WSO2 Application Keys API

The Application Keys API from WSO2 — 10 operation(s) for application keys.

Business capability
Developer Identity & Credential Management BC-4270.40

Operations 13

POST /applications/{applicationId}/generate-keys Generate Application Keys #
POST /applications/{applicationId}/map-keys Map Application Keys #
GET /applications/{applicationId}/keys Retrieve All Application Keys #
GET /applications/{applicationId}/keys/{keyType} Get Key Details of a Given Type #
PUT /applications/{applicationId}/keys/{keyType} Update Grant Types and Callback Url of an Application #
POST /applications/{applicationId}/keys/{keyType}/regenerate-secret Re-Generate Consumer Secret #
POST /applications/{applicationId}/keys/{keyType}/clean-up Clean-Up Application Keys #
GET /applications/{applicationId}/oauth-keys Retrieve All Application Keys #
GET /applications/{applicationId}/oauth-keys/{keyMappingId} Get Key Details of a Given Type #
PUT /applications/{applicationId}/oauth-keys/{keyMappingId} Update Grant Types and Callback URL of an Application #
DELETE /applications/{applicationId}/oauth-keys/{keyMappingId} Remove Generated Application Keys #
POST /applications/{applicationId}/oauth-keys/{keyMappingId}/regenerate-secret Re-Generate Consumer Secret #
POST /applications/{applicationId}/oauth-keys/{keyMappingId}/clean-up Clean-Up Application Keys #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/wso2-application-keys-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

wso2-application-keys-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: WSO2 API Manager - Developer Portal Application Keys API
  description: This document specifies a **RESTful API** for WSO2 **API Manager** - **Developer Portal**.
  contact:
    name: WSO2
    url: https://wso2.com/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  version: v3
servers:
- url: https://apis.wso2.com/api/am/devportal/v3
tags:
- name: Application Keys
paths:
  /applications/{applicationId}/generate-keys:
    post:
      tags:
      - Application Keys
      summary: Generate Application Keys
      description: Generate keys (Consumer key/secret) for application
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/requestedTenant'
      requestBody:
        description: 'Application key generation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationKeyGenerateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Keys are generated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKey'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/generate-keys"'
      operationId: postApplicationsByApplicationIdGenerateKeys
      x-operation-id-source: derived
  /applications/{applicationId}/map-keys:
    post:
      tags:
      - Application Keys
      summary: Map Application Keys
      description: Map keys (Consumer key/secret) to an application
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/requestedTenant'
      requestBody:
        description: 'Application key mapping request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationKeyMappingRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Keys are mapped.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKey'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/map-keys"'
      operationId: postApplicationsByApplicationIdMapKeys
      x-operation-id-source: derived
  /applications/{applicationId}/keys:
    get:
      tags:
      - Application Keys
      summary: Retrieve All Application Keys
      description: Retrieve keys (Consumer key/secret) of application
      parameters:
      - $ref: '#/components/parameters/applicationId'
      responses:
        200:
          description: 'OK.

            Keys are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      deprecated: true
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/keys"'
      operationId: getApplicationsByApplicationIdKeys
      x-operation-id-source: derived
  /applications/{applicationId}/keys/{keyType}:
    get:
      tags:
      - Application Keys
      summary: Get Key Details of a Given Type
      description: This operation can be used to retrieve key details of an individual application specifying the key type in the URI.
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/groupId'
      responses:
        200:
          description: 'OK.

            Keys of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKey'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      deprecated: true
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/keys/PRODUCTION"'
      operationId: getApplicationsByApplicationIdKeysByKeyType
      x-operation-id-source: derived
    put:
      tags:
      - Application Keys
      summary: Update Grant Types and Callback Url of an Application
      description: This operation can be used to update grant types and callback url of an application. (Consumer Key and Consumer Secret are ignored) Upon succesfull you will retrieve the updated key details as the response.
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      requestBody:
        description: 'Grant types/Callback URL update request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationKey'
        required: true
      responses:
        200:
          description: 'Ok.

            Grant types or/and callback url is/are updated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKey'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      deprecated: true
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X PUT -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/keys/PRODUCTION"'
      operationId: putApplicationsByApplicationIdKeysByKeyType
      x-operation-id-source: derived
  /applications/{applicationId}/keys/{keyType}/regenerate-secret:
    post:
      tags:
      - Application Keys
      summary: Re-Generate Consumer Secret
      description: This operation can be used to re generate consumer secret for an application for the give key type
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      responses:
        200:
          description: 'OK.

            Keys are re generated.

            '
          headers:
            ETag:
              description: 'Entity Tag of the response resource.

                Used by caches, or in conditional requests (Will be supported in future).

                '
              schema:
                type: string
            Last-Modified:
              description: 'Date and time the resource has been modifed the last time.

                Used by caches, or in conditional requests (Will be supported in future).‚

                '
              schema:
                type: string
            Content-Type:
              description: 'The content type of the body.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKeyReGenerateResponse'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      deprecated: true
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/keys/PRODUCTION/regenerate-secret"'
      operationId: postApplicationsByApplicationIdKeysByKeyTypeRegenerateSecret
      x-operation-id-source: derived
  /applications/{applicationId}/keys/{keyType}/clean-up:
    post:
      tags:
      - Application Keys
      summary: Clean-Up Application Keys
      description: Clean up keys after failed key generation of an application
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      responses:
        200:
          description: 'OK.

            Clean up is performed

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      deprecated: true
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST "https://localhost:9443/api/am/devportal/v3/applications/896658a0-b4ee-4535-bbfa-806c894a4015/keys/PRODUCTION/clean-up"'
      operationId: postApplicationsByApplicationIdKeysByKeyTypeCleanUp
      x-operation-id-source: derived
  /applications/{applicationId}/oauth-keys:
    get:
      tags:
      - Application Keys
      summary: Retrieve All Application Keys
      description: Retrieve keys (Consumer key/secret) of application
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/requestedTenant'
      responses:
        200:
          description: 'OK.

            Keys are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/oauth-keys"'
      operationId: getApplicationsByApplicationIdOauthKeys
      x-operation-id-source: derived
  /applications/{applicationId}/oauth-keys/{keyMappingId}:
    get:
      tags:
      - Application Keys
      summary: Get Key Details of a Given Type
      description: This operation can be used to retrieve key details of an individual application specifying the key type in the URI.
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyMappingId'
      - $ref: '#/components/parameters/groupId'
      responses:
        200:
          description: 'OK.

            Keys of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKey'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/oauth-keys/df972173-c957-46d4-96ac-99be8e303584"'
      operationId: getApplicationsByApplicationIdOauthKeysByKeyMappingId
      x-operation-id-source: derived
    put:
      tags:
      - Application Keys
      summary: Update Grant Types and Callback URL of an Application
      description: This operation can be used to update grant types and callback url of an application. (Consumer Key and Consumer Secret are ignored) Upon succesfull you will retrieve the updated key details as the response.
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyMappingId'
      requestBody:
        description: 'Grant types/Callback URL update request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApplicationKey'
        required: true
      responses:
        200:
          description: 'Ok.

            Grant types or/and callback url is/are updated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKey'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X PUT -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/oauth-keys/df972173-c957-46d4-96ac-99be8e303584"'
      operationId: putApplicationsByApplicationIdOauthKeysByKeyMappingId
      x-operation-id-source: derived
    delete:
      tags:
      - Application Keys
      summary: Remove Generated Application Keys
      description: Remove generated application keys from dev portal rest api
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyMappingId'
      - $ref: '#/components/parameters/requestedTenant'
      responses:
        200:
          description: 'OK.

            Key removed successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X DELETE "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/oauth-keys/df972173-c957-46d4-96ac-99be8e303584"'
      operationId: deleteApplicationsByApplicationIdOauthKeysByKeyMappingId
      x-operation-id-source: derived
  /applications/{applicationId}/oauth-keys/{keyMappingId}/regenerate-secret:
    post:
      tags:
      - Application Keys
      summary: Re-Generate Consumer Secret
      description: This operation can be used to re generate consumer secret for an application for the give key type
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyMappingId'
      responses:
        200:
          description: 'OK.

            Keys are re generated.

            '
          headers:
            ETag:
              description: 'Entity Tag of the response resource.

                Used by caches, or in conditional requests (Will be supported in future).

                '
              schema:
                type: string
            Last-Modified:
              description: 'Date and time the resource has been modifed the last time.

                Used by caches, or in conditional requests (Will be supported in future).‚

                '
              schema:
                type: string
            Content-Type:
              description: 'The content type of the body.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApplicationKeyReGenerateResponse'
        400:
          $ref: '#/components/responses/BadRequest'
        403:
          $ref: '#/components/responses/Forbidden'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/oauth-keys/df972173-c957-46d4-96ac-99be8e303584/regenerate-secret"'
      operationId: postApplicationsByApplicationIdOauthKeysByKeyMappingIdRegenerateSecret
      x-operation-id-source: derived
  /applications/{applicationId}/oauth-keys/{keyMappingId}/clean-up:
    post:
      tags:
      - Application Keys
      summary: Clean-Up Application Keys
      description: Clean up keys after failed key generation of an application
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyMappingId'
      - $ref: '#/components/parameters/If-Match'
      responses:
        200:
          description: 'OK.

            Clean up is performed

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/oauth-keys/df972173-c957-46d4-96ac-99be8e303584/clean-up"'
      operationId: postApplicationsByApplicationIdOauthKeysByKeyMappingIdCleanUp
      x-operation-id-source: derived
components:
  schemas:
    ConsumerSecret:
      type: object
      properties:
        secretId:
          type: string
          description: Unique identifier for the secret
          example: sec_123456
        secretValue:
          type: string
          description: The actual secret string
          example: '***r3tV@lu3'
        additionalProperties:
          type: object
          description: Additional dynamic properties for the secret creation request.
          additionalProperties:
            type: object
          example:
            expiresAt: 1761568483
            description: pizza application secret
    ErrorListItem:
      title: Description of individual errors that may have occurred during a request.
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          description: 'Description about individual errors occurred

            '
    ApplicationKeyMappingRequest:
      title: Application key provision request object
      required:
      - consumerKey
      - keyType
      type: object
      properties:
        consumerKey:
          type: string
          description: Consumer key of the application
          example: oYhwZu4P2ThDmiDprBk6c0YfjR8a
        consumerSecret:
          type: string
          description: Consumer secret of the application
          example: ondWGtFTCOVM4sfPyOfZ7fel610a
        keyManager:
          type: string
          description: Key Manager Name
          example: Resident Key Manager
        keyType:
          type: string
          enum:
          - PRODUCTION
          - SANDBOX
    ApplicationToken:
      title: Application token details to invoke APIs
      type: object
      properties:
        accessToken:
          type: string
          description: Access token
          example: 1.2345678901234568E30
        tokenScopes:
          type: array
          description: Valid comma seperated scopes for the access token
          example:
          - default
          - read_api
          - write_api
          items:
            type: string
        validityTime:
          type: integer
          description: Maximum validity time for the access token
          format: int64
          example: 3600
    ApplicationKeyGenerateRequest:
      title: Application key generation request object
      required:
      - grantTypesToBeSupported
      - keyType
      type: object
      properties:
        keyType:
          type: string
          enum:
          - PRODUCTION
          - SANDBOX
        keyManager:
          type: string
          description: key Manager to Generate Keys
          example: Resident Key Manager
        grantTypesToBeSupported:
          type: array
          description: Grant types that should be supported by the application
          example:
          - password
          - client_credentials
          items:
            type: string
        callbackUrl:
          type: string
          description: Callback URL
          example: http://sample.com/callback/url
        scopes:
          type: array
          description: Allowed scopes for the access token
          example:
          - am_application_scope
          - default
          items:
            type: string
        validityTime:
          type: string
          example: '3600'
        clientId:
          type: string
          description: Client ID for generating access token.
          readOnly: true
          example: sZzoeSCI_vL2cjSXZQmsmV8JEyga
        clientSecret:
          type: string
          description: Client secret for generating access token. This is given together with the client Id.
          readOnly: true
          example: nrs3YAP4htxnz_DqpvGhf9Um04oa
        additionalProperties:
          type: object
          properties: {}
          description: Additional properties needed.
          example: {}
    ApplicationKeyReGenerateResponse:
      title: Application key details after re generating consumer secret
      type: object
      properties:
        consumerKey:
          type: string
          description: The consumer key associated with the application, used to indetify the client
          example: vYDoc9s7IgAFdkSyNDaswBX7ejoa
        consumerSecret:
          type: string
          description: The client secret that is used to authenticate the client with the authentication server
          example: TIDlOFkpzB7WjufO3OJUhy1fsvAa
    Error:
      title: Error object returned with 4XX HTTP status
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: integer
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
        moreInfo:
          type: string
          description: 'Preferably an url with more details about the error.

            '
        error:
          type: array
          description: 'If there are more than one error list them out.

            For example, list out validation errors by each field.

            '
          items:
            $ref: '#/components/schemas/ErrorListItem'
    ApplicationKey:
      title: Application key details
      type: object
      properties:
        keyMappingId:
          type: string
          description: Key Manager Mapping UUID
          readOnly: true
          example: 92ab520c-8847-427a-a921-3ed19b15aad7
        keyManager:
          type: string
          description: Key Manager Name
          example: Resident Key Manager
        consumerKey:
          type: string
          description: Consumer key of the application
          readOnly: true
          example: vYDoc9s7IgAFdkSyNDaswBX7ejoa
        consumerSecret:
          type: string
          description: Consumer secret of the application
          readOnly: true
          example: TIDlOFkpzB7WjufO3OJUhy1fsvAa
        consumerSecrets:
          type: array
          description: A list of all consumer secrets of the application When multiple consumer secrets are enabled
          items:
            $ref: '#/components/schemas/ConsumerSecret'
        supportedGrantTypes:
          type: array
          description: The grant types that are supported by the application
          example:
          - client_credentials
          - password
          items:
            type: string
        callbackUrl:
          type: string
          description: Callback URL
          example: http://sample.com/callback/url
        keyState:
          type: string
          description: Describes the state of the key generation.
          example: APPROVED
        keyType:
          type: string
          description: Describes to which endpoint the key belongs
          example: PRODUCTION
          enum:
          - PRODUCTION
          - SANDBOX
        mode:
          type: string
          description: Describe the which mode Application Mapped.
          example: CREATED
          enum:
          - MAPPED
          - CREATED
        groupId:
          type: string
          description: Application group id (if any).
          example: '2'
        token:
          $ref: '#/components/schemas/ApplicationToken'
        additionalProperties:
          type: object
          properties: {}
          description: additionalProperties (if any).
    ApplicationKeyList:
      title: Application Keys List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of applications keys returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/ApplicationKey'
  responses:
    BadRequest:
      description: Bad Request. Invalid request or validation error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 400
            message: Bad Request
            description: Invalid request or validation error
            moreInfo: ''
            error: []
    PreconditionFailed:
      description: Precondition Failed. The request has not been performed because one of the preconditions is not met.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 412
            message: Precondition Failed
            description: The request has not been performed because one of the preconditions is not met
            moreInfo: ''
            error: []
    Forbidden:
      description: Forbidden. The user does not have permission to perform this action.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 403
            message: Forbidden
            description: The user does not have permission to perform this action
            moreInfo: ''
            error: []
    NotFound:
      description: Not Found. The specified resource does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 404
            message: Not Found
            description: The specified resource does not exist
            moreInfo: ''
            error: []
  parameters:
    If-Match:
      name: If-Match
      in: header
      description: 'Validator for conditional requests; based on ETag.

        '
      schema:
        type: string
    groupId:
      name: groupId
      in: query
      description: 'Application Group Id

        '
      schema:
        type: string
    applicationId:
      name: applicationId
      in: path
      description: 'Application Identifier consisting of the UUID of the Application.

        '
      required: true
      schema:
        type: string
    requestedTenant:
      name: X-WSO2-Tenant
      in: header
      description: "For cross-tenant invocations, this is used to specify the tenant domain, where the resource need to be\n  retrieved from.\n"
      schema:
        type: string
    keyMappingId:
      name: keyMappingId
      in: path
      description: 'OAuth Key Identifier consisting of the UUID of the Oauth Key Mapping.

        '
      required: true
      schema:
        type: string
    keyType:
      name: keyType
      in: path
      description: '**Application Key Type** standing for the type of the keys (i.e. Production or Sandbox).

        '
      required: true
      schema:
        type: string
        enum:
        - PRODUCTION
        - SANDBOX
  securitySchemes:
    OAuth2Security:
      type: oauth2
      flows:
        password:
          tokenUrl: https://localhost:9443/oauth2/token
          scopes:
            openid: Authorize access to user details
            apim:subscribe: Subscribe API
            apim:api_key: Generate API Keys
            apim:app_manage: Retrieve, Manage and Import, Export applications
            apim:sub_manage: Retrieve, Manage subscriptions
            apim:store_settings: Retrieve Developer Portal settings
            apim:sub_alert_manage: Retrieve, subscribe and configure Developer Portal alert types
            apim:app_import_export: Import and export applications related operations
            apim:admin: Manage all admin operations