WSO2 Platform Gateways API

The Platform Gateways API from WSO2 — 3 operation(s) for platform gateways.

OpenAPI Specification

wso2-platform-gateways-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: WSO2 API Manager - Admin Advanced Policy (Collection) Advanced Policy (Collection) Platform Gateways API
  description: "This document specifies a **RESTful API** for WSO2 **API Manager** - **Admin Portal**.\nPlease see [full OpenAPI Specification](https://raw.githubusercontent.com/wso2/carbon-apimgt/master/components/apimgt/org.wso2.carbon.apimgt.rest.api.admin.v1/src/main/resources/admin-api.yaml) of the API which is written using [OAS 3.0](http://swagger.io/) specification.\n\n# Authentication\nThe Admin REST API is protected using OAuth2 and access control is achieved through scopes. Before you start invoking\nthe the API you need to obtain an access token with the required scopes. This guide will walk you through the steps\nthat you will need to follow to obtain an access token.\nFirst you need to obtain the consumer key/secret key pair by calling the dynamic client registration (DCR) endpoint. You can add your preferred grant types\nin the payload. A sample payload is shown below.\n```\n  {\n  \"callbackUrl\":\"www.example.com\",\n  \"clientName\":\"rest_api_admin\",\n  \"owner\":\"admin\",\n  \"grantType\":\"client_credentials password refresh_token\",\n  \"saasApp\":true\n  }\n```\nCreate a file (payload.json) with the above sample payload, and use the cURL shown bellow to invoke the DCR endpoint. Authorization header of this should contain the\nbase64 encoded admin username and password.\n**Format of the request**\n```\n  curl -X POST -H \"Authorization: Basic Base64(admin_username:admin_password)\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://<host>:<servlet_port>/client-registration/v0.17/register\n```\n**Sample request**\n```\n  curl -X POST -H \"Authorization: Basic YWRtaW46YWRtaW4=\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://localhost:9443/client-registration/v0.17/register\n```\nFollowing is a sample response after invoking the above curl.\n```\n{\n\"clientId\": \"fOCi4vNJ59PpHucC2CAYfYuADdMa\",\n\"clientName\": \"rest_api_admin\",\n\"callBackURL\": \"www.example.com\",\n\"clientSecret\": \"a4FwHlq0iCIKVs2MPIIDnepZnYMa\",\n\"isSaasApplication\": true,\n\"appOwner\": \"admin\",\n\"jsonString\": \"{\\\"grant_types\\\":\\\"client_credentials password refresh_token\\\",\\\"redirect_uris\\\":\\\"www.example.com\\\",\\\"client_name\\\":\\\"rest_api_admin\\\"}\",\n\"jsonAppAttribute\": \"{}\",\n\"tokenType\": null\n}\n```\nNote that in a distributed deployment or IS as KM separated environment to invoke RESTful APIs (product APIs), users must generate tokens through API-M Control Plane's token endpoint.\nThe tokens generated using third party key managers, are to manage end-user authentication when accessing APIs.\n\nNext you must use the above client id and secret to obtain the access token.\nWe will be using the password grant type for this, you can use any grant type you desire.\nYou also need to add the proper **scope** when getting the access token. All possible scopes for Admin REST API can be viewed in **OAuth2 Security** section\nof this document and scope for each resource is given in **authorizations** section of resource documentation.\nFollowing is the format of the request if you are using the password grant type.\n```\ncurl -k -d \"grant_type=password&username=<admin_username>&password=<admin_passowrd>&scope=<scopes seperated by space>\"\n\\ -H \"Authorization: Basic base64(cliet_id:client_secret)\"\n\\ https://<host>:<server_port>/oauth2/token\n```\n**Sample request**\n```\ncurl https://localhost:9443/oauth2/token -k \\\n-H \"Authorization: Basic Zk9DaTR2Tko1OVBwSHVjQzJDQVlmWXVBRGRNYTphNEZ3SGxxMGlDSUtWczJNUElJRG5lcFpuWU1h\" \\\n-d \"grant_type=password&username=admin&password=admin&scope=apim:admin apim:tier_view\"\n```\nShown below is a sample response to the above request.\n```\n{\n\"access_token\": \"e79bda48-3406-3178-acce-f6e4dbdcbb12\",\n\"refresh_token\": \"a757795d-e69f-38b8-bd85-9aded677a97c\",\n\"scope\": \"apim:admin apim:tier_view\",\n\"token_type\": \"Bearer\",\n\"expires_in\": 3600\n}\n```\nNow you have a valid access token, which you can use to invoke an API.\nNavigate through the API descriptions to find the required API, obtain an access token as described above and invoke the API with the authentication header.\nIf you use a different authentication mechanism, this process may change.\n\n# Try out in Postman\nIf you want to try-out the embedded postman collection with \"Run in Postman\" option, please follow the guidelines listed below.\n* All of the OAuth2 secured endpoints have been configured with an Authorization Bearer header with a parameterized access token. Before invoking any REST API resource make sure you run the `Register DCR Application` and `Generate Access Token` requests to fetch an access token with all required scopes.\n* Make sure you have an API Manager instance up and running.\n* Update the `basepath` parameter to match the hostname and port of the APIM instance.\n\n[![Run in Postman](https://run.pstmn.io/button.svg)](https://app.getpostman.com/run-collection/32294946-71bea2bc-f808-4208-a4f6-861ede6f0434)\n"
  contact:
    name: WSO2
    url: https://wso2.com/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  version: v4
servers:
- url: https://apis.wso2.com/api/am/admin/v4
tags:
- name: Platform Gateways
paths:
  /gateways:
    get:
      operationId: getPlatformGateways
      tags:
      - Platform Gateways
      summary: Get all platform gateways
      description: 'Get all registered platform gateways for the organization.

        '
      responses:
        200:
          description: 'OK.

            List of platform gateways returned (without registration tokens).

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GatewayList'
        404:
          $ref: '#/components/responses/NotFound'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://127.0.0.1:9443/api/am/admin/v4/gateways"'
    post:
      operationId: createPlatformGateway
      tags:
      - Platform Gateways
      summary: Register a platform gateway
      description: 'Register a new platform gateway. A registration token is generated and returned

        once in the response; store it (e.g. as GATEWAY_CONTROL_PLANE_TOKEN in Docker Compose) for the

        gateway to connect to the control plane WebSocket. The token is stored hashed and cannot be retrieved later.

        '
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreatePlatformGatewayRequest'
      responses:
        201:
          description: 'Created.

            Gateway and registration token (returned once) in the response body.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GatewayResponseWithToken'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        409:
          $ref: '#/components/responses/Conflict'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -X POST -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -d @data.json "https://127.0.0.1:9443/api/am/admin/v4/gateways"'
  /gateways/{gatewayId}/regenerate-token:
    post:
      operationId: regeneratePlatformGatewayToken
      tags:
      - Platform Gateways
      summary: Regenerate registration token for a platform gateway
      description: 'Regenerate the registration token for an existing platform gateway. The old token is revoked

        and a new one is generated. Store the new token (e.g. as GATEWAY_CONTROL_PLANE_TOKEN in Docker Compose)

        for the gateway to reconnect to the control plane WebSocket. The token is returned only once.

        '
      parameters:
      - name: gatewayId
        in: path
        description: Gateway UUID
        required: true
        schema:
          type: string
      responses:
        200:
          description: 'OK.

            Gateway and new registration token (returned once) in the response body.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GatewayResponseWithToken'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -X POST -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" "https://127.0.0.1:9443/api/am/admin/v4/gateways/{gatewayId}/regenerate-token"'
  /gateways/{gatewayId}:
    put:
      operationId: updatePlatformGateway
      tags:
      - Platform Gateways
      summary: Update a platform gateway
      description: 'Update platform gateway metadata. Request body must include all updatable fields (displayName,

        description, properties, permissions). Name and vhost cannot be changed. UI should send

        the full resource representation to align with PUT semantics.

        '
      parameters:
      - name: gatewayId
        in: path
        description: Gateway UUID
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdatePlatformGatewayRequest'
      responses:
        200:
          description: OK. Updated platform gateway in the response body.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformGatewayResponse'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
      security:
      - OAuth2Security:
        - apim:admin
    delete:
      operationId: deletePlatformGateway
      tags:
      - Platform Gateways
      summary: Delete a platform gateway
      description: 'Delete a platform gateway and all its references (tokens, instance mappings, revision deployment

        records, gateway environment, permissions). Fails with 409 if any API revisions are currently

        deployed to this gateway; undeploy all APIs from the gateway first.

        '
      parameters:
      - name: gatewayId
        in: path
        description: Gateway UUID
        required: true
        schema:
          type: string
      responses:
        200:
          description: OK. Gateway and all references removed.
        404:
          $ref: '#/components/responses/NotFound'
        409:
          description: Conflict. Cannot delete gateway while API revisions are deployed to it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - OAuth2Security:
        - apim:admin
components:
  schemas:
    PlatformGatewayResponse:
      title: Platform Gateway Response
      description: Platform gateway response (without registration token). Used for list and get.
      type: object
      properties:
        id:
          type: string
          readOnly: true
          description: Gateway UUID
        name:
          type: string
        displayName:
          type: string
        description:
          type: string
        properties:
          type: object
          additionalProperties: true
          description: Custom key-value properties
        vhost:
          type: string
          format: uri
          readOnly: true
          description: Gateway URL (e.g. https://host or https://host:9443). Same name as platform API; type is URL.
        isActive:
          type: boolean
          readOnly: true
          description: Indicates if the gateway is currently connected to the control plane via WebSocket
        permissions:
          type: object
          description: Gateway visibility permissions configuration
          properties:
            permissionType:
              type: string
              enum:
              - PUBLIC
              - ALLOW
              - DENY
              default: PUBLIC
              description: 'Permission type for gateway visibility:

                - PUBLIC: Gateway is visible to all users

                - ALLOW: Gateway is visible only to specified roles

                - DENY: Gateway is hidden from specified roles

                '
            roles:
              type: array
              items:
                type: string
              description: List of roles for ALLOW/DENY permission types
        createdAt:
          type: string
          format: date-time
          readOnly: true
        updatedAt:
          type: string
          format: date-time
          readOnly: true
    ErrorListItem:
      title: Description of individual errors that may have occurred during a request.
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: Error code
        message:
          type: string
          description: 'Description about individual errors occurred

            '
    UpdatePlatformGatewayRequest:
      title: Update Platform Gateway Request
      description: 'Request body for PUT /gateways/{gatewayId}. Per PUT semantics, send the full resource

        representation. Name and vhost are immutable (server validates they match the existing gateway).

        '
      required:
      - name
      - displayName
      - vhost
      type: object
      properties:
        name:
          type: string
          pattern: ^[a-z0-9-]+$
          minLength: 3
          maxLength: 64
          description: Gateway identifier (immutable; must match existing). Required for PUT full representation.
        vhost:
          type: string
          format: uri
          description: Gateway URL (immutable; must match existing). Same name as platform API; type is URL. Example https://mg.wso2.com
          example: https://mg.wso2.com
        displayName:
          type: string
          minLength: 1
          maxLength: 128
          description: Human-readable gateway name
          example: Production Gateway 01
        description:
          type: string
          maxLength: 1023
          description: Optional description
        properties:
          type: object
          additionalProperties: true
          description: Custom key-value properties for the gateway
          example:
            region: us-west
            tier: premium
        permissions:
          type: object
          description: Gateway visibility permissions (on-prem extension)
          properties:
            permissionType:
              type: string
              enum:
              - PUBLIC
              - ALLOW
              - DENY
              default: PUBLIC
            roles:
              type: array
              items:
                type: string
              description: List of roles for ALLOW/DENY permission types
    Error:
      title: Error object returned with 4XX HTTP status
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: integer
          description: Error code
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
        moreInfo:
          type: string
          description: 'Preferably an url with more details about the error.

            '
        error:
          type: array
          description: 'If there are more than one error list them out.

            For example, list out validation errors by each field.

            '
          items:
            $ref: '#/components/schemas/ErrorListItem'
    CreatePlatformGatewayRequest:
      title: Create Platform Gateway Request
      description: Request body for creating a platform gateway (name, displayName, vhost as URL, optional properties). Same property name as platform API; type is URL.
      required:
      - name
      - displayName
      - vhost
      type: object
      properties:
        name:
          type: string
          pattern: ^[a-z0-9-]+$
          minLength: 3
          maxLength: 64
          description: URL-friendly gateway identifier (lowercase alphanumeric with hyphens, unique per organization)
          example: prod-gateway-01
        displayName:
          type: string
          minLength: 1
          maxLength: 128
          description: Human-readable gateway name
          example: Production Gateway 01
        description:
          type: string
          maxLength: 1023
          description: Optional description
        vhost:
          type: string
          format: uri
          description: Gateway URL (e.g. https://mg.example.com:9443). Same name as platform API; type is URL. Server persists host internally.
          example: https://mg.wso2.com
        properties:
          type: object
          additionalProperties: true
          description: Custom key-value properties for the gateway
          example:
            region: us-west
            tier: premium
        permissions:
          type: object
          description: Gateway visibility permissions configuration
          properties:
            permissionType:
              type: string
              enum:
              - PUBLIC
              - ALLOW
              - DENY
              default: PUBLIC
              description: 'Permission type for gateway visibility:

                - PUBLIC: Gateway is visible to all users

                - ALLOW: Gateway is visible only to specified roles

                - DENY: Gateway is hidden from specified roles

                '
            roles:
              type: array
              items:
                type: string
              description: List of roles for ALLOW/DENY permission types
              example:
              - admin
              - publisher
          example:
            permissionType: ALLOW
            roles:
            - admin
            - publisher
    GatewayResponseWithToken:
      title: Gateway Response With Token
      description: Platform gateway response including the one-time registration token (POST create or regenerate-token).
      allOf:
      - $ref: '#/components/schemas/PlatformGatewayResponse'
      - type: object
        properties:
          registrationToken:
            type: string
            description: 'Registration token (returned only once on create or regenerate). Use as api-key when connecting

              the gateway to the control plane WebSocket. Store e.g. as GATEWAY_REGISTRATION_TOKEN.

              '
    GatewayList:
      title: Gateway List
      type: object
      properties:
        count:
          type: integer
          description: Number of platform gateways returned
        list:
          type: array
          items:
            $ref: '#/components/schemas/PlatformGatewayResponse'
  responses:
    NotFound:
      description: Not Found. The specified resource does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 404
            message: Not Found
            description: The specified resource does not exist
            moreInfo: ''
            error: []
    Conflict:
      description: Conflict. Specified resource already exists.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 409
            message: Conflict
            description: Specified resource already exists
            moreInfo: ''
            error: []
    BadRequest:
      description: Bad Request. Invalid request or validation error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 400
            message: Bad Request
            description: Invalid request or validation error
            moreInfo: ''
            error: []
  securitySchemes:
    OAuth2Security:
      type: oauth2
      flows:
        password:
          tokenUrl: https://localhost:9443/oauth2/token
          scopes:
            openid: Authorize access to user details
            apim:policies_import_export: Export and import policies related operations
            apim:admin: Manage all admin operations
            apim:tier_view: View throttling policies
            apim:tier_manage: Update and delete throttling policies
            apim:admin_tier_view: View throttling policies
            apim:admin_tier_manage: Update and delete throttling policies
            apim:bl_view: View deny policies
            apim:bl_manage: Update and delete deny policies
            apim:mediation_policy_view: View mediation policies
            apim:mediation_policy_create: Create and update mediation policies
            apim:app_owner_change: Retrieve and manage applications
            apim:app_settings_change: Change Application Settings
            apim:app_import_export: Import and export applications related operations
            apim:api_import_export: Import and export APIs related operations
            apim:api_product_import_export: Import and export API Products related operations
            apim:environment_manage: Manage gateway environments
            apim:environment_read: Retrieve gateway environments
            apim:monetization_usage_publish: Retrieve and publish Monetization related usage records
            apim:api_workflow_approve: Manage workflows
            apim:bot_data: Retrieve bot detection data
            apim:tenantInfo: Retrieve tenant related information
            apim:tenant_theme_manage: Manage tenant themes
            apim:admin_operations: Manage API categories and Key Managers related operations
            apim:api_category: Manage API categories
            apim:admin_settings: Retrieve admin settings
            apim:admin_alert_manage: Manage admin alerts
            apim:api_workflow_view: Retrive workflow requests
            apim:scope_manage: Manage system scopes
            apim:role_manage: Manage system roles
            apim:admin_application_view: View Applications
            apim:keymanagers_manage: Manage Key Managers
            apim:api_provider_change: Retrieve and manage applications
            apim:llm_provider_manage: Manage LLM Providers
            apim:gov_policy_read: Retrieve governance policies
            apim:gov_policy_manage: Manage governance policies
            apim:gov_result_read: Retrieve governance results
            apim:gov_rule_read: Retrieve governance rules
            apim:gov_rule_manage: Manage governance rules
            apim:organization_manage: Manage Organizations
            apim:organization_read: Read Organizations