openapi: 3.2.0 info: title: Aembit Cloud Credential Provider v2 API version: v1 servers: - url: https://{tenant}.aembit.io variables: tenant: default: tenant description: Aembit Tenant ID security: - {} tags: - name: Credential Provider v2 paths: /api/v2/credential-providers: post: tags: - Credential Provider v2 summary: Create a Credential Provider description: Create a Credential Provider. operationId: post-credential-provider2 parameters: - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid requestBody: description: CredentialProviderV2DTO content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' responses: '201': description: Created Credential Provider content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' put: tags: - Credential Provider v2 summary: Update a Credential Provider description: Update a Credential Provider. operationId: put-credential-provider2 parameters: - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid requestBody: description: CredentialProviderV2DTO content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' responses: '200': description: Updated Credential Provider content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' get: tags: - Credential Provider v2 summary: Get a page of Credential Providers description: Get a page of Credential Providers. operationId: get-credential-providers-v2 parameters: - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid - name: page in: query schema: type: integer format: int32 default: 1 - name: per-page in: query schema: type: integer format: int32 default: 100 - name: filter in: query schema: type: string default: '' - name: order in: query schema: type: string default: '' - name: group-by in: query schema: type: string default: '' responses: '200': description: Page of Credential Providers content: application/json: schema: description: Page of Credential Providers $ref: '#/components/schemas/CredentialProviderV2DTOCredentialProviderListDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' /api/v2/credential-providers/{id}: get: tags: - Credential Provider v2 summary: Get a Credential Provider description: Get a Credential Provider identified by its ID. operationId: get-credential-provider2 parameters: - name: id in: path description: ID of Credential Provider required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid responses: '200': description: Credential Provider content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' '204': description: Credential Provider Not Found '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' delete: tags: - Credential Provider v2 summary: Delete a Credential Provider description: Delete a Credential Provider identified by its ID. operationId: delete-credential-provider2 parameters: - name: id in: path description: ID of Credential Provider required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid responses: '204': description: Deleted Credential Provider '400': description: Bad Request '401': description: Not Authenticated '404': description: Not Found '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' patch: tags: - Credential Provider v2 summary: Patch a Credential Provider description: Patch a Credential Provider. operationId: patch-credential-provider-v2 parameters: - name: id in: path description: ID of Credential Provider required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid requestBody: description: CredentialProviderPatchDTO content: application/json: schema: description: Patch request for an individual Credential Provider $ref: '#/components/schemas/CredentialProviderPatchDTO' responses: '200': description: Patched Credential Provider content: application/json: schema: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' /api/v2/credential-providers/{id}/verification: get: tags: - Credential Provider v2 summary: Verify the Credential Provider description: Verify the Credential Provider will successfully return a credential. operationId: get-credential-provider-verification-v2 parameters: - name: id in: path description: ID of Credential Provider required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid responses: '200': description: Details on the verification of a Credential Provider content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' /api/v2/credential-providers/{id}/authorize: get: tags: - Credential Provider v2 summary: Get a Credential Provider Authorization URL description: Get a Credential Provider Authorization URL identified by the Credential Provider ID. operationId: get-credential-provider-authorization-v2 parameters: - name: id in: path description: ID of Credential Provider required: true schema: type: string format: uuid - name: X-Aembit-ResourceSet in: header schema: type: string format: uuid responses: '302': description: Redirects to the Credential Provider Authorization URL '400': description: Bad Request '401': description: Not Authenticated '500': description: Internal Server Error content: application/json: schema: description: DTO for a Generic API Response $ref: '#/components/schemas/GenericResponseDTO' components: schemas: CredentialProviderV2DTOCredentialProviderListDTO: type: object properties: page: type: integer description: Page of entities format: int32 perPage: type: integer description: Number of entities requested for the current page format: int32 order: type: - 'null' - string description: Ordering criteria used for the current page statusCode: type: integer description: HTTP Status Code of the response format: int32 recordsTotal: type: integer description: Total number of Credential Providers format: int32 credentialProviders: type: - 'null' - array items: oneOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - $ref: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' - $ref: '#/components/schemas/CPTypeApiKeyUIV2DTO' - $ref: '#/components/schemas/CPAwsStsV2DTO' - $ref: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' - $ref: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' - $ref: '#/components/schemas/CPTypeClaudeWifV2DTO' - $ref: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' - $ref: '#/components/schemas/CPGitLabManagedAccountDTO' - $ref: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' - $ref: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' - $ref: '#/components/schemas/CPTypeOpenAiWifV2DTO' - $ref: '#/components/schemas/CPTypeJWTTokenV2DTO' - $ref: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' - $ref: '#/components/schemas/CPTypeVaultClientTokenV2DTO' description: Page of Credential Providers additionalProperties: false description: Page of Credential Providers CPTypeUsernamePasswordUIV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - password - username type: object properties: username: minLength: 1 type: string description: Username password: minLength: 1 type: string description: Password. Set to null on updates if not wish to change it additionalProperties: false CPTypeOAuth2CustomParameters: type: object properties: key: type: - 'null' - string value: type: - 'null' - string valueType: type: - 'null' - string additionalProperties: false CPTypeVaultClientTokenV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - authenticationPath - issuer - lifetime - port - subject - vaultHost type: object properties: issuer: minLength: 1 type: string description: Issuer of the Access Token format: https://your_tenant_id.id.aembit.io subject: minLength: 1 type: string description: Subject of the Access Token subjectType: type: - 'null' - string description: 'Subject type, Accepted values: ''literal'', ''dynamic''' lifetime: type: integer description: Access Token(used for authentication against vault OIDC provider) Lifetime in seconds format: int32 customClaimNames: type: - 'null' - array items: $ref: '#/components/schemas/JWTClaimDTO' description: Custom Claims that are added to the Access Token vaultHost: minLength: 1 type: string description: Vault host tls: type: boolean description: Tls enabled/disabled when connecting to the vault instance port: maximum: 65535 minimum: 1 type: integer description: Port number for connecting to the vault instance format: int32 authenticationPath: minLength: 1 type: string description: Vault authentication path namespace: type: - 'null' - string description: Namespace to be used when connecting to the vault instance role: type: - 'null' - string description: User role to be used when connecting to the vault instance forwardingConfig: type: - 'null' - string description: 'Forwarding configuration for the vault request. Accepted values: '''', ''conditional'', ''unconditional''' privateNetworkAccess: type: boolean description: Specifies whether the Vault instance is accessible over a private network additionalProperties: false CPTypeApiKeyUIV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - apiKey type: object properties: apiKey: minLength: 1 type: string description: API Key additionalProperties: false CPGitLabManagedAccountDTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - accessLevel - lifetimeInSeconds - scope type: object properties: groupIds: type: - 'null' - string description: Comma separated list of GitLab Group Identifiers or Paths projectIds: type: - 'null' - string description: Comma separated list of GitLab Project Identifiers or Paths accessLevel: type: integer description: Access level code to use while assigning Managed Service Account to a group or a project format: int32 lifetimeInSeconds: type: integer description: Lifetime (in seconds) of a Personal Access Token of the Managed Service Account format: int32 scope: minLength: 1 type: string description: A space separated list of scopes to be specified when requesting a Personal Access Token of a Managed Service Account userId: type: integer description: GitLab user ID of the Managed Service Account. format: int32 readOnly: true username: type: - 'null' - string description: GitLab username of the Managed Service Account. readOnly: true tokenSensitiveDataId: type: string format: uuid tokenId: type: - 'null' - string tokenExpiration: type: - 'null' - string description: Expiration timestamp of the Personal Access Token of the Managed Service Account. format: date-time readOnly: true lastOperationTimestamp: type: - 'null' - string description: Timestamp of the latest operation performed with the Personal Access Token of the Managed Service Account. format: date-time readOnly: true status: type: - 'null' - string description: Status of the Personal Access Token of the Managed Service Account. readOnly: true errorMessage: type: - 'null' - string description: Contains an error message related to the last unsuccessful operation using the Personal Access Token of the Managed Service Account. readOnly: true credentialProviderIntegrationExternalId: type: string description: ID of the Credential Provider Integration with which this Managed GitLab Account Credential Provider is associated format: uuid additionalProperties: false CPTypeGoogleWorkflowIDFederationV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - audience - serviceAccountEmail type: object properties: audience: minLength: 1 type: string description: Audience for the access token serviceAccountEmail: minLength: 1 type: string description: Service account email format: email lifetime: type: - 'null' - integer description: Access token lifetime (in seconds) format: int32 additionalProperties: false CredentialProviderV2DTO: required: - isActive - name - resourceSet - type type: object properties: type: minLength: 1 type: string externalId: type: string format: uuid name: maxLength: 128 minLength: 1 type: string description: Name of the Entity description: type: - 'null' - string description: Description of the Entity isActive: type: boolean description: True/False value that determines if this entity is Active or Disabled format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' createdAt: type: string format: date-time modifiedAt: type: - 'null' - string format: date-time createdBy: type: - 'null' - string modifiedBy: type: - 'null' - string resourceSet: type: string description: ID of the Resource Set in which this Access Entity exists format: uuid lifetimeTimeSpanSeconds: type: integer format: int32 lifetimeExpiration: type: - 'null' - string format: date-time accessPolicyCount: type: integer description: Access Policies associated with this Credential Provider format: int32 additionalProperties: false discriminator: propertyName: type mapping: aembit-access-token: '#/components/schemas/CPTypeAembitAccessTokenV2DTO' apikey: '#/components/schemas/CPTypeApiKeyUIV2DTO' aws-sts-oidc: '#/components/schemas/CPAwsStsV2DTO' azure-entra-federation: '#/components/schemas/CPTypeAzureEntraFederationV2DTO' azure-key-vault-value: '#/components/schemas/CPTypeAzureKeyVaultValueDTO' claude-wif: '#/components/schemas/CPTypeClaudeWifV2DTO' gcp-identity-federation: '#/components/schemas/CPTypeGoogleWorkflowIDFederationV2DTO' gitlab-managed-account: '#/components/schemas/CPGitLabManagedAccountDTO' oauth-authorization-code: '#/components/schemas/CPTypeOAuth2AuthorizationCodeUIV2DTO' oauth-client-credential: '#/components/schemas/CPTypeOAuth2ClientCredentialsUIV2DTO' openai-wif: '#/components/schemas/CPTypeOpenAiWifV2DTO' signed-jwt: '#/components/schemas/CPTypeJWTTokenV2DTO' username-password: '#/components/schemas/CPTypeUsernamePasswordUIV2DTO' vaultClientToken: '#/components/schemas/CPTypeVaultClientTokenV2DTO' CPTypeOAuth2ClientCredentialsUIV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - clientID - url type: object properties: clientID: minLength: 1 type: string description: 'OAuth Client ID ' clientSecret: type: - 'null' - string description: OAuth Client Secret scope: type: - 'null' - string description: OAuth Scopes customParameters: type: - 'null' - array items: $ref: '#/components/schemas/CPTypeOAuth2CustomParameters' description: Custom Claims that are added to the Access Token url: minLength: 1 type: string description: OAuth Token URL for handling token requests credentialStyle: type: - 'null' - string description: 'Defines how credential would be transmitted. Accepted value: ''postBody'', ''authHeader''' additionalProperties: false CredentialProviderPatchDTO: type: object properties: name: maxLength: 128 type: - 'null' - string description: New Name for the identified entity description: type: - 'null' - string description: New Description for the identified entity isActive: type: - 'null' - boolean description: New Status for the identified entity format: boolean tags: type: - 'null' - array items: description: Aembit Entity Tag Details $ref: '#/components/schemas/TagDTO' description: New Tags for the identified entity providerDetailJSON: type: - 'null' - string description: JSON representation of the Credential Provider configuration details type: type: - 'null' - string description: Credential Provider Type (e.g. oauth-client-credential, username-password, etc.) additionalProperties: false description: Patch request for an individual Credential Provider GenericResponseDTO: type: object properties: success: type: boolean description: True if the API call was successful, False otherwise message: type: - 'null' - string description: Message to indicate why the API call failed id: type: integer description: Unique identifier of the API response format: int32 additionalProperties: false description: DTO for a Generic API Response CPTypeAzureKeyVaultValueDTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - credentialProviderIntegrationExternalId type: object properties: secretName1: type: - 'null' - string description: The first secret. Used when specifying a single key or a key representing a username when working with a username/password pair. secretName2: type: - 'null' - string description: The second secret. Used when specifying a password when working with a username/password pair. credentialProviderIntegrationExternalId: type: string description: ID of the Azure Entra Federation Credential Provider Integration with which this Azure Key Vault Value Credential is associated format: uuid privateNetworkAccess: type: boolean description: Indicates if the Azure Key Vault Value Credential should be accessed over a private network additionalProperties: false TagDTO: required: - key - value type: object properties: key: minLength: 1 type: string description: Tag Key value: minLength: 1 type: string description: Tag Key Value additionalProperties: false description: Aembit Entity Tag Details CPTypeAembitAccessTokenV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - audience - lifetimeInSeconds - roleId type: object properties: audience: minLength: 1 type: string description: Audience for the access token format: your_tenant_id.api.aembit.io roleId: type: string description: Aembit Role Id format: uuid lifetimeInSeconds: type: integer description: Access token lifetime (in seconds) format: int32 absoluteTokenLifetime: type: - 'null' - integer description: Absolute Lifetime of the Refresh Token. Setting a value indicates Refresh Token Support will be enabled. format: int32 additionalProperties: false CPTypeJWTTokenV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - algorithmType - issuer - lifetime - subject - tokenConfiguration type: object properties: tokenConfiguration: minLength: 1 type: string description: 'Token configuration type. Accepted value: ''snowflake''' lifetime: type: integer description: Access token lifetime (in seconds) format: int32 algorithmType: minLength: 1 type: string description: 'Token signing algorithm. Accepted value: ''RS256''' issuer: minLength: 1 type: string description: Issuer of the access token format: Snowflake_Account_Name.Snowflake_Username.SHA256:{sha256(publicKey)} subject: minLength: 1 type: string description: Subject of the access token format: Snowflake_Account_Name.Snowflake_Username keyContent: type: - 'null' - string privateKey: type: - 'null' - string additionalProperties: false CPTypeOAuth2AuthorizationCodeUIV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - authorizationUrl - clientID - oAuthUrl - tokenUrl type: object properties: clientID: minLength: 1 type: string description: 'OAuth Client ID ' clientSecret: type: - 'null' - string description: OAuth Client Secret scope: type: - 'null' - string description: OAuth Scopes customParameters: type: - 'null' - array items: $ref: '#/components/schemas/CPTypeOAuth2CustomParameters' description: Custom Claims that are added to the Access Token oAuthUrl: minLength: 1 type: string description: OAuth well-known metadata endpoint authorizationUrl: minLength: 1 type: string description: OAuth Authorization URL for handling authorization requests tokenUrl: minLength: 1 type: string description: OAuth Token URL for handling token requests introspectionUrl: type: - 'null' - string description: Introspection Url of the OAuth 2.0 introspection endpoint, used to validate and obtain metadata about access tokens isPkceRequired: type: boolean description: Indicates if Proof Key for Code Exchange (PKCE) protocol flow must be used callBackUrl: type: - 'null' - string description: The callback URL where the Authorization Server sends the Authorization Code format: '' finalCallbackUrl: type: - 'null' - string description: Redirect URL after Aembit successfully completes OAuth authorization. Only available to Tenants which are entitled - contact Aembit support if you require this functionality. userAuthorizationUrl: type: - 'null' - string description: Authorization URL to be used for authorization of the Credential Provider by a privileged user state: type: - 'null' - string description: State parameter to maintain state between the authorization request and callback additionalProperties: false CPTypeClaudeWifV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - federationRuleId - organizationId - scope - serviceAccountId type: object properties: federationRuleId: minLength: 1 pattern: ^fdrl_.+$ type: string description: Federation Rule ID organizationId: minLength: 1 pattern: ^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$ type: string description: Organization ID serviceAccountId: minLength: 1 pattern: ^svac_.+$ type: string description: Service Account ID workspaceId: pattern: ^wrkspc_.+$ type: - 'null' - string description: Workspace ID audience: type: - 'null' - string description: Audience scope: minLength: 1 type: string description: Scope lifetime: maximum: 43200 minimum: 300 type: - 'null' - integer description: Access token lifetime (in seconds) format: int32 additionalProperties: false CPAwsStsV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - awsIAMRoleArn type: object properties: awsIAMRoleArn: minLength: 1 type: string description: Amazon Resource Name(ARN) for AWS IAM Role lifetime: type: - 'null' - integer description: Access token lifetime (in seconds) format: int32 additionalProperties: false JWTClaimDTO: type: object properties: key: type: - 'null' - string value: type: - 'null' - string valueType: type: - 'null' - string additionalProperties: false CPTypeOpenAiWifV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - identityProviderId - serviceAccountId type: object properties: identityProviderId: minLength: 1 pattern: ^idp_.+$ type: string description: Identity Provider ID serviceAccountId: minLength: 1 pattern: ^user-.+$ type: string description: Service Account ID audience: type: - 'null' - string description: Audience additionalProperties: false CPTypeAzureEntraFederationV2DTO: allOf: - $ref: '#/components/schemas/CredentialProviderV2DTO' - required: - audience - azureTenant - clientId - scope - subject type: object properties: audience: minLength: 1 type: string description: Audience for the access token subject: minLength: 1 type: string description: Subject for the access token scope: minLength: 1 type: string description: Scope for the access token azureTenant: minLength: 1 type: string description: Azure tenant ID clientId: minLength: 1 type: string description: Azure client ID additionalProperties: false securitySchemes: bearerAuth: type: http description: Authorization header using the Bearer scheme. scheme: bearer bearerFormat: Reference