openapi: 3.0.0 info: version: 2015-05-28 x-release: v4 title: AWS IoT Accept Certificate Transfer Authorizer API description: 'IoT

IoT provides secure, bi-directional communication between Internet-connected devices (such as sensors, actuators, embedded devices, or smart appliances) and the Amazon Web Services cloud. You can discover your custom IoT-Data endpoint to communicate with, configure rules for data processing and integration with other services, organize resources associated with each device (Registry), configure logging, and create and manage policies and credentials to authenticate devices.

The service endpoints that expose this API are listed in Amazon Web Services IoT Core Endpoints and Quotas. You must use the endpoint for the region that has the resources you want to access.

The service name used by Amazon Web Services Signature Version 4 to sign the request is: execute-api.

For more information about how IoT works, see the Developer Guide.

For information about how to use the credentials provider for IoT, see Authorizing Direct Calls to Amazon Web Services Services.

' x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: iot x-aws-signingName: iot x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/iot-2015-05-28.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://iot.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS IoT multi-region endpoint - url: https://iot.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS IoT multi-region endpoint - url: http://iot.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS IoT endpoint for China (Beijing) and China (Ningxia) - url: https://iot.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS IoT endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: Authorizer paths: /authorizer/{authorizerName}: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: CreateAuthorizer description:

Creates an authorizer.

Requires permission to access the CreateAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/CreateAuthorizerResponse' '480': description: ResourceAlreadyExistsException content: application/json: schema: $ref: '#/components/schemas/ResourceAlreadyExistsException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object required: - authorizerFunctionArn properties: authorizerFunctionArn: description: The ARN of the authorizer's Lambda function. type: string pattern: '[\s\S]*' maxLength: 2048 tokenKeyName: description: The name of the token key used to extract the token from the HTTP headers. type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 tokenSigningPublicKeys: description: The public keys used to verify the digital signature returned by your custom authentication service. type: object additionalProperties: $ref: '#/components/schemas/KeyValue' status: description: The status of the create authorizer request. type: string enum: - ACTIVE - INACTIVE tags: description: '

Metadata which can be used to manage the custom authorizer.

For URI Request parameters use format: ...key1=value1&key2=value2...

For the CLI command-line parameter use format: &&tags "key1=value1&key2=value2..."

For the cli-input-json file use format: "tags": "key1=value1&key2=value2..."

' type: array items: $ref: '#/components/schemas/Tag' signingDisabled: description: Specifies whether IoT validates the token signature in an authorization request. type: boolean enableCachingForHttp: description:

When true, the result from the authorizer’s Lambda function is cached for clients that use persistent HTTP connections. The results are cached for the time specified by the Lambda function in refreshAfterInSeconds. This value does not affect authorization of clients that use MQTT connections.

The default value is false.

type: boolean summary: Amazon IoT Core Create Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer delete: operationId: DeleteAuthorizer description:

Deletes an authorizer.

Requires permission to access the DeleteAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DeleteAuthorizerResponse' '480': description: DeleteConflictException content: application/json: schema: $ref: '#/components/schemas/DeleteConflictException' '481': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '482': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The name of the authorizer to delete. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 summary: Amazon IoT Core Delete Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer get: operationId: DescribeAuthorizer description:

Describes an authorizer.

Requires permission to access the DescribeAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DescribeAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '484': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '485': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The name of the authorizer to describe. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 summary: Amazon IoT Core Describe Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer put: operationId: UpdateAuthorizer description:

Updates an authorizer.

Requires permission to access the UpdateAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/UpdateAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object properties: authorizerFunctionArn: description: The ARN of the authorizer's Lambda function. type: string pattern: '[\s\S]*' maxLength: 2048 tokenKeyName: description: 'The key used to extract the token from the HTTP headers. ' type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 tokenSigningPublicKeys: description: The public keys used to verify the token signature. type: object additionalProperties: $ref: '#/components/schemas/KeyValue' status: description: The status of the update authorizer request. type: string enum: - ACTIVE - INACTIVE enableCachingForHttp: description: When true, the result from the authorizer’s Lambda function is cached for the time specified in refreshAfterInSeconds. The cached result is used while the device reuses the same HTTP connection. type: boolean summary: Amazon IoT Core Update Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer /authorizer/{authorizerName}/test: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: TestInvokeAuthorizer description:

Tests a custom authorization behavior by invoking a specified custom authorizer. Use this to test and debug the custom authorization behavior of devices that connect to the IoT device gateway.

Requires permission to access the TestInvokeAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/TestInvokeAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '484': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '485': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' '486': description: InvalidResponseException content: application/json: schema: $ref: '#/components/schemas/InvalidResponseException' parameters: - name: authorizerName in: path required: true description: The custom authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object properties: token: description: The token returned by your custom authentication service. type: string pattern: '[\s\S]*' minLength: 1 maxLength: 6144 tokenSignature: description: The signature made with the token and your custom authentication service's private key. This value must be Base-64-encoded. type: string pattern: '[A-Za-z0-9+/]+={0,2}' minLength: 1 maxLength: 2560 httpContext: description: Specifies the HTTP context to use for the test authorizer request. type: object properties: headers: allOf: - $ref: '#/components/schemas/HttpHeaders' - description: The header keys and values in an HTTP authorization request. queryString: allOf: - $ref: '#/components/schemas/HttpQueryString' - description: The query string keys and values in an HTTP authorization request. mqttContext: description: Specifies the MQTT context to use for the test authorizer request type: object properties: username: allOf: - $ref: '#/components/schemas/MqttUsername' - description: The value of the username key in an MQTT authorization request. password: allOf: - $ref: '#/components/schemas/MqttPassword' - description: The value of the password key in an MQTT authorization request. clientId: allOf: - $ref: '#/components/schemas/MqttClientId' - description: The value of the clientId key in an MQTT authorization request. tlsContext: description: Specifies the TLS context to use for the test authorizer request. type: object properties: serverName: allOf: - $ref: '#/components/schemas/ServerName' - description: The value of the serverName key in a TLS authorization request. summary: Amazon IoT Core Test Invoke Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer components: schemas: ResourceNotFoundException: {} IsAuthenticated: type: boolean AuthorizerName: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 MqttPassword: type: string minLength: 1 maxLength: 65535 DeleteAuthorizerResponse: type: object properties: {} TagKey: type: string pattern: ^([\p{L}\p{Z}\p{N}_.:/=+\-@]*)$ minLength: 1 maxLength: 128 PrincipalId: type: string pattern: '[a-zA-Z0-9]+' minLength: 1 maxLength: 128 ThrottlingException: {} DescribeAuthorizerResponse: type: object properties: authorizerDescription: allOf: - $ref: '#/components/schemas/AuthorizerDescription' - description: The authorizer description. DateType: type: string format: date-time InvalidRequestException: {} HttpHeaderValue: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 8192 UpdateAuthorizerResponse: type: object properties: authorizerName: allOf: - $ref: '#/components/schemas/AuthorizerName' - description: The authorizer name. authorizerArn: allOf: - $ref: '#/components/schemas/AuthorizerArn' - description: The authorizer ARN. AuthorizerFunctionArn: type: string pattern: '[\s\S]*' maxLength: 2048 MqttClientId: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 65535 InternalFailureException: {} LimitExceededException: {} AuthorizerDescription: type: object properties: authorizerName: allOf: - $ref: '#/components/schemas/AuthorizerName' - description: The authorizer name. authorizerArn: allOf: - $ref: '#/components/schemas/AuthorizerArn' - description: The authorizer ARN. authorizerFunctionArn: allOf: - $ref: '#/components/schemas/AuthorizerFunctionArn' - description: The authorizer's Lambda function ARN. tokenKeyName: allOf: - $ref: '#/components/schemas/TokenKeyName' - description: The key used to extract the token from the HTTP headers. tokenSigningPublicKeys: allOf: - $ref: '#/components/schemas/PublicKeyMap' - description: The public keys used to validate the token signature returned by your custom authentication service. status: allOf: - $ref: '#/components/schemas/AuthorizerStatus' - description: The status of the authorizer. creationDate: allOf: - $ref: '#/components/schemas/DateType' - description: The UNIX timestamp of when the authorizer was created. lastModifiedDate: allOf: - $ref: '#/components/schemas/DateType' - description: The UNIX timestamp of when the authorizer was last updated. signingDisabled: allOf: - $ref: '#/components/schemas/BooleanKey' - description: Specifies whether IoT validates the token signature in an authorization request. enableCachingForHttp: allOf: - $ref: '#/components/schemas/EnableCachingForHttp' - description: When true, the result from the authorizer’s Lambda function is cached for the time specified in refreshAfterInSeconds. The cached result is used while the device reuses the same HTTP connection. description: The authorizer description. CreateAuthorizerResponse: type: object properties: authorizerName: allOf: - $ref: '#/components/schemas/AuthorizerName' - description: The authorizer's name. authorizerArn: allOf: - $ref: '#/components/schemas/AuthorizerArn' - description: The authorizer ARN. HttpQueryString: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 4096 TokenKeyName: type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 PolicyDocument: type: string pattern: '[\s\S]*' minLength: 0 maxLength: 404600 BooleanKey: type: boolean HttpHeaders: type: object additionalProperties: $ref: '#/components/schemas/HttpHeaderValue' Tag: type: object required: - Key properties: Key: allOf: - $ref: '#/components/schemas/TagKey' - description: The tag's key. Value: allOf: - $ref: '#/components/schemas/TagValue' - description: The tag's value. description: A set of key/value pairs that are used to manage the resource. PolicyDocuments: type: array items: $ref: '#/components/schemas/PolicyDocument' ResourceAlreadyExistsException: {} AuthorizerArn: type: string maxLength: 2048 UnauthorizedException: {} MqttUsername: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 65535 TagValue: type: string minLength: 0 maxLength: 256 DeleteConflictException: {} EnableCachingForHttp: type: boolean TestInvokeAuthorizerResponse: type: object properties: isAuthenticated: allOf: - $ref: '#/components/schemas/IsAuthenticated' - description: True if the token is authenticated, otherwise false. principalId: allOf: - $ref: '#/components/schemas/PrincipalId' - description: The principal ID. policyDocuments: allOf: - $ref: '#/components/schemas/PolicyDocuments' - description: IAM policy documents. refreshAfterInSeconds: allOf: - $ref: '#/components/schemas/Seconds' - description: The number of seconds after which the temporary credentials are refreshed. disconnectAfterInSeconds: allOf: - $ref: '#/components/schemas/Seconds' - description: The number of seconds after which the connection is terminated. Seconds: type: integer ServerName: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 253 KeyValue: type: string pattern: '[\s\S]*' maxLength: 5120 ServiceUnavailableException: {} AuthorizerStatus: type: string enum: - ACTIVE - INACTIVE PublicKeyMap: type: object additionalProperties: $ref: '#/components/schemas/KeyValue' InvalidResponseException: {} parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/iot/ x-hasEquivalentPaths: true