Newstore identity-providers API

Identity Providers

OpenAPI Specification

newstore-identity-providers-api-openapi.yml Raw ↑
swagger: '2.0'
info:
  version: '1.0'
  title: NewStore address identity-providers API
  description: NewStore public APIs
  contact:
    email: support@newstore.com
    name: NewStore API Support
    url: https://developer.newstore.com
host: dodici-demo.p.newstore.net
basePath: /
schemes:
- https
consumes:
- application/json
produces:
- application/json
security: []
tags:
- name: identity-providers
  description: Identity Providers
paths:
  /iam/providers:
    get:
      description: Returns a list of configured identity providers for the tenant
      summary: listProviders
      tags:
      - identity-providers
      operationId: listProviders
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters: []
      responses:
        default:
          description: Default Response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: OK
          schema:
            $ref: '#/definitions/IdentityProvidersResponse'
          headers: {}
        '400':
          description: Bad Request
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:providers:read
    post:
      description: Creates and configures a new identity provider for the vendor / protocol combination.
      summary: createProvider
      tags:
      - identity-providers
      operationId: createProvider
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      consumes:
      - application/json
      parameters:
      - name: Content-Type
        in: header
        required: false
        enum:
        - application/json
        type: string
        description: ''
      - name: body
        in: body
        required: true
        description: provider configuration
        schema:
          $ref: '#/definitions/CreateIdentityProviderRequest'
      responses:
        default:
          description: Default Response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '201':
          description: Created
          schema:
            $ref: '#/definitions/IdentityProvidersResponse'
          headers: {}
        '400':
          description: Bad Request
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '409':
          description: Conflict
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:providers:write
  /iam/providers/{alias}:
    delete:
      description: Deletes the identity provider identified by its alias
      summary: destroyProvider
      tags:
      - identity-providers
      operationId: destroyProvider
      deprecated: false
      produces:
      - application/problem+json
      parameters:
      - name: alias
        in: path
        required: true
        type: string
        description: identity provider alias
      responses:
        default:
          description: Default Response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '204':
          description: No Content
          headers: {}
        '401':
          description: Unauthorized
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Not Found
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:providers:write
    get:
      description: Returns the identity provider identified by its alias
      summary: showProvider
      tags:
      - identity-providers
      operationId: showProvider
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters:
      - name: alias
        in: path
        required: true
        type: string
        description: identity provider alias
      responses:
        default:
          description: Default Response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: OK
          schema:
            $ref: '#/definitions/IdentityProviderResponse'
          headers: {}
        '400':
          description: Bad Request
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Not Found
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:providers:read
    patch:
      description: Change the configuration of the identity provider identified by its alias
      summary: updateProvider
      tags:
      - identity-providers
      operationId: updateProvider
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      consumes:
      - application/json
      parameters:
      - name: alias
        in: path
        required: true
        type: string
        description: identity provider alias
      - name: Content-Type
        in: header
        required: false
        enum:
        - application/json
        type: string
        description: ''
      - name: body
        in: body
        required: true
        description: provider configuration
        schema:
          $ref: '#/definitions/UpdateIdentityProviderRequest'
      responses:
        default:
          description: Default Response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: OK
          schema:
            $ref: '#/definitions/IdentityProviderResponse'
          headers: {}
        '400':
          description: Bad Request
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Not Found
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:providers:write
  /iam/supported-providers:
    get:
      description: Returns a list of supported identity providers and protocols
      summary: listSupportedProviders
      tags:
      - identity-providers
      operationId: listSupportedProviders
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters: []
      responses:
        default:
          description: Default Response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: OK
          schema:
            $ref: '#/definitions/SupportedIdentityProviders'
          headers: {}
        '401':
          description: Unauthorized
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:providers:read
definitions:
  IdentityProviderVendor:
    title: IdentityProviderVendor
    description: Supported Vendors for Identity Providers
    type: string
    enum:
    - MICROSOFT
    - OKTA
    - GOOGLE
  UpdateIdentityProviderRequest:
    title: UpdateIdentityProviderRequest
    description: Update an Identity Provider.
    type: object
    properties:
      config: {}
      enabled:
        type: boolean
        default: true
    required:
    - config
  Problem:
    title: Problem
    type: object
    properties:
      detail:
        description: A human readable explanation specific to this occurrence of the problem that is helpful to locate the problem and give advice on how to proceed. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
        example: some description for the error situation
        type: string
      error_code:
        type: string
      instance:
        description: A URI reference that identifies the specific occurrence of the problem, e.g. by adding a fragment identifier or sub-path to the problem type. May be used to locate the root of this problem in the source code.
        example: /some/uri-reference#specific-occurrence-context
        type: string
      message:
        type: string
      messages:
        type: array
        items:
          type: string
      request_id:
        type: string
      status:
        description: The HTTP status code generated by the origin server for this occurrence of the problem.
        type: integer
        minimum: 100.0
        maximum: 600.0
        exclusiveMaximum: true
        format: int32
      title:
        description: A short summary of the problem type. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
        example: some title for the error situation
        type: string
      type:
        description: A URI reference that uniquely identifies the problem type only in the context of the provided API. Opposed to the specification in RFC-7807, it is neither recommended to be dereferenceable and point to a human-readable documentation nor globally unique for the problem type.
        example: /some/uri-reference
        type: string
        default: about:blank
  IdentityProviderResponse:
    title: IdentityProviderResponse
    description: Configured identity provider
    type: object
    properties:
      alias:
        description: The unique name of the configured IdP
        type: string
      config:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderConfig'
        - description: Identity Provider configuration
      enabled:
        type: boolean
        default: true
      protocol:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderProtocol'
        - description: Supported Protocols for Identity Providers
      vendor:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderVendor'
        - description: Supported Vendors for Identity Providers
  CreateIdentityProviderRequest:
    title: CreateIdentityProviderRequest
    description: Create an Identity Provider
    type: object
    properties:
      config: {}
      enabled:
        type: boolean
        default: true
      protocol:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderProtocol'
        - description: Supported Protocols for Identity Providers
      vendor:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderVendor'
        - description: Supported Vendors for Identity Providers
    required:
    - config
    - protocol
    - vendor
  IdentityProvidersResponse:
    title: IdentityProvidersResponse
    description: A list of configured identity providers
    type: object
    properties:
      items:
        type: array
        items:
          $ref: '#/definitions/IdentityProviderResponse'
  SupportedIdentityProvider:
    title: SupportedIdentityProvider
    description: Supported identity providers and protocols
    type: object
    properties:
      protocol:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderProtocol'
        - description: Supported Protocols for Identity Providers
      vendor:
        type: object
        allOf:
        - $ref: '#/definitions/IdentityProviderVendor'
        - description: Supported Vendors for Identity Providers
  SupportedIdentityProviders:
    title: SupportedIdentityProviders
    description: A list of supported identity providers and protocols
    type: object
    properties:
      items:
        type: array
        items:
          $ref: '#/definitions/SupportedIdentityProvider'
  IdentityProviderConfig:
    title: IdentityProviderConfig
    description: Identity Provider configuration
    type: object
    properties:
      client_id:
        type: string
      directory_id:
        type: string
      entity_id:
        type: string
      logout_uri:
        type: string
      redirect_uri:
        type: string
  IdentityProviderProtocol:
    title: IdentityProviderProtocol
    description: Supported Protocols for Identity Providers
    type: string
    enum:
    - OIDC
    - SAML
securityDefinitions:
  oauth:
    type: oauth2
    flow: application
    tokenUrl: https://id.p.newstore.net/auth/realms/dodici-demo/protocol/openid-connect/token
    scopes:
      catalog:import-schemas:read: Grants privileges to read import schema
      catalog:import-schemas:write: Grants privileges to write import schema
      catalog:pricebook-export:read: Grants privileges to export pricebook data
      catalog:product-export:read: Grants privileges to export product data
      checkout:carts:read: Grants privileges to read cart data
      checkout:carts:write: Grants privileges to write cart data
      clienteling:profile:read: Grants privileges to read clienteling profiles
      customer:profile:read: Grants privileges to read API customer data
      customer:profile:write: Grants privileges to modify API customer data
      newstore:configuration:read: Grants privileges to read configuration
      newstore:configuration:write: Grants privileges to write configuration
      fiscalization:orders:read: View orders with fiscal transactions and signatures
      fiscalization:orders:write: Create orders with fiscal transactions and signatures
      shipments:read: Read Shipping Options and Audits
      iam:providers:read: ' Grants read privileges to provider resources'
      iam:providers:write: ' Grants write privileges to provider resources'
      iam:roles:read: ' Grants privileges to read roles data'
      iam:roles:write: ' Grants privileges to write roles data'
      iam:users:read: ' Grants privileges to read user data'
      iam:users:write: ' Grants privileges to write user data'
      inventory:reservations:read: Allows access to retrieve reservations
      inventory:reservations:write: Allows access to create and update reservations
      promotions:config:read: Grants privileges to read configuration
      promotions:config:write: Grants privileges to write into configuration
      promotions:reason-codes:read: Grants privileges to list reason codes
      promotions:reason-codes:write: Grants privileges to create and update reason codes
      audit-events:read: Grants read access to the tenant's audit events.
      taxes:preview-transactions:write: Preview tax transactions
      taxes:transactions:read: Read tax transactions