openapi: 3.0.3 info: title: Authlete Authorization Endpoint Service Management API description: "Welcome to the **Authlete API documentation**. Authlete is an **API-first service** where every aspect of the \nplatform is configurable via API. This documentation will help you authenticate and integrate with Authlete to \nbuild powerful OAuth 2.0 and OpenID Connect servers.\n\nAt a high level, the Authlete API is grouped into two categories:\n\n- **Management APIs**: Enable you to manage services and clients.\n- **Runtime APIs**: Allow you to build your own Authorization Servers or Verifiable Credential (VC) issuers.\n\n## \U0001F310 API Servers\n\nAuthlete is a global service with clusters available in multiple regions across the world:\n\n- \U0001F1FA\U0001F1F8 **US**: `https://us.authlete.com`\n- \U0001F1EF\U0001F1F5 **Japan**: `https://jp.authlete.com`\n- \U0001F1EA\U0001F1FA **Europe**: `https://eu.authlete.com`\n- \U0001F1E7\U0001F1F7 **Brazil**: `https://br.authlete.com`\n\nOur customers can host their data in the region that best meets their requirements.\n\n## \U0001F511 Authentication\n\nAll API endpoints are secured using **Bearer token authentication**. You must include an access token in every request:\n\n```\nAuthorization: Bearer YOUR_ACCESS_TOKEN\n```\n\n### Getting Your Access Token\n\nAuthlete supports two types of access tokens:\n\n**Service Access Token** - Scoped to a single service (authorization server instance)\n\n1. Log in to [Authlete Console](https://console.authlete.com)\n2. Navigate to your service → **Settings** → **Access Tokens**\n3. Click **Create Token** and select permissions (e.g., `service.read`, `client.write`)\n4. Copy the generated token\n\n**Organization Token** - Scoped to your entire organization\n\n1. Log in to [Authlete Console](https://console.authlete.com)\n2. Navigate to **Organization Settings** → **Access Tokens**\n3. Click **Create Token** and select org-level permissions\n4. Copy the generated token\n\n> ⚠️ **Important Note**: Tokens inherit the permissions of the account that creates them. Service tokens can only \n> access their specific service, while organization tokens can access all services within your org.\n\n### Token Security Best Practices\n\n- **Never commit tokens to version control** - Store in environment variables or secure secret managers\n- **Rotate regularly** - Generate new tokens periodically and revoke old ones\n- **Scope appropriately** - Request only the permissions your application needs\n- **Revoke unused tokens** - Delete tokens you're no longer using from the console\n\n### Quick Test\n\nVerify your token works with a simple API call:\n\n```bash\ncurl -X GET https://us.authlete.com/api/service/get/list \\\n -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\"\n```\n\n## \U0001F393 Tutorials\n\nIf you're new to Authlete or want to see sample implementations, these resources will help you get started:\n\n- [Getting Started with Authlete](https://www.authlete.com/developers/getting_started/)\n- [From Sign-Up to the First API Request](https://www.authlete.com/developers/tutorial/signup/)\n\n## \U0001F6E0 Contact Us\n\nIf you have any questions or need assistance, our team is here to help:\n\n- [Contact Page](https://www.authlete.com/contact/)\n" version: 3.0.16 license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html servers: - description: 🇺🇸 US Cluster url: https://us.authlete.com - description: 🇯🇵 Japan Cluster url: https://jp.authlete.com - description: 🇪🇺 Europe Cluster url: https://eu.authlete.com - description: 🇧🇷 Brazil Cluster url: https://br.authlete.com security: - bearer: [] tags: - name: Service Management description: API endpoints for managing services, including creation, update, and deletion of services. x-tag-expanded: false paths: /api/{serviceId}/service/get: get: summary: Get Service description: 'Get a service. If the access token can only view or modify clients underneath this service, but does not have access to view this service directly, a limited view of the service will be returned. ' parameters: - in: path name: serviceId description: A service ID. schema: type: string required: true responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/service' examples: full: summary: Example showing the full service object. value: accessTokenDuration: 3600 accessTokenType: Bearer allowableClockSkew: 0 apiKey: 21653835348762 attributes: - key: attribute1-key value: attribute1-value - key: attribute2-key value: attribute2-value authorizationEndpoint: https://my-service.example.com/authz authorizationResponseDuration: 0 authorizationCodeDuration: 0 backchannelAuthReqIdDuration: 0 backchannelBindingMessageRequiredInFapi: false backchannelPollingInterval: 0 backchannelUserCodeParameterSupported: false claimShortcutRestrictive: false clientIdAliasEnabled: true clientsPerDeveloper: 0 createdAt: 1639373421000 dcrScopeUsedAsRequestable: false deviceFlowCodeDuration: 0 deviceFlowPollingInterval: 0 directAuthorizationEndpointEnabled: false directIntrospectionEndpointEnabled: false directJwksEndpointEnabled: false directRevocationEndpointEnabled: false directTokenEndpointEnabled: false directUserInfoEndpointEnabled: false dynamicRegistrationSupported: false errorDescriptionOmitted: false errorUriOmitted: false frontChannelRequestObjectEncryptionRequired: false grantManagementActionRequired: false hsmEnabled: false idTokenDuration: 0 introspectionEndpoint: https://my-service.example.com/introspection issSuppressed: false issuer: https://my-service.example.com metadata: - key: clientCount value: '1' missingClientIdAllowed: false modifiedAt: 1639373421000 mutualTlsValidatePkiCertChain: false nbfOptional: false number: 5041 parRequired: false pkceRequired: true pkceS256Required: false pushedAuthReqDuration: 0 refreshTokenDuration: 3600 refreshTokenDurationKept: false refreshTokenDurationReset: false refreshTokenKept: false requestObjectEncryptionAlgMatchRequired: false requestObjectEncryptionEncMatchRequired: false requestObjectRequired: false revocationEndpoint: https://my-service.example.com/revocation scopeRequired: false serviceName: My service serviceOwnerNumber: 2 singleAccessTokenPerSubject: false supportedClaimTypes: - NORMAL supportedDisplays: - PAGE supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN supportedIntrospectionAuthMethods: - CLIENT_SECRET_BASIC supportedResponseTypes: - CODE supportedRevocationAuthMethods: - CLIENT_SECRET_BASIC supportedScopes: - defaultEntry: false description: A permission to read your history. name: history.read - defaultEntry: false description: A permission to read your timeline. name: timeline.read supportedTokenAuthMethods: - CLIENT_SECRET_BASIC tlsClientCertificateBoundAccessTokens: false tokenEndpoint: https://my-service.example.com/token tokenExpirationLinked: false traditionalRequestObjectProcessingApplied: false unauthorizedOnClientConfigSupported: false userCodeLength: 0 limited: summary: Example showing the limited service object. value: apiKey: 21653835348762 description: This Service. number: 5041 serviceName: My service links: service_get_list: $ref: '#/components/links/service_get_list' service_update: $ref: '#/components/links/service_update' service_delete: $ref: '#/components/links/service_delete' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' operationId: service_get_api x-code-samples: - lang: shell label: curl source: 'curl -v https://us.authlete.com/api/21653835348762/service/get \ -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'' ' - lang: java label: java source: 'AuthleteConfiguration conf = ...; AuthleteApi api = AuthleteApiFactory.create(conf); long serviceId = ...; api.getService(serviceId); ' - lang: python source: 'conf = ... api = AuthleteApiImpl(conf) serviceId = ... api.getService(serviceId) ' tags: - Service Management /api/service/get/list: get: summary: List Services description: 'Get a list of services. If the access token can only view or modify clients underneath a service, but does not have access to view that service directly, a limited view of the service will be returned. Otherwise, all properties of the service are returned. If the access token is an administrative token, this returns a list of all services on the Authlete instance. Otherwise, all services that the access token can view, even in a limited fashion, are returned. ' parameters: - in: query name: start schema: type: integer format: int32 required: false description: Start index (inclusive) of the result set. The default value is 0. Must not be a negative number. - in: query name: end schema: type: integer format: int32 required: false description: End index (exclusive) of the result set. The default value is 5. Must not be a negative number. responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/service_get_list_response' examples: full: summary: Example showing the full service view. value: start: 0 end: 5 totalCount: 1 services: - accessTokenDuration: 3600 accessTokenType: Bearer allowableClockSkew: 0 apiKey: 21653835348762 apiSecret: uE4NgqeIpuSV_XejQ7Ds3jsgA1yXhjR1MXJ1LbPuyls attributes: - key: attribute1-key value: attribute1-value - key: attribute2-key value: attribute2-value authorizationEndpoint: https://as.example.com/authz authorizationResponseDuration: 0 authorizationCodeDuration: 0 backchannelAuthReqIdDuration: 0 backchannelBindingMessageRequiredInFapi: false backchannelPollingInterval: 0 backchannelUserCodeParameterSupported: false claimShortcutRestrictive: false clientIdAliasEnabled: true createdAt: 1639373421000 dcrScopeUsedAsRequestable: false deviceFlowCodeDuration: 0 deviceFlowPollingInterval: 0 directAuthorizationEndpointEnabled: false directIntrospectionEndpointEnabled: false directJwksEndpointEnabled: false directRevocationEndpointEnabled: false directTokenEndpointEnabled: false directUserInfoEndpointEnabled: false dynamicRegistrationSupported: false errorDescriptionOmitted: false errorUriOmitted: false frontChannelRequestObjectEncryptionRequired: false grantManagementActionRequired: false hsmEnabled: false idTokenDuration: 0 introspectionEndpoint: https://my-service.example.com/introspection issSuppressed: false issuer: https://my-service.example.com metadata: - key: clientCount value: '1' missingClientIdAllowed: false modifiedAt: 1639373421000 mutualTlsValidatePkiCertChain: false nbfOptional: false number: 5041 parRequired: false pkceRequired: true pkceS256Required: false pushedAuthReqDuration: 0 refreshTokenDuration: 3600 refreshTokenDurationKept: false refreshTokenDurationReset: false refreshTokenKept: false requestObjectEncryptionAlgMatchRequired: false requestObjectEncryptionEncMatchRequired: false requestObjectRequired: false revocationEndpoint: https://my-service.example.com/revocation scopeRequired: false serviceName: My service serviceOwnerNumber: 2 singleAccessTokenPerSubject: false supportedClaimTypes: - NORMAL supportedDisplays: - PAGE supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN supportedIntrospectionAuthMethods: - CLIENT_SECRET_BASIC supportedResponseTypes: - CODE supportedRevocationAuthMethods: - CLIENT_SECRET_BASIC supportedScopes: - defaultEntry: false description: A permission to read your history. name: history.read - defaultEntry: false description: A permission to read your timeline. name: timeline.read supportedTokenAuthMethods: - CLIENT_SECRET_BASIC tlsClientCertificateBoundAccessTokens: false tokenEndpoint: https://my-service.example.com/token tokenExpirationLinked: false traditionalRequestObjectProcessingApplied: false unauthorizedOnClientConfigSupported: false userCodeLength: 0 limited: summary: Example showing the limited service view. value: start: 0 end: 5 totalCount: 1 services: - apiKey: 21653835348762 clientIdAliasEnabled: true number: 5041 serviceName: My service links: service_create: $ref: '#/components/links/service_create' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' operationId: service_get_list_api x-code-samples: - lang: shell label: curl source: 'curl -v https://us.authlete.com/api/9503564192/service/get/list?start=0\&end=5 \ -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'' ' - lang: java label: java source: 'AuthleteConfiguration conf = ...; AuthleteApi api = AuthleteApiFactory.create(conf); int start = 0; int end = 5; api.getServiceList(start, end); ' - lang: python source: 'conf = ... api = AuthleteApiImpl(conf) start = 0 end = 5 api.getServiceList(start, end) ' tags: - Service Management /api/service/create: post: summary: Create Service description: 'Create a new service. ' requestBody: required: false content: application/json: schema: $ref: '#/components/schemas/service' example: serviceName: My service issuer: https://my-service.example.com clientIdAliasEnabled: true supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN supportedResponseTypes: - CODE authorizationEndpoint: https://my-service.example.com/authz pkceRequired: true tokenEndpoint: https://my-service.example.com/token supportedTokenAuthMethods: - CLIENT_SECRET_BASIC revocationEndpoint: https://my-service.example.com/revocation supportedRevocationAuthMethods: - CLIENT_SECRET_BASIC introspectionEndpoint: https://my-service.example.com/introspection supportedIntrospectionAuthMethods: - CLIENT_SECRET_BASIC accessTokenType: Bearer accessTokenDuration: 3600 refreshTokenDuration: 3600 supportedScopes: - name: timeline.read defaultEntry: false description: A permission to read your timeline. - name: history.read defaultEntry: false description: A permission to read your history. attributes: - key: attribute1-key value: attribute1-value - key: attribute2-key value: attribute2-value application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/service' responses: '200': description: Service created successfully (legacy compatibility) content: application/json: schema: $ref: '#/components/schemas/service' example: accessTokenDuration: 3600 '201': description: Service created successfully content: application/json: schema: $ref: '#/components/schemas/service' example: accessTokenDuration: 3600 accessTokenType: Bearer allowableClockSkew: 0 apiKey: 21653835348762 apiSecret: uE4NgqeIpuSV_XejQ7Ds3jsgA1yXhjR1MXJ1LbPuyls attributes: - key: attribute1-key value: attribute1-value - key: attribute2-key value: attribute2-value authorizationEndpoint: https://my-service.example.com/authz authorizationResponseDuration: 0 authorizationCodeDuration: 0 backchannelAuthReqIdDuration: 0 backchannelBindingMessageRequiredInFapi: false backchannelPollingInterval: 0 backchannelUserCodeParameterSupported: false claimShortcutRestrictive: false clientIdAliasEnabled: true clientsPerDeveloper: 0 createdAt: 1639373421000 dcrScopeUsedAsRequestable: false deviceFlowCodeDuration: 0 deviceFlowPollingInterval: 0 directAuthorizationEndpointEnabled: false directIntrospectionEndpointEnabled: false directJwksEndpointEnabled: false directRevocationEndpointEnabled: false directTokenEndpointEnabled: false directUserInfoEndpointEnabled: false dynamicRegistrationSupported: false errorDescriptionOmitted: false errorUriOmitted: false frontChannelRequestObjectEncryptionRequired: false grantManagementActionRequired: false hsmEnabled: false idTokenDuration: 0 introspectionEndpoint: https://my-service.example.com/introspection issSuppressed: false issuer: https://my-service.example.com metadata: - key: clientCount value: '0' missingClientIdAllowed: false modifiedAt: 1639373421000 mutualTlsValidatePkiCertChain: false nbfOptional: false number: 5041 parRequired: false pkceRequired: true pkceS256Required: false pushedAuthReqDuration: 0 refreshTokenDuration: 3600 refreshTokenDurationKept: false refreshTokenDurationReset: false refreshTokenKept: false requestObjectEncryptionAlgMatchRequired: false requestObjectEncryptionEncMatchRequired: false requestObjectRequired: false revocationEndpoint: https://my-service.example.com/revocation scopeRequired: false serviceName: My service serviceOwnerNumber: 2 singleAccessTokenPerSubject: false supportedClaimTypes: - NORMAL supportedDisplays: - PAGE supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN supportedIntrospectionAuthMethods: - CLIENT_SECRET_BASIC supportedResponseTypes: - CODE supportedRevocationAuthMethods: - CLIENT_SECRET_BASIC supportedScopes: - defaultEntry: false description: A permission to read your history. name: history.read - defaultEntry: false description: A permission to read your timeline. name: timeline.read supportedTokenAuthMethods: - CLIENT_SECRET_BASIC tlsClientCertificateBoundAccessTokens: false tokenEndpoint: https://my-service.example.com/token tokenExpirationLinked: false traditionalRequestObjectProcessingApplied: false unauthorizedOnClientConfigSupported: false userCodeLength: 0 '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' operationId: service_create_api x-code-samples: - lang: shell label: curl source: 'curl -v -X POST https://us.authlete.com/api/service/create \ -H ''Content-Type:application/json'' \ -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'' \ -d ''{ "serviceName": "My Service", ... }'' ' - lang: java label: java source: 'AuthleteConfiguration conf = ...; AuthleteApi api = AuthleteApiFactory.create(conf); Service service = new Service(); service.setServiceName("My Service"); ... api.createService(service); ' - lang: python source: 'conf = ... api = AuthleteApiImpl(conf) service = Service() service.serviceName = ''My Service'' ... api.createService(service) ' tags: - Service Management /api/{serviceId}/service/update: post: summary: Update Service description: 'Update a service. ' parameters: - in: path name: serviceId description: A service ID. schema: type: string required: true requestBody: required: false content: application/json: schema: $ref: '#/components/schemas/service' example: accessTokenDuration: 3600 accessTokenType: Bearer allowableClockSkew: 0 attributes: - key: attribute1-key value: attribute1-value - key: attribute2-key value: attribute2-value authorizationEndpoint: https://my-service.example.com/authz authorizationResponseDuration: 0 authorizationCodeDuration: 0 backchannelAuthReqIdDuration: 0 backchannelBindingMessageRequiredInFapi: false backchannelPollingInterval: 0 backchannelUserCodeParameterSupported: false claimShortcutRestrictive: false clientIdAliasEnabled: true clientsPerDeveloper: 0 dcrScopeUsedAsRequestable: false deviceFlowCodeDuration: 0 deviceFlowPollingInterval: 0 directAuthorizationEndpointEnabled: false directIntrospectionEndpointEnabled: false directJwksEndpointEnabled: false directRevocationEndpointEnabled: false directTokenEndpointEnabled: false directUserInfoEndpointEnabled: false dynamicRegistrationSupported: false errorDescriptionOmitted: false errorUriOmitted: false frontChannelRequestObjectEncryptionRequired: false grantManagementActionRequired: false hsmEnabled: false idTokenDuration: 0 introspectionEndpoint: https://my-service.example.com/introspection issSuppressed: false issuer: https://my-service.example.com missingClientIdAllowed: false mutualTlsValidatePkiCertChain: false nbfOptional: false parRequired: false pkceRequired: true pkceS256Required: false pushedAuthReqDuration: 0 refreshTokenDuration: 3600 refreshTokenDurationKept: false refreshTokenDurationReset: false refreshTokenKept: false requestObjectEncryptionAlgMatchRequired: false requestObjectEncryptionEncMatchRequired: false requestObjectRequired: false revocationEndpoint: https://my-service.example.com/revocation scopeRequired: false serviceName: My updated service singleAccessTokenPerSubject: false supportedClaimTypes: - NORMAL supportedDisplays: - PAGE supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN supportedIntrospectionAuthMethods: - CLIENT_SECRET_BASIC supportedResponseTypes: - CODE supportedRevocationAuthMethods: - CLIENT_SECRET_BASIC supportedScopes: - defaultEntry: false description: A permission to read your history. name: history.read - defaultEntry: false description: A permission to read your timeline. name: timeline.read supportedTokenAuthMethods: - CLIENT_SECRET_BASIC tlsClientCertificateBoundAccessTokens: false tokenEndpoint: https://my-service.example.com/token tokenExpirationLinked: false traditionalRequestObjectProcessingApplied: false unauthorizedOnClientConfigSupported: false userCodeLength: 0 application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/service' responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/service' example: accessTokenDuration: 3600 accessTokenType: Bearer allowableClockSkew: 0 apiKey: 21653835348762 apiSecret: uE4NgqeIpuSV_XejQ7Ds3jsgA1yXhjR1MXJ1LbPuyls attributes: - key: attribute1-key value: attribute1-value - key: attribute2-key value: attribute2-value authorizationEndpoint: https://my-service.example.com/authz authorizationResponseDuration: 0 authorizationCodeDuration: 0 backchannelAuthReqIdDuration: 0 backchannelBindingMessageRequiredInFapi: false backchannelPollingInterval: 0 backchannelUserCodeParameterSupported: false claimShortcutRestrictive: false clientIdAliasEnabled: true clientsPerDeveloper: 0 createdAt: 1639373421000 dcrScopeUsedAsRequestable: false deviceFlowCodeDuration: 0 deviceFlowPollingInterval: 0 directAuthorizationEndpointEnabled: false directIntrospectionEndpointEnabled: false directJwksEndpointEnabled: false directRevocationEndpointEnabled: false directTokenEndpointEnabled: false directUserInfoEndpointEnabled: false dynamicRegistrationSupported: false errorDescriptionOmitted: false errorUriOmitted: false frontChannelRequestObjectEncryptionRequired: false grantManagementActionRequired: false hsmEnabled: false idTokenDuration: 0 introspectionEndpoint: https://my-service.example.com/introspection issSuppressed: false issuer: https://my-service.example.com metadata: - key: clientCount value: '1' missingClientIdAllowed: false modifiedAt: 1639373420725 mutualTlsValidatePkiCertChain: false nbfOptional: false number: 5041 parRequired: false pkceRequired: true pkceS256Required: false pushedAuthReqDuration: 0 refreshTokenDuration: 3600 refreshTokenDurationKept: false refreshTokenDurationReset: false refreshTokenKept: false requestObjectEncryptionAlgMatchRequired: false requestObjectEncryptionEncMatchRequired: false requestObjectRequired: false revocationEndpoint: https://my-service.example.com/revocation scopeRequired: false serviceName: My updated service serviceOwnerNumber: 2 singleAccessTokenPerSubject: false supportedClaimTypes: - NORMAL supportedDisplays: - PAGE supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN supportedIntrospectionAuthMethods: - CLIENT_SECRET_BASIC supportedResponseTypes: - CODE supportedRevocationAuthMethods: - CLIENT_SECRET_BASIC supportedScopes: - defaultEntry: false description: A permission to read your history. name: history.read - defaultEntry: false description: A permission to read your timeline. name: timeline.read supportedTokenAuthMethods: - CLIENT_SECRET_BASIC tlsClientCertificateBoundAccessTokens: false tokenEndpoint: https://my-service.example.com/token tokenExpirationLinked: false traditionalRequestObjectProcessingApplied: false unauthorizedOnClientConfigSupported: false userCodeLength: 0 '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' operationId: service_update_api x-code-samples: - lang: shell label: curl source: 'curl -v -X POST https://us.authlete.com/api/21653835348762/service/update \ -H ''Content-Type:application/json'' \ -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'' \ -d ''{ "serviceName": "My updated service", ... }'' ' - lang: java label: java source: 'AuthleteConfiguration conf = ...; AuthleteApi api = AuthleteApiFactory.create(conf); // Get an existing service. long serviceId = ...; Service service = api.getService(serviceId); // Update "service name". service.setAServiceName("My updated service"); api.updateService(service); ' - lang: python source: 'conf = ... api = AuthleteApiImpl(conf) # Get an existing service. serviceId = ... service = api.getService(serviceId) # Update "service name". service.serviceName = ''My updated service'' api.updateService(service) ' tags: - Service Management /api/{serviceId}/service/delete: delete: summary: Delete Service ⚡ description: 'Delete a service. ' parameters: - in: path name: serviceId description: A service ID. schema: type: string required: true responses: '204': description: The service was successfully deleted. '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' operationId: service_delete_api x-code-samples: - lang: shell label: curl source: 'curl -v -X DELETE https://us.authlete.com/api/9503564192/service/delete/21653835348762 \ -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'' ' - lang: java label: java source: 'AuthleteConfiguration conf = ...; AuthleteApi api = AuthleteApiFactory.create(conf); long serviceId = ...; api.deleteService(serviceId); ' - lang: python source: 'conf = ... api = AuthleteApiImpl(conf) serviceId = ... api.deleteService(serviceId) ' tags: - Service Management /api/{serviceId}/service/configuration: get: summary: Get Service Configuration description: 'This API gathers configuration information about a service. This API is supposed to be called from within the implementation of the configuration endpoint of the service where the service that supports OpenID Connect and [OpenID Connect Discovery 1.0](https://openid.net/specs/openid-connect-discovery-1_0.html) must expose its configuration information in a JSON format. Details about the format are described in "[3. OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)" in OpenID Connect Discovery 1.0. ' parameters: - in: path name: serviceId description: A service ID. required: true schema: type: string - in: query name: pretty schema: type: boolean required: false description: This boolean value indicates whether the JSON in the response should be formatted or not. If `true`, the JSON in the response is pretty-formatted. The default value is `false`. - in: query name: patch schema: type: string required: false description: Get the JSON Patch [RFC 6902 JavaScript Object Notation (JSON) Patch](https://www.rfc-editor.org/rfc/rfc6902) to be applied. responses: '200': description: Service configuration retrieved successfully content: application/json: schema: type: object additionalProperties: true description: 'An object representing OpenID Provider configuration information. See [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata) and [OpenID Provider Configuration Response](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfigurationResponse) for more details. ' example: issuer: https://my-service.example.com authorization_endpoint: https://my-service.example.com/authz token_endpoint: https://my-service.example.com/token scopes_supported: - history.read - timeline.read response_types_supported: - code response_modes_supported: - query - fragment - form_post - query.jwt - fragment.jwt - form_post.jwt - jwt grant_types_supported: - authorization_code - password - refresh_token subject_types_supported: - public - pairwise id_token_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA id_token_encryption_alg_values_supported: - RSA1_5 - RSA-OAEP - RSA-OEAP-256 - ECDH-ES - ECDH-ES+A128KW - ECDH-ES+A192KW - ECDH-ES+A256KW - A128KW - A192KW - A256KW - dir - A128GCMKW - A192GCMKW - A256GCMKW - PBES2-HS256+A128KW - PBES2-HS384+A192KW - PBES2-HS512+A256KW id_token_encryption_enc_values_supported: - A128CBC-HS256 - A192CBC-HS384 - A256CBC-HS512 - A128GCM - A192GCM - A256GCM userinfo_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA - none userinfo_encryption_alg_values_supported: - RSA1_5 - RSA-OAEP - RSA-OEAP-256 - ECDH-ES - ECDH-ES+A128KW - ECDH-ES+A192KW - ECDH-ES+A256KW - A128KW - A192KW - A256KW - dir - A128GCMKW - A192GCMKW - A256GCMKW - PBES2-HS256+A128KW - PBES2-HS384+A192KW - PBES2-HS512+A256KW userinfo_encryption_enc_values_supported: - A128CBC-HS256 - A192CBC-HS384 - A256CBC-HS512 - A128GCM - A192GCM - A256GCM request_object_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA request_object_encryption_alg_values_supported: - RSA1_5 - RSA-OAEP - RSA-OEAP-256 - ECDH-ES - ECDH-ES+A128KW - ECDH-ES+A192KW - ECDH-ES+A256KW - A128KW - A192KW - A256KW - dir - A128GCMKW - A192GCMKW - A256GCMKW - PBES2-HS256+A128KW - PBES2-HS384+A192KW - PBES2-HS512+A256KW request_object_encryption_enc_values_supported: - A128CBC-HS256 - A192CBC-HS384 - A256CBC-HS512 - A128GCM - A192GCM - A256GCM authorization_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA authorization_encryption_alg_values_supported: - RSA1_5 - RSA-OAEP - RSA-OEAP-256 - ECDH-ES - ECDH-ES+A128KW - ECDH-ES+A192KW - ECDH-ES+A256KW - A128KW - A192KW - A256KW - dir - A128GCMKW - A192GCMKW - A256GCMKW - PBES2-HS256+A128KW - PBES2-HS384+A192KW - PBES2-HS512+A256KW authorization_encryption_enc_values_supported: - A128CBC-HS256 - A192CBC-HS384 - A256CBC-HS512 - A128GCM - A192GCM - A256GCM token_endpoint_auth_methods_supported: - client_secret_basic token_endpoint_auth_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA display_values_supported: - page claim_types_supported: - normal claims_parameter_supported: true request_parameter_supported: true request_uri_parameter_supported: true require_request_uri_registration: true revocation_endpoint: https://my-service.example.com/revocation revocation_endpoint_auth_methods_supported: [] revocation_endpoint_auth_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA introspection_endpoint: https://my-service.example.com/introspection introspection_endpoint_auth_methods_supported: [] introspection_endpoint_auth_signing_alg_values_supported: - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA code_challenge_methods_supported: - plain - S256 tls_client_certificate_bound_access_tokens: false backchannel_token_delivery_modes_supported: [] backchannel_authentication_request_signing_alg_values_supported: - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA backchannel_user_code_parameter_supported: false require_pushed_authorization_requests: false authorization_details_supported: true verified_claims_supported: false dpop_signing_alg_values_supported: - RS256 - RS384 - RS512 - PS256 - PS384 - PS512 - ES256 - ES384 - ES512 - ES256K - EdDSA require_signed_request_object: false authorization_response_iss_parameter_supported: true '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' operationId: service_configuration_api x-code-samples: - lang: shell label: curl source: 'curl -v https://us.authlete.com/api/21653835348762/service/configuration?pretty=true \ -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'' ' - lang: java label: java source: 'AuthleteConfiguration conf = ...; AuthleteApi api = AuthleteApiFactory.create(conf); api.getServiceConfiguration(true); ' - lang: python source: 'conf = ... api = AuthleteApiImpl(conf) api.getServiceConfiguration(True) ' tags: - Service Management components: schemas: grant_type: type: string description: 'The grant type of the access token when the access token was created. ' enum: - AUTHORIZATION_CODE - IMPLICIT - PASSWORD - CLIENT_CREDENTIALS - REFRESH_TOKEN - CIBA - DEVICE_CODE - TOKEN_EXCHANGE - JWT_BEARER - PRE_AUTHORIZED_CODE client_registration_type: type: string description: "Values for the `client_registration_types` RP metadata and the\n `client_registration_types_supported` OP metadata that are defined in\n [OpenID Connect Federation 1.0](https://openid.net/specs/openid-connect-federation-1_0.html).\n" enum: - AUTOMATIC - EXPLICIT credential_issuer_metadata: type: object properties: authorizationServers: type: array items: type: string description: 'The identifiers of the authorization servers that the credential issuer relies on for authorization. This property corresponds to the authorization_servers metadata. When the credential issuer works as an authorization server for itself, this property should be omitted. ' credentialIssuer: type: string description: The identifier of a credential request. credentialEndpoint: type: string format: uri description: The URL of the credential endpoint of the credential issuer. batchCredentialEndpoint: type: string format: uri description: The URL of the batch credential endpoint of the credential issuer. deferredCredentialEndpoint: type: string description: The URL of the deferred credential endpoint of the credential issuer. credentialsSupported: type: string description: 'A JSON object describing supported credential configurations. This property corresponds to the credential_configurations_supported metadata. Note: Due to a breaking change in December 2023, this was changed from a JSON array to a JSON object. ' credentialResponseEncryptionAlgValuesSupported: type: array items: type: string description: 'The supported JWE `alg` algorithms for credential response encryption. This property corresponds to the `credential_response_encryption.alg_values_supported` metadata. ' credentialResponseEncryptionEncValuesSupported: type: array items: type: string description: 'The supported JWE `enc` algorithms for credential response encryption. This property corresponds to the `credential_response_encryption.enc_values_supported` metadata. ' requireCredentialResponseEncryption: type: boolean description: 'The boolean flag indicating whether credential response encryption is required. This property corresponds to the `credential_response_encryption.encryption_required metadata`. If this flag is `true`, every credential request to the credential issuer must include the `credential_response_encryption` property. ' response_type: type: string enum: - NONE - CODE - TOKEN - ID_TOKEN - CODE_TOKEN - CODE_ID_TOKEN - ID_TOKEN_TOKEN - CODE_ID_TOKEN_TOKEN tagged_value: type: object properties: tag: type: string description: The language tag part. value: type: string description: The value part. hsk: type: object description: 'Holds information about a key managed in an HSM (Hardware Security Module) ' properties: kty: type: string description: 'The key type (EC or RSA) ' use: type: string description: 'Get the use of the key on the HSM. When the key use is "sig" (signature), the private key on the HSM is used to sign data and the corresponding public key is used to verify the signature. When the key use is "enc" (encryption), the private key on the HSM is used to decrypt encrypted data which have been encrypted with the corresponding public key ' kid: type: string description: 'Key ID for the key on the HSM. ' hsmName: type: string description: 'The name of the HSM. The identifier for the HSM that sits behind the Authlete server. For example, "google". ' handle: type: string description: 'The handle for the key on the HSM. A handle is a base64url-encoded 256-bit random value (43 letters) which is assigned by Authlete on the call of the /api/hsk/create API ' publicKey: type: string description: 'The public key that corresponds to the key on the HSM. ' alg: type: string description: 'The algorithm of the key on the HSM. When the key use is `"sig"`, the algorithm represents a signing algorithm such as `"ES256"`. When the key use is `"enc"`, the algorithm represents an encryption algorithm such as `"RSA-OAEP-256"`. ' display: type: string description: 'The display mode which the client application requests by `display` request parameter. When the authorization request does not have `display` request parameter, `PAGE` is set as the default value. It is ensured that the value of `display` is one of the supported display modes which are specified by `supportedDisplays` configuration parameter of the service. If the display mode specified by the authorization request is not supported, an error is raised. Values for this property correspond to the values listed in "[OpenID Connect Core 1.0, 3.1.2.1. Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest), display". ' enum: - PAGE - POPUP - TOUCH - WAP jws_alg: type: string nullable: true description: "The signature algorithm for JWT. This value is represented on 'alg' attribute\nof the header of JWT.\n\nit's semantics depends upon where is this defined, for instance:\n - as service accessTokenSignAlg value, it defines that access token are JWT and the algorithm used to sign it. Check your [KB article](https://kb.authlete.com/en/s/oauth-and-openid-connect/a/jwt-based-access-token).\n - as client authorizationSignAlg value, it represents the signature algorithm used when [creating a JARM response](https://kb.authlete.com/en/s/oauth-and-openid-connect/a/enabling-jarm).\n - or as client requestSignAlg value, it specifies which is the expected signature used by [client on a Request Object](https://kb.authlete.com/en/s/oauth-and-openid-connect/a/request-objects).\n" enum: - NONE - HS256 - HS384 - HS512 - RS256 - RS384 - RS512 - ES256 - ES384 - ES512 - PS256 - PS384 - PS512 - ES256K - EdDSA sns_credentials: type: object properties: sns: type: string description: SNS. apiKey: type: string description: API key. apiSecret: type: string description: API secret. attachment_type: type: string description: "Supported attachment types. This property corresponds to the `attachments_supported`\n server metadata which was added by the third implementer's draft of OpenID Connect\n for Identity Assurance 1.0.\n" enum: - EMBEDDED - EXTERNAL service_get_list_response: type: object properties: start: type: integer format: int32 description: 'Start index (inclusive) of the result set. The default value is 0. Must not be a negative number. ' end: type: integer format: int32 description: 'Start index (inclusive) of the result set. The default value is 0. Must not be a negative number. ' totalCount: type: integer format: int32 description: 'Total number of services owned by the service owner. This doesn''t mean the number of services contained in the response. ' services: type: array items: $ref: '#/components/schemas/service' description: 'An array of services. ' trust_anchor: type: object properties: entityId: type: string description: 'the entity ID of the trust anchor ' jwks: type: string description: 'the JWK Set document containing public keys of the trust anchor ' fapi_mode: type: string enum: - FAPI1_ADVANCED - FAPI1_BASELINE - FAPI2_MESSAGE_SIGNING_AUTH_REQ - FAPI2_MESSAGE_SIGNING_AUTH_RES - FAPI2_MESSAGE_SIGNING_INTROSPECTION_RES - FAPI2_SECURITY prompt: type: string description: 'The prompt that the UI displayed to the end-user must satisfy as the minimum level. This value comes from `prompt` request parameter. When the authorization request does not contain `prompt` request parameter, `CONSENT` is used as the default value. See "[OpenID Connect Core 1.0, 3.1.2.1. Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest), prompt" for `prompt` request parameter. ' enum: - NONE - LOGIN - CONSENT - SELECT_ACCOUNT - CREATE claim_type: type: string enum: - NORMAL - AGGREGATED - DISTRIBUTED service: type: object example: number: 715948317 serviceName: My Test Service issuer: https://example.com supportedScopes: - profile - email - openid supportedResponseTypes: - CODE supportedGrantTypes: - AUTHORIZATION_CODE - REFRESH_TOKEN properties: number: type: integer format: int32 readOnly: true description: The sequential number of the service. The value of this property is assigned by Authlete. serviceName: type: string description: The name of this service. issuer: type: string description: 'The issuer identifier of the service. A URL that starts with https:// and has no query or fragment component. The value of this property is used as `iss` claim in an [ID token](https://openid.net/specs/openid-connect-core-1_0.html#IDToken) and `issuer` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' description: type: string description: The description about the service. apiKey: type: integer format: int64 readOnly: true description: The service ID used in Authlete API calls. The value of this property is assigned by Authlete. apiSecret: type: string readOnly: true description: "The API secret of this service. This value is assigned by Authlete and \nis used for service authentication in API calls.\n" tokenBatchNotificationEndpoint: type: string format: uri description: "The endpoint for batch token notifications. This endpoint is called when \nmultiple tokens are issued or revoked in a batch operation.\n" clientAssertionAudRestrictedToIssuer: type: boolean description: "The flag indicating whether the audience of client assertion JWTs must \nmatch the issuer identifier of this service.\n" serviceOwnerNumber: type: integer format: int32 readOnly: true description: "The number of the organization that owns this service. This value is \nassigned by Authlete.\n" clientsPerDeveloper: type: integer format: int32 description: 'The maximum number of client applications that a developer can have. ' developerAuthenticationCallbackEndpoint: type: string format: uri description: "The endpoint for developer authentication callbacks. This is used when \ndevelopers log into the developer portal.\n" developerAuthenticationCallbackApiKey: type: string description: "The API key for basic authentication at the developer authentication \ncallback endpoint.\n" developerAuthenticationCallbackApiSecret: type: string description: "The API secret for basic authentication at the developer authentication \ncallback endpoint.\n" supportedSnses: type: array items: type: string enum: - FACEBOOK description: "Social login services (SNS) that this service supports for end-user \nauthentication.\n" snsCredentials: type: array items: $ref: '#/components/schemas/sns_credentials' description: "The credentials for social login services (SNS) that are used for \nend-user authentication.\n" clientIdAliasEnabled: type: boolean description: Deprecated. Always `true`. metadata: type: array items: $ref: '#/components/schemas/pair' description: "The `metadata` of the service. The content of the returned array depends on contexts.\nThe predefined service metadata is listed in the following table.\n\n | Key | Description |\n | --- | --- |\n | `clientCount` | The number of client applications which belong to this service. |\n" createdAt: type: integer format: int64 readOnly: true description: 'The time at which this service was created. The value is represented as milliseconds since the UNIX epoch (`1970-01-01`). ' modifiedAt: type: integer format: int64 readOnly: true description: 'The time at which this service was last modified. The value is represented as milliseconds since the UNIX epoch (1970-01-01). ' authenticationCallbackEndpoint: type: string format: uri description: 'A Web API endpoint for user authentication which is to be prepared on the service side. The endpoint must be implemented if you do not implement the UI at the authorization endpoint but use the one provided by Authlete. The user authentication at the authorization endpoint provided by Authlete is performed by making a `POST` request to this endpoint. ' authenticationCallbackApiKey: type: string description: 'API key for basic authentication at the authentication callback endpoint. If the value is not empty, Authlete generates Authorization header for Basic authentication when making a request to the authentication callback endpoint. ' authenticationCallbackApiSecret: type: string description: API secret for `basic` authentication at the authentication callback endpoint. supportedAcrs: readOnly: true type: array items: type: string description: 'Values of acrs (authentication context class references) that the service supports. The value of this property is used as `acr_values_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' supportedGrantTypes: type: array items: $ref: '#/components/schemas/grant_type' description: 'Values of `grant_type` request parameter that the service supports. The value of this property is used as `grant_types_supported property` in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' supportedResponseTypes: type: array items: $ref: '#/components/schemas/response_type' description: 'Values of `response_type` request parameter that the service supports. Valid values are listed in Response Type. The value of this property is used as `response_types_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' supportedAuthorizationDetailsTypes: type: array items: type: string description: 'The supported data types that can be used as values of the type field in `authorization_details`. This property corresponds to the `authorization_details_types_supported` metadata. See "OAuth 2.0 Rich Authorization Requests" (RAR) for details. ' supportedServiceProfiles: type: array items: $ref: '#/components/schemas/service_profile' description: 'The profiles that this service supports. ' errorDescriptionOmitted: type: boolean description: 'The flag to indicate whether the `error_description` response parameter is omitted. According to [RFC 6749](https://tools.ietf.org/html/rfc6749), an authorization server may include the `error_description` response parameter in error responses. If `true`, Authlete does not embed the `error_description` response parameter in error responses. ' errorUriOmitted: type: boolean description: 'The flag to indicate whether the `error_uri` response parameter is omitted. According to [RFC 6749](https://tools.ietf.org/html/rfc6749), an authorization server may include the `error_uri` response parameter in error responses. If `true`, Authlete does not embed the `error_uri` response parameter in error responses. ' authorizationEndpoint: type: string format: uri description: 'The authorization endpoint of the service. A URL that starts with `https://` and has no fragment component. For example, `https://example.com/auth/authorization`. The value of this property is used as `authorization_endpoint` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' directAuthorizationEndpointEnabled: type: boolean description: 'The flag to indicate whether the direct authorization endpoint is enabled or not. The path of the endpoint is `/api/auth/authorization/direct/service-api-key`. ' supportedUiLocales: type: array items: type: string description: 'UI locales that the service supports. Each element is a language tag defined in [RFC 5646](https://tools.ietf.org/html/rfc5646). For example, `en-US` and `ja-JP`. The value of this property is used as `ui_locales_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' supportedDisplays: type: array items: $ref: '#/components/schemas/display' description: 'Values of `display` request parameter that service supports. The value of this property is used as `display_values_supported` property in the Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' pkceRequired: type: boolean description: 'The flag to indicate whether the use of Proof Key for Code Exchange (PKCE) is always required for authorization requests by Authorization Code Flow. If `true`, `code_challenge` request parameter is always required for authorization requests using Authorization Code Flow. See [RFC 7636](https://tools.ietf.org/html/rfc7636) (Proof Key for Code Exchange by OAuth Public Clients) for details about `code_challenge` request parameter. ' pkceS256Required: type: boolean description: 'The flag to indicate whether `S256` is always required as the code challenge method whenever [PKCE (RFC 7636)](https://tools.ietf.org/html/rfc7636) is used. If this flag is set to `true`, `code_challenge_method=S256` must be included in the authorization request whenever it includes the `code_challenge` request parameter. Neither omission of the `code_challenge_method` request parameter nor use of plain (`code_challenge_method=plain`) is allowed. ' authorizationResponseDuration: type: integer format: int64 description: 'The duration of authorization response JWTs in seconds. [Financial-grade API: JWT Secured Authorization Response Mode for OAuth 2.0 (JARM)](https://openid.net/specs/openid-financial-api-jarm.html) defines new values for the `response_mode` request parameter. They are `query.jwt`, `fragment.jwt`, `form_post.jwt` and `jwt`. If one of them is specified as the response mode, response parameters from the authorization endpoint will be packed into a JWT. This property is used to compute the value of the `exp` claim of the JWT. ' authorizationCodeDuration: type: integer format: int64 description: 'The duration of authorization codes in seconds. ' tokenEndpoint: type: string format: uri description: 'The [token endpoint](https://tools.ietf.org/html/rfc6749#section-3.2) of the service. A URL that starts with `https://` and has not fragment component. For example, `https://example.com/auth/token`. The value of this property is used as `token_endpoint` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' directTokenEndpointEnabled: type: boolean description: 'The flag to indicate whether the direct token endpoint is enabled or not. The path of the endpoint is `/api/auth/token/direct/service-api-key`. ' supportedTokenAuthMethods: type: array items: $ref: '#/components/schemas/client_auth_method' description: 'Client authentication methods supported by the token endpoint of the service. The value of this property is used as `token_endpoint_auth_methods_supports` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' missingClientIdAllowed: type: boolean description: 'The flag to indicate token requests from public clients without the `client_id` request parameter are allowed when the client can be guessed from `authorization_code` or `refresh_token`. This flag should not be set unless you have special reasons. ' revocationEndpoint: type: string format: uri description: 'The [revocation endpoint](https://tools.ietf.org/html/rfc7009) of the service. A URL that starts with `https://`. For example, `https://example.com/auth/revocation`. ' directRevocationEndpointEnabled: type: boolean description: 'The flag to indicate whether the direct revocation endpoint is enabled or not. The URL of the endpoint is `/api/auth/revocation/direct/service-api-key`. ' supportedRevocationAuthMethods: type: array items: $ref: '#/components/schemas/client_auth_method' description: 'Client authentication methods supported at the revocation endpoint. ' introspectionEndpoint: type: string description: The URI of the introspection endpoint. format: uri directIntrospectionEndpointEnabled: type: boolean description: 'The flag to indicate whether the direct userinfo endpoint is enabled or not. The path of the endpoint is `/api/auth/userinfo/direct/{serviceApiKey}`. ' supportedIntrospectionAuthMethods: type: array description: 'Client authentication methods supported at the introspection endpoint. ' items: $ref: '#/components/schemas/client_auth_method' pushedAuthReqEndpoint: type: string description: 'The URI of the pushed authorization request endpoint. This property corresponds to the `pushed_authorization_request_endpoint` metadata defined in "[5. Authorization Server Metadata](https://tools.ietf.org/html/draft-lodderstedt-oauth-par#section-5)" of OAuth 2.0 Pushed Authorization Requests. ' format: uri pushedAuthReqDuration: type: integer format: int64 description: 'The duration of pushed authorization requests in seconds. ' x-mint: metadata: description: The duration of pushed authorization requests in seconds. content: ' [OAuth 2.0 Pushed Authorization Requests](https://tools.ietf.org/html/draft-lodderstedt-oauth-par) defines an endpoint (called "pushed authorization request endpoint") which client applications can register authorization requests into and get corresponding URIs (called "request URIs") from. The issued URIs represent the registered authorization requests. The client applications can use the URIs as the value of the `request_uri` request parameter in an authorization request. The property represents the duration of registered authorization requests and is used as the value of the `expires_in` parameter in responses from the pushed authorization request endpoint. ' parRequired: type: boolean description: 'The flag to indicate whether this service requires that clients use the pushed authorization request endpoint. This property corresponds to the `require_pushed_authorization_requests` server metadata defined in [OAuth 2.0 Pushed Authorization Requests](https://tools.ietf.org/html/draft-lodderstedt-oauth-par). ' requestObjectRequired: type: boolean description: 'The flag to indicate whether this service requires that authorization requests always utilize a request object by using either request or `request_uri` request parameter. If this flag is set to `true` and the value of `traditionalRequestObjectProcessingApplied` is `false`, the value of `require_signed_request_object` server metadata of this service is reported as `true` in the discovery document. The metadata is defined in JAR (JWT Secured Authorization Request). That `require_signed_request_object` is `true` means that authorization requests which don''t conform to the JAR specification are rejected. ' traditionalRequestObjectProcessingApplied: type: boolean description: 'The flag to indicate whether a request object is processed based on rules defined in [OpenID Connect Core 1.0](https://openid.net/specs/openid-connect-core-1_0.html) or JAR (JWT Secured Authorization Request). ' x-mint: metadata: description: The flag to indicate whether a request object is processed based on rules defined in [OpenID Connect Core 1.0](https://openid.net/specs/openid-connect-core-1_0.html) or JAR (JWT Secured Authorization Request). content: "\nDifferences between rules in OpenID Connect Core 1.0 and ones in JAR are as follows.\n - JAR requires that a request object be always -signed.\n - JAR does not allow request parameters outside a request object to be referred to.\n - OIDC Core 1.0 requires that response_type request parameter exist outside a request object even if the request object includes the request parameter.\n - OIDC Core 1.0 requires that scope request parameter exist outside a request object if the authorization request is an\n - OIDC request even if the request object includes the request parameter.\n\nIf this flag is set to `false` and the value of `requestObjectRequired` is `true`, the value of\n`require_signed_request_object` server metadata of this service\nis reported as `true` in the discovery document. The metadata is defined in JAR (JWT Secured\nAuthorization Request). That `require_signed_request_object` is `true` means that authorization\nrequests which don't conform to the JAR specification are rejected.\n\n" mutualTlsValidatePkiCertChain: type: boolean description: 'The flag to indicate whether this service validates certificate chains during PKI-based client mutual TLS authentication. ' trustedRootCertificates: type: array items: type: string description: 'The list of root certificates trusted by this service for PKI-based client mutual TLS authentication. ' mtlsEndpointAliases: type: array items: $ref: '#/components/schemas/named_uri' description: 'The MTLS endpoint aliases. ' x-mint: metadata: description: The MTLS endpoint aliases. content: "\nThis property corresponds to the mtls_endpoint_aliases metadata defined in \"5. Metadata for Mutual TLS Endpoint Aliases\" of [OAuth 2.0 Mutual TLS Client Authentication and Certificate-Bound Access Tokens](https://datatracker.ietf.org/doc/rfc8705/).\n\nThe aliases will be embedded in the response from the discovery endpoint like the following.\n\n```json\n{\n ......,\n \"mtls_endpoint_aliases\": {\n \"token_endpoint\": \"https://mtls.example.com/token\",\n \"revocation_endpoint\": \"https://mtls.example.com/revo\",\n \"introspection_endpoint\": \"https://mtls.example.com/introspect\"\n }\n}\n```\n\n" accessTokenType: type: string description: 'The access token type. This value is used as the value of `token_type` property in access token responses. If this service complies with [RFC 6750](https://tools.ietf.org/html/rfc6750), the value of this property should be `Bearer`. See [RFC 6749 (OAuth 2.0), 7.1. Access Token Types](https://tools.ietf.org/html/rfc6749#section-7.1) for details. ' tlsClientCertificateBoundAccessTokens: type: boolean description: 'The flag to indicate whether this service supports issuing TLS client certificate bound access tokens. ' accessTokenDuration: type: integer format: int64 description: 'The duration of access tokens in seconds. This value is used as the value of `expires_in` property in access token responses. `expires_in` is defined [RFC 6749, 5.1. Successful Response](https://tools.ietf.org/html/rfc6749#section-5.1). ' singleAccessTokenPerSubject: type: boolean description: 'The flag to indicate whether the number of access tokens per subject (and per client) is at most one or can be more. If `true`, an attempt to issue a new access token invalidates existing access tokens that are associated with the same subject and the same client. Note that, however, attempts by [Client Credentials Flow](https://tools.ietf.org/html/rfc6749#section-4.4) do not invalidate existing access tokens because access tokens issued by Client Credentials Flow are not associated with any end-user''s subject. Also note that an attempt by [Refresh Token Flow](https://tools.ietf.org/html/rfc6749#section-6) invalidates the coupled access token only and this invalidation is always performed regardless of whether the value of this setting item is `true` or `false`. ' accessTokenSignAlg: $ref: '#/components/schemas/jws_alg' accessTokenSignatureKeyId: type: string description: 'The key ID to identify a JWK used for signing access tokens. A JWK Set can be registered as a property of a service. A JWK Set can contain 0 or more JWKs. Authlete Server has to pick up one JWK for signing from the JWK Set when it generates a JWT-based access token. Authlete Server searches the registered JWK Set for a JWK which satisfies conditions for access token signature. If the number of JWK candidates which satisfy the conditions is 1, there is no problem. On the other hand, if there exist multiple candidates, a Key ID is needed to be specified so that Authlete Server can pick up one JWK from among the JWK candidates. ' refreshTokenDuration: type: integer format: int64 description: The duration of refresh tokens in seconds. The related specifications have no requirements on refresh token duration, but Authlete sets expiration for refresh tokens. refreshTokenDurationKept: type: boolean description: 'The flag to indicate whether the remaining duration of the used refresh token is taken over to the newly issued refresh token. ' refreshTokenDurationReset: type: boolean description: 'The flag which indicates whether duration of refresh tokens are reset when they are used even if the `refreshTokenKept` property of this service set to is `true` (= even if "Refresh Token Continuous Use" is "Kept"). This flag has no effect when the `refreshTokenKept` property is set to `false`. In other words, if this service issues a new refresh token on every refresh token request, the refresh token will have fresh duration (unless `refreshTokenDurationKept` is set to `true`) and this `refreshTokenDurationReset` property is not referenced. ' refreshTokenKept: type: boolean description: 'The flag to indicate whether a refresh token remains unchanged or gets renewed after its use. If `true`, a refresh token used to get a new access token remains valid after its use. Otherwise, if `false`, a refresh token is invalidated after its use and a new refresh token is issued. See [RFC 6749 6. Refreshing an Access Token](https://tools.ietf.org/html/rfc6749#section-6), as to how to get a new access token using a refresh token. ' supportedScopes: type: array items: $ref: '#/components/schemas/scope' description: 'Scopes supported by the service. ' x-mint: metadata: description: Scopes supported by the service. content: ' Authlete strongly recommends that the service register at least the following scopes. | Name | Description | | --- | --- | | openid | A permission to get an ID token of an end-user. The `openid` scope appears in [OpenID Connect Core 1.0, 3.1.2.1. Authentication Request, scope](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest). Without this scope, Authlete does not allow `response_type` request parameter to have values other than code and token. | | profile | A permission to get information about `name`, `family_name`, `given_name`, `middle_name`, `nickname`, `preferred_username`, `profile`, `picture`, `website`, `gender`, `birthdate`, `zoneinfo`, `locale` and `updated_at` from the user info endpoint. See [OpenID Connect Core 1.0, 5.4. Requesting Claims using Scope Values](https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims) for details. | | email | A permission to get information about `email` and `email_verified` from the user info endpoint. See [OpenID Connect Core 1.0, 5.4. Requesting Claims using Scope Values](https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims) for details. | | address | A permission to get information about address from the user info endpoint. See [OpenID Connect Core 1.0, 5.4. Requesting Claims using Scope Values](https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims) and [5.1.1. Address Claim](https://openid.net/specs/openid-connect-core-1_0.html#AddressClaim) for details. | | phone | A permission to get information about `phone_number` and `phone_number_verified` from the user info endpoint. See [OpenID Connect Core 1.0, 5.4. Requesting Claims using Scope Values](https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims) for details. | | offline_access | A permission to get information from the user info endpoint even when the end-user is not present. See [OpenID Connect Core 1.0, 11. Offline Access](https://openid.net/specs/openid-connect-core-1_0.html#OfflineAccess) for details. | The value of this property is used as `scopes_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' scopeRequired: type: boolean description: 'The flag to indicate whether requests that request no scope are rejected or not. ' x-mint: metadata: description: The flag to indicate whether requests that request no scope are rejected or not. content: ' When a request has no explicit `scope` parameter and the service''s pre-defined default scope set is empty, the authorization server regards the request requests no scope. When this flag is set to `true`, requests that request no scope are rejected. The requirement below excerpted from [RFC 6749 Section 3.3](https://tools.ietf.org/html/rfc6749#section-3.3) does not explicitly mention the case where the default scope set is empty. > If the client omits the scope parameter when requesting authorization, the authorization server MUST either process the request using a pre-defined default value or fail the request indicating an invalid scope. However, if you interpret *"the default scope set exists but is empty"* as *"the default scope set does not exist"* and want to strictly conform to the requirement above, this flag has to be `true`. ' idTokenDuration: type: integer format: int64 description: '''The duration of [ID token](https://openid.net/specs/openid-connect-core-1_0.html#IDToken)s in seconds. This value is used to calculate the value of `exp` claim in an ID token.'' ' allowableClockSkew: type: integer format: int32 description: 'The allowable clock skew between the server and clients in seconds. The clock skew is taken into consideration when time-related claims in a JWT (e.g. `exp`, `iat`, `nbf`) are verified. ' supportedClaimTypes: type: array items: $ref: '#/components/schemas/claim_type' description: 'Claim types supported by the service. Valid values are listed in Claim Type. Note that Authlete currently doesn''t provide any API to help implementations for `AGGREGATED` and `DISTRIBUTED`. The value of this property is used as `claim_types_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' supportedClaimLocales: type: array items: type: string description: 'Claim locales that the service supports. Each element is a language tag defined in [RFC 5646](https://tools.ietf.org/html/rfc5646). For example, `en-US` and `ja-JP`. See [OpenID Connect Core 1.0, 5.2. Languages and Scripts](https://openid.net/specs/openid-connect-core-1_0.html#ClaimsLanguagesAndScripts) for details. The value of this property is used as `claims_locales_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' supportedClaims: type: array items: type: string description: 'Claim names that the service supports. The standard claim names listed in [OpenID Connect Core 1.0, 5.1. Standard Claim](https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims) should be supported. The following is the list of standard claims. ' x-mint: metadata: description: Claim names that the service supports. The standard claim names listed in [OpenID Connect Core 1.0, 5.1. Standard Claim](https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims) should be supported. The following is the list of standard claims. content: ' - `sub` - `name` - `given_name` - `family_name` - `middle_name` - `nickname` - `preferred_username` - `profile` - `picture` - `website` - `email` - `email_verified` - `gender` - `birthdate` - `zoneinfo` - `locale` - `phone_number` - `phone_number_verified` - `address` - `updated_at` The value of this property is used as `claims_supported` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). The service may support its original claim names. See [OpenID Connect Core 1.0, 5.1.2. Additional Claims](https://openid.net/specs/openid-connect-core-1_0.html#AdditionalClaims). ' claimShortcutRestrictive: type: boolean description: 'The flag indicating whether claims specified by shortcut scopes (e.g. `profile`) are included in the issued ID token only when no access token is issued. ' x-mint: metadata: description: The flag indicating whether claims specified by shortcut scopes (e.g. `profile`) are included in the issued ID token only when no access token is issued. content: ' To strictly conform to the description below excerpted from [OpenID Connect Core 1.0 Section 5.4](https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims), this flag has to be `true`. > The Claims requested by the profile, email, address, and phone scope values are returned from the UserInfo Endpoint, as described in Section 5.3.2, when a response_type value is used that results in an Access Token being issued. However, when no Access Token is issued (which is the case for the response_type value id_token), the resulting Claims are returned in the ID Token. ' jwksUri: type: string format: uri description: 'The URL of the service''s [JSON Web Key Set](https://tools.ietf.org/html/rfc7517) document. For example, `http://example.com/auth/jwks`. Client applications accesses this URL (1) to get the public key of the service to validate the signature of an ID token issued by the service and (2) to get the public key of the service to encrypt an request object of the client application. See [OpenID Connect Core 1.0, 10. Signatures and Encryption](https://openid.net/specs/openid-connect-core-1_0.html#SigEnc) for details. The value of this property is used as `jwks_uri` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' directJwksEndpointEnabled: type: boolean description: '''The flag to indicate whether the direct jwks endpoint is enabled or not. The path of the endpoint is `/api/service/jwks/get/direct/service-api-key`. '' ' jwks: type: string description: 'The content of the service''s [JSON Web Key Set](https://tools.ietf.org/html/rfc7517) document. If this property is not `null` in a `/service/create` request or a `/service/update` request, Authlete hosts the content in the database. This property must not be `null` and must contain pairs of public/private keys if the service wants to support asymmetric signatures for ID tokens and asymmetric encryption for request objects. See [OpenID Connect Core 1.0, 10. Signatures and Encryption](https://openid.net/specs/openid-connect-core-1_0.html#SigEnc) for details. ' idTokenSignatureKeyId: type: string description: 'The key ID to identify a JWK used for ID token signature using an asymmetric key. ' x-mint: metadata: description: The key ID to identify a JWK used for ID token signature using an asymmetric key. content: ' A JWK Set can be registered as a property of a Service. A JWK Set can contain 0 or more JWKs (See [RFC 7517](https://tools.ietf.org/html/rfc7517) for details about JWK). Authlete Server has to pick up one JWK for signature from the JWK Set when it generates an ID token and signature using an asymmetric key is required. Authlete Server searches the registered JWK Set for a JWK which satisfies conditions for ID token signature. If the number of JWK candidates which satisfy the conditions is 1, there is no problem. On the other hand, if there exist multiple candidates, a [Key ID](https://tools.ietf.org/html/rfc7517#section-4.5) is needed to be specified so that Authlete Server can pick up one JWK from among the JWK candidates. This `idTokenSignatureKeyId` property exists for the purpose described above. For key rotation (OpenID Connect Core 1.0, [10.1.1. Rotation of Asymmetric Signing Keys](http://openid.net/specs/openid-connect-core-1_0.html#RotateSigKeys)), this mechanism is needed. ' userInfoSignatureKeyId: type: string description: 'The key ID to identify a JWK used for user info signature using an asymmetric key. ' x-mint: metadata: description: The key ID to identify a JWK used for user info signature using an asymmetric key. content: ' A JWK Set can be registered as a property of a Service. A JWK Set can contain 0 or more JWKs (See [RFC 7517](https://tools.ietf.org/html/rfc7517) for details about JWK). Authlete Server has to pick up one JWK for signature from the JWK Set when it is required to sign user info (which is returned from [userinfo endpoint](http://openid.net/specs/openid-connect-core-1_0.html#UserInfo)) using an asymmetric key. Authlete Server searches the registered JWK Set for a JWK which satisfies conditions for user info signature. If the number of JWK candidates which satisfy the conditions is 1, there is no problem. On the other hand, if there exist multiple candidates, a [Key ID](https://tools.ietf.org/html/rfc7517#section-4.5) is needed to be specified so that Authlete Server can pick up one JWK from among the JWK candidates. This `userInfoSignatureKeyId` property exists for the purpose described above. For key rotation (OpenID Connect Core 1.0, [10.1.1. Rotation of Asymmetric Signing Keys](http://openid.net/specs/openid-connect-core-1_0.html#RotateSigKeys)), this mechanism is needed. ' authorizationSignatureKeyId: type: string description: 'The key ID to identify a JWK used for signing authorization responses using an asymmetric key. ' x-mint: metadata: description: The key ID to identify a JWK used for signing authorization responses using an asymmetric key. content: ' [Financial-grade API: JWT Secured Authorization Response Mode for OAuth 2.0 (JARM)](https://openid.net/specs/openid-financial-api-jarm.html) defines new values for the `response_mode` request parameter. They are `query.jwt`, `fragment.jwt`, `form_post.jwt` and `jwt`. If one of them is specified as the response mode, response parameters from the authorization endpoint will be packed into a JWT. This property is used to compute the value of the `exp` claim of the JWT. Authlete Server searches the JWK Set for a JWK which satisfies conditions for authorization response signature. If the number of JWK candidates which satisfy the conditions is 1, there is no problem. On the other hand, if there exist multiple candidates, a Key ID is needed to be specified so that Authlete Server can pick up one JWK from among the JWK candidates. This property exists to specify the key ID. ' userInfoEndpoint: type: string description: 'The [user info endpoint](http://openid.net/specs/openid-connect-core-1_0.html#UserInfo) of the service. A URL that starts with `https://`. For example, `https://example.com/auth/userinfo`. The value of this property is used as `userinfo_endpoint` property in the [OpenID Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' format: uri directUserInfoEndpointEnabled: type: boolean description: 'The flag to indicate whether the direct userinfo endpoint is enabled or not. The path of the endpoint is `/api/auth/userinfo/direct/service-api-key`. ' dynamicRegistrationSupported: type: boolean description: 'The boolean flag which indicates whether the [OAuth 2.0 Dynamic Client Registration Protocol](https://tools.ietf.org/html/rfc7591) is supported. ' registrationEndpoint: type: string description: 'The [registration endpoint](http://openid.net/specs/openid-connect-registration-1_0.html#ClientRegistration) of the service. A URL that starts with `https://`. For example, `https://example.com/auth/registration`. The value of this property is used as `registration_endpoint` property in the [OpenID Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' format: uri registrationManagementEndpoint: type: string description: 'The URI of the registration management endpoint. If dynamic client registration is supported, and this is set, this URI will be used as the basis of the client''s management endpoint by appending `/clientid}/` to it as a path element. If this is unset, the value of `registrationEndpoint` will be used as the URI base instead. ' format: uri policyUri: type: string description: 'The URL of the "Policy" of the service. The value of this property is used as `op_policy_uri` property in the [OpenID Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' format: uri tosUri: type: string description: 'The URL of the "Terms Of Service" of the service. The value of this property is used as `op_tos_uri` property in the [OpenID Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' format: uri serviceDocumentation: type: string description: 'The URL of a page where documents for developers can be found. The value of this property is used as `service_documentation` property in the [OpenID Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' format: uri backchannelAuthenticationEndpoint: type: string description: 'The URI of backchannel authentication endpoint, which is defined in the specification of [CIBA (Client Initiated Backchannel Authentication)](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html). ' format: uri supportedBackchannelTokenDeliveryModes: type: array items: $ref: '#/components/schemas/delivery_mode' description: 'The supported backchannel token delivery modes. This property corresponds to the `backchannel_token_delivery_modes_supported` metadata. Backchannel token delivery modes are defined in the specification of [CIBA (Client Initiated Backchannel Authentication)](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html). ' backchannelAuthReqIdDuration: type: integer format: int32 description: 'The duration of backchannel authentication request IDs issued from the backchannel authentication endpoint in seconds. This is used as the value of the `expires_in` property in responses from the backchannel authentication endpoint. ' backchannelPollingInterval: type: integer format: int32 description: 'The minimum interval between polling requests to the token endpoint from client applications in seconds. This is used as the value of the `interval` property in responses from the backchannel authentication endpoint. ' backchannelUserCodeParameterSupported: type: boolean description: 'The boolean flag which indicates whether the `user_code` request parameter is supported at the backchannel authentication endpoint. This property corresponds to the `backchannel_user_code_parameter_supported` metadata. ' backchannelBindingMessageRequiredInFapi: type: boolean description: 'The flag to indicate whether the `binding_message` request parameter is always required whenever a backchannel authentication request is judged as a request for Financial-grade API. ' x-mint: metadata: description: The flag to indicate whether the `binding_message` request parameter is always required whenever a backchannel authentication request is judged as a request for Financial-grade API. content: ' The FAPI-CIBA profile requires that the authorization server _"shall ensure unique authorization context exists in the authorization request or require a `binding_message` in the authorization request"_ (FAPI-CIBA, 5.2.2, 2). The simplest way to fulfill this requirement is to set this property to `true`. If this property is set to `false`, the `binding_message` request parameter remains optional even in FAPI context, but in exchange, your authorization server must implement a custom mechanism that ensures each backchannel authentication request has unique context. ' deviceAuthorizationEndpoint: type: string format: uri description: 'The URI of the device authorization endpoint. Device authorization endpoint is defined in the specification of OAuth 2.0 Device Authorization Grant. ' deviceVerificationUri: type: string format: uri description: 'The verification URI for the device flow. This URI is used as the value of the `verification_uri` parameter in responses from the device authorization endpoint. ' deviceVerificationUriComplete: type: string format: uri description: 'The verification URI for the device flow with a placeholder for a user code. This URI is used to build the value of the `verification_uri_complete` parameter in responses from the device authorization endpoint. ' x-mint: metadata: description: The verification URI for the device flow with a placeholder for a user code. This URI is used to build the value of the `verification_uri_complete` parameter in responses from the device authorization endpoint. content: ' It is expected that the URI contains a fixed string `USER_CODE` somewhere as a placeholder for a user code. For example, like the following. `https://example.com/device?user_code=USER_CODE` The fixed string is replaced with an actual user code when Authlete builds a verification URI with a user code for the `verification_uri_complete` parameter. If this URI is not set, the `verification_uri_complete` parameter won''t appear in device authorization responses. ' deviceFlowCodeDuration: type: integer format: int32 description: 'The duration of device verification codes and end-user verification codes issued from the device authorization endpoint in seconds. This is used as the value of the `expires_in` property in responses from the device authorization endpoint. ' deviceFlowPollingInterval: type: integer format: int32 description: 'The minimum interval between polling requests to the token endpoint from client applications in seconds in device flow. This is used as the value of the `interval` property in responses from the device authorization endpoint. ' userCodeCharset: $ref: '#/components/schemas/user_code_charset' userCodeLength: type: integer format: int32 description: 'The length of end-user verification codes (`user_code`) for Device Flow. ' supportedTrustFrameworks: type: array items: type: string description: 'Trust frameworks supported by this service. This corresponds to the `trust_frameworks_supported` [metadata](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#rfc.section.7). ' supportedEvidence: type: array items: type: string description: 'Evidence supported by this service. This corresponds to the `evidence_supported` [metadata](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#rfc.section.7). ' supportedIdentityDocuments: type: array items: type: string description: 'Identity documents supported by this service. This corresponds to the `id_documents_supported` [metadata](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#rfc.section.7). ' supportedVerificationMethods: type: array items: type: string description: 'Verification methods supported by this service. This corresponds to the `id_documents_verification_methods_supported` [metadata](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#rfc.section.7). ' supportedVerifiedClaims: type: array items: type: string description: 'Verified claims supported by this service. This corresponds to the `claims_in_verified_claims_supported` [metadata](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#rfc.section.7). ' verifiedClaimsValidationSchemaSet: $ref: '#/components/schemas/verified_claims_validation_schema' type: string description: 'OIDC4IDA / verifiedClaimsValidationSchemaSet ' attributes: type: array items: $ref: '#/components/schemas/pair' description: 'The attributes of this service. ' nbfOptional: type: boolean description: 'The flag indicating whether the nbf claim in the request object is optional even when the authorization request is regarded as a FAPI-Part2 request. ' x-mint: metadata: description: The flag indicating whether the nbf claim in the request object is optional even when the authorization request is regarded as a FAPI-Part2 request. content: ' The final version of Financial-grade API was approved in January, 2021. The Part 2 of the final version has new requirements on lifetime of request objects. They require that request objects contain an `nbf` claim and the lifetime computed by `exp` - `nbf` be no longer than 60 minutes. Therefore, when an authorization request is regarded as a FAPI-Part2 request, the request object used in the authorization request must contain an nbf claim. Otherwise, the authorization server rejects the authorization request. When this flag is `true`, the `nbf` claim is treated as an optional claim even when the authorization request is regarded as a FAPI-Part2 request. That is, the authorization server does not perform the validation on lifetime of the request object. Skipping the validation is a violation of the FAPI specification. The reason why this flag has been prepared nevertheless is that the new requirements (which do not exist in the Implementer''s Draft 2 released in October, 2018) have big impacts on deployed implementations of client applications and Authlete thinks there should be a mechanism whereby to make the migration from ID2 to Final smooth without breaking live systems. ' issSuppressed: type: boolean description: 'The flag indicating whether generation of the iss response parameter is suppressed. ' x-mint: metadata: description: The flag indicating whether generation of the iss response parameter is suppressed. content: ' "OAuth 2.0 Authorization Server Issuer Identifier in Authorization Response" has defined a new authorization response parameter, `iss`, as a countermeasure for a certain type of mix-up attacks. The specification requires that the `iss` response parameter always be included in authorization responses unless JARM (JWT Secured Authorization Response Mode) is used. When this flag is `true`, the authorization server does not include the `iss` response parameter in authorization responses. By turning this flag on and off, developers of client applications can experiment the mix-up attack and the effect of the `iss` response parameter. Note that this flag should not be `true` in production environment unless there are special reasons for it. ' supportedCustomClientMetadata: type: array items: type: string description: 'custom client metadata supported by this service. ' x-mint: metadata: description: custom client metadata supported by this service. content: ' Standard specifications define client metadata as necessary. The following are such examples. * [OpenID Connect Dynamic Client Registration 1.0](https://openid.net/specs/openid-connect-registration-1_0.html) * [RFC 7591 OAuth 2.0 Dynamic Client Registration Protocol](https://www.rfc-editor.org/rfc/rfc7591.html) * [RFC 8705 OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens](https://www.rfc-editor.org/rfc/rfc8705.html) * [OpenID Connect Client-Initiated Backchannel Authentication Flow - Core 1.0](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html) * [The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)](https://datatracker.ietf.org/doc/draft-ietf-oauth-jwsreq/) * [Financial-grade API: JWT Secured Authorization Response Mode for OAuth 2.0 (JARM)](https://openid.net/specs/openid-financial-api-jarm.html) * [OAuth 2.0 Pushed Authorization Requests (PAR)](https://datatracker.ietf.org/doc/rfc9126/) * [OAuth 2.0 Rich Authorization Requests (RAR)](https://datatracker.ietf.org/doc/draft-ietf-oauth-rar/) Standard client metadata included in Client Registration Request and Client Update Request (cf. [OIDC DynReg](https://openid.net/specs/openid-connect-registration-1_0.html), [RFC 7591](https://www.rfc-editor.org/rfc/rfc7591.html) and [RFC 7592](https://www.rfc-editor.org/rfc/rfc7592.html)) are, if supported by Authlete, stored into Authlete database. On the other hand, unrecognized client metadata are discarded. By listing up custom client metadata in advance by using this property (`supportedCustomClientMetadata`), Authlete can recognize them and stores their values into the database. The stored custom client metadata values can be referenced by `customMetadata`. ' tokenExpirationLinked: type: boolean description: 'The flag indicating whether the expiration date of an access token never exceeds that of the corresponding refresh token. ' x-mint: metadata: description: The flag indicating whether the expiration date of an access token never exceeds that of the corresponding refresh token. content: ' When a new access token is issued by a refresh token request (= a token request with `grant_type=refresh_token`), the expiration date of the access token may exceed the expiration date of the corresponding refresh token. This behavior itself is not wrong and may happen when `refreshTokenKept` is `true` and/or when `refreshTokenDurationKept` is `true`. When this flag is `true`, the expiration date of an access token never exceeds that of the corresponding refresh token regardless of the calculated duration based on other settings such as `accessTokenDuration`, `accessTokenDuration` in `extension` and `access_token.duration` scope attribute. It is technically possible to set a value which is bigger than the duration of refresh tokens as the duration of access tokens although it is strange. In the case, the duration of an access token becomes longer than the duration of the refresh token which is issued together with the access token. Even if the duration values are configured so, if this flag is `true`, the expiration date of the access token does not exceed that of the refresh token. That is, the duration of the access token will be shortened, and as a result, the access token and the refresh token will have the same expiration date. ' frontChannelRequestObjectEncryptionRequired: type: boolean description: 'The flag indicating whether encryption of request object is required when the request object is passed through the front channel. ' x-mint: metadata: description: The flag indicating whether encryption of request object is required when the request object is passed through the front channel. content: ' This flag does not affect the processing of request objects at the Pushed Authorization Request Endpoint, which is defined in [OAuth 2.0 Pushed Authorization Requests](https://datatracker.ietf.org/doc/rfc9126/). Unecrypted request objects are accepted at the endpoint even if this flag is `true`. This flag does not indicate whether a request object is always required. There is a different flag, `requestObjectRequired`, for the purpose. See the description of `requestObjectRequired` for details. Even if this flag is `false`, encryption of request object is required if the `frontChannelRequestObjectEncryptionRequired` flag of the client is `true`. ' requestObjectEncryptionAlgMatchRequired: type: boolean description: 'The flag indicating whether the JWE alg of encrypted request object must match the `request_object_encryption_alg` client metadata of the client that has sent the request object. ' x-mint: metadata: description: The flag indicating whether the JWE alg of encrypted request object must match the `request_object_encryption_alg` client metadata of the client that has sent the request object. content: ' The request_object_encryption_alg client metadata itself is defined in [OpenID Connect Dynamic Client Registration 1.0](https://openid.net/specs/openid-connect-registration-1_0.html) as follows. > request_object_encryption_alg > > OPTIONAL. JWE [JWE] alg algorithm [JWA] the RP is declaring that it may use for encrypting Request Objects sent to the OP. This parameter SHOULD be included when symmetric encryption will be used, since this signals to the OP that a client_secret value needs to be returned from which the symmetric key will be derived, that might not otherwise be returned. The RP MAY still use other supported encryption algorithms or send unencrypted Request Objects, even when this parameter is present. If both signing and encryption are requested, the Request Object will be signed then encrypted, with the result being a Nested JWT, as defined in [JWT]. The default, if omitted, is that the RP is not declaring whether it might encrypt any Request Objects. The point here is "The RP MAY still use other supported encryption algorithms or send unencrypted Request Objects, even when this parameter is present." The Client''s property that represents the client metadata is `requestEncryptionAlg`. See the description of `requestEncryptionAlg` for details. Even if this flag is `false`, the match is required if the `requestObjectEncryptionAlgMatchRequired` flag of the client is `true`. ' requestObjectEncryptionEncMatchRequired: type: boolean description: 'The flag indicating whether the JWE `enc` of encrypted request object must match the `request_object_encryption_enc` client metadata of the client that has sent the request object. ' x-mint: metadata: description: The flag indicating whether the JWE `enc` of encrypted request object must match the `request_object_encryption_enc` client metadata of the client that has sent the request object. content: ' The `request_object_encryption_enc` client metadata itself is defined in [OpenID Connect Dynamic Client Registration 1.0](https://openid.net/specs/openid-connect-registration-1_0.html) as follows. > request_object_encryption_enc > > OPTIONAL. JWE enc algorithm [JWA] the RP is declaring that it may use for encrypting Request Objects sent to the OP. If request_object_encryption_alg is specified, the default for this value is A128CBC-HS256. When request_object_encryption_enc is included, request_object_encryption_alg MUST also be provided. The Client''s property that represents the client metadata is `requestEncryptionEnc`. See the description of `requestEncryptionEnc` for details. Even if this flag is false, the match is required if the `requestObjectEncryptionEncMatchRequired` flag is `true`. ' hsmEnabled: type: boolean description: 'The flag indicating whether HSM (Hardware Security Module) support is enabled for this service. When this flag is `false`, keys managed in HSMs are not used even if they exist. In addition, `/api/hsk/*` APIs reject all requests. Even if this flag is `true`, HSM-related features do not work if the configuration of the Authlete server you are using does not support HSM. ' hsks: type: array items: $ref: '#/components/schemas/hsk' description: 'The information about keys managed on HSMs (Hardware Security Modules). This `hsks` property is output only, meaning that `hsks` in requests to `/api/service/create` API and `/api/service/update` API do not have any effect. The contents of this property is controlled only by `/api/hsk/*` APIs. ' grantManagementEndpoint: type: string description: 'The URL of the grant management endpoint. ' grantManagementActionRequired: type: boolean description: 'The flag indicating whether every authorization request (and any request serving as an authorization request such as CIBA backchannel authentication request and device authorization request) must include the `grant_management_action` request parameter. ' x-mint: metadata: description: The flag indicating whether every authorization request (and any request serving as an authorization request such as CIBA backchannel authentication request and device authorization request) must include the `grant_management_action` request parameter. content: ' This property corresponds to the `grant_management_action_required` server metadata defined in [Grant Management for OAuth 2.0](https://openid.net/specs/fapi-grant-management.html). Note that setting true to this property will result in blocking all public clients because the specification requires that grant management be usable only by confidential clients for security reasons. ' unauthorizedOnClientConfigSupported: type: boolean description: 'The flag indicating whether Authlete''s `/api/client/registration` API uses `UNAUTHORIZED` as a value of the `action` response parameter when appropriate. ' x-mint: metadata: description: The flag indicating whether Authlete's `/api/client/registration` API uses `UNAUTHORIZED` as a value of the `action` response parameter when appropriate. content: ' The `UNAUTHORIZED` enum value was initially not defined as a possible value of the `action` parameter in an `/api/client/registration` API response. This means that implementations of client `configuration` endpoint were not able to conform to [RFC 7592](https://www.rfc-editor.org/rfc/rfc7592.html) strictly. For backward compatibility (to avoid breaking running systems), Authlete''s `/api/client/registration` API does not return the `UNAUTHORIZED` enum value if this flag is not turned on. The steps an existing implementation of client configuration endpoint has to do in order to conform to the requirement related to "401 Unauthorized" are as follows. 1. Update the Authlete library (e.g. authlete-java-common) your system is using. 2. Update your implementation of client configuration endpoint so that it can handle the `UNAUTHORIZED` action. 3. Turn on this `unauthorizedOnClientConfigSupported` flag. ' dcrScopeUsedAsRequestable: type: boolean description: 'The flag indicating whether the `scope` request parameter in dynamic client registration and update requests (RFC 7591 and RFC 7592) is used as scopes that the client can request. Limiting the range of scopes that a client can request is achieved by listing scopes in the `client.extension.requestableScopes` property and setting the `client.extension.requestableScopesEnabled` property to `true`. This feature is called "requestable scopes". This property affects behaviors of `/api/client/registration` and other family APIs. ' endSessionEndpoint: type: string format: uri description: 'The endpoint for clients ending the sessions. A URL that starts with `https://` and has no fragment component. For example, `https://example.com/auth/endSession`. The value of this property is used as `end_session_endpoint` property in the [OpenID Provider Metadata](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata). ' loopbackRedirectionUriVariable: type: boolean description: 'The flag indicating whether the port number component of redirection URIs can be variable when the host component indicates loopback. ' x-mint: metadata: description: The flag indicating whether the port number component of redirection URIs can be variable when the host component indicates loopback. content: ' When this flag is `true`, if the host component of a redirection URI specified in an authorization request indicates loopback (to be precise, when the host component is localhost, `127.0.0.1` or `::1`), the port number component is ignored when the specified redirection URI is compared to pre-registered ones. This behavior is described in [7.3. Loopback Interface Redirection]( https://www.rfc-editor.org/rfc/rfc8252.html#section-7.3) of [RFC 8252 OAuth 2.0](https://www.rfc-editor.org/rfc/rfc8252.html) for Native Apps. [3.1.2.3. Dynamic Configuration](https://www.rfc-editor.org/rfc/rfc6749.html#section-3.1.2.3) of [RFC 6749](https://www.rfc-editor.org/rfc/rfc6749.html) states _"If the client registration included the full redirection URI, the authorization server MUST compare the two URIs using simple string comparison as defined in [RFC3986] Section 6.2.1."_ Also, the description of `redirect_uri` in [3.1.2.1. Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest) of [OpenID Connect Core 1.0](https://openid.net/specs/openid-connect-core-1_0.html) states _"This URI MUST exactly match one of the Redirection URI values for the Client pre-registered at the OpenID Provider, with the matching performed as described in Section 6.2.1 of [RFC3986] (**Simple String Comparison**)."_ These "Simple String Comparison" requirements are preceded by this flag. That is, even when the conditions described in RFC 6749 and OpenID Connect Core 1.0 are satisfied, the port number component of loopback redirection URIs can be variable when this flag is `true`. [8.3. Loopback Redirect Considerations](https://www.rfc-editor.org/rfc/rfc8252.html#section-8.3) of [RFC 8252](https://www.rfc-editor.org/rfc/rfc8252.html) states as follows. > While redirect URIs using localhost (i.e., `"http://localhost:{port}/{path}"`) function similarly to loopback IP redirects described in Section 7.3, the use of localhost is NOT RECOMMENDED. Specifying a redirect URI with the loopback IP literal rather than localhost avoids inadvertently listening on network interfaces other than the loopback interface. It is also less susceptible to client-side firewalls and misconfigured host name resolution on the user''s device. However, Authlete allows the port number component to be variable in the case of `localhost`, too. It is left to client applications whether they use `localhost` or a literal loopback IP address (`127.0.0.1` for IPv4 or `::1` for IPv6). Section 7.3 and Section 8.3 of [RFC 8252](https://www.rfc-editor.org/rfc/rfc8252.html) state that loopback redirection URIs use the `"http"` scheme, but Authlete allows the port number component to be variable in other cases (e.g. in the case of the `"https"` scheme), too. ' requestObjectAudienceChecked: type: boolean description: 'The flag indicating whether Authlete checks whether the `aud` claim of request objects matches the issuer identifier of this service. ' x-mint: metadata: description: The flag indicating whether Authlete checks whether the `aud` claim of request objects matches the issuer identifier of this service. content: ' [Section 6.1. Passing a Request Object by Value](https://openid.net/specs/openid-connect-core-1_0.html#JWTRequests) of [OpenID Connect Core 1.0](https://openid.net/specs/openid-connect-core-1_0.html) has the following statement. > The `aud` value SHOULD be or include the OP''s Issuer Identifier URL. Likewise, [Section 4. Request Object](https://www.rfc-editor.org/rfc/rfc9101.html#section-4) of [RFC 9101](https://www.rfc-editor.org/rfc/rfc9101.html) (The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR)) has the following statement. > The value of aud should be the value of the authorization server (AS) issuer, as defined in [RFC 8414](https://www.rfc-editor.org/rfc/rfc8414.html). As excerpted above, validation on the `aud` claim of request objects is optional. However, if this flag is turned on, Authlete checks whether the `aud` claim of request objects matches the issuer identifier of this service and raises an error if they are different. ' accessTokenForExternalAttachmentEmbedded: type: boolean description: 'The flag indicating whether Authlete generates access tokens for external attachments and embeds them in ID tokens and userinfo responses. ' authorityHints: type: array items: type: string description: 'Identifiers of entities that can issue entity statements for this service. This property corresponds to the `authority_hints` property that appears in a self-signed entity statement that is defined in OpenID Connect Federation 1.0. ' federationEnabled: type: boolean description: 'flag indicating whether this service supports OpenID Connect Federation 1 ' federationJwks: type: string description: 'JWK Set document containing keys that are used to sign (1) self-signed entity statement of this service and (2) the response from `signed_jwks_uri`. ' federationSignatureKeyId: type: string description: 'A key ID to identify a JWK used to sign the entity configuration and the signed JWK Set. ' federationConfigurationDuration: type: integer description: 'The duration of the entity configuration in seconds. ' federationRegistrationEndpoint: type: string description: 'The URI of the federation registration endpoint. This property corresponds to the `federation_registration_endpoint` server metadata that is defined in OpenID Connect Federation 1.0. ' organizationName: type: string description: 'The human-readable name representing the organization that operates this service. This property corresponds to the `organization_name` server metadata that is defined in OpenID Connect Federation 1.0. ' predefinedTransformedClaims: type: string description: 'The transformed claims predefined by this service in JSON format. This property corresponds to the `transformed_claims_predefined` server metadata. ' refreshTokenIdempotent: type: boolean description: 'flag indicating whether refresh token requests with the same refresh token can be made multiple times in quick succession and they can obtain the same renewed refresh token within the short period. ' signedJwksUri: type: string description: 'The URI of the endpoint that returns this service''s JWK Set document in the JWT format. This property corresponds to the `signed_jwks_uri` server metadata defined in OpenID Connect Federation 1.0. ' supportedAttachments: type: array items: $ref: '#/components/schemas/attachment_type' description: 'Supported attachment types. This property corresponds to the {@code attachments_supported} server metadata which was added by the third implementer''s draft of OpenID Connect for Identity Assurance 1.0. ' supportedDigestAlgorithms: type: array items: type: string description: 'Supported algorithms used to compute digest values of external attachments. This property corresponds to the `digest_algorithms_supported` server metadata which was added by the third implementer''s draft of OpenID Connect for Identity Assurance 1.0. ' supportedDocuments: type: array items: type: string description: 'Document types supported by this service. This property corresponds to the `documents_supported` server metadata. ' supportedDocumentsMethods: type: array items: type: string description: 'validation and verification processes supported by this service. This property corresponds to the `documents_methods_supported` server metadata. The third implementer''s draft of [OpenID Connect for Identity Assurance 1.0](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html) renamed the `id_documents_verification_methods_supported` server metadata to `documents_methods_supported`. ' supportedDocumentsValidationMethods: type: array items: type: string description: 'Document validation methods supported by this service. This property corresponds to the `documents_validation_methods_supported` server metadata which was added by the third implementer''s draft of ' supportedDocumentsVerificationMethods: type: array items: type: string description: 'Document verification methods supported by this service. This property corresponds to the `documents_verification_methods_supported` server metadata which was added by the third implementer''s draft of [OpenID Connect for Identity Assurance 1.0](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html) ' supportedElectronicRecords: type: array items: type: string description: 'Electronic record types supported by this service. This property corresponds to the `electronic_records_supported` server metadata which was added by the third implementer''s draft of [OpenID Connect for Identity Assurance 1.0](https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html) ' supportedClientRegistrationTypes: type: array items: $ref: '#/components/schemas/client_registration_type' tokenExchangeByIdentifiableClientsOnly: type: boolean description: 'The flag indicating whether to prohibit unidentifiable clients from making token exchange requests. ' tokenExchangeByConfidentialClientsOnly: type: boolean description: 'The flag indicating whether to prohibit public clients from making token exchange requests. ' tokenExchangeByPermittedClientsOnly: type: boolean description: 'The flag indicating whether to prohibit clients that have no explicit permission from making token exchange requests. ' tokenExchangeEncryptedJwtRejected: type: boolean description: 'The flag indicating whether to reject token exchange requests which use encrypted JWTs as input tokens. ' tokenExchangeUnsignedJwtRejected: type: boolean description: 'The flag indicating whether to reject token exchange requests which use unsigned JWTs as input tokens. ' jwtGrantByIdentifiableClientsOnly: type: boolean description: 'The flag indicating whether to prohibit unidentifiable clients from using the grant type "urn:ietf:params:oauth:grant-type:jwt-bearer". ' jwtGrantEncryptedJwtRejected: type: boolean description: 'The flag indicating whether to reject token requests that use an encrypted JWT as an authorization grant with the grant type "urn:ietf:params:oauth:grant-type:jwt-bearer". ' jwtGrantUnsignedJwtRejected: type: boolean description: 'The flag indicating whether to reject token requests that use an unsigned JWT as an authorization grant with the grant type "urn:ietf:params:oauth:grant-type:jwt-bearer". ' dcrDuplicateSoftwareIdBlocked: type: boolean description: 'The flag indicating whether to block DCR (Dynamic Client Registration) requests whose "software_id" has already been used previously. ' trustAnchors: type: array items: $ref: '#/components/schemas/trust_anchor' description: 'The trust anchors that are referenced when this service resolves trust chains of relying parties. If this property is empty, client registration fails regardless of whether its type is `automatic` or `explicit`. It means that OpenID Connect Federation 1.0 does not work. ' openidDroppedOnRefreshWithoutOfflineAccess: type: boolean description: 'The flag indicating whether the openid scope should be dropped from scopes list assigned to access token issued when a refresh token grant is used. ' supportedDocumentsCheckMethods: type: array items: type: string description: 'Supported document check methods. This property corresponds to the `documents_check_methods_supported` server metadata which was added by the fourth implementer''s draft of OpenID Connect for Identity Assurance 1.0. ' rsResponseSigned: type: boolean description: 'The flag indicating whether this service signs responses from the resource server. ' cnonceDuration: type: integer format: int64 description: 'The duration of `c_nonce`. ' dpopNonceRequired: type: boolean description: 'Whether to require DPoP proof JWTs to include the `nonce` claim whenever they are presented. ' verifiableCredentialsEnabled: type: boolean description: 'Get the flag indicating whether the feature of Verifiable Credentials for this service is enabled or not. ' credentialJwksUri: type: string description: 'The URL at which the JWK Set document of the credential issuer is exposed. ' credentialOfferDuration: type: integer format: int64 description: 'The default duration of credential offers in seconds. ' dpopNonceDuration: type: integer format: int64 description: 'The duration of nonce values for DPoP proof JWTs in seconds. ' preAuthorizedGrantAnonymousAccessSupported: type: boolean description: 'The flag indicating whether token requests using the pre-authorized code grant flow by unidentifiable clients are allowed. ' credentialTransactionDuration: type: integer format: int64 description: 'The duration of transaction ID in seconds that may be issued as a result of a credential request or a batch credential request. ' introspectionSignatureKeyId: type: string description: 'The key ID of the key for signing introspection responses. ' resourceSignatureKeyId: type: string description: 'The key ID of the key for signing introspection responses. ' userPinLength: type: integer format: int32 description: 'The default length of user PINs. ' supportedPromptValues: type: array items: $ref: '#/components/schemas/prompt' description: 'The supported `prompt` values. ' idTokenReissuable: type: boolean description: 'The flag indicating whether to enable the feature of ID token reissuance in the refresh token flow. ' credentialJwks: type: string description: 'The JWK Set document containing private keys that are used to sign verifiable credentials. ' fapiModes: type: array items: $ref: '#/components/schemas/fapi_mode' description: 'FAPI modes for this service. When the value of this property is not `null`, Authlete always processes requests to this service based on the specified FAPI modes if the FAPI feature is enabled in Authlete and the FAPI profile is supported by this service. For instance, when this property is set to an array containing `FAPI1_ADVANCED` only, Authlete always processes requests to this service based on "Financial-grade API Security Profile 1.0 - Part 2: Advanced" if the FAPI feature is enabled in Authlete and the FAPI profile is supported by this service. ' credentialDuration: type: integer format: int64 description: 'The default duration of verifiable credentials in seconds. ' credentialIssuerMetadata: $ref: '#/components/schemas/credential_issuer_metadata' idTokenAudType: type: string description: 'The type of the `aud` claim in ID tokens. ' nativeSsoSupported: type: boolean description: 'Flag that enables the [OpenID Connect Native SSO for Mobile Apps 1.0](https://openid.net/specs/openid-connect-native-sso-1_0.html) specification (“Native SSO”). When this property is **not** `true`, Native SSO specific parameters are ignored or treated as errors. For example: * The `device_sso` scope has no special meaning (Authlete does not embed the `sid` claim in ID tokens). * The `urn:openid:params:token-type:device-secret` token type is treated as unknown and results in an error. When set to `true`, the server metadata advertises `"native_sso_supported": true`. See [OpenID Connect Discovery 1.0](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata) and [RFC 8414 §2](https://www.rfc-editor.org/rfc/rfc8414.html#section-2) for background. Native SSO is available in Authlete 3.0 and later. ' oid4vciVersion: type: string description: 'Version of the [OpenID for Verifiable Credential Issuance](https://www.authlete.com/developers/oid4vci/) (OID4VCI) specification to support. Accepted values are: * `null` or `"1.0-ID1"` → Implementer’s Draft 1. * `"1.0"` or `"1.0-Final"` → Final 1.0 specification. Choose the value that matches the OID4VCI behaviour your service should expose. See the OID4VCI documentation for details. ' cimdMetadataPolicyEnabled: type: boolean description: 'Flag that controls whether the CIMD metadata policy is applied to client metadata obtained through the Client ID Metadata Document (CIMD) mechanism. ' clientIdMetadataDocumentSupported: type: boolean description: 'Indicates whether the Client ID Metadata Document (CIMD) mechanism is supported. When `true`, the service will attempt to retrieve client metadata via CIMD where applicable. ' cimdAllowlistEnabled: type: boolean description: 'Enables the allowlist for CIMD. When `true`, only CIMD endpoints that are on the allowlist are used. ' cimdAllowlist: type: array items: type: string description: 'The allowlist of CIMD endpoints (hosts/URIs) that may be used when retrieving client metadata via Client ID Metadata Documents. ' cimdAlwaysRetrieved: type: boolean description: 'If `true`, CIMD retrieval is always attempted for clients, regardless of other conditions. ' cimdHttpPermitted: type: boolean description: 'Allows CIMD retrieval over plain HTTP. When `false`, only HTTPS CIMD endpoints are allowed. ' cimdQueryPermitted: type: boolean description: 'Allows the use of query parameters when retrieving CIMD metadata. When `false`, query parameters are disallowed for CIMD requests. ' cimdMetadataPolicy: type: string description: 'The metadata policy applied to client metadata obtained through the CIMD mechanism. The value must follow the metadata policy grammar defined in [OpenID Federation 1.0 §6.1 Metadata Policy](https://openid.net/specs/openid-federation-1_0.html#name-metadata-policy). ' httpAliasProhibited: type: boolean description: 'When `true`, client ID aliases starting with `https://` or `http://` are prohibited. ' attestationChallengeTimeWindow: type: integer format: int64 description: 'The time window of attestation challenges in seconds. This is used for OAuth 2.0 Attestation-Based Client Authentication. ' service_profile: type: string enum: - FAPI - OPEN_BANKING result: type: object properties: resultCode: type: string description: The code which represents the result of the API call. resultMessage: type: string description: A short message which explains the result of the API call. delivery_mode: type: string enum: - PING - POLL - PUSH scope: type: object properties: name: type: string description: The name of the scope. defaultEntry: type: boolean description: '`true` to mark the scope as default. Scopes marked as default are regarded as requested when an authorization request from a client application does not contain scope request parameter. ' description: type: string description: The description about the scope. descriptions: type: array description: The descriptions about this scope in multiple languages. items: $ref: '#/components/schemas/tagged_value' attributes: type: array description: The attributes of the scope. items: $ref: '#/components/schemas/pair' client_auth_method: type: string description: 'The client authentication method that the client application declares that it uses at the token endpoint. This property corresponds to `token_endpoint_auth_method` in [OpenID Connect Dynamic Client Registration 1.0, 2. Client Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata). ' enum: - NONE - CLIENT_SECRET_BASIC - CLIENT_SECRET_POST - CLIENT_SECRET_JWT - PRIVATE_KEY_JWT - TLS_CLIENT_AUTH - SELF_SIGNED_TLS_CLIENT_AUTH - ATTEST_JWT_CLIENT_AUTH pair: type: object properties: key: type: string description: The key part. value: type: string description: The value part. user_code_charset: type: string description: 'The character set for end-user verification codes (`user_code`) for Device Flow. ' enum: - BASE20 - NUMERIC named_uri: type: object properties: name: type: string uri: type: string format: uri verified_claims_validation_schema: type: string description: 'The verified claims validation schema set. ' enum: - standard - standard+id_document responses: '500': description: '' content: application/json: schema: $ref: '#/components/schemas/result' example: resultCode: A001101 resultMessage: '[A001101] /auth/authorization, Authlete Server error.' '401': description: '' content: application/json: schema: $ref: '#/components/schemas/result' example: resultCode: A001202 resultMessage: '[A001202] /auth/authorization, Authorization header is missing.' '400': description: '' content: application/json: schema: $ref: '#/components/schemas/result' example: resultCode: A001201 resultMessage: '[A001201] /auth/authorization, TLS must be used.' '403': description: '' content: application/json: schema: $ref: '#/components/schemas/result' example: resultCode: A001215 resultMessage: '[A001215] /auth/authorization, The client (ID = 26837717140341) is locked.' links: service_delete: operationId: service_delete_api parameters: serviceId: $request.path.serviceId service_update: operationId: service_update_api parameters: serviceId: $request.path.serviceId service_create: operationId: service_create_api service_get_list: operationId: service_get_list_api securitySchemes: bearer: type: http scheme: bearer bearerFormat: JWT description: 'Authenticate every request with a **Service Access Token** or **Organization Token**. Set the token value in the `Authorization: Bearer ` header. **Service Access Token**: Scoped to a single service. Use when automating service-level configuration or runtime flows. **Organization Token**: Scoped to the organization; inherits permissions across services. Use for org-wide automation or when managing multiple services programmatically. Both token types are issued by the Authlete console or provisioning APIs. '