openapi: 3.0.0
info:
version: 2015-05-28
x-release: v4
title: AWS IoT Accept Certificate Transfer Authorizer API
description: '
IoT provides secure, bi-directional communication between Internet-connected devices (such as sensors, actuators, embedded devices, or smart appliances) and the Amazon Web Services cloud. You can discover your custom IoT-Data endpoint to communicate with, configure rules for data processing and integration with other services, organize resources associated with each device (Registry), configure logging, and create and manage policies and credentials to authenticate devices.
The service endpoints that expose this API are listed in Amazon Web Services IoT Core Endpoints and Quotas. You must use the endpoint for the region that has the resources you want to access.
The service name used by Amazon Web Services Signature Version 4 to sign the request is: execute-api.
For more information about how IoT works, see the Developer Guide.
For information about how to use the credentials provider for IoT, see Authorizing Direct Calls to Amazon Web Services Services.
' x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: iot x-aws-signingName: iot x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/iot-2015-05-28.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://iot.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS IoT multi-region endpoint - url: https://iot.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS IoT multi-region endpoint - url: http://iot.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS IoT endpoint for China (Beijing) and China (Ningxia) - url: https://iot.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS IoT endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: Authorizer paths: /authorizer/{authorizerName}: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: CreateAuthorizer description:Creates an authorizer.
Requires permission to access the CreateAuthorizer action.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/CreateAuthorizerResponse' '480': description: ResourceAlreadyExistsException content: application/json: schema: $ref: '#/components/schemas/ResourceAlreadyExistsException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object required: - authorizerFunctionArn properties: authorizerFunctionArn: description: The ARN of the authorizer's Lambda function. type: string pattern: '[\s\S]*' maxLength: 2048 tokenKeyName: description: The name of the token key used to extract the token from the HTTP headers. type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 tokenSigningPublicKeys: description: The public keys used to verify the digital signature returned by your custom authentication service. type: object additionalProperties: $ref: '#/components/schemas/KeyValue' status: description: The status of the create authorizer request. type: string enum: - ACTIVE - INACTIVE tags: description: 'Metadata which can be used to manage the custom authorizer.
For URI Request parameters use format: ...key1=value1&key2=value2...
For the CLI command-line parameter use format: &&tags "key1=value1&key2=value2..."
For the cli-input-json file use format: "tags": "key1=value1&key2=value2..."
When true, the result from the authorizer’s Lambda function is cached for clients that use persistent HTTP connections. The results are cached for the time specified by the Lambda function in refreshAfterInSeconds. This value does not affect authorization of clients that use MQTT connections.
The default value is false.
Deletes an authorizer.
Requires permission to access the DeleteAuthorizer action.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DeleteAuthorizerResponse' '480': description: DeleteConflictException content: application/json: schema: $ref: '#/components/schemas/DeleteConflictException' '481': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '482': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The name of the authorizer to delete. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 summary: Amazon IoT Core Delete Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer get: operationId: DescribeAuthorizer description:Describes an authorizer.
Requires permission to access the DescribeAuthorizer action.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DescribeAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '484': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '485': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The name of the authorizer to describe. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 summary: Amazon IoT Core Describe Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer put: operationId: UpdateAuthorizer description:Updates an authorizer.
Requires permission to access the UpdateAuthorizer action.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/UpdateAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object properties: authorizerFunctionArn: description: The ARN of the authorizer's Lambda function. type: string pattern: '[\s\S]*' maxLength: 2048 tokenKeyName: description: 'The key used to extract the token from the HTTP headers. ' type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 tokenSigningPublicKeys: description: The public keys used to verify the token signature. type: object additionalProperties: $ref: '#/components/schemas/KeyValue' status: description: The status of the update authorizer request. type: string enum: - ACTIVE - INACTIVE enableCachingForHttp: description: Whentrue, the result from the authorizer’s Lambda function is cached for the time specified in refreshAfterInSeconds. The cached result is used while the device reuses the same HTTP connection.
type: boolean
summary: Amazon IoT Core Update Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
/authorizer/{authorizerName}/test:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
post:
operationId: TestInvokeAuthorizer
description: Tests a custom authorization behavior by invoking a specified custom authorizer. Use this to test and debug the custom authorization behavior of devices that connect to the IoT device gateway.
Requires permission to access the TestInvokeAuthorizer action.
responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/TestInvokeAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '484': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '485': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' '486': description: InvalidResponseException content: application/json: schema: $ref: '#/components/schemas/InvalidResponseException' parameters: - name: authorizerName in: path required: true description: The custom authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object properties: token: description: The token returned by your custom authentication service. type: string pattern: '[\s\S]*' minLength: 1 maxLength: 6144 tokenSignature: description: The signature made with the token and your custom authentication service's private key. This value must be Base-64-encoded. type: string pattern: '[A-Za-z0-9+/]+={0,2}' minLength: 1 maxLength: 2560 httpContext: description: Specifies the HTTP context to use for the test authorizer request. type: object properties: headers: allOf: - $ref: '#/components/schemas/HttpHeaders' - description: The header keys and values in an HTTP authorization request. queryString: allOf: - $ref: '#/components/schemas/HttpQueryString' - description: The query string keys and values in an HTTP authorization request. mqttContext: description: Specifies the MQTT context to use for the test authorizer request type: object properties: username: allOf: - $ref: '#/components/schemas/MqttUsername' - description: The value of theusername key in an MQTT authorization request.
password:
allOf:
- $ref: '#/components/schemas/MqttPassword'
- description: The value of the password key in an MQTT authorization request.
clientId:
allOf:
- $ref: '#/components/schemas/MqttClientId'
- description: The value of the clientId key in an MQTT authorization request.
tlsContext:
description: Specifies the TLS context to use for the test authorizer request.
type: object
properties:
serverName:
allOf:
- $ref: '#/components/schemas/ServerName'
- description: The value of the serverName key in a TLS authorization request.
summary: Amazon IoT Core Test Invoke Authorizer
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- Authorizer
components:
schemas:
ResourceNotFoundException: {}
IsAuthenticated:
type: boolean
AuthorizerName:
type: string
pattern: '[\w=,@-]+'
minLength: 1
maxLength: 128
MqttPassword:
type: string
minLength: 1
maxLength: 65535
DeleteAuthorizerResponse:
type: object
properties: {}
TagKey:
type: string
pattern: ^([\p{L}\p{Z}\p{N}_.:/=+\-@]*)$
minLength: 1
maxLength: 128
PrincipalId:
type: string
pattern: '[a-zA-Z0-9]+'
minLength: 1
maxLength: 128
ThrottlingException: {}
DescribeAuthorizerResponse:
type: object
properties:
authorizerDescription:
allOf:
- $ref: '#/components/schemas/AuthorizerDescription'
- description: The authorizer description.
DateType:
type: string
format: date-time
InvalidRequestException: {}
HttpHeaderValue:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 8192
UpdateAuthorizerResponse:
type: object
properties:
authorizerName:
allOf:
- $ref: '#/components/schemas/AuthorizerName'
- description: The authorizer name.
authorizerArn:
allOf:
- $ref: '#/components/schemas/AuthorizerArn'
- description: The authorizer ARN.
AuthorizerFunctionArn:
type: string
pattern: '[\s\S]*'
maxLength: 2048
MqttClientId:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 65535
InternalFailureException: {}
LimitExceededException: {}
AuthorizerDescription:
type: object
properties:
authorizerName:
allOf:
- $ref: '#/components/schemas/AuthorizerName'
- description: The authorizer name.
authorizerArn:
allOf:
- $ref: '#/components/schemas/AuthorizerArn'
- description: The authorizer ARN.
authorizerFunctionArn:
allOf:
- $ref: '#/components/schemas/AuthorizerFunctionArn'
- description: The authorizer's Lambda function ARN.
tokenKeyName:
allOf:
- $ref: '#/components/schemas/TokenKeyName'
- description: The key used to extract the token from the HTTP headers.
tokenSigningPublicKeys:
allOf:
- $ref: '#/components/schemas/PublicKeyMap'
- description: The public keys used to validate the token signature returned by your custom authentication service.
status:
allOf:
- $ref: '#/components/schemas/AuthorizerStatus'
- description: The status of the authorizer.
creationDate:
allOf:
- $ref: '#/components/schemas/DateType'
- description: The UNIX timestamp of when the authorizer was created.
lastModifiedDate:
allOf:
- $ref: '#/components/schemas/DateType'
- description: The UNIX timestamp of when the authorizer was last updated.
signingDisabled:
allOf:
- $ref: '#/components/schemas/BooleanKey'
- description: Specifies whether IoT validates the token signature in an authorization request.
enableCachingForHttp:
allOf:
- $ref: '#/components/schemas/EnableCachingForHttp'
- description: When true, the result from the authorizer’s Lambda function is cached for the time specified in refreshAfterInSeconds. The cached result is used while the device reuses the same HTTP connection.
description: The authorizer description.
CreateAuthorizerResponse:
type: object
properties:
authorizerName:
allOf:
- $ref: '#/components/schemas/AuthorizerName'
- description: The authorizer's name.
authorizerArn:
allOf:
- $ref: '#/components/schemas/AuthorizerArn'
- description: The authorizer ARN.
HttpQueryString:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 4096
TokenKeyName:
type: string
pattern: '[a-zA-Z0-9_-]+'
minLength: 1
maxLength: 128
PolicyDocument:
type: string
pattern: '[\s\S]*'
minLength: 0
maxLength: 404600
BooleanKey:
type: boolean
HttpHeaders:
type: object
additionalProperties:
$ref: '#/components/schemas/HttpHeaderValue'
Tag:
type: object
required:
- Key
properties:
Key:
allOf:
- $ref: '#/components/schemas/TagKey'
- description: The tag's key.
Value:
allOf:
- $ref: '#/components/schemas/TagValue'
- description: The tag's value.
description: A set of key/value pairs that are used to manage the resource.
PolicyDocuments:
type: array
items:
$ref: '#/components/schemas/PolicyDocument'
ResourceAlreadyExistsException: {}
AuthorizerArn:
type: string
maxLength: 2048
UnauthorizedException: {}
MqttUsername:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 65535
TagValue:
type: string
minLength: 0
maxLength: 256
DeleteConflictException: {}
EnableCachingForHttp:
type: boolean
TestInvokeAuthorizerResponse:
type: object
properties:
isAuthenticated:
allOf:
- $ref: '#/components/schemas/IsAuthenticated'
- description: True if the token is authenticated, otherwise false.
principalId:
allOf:
- $ref: '#/components/schemas/PrincipalId'
- description: The principal ID.
policyDocuments:
allOf:
- $ref: '#/components/schemas/PolicyDocuments'
- description: IAM policy documents.
refreshAfterInSeconds:
allOf:
- $ref: '#/components/schemas/Seconds'
- description: The number of seconds after which the temporary credentials are refreshed.
disconnectAfterInSeconds:
allOf:
- $ref: '#/components/schemas/Seconds'
- description: The number of seconds after which the connection is terminated.
Seconds:
type: integer
ServerName:
type: string
pattern: '[\s\S]*'
minLength: 1
maxLength: 253
KeyValue:
type: string
pattern: '[\s\S]*'
maxLength: 5120
ServiceUnavailableException: {}
AuthorizerStatus:
type: string
enum:
- ACTIVE
- INACTIVE
PublicKeyMap:
type: object
additionalProperties:
$ref: '#/components/schemas/KeyValue'
InvalidResponseException: {}
parameters:
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/iot/
x-hasEquivalentPaths: true