WSO2 Key Manager (Collection) API

The Key Manager (Collection) API from WSO2 — 2 operation(s) for key manager (collection).

Operations 3

GET /key-managers Get all Key managers #
POST /key-managers Add a new API Key Manager #
POST /key-managers/discover Retrieve Well-known information from Key Manager Well-known Endpoint #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/wso2-key-manager-collection-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

wso2-key-manager-collection-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: WSO2 API Manager - Admin Key Manager (Collection) API
  description: This document specifies a **RESTful API** for WSO2 **API Manager** - **Admin Portal**.
  contact:
    name: WSO2
    url: https://wso2.com/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  version: v4
servers:
- url: https://apis.wso2.com/api/am/admin/v4
tags:
- name: Key Manager (Collection)
paths:
  /key-managers:
    get:
      tags:
      - Key Manager (Collection)
      summary: Get all Key managers
      responses:
        200:
          description: 'OK.

            KeyManagers returned

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyManagerList'
      security:
      - OAuth2Security:
        - apim:admin
        - apim:admin_operations
        - apim:keymanagers_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://127.0.0.1:9443/api/am/admin/v4/key-managers"'
      operationId: getKeyManagers
      x-operation-id-source: derived
    post:
      tags:
      - Key Manager (Collection)
      summary: Add a new API Key Manager
      requestBody:
        description: 'Key Manager object that should to be added

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KeyManager'
        required: true
      responses:
        201:
          description: 'Created.

            Successful response with the newly created object as entity in the body.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyManager'
        400:
          $ref: '#/components/responses/BadRequest'
      security:
      - OAuth2Security:
        - apim:admin
        - apim:admin_operations
        - apim:keymanagers_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -X POST -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -d @data.json "https://127.0.0.1:9443/api/am/admin/v4/key-managers"'
      operationId: postKeyManagers
      x-operation-id-source: derived
  /key-managers/discover:
    post:
      tags:
      - Key Manager (Collection)
      summary: Retrieve Well-known information from Key Manager Well-known Endpoint
      description: Retrieve well-known information from key manager's well-known endpoint
      requestBody:
        content:
          multipart/form-data:
            schema:
              properties:
                url:
                  type: string
                  description: Well-Known Endpoint
                type:
                  type: string
                  description: 'Key Manager Type

                    '
                  default: 'false'
      responses:
        200:
          description: 'OK.

            KeyManagers returned

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyManagerWellKnownResponse'
      security:
      - OAuth2Security:
        - apim:admin
        - apim:admin_operations
        - apim:keymanagers_manage
      x-code-samples:
      - lang: Curl
        source: 'curl -k -X POST -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -F "type=WSO2-IS" "https://127.0.0.1:9443/api/am/admin/v4/key-managers/discover"'
      operationId: postKeyManagersDiscover
      x-operation-id-source: derived
components:
  schemas:
    KeyManagerInfo:
      title: Key Manager Info
      required:
      - name
      - type
      type: object
      properties:
        id:
          type: string
          example: 01234567-0123-0123-0123-012345678901
        name:
          type: string
          example: WSO2 IS
        type:
          type: string
          example: IS
        description:
          type: string
          example: This is a key manager for Developers
        enabled:
          type: boolean
          example: true
        isGlobal:
          type: boolean
          example: true
        isUsed:
          type: boolean
          example: true
        tokenType:
          type: string
          description: The type of the tokens to be used (exchanged or without exchanged). Accepted values are EXCHANGED, DIRECT and BOTH.
          example: EXCHANGED
          default: DIRECT
          enum:
          - EXCHANGED
          - DIRECT
          - BOTH
    KeyManagerWellKnownResponse:
      title: Key Manager Well-Known Response.
      type: object
      properties:
        valid:
          type: boolean
          example: true
          default: false
        value:
          $ref: '#/components/schemas/KeyManager'
    Error:
      title: Error object returned with 4XX HTTP status
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: integer
          description: Error code
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
        moreInfo:
          type: string
          description: 'Preferably an url with more details about the error.

            '
        error:
          type: array
          description: 'If there are more than one error list them out.

            For example, list out validation errors by each field.

            '
          items:
            $ref: '#/components/schemas/ErrorListItem'
    TokenValidation:
      title: Token handling Configuration
      type: object
      properties:
        id:
          type: integer
        enable:
          type: boolean
          example: false
          default: true
        type:
          type: string
          enum:
          - REFERENCE
          - JWT
          - CUSTOM
        value:
          type: object
          properties: {}
    KeyManagerList:
      title: Key Manager List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of Key managers returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/KeyManagerInfo'
    KeyManagerEndpoint:
      title: Key Manager Endpoint.
      required:
      - name
      - value
      type: object
      properties:
        name:
          type: string
          example: token_endpoint
        value:
          type: string
          example: https://localhost:9443/oauth2/token
    ClaimMappingEntry:
      title: Claim Mapping Configuration
      type: object
      properties:
        remoteClaim:
          type: string
          example: http://idp.org/username
        localClaim:
          type: string
          example: http://wso2.org/username
    ErrorListItem:
      title: Description of individual errors that may have occurred during a request.
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: Error code
        message:
          type: string
          description: 'Description about individual errors occurred

            '
    KeyManager:
      title: Key Manager
      required:
      - name
      - type
      type: object
      properties:
        id:
          type: string
          readOnly: true
          example: 01234567-0123-0123-0123-012345678901
        name:
          maxLength: 100
          minLength: 1
          type: string
          example: WSO2 Identity Server
        displayName:
          maxLength: 100
          type: string
          description: 'display name of Key Manager to  show in UI

            '
          example: WSO2 Identity Server
        type:
          maxLength: 45
          minLength: 1
          type: string
          example: WSO2-IS
        description:
          maxLength: 256
          type: string
          example: This is a key manager for Developers
        wellKnownEndpoint:
          type: string
          description: 'Well-Known Endpoint of Identity Provider.

            '
          example: ''
        introspectionEndpoint:
          type: string
          example: https://localhost:9444/oauth2/introspect
          deprecated: true
        clientRegistrationEndpoint:
          type: string
          example: https://localhost:9444/keymanager-operations/dcr/register
          deprecated: true
        tokenEndpoint:
          type: string
          example: https://localhost:9444/oauth2/token
          deprecated: true
        displayTokenEndpoint:
          type: string
          example: https://localhost:9444/oauth2/token
          deprecated: true
        revokeEndpoint:
          type: string
          example: https://localhost:9444/oauth2/revoke
          deprecated: true
        displayRevokeEndpoint:
          type: string
          example: https://localhost:9444/oauth2/revoke
          deprecated: true
        userInfoEndpoint:
          type: string
          example: https://localhost:9444/oauth2/userinfo?schema=openid
          deprecated: true
        authorizeEndpoint:
          type: string
          example: https://localhost:9444/oauth2/authorize
          deprecated: true
        endpoints:
          type: array
          items:
            $ref: '#/components/schemas/KeyManagerEndpoint'
        certificates:
          type: object
          properties:
            type:
              type: string
              enum:
              - JWKS
              - PEM
            value:
              type: string
        issuer:
          type: string
          example: https://localhost:9444/services
        alias:
          type: string
          description: 'The alias of Identity Provider.

            If the tokenType is EXCHANGED, the alias value should be inclusive in the audience values of the JWT token

            '
          example: https://localhost:9443/oauth2/token
        scopeManagementEndpoint:
          type: string
          example: https://wso2is.com:9444/api/identity/oauth2/v1.0/scopes
          deprecated: true
        availableGrantTypes:
          type: array
          items:
            type: string
            example: client_credentials
        enableTokenGeneration:
          type: boolean
          example: true
        enableTokenEncryption:
          type: boolean
          example: false
          default: false
        enableTokenHashing:
          type: boolean
          example: false
          default: false
        enableMapOAuthConsumerApps:
          type: boolean
          example: false
          default: false
        enableOAuthAppCreation:
          type: boolean
          example: false
          default: false
        enableSelfValidationJWT:
          type: boolean
          example: true
          default: true
        claimMapping:
          type: array
          items:
            $ref: '#/components/schemas/ClaimMappingEntry'
        consumerKeyClaim:
          type: string
          example: azp
        scopesClaim:
          type: string
          example: scp
        tokenValidation:
          type: array
          items:
            $ref: '#/components/schemas/TokenValidation'
        enabled:
          type: boolean
          example: true
        global:
          type: boolean
          example: true
        additionalProperties:
          type: object
          properties: {}
          example:
            self_validate_jwt: true
            Username: admin
            Password: admin
        permissions:
          type: object
          properties:
            permissionType:
              type: string
              example: ALLOW
              default: PUBLIC
              enum:
              - PUBLIC
              - ALLOW
              - DENY
            roles:
              type: array
              items:
                type: string
                example: Internal/subscriber
        tokenType:
          type: string
          description: The type of the tokens to be used (exchanged or without exchanged). Accepted values are EXCHANGED, DIRECT and BOTH.
          example: EXCHANGED
          default: DIRECT
          enum:
          - EXCHANGED
          - DIRECT
          - BOTH
        allowedOrganizations:
          type: array
          items:
            type: string
  responses:
    BadRequest:
      description: Bad Request. Invalid request or validation error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 400
            message: Bad Request
            description: Invalid request or validation error
            moreInfo: ''
            error: []
  securitySchemes:
    OAuth2Security:
      type: oauth2
      flows:
        password:
          tokenUrl: https://localhost:9443/oauth2/token
          scopes:
            openid: Authorize access to user details
            apim:policies_import_export: Export and import policies related operations
            apim:admin: Manage all admin operations
            apim:tier_view: View throttling policies
            apim:tier_manage: Update and delete throttling policies
            apim:admin_tier_view: View throttling policies
            apim:admin_tier_manage: Update and delete throttling policies
            apim:bl_view: View deny policies
            apim:bl_manage: Update and delete deny policies
            apim:mediation_policy_view: View mediation policies
            apim:mediation_policy_create: Create and update mediation policies
            apim:app_owner_change: Retrieve and manage applications
            apim:app_settings_change: Change Application Settings
            apim:app_import_export: Import and export applications related operations
            apim:api_import_export: Import and export APIs related operations
            apim:api_product_import_export: Import and export API Products related operations
            apim:environment_manage: Manage gateway environments
            apim:environment_read: Retrieve gateway environments
            apim:monetization_usage_publish: Retrieve and publish Monetization related usage records
            apim:api_workflow_approve: Manage workflows
            apim:bot_data: Retrieve bot detection data
            apim:tenantInfo: Retrieve tenant related information
            apim:tenant_theme_manage: Manage tenant themes
            apim:admin_operations: Manage API categories and Key Managers related operations
            apim:api_category: Manage API categories
            apim:admin_settings: Retrieve admin settings
            apim:admin_alert_manage: Manage admin alerts
            apim:api_workflow_view: Retrive workflow requests
            apim:scope_manage: Manage system scopes
            apim:role_manage: Manage system roles
            apim:admin_application_view: View Applications
            apim:keymanagers_manage: Manage Key Managers
            apim:api_provider_change: Retrieve and manage applications
            apim:llm_provider_manage: Manage LLM Providers
            apim:gov_policy_read: Retrieve governance policies
            apim:gov_policy_manage: Manage governance policies
            apim:gov_result_read: Retrieve governance results
            apim:gov_rule_read: Retrieve governance rules
            apim:gov_rule_manage: Manage governance rules
            apim:organization_manage: Manage Organizations
            apim:organization_read: Read Organizations