Kong Portal Auth Settings API

APIs related to configuration of Konnect Developer Portal auth settings.

OpenAPI Specification

kong-portal-auth-settings-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API.


    You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com).

    Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.'
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: Kong Enterprise Admin ACLs Portal Auth Settings API
  version: 3.14.0
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
security:
- adminToken: []
tags:
- name: Portal Auth Settings
  description: APIs related to configuration of Konnect Developer Portal auth settings.
paths:
  /v3/portals/{portalId}/authentication-settings:
    parameters:
    - $ref: '#/components/parameters/PortalId'
    get:
      x-speakeasy-entity-operation:
        terraform-resource: PortalAuth#read
        terraform-datasource: null
      operationId: get-portal-authentication-settings
      summary: Get Auth Settings
      description: Returns the developer authentication configuration for a portal, which determines how developers can log in and how they are assigned to teams.
      responses:
        '200':
          $ref: '#/components/responses/PortalAuthenticationSettings'
        '401':
          $ref: '#/components/responses/Unauthorized'
      tags:
      - Portal Auth Settings
    patch:
      x-speakeasy-entity-operation:
        terraform-resource: PortalAuth#create,update
        terraform-datasource: null
      operationId: update-portal-authentication-settings
      summary: Update Auth Settings
      description: Updates the developer authentication configuration for a portal. Developers can be allowed to login using basic auth (email & password) or use Single-Sign-On through an Identity Provider. Developers can be automatically assigned to teams by mapping claims from their IdP account.
      requestBody:
        $ref: '#/components/requestBodies/UpdatePortalAuthenticationSettings'
      responses:
        '200':
          $ref: '#/components/responses/PortalAuthenticationSettings'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/BadRequestError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Portal Auth Settings
  /v3/portals/{portalId}/identity-provider/team-group-mappings:
    parameters:
    - $ref: '#/components/parameters/PortalId'
    get:
      operationId: list-portal-team-group-mappings
      summary: List Team Group Mappings
      description: '**Pre-release Endpoint**

        This endpoint is currently in beta and is subject to change.


        Lists mappings between Konnect portal teams and Identity Provider (IdP) groups. Returns a 400 error if an IdP has not yet been configured.'
      parameters:
      - $ref: '#/components/parameters/PageSize'
      - $ref: '#/components/parameters/PageNumber'
      responses:
        '200':
          $ref: '#/components/responses/PortalTeamGroupMappingCollection'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/BadRequestError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Portal Auth Settings
    patch:
      operationId: update-portal-team-group-mappings
      summary: Update Team Group Mappings
      description: '**Pre-release Endpoint**

        This endpoint is currently in beta and is subject to change.


        Allows partial updates to the mappings between Konnect portal teams and Identity Provider (IdP) groups. The request body must be keyed on team ID. For a given team ID, the given group list is a complete replacement. To remove all mappings for a given team, provide an empty group list.

        Returns a 400 error if an IdP has not yet been configured, or if a team ID in the request body is not found or is not a UUID.'
      requestBody:
        $ref: '#/components/requestBodies/UpdatePortalTeamGroupMappings'
      responses:
        '200':
          $ref: '#/components/responses/PortalTeamGroupMappingCollection'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/BadRequestError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Portal Auth Settings
  /v3/portals/{portalId}/identity-providers:
    parameters:
    - $ref: '#/components/parameters/PortalId'
    get:
      operationId: get-portal-identity-providers
      summary: List Identity Providers
      description: 'Retrieves the identity providers available within the portal. This operation provides information about

        various identity providers for SAML or OIDC authentication integrations.

        '
      parameters:
      - name: filter
        in: query
        description: Filter identity providers returned in the response.
        required: false
        schema:
          type: object
          properties:
            type:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
        style: deepObject
      responses:
        '200':
          $ref: '#/components/responses/IdentityProviders'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Portal Auth Settings
    post:
      operationId: create-portal-identity-provider
      summary: Create Identity Provider
      description: 'Creates a new identity provider. This operation allows the creation of a new identity provider for

        authentication purposes.

        '
      requestBody:
        $ref: '#/components/requestBodies/CreateIdentityProviderRequest'
      responses:
        '201':
          $ref: '#/components/responses/IdentityProvider'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          $ref: '#/components/responses/Conflict'
      tags:
      - Portal Auth Settings
  /v3/portals/{portalId}/identity-providers/{id}:
    parameters:
    - $ref: '#/components/parameters/PortalId'
    - $ref: '#/components/parameters/IdentityProviderId'
    get:
      operationId: get-portal-identity-provider
      summary: Get Identity Provider
      description: 'Retrieves the configuration of a single identity provider. This operation returns information about a

        specific identity provider''s settings and authentication integration details.

        '
      responses:
        '200':
          $ref: '#/components/responses/IdentityProvider'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Portal Auth Settings
    patch:
      operationId: update-portal-identity-provider
      summary: Update Identity Provider
      description: 'Updates the configuration of an existing identity provider. This operation allows modifications to be made

        to an existing identity provider''s configuration.

        '
      requestBody:
        $ref: '#/components/requestBodies/UpdateIdentityProviderRequest'
      responses:
        '200':
          $ref: '#/components/responses/IdentityProvider'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
      tags:
      - Portal Auth Settings
    delete:
      operationId: delete-portal-identity-provider
      summary: Delete Identity Provider
      description: 'Deletes an existing identity provider configuration. This operation removes a specific identity provider

        from the portal.

        '
      responses:
        '204':
          description: No Content
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Portal Auth Settings
  /v3/portals/{portalId}/identity-providers/{id}/team-group-mappings:
    parameters:
    - $ref: '#/components/parameters/PortalId'
    - $ref: '#/components/parameters/IdentityProviderId'
    get:
      operationId: list-portal-idp-team-group-mappings
      summary: List Team Group Mappings
      description: 'Returns a paginated list of team group mappings for the specified identity provider.

        '
      parameters:
      - $ref: '#/components/parameters/PageSize'
      - $ref: '#/components/parameters/PageAfter'
      - $ref: '#/components/parameters/PageBefore'
      - name: filter
        in: query
        description: Filter mappings by team ID or group name.
        required: false
        schema:
          type: object
          properties:
            team_id:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
            group:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
        style: deepObject
      responses:
        '200':
          $ref: '#/components/responses/PortalIdpTeamGroupMappingCollection'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Portal Auth Settings
    post:
      operationId: create-portal-idp-team-group-mapping
      summary: Create Team Group Mapping
      description: 'Creates a new team group mapping for the specified identity provider.

        '
      requestBody:
        $ref: '#/components/requestBodies/CreatePortalIdpTeamGroupMapping'
      responses:
        '201':
          $ref: '#/components/responses/PortalIdpTeamGroupMapping'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
      tags:
      - Portal Auth Settings
  /v3/portals/{portalId}/identity-providers/{id}/team-group-mappings/{mappingId}:
    parameters:
    - $ref: '#/components/parameters/PortalId'
    - $ref: '#/components/parameters/IdentityProviderId'
    - $ref: '#/components/parameters/TeamGroupMappingId'
    get:
      operationId: get-portal-idp-team-group-mapping
      summary: Get Team Group Mapping
      description: Returns the team group mapping for the specified ID.
      responses:
        '200':
          $ref: '#/components/responses/PortalIdpTeamGroupMapping'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Portal Auth Settings
    delete:
      operationId: delete-portal-idp-team-group-mapping
      summary: Delete Team Group Mapping
      description: 'Deletes a team group mapping by ID.

        Returns 204 if the mapping was deleted, or 404 if the mapping was not found.

        '
      responses:
        '204':
          description: No Content
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Portal Auth Settings
components:
  responses:
    PortalTeamGroupMappingCollection:
      description: A paginated collection of mappings grouped by team ID.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PortalTeamGroupMappingResponse'
    PortalIdpTeamGroupMapping:
      description: A team group mapping for an identity provider.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PortalIdpTeamGroupMapping'
    NotFound:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/NotFoundError'
    BadRequest:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/BadRequestError'
    IdentityProviders:
      description: 'A collection of identity providers. This response contains a collection of identity providers, which may  include both OIDC and SAML identity providers.

        '
      content:
        application/json:
          schema:
            type: array
            items:
              $ref: '#/components/schemas/IdentityProvider'
            title: Identity Provider Collection Response
    Conflict:
      description: Conflict
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ConflictError'
    PortalAuthenticationSettings:
      description: Details about a portal's authentication settings.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PortalAuthenticationSettingsResponse'
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            description: The error response object.
            type: object
            properties:
              status:
                description: The HTTP status code.
                type: integer
                example: 403
              title:
                description: The Error Response.
                type: string
                example: Unauthorized
              instance:
                description: The Konnect traceback code.
                type: string
                example: konnect:trace:952172606039454040
              detail:
                description: Details about the error response.
                type: string
                example: You do not have permission to perform this action
            $ref: '#/components/schemas/UnauthorizedError'
            title: Unauthorized Response
    PortalIdpTeamGroupMappingCollection:
      description: A paginated collection of team group mappings.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PortalIdpTeamGroupMappingCollectionResponse'
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ForbiddenError'
    IdentityProvider:
      description: 'An identity provider configuration. This response represents the configuration of a specific identity provider, which can be either OIDC or SAML.

        '
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/IdentityProvider'
  schemas:
    IdentityProvider:
      x-speakeasy-entity: IdentityProvider
      description: The identity provider that contains configuration data for authentication integration.
      type: object
      properties:
        id:
          $ref: '#/components/schemas/UUID'
        type:
          $ref: '#/components/schemas/IdentityProviderType'
        enabled:
          $ref: '#/components/schemas/IdentityProviderEnabled'
        login_path:
          $ref: '#/components/schemas/IdentityProviderLoginPath'
        config:
          type: object
          oneOf:
          - $ref: '#/components/schemas/OIDCIdentityProviderConfig'
          - $ref: '#/components/schemas/SAMLIdentityProviderConfig'
        created_at:
          $ref: '#/components/schemas/CreatedAt'
        updated_at:
          $ref: '#/components/schemas/UpdatedAt'
      title: Identity Provider
    InvalidParameterMinimumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - min_length
          - min_digits
          - min_lowercase
          - min_uppercase
          - min_symbols
          - min_items
          - min
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - minimum
    SAMLIdentityProviderMetadata:
      description: 'The identity provider''s SAML metadata. If the identity provider supports a metadata URL, you can use the `idp_metadata_url` field instead.

        '
      type: string
      example: "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<EntityDescriptor xmlns=\"urn:oasis:names:tc:SAML:2.0:metadata\">\n  <!-- SAML metadata content here -->\n</EntityDescriptor>\n"
      title: SAML Identity Provider Metadata
    PortalTeamGroupMappingResponse:
      description: A paginated list of portal team group mappings.
      type: object
      properties:
        meta:
          $ref: '#/components/schemas/PaginatedMeta'
        data:
          type: array
          items:
            $ref: '#/components/schemas/PortalTeamGroupMapping'
      example:
        meta:
          page:
            number: 1
            size: 10
            total: 2
        data:
        - team_id: 6801e673-cc10-498a-94cd-4271de07a0d3
          groups:
          - Tech Leads
          - API Engineers
        - team_id: 7301e673-cc10-498a-94cd-4271de07a0d3
          groups:
          - Managers
          - Directors
      title: PortalTeamGroupMappingResponse
    PortalIdpTeamGroupMapping:
      type: object
      properties:
        id:
          description: The mapping ID.
          type: string
          format: uuid
          example: a1b2c3d4-e5f6-4a8b-9c0d-1e2f3a4b5c6d
          readOnly: true
        team_id:
          description: The Konnect team ID.
          type: string
          format: uuid
          example: 6801e673-cc10-498a-94cd-4271de07a0d3
        group:
          description: The IdP group name.
          type: string
          example: API Engineers
        created_at:
          description: Creation timestamp.
          type: string
          format: date-time
          example: '2024-01-15T10:30:00Z'
          readOnly: true
        updated_at:
          description: Last update timestamp.
          type: string
          format: date-time
          example: '2024-01-15T10:30:00Z'
          readOnly: true
      required:
      - id
      - team_id
      - group
      - created_at
      - updated_at
    UpdatedAt:
      description: An ISO-8601 timestamp representation of entity update date.
      type: string
      format: date-time
      example: '2022-11-04T20:10:06.927Z'
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    InvalidParameterChoiceItem:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - enum
          nullable: false
          readOnly: true
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          items: {}
          minItems: 1
          nullable: false
          readOnly: true
          uniqueItems: true
        source:
          type: string
          example: body
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - choices
    ConflictError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 409
          title:
            example: Conflict
          type:
            example: https://httpstatuses.com/409
          instance:
            example: kong:trace:1234567890
          detail:
            example: Conflict
    InvalidParameterMaximumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - max_length
          - max_items
          - max
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - maximum
    OIDCIdentityProviderClaimMappings:
      description: "Defines the mappings between OpenID Connect (OIDC) claims and local claims used by your application for \nauthentication.\n"
      type: object
      properties:
        name:
          description: The claim mapping for the user's name.
          type: string
          example: name
          default: name
        email:
          description: The claim mapping for the user's email address.
          type: string
          example: email
          default: email
        groups:
          description: The claim mapping for the user's group membership information.
          type: string
          example: groups
          default: groups
      title: OIDC Claim Mappings
    OIDCIdentityProviderScopes:
      description: The scopes requested by your application when authenticating with the identity provider.
      type: array
      items:
        type: string
      default:
      - email
      - openid
      - profile
      title: OIDC Identity Provider Scopes Property
    PortalTeamGroupMappingsUpdateRequest:
      description: A set of mappings to update from a team to their groups.
      type: object
      properties:
        data:
          description: The IdP groups to map to the given team.
          type: array
          items:
            type: object
            properties:
              team_id:
                type: string
                format: uuid
              groups:
                type: array
                items:
                  type: string
      example:
        data:
        - team_id: af91db4c-6e51-403e-a2bf-33d27ae50c0a
          groups:
          - Service Developer
      title: PortalTeamGroupMappingsUpdateRequest
    PortalTeamGroupMapping:
      description: A map of portal teams to Identity Provider groups.
      type: object
      properties:
        team_id:
          description: The Konnect team ID.
          type: string
          format: uuid
          example: 6801e673-cc10-498a-94cd-4271de07a0d3
        groups:
          description: The IdP groups that are mapped to the specified team.
          type: array
          items:
            type: string
            example: API Engineers
          uniqueItems: true
      example:
        team_id: 6801e673-cc10-498a-94cd-4271de07a0d3
        groups:
        - Tech Leads
        - API Engineers
      title: PortalTeamGroupMapping
    IdentityProviderLoginPath:
      description: The path used for initiating login requests with the identity provider.
      type: string
      example: myapp
      title: Identity Provider Login Path Property
    UpdateIdentityProvider:
      x-speakeasy-entity: IdentityProvider
      description: The identity provider that contains configuration data for updating an authentication integration.
      type: object
      properties:
        enabled:
          $ref: '#/components/schemas/IdentityProviderEnabled'
        login_path:
          $ref: '#/components/schemas/IdentityProviderLoginPath'
        config:
          type: object
          oneOf:
          - $ref: '#/components/schemas/OIDCIdentityProviderConfig'
          - $ref: '#/components/schemas/SAMLIdentityProviderConfig'
      title: Identity Provider
    PortalClaimMappings:
      description: Mappings from a portal developer atribute to an Identity Provider claim.
      type: object
      properties:
        name:
          type: string
          example: name
          default: name
        email:
          type: string
          example: email
          default: email
        groups:
          type: string
          example: custom-group-claim
          default: groups
      example:
        name: name
        email: email
        groups: custom-group-claim
      maxProperties: 3
      minProperties: 0
      title: PortalClaimMappings
    CreateIdentityProvider:
      x-speakeasy-entity: IdentityProvider
      description: The identity provider that contains configuration data for creating an authentication integration.
      type: object
      properties:
        type:
          $ref: '#/components/schemas/IdentityProviderType'
        enabled:
          $ref: '#/components/schemas/IdentityProviderEnabled'
        login_path:
          $ref: '#/components/schemas/IdentityProviderLoginPath'
        config:
          type: object
          oneOf:
          - $ref: '#/components/schemas/OIDCIdentityProviderConfig'
          - $ref: '#/components/schemas/SAMLIdentityProviderConfig'
      title: Identity Provider
    UUID:
      description: Contains a unique identifier used for this resource.
      type: string
      format: uuid
      example: 5f9fd312-a987-4628-b4c5-bb4f4fddd5f7
      readOnly: true
    SAMLAuthEnabled:
      description: A Konnect Identity Admin assigns teams to a developer.
      type: boolean
      example: false
      deprecated: true
      x-speakeasy-param-computed: true
    ForbiddenError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 403
          title:
            example: Forbidden
          type:
            example: https://httpstatuses.com/403
          instance:
            example: kong:trace:1234567890
          detail:
            example: Forbidden
    UnauthorizedError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 401
          title:
            example: Unauthorized
          type:
            example: https://httpstatuses.com/401
          instance:
            example: kong:trace:1234567890
          detail:
            example: Invalid credentials
    CursorMetaPage:
      type: object
      properties:
        first:
          description: URI to the first page
          type: string
          format: path
        last:
          description: URI to the last page
          type: string
          format: path
        next:
          description: URI to the next page
          type: string
          format: path
          nullable: true
        previous:
          description: URI to the previous page
          type: string
          format: path
          nullable: true
        size:
          description: Requested page size
          type: number
          example: 10
      required:
      - size
      - next
      - previous
    CreatePortalIdpTeamGroupMappingRequest:
      type: object
      properties:
        team_id:
          description: The Konnect team ID.
          type: string
          format: uuid
          example: 6801e673-cc10-498a-94cd-4271de07a0d3
        group:
          description: The IdP group name.
          type: string
          example: API Engineers
      required:
      - team_id
      - group
    SAMLIdentityProviderMetadataURL:
      description: The identity provider's metadata URL where the identity provider's metadata can be obtained.
      type: string
      format: uri
      example: https://mocksaml.com/api/saml/metadata
      title: SAML Identity Provider Metadata URL
    CursorMeta:
      description: Pagination metadata.
      type: object
      properties:
        page:
          $ref: '#/components/schemas/CursorMetaPage'
      required:
      - page
    OIDCIdentityProviderClientSecret:
      description: The Client Secret assigned to your application by the identity provider.
      type: string
      example: YOUR_CLIENT_SECRET
      title: OIDC Identity Provider Login Client Secret Property
      writeOnly: true
      x-speakeasy-param-sensitive: true
      x-speakeasy-terraform-plan-only: true
    PortalAuthenticationSettingsResponse:
      x-speakeasy-entity: PortalAuth
      description: The developer authentication settings for a portal.
      type: object
      properties:
        basic_auth_enabled:
          description: The portal has basic auth enabled or disabled.
          type: boolean
          example: true
        oidc_auth_enabled:
          $ref: '#/components/schemas/OIDCAuthEnabled'
        saml_auth_enabled:
          $ref: '#/components/schemas/SAMLAuthEnabled'
        oidc_team_mapping_enabled:
          $ref: '#/components/schemas/OIDCIdpMappingEnabled'
        idp_mapping_enabled:
          $ref: '#/components/schemas/IDPMappingEnabled'
        konnect_mapping_enabled:
          description: A Konnect Identity Admin assigns teams to a developer.
          type: boolean
          example: false
        oidc_config:
          description: Configuration properties for an OpenID Connect Identity Provider.
          type: object
          example:
            issuer: https://identity.example.com/v2
            client_id: x7id0o42lklas0blidl2
            scopes:
            - email
            - openid
            - profile
            claim_mappings:
              name: name
              email: email
              groups: custom-group-claim
          deprecated: true
          properties:
            issuer:
              type: string
              example: https://identity.example.com/v2
            client_id:
              type: string
              example: x7id0o42lklas0blidl2
            scopes:
              type: array
              items:
                type: string
                default: openid
              example:
              - email
              - openid
              - profile
              default:
              - email
              - openid
              - profile
            claim_mappings:
              $ref: '#/components/schemas/PortalClaimMappings'
          readOnly: true
          required:
          - issuer
          - client_id
          title: PortalOIDCConfig
      example:
        basic_auth_enabled: true
        oidc_auth_enabled: true
        oidc_team_mapping_enabled: true
        konnect_mapping_enabled: false
        oidc_config:
          issuer: https://identity.example.com/v2
          client_id: x7id0o42lklas0blidl2
          scopes:
          - email
          - openid
          - profile
          claim_mappings:
            name: name
            email: email
            groups: custom-group-claim
      required:
      - basic_auth_enabled
      - konnect_mapping_enabled
      - oidc_auth_enabled
      - oidc_team_mapping_enabled
      title: PortalAuth

# --- truncated at 32 KB (49 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/kong/refs/heads/main/openapi/kong-portal-auth-settings-api-openapi.yml