openapi: 3.0.0 info: version: 2015-05-28 x-release: v4 title: AWS IoT Accept Certificate Transfer Authorizer API description: 'IoT

IoT provides secure, bi-directional communication between Internet-connected devices (such as sensors, actuators, embedded devices, or smart appliances) and the Amazon Web Services cloud. You can discover your custom IoT-Data endpoint to communicate with, configure rules for data processing and integration with other services, organize resources associated with each device (Registry), configure logging, and create and manage policies and credentials to authenticate devices.

The service endpoints that expose this API are listed in Amazon Web Services IoT Core Endpoints and Quotas. You must use the endpoint for the region that has the resources you want to access.

The service name used by Amazon Web Services Signature Version 4 to sign the request is: execute-api.

For more information about how IoT works, see the Developer Guide.

For information about how to use the credentials provider for IoT, see Authorizing Direct Calls to Amazon Web Services Services.

' x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: iot x-aws-signingName: iot x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/iot-2015-05-28.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://iot.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS IoT multi-region endpoint - url: https://iot.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The AWS IoT multi-region endpoint - url: http://iot.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS IoT endpoint for China (Beijing) and China (Ningxia) - url: https://iot.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The AWS IoT endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: Authorizer paths: /authorizer/{authorizerName}: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: CreateAuthorizer description:

Creates an authorizer.

Requires permission to access the CreateAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/CreateAuthorizerResponse' '480': description: ResourceAlreadyExistsException content: application/json: schema: $ref: '#/components/schemas/ResourceAlreadyExistsException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object required: - authorizerFunctionArn properties: authorizerFunctionArn: description: The ARN of the authorizer's Lambda function. type: string pattern: '[\s\S]*' maxLength: 2048 tokenKeyName: description: The name of the token key used to extract the token from the HTTP headers. type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 tokenSigningPublicKeys: description: The public keys used to verify the digital signature returned by your custom authentication service. type: object additionalProperties: $ref: '#/components/schemas/KeyValue' status: description: The status of the create authorizer request. type: string enum: - ACTIVE - INACTIVE tags: description: '

Metadata which can be used to manage the custom authorizer.

For URI Request parameters use format: ...key1=value1&key2=value2...

For the CLI command-line parameter use format: &&tags "key1=value1&key2=value2..."

For the cli-input-json file use format: "tags": "key1=value1&key2=value2..."

' type: array items: $ref: '#/components/schemas/Tag' signingDisabled: description: Specifies whether IoT validates the token signature in an authorization request. type: boolean enableCachingForHttp: description:

When true, the result from the authorizer’s Lambda function is cached for clients that use persistent HTTP connections. The results are cached for the time specified by the Lambda function in refreshAfterInSeconds. This value does not affect authorization of clients that use MQTT connections.

The default value is false.

type: boolean summary: Amazon IoT Device Management Create Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer delete: operationId: DeleteAuthorizer description:

Deletes an authorizer.

Requires permission to access the DeleteAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DeleteAuthorizerResponse' '480': description: DeleteConflictException content: application/json: schema: $ref: '#/components/schemas/DeleteConflictException' '481': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '482': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The name of the authorizer to delete. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 summary: Amazon IoT Device Management Delete Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer get: operationId: DescribeAuthorizer description:

Describes an authorizer.

Requires permission to access the DescribeAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DescribeAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '484': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '485': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The name of the authorizer to describe. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 summary: Amazon IoT Device Management Describe Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer put: operationId: UpdateAuthorizer description:

Updates an authorizer.

Requires permission to access the UpdateAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/UpdateAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: LimitExceededException content: application/json: schema: $ref: '#/components/schemas/LimitExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '485': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '486': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' parameters: - name: authorizerName in: path required: true description: The authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object properties: authorizerFunctionArn: description: The ARN of the authorizer's Lambda function. type: string pattern: '[\s\S]*' maxLength: 2048 tokenKeyName: description: 'The key used to extract the token from the HTTP headers. ' type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 tokenSigningPublicKeys: description: The public keys used to verify the token signature. type: object additionalProperties: $ref: '#/components/schemas/KeyValue' status: description: The status of the update authorizer request. type: string enum: - ACTIVE - INACTIVE enableCachingForHttp: description: When true, the result from the authorizer’s Lambda function is cached for the time specified in refreshAfterInSeconds. The cached result is used while the device reuses the same HTTP connection. type: boolean summary: Amazon IoT Device Management Update Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer /authorizer/{authorizerName}/test: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: TestInvokeAuthorizer description:

Tests a custom authorization behavior by invoking a specified custom authorizer. Use this to test and debug the custom authorization behavior of devices that connect to the IoT device gateway.

Requires permission to access the TestInvokeAuthorizer action.

responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/TestInvokeAuthorizerResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InvalidRequestException content: application/json: schema: $ref: '#/components/schemas/InvalidRequestException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: UnauthorizedException content: application/json: schema: $ref: '#/components/schemas/UnauthorizedException' '484': description: ServiceUnavailableException content: application/json: schema: $ref: '#/components/schemas/ServiceUnavailableException' '485': description: InternalFailureException content: application/json: schema: $ref: '#/components/schemas/InternalFailureException' '486': description: InvalidResponseException content: application/json: schema: $ref: '#/components/schemas/InvalidResponseException' parameters: - name: authorizerName in: path required: true description: The custom authorizer name. schema: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 requestBody: required: true content: application/json: schema: type: object properties: token: description: The token returned by your custom authentication service. type: string pattern: '[\s\S]*' minLength: 1 maxLength: 6144 tokenSignature: description: The signature made with the token and your custom authentication service's private key. This value must be Base-64-encoded. type: string pattern: '[A-Za-z0-9+/]+={0,2}' minLength: 1 maxLength: 2560 httpContext: description: Specifies the HTTP context to use for the test authorizer request. type: object properties: headers: allOf: - $ref: '#/components/schemas/HttpHeaders' - description: The header keys and values in an HTTP authorization request. queryString: allOf: - $ref: '#/components/schemas/HttpQueryString' - description: The query string keys and values in an HTTP authorization request. mqttContext: description: Specifies the MQTT context to use for the test authorizer request type: object properties: username: allOf: - $ref: '#/components/schemas/MqttUsername' - description: The value of the username key in an MQTT authorization request. password: allOf: - $ref: '#/components/schemas/MqttPassword' - description: The value of the password key in an MQTT authorization request. clientId: allOf: - $ref: '#/components/schemas/MqttClientId' - description: The value of the clientId key in an MQTT authorization request. tlsContext: description: Specifies the TLS context to use for the test authorizer request. type: object properties: serverName: allOf: - $ref: '#/components/schemas/ServerName' - description: The value of the serverName key in a TLS authorization request. summary: Amazon IoT Device Management Test Invoke Authorizer x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Authorizer components: parameters: X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false schemas: AuthorizerFunctionArn: type: string pattern: '[\s\S]*' maxLength: 2048 TokenKeyName: type: string pattern: '[a-zA-Z0-9_-]+' minLength: 1 maxLength: 128 InvalidResponseException: {} KeyValue: type: string pattern: '[\s\S]*' maxLength: 5120 Tag: type: object required: - Key properties: Key: allOf: - $ref: '#/components/schemas/TagKey' - description: The tag's key. Value: allOf: - $ref: '#/components/schemas/TagValue' - description: The tag's value. description: A set of key/value pairs that are used to manage the resource. ServiceUnavailableException: {} AuthorizerArn: type: string maxLength: 2048 UnauthorizedException: {} BooleanKey: type: boolean PublicKeyMap: type: object additionalProperties: $ref: '#/components/schemas/KeyValue' ThrottlingException: {} MqttClientId: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 65535 Seconds: type: integer ResourceAlreadyExistsException: {} TagKey: type: string pattern: ^([\p{L}\p{Z}\p{N}_.:/=+\-@]*)$ minLength: 1 maxLength: 128 ServerName: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 253 UpdateAuthorizerResponse: type: object properties: authorizerName: allOf: - $ref: '#/components/schemas/AuthorizerName' - description: The authorizer name. authorizerArn: allOf: - $ref: '#/components/schemas/AuthorizerArn' - description: The authorizer ARN. InternalFailureException: {} PolicyDocuments: type: array items: $ref: '#/components/schemas/PolicyDocument' DeleteConflictException: {} DeleteAuthorizerResponse: type: object properties: {} LimitExceededException: {} AuthorizerStatus: type: string enum: - ACTIVE - INACTIVE HttpHeaders: type: object additionalProperties: $ref: '#/components/schemas/HttpHeaderValue' HttpHeaderValue: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 8192 AuthorizerName: type: string pattern: '[\w=,@-]+' minLength: 1 maxLength: 128 IsAuthenticated: type: boolean MqttPassword: type: string minLength: 1 maxLength: 65535 InvalidRequestException: {} HttpQueryString: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 4096 PolicyDocument: type: string pattern: '[\s\S]*' minLength: 0 maxLength: 404600 DescribeAuthorizerResponse: type: object properties: authorizerDescription: allOf: - $ref: '#/components/schemas/AuthorizerDescription' - description: The authorizer description. PrincipalId: type: string pattern: '[a-zA-Z0-9]+' minLength: 1 maxLength: 128 AuthorizerDescription: type: object properties: authorizerName: allOf: - $ref: '#/components/schemas/AuthorizerName' - description: The authorizer name. authorizerArn: allOf: - $ref: '#/components/schemas/AuthorizerArn' - description: The authorizer ARN. authorizerFunctionArn: allOf: - $ref: '#/components/schemas/AuthorizerFunctionArn' - description: The authorizer's Lambda function ARN. tokenKeyName: allOf: - $ref: '#/components/schemas/TokenKeyName' - description: The key used to extract the token from the HTTP headers. tokenSigningPublicKeys: allOf: - $ref: '#/components/schemas/PublicKeyMap' - description: The public keys used to validate the token signature returned by your custom authentication service. status: allOf: - $ref: '#/components/schemas/AuthorizerStatus' - description: The status of the authorizer. creationDate: allOf: - $ref: '#/components/schemas/DateType' - description: The UNIX timestamp of when the authorizer was created. lastModifiedDate: allOf: - $ref: '#/components/schemas/DateType' - description: The UNIX timestamp of when the authorizer was last updated. signingDisabled: allOf: - $ref: '#/components/schemas/BooleanKey' - description: Specifies whether IoT validates the token signature in an authorization request. enableCachingForHttp: allOf: - $ref: '#/components/schemas/EnableCachingForHttp' - description: When true, the result from the authorizer’s Lambda function is cached for the time specified in refreshAfterInSeconds. The cached result is used while the device reuses the same HTTP connection. description: The authorizer description. DateType: type: string format: date-time CreateAuthorizerResponse: type: object properties: authorizerName: allOf: - $ref: '#/components/schemas/AuthorizerName' - description: The authorizer's name. authorizerArn: allOf: - $ref: '#/components/schemas/AuthorizerArn' - description: The authorizer ARN. TestInvokeAuthorizerResponse: type: object properties: isAuthenticated: allOf: - $ref: '#/components/schemas/IsAuthenticated' - description: True if the token is authenticated, otherwise false. principalId: allOf: - $ref: '#/components/schemas/PrincipalId' - description: The principal ID. policyDocuments: allOf: - $ref: '#/components/schemas/PolicyDocuments' - description: IAM policy documents. refreshAfterInSeconds: allOf: - $ref: '#/components/schemas/Seconds' - description: The number of seconds after which the temporary credentials are refreshed. disconnectAfterInSeconds: allOf: - $ref: '#/components/schemas/Seconds' - description: The number of seconds after which the connection is terminated. ResourceNotFoundException: {} MqttUsername: type: string pattern: '[\s\S]*' minLength: 1 maxLength: 65535 EnableCachingForHttp: type: boolean TagValue: type: string minLength: 0 maxLength: 256 securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/iot/ x-hasEquivalentPaths: true