Virtru authorization.AuthorizationService API

The authorization.AuthorizationService API from Virtru — 3 operation(s) for authorization.authorizationservice.

OpenAPI Specification

virtru-authorization-authorizationservice-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: authorization authorization.AuthorizationService API
security: []
tags:
- name: authorization.AuthorizationService
paths:
  /authorization.AuthorizationService/GetDecisions:
    post:
      tags:
      - authorization.AuthorizationService
      summary: GetDecisions
      operationId: authorization.AuthorizationService.GetDecisions
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/authorization.GetDecisionsRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/authorization.GetDecisionsResponse'
  /authorization.AuthorizationService/GetDecisionsByToken:
    post:
      tags:
      - authorization.AuthorizationService
      summary: GetDecisionsByToken
      operationId: authorization.AuthorizationService.GetDecisionsByToken
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/authorization.GetDecisionsByTokenRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/authorization.GetDecisionsByTokenResponse'
  /authorization.AuthorizationService/GetEntitlements:
    post:
      tags:
      - authorization.AuthorizationService
      summary: GetEntitlements
      operationId: authorization.AuthorizationService.GetEntitlements
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/authorization.GetEntitlementsRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/authorization.GetEntitlementsResponse'
components:
  schemas:
    policy.PublicKey:
      type: object
      oneOf:
      - properties:
          cached:
            title: cached
            description: public key with additional information. Current preferred version
            $ref: '#/components/schemas/policy.KasPublicKeySet'
        title: cached
        required:
        - cached
      - properties:
          remote:
            type: string
            title: remote
            description: 'kas public key url - optional since can also be retrieved via public key

              URI must be a valid URL (e.g., ''https://demo.com/'') followed by additional segments. Each segment must start and end with an alphanumeric character, can contain hyphens, alphanumeric characters, and slashes.:

              ```

              this.matches(''^https://[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*(/.*)?$'')

              ```


              '
        title: remote
        required:
        - remote
      title: PublicKey
      additionalProperties: false
      description: Deprecated
    policy.Algorithm:
      type: string
      title: Algorithm
      enum:
      - ALGORITHM_UNSPECIFIED
      - ALGORITHM_RSA_2048
      - ALGORITHM_RSA_4096
      - ALGORITHM_EC_P256
      - ALGORITHM_EC_P384
      - ALGORITHM_EC_P521
      - ALGORITHM_HPQT_XWING
      - ALGORITHM_HPQT_SECP256R1_MLKEM768
      - ALGORITHM_HPQT_SECP384R1_MLKEM1024
      - ALGORITHM_MLKEM_768
      - ALGORITHM_MLKEM_1024
      description: Supported key algorithms.
    policy.SourceType:
      type: string
      title: SourceType
      enum:
      - SOURCE_TYPE_UNSPECIFIED
      - SOURCE_TYPE_INTERNAL
      - SOURCE_TYPE_EXTERNAL
      description: "Describes whether this kas is managed by the organization or if they imported\n the kas information from an external party. These two modes are necessary in order\n to encrypt a tdf dek with an external parties kas public key."
    common.Metadata:
      type: object
      properties:
        createdAt:
          title: created_at
          description: created_at set by server (entity who created will recorded in an audit event)
          $ref: '#/components/schemas/google.protobuf.Timestamp'
        updatedAt:
          title: updated_at
          description: updated_at set by server (entity who updated will recorded in an audit event)
          $ref: '#/components/schemas/google.protobuf.Timestamp'
        labels:
          type: object
          title: labels
          additionalProperties:
            type: string
            title: value
          description: optional short description
      title: Metadata
      additionalProperties: false
      description: Struct to uniquely identify a resource with optional additional metadata
    authorization.ResourceAttribute:
      type: object
      properties:
        resourceAttributesId:
          type: string
          title: resource_attributes_id
        attributeValueFqns:
          type: array
          items:
            type: string
          title: attribute_value_fqns
      title: ResourceAttribute
      additionalProperties: false
      description: A logical bucket of attributes belonging to a "Resource"
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
      - 1
      description: Define the version of the Connect protocol
      const: 1
    authorization.TokenDecisionRequest:
      type: object
      properties:
        actions:
          type: array
          items:
            $ref: '#/components/schemas/policy.Action'
          title: actions
        tokens:
          type: array
          items:
            $ref: '#/components/schemas/authorization.Token'
          title: tokens
        resourceAttributes:
          type: array
          items:
            $ref: '#/components/schemas/authorization.ResourceAttribute'
          title: resource_attributes
      title: TokenDecisionRequest
      additionalProperties: false
      description: 'Example Request Get Decisions by Token to answer the question -  Do Bob and client1 (represented by token tok1)

        and Alice and client2 (represented by token tok2) have TRANSMIT authorization for

        2 resources; resource1 (attr-set-1) defined by attributes foo:bar  resource2 (attr-set-2) defined by attribute foo:bar, color:red ?


        {

        "actions": [

        {

        "standard": "STANDARD_ACTION_TRANSMIT"

        }

        ],

        "tokens": [

        {

        "id": "tok1",

        "jwt": ....

        },

        {

        "id": "tok2",

        "jwt": .....

        }

        ],

        "resourceAttributes": [

        {

        "attributeFqns": [

        "https://www.example.org/attr/foo/value/value1"

        ]

        },

        {

        "attributeFqns": [

        "https://example.net/attr/attr1/value/value1",

        "https://example.net/attr/attr1/value/value2"

        ]

        }

        ]

        }'
    authorization.GetDecisionsByTokenRequest:
      type: object
      properties:
        decisionRequests:
          type: array
          items:
            $ref: '#/components/schemas/authorization.TokenDecisionRequest'
          title: decision_requests
      title: GetDecisionsByTokenRequest
      additionalProperties: false
    authorization.EntityEntitlements:
      type: object
      properties:
        entityId:
          type: string
          title: entity_id
        attributeValueFqns:
          type: array
          items:
            type: string
          title: attribute_value_fqns
      title: EntityEntitlements
      additionalProperties: false
    google.protobuf.Any:
      type: object
      properties:
        type:
          type: string
        value:
          type: string
          format: binary
        debug:
          type: object
          additionalProperties: true
      additionalProperties: true
      description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
    policy.KasPublicKey:
      type: object
      properties:
        pem:
          type: string
          title: pem
          maxLength: 8192
          minLength: 1
          description: x509 ASN.1 content in PEM envelope, usually
        kid:
          type: string
          title: kid
          maxLength: 32
          minLength: 1
          description: A unique string identifier for this key
        alg:
          not:
            enum:
            - 0
          title: alg
          description: "A known algorithm type with any additional parameters encoded.\n To start, these may be `rsa:2048` for RSA-based wrapping and\n `ec:secp256r1` for EC-based wrapping, but more formats may be added as needed."
          $ref: '#/components/schemas/policy.KasPublicKeyAlgEnum'
      title: KasPublicKey
      additionalProperties: false
      description: "Deprecated\n A KAS public key and some associated metadata for further identifcation"
    authorization.GetDecisionsByTokenResponse:
      type: object
      properties:
        decisionResponses:
          type: array
          items:
            $ref: '#/components/schemas/authorization.DecisionResponse'
          title: decision_responses
      title: GetDecisionsByTokenResponse
      additionalProperties: false
    policy.KeyAccessServer:
      type: object
      properties:
        id:
          type: string
          title: id
        uri:
          type: string
          title: uri
          description: 'Address of a KAS instance

            URI must be a valid URL (e.g., ''https://demo.com/'') followed by additional segments. Each segment must start and end with an alphanumeric character, can contain hyphens, alphanumeric characters, and slashes.:

            ```

            this.matches(''^https?://[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*(:[0-9]+)?(/.*)?$'')

            ```


            '
        publicKey:
          title: public_key
          description: 'Deprecated: KAS can have multiple key pairs'
          $ref: '#/components/schemas/policy.PublicKey'
        sourceType:
          title: source_type
          description: 'The source of the KAS: (INTERNAL, EXTERNAL)'
          $ref: '#/components/schemas/policy.SourceType'
        kasKeys:
          type: array
          items:
            $ref: '#/components/schemas/policy.SimpleKasKey'
          title: kas_keys
          description: Kas keys associated with this KAS
        name:
          type: string
          title: name
          description: "Optional\n Unique name of the KAS instance"
        metadata:
          title: metadata
          description: Common metadata
          $ref: '#/components/schemas/common.Metadata'
      title: KeyAccessServer
      additionalProperties: false
      description: Key Access Server Registry
    google.protobuf.Timestamp:
      type: string
      examples:
      - 1s
      - 1.000340012s
      format: date-time
      description: "A Timestamp represents a point in time independent of any time zone or local\n calendar, encoded as a count of seconds and fractions of seconds at\n nanosecond resolution. The count is relative to an epoch at UTC midnight on\n January 1, 1970, in the proleptic Gregorian calendar which extends the\n Gregorian calendar backwards to year one.\n\n All minutes are 60 seconds long. Leap seconds are \"smeared\" so that no leap\n second table is needed for interpretation, using a [24-hour linear\n smear](https://developers.google.com/time/smear).\n\n The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By\n restricting to that range, we ensure that we can convert to and from [RFC\n 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings.\n\n # Examples\n\n Example 1: Compute Timestamp from POSIX `time()`.\n\n     Timestamp timestamp;\n     timestamp.set_seconds(time(NULL));\n     timestamp.set_nanos(0);\n\n Example 2: Compute Timestamp from POSIX `gettimeofday()`.\n\n     struct timeval tv;\n     gettimeofday(&tv, NULL);\n\n     Timestamp timestamp;\n     timestamp.set_seconds(tv.tv_sec);\n     timestamp.set_nanos(tv.tv_usec * 1000);\n\n Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`.\n\n     FILETIME ft;\n     GetSystemTimeAsFileTime(&ft);\n     UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;\n\n     // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z\n     // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.\n     Timestamp timestamp;\n     timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));\n     timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));\n\n Example 4: Compute Timestamp from Java `System.currentTimeMillis()`.\n\n     long millis = System.currentTimeMillis();\n\n     Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)\n         .setNanos((int) ((millis % 1000) * 1000000)).build();\n\n Example 5: Compute Timestamp from Java `Instant.now()`.\n\n     Instant now = Instant.now();\n\n     Timestamp timestamp =\n         Timestamp.newBuilder().setSeconds(now.getEpochSecond())\n             .setNanos(now.getNano()).build();\n\n Example 6: Compute Timestamp from current time in Python.\n\n     timestamp = Timestamp()\n     timestamp.GetCurrentTime()\n\n # JSON Mapping\n\n In JSON format, the Timestamp type is encoded as a string in the\n [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the\n format is \"{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z\"\n where {year} is always expressed using four digits while {month}, {day},\n {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional\n seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution),\n are optional. The \"Z\" suffix indicates the timezone (\"UTC\"); the timezone\n is required. A proto3 JSON serializer should always use UTC (as indicated by\n \"Z\") when printing the Timestamp type and a proto3 JSON parser should be\n able to accept both UTC and other timezones (as indicated by an offset).\n\n For example, \"2017-01-15T01:30:15.01Z\" encodes 15.01 seconds past\n 01:30 UTC on January 15, 2017.\n\n In JavaScript, one can convert a Date object to this format using the\n standard\n [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString)\n method. In Python, a standard `datetime.datetime` object can be converted\n to this format using\n [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with\n the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use\n the Joda Time's [`ISODateTimeFormat.dateTime()`](\n http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime()\n ) to obtain a formatter capable of generating timestamps in this format."
    authorization.Entity.Category:
      type: string
      title: Category
      enum:
      - CATEGORY_UNSPECIFIED
      - CATEGORY_SUBJECT
      - CATEGORY_ENVIRONMENT
    policy.Action.StandardAction:
      type: string
      title: StandardAction
      enum:
      - STANDARD_ACTION_UNSPECIFIED
      - STANDARD_ACTION_DECRYPT
      - STANDARD_ACTION_TRANSMIT
    policy.KasPublicKeyAlgEnum:
      type: string
      title: KasPublicKeyAlgEnum
      enum:
      - KAS_PUBLIC_KEY_ALG_ENUM_UNSPECIFIED
      - KAS_PUBLIC_KEY_ALG_ENUM_RSA_2048
      - KAS_PUBLIC_KEY_ALG_ENUM_RSA_4096
      - KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP256R1
      - KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP384R1
      - KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP521R1
      - KAS_PUBLIC_KEY_ALG_ENUM_HPQT_XWING
      - KAS_PUBLIC_KEY_ALG_ENUM_HPQT_SECP256R1_MLKEM768
      - KAS_PUBLIC_KEY_ALG_ENUM_HPQT_SECP384R1_MLKEM1024
      - KAS_PUBLIC_KEY_ALG_ENUM_MLKEM_768
      - KAS_PUBLIC_KEY_ALG_ENUM_MLKEM_1024
    authorization.EntityChain:
      type: object
      properties:
        id:
          type: string
          title: id
          description: ephemeral id for tracking between request and response
        entities:
          type: array
          items:
            $ref: '#/components/schemas/authorization.Entity'
          title: entities
      title: EntityChain
      additionalProperties: false
      description: A set of related PE and NPE
    authorization.GetDecisionsRequest:
      type: object
      properties:
        decisionRequests:
          type: array
          items:
            $ref: '#/components/schemas/authorization.DecisionRequest'
          title: decision_requests
      title: GetDecisionsRequest
      additionalProperties: false
    authorization.GetEntitlementsRequest:
      type: object
      properties:
        entities:
          type: array
          items:
            $ref: '#/components/schemas/authorization.Entity'
          title: entities
          description: list of requested entities
        scope:
          title: scope
          description: optional attribute fqn as a scope
          nullable: true
          $ref: '#/components/schemas/authorization.ResourceAttribute'
        withComprehensiveHierarchy:
          type: boolean
          title: with_comprehensive_hierarchy
          description: optional parameter to return a full list of entitlements - returns lower hierarchy attributes
          nullable: true
      title: GetEntitlementsRequest
      additionalProperties: false
      description: 'Request to get entitlements for one or more entities for an optional attribute scope


        Example: Get entitlements for bob and alice (both represented using an email address


        {

        "entities": [

        {

        "id": "e1",

        "emailAddress": "bob@example.org"

        },

        {

        "id": "e2",

        "emailAddress": "alice@example.org"

        }

        ],

        "scope": {

        "attributeFqns": [

        "https://example.net/attr/attr1/value/value1",

        "https://example.net/attr/attr1/value/value2"

        ]

        }

        }'
    policy.SimpleKasPublicKey:
      type: object
      properties:
        algorithm:
          title: algorithm
          $ref: '#/components/schemas/policy.Algorithm'
        kid:
          type: string
          title: kid
        pem:
          type: string
          title: pem
      title: SimpleKasPublicKey
      additionalProperties: false
    authorization.GetDecisionsResponse:
      type: object
      properties:
        decisionResponses:
          type: array
          items:
            $ref: '#/components/schemas/authorization.DecisionResponse'
          title: decision_responses
      title: GetDecisionsResponse
      additionalProperties: false
    authorization.DecisionResponse:
      type: object
      properties:
        entityChainId:
          type: string
          title: entity_chain_id
          description: ephemeral entity chain id from the request
        resourceAttributesId:
          type: string
          title: resource_attributes_id
          description: ephemeral resource attributes id from the request
        action:
          title: action
          description: Action of the decision response
          $ref: '#/components/schemas/policy.Action'
        decision:
          title: decision
          description: The decision response
          $ref: '#/components/schemas/authorization.DecisionResponse.Decision'
        obligations:
          type: array
          items:
            type: string
          title: obligations
          description: optional list of obligations represented in URI format
      title: DecisionResponse
      additionalProperties: false
      description: 'Example response for a Decision Request -  Do Bob (represented by entity chain ec1)

        and Alice (represented by entity chain ec2) have TRANSMIT authorization for

        2 resources; resource1 (attr-set-1) defined by attributes foo:bar  resource2 (attr-set-2) defined by attribute foo:bar, color:red ?


        Results:

        - bob has permitted authorization to transmit for a resource defined by attr-set-1 attributes and has a watermark obligation

        - bob has denied authorization to transmit a for a resource defined by attr-set-2 attributes

        - alice has permitted authorization to transmit for a resource defined by attr-set-1 attributes

        - alice has denied authorization to transmit a for a resource defined by attr-set-2 attributes


        {

        "entityChainId":  "ec1",

        "resourceAttributesId":  "attr-set-1",

        "decision":  "DECISION_PERMIT",

        "obligations":  [

        "http://www.example.org/obligation/watermark"

        ]

        },

        {

        "entityChainId":  "ec1",

        "resourceAttributesId":  "attr-set-2",

        "decision":  "DECISION_PERMIT"

        },

        {

        "entityChainId":  "ec2",

        "resourceAttributesId":  "attr-set-1",

        "decision":  "DECISION_PERMIT"

        },

        {

        "entityChainId":  "ec2",

        "resourceAttributesId":  "attr-set-2",

        "decision":  "DECISION_DENY"

        }'
    policy.Action:
      type: object
      oneOf:
      - properties:
          custom:
            type: string
            title: custom
            description: Deprecated
        title: custom
        required:
        - custom
      - properties:
          standard:
            title: standard
            description: Deprecated
            $ref: '#/components/schemas/policy.Action.StandardAction'
        title: standard
        required:
        - standard
      properties:
        id:
          type: string
          title: id
          description: Generated uuid in database
        name:
          type: string
          title: name
        namespace:
          title: namespace
          description: Namespace context for this action
          $ref: '#/components/schemas/policy.Namespace'
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
      title: Action
      additionalProperties: false
      description: An action an entity can take
    policy.SimpleKasKey:
      type: object
      properties:
        kasUri:
          type: string
          title: kas_uri
          description: The URL of the Key Access Server
        publicKey:
          title: public_key
          description: The public key of the Key that belongs to the KAS
          $ref: '#/components/schemas/policy.SimpleKasPublicKey'
        kasId:
          type: string
          title: kas_id
          description: The ID of the Key Access Server
      title: SimpleKasKey
      additionalProperties: false
    authorization.DecisionResponse.Decision:
      type: string
      title: Decision
      enum:
      - DECISION_UNSPECIFIED
      - DECISION_DENY
      - DECISION_PERMIT
    authorization.EntityCustom:
      type: object
      properties:
        extension:
          title: extension
          $ref: '#/components/schemas/google.protobuf.Any'
      title: EntityCustom
      additionalProperties: false
      description: Entity type for custom entities beyond the standard types
    policy.KasPublicKeySet:
      type: object
      properties:
        keys:
          type: array
          items:
            $ref: '#/components/schemas/policy.KasPublicKey'
          title: keys
      title: KasPublicKeySet
      additionalProperties: false
      description: "Deprecated\n A list of known KAS public keys"
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    authorization.GetEntitlementsResponse:
      type: object
      properties:
        entitlements:
          type: array
          items:
            $ref: '#/components/schemas/authorization.EntityEntitlements'
          title: entitlements
      title: GetEntitlementsResponse
      additionalProperties: false
      description: 'Example Response for a request of : Get entitlements for bob and alice (both represented using an email address


        {

        "entitlements":  [

        {

        "entityId":  "e1",

        "attributeValueReferences":  [

        {

        "attributeFqn":  "http://www.example.org/attr/foo/value/bar"

        }

        ]

        },

        {

        "entityId":  "e2",

        "attributeValueReferences":  [

        {

        "attributeFqn":  "http://www.example.org/attr/color/value/red"

        }

        ]

        }

        ]

        }'
    authorization.Entity:
      type: object
      oneOf:
      - properties:
          claims:
            title: claims
            $ref: '#/components/schemas/google.protobuf.Any'
        title: claims
        required:
        - claims
      - properties:
          clientId:
            type: string
            title: client_id
        title: client_id
        required:
        - clientId
      - properties:
          custom:
            title: custom
            $ref: '#/components/schemas/authorization.EntityCustom'
        title: custom
        required:
        - custom
      - properties:
          emailAddress:
            type: string
            title: email_address
            description: one of the entity options must be set
        title: email_address
        required:
        - emailAddress
      - properties:
          remoteClaimsUrl:
            type: string
            title: remote_claims_url
        title: remote_claims_url
        required:
        - remoteClaimsUrl
      - properties:
          userName:
            type: string
            title: user_name
        title: user_name
        required:
        - userName
      - properties:
          uuid:
            type: string
            title: uuid
        title: uuid
        required:
        - uuid
      properties:
        id:
          type: string
          title: id
          description: ephemeral id for tracking between request and response
        category:
          title: category
          $ref: '#/components/schemas/authorization.Entity.Category'
      title: Entity
      additionalProperties: false
      description: PE (Person Entity) or NPE (Non-Person Entity)
    authorization.DecisionRequest:
      type: object
      properties:
        actions:
          type: array
          items:
            $ref: '#/components/schemas/policy.Action'
          title: actions
        entityChains:
          type: array
          items:
            $ref: '#/components/schemas/authorization.EntityChain'
          title: entity_chains
        resourceAttributes:
          type: array
          items:
            $ref: '#/components/schemas/authorization.ResourceAttribute'
          title: resource_attributes
      title: DecisionRequest
      additionalProperties: false
      description: 'Example Request Get Decisions to answer the question -  Do Bob (represented by entity chain ec1)

        and Alice (represented by entity chain ec2) have TRANSMIT authorization for

        2 resources; resource1 (attr-set-1) defined by attributes foo:bar  resource2 (attr-set-2) defined by attribute foo:bar, color:red ?


        {

        "actions": [

        {

        "standard": "STANDARD_ACTION_TRANSMIT"

        }

        ],

        "entityChains": [

        {

        "id": "ec1",

        "entities": [

        {

        "emailAddress": "bob@example.org"

        }

        ]

        },

        {

        "id": "ec2",

        "entities": [

        {

        "userName": "alice@example.org"

        }

        ]

        }

        ],

        "resourceAttributes": [

        {

        "resourceAttributeId":  "attr-set-1",

        "attributeFqns": [

        "https://www.example.org/attr/foo/value/value1"

        ]

        },

        {

        "resourceAttributeId":  "attr-set-2",

        "attributeFqns": [

        "https://example.net/attr/attr1/value/value1",

        "https://example.net/attr/attr1/value/value2"

        ]

        }

        ]

        }'
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
          - not_found
          enum:
          - canceled
          - unknown
          - invalid_argument
          - deadline_exceeded
          - not_found
          - already_exists
          - permission_denied
          - resource_exhausted
          - failed_precondition
          - aborted
          - out_of_range
          - unimplemented
          - internal
          - unavailable
          - data_loss
          - unauthenticated
          description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
        detail:
          $ref: '#/components/schemas/google.protobuf.Any'
      title: Connect Error
      additionalProperties: true
      description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation'
    google.protobuf.BoolValue:
      type: boolean
      description: "Wrapper message for `bool`.\n\n The JSON representation for `BoolValue` is JSON `true` and `false`.\n\n Not recommended for use in new APIs, but still useful for legacy APIs and\n has no plan to be removed."
    policy.Namespace:
      type: object
      properties:
        id:
          type: string
          title: id
          description: generated uuid in database
        name:
          type: string
          title: name
          description: "used to partition Attribute Definitions, support by namespace AuthN and\n enable federation"
        fqn:
          type: string
          title: fqn
        active:
          title: active
          description: active by default until explicitly deactivated
          $ref: '#/components/schemas/google.protobuf.BoolValue'
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
        grants:
          type: array
          items:
            $ref: '#/components/schemas/policy.KeyAccessServer'
          title: grants
          description: Deprecated KAS grants for the namespace. Use kas_keys instead.
        kasKeys:
          type: array
          items:
            $ref: '#/components/schemas/policy.SimpleKasKey'
          title: kas_keys
          description: Keys for the namespace
      title: Namespace
      additionalProperties: false
    authorization.Token:
      type: object
      properties:
        id:
          type: string
          title: id
          description: ephemeral id for tracking between request and response
        jwt:
          type: string
          title: jwt
          description: the token
      title: Token
      additionalProperties: false