorization: Basic` header.\n\n```sh\ncurl --get \"INFLUX_URL/api/v2/signin\"\n    --user \"EMAIL_ADDRESS\":\"PASSWORD\"\n```\n\n#### Encode credentials with Flux\n\nThe Flux [`http.basicAuth()` function](https://docs.influxdata.com/flux/v0.x/stdlib/http/basicauth/) returns a Base64-encoded\nbasic authentication header using a specified username and password combination.\n\n#### Encode credentials with JavaScript\n\nThe following example shows how to use the JavaScript `btoa()` function\nto create a Base64-encoded string:\n\n```js\nbtoa('EMAIL_ADDRESS:PASSWORD')\n```\n\nThe output is the following:\n\n```js\n'VVNFUk5BTUU6UEFTU1dPUkQ='\n```\n\nOnce you have the Base64-encoded credentials, you can pass them in the\n`Authorization` header--for example:\n\n```sh\ncurl --get \"INFLUX_URL/api/v2/signin\"\n    --header \"Authorization: Basic VVNFUk5BTUU6UEFTU1dPUkQ=\"\n```\n\nTo learn more about HTTP authentication, see\n[Mozilla Developer Network (MDN) Web Docs, HTTP authentication](https://developer.mozilla.org/en-US/docs/Web/HTTP/Authentication)._\n"
      scheme: basic
      type: http
    TokenAuthentication:
      description: "Use the [Token authentication](#section/Authentication/TokenAuthentication)\nscheme to authenticate to the InfluxDB API.\n\nIn your API requests, send an `Authorization` header.\nFor the header value, provide the word `Token` followed by a space and an InfluxDB API token.\nThe word `Token` is case-sensitive.\n\n### Syntax\n\n`Authorization: Token INFLUX_API_TOKEN`\n\n### Example\n\n#### Use Token authentication with cURL\n\nThe following example shows how to use cURL to send an API request that uses Token authentication:\n\n```sh\ncurl --request GET \"INFLUX_URL/api/v2/buckets\" \\\n     --header \"Authorization: Token INFLUX_API_TOKEN\"\n```\n\nReplace the following:\n\n  - *`INFLUX_URL`*: your InfluxDB Cloud URL\n  - *`INFLUX_API_TOKEN`*: your [InfluxDB API token](https://docs.influxdata.com/influxdb/cloud/reference/glossary/#token)\n\n### Related endpoints\n\n- [`/authorizations` endpoints](#tag/Authorizations-(API-tokens))\n\n### Related guides\n\n- [Authorize API requests](https://docs.influxdata.com/influxdb/cloud/api-guide/api_intro/#authentication)\n- [Manage API tokens](https://docs.influxdata.com/influxdb/cloud/security/tokens/)\n"
      in: header
      name: Authorization
      type: apiKey
x-tagGroups:
- name: Overview
  tags:
  - Quick start
  - Authentication
  - Supported operations
  - Headers
  - Pagination
  - Response codes
- name: Popular endpoints
  tags:
  - Data I/O endpoints
  - Security and access endpoints
  - System information endpoints
- name: All endpoints
  tags: []