The Things Network / The Things Stack ClientRegistry API

The ClientRegistry API from The Things Network / The Things Stack — 8 operation(s) for clientregistry.

Operations 10

GET /clients List OAuth clients where the given user or organization is a direct collaborator. If no user or organization is given, this returns the OAuth clients the caller has access to. Simi #
PUT /clients/{client.ids.client_id} Update the OAuth client, changing the fields specified by the field mask to the provided values. #
GET /clients/{client_ids.client_id} Get the OAuth client with the given identifiers, selecting the fields specified in the field mask. More or less fields may be returned, depending on the rights of the caller. #
DELETE /clients/{client_id} Delete the OAuth client. This may not release the client ID for reuse. #
DELETE /clients/{client_id}/purge Purge the client. This will release the client ID for reuse. #
POST /clients/{client_id}/restore Restore a recently deleted client. #
GET /organizations/{collaborator.organization_ids.organization_id}/clients List OAuth clients where the given user or organization is a direct collaborator. If no user or organization is given, this returns the OAuth clients the caller has access to. Simi #
POST /organizations/{collaborator.organization_ids.organization_id}/clients Create a new OAuth client. This also sets the given organization or user as first collaborator with all possible rights. #
GET /users/{collaborator.user_ids.user_id}/clients List OAuth clients where the given user or organization is a direct collaborator. If no user or organization is given, this returns the OAuth clients the caller has access to. Simi #
POST /users/{collaborator.user_ids.user_id}/clients Create a new OAuth client. This also sets the given organization or user as first collaborator with all possible rights. #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/the-things-network-clientregistry-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

the-things-network-clientregistry-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Things Stack — Application Server AppAs Client Registry API
  version: v3.36
  description: The Things Stack is an open-source LoRaWAN Network Server implementation. This OpenAPI was derived from the upstream gRPC-Gateway generated api.swagger.json published by TheThingsNetwork/lorawan-stack v3.36.
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  contact:
    name: The Things Industries
    url: https://www.thethingsindustries.com
servers:
- url: https://eu1.cloud.thethings.industries/api/v3
security:
- ApiKeyAuth: []
tags:
- name: ClientRegistry
paths:
  /clients:
    get:
      summary: 'List OAuth clients where the given user or organization is a direct collaborator.

        If no user or organization is given, this returns the OAuth clients the caller

        has access to.

        Similar to Get, this selects the fields specified in the field mask.

        More or less fields may be returned, depending on the rights of the caller.'
      operationId: ClientRegistry_List
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Clients'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: collaborator.organization_ids.organization_id
        description: This ID shares namespace with user IDs.
        in: query
        required: false
        schema:
          type: string
      - name: collaborator.user_ids.user_id
        description: This ID shares namespace with organization IDs.
        in: query
        required: false
        schema:
          type: string
      - name: collaborator.user_ids.email
        description: Secondary identifier, which can only be used in specific requests.
        in: query
        required: false
        schema:
          type: string
      - name: field_mask
        description: The names of the client fields that should be returned.
        in: query
        required: false
        schema:
          type: string
      - name: order
        description: 'Order the results by this field path (must be present in the field mask).

          Default ordering is by ID. Prepend with a minus (-) to reverse the order.'
        in: query
        required: false
        schema:
          type: string
      - name: limit
        description: Limit the number of results per page.
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: page
        description: Page number for pagination. 0 is interpreted as 1.
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: deleted
        description: Only return recently deleted clients.
        in: query
        required: false
        schema:
          type: boolean
      tags:
      - ClientRegistry
  /clients/{client.ids.client_id}:
    put:
      summary: Update the OAuth client, changing the fields specified by the field mask to the provided values.
      operationId: ClientRegistry_Update
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Client'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: client.ids.client_id
        in: path
        required: true
        schema:
          type: string
      tags:
      - ClientRegistry
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v3ClientRegistryUpdateBody'
        required: true
  /clients/{client_ids.client_id}:
    get:
      summary: 'Get the OAuth client with the given identifiers, selecting the fields specified

        in the field mask.

        More or less fields may be returned, depending on the rights of the caller.'
      operationId: ClientRegistry_Get
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Client'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: client_ids.client_id
        in: path
        required: true
        schema:
          type: string
      - name: field_mask
        description: The names of the client fields that should be returned.
        in: query
        required: false
        schema:
          type: string
      tags:
      - ClientRegistry
  /clients/{client_id}:
    delete:
      summary: Delete the OAuth client. This may not release the client ID for reuse.
      operationId: ClientRegistry_Delete
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                type: object
                properties: {}
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: client_id
        in: path
        required: true
        schema:
          type: string
      tags:
      - ClientRegistry
  /clients/{client_id}/purge:
    delete:
      summary: Purge the client. This will release the client ID for reuse.
      operationId: ClientRegistry_Purge
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                type: object
                properties: {}
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: client_id
        in: path
        required: true
        schema:
          type: string
      tags:
      - ClientRegistry
  /clients/{client_id}/restore:
    post:
      summary: Restore a recently deleted client.
      description: 'Deployment configuration may specify if, and for how long after deletion,

        entities can be restored.'
      operationId: ClientRegistry_Restore
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                type: object
                properties: {}
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: client_id
        in: path
        required: true
        schema:
          type: string
      tags:
      - ClientRegistry
  /organizations/{collaborator.organization_ids.organization_id}/clients:
    get:
      summary: 'List OAuth clients where the given user or organization is a direct collaborator.

        If no user or organization is given, this returns the OAuth clients the caller

        has access to.

        Similar to Get, this selects the fields specified in the field mask.

        More or less fields may be returned, depending on the rights of the caller.'
      operationId: ClientRegistry_List3
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Clients'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: collaborator.organization_ids.organization_id
        description: This ID shares namespace with user IDs.
        in: path
        required: true
        schema:
          type: string
      - name: collaborator.user_ids.user_id
        description: This ID shares namespace with organization IDs.
        in: query
        required: false
        schema:
          type: string
      - name: collaborator.user_ids.email
        description: Secondary identifier, which can only be used in specific requests.
        in: query
        required: false
        schema:
          type: string
      - name: field_mask
        description: The names of the client fields that should be returned.
        in: query
        required: false
        schema:
          type: string
      - name: order
        description: 'Order the results by this field path (must be present in the field mask).

          Default ordering is by ID. Prepend with a minus (-) to reverse the order.'
        in: query
        required: false
        schema:
          type: string
      - name: limit
        description: Limit the number of results per page.
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: page
        description: Page number for pagination. 0 is interpreted as 1.
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: deleted
        description: Only return recently deleted clients.
        in: query
        required: false
        schema:
          type: boolean
      tags:
      - ClientRegistry
    post:
      summary: 'Create a new OAuth client. This also sets the given organization or user as

        first collaborator with all possible rights.'
      operationId: ClientRegistry_Create2
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Client'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: collaborator.organization_ids.organization_id
        description: This ID shares namespace with user IDs.
        in: path
        required: true
        schema:
          type: string
      tags:
      - ClientRegistry
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v3ClientRegistryCreateBody'
        required: true
  /users/{collaborator.user_ids.user_id}/clients:
    get:
      summary: 'List OAuth clients where the given user or organization is a direct collaborator.

        If no user or organization is given, this returns the OAuth clients the caller

        has access to.

        Similar to Get, this selects the fields specified in the field mask.

        More or less fields may be returned, depending on the rights of the caller.'
      operationId: ClientRegistry_List2
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Clients'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: collaborator.user_ids.user_id
        description: This ID shares namespace with organization IDs.
        in: path
        required: true
        schema:
          type: string
      - name: collaborator.organization_ids.organization_id
        description: This ID shares namespace with user IDs.
        in: query
        required: false
        schema:
          type: string
      - name: collaborator.user_ids.email
        description: Secondary identifier, which can only be used in specific requests.
        in: query
        required: false
        schema:
          type: string
      - name: field_mask
        description: The names of the client fields that should be returned.
        in: query
        required: false
        schema:
          type: string
      - name: order
        description: 'Order the results by this field path (must be present in the field mask).

          Default ordering is by ID. Prepend with a minus (-) to reverse the order.'
        in: query
        required: false
        schema:
          type: string
      - name: limit
        description: Limit the number of results per page.
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: page
        description: Page number for pagination. 0 is interpreted as 1.
        in: query
        required: false
        schema:
          type: integer
          format: int64
      - name: deleted
        description: Only return recently deleted clients.
        in: query
        required: false
        schema:
          type: boolean
      tags:
      - ClientRegistry
    post:
      summary: 'Create a new OAuth client. This also sets the given organization or user as

        first collaborator with all possible rights.'
      operationId: ClientRegistry_Create
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v3Client'
        default:
          description: An unexpected error response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
      parameters:
      - name: collaborator.user_ids.user_id
        description: This ID shares namespace with organization IDs.
        in: path
        required: true
        schema:
          type: string
      tags:
      - ClientRegistry
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v3ClientRegistryCreateBody'
        required: true
components:
  schemas:
    v3ContactInfo:
      type: object
      properties:
        contact_type:
          $ref: '#/components/schemas/v3ContactType'
        contact_method:
          $ref: '#/components/schemas/v3ContactMethod'
        value:
          type: string
        public:
          type: boolean
        validated_at:
          type: string
          format: date-time
    v3ContactType:
      type: string
      enum:
      - CONTACT_TYPE_OTHER
      - CONTACT_TYPE_ABUSE
      - CONTACT_TYPE_BILLING
      - CONTACT_TYPE_TECHNICAL
      default: CONTACT_TYPE_OTHER
    v3ContactMethod:
      type: string
      enum:
      - CONTACT_METHOD_OTHER
      - CONTACT_METHOD_EMAIL
      - CONTACT_METHOD_PHONE
      default: CONTACT_METHOD_OTHER
    protobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: "A URL/resource name that uniquely identifies the type of the serialized\nprotocol buffer message. This string must contain at least\none \"/\" character. The last segment of the URL's path must represent\nthe fully qualified name of the type (as in\n`path/google.protobuf.Duration`). The name should be in a canonical form\n(e.g., leading \".\" is not accepted).\n\nIn practice, teams usually precompile into the binary all types that they\nexpect it to use in the context of Any. However, for URLs which use the\nscheme `http`, `https`, or no scheme, one can optionally set up a type\nserver that maps type URLs to message definitions as follows:\n\n* If no scheme is provided, `https` is assumed.\n* An HTTP GET on the URL must yield a [google.protobuf.Type][]\n  value in binary format, or produce an error.\n* Applications are allowed to cache lookup results based on the\n  URL, or have them precompiled into a binary to avoid any\n  lookup. Therefore, binary compatibility needs to be preserved\n  on changes to types. (Use versioned type names to manage\n  breaking changes.)\n\nNote: this functionality is not currently available in the official\nprotobuf release, and it is not used for type URLs beginning with\ntype.googleapis.com. As of May 2023, there are no widely used type server\nimplementations and no plans to implement one.\n\nSchemes other than `http`, `https` (or the empty scheme) might be\nused with implementation specific semantics."
      additionalProperties: {}
      description: "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nProtobuf library provides support to pack/unpack Any values in the form\nof utility functions or additional generated methods of the Any type.\n\nExample 1: Pack and unpack a message in C++.\n\n    Foo foo = ...;\n    Any any;\n    any.PackFrom(foo);\n    ...\n    if (any.UnpackTo(&foo)) {\n      ...\n    }\n\nExample 2: Pack and unpack a message in Java.\n\n    Foo foo = ...;\n    Any any = Any.pack(foo);\n    ...\n    if (any.is(Foo.class)) {\n      foo = any.unpack(Foo.class);\n    }\n    // or ...\n    if (any.isSameTypeAs(Foo.getDefaultInstance())) {\n      foo = any.unpack(Foo.getDefaultInstance());\n    }\n\n Example 3: Pack and unpack a message in Python.\n\n    foo = Foo(...)\n    any = Any()\n    any.Pack(foo)\n    ...\n    if any.Is(Foo.DESCRIPTOR):\n      any.Unpack(foo)\n      ...\n\n Example 4: Pack and unpack a message in Go\n\n     foo := &pb.Foo{...}\n     any, err := anypb.New(foo)\n     if err != nil {\n       ...\n     }\n     ...\n     foo := &pb.Foo{}\n     if err := any.UnmarshalTo(foo); err != nil {\n       ...\n     }\n\nThe pack methods provided by protobuf library will by default use\n'type.googleapis.com/full.type.name' as the type URL and the unpack\nmethods only use the fully qualified type name after the last '/'\nin the type URL, for example \"foo.bar.com/x/y.z\" will yield type\nname \"y.z\".\n\nJSON\n====\nThe JSON representation of an `Any` value uses the regular\nrepresentation of the deserialized, embedded message, with an\nadditional field `@type` which contains the type URL. Example:\n\n    package google.profile;\n    message Person {\n      string first_name = 1;\n      string last_name = 2;\n    }\n\n    {\n      \"@type\": \"type.googleapis.com/google.profile.Person\",\n      \"firstName\": <string>,\n      \"lastName\": <string>\n    }\n\nIf the embedded message type is well-known and has a custom JSON\nrepresentation, that representation will be embedded adding a field\n`value` which holds the custom JSON in addition to the `@type`\nfield. Example (for message [google.protobuf.Duration][]):\n\n    {\n      \"@type\": \"type.googleapis.com/google.protobuf.Duration\",\n      \"value\": \"1.212s\"\n    }"
    googlerpcStatus:
      type: object
      properties:
        code:
          type: integer
          format: int32
        message:
          type: string
        details:
          type: array
          items:
            type: object
            $ref: '#/components/schemas/protobufAny'
    v3OrganizationIdentifiers:
      type: object
      properties:
        organization_id:
          type: string
          description: This ID shares namespace with user IDs.
    v3State:
      type: string
      enum:
      - STATE_REQUESTED
      - STATE_APPROVED
      - STATE_REJECTED
      - STATE_FLAGGED
      - STATE_SUSPENDED
      default: STATE_REQUESTED
      description: "State enum defines states that an entity can be in.\n\n - STATE_REQUESTED: Denotes that the entity has been requested and is pending review by an admin.\n - STATE_APPROVED: Denotes that the entity has been reviewed and approved by an admin.\n - STATE_REJECTED: Denotes that the entity has been reviewed and rejected by an admin.\n - STATE_FLAGGED: Denotes that the entity has been flagged and is pending review by an admin.\n - STATE_SUSPENDED: Denotes that the entity has been reviewed and suspended by an admin."
    v3UserIdentifiers:
      type: object
      properties:
        user_id:
          type: string
          description: This ID shares namespace with organization IDs.
        email:
          type: string
          description: Secondary identifier, which can only be used in specific requests.
    v3ClientIdentifiers:
      type: object
      properties:
        client_id:
          type: string
    v3ClientRegistryUpdateBody:
      type: object
      properties:
        client:
          type: object
          properties:
            ids:
              type: object
              description: The identifiers of the OAuth client. These are public and can be seen by any authenticated user in the network.
              title: The identifiers of the OAuth client. These are public and can be seen by any authenticated user in the network.
            created_at:
              type: string
              format: date-time
              description: When the OAuth client was created. This information is public and can be seen by any authenticated user in the network.
            updated_at:
              type: string
              format: date-time
              description: When the OAuth client was last updated. This information is public and can be seen by any authenticated user in the network.
            deleted_at:
              type: string
              format: date-time
              description: When the OAuth client was deleted. This information is public and can be seen by any authenticated user in the network.
            name:
              type: string
              description: The name of the OAuth client. This information is public and can be seen by any authenticated user in the network.
            description:
              type: string
              description: A description for the OAuth client. This information is public and can be seen by any authenticated user in the network.
            attributes:
              type: object
              additionalProperties:
                type: string
              description: Key-value attributes for this client. Typically used for organizing clients or for storing integration-specific data.
            contact_info:
              type: array
              items:
                type: object
                $ref: '#/components/schemas/v3ContactInfo'
              description: 'Contact information for this client. Typically used to indicate who to contact with technical/security questions about the application.

                This information is public and can be seen by any authenticated user in the network.

                This field is deprecated. Use administrative_contact and technical_contact instead.'
            administrative_contact:
              $ref: '#/components/schemas/v3OrganizationOrUserIdentifiers'
            technical_contact:
              $ref: '#/components/schemas/v3OrganizationOrUserIdentifiers'
            secret:
              type: string
              description: The client secret is only visible to collaborators of the client.
            redirect_uris:
              type: array
              items:
                type: string
              description: 'The allowed redirect URIs against which authorization requests are checked.

                If the authorization request does not pass a redirect URI, the first one

                from this list is taken.

                This information is public and can be seen by any authenticated user in the network.'
            logout_redirect_uris:
              type: array
              items:
                type: string
              description: 'The allowed logout redirect URIs against which client initiated logout

                requests are checked. If the authorization request does not pass a redirect

                URI, the first one from this list is taken.

                This information is public and can be seen by any authenticated user in the network.'
            state:
              $ref: '#/components/schemas/v3State'
              description: 'The reviewing state of the client.

                This information is public and can be seen by any authenticated user in the network.

                This field can only be modified by admins.

                If state_description is not updated when updating state, state_description is cleared.'
            state_description:
              type: string
              description: 'A description for the state field.

                This field can only be modified by admins, and should typically only be updated

                when also updating `state`.'
            skip_authorization:
              type: boolean
              description: 'If set, the authorization page will be skipped.

                This information is public and can be seen by any authenticated user in the network.

                This field can only be modified by admins.'
            endorsed:
              type: boolean
              description: 'If set, the authorization page will show endorsement.

                This information is public and can be seen by any authenticated user in the network.

                This field can only be modified by admins.'
            grants:
              type: array
              items:
                $ref: '#/components/schemas/v3GrantType'
              description: 'OAuth flows that can be used for the client to get a token.

                This information is public and can be seen by any authenticated user in the network.

                After a client is created, this field can only be modified by admins.'
            rights:
              type: array
              items:
                $ref: '#/components/schemas/v3Right'
              description: 'Rights denotes what rights the client will have access to.

                This information is public and can be seen by any authenticated user in the network.

                Users that previously authorized this client will have to re-authorize the

                client after rights are added to this list.'
          description: An OAuth client on the network.
        field_mask:
          type: string
          description: The names of the client fields that should be updated.
    v3GrantType:
      type: string
      enum:
      - GRANT_AUTHORIZATION_CODE
      - GRANT_PASSWORD
      - GRANT_REFRESH_TOKEN
      default: GRANT_AUTHORIZATION_CODE
      description: "The OAuth2 flows an OAuth client can use to get an access token.\n\n - GRANT_AUTHORIZATION_CODE: Grant type used to exchange an authorization code for an access token.\n - GRANT_PASSWORD: Grant type used to exchange a user ID and password for an access token.\n - GRANT_REFRESH_TOKEN: Grant type used to exchange a refresh token for an access token."
    v3ClientRegistryCreateBody:
      type: object
      properties:
        client:
          $ref: '#/components/schemas/v3Client'
        collaborator:
          type: object
          properties:
            organization_ids:
              type: object
            user_ids:
              $ref: '#/components/schemas/v3UserIdentifiers'
          description: Collaborator to grant all rights on the newly created client.
          title: Collaborator to grant all rights on the newly created client.
    v3Right:
      type: string
      enum:
      - right_invalid
      - RIGHT_USER_INFO
      - RIGHT_USER_SETTINGS_BASIC
      - RIGHT_USER_LIST
      - RIGHT_USER_CREATE
      - RIGHT_USER_SETTINGS_API_KEYS
      - RIGHT_USER_DELETE
      - RIGHT_USER_PURGE
      - RIGHT_USER_AUTHORIZED_CLIENTS
      - RIGHT_USER_APPLICATIONS_LIST
      - RIGHT_USER_APPLICATIONS_CREATE
      - RIGHT_USER_GATEWAYS_LIST
      - RIGHT_USER_GATEWAYS_CREATE
      - RIGHT_USER_CLIENTS_LIST
      - RIGHT_USER_CLIENTS_CREATE
      - RIGHT_USER_ORGANIZATIONS_LIST
      - RIGHT_USER_ORGANIZATIONS_CREATE
      - RIGHT_USER_NOTIFICATIONS_READ
      - RIGHT_USER_ALL
      - RIGHT_APPLICATION_INFO
      - RIGHT_APPLICATION_SETTINGS_BASIC
      - RIGHT_APPLICATION_SETTINGS_API_KEYS
      - RIGHT_APPLICATION_SETTINGS_COLLABORATORS
      - RIGHT_APPLICATION_SETTINGS_PACKAGES
      - RIGHT_APPLICATION_DELETE
      - RIGHT_APPLICATION_PURGE
      - RIGHT_APPLICATION_DEVICES_READ
      - RIGHT_APPLICATION_DEVICES_WRITE
      - RIGHT_APPLICATION_DEVICES_READ_KEYS
      - RIGHT_APPLICATION_DEVICES_WRITE_KEYS
      - RIGHT_APPLICATION_TRAFFIC_READ
      - RIGHT_APPLICATION_TRAFFIC_UP_WRITE
      - RIGHT_APPLICATION_TRAFFIC_DOWN_WRITE
      - RIGHT_APPLICATION_LINK
      - RIGHT_APPLICATION_ALL
      - RIGHT_CLIENT_ALL
      - RIGHT_CLIENT_INFO
      - RIGHT_CLIENT_SETTINGS_BASIC
      - RIGHT_CLIENT_SETTINGS_COLLABORATORS
      - RIGHT_CLIENT_DELETE
      - RIGHT_CLIENT_PURGE
      - RIGHT_GATEWAY_INFO
      - RIGHT_GATEWAY_SETTINGS_BASIC
      - RIGHT_GATEWAY_SETTINGS_API_KEYS
      - RIGHT_GATEWAY_SETTINGS_COLLABORATORS
      - RIGHT_GATEWAY_DELETE
      - RIGHT_GATEWAY_PURGE
      - RIGHT_GATEWAY_TRAFFIC_READ
      - RIGHT_GATEWAY_TRAFFIC_DOWN_WRITE
      - RIGHT_GATEWAY_LINK
      - RIGHT_GATEWAY_STATUS_READ
      - RIGHT_GATEWAY_LOCATION_READ
      - RIGHT_GATEWAY_WRITE_SECRETS
      - RIGHT_GATEWAY_READ_SECRETS
      - RIGHT_GATEWAY_ALL
      - RIGHT_ORGANIZATION_INFO
      - RIGHT_ORGANIZATION_SETTINGS_BASIC
      - RIGHT_ORGANIZATION_SETTINGS_API_KEYS
      - RIGHT_ORGANIZATION_SETTINGS_MEMBERS
      - RIGHT_ORGANIZATION_DELETE
      - RIGHT_ORGANIZATION_PURGE
      - RIGHT_ORGANIZATION_APPLICATIONS_LIST
      - RIGHT_ORGANIZATION_APPLICATIONS_CREATE
      - RIGHT_ORGANIZATION_GATEWAYS_LIST
      - RIGHT_ORGANIZATION_GATEWAYS_CREATE
      - RIGHT_ORGANIZATION_CLIENTS_LIST
      - RIGHT_ORGANIZATION_CLIENTS_CREATE
      - RIGHT_ORGANIZATION_ADD_AS_COLLABORATOR
      - RIGHT_ORGANIZATION_ALL
      - RIGHT_SEND_INVITES
      - RIGHT_ALL
      default: right_invalid
      description: "Right is the enum that defines all the different rights to do something in the network.\n\n - RIGHT_USER_INFO: The right to view user information.\n - RIGHT_USER_SETTINGS_BASIC: The right to edit basic user settings.\n - RIGHT_USER_LIST: The right to list users accounts.\n - RIGHT_USER_CREATE: The right to create an user account.\n - RIGHT_USER_SETTINGS_API_KEYS: The right to view and edit user API keys.\n - RIGHT_USER_DELETE: The right to delete user account.\n - RIGHT_USER_PURGE: The right to delete user account.\n - RIGHT_USER_AUTHORIZED_CLIENTS: The right to view and edit authorized OAuth clients of the user.\n - RIGHT_USER_APPLICATIONS_LIST: The right to list applications the user is a collaborator of.\n - RIGHT_USER_APPLICATIONS_CREATE: The right to create an application under the user account.\n - RIGHT_USER_GATEWAYS_LIST: The right to list gateways the user is a collaborator of.\n - RIGHT_USER_GATEWAYS_CREATE: The right to create a gateway under the account of the user.\n - RIGHT_USER_CLIENTS_LIST: The right to list OAuth clients the user is a collaborator of.\n - RIGHT_USER_CLIENTS_CREATE: The right to create an OAuth client under the account of the user.\n - RIGHT_USER_ORGANIZATIONS_LIST: The right to list organizations the user is a member of.\n - RIGHT_USER_ORGANIZATIONS_CREATE: The right to create an organization under the user account.\n - RIGHT_USER_NOTIFICATIONS_READ: The right to read notifications sent to the user.\n - RIGHT_USER_ALL: The pseudo-right for all (current and future) user rights.\n - RIGHT_APPLICATION_INFO: The right to view application information.\n - RIGHT_APPLICATION_SETTINGS_BASIC: The right to edit basic application settings.\n - RIGHT_APPLICATION_SETTINGS_API_KEYS: The right to view and edit application API keys.\n - RIGHT_APPLICATION_SETTINGS_COLLABORATORS: The right to view and edit application collaborators.\n - RIGHT_APPLICATION_SETTINGS_PACKAGES: The right to view and edit application packages and associations.\n - RIGHT_APPLICATION_DELETE: The right to delete application.\n - RIGHT_APPLICATION_PURGE: The right to purge application.\n - RIGHT_APPLICATION_DEVICES_READ: The right to view devices in application.\n - RIGHT_APPLICATION_DEVICES_WRITE: The right to create devices in application.\n - RIGHT_APPLICATION_DEVICES_READ_KEYS: The right to view d

# --- truncated at 32 KB (41 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/the-things-network/refs/heads/main/openapi/the-things-network-clientregistry-api-openapi.yml