openapi: 3.0.0 info: version: 1.0.1 title: 'Auth API' description: "The Auth Api adheres to definitions in RFC6749 - The OAuth 2.0 Authorization Framework. It is used for authentication and authorization in Ericsson IoT.\n\n# Important\n\nAPI audience must be prepared for compatible API extensions:\n\n- Be tolerant with unknown fields in the payload (see also the following post from Martin Fowler \"TolerantReader\"), that is, ignore new fields but do not eliminate them from payload if needed for subsequent PUT requests.\n\n- Be prepared that \"x-extensible-enum\" return parameter may deliver new values. Either be agnostic or provide default behavior for unknown values.\n\n- Be prepared to handle HTTP status codes not explicitly specified in endpoint definitions.\n\n- Follow the redirect when the server returns HTTP status 301 Moved Permanently.\n\n# Versioning\n\nWhen changes are made to this API, the goal is to always do so in a backwards compatible way. When that cannot be avoided for some reason, versioning is performed using media type versioning. The HTTP Content-Type and Accept headers are used for this. This versioning only applies to the request and response content schema, not to URI or method semantics.\n\nFor example, to call version 2 of an API resource set:\n\n```\n\nAccept: application/json;version=2\n\n```\n\nThe API will respond to this with the Content-Type header set to this new version:\n\n```\n\nContent-Type: application/json;version=2\n\n```\n\nAs long as there are no incompatible changes, the standard media type application/json is used.\n\n# Deprecation\n\nAPI deprecation will be reflected in the OpenAPI specification. If a method on a path, a whole path or even a whole API endpoint (multiple paths) should be deprecated, they will be marked as deprecated.\nDuring deprecation phase, a Warning header (see RFC 7234 - Warning header) field will be added in the response. The warn-code will be 299 and the warn-text will inform about what is deprecated and when it will be completely removed.\n\nAPI audience should not start using a deprecated API.\n\nAPI audience is encouraged to monitor for Warning header." x-audience: external-public x-api-id: 38254dbd-d8fe-44cb-b1d6-4508cf74fd50 tags: - name: Auth description: "Endpoints for authentication and authorization." servers: - url: 'https://iot-api.aeris.com/iot/api/auth' description: 'API server' paths: /token: post: tags: - Auth summary: 'Retrieve JSON Web Token (JWT)' description: "" requestBody: description: 'Request body' required: true content: application/x-www-form-urlencoded: schema: type: object properties: grant_type: description: | The method used to accquire an access token. _Available values:_ - password type: string x-extensible-enum: - password client_id: description: | The client id used to accquire an access token. _Available values:_ - cm-public-api-client type: string x-extensible-enum: - cm-public-api-client username: description: 'The name of the user who requests an access token' type: string password: description: 'The password of the user who requests an access token' type: string required: - grant_type - client_id - username - password example: grant_type: password username: exampleuser password: examplepassword responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/TokenResponse' '400': description: 'Bad request' content: application/json: schema: $ref: '#/components/schemas/BadRequestTokenError' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/UnauthorizedTokenError' '500': description: Internal Server Error security: [] /certs: get: tags: - Auth summary: 'Retrieve public keys as JSON Web Key (JWK)' description: "Retrieve the public key(s) of the signing certificate. This endpoint returns public keys in JSON Web Key (JWK) format as defined in RFC 7517." responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CertsResponse' '404': description: 'Not found' '500': description: Internal Server Error security: [] components: schemas: TokenResponse: type: object properties: access_token: type: string description: 'Access token in Base 64 encoding.' token_type: type: string description: 'Type of token e.g JWT.' expires_in: type: integer description: 'Life time of current Access token in seconds.' required: - access_token - token_type - expires_in example: access_token: eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJtT2RVVDYzSG90NTI3Z3pSRGdDczRkWklYUzZONjZ4OUxuekZtaGNzbEEwIn0.eyJqdGkiOiIwMGQ0YmUxNC05YTYzLTQ3YzItYmEyMi01ZmM3NWFhOTZkYjUiLCJleHAiOjE1NjY4MTE2NzgsIm5iZiI6MCwiaWF0IjoxNTY2ODExMzc4LCJpc3MiOiJodHRwOi8vbG9jYWxob3N0OjgxODEvYXV0aC9yZWFsbXMvaW90IiwiYXVkIjpbImlvdC1yZXNvdXJjZSIsImFjY291bnQiXSwic3ViIjoiY2M4NWRhNGMtMDk1NC00MTA2LWJjM2YtZTY2ZTc3ZDAxZDQxIiwidHlwIjoiQmVhcmVyIiwiYXpwIjoiaW90LWJhc2ljLWNsaWVudCIsImF1dGhfdGltZSI6MCwic2Vzc2lvbl9zdGF0ZSI6IjA3YzkxZWQ5LTM5OTAtNDRkNi04MjQxLTY4YWUyZmZkZDU2MSIsImFjciI6IjEiLCJyZWFsbV9hY2Nlc3MiOnsicm9sZXMiOlsib2ZmbGluZV9hY2Nlc3MiLCJ1bWFfYXV0aG9yaXphdGlvbiJdfSwicmVzb3VyY2VfYWNjZXNzIjp7ImlvdC1yZXNvdXJjZSI6eyJyb2xlcyI6WyJ4ZHItcmF3LWFwaS5yZWFkIiwieGRyLXJlcG9ydC1hcGkucmVhZCIsInhkci1sb2NhdGlvbi1hcGkucmVhZCJdfSwiYWNjb3VudCI6eyJyb2xlcyI6WyJtYW5hZ2UtYWNjb3VudCIsIm1hbmFnZS1hY2NvdW50LWxpbmtzIiwidmlldy1wcm9maWxlIl19fSwic2NvcGUiOiJkZWZhdWx0Q2xpZW50VGVtcGxhdGUgcHJvZmlsZSBlbWFpbCIsImRjcCI6eyJjb21wYW55X2lkIjoiUGlnZ3lzQmFjb24ifSwidXBuIjoiY2M4NWRhNGMtMDk1NC00MTA2LWJjM2YtZTY2ZTc3ZDAxZDQxIiwiZW1haWxfdmVyaWZpZWQiOmZhbHNlLCJncm91cHMiOlsieGRyLXJhdy1hcGkucmVhZCIsInhkci1yZXBvcnQtYXBpLnJlYWQiLCJ4ZHItbG9jYXRpb24tYXBpLnJlYWQiXSwicHJlZmVycmVkX3VzZXJuYW1lIjoiYWxpY2UifQ.bJMBcGQOkRPhP29I2xyrpPFiuA4sf1N3gkm8pnI5zPm2n3mnUuWSIX8fO6StnvF5Fuid2zkFIFbSsN8vWveZmQwty6Tn17fnmLWy7AJ2nmn8VQlAxaGo8Ldwsd_zygyalhJKKos2rnT8b95_57hW8OCPJzF8OpQB0uOb9UHk25JKUeaHRhOfKyN7MRffnd48RIvQ54J1YWMIrtbHrRFsWx1ZMZa0GbIlcVbi3GUN_s8Tn1EXBFCtw2a4Wf-THmyI6o1ogqBAisR6QzkW6el1KcEqz5--Dl06EEV_TQDUEBEVROswXQlHwBaD6AKezT8wtoyzQSyXIEoYR9cl6ayJpQ token_type: JWT expires_in: 60 BadRequestTokenError: type: object properties: code: type: integer description: 'Application-specific error code.' example: 4000 httpStatus: type: integer description: 'HTTP status code returned.' example: 400 message: type: string description: 'Short, human-readable error summary.' example: 'Request validation failed' detailedMessage: type: string description: 'Detailed explanation of the validation failure.' example: 'tokenV3.arg1.username: username must not be null' required: - code - httpStatus - message - detailedMessage example: code: 4000 httpStatus: 400 message: 'Request validation failed' detailedMessage: 'tokenV3.arg1.username: username must not be null' UnauthorizedTokenError: type: object properties: code: type: integer description: 'Application-specific error code.' example: 2040 httpStatus: type: integer description: 'HTTP status code returned.' example: 401 message: type: string description: 'Human-readable error message.' example: 'Invalid credentials' required: - code - httpStatus - message example: code: 2040 httpStatus: 401 message: 'Invalid credentials' CertsResponse: type: object properties: keys: type: array items: type: object properties: kty: type: string description: 'Key type parameter.' alg: type: string description: 'Algorithm parameter.' use: type: string description: 'Intended use of the public key, "sig".' kid: type: string description: 'Key id parameter.' n: type: string description: 'Modulus value for the RSA public key.' e: type: string description: 'Exponent value for the RSA public key.' x5c: type: array description: 'X509 certificate chain.' items: type: string required: - kty - kid - n - e - x5c example: kty: RSA alg: RS256 kid: token3key use: sig n: "tg9Gyx05dRi6CDYtiRBeagGiK4XBF9iqoBNFBKogolM2FUj-qLWL7us4hygvIije5gCColPa0Nv0VLm4mDzyDJDzkBPMOIHmz4_30JinP60jRyYzsR6tYlwqse_wm99mOP3gCNlPpYiV1KEZNCDA9WQ30CwXsBj3wyQeWRparr6Ne3LkGHVcPduAc2nwZ4io5rN8FwrO9JG88Fq69gAySR8xWB7GciJtMtJU0ic4eXzF7BCHL2RzaY9_BI2U1S-StlB-q2XW_DgEbD9n1dJEkiaEMPgjABIu_VSItnM6FQjKrG_du2zo6oL24QaC9_6A04EahPeGLrGZcGeEm3Jezw" e: "AQAB" x5c: [ "MIIFJzCCAw+gAwIBAgIEWAqkOTANBgkqhkiG9w0BAQsFADBEMRMwEQYKCZImiZPyLGQBGRYDbmV0MRgwFgYKCZImiZPyLGQBGRYIZXJpY3Nzb24xEzARBgoJkiaJk/IsZAEZFgNpb3QwHhcNMjAwMTE2MTE1MTI1WhcNMjEwMTE1MTE1MTI1WjBEMRMwEQYKCZImiZPyLGQBGRYDbmV0MRgwFgYKCZImiZPyLGQBGRYIZXJpY3Nzb24xEzARBgoJkiaJk/IsZAEZFgNpb3QwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCBjI+6c7DYmFzAddJzmrZQcRnESmIMNESd8U+A2KDg68zRdXc5Dy9LG+wYwUxz2aCFKNILIlCKBZ1jJUqdoP/5N3hkhKV31ihNU06B2+AwXBGdc3Nifr/Aextfv70leWeqwlMGJry7c6B9gnVLI/erJu4yNOrLifCoh6qjwAtz4t0DODfTCO7/5nGArIMUCC/0wAHk52AwUgt4BC2neuJnuAJV1+FhCBM5/ZvEVmzGiQVU9Uv4s8KWl8Z6c3AOaCsItfNBjBFfqGPy/Y4EwZQjSX9gNxyU2OBdVdIiKmv+NDgt9725/A4pYGISWxdXC3ku7D0trNlamc2OBvwGkPdwwMCFWlrVqq/ZcHK/oVBkyRGMlcplxKmwkUlNDfPk58IR3SQfkQxj3hFMtabccaF6mf2EW7bb1phWSBPEd7ha2duSpNEPGeK+Hv8ZQVIFIvsCUJycoBtPq7NEy5DEiOUUW7ti2XClnIxdK/MESjXgpkKx85zWPfye0HM0b+VgDLt4TeInzWpk3R/TKEed4gpUaCQ2lECTJwI7AgCBkSWecFOvyg0L+Skf99f5SyunKO+kgyZbiRiKDc0KRJEswyLnHkNh/eYV6HcxkgiWEVNSaeKNPX0PF0Y3sBxFzpP2W2FVdHEAWRo44GdzBuyMe9R3+8/pkfNgOdH2qivJvKXtpQIDAQABoyEwHzAdBgNVHQ4EFgQUbYnMU8UlC0s5nxS0qN0/Hj/E0n4wDQYJKoZIhvcNAQELBQADggIBAHI8LuIFZeaBWJksxFvD8fFwlNIHqwKVVw04zRCqa65f0/PIGGhFjFrEa2x3EpCkrDuGSYkRsPUFXlHlzO+8HpabQX0vxEpbuqfktFkd4PHqDp3VVG2oj15ezdMtT9zdRViBKuIlwKHyVEF/xyEgsUm9l+96SWdv9L+wWYp/9vhckULArzVxRYcgz/iRQ0cWS953GNoTSDhkV5R5Ixi89b9+bFEs+2eT/kgzA8NTYMbWWxw9wfFDmQxw9c5GXRHRJI6vruP30JhPGRGEe6Y+wBZcVIXY1mvdbBYSt7xEt9oPN2/Df5ra97Kzk5DjrUjVpv1Sw8maeVR5hNxws0wEd1CEc8X6ut0r4NHJN1FzBqPlvMxJj/TLtEM/lrdIIqdngYmqmDDA5fSJUYMXWkSZQx/xm3eTZp3l2Ze3bU6SbazExxL3QClDe5uOY/SDY+CJJpSxjQ2m1ka4NIuCO1U5/9vHfRX1W7tsTl4yuMxXI1VvG7bSqNZvOaPGBXrFb/FLM/bnJL3LqH9X1NpB1UA1GOfgHwbM8rCu9Do1pJM/xvAAFyoMvkhY2+ULPtR++1Wym/IJLpo4WyLk+ZsMpm9c0wrM0BWUT48r+5CaIq5xtwRk962xNr2NPgQS9tsGKWejd8hGQBH2RnKlF6IbEyTH2gVkFfnugn3GrS+ryJsh/cec" ]