openapi: 3.2.0 info: title: Applications Service Principals.federated Identity… version: v1.0 servers: - url: https://graph.microsoft.com/v1.0/ description: Core security: - azureaadv2: [] tags: - name: servicePrincipals.federatedIdentityCredential paths: /servicePrincipals/{servicePrincipal-id}/federatedIdentityCredentials: get: tags: - servicePrincipals.federatedIdentityCredential summary: Get federatedIdentityCredentials from servicePrincipals description: Federated identities for a specific type of service principal - managed identity. Supports $expand and $filter (/$count eq 0, /$count ne 0). operationId: servicePrincipal_ListFederatedIdentityCredential parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/top' - $ref: '#/components/parameters/skip' - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/count' - name: $orderby in: query description: Order items by property values style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: $ref: '#/components/responses/microsoft.graph.federatedIdentityCredentialCollectionResponse' default: $ref: '#/components/responses/error' x-ms-pageable: nextLinkName: '@odata.nextLink' operationName: listMore x-ms-docs-operation-type: operation post: tags: - servicePrincipals.federatedIdentityCredential summary: Create new navigation property to federatedIdentityCredentials for… operationId: servicePrincipal_CreateFederatedIdentityCredential parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal requestBody: description: New navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' required: true responses: 2XX: description: Created navigation property. content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/federatedIdentityCredentials/{federatedIdentityCredential-id}: get: tags: - servicePrincipals.federatedIdentityCredential summary: Get federatedIdentityCredentials from servicePrincipals description: Federated identities for a specific type of service principal - managed identity. Supports $expand and $filter (/$count eq 0, /$count ne 0). operationId: servicePrincipal_GetFederatedIdentityCredential parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: federatedIdentityCredential-id in: path description: The unique identifier of federatedIdentityCredential required: true style: simple schema: type: string x-ms-docs-key-type: federatedIdentityCredential - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.federatedIdentityCredential summary: Update the navigation property federatedIdentityCredentials in servicePrincipals operationId: servicePrincipal_UpdateFederatedIdentityCredential parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: federatedIdentityCredential-id in: path description: The unique identifier of federatedIdentityCredential required: true style: simple schema: type: string x-ms-docs-key-type: federatedIdentityCredential requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.federatedIdentityCredential summary: Delete navigation property federatedIdentityCredentials for servicePrincipals operationId: servicePrincipal_DeleteFederatedIdentityCredential parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: federatedIdentityCredential-id in: path description: The unique identifier of federatedIdentityCredential required: true style: simple schema: type: string x-ms-docs-key-type: federatedIdentityCredential - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/federatedIdentityCredentials(name='{name}'): get: tags: - servicePrincipals.federatedIdentityCredential summary: Get federatedIdentityCredentials from servicePrincipals description: Federated identities for a specific type of service principal - managed identity. Supports $expand and $filter (/$count eq 0, /$count ne 0). operationId: servicePrincipal.federatedIdentityCredential_GetGraphBPreName parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: name in: path description: Alternate key of federatedIdentityCredential required: true style: simple schema: type: string - name: $select in: query description: Select properties to be returned style: form explode: false schema: uniqueItems: true type: array items: type: string - name: $expand in: query description: Expand related entities style: form explode: false schema: uniqueItems: true type: array items: type: string responses: 2XX: description: Retrieved navigation property content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation patch: tags: - servicePrincipals.federatedIdentityCredential summary: Update the navigation property federatedIdentityCredentials in servicePrincipals operationId: servicePrincipal.federatedIdentityCredential_UpdateGraphBPreName parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: name in: path description: Alternate key of federatedIdentityCredential required: true style: simple schema: type: string requestBody: description: New navigation property values content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' required: true responses: 2XX: description: Success content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation delete: tags: - servicePrincipals.federatedIdentityCredential summary: Delete navigation property federatedIdentityCredentials for servicePrincipals operationId: servicePrincipal.federatedIdentityCredential_DeleteGraphBPreName parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - name: name in: path description: Alternate key of federatedIdentityCredential required: true style: simple schema: type: string - name: If-Match in: header description: ETag style: simple schema: type: string responses: 2XX: description: Success default: $ref: '#/components/responses/error' x-ms-docs-operation-type: operation /servicePrincipals/{servicePrincipal-id}/federatedIdentityCredentials/$count: get: tags: - servicePrincipals.federatedIdentityCredential summary: Get the number of the resource operationId: servicePrincipal.federatedIdentityCredential_GetCount parameters: - name: servicePrincipal-id in: path description: The unique identifier of servicePrincipal required: true style: simple schema: type: string x-ms-docs-key-type: servicePrincipal - $ref: '#/components/parameters/search' - $ref: '#/components/parameters/filter' responses: 2XX: $ref: '#/components/responses/ODataCountResponse' default: $ref: '#/components/responses/error' components: responses: microsoft.graph.federatedIdentityCredentialCollectionResponse: description: Retrieved collection content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredentialCollectionResponse' error: description: error content: application/json: schema: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError' ODataCountResponse: description: The count of the resource content: text/plain: schema: $ref: '#/components/schemas/ODataCountResponse' parameters: top: name: $top in: query description: Show only the first n items style: form explode: false schema: minimum: 0 type: integer example: 50 count: name: $count in: query description: Include count of items style: form explode: false schema: type: boolean filter: name: $filter in: query description: Filter items by property values style: form explode: false schema: type: string search: name: $search in: query description: Search items by search phrases style: form explode: false schema: type: string skip: name: $skip in: query description: Skip the first n items style: form explode: false schema: minimum: 0 type: integer schemas: microsoft.graph.ODataErrors.InnerError: type: object additionalProperties: type: object description: The structure of this object is service-specific microsoft.graph.ODataErrors.ErrorDetails: required: - code - message type: object properties: code: type: string message: type: string target: type: - string - 'null' additionalProperties: type: object microsoft.graph.federatedIdentityCredential: allOf: - $ref: '#/components/schemas/microsoft.graph.entity' - title: federatedIdentityCredential type: object properties: audiences: type: array items: type: string description: The audience that can appear in the external token. This field is mandatory and should be set to api://AzureADTokenExchange for Microsoft Entra ID. It says what Microsoft identity platform should accept in the aud claim in the incoming token. This value represents Microsoft Entra ID in your external identity provider and has no fixed value across identity providers - you might need to create a new application registration in your identity provider to serve as the audience of this token. This field can only accept a single value and has a limit of 600 characters. Required. description: type: - string - 'null' description: The unvalidated description of the federated identity credential, provided by the user. It has a limit of 600 characters. Optional. issuer: type: string description: The URL of the external identity provider, which must match the issuer claim of the external token being exchanged. The combination of the values of issuer and subject must be unique within the app. It has a limit of 600 characters. Required. name: type: string description: The unique identifier for the federated identity credential, which has a limit of 120 characters and must be URL friendly. The string is immutable after it's created. Alternate key. Required. Not nullable. Supports $filter (eq). subject: type: - string - 'null' description: Required. The identifier of the external software workload within the external identity provider. Like the audience value, it has no fixed format; each identity provider uses their own - sometimes a GUID, sometimes a colon delimited identifier, sometimes arbitrary strings. The value here must match the sub claim within the token presented to Microsoft Entra ID. The combination of issuer and subject must be unique within the app. It has a limit of 600 characters. Supports $filter (eq). additionalProperties: type: object microsoft.graph.ODataErrors.MainError: required: - code - message type: object properties: code: type: string message: type: string x-ms-primary-error-message: true target: type: - string - 'null' details: type: array items: $ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails' innerError: $ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError' additionalProperties: type: object microsoft.graph.federatedIdentityCredentialCollectionResponse: title: Collection of federatedIdentityCredential type: object properties: value: type: array items: $ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential' '@odata.nextLink': type: - string - 'null' additionalProperties: type: object microsoft.graph.ODataErrors.ODataError: required: - error type: object properties: error: $ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError' additionalProperties: type: object microsoft.graph.entity: title: entity type: object properties: id: type: string description: The unique identifier for an entity. Read-only. additionalProperties: type: object ODataCountResponse: type: integer format: int32 securitySchemes: azureaadv2: type: oauth2 flows: authorizationCode: authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token scopes: {}