openapi: 3.2.0 info: title: Aembit Cloud Credential Provider Integration API version: v1 servers: - url: https://{tenant}.aembit.io variables: tenant: default: tenant description: Aembit Tenant ID security: - {} tags: - name: Credential Provider Integration paths: /api/v1/credential-integrations/{id}: get: tags: - Credential Provider Integration summary: Get a Credential Provider Integration description: Get a Credential Provider Integration identified by its ID. operationId: get-credential-provider-integration parameters: - name: id in: path description: ID of Credential Provider Integration required: true schema: type: string format: uuid responses: '200': description: Credential Provider Integration content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - $ref: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' - $ref: '#/components/schemas/AwsIamRoleCpiDTO' - $ref: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' description: Individual Credential Provider Integration '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' delete: tags: - Credential Provider Integration summary: Delete a Credential Provider Integration description: Delete a Credential Provider Integration identified by its ID. operationId: delete-credential-provider-integration parameters: - name: id in: path description: ID of Credential Provider Integration required: true schema: type: string format: uuid responses: '204': description: Successfully deleted Credential Provider Integration '400': description: Bad Request '401': description: Not Authenticated '404': description: Not Found '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' patch: tags: - Credential Provider Integration summary: Patch a Credential Provider Integration description: Patch a Credential Provider Integration identified by its ID. operationId: patch-credential-provider-integration parameters: - name: id in: path description: ID of Credential Provider Integration required: true schema: type: string format: uuid requestBody: description: CredentialProviderIntegrationPatchDTO content: application/json: schema: description: Patch Request for an individual Credential Provider Integration $ref: '#/components/schemas/CredentialProviderIntegrationPatchDTO' responses: '200': description: Patched Credential Provider Integration content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - $ref: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' - $ref: '#/components/schemas/AwsIamRoleCpiDTO' - $ref: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' description: Individual Credential Provider Integration '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' /api/v1/credential-integrations: get: tags: - Credential Provider Integration summary: Get a page of Credential Provider Integrations description: Get a page of Credential Provider Integrations. operationId: get-credential-provider-integrations parameters: - name: page in: query schema: type: integer format: int32 default: 1 - name: per-page in: query schema: type: integer format: int32 default: 100 - name: filter in: query schema: type: string default: '' - name: order in: query schema: type: string default: '' - name: group-by in: query schema: type: string default: '' responses: '200': description: Page of Credential Provider Integrations content: application/json: schema: $ref: '#/components/schemas/ListCredentialProviderIntegrationDTOListDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' post: tags: - Credential Provider Integration summary: Create a Credential Provider Integration description: Create a Credential Provider Integration. operationId: post-credential-provider-integration requestBody: description: CredentialProviderIntegrationDTO content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - $ref: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' - $ref: '#/components/schemas/AwsIamRoleCpiDTO' - $ref: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' description: Individual Credential Provider Integration responses: '201': description: Created Credential Provider Integration content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - $ref: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' - $ref: '#/components/schemas/AwsIamRoleCpiDTO' - $ref: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' description: Individual Credential Provider Integration '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' put: tags: - Credential Provider Integration summary: Update a Credential Provider Integration description: Update a Credential Provider Integration. operationId: put-credential-provider-integration requestBody: description: CredentialProviderIntegrationDTO content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - $ref: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' - $ref: '#/components/schemas/AwsIamRoleCpiDTO' - $ref: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' description: Individual Credential Provider Integration responses: '200': description: Updated Credential Provider Integration content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - $ref: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' - $ref: '#/components/schemas/AwsIamRoleCpiDTO' - $ref: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' description: Individual Credential Provider Integration '400': description: Bad Request '401': description: Not Authenticated '404': description: Not Found '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' /api/v1/credential-integrations/list/{type}: get: tags: - Credential Provider Integration summary: Get a list of Credential Provider Integrations by type description: Get a list of Credential Provider Integrations by type. The most common usage is to populate a dropdown or selection list in the UI. operationId: get-credential-provider-integration-list parameters: - name: type in: path description: Type of Credential Provider Integration required: true schema: $ref: '#/components/schemas/CredentialProviderIntegrationType' responses: '200': description: List of Credential Provider Integrations content: application/json: schema: type: array items: $ref: '#/components/schemas/GuidStringKeyValuePairDto' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' components: schemas: CredentialProviderIntegrationType: enum: - GitLab - AwsIamRole - AzureEntraFederation type: string CredentialProviderIntegrationDTO: required: - isActive - name - resourceSet - type type: object properties: type: $ref: '#/components/schemas/CredentialProviderIntegrationType' externalId: type: string format: uuid name: maxLength: 128 minLength: 1 type: string description: Name of the Entity description: type: - 'null' - string description: Description of the Entity isActive: type: boolean description: True/False value that determines if this entity is Active or Disabled format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' createdAt: type: string format: date-time modifiedAt: type: - 'null' - string format: date-time createdBy: type: - 'null' - string modifiedBy: type: - 'null' - string resourceSet: type: string description: ID of the Resource Set in which this Access Entity exists format: uuid tokenExpiration: type: - 'null' - string format: date-time lastOperationTimestamp: type: - 'null' - string format: date-time status: type: - 'null' - string errorMessage: type: - 'null' - string additionalProperties: false description: Individual Credential Provider Integration discriminator: propertyName: type mapping: GitLab: '#/components/schemas/GitLabCredentialProviderIntegrationDTO' AwsIamRole: '#/components/schemas/AwsIamRoleCpiDTO' AzureEntraFederation: '#/components/schemas/AzureEntraFederationCredentialProviderIntegrationDTO' GuidStringKeyValuePairDto: type: object properties: key: type: string format: uuid value: type: - 'null' - string additionalProperties: false TagDTO: required: - key - value type: object properties: key: minLength: 1 type: string description: Tag Key value: minLength: 1 type: string description: Tag Key Value additionalProperties: false description: Aembit Entity Tag Details CredentialProviderIntegrationPatchDTO: type: object properties: name: maxLength: 128 type: - 'null' - string description: New Name for the identified entity description: type: - 'null' - string description: New Description for the identified entity isActive: type: - 'null' - boolean description: New Status for the identified entity format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' description: New Tags for the identified entity additionalProperties: false description: Patch Request for an individual Credential Provider Integration AwsIamRoleCpiDTO: allOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - required: - roleArn type: object properties: roleArn: minLength: 1 pattern: ^arn:aws:iam::\d{12}:role/[\w+=,.@/-]+$ type: string description: ARN of the AWS IAM Role to assume for access lifetimeInSeconds: maximum: 43200 minimum: 900 type: integer description: Lifetime of the access credentials in seconds, default is 3600 seconds (1 hour) format: int32 fetchSecretArns: type: boolean description: Indicates whether to fetch and populate the ARNs of secrets on AWS Secrets Manager Value Credential Provider UI additionalProperties: false description: DTO for AWS IAM Role Credential Provider Integration GenericResponseDTO: type: object properties: success: type: boolean description: True if the API call was successful, False otherwise message: type: - 'null' - string description: Message to indicate why the API call failed id: type: integer description: Unique identifier of the API response format: int32 additionalProperties: false description: DTO for a Generic API Response ListCredentialProviderIntegrationDTO: required: - isActive - name type: object properties: externalId: type: string format: uuid name: maxLength: 128 minLength: 1 type: string description: Name of the Entity description: type: - 'null' - string description: Description of the Entity isActive: type: boolean description: True/False value that determines if this entity is Active or Disabled format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' createdAt: type: string format: date-time modifiedAt: type: - 'null' - string format: date-time createdBy: type: - 'null' - string modifiedBy: type: - 'null' - string url: type: - 'null' - string type: $ref: '#/components/schemas/CredentialProviderIntegrationType' status: type: - 'null' - string lastOperationTimestamp: type: - 'null' - string format: date-time additionalProperties: false description: Page of Credential Provider Integrations ListCredentialProviderIntegrationDTOListDTO: type: object properties: page: type: integer description: Current page number of entities format: int32 perPage: type: integer description: Number of entities requested for the current page format: int32 order: type: - 'null' - string description: Ordering criteria used for the current page statusCode: type: integer description: HTTP StatusCode for the current result format: int32 recordsTotal: type: integer description: Total number of entities available format: int32 entities: type: - 'null' - array items: description: Page of Credential Provider Integrations $ref: '#/components/schemas/ListCredentialProviderIntegrationDTO' description: Page of entities for this request additionalProperties: false GitLabCredentialProviderIntegrationDTO: allOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - required: - url type: object properties: url: minLength: 1 pattern: ^https://[a-zA-Z0-9\-.]+\.[a-zA-Z]{2,}(:\d+)?(/\S*)?$ type: string userId: type: - 'null' - string topLevelGroupId: type: - 'null' - string personalAccessToken: type: - 'null' - string additionalProperties: false description: Individual Credential Provider Integration AzureEntraFederationCredentialProviderIntegrationDTO: allOf: - $ref: '#/components/schemas/CredentialProviderIntegrationDTO' - required: - audience - azureTenant - clientId - keyVaultName - subject type: object properties: audience: minLength: 1 pattern: ^\S+$ type: string description: Audience of the federated OIDC token to authenticate against Azure Entra ID subject: minLength: 1 type: string description: Subject of the federated OIDC token to authenticate against Azure Entra ID azureTenant: minLength: 1 pattern: ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ type: string description: Tenant ID of the Azure Entra ID to authenticate against Azure Key Vault clientId: minLength: 1 pattern: ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$ type: string description: Client ID of the Azure application to authenticate against Azure Key Vault keyVaultName: minLength: 1 pattern: ^[a-zA-Z](?!.*--)[a-zA-Z0-9-]{1,22}[a-zA-Z0-9]$ type: string description: Name of the Azure Key Vault to fetch secrets from fetchSecretNames: type: boolean description: Indicates whether to fetch and populate the names of secrets on Azure Key Vault Value Credential Provider UI additionalProperties: false description: Individual Credential Provider Integration securitySchemes: bearerAuth: type: http description: Authorization header using the Bearer scheme. scheme: bearer bearerFormat: Reference