openapi: 3.2.0 info: license: name: Apache 2.0 url: http://www.apache.org/licenses/LICENSE-2.0.html title: Benchling Warehouse Credential API version: 2.0.0 description: 'Represents credentials for connecting to Benchling''s data warehouse, enabling users to query data using SQL tools like database clients or BI platforms. This includes all warehouse login types: user-generated Direct Access credentials, as well as temporary Insights and Agent credentials. Each WarehouseCredential is tied to a specific Benchling `user` whose permissions determine what data is accessible through those credentials. Credentials can have an optional `expiresAt` date for time-limited access and can be permanently disabled via the `revoked` flag. Once revoked, credentials cannot be reactivated. Users can create multiple credentials (up to a per-user limit) with different `label` values to distinguish between uses.' servers: - url: /api/v3 security: - oAuth: [] - basicApiKeyAuth: [] tags: - description: 'Represents credentials for connecting to Benchling''s data warehouse, enabling users to query data using SQL tools like database clients or BI platforms. This includes all warehouse login types: user-generated Direct Access credentials, as well as temporary Insights and Agent credentials. Each WarehouseCredential is tied to a specific Benchling `user` whose permissions determine what data is accessible through those credentials. Credentials can have an optional `expiresAt` date for time-limited access and can be permanently disabled via the `revoked` flag. Once revoked, credentials cannot be reactivated. Users can create multiple credentials (up to a per-user limit) with different `label` values to distinguish between uses.' name: WarehouseCredential x-bnch-organization: Benchling paths: /warehouse-credential/items: get: description: List WarehouseCredential items. operationId: WarehouseCredential.List parameters: - $ref: '#/components/parameters/createdAt.gt' - $ref: '#/components/parameters/createdAt.gte' - $ref: '#/components/parameters/createdAt.lt' - $ref: '#/components/parameters/createdAt.lte' - $ref: '#/components/parameters/id.anyOf' - $ref: '#/components/parameters/modifiedAt.gt' - $ref: '#/components/parameters/modifiedAt.gte' - $ref: '#/components/parameters/modifiedAt.lt' - $ref: '#/components/parameters/modifiedAt.lte' - $ref: '#/components/parameters/nextToken' - $ref: '#/components/parameters/omit' - $ref: '#/components/parameters/pageSize' - $ref: '#/components/parameters/returning' - $ref: '#/components/parameters/userId.anyOf' - description: 'Method by which to order results. Valid sorts are: createdAt (created time, oldest first) and modifiedAt (modified time, oldest first). Use :asc or :desc to specify ascending or descending order. Default is modifiedAt:desc.' in: query name: sort schema: default: modifiedAt:desc enum: - createdAt:asc - createdAt:desc - modifiedAt:asc - modifiedAt:desc type: string - description: Set to true to access beta operations via /api/v3. in: header name: EARLY-ACCESS required: false schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/WarehouseCredentialPaginatedList' description: OK headers: {} '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' '500': $ref: '#/components/responses/InternalServerError' summary: List WarehouseCredential items tags: - WarehouseCredential x-bnch-rate-limit-tier: 4 /warehouse-credential/{warehouse_credential_id}: get: description: Get a single WarehouseCredential by ID. operationId: WarehouseCredential.Get parameters: - description: ID of the WarehouseCredential. in: path name: warehouse_credential_id required: true schema: type: string - $ref: '#/components/parameters/returning' - $ref: '#/components/parameters/omit' - description: Set to true to access beta operations via /api/v3. in: header name: EARLY-ACCESS required: false schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/WarehouseCredential' description: OK headers: {} '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' '500': $ref: '#/components/responses/InternalServerError' summary: Get WarehouseCredential by ID tags: - WarehouseCredential x-bnch-rate-limit-tier: 5 patch: description: Update WarehouseCredential. operationId: WarehouseCredential.Update parameters: - description: ID of the WarehouseCredential. in: path name: warehouse_credential_id required: true schema: type: string - description: Set to true to access beta operations via /api/v3. in: header name: EARLY-ACCESS required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateWarehouseCredentialInput' responses: '200': content: application/json: schema: $ref: '#/components/schemas/WarehouseCredential' description: OK '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' '500': $ref: '#/components/responses/InternalServerError' summary: Update WarehouseCredential tags: - WarehouseCredential x-bnch-rate-limit-tier: 4 /warehouse-credential:batch-update: patch: description: Batch update WarehouseCredential synchronously in one transaction. Maximum 25 items per request. operationId: WarehouseCredential.BatchUpdate parameters: - description: Set to true to access beta operations via /api/v3. in: header name: EARLY-ACCESS required: false schema: type: string requestBody: content: application/json: schema: additionalProperties: false properties: items: items: $ref: '#/components/schemas/UpdateWarehouseCredentialInputWithPathParams' maxItems: 25 minItems: 1 type: array required: - items type: object responses: '200': content: application/json: schema: additionalProperties: false properties: items: items: $ref: '#/components/schemas/WarehouseCredential' type: array required: - items type: object description: OK '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' '500': $ref: '#/components/responses/InternalServerError' summary: Batch update WarehouseCredential tags: - WarehouseCredential x-bnch-rate-limit-tier: 3 /warehouse-credential:bulk-update: patch: description: Bulk update WarehouseCredential. operationId: WarehouseCredential.BulkUpdate parameters: - description: Set to true to access beta operations via /api/v3. in: header name: EARLY-ACCESS required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/BulkImport' responses: '202': content: application/json: schema: $ref: '#/components/schemas/AsyncTaskLink' description: Task started '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' '500': $ref: '#/components/responses/InternalServerError' summary: Bulk update WarehouseCredential tags: - WarehouseCredential x-bnch-rate-limit-tier: 2 /warehouse-credential:create-warehouse-credential: post: description: Create a new WarehouseCredential. Generates a username and password, provisions the credential in the warehouse, and returns the one-time password. operationId: WarehouseCredential.CreateWarehouseCredential parameters: - description: Set to true to access beta operations via /api/v3. in: header name: EARLY-ACCESS required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateWarehouseCredentialCustomMethodInput' responses: '200': content: application/json: schema: $ref: '#/components/schemas/CreateWarehouseCredentialOutput' description: OK '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/TooManyRequests' '500': $ref: '#/components/responses/InternalServerError' summary: Create a new WarehouseCredential. Generates a username and password, provisions the credential in the warehouse, and returns the one-time password. tags: - WarehouseCredential x-bnch-rate-limit-tier: 4 components: parameters: pageSize: description: Number of results to return. Defaults to 50, maximum of 100. in: query name: pageSize schema: type: integer createdAt.gte: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created at or after the specified time. e.g. >= 2017-04-30. in: query name: createdAt.gte schema: format: datetime type: string modifiedAt.gt: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified after the specified time. e.g. > 2017-04-30. in: query name: modifiedAt.gt schema: format: datetime type: string modifiedAt.lte: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified at or before the specified time. e.g. <= 2017-04-30. in: query name: modifiedAt.lte schema: format: datetime type: string id.anyOf: description: Restricts results to those matching any of the specified IDs. Comma-separated list. explode: false in: query name: id.anyOf schema: items: type: string maxItems: 100 type: array omit: description: Comma-separated list of top-level fields to omit from each returned item. Cannot overlap with returning. explode: false in: query name: omit schema: items: type: string type: array modifiedAt.lt: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified before the specified time. e.g. < 2017-04-30. in: query name: modifiedAt.lt schema: format: datetime type: string createdAt.gt: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created after the specified time. e.g. > 2017-04-30. in: query name: createdAt.gt schema: format: datetime type: string createdAt.lt: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created before the specified time. e.g. < 2017-04-30. in: query name: createdAt.lt schema: format: datetime type: string returning: description: Comma-separated list of top-level fields to include in each returned item. Cannot overlap with omit. explode: false in: query name: returning schema: items: type: string type: array userId.anyOf: description: Restricts results to those associated with any of the specified user API IDs. Comma-separated list. explode: false in: query name: userId.anyOf schema: items: type: string maxItems: 100 type: array nextToken: description: Token for pagination in: query name: nextToken schema: type: string modifiedAt.gte: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified at or after the specified time. e.g. >= 2017-04-30. in: query name: modifiedAt.gte schema: format: datetime type: string createdAt.lte: description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created at or before the specified time. e.g. <= 2017-04-30. in: query name: createdAt.lte schema: format: datetime type: string schemas: UpdateWarehouseCredentialInput: additionalProperties: false properties: revoked: description: Indicates whether or not the WarehouseCredential has been revoked. When a WarehouseCredential is revoked, the credentials are deleted in the warehouse and can not be reactivated. The only valid value for this field is `true`. type: boolean required: - revoked type: object WarehouseCredentialPaginatedList: additionalProperties: false properties: items: items: $ref: '#/components/schemas/WarehouseCredential' type: array nextToken: type: string type: object InternalServerError: properties: detail: type: - 'null' - string - object errorId: type: string instance: type: string status: type: integer title: type: - 'null' - string type: type: string required: - type - title - detail - status - instance type: object CreateWarehouseCredentialCustomMethodInput: additionalProperties: false properties: expiresAt: description: The time after which new connections using the username/password will not be permitted. Upon expiration, currently open connections are not terminated. format: datetime type: - 'null' - string label: description: An optional label defined by the user who created the WarehouseCredential. type: - 'null' - string type: object AsyncTaskLink: properties: pollingUri: format: uri type: string taskId: type: string type: object BulkImport: example: fileId: scrfile_jdf8BV24kLmN properties: fileId: description: The API ID of the scratch file (`scrfile_XXXXXXXX`) containing the items to import. The referenced file must be a scratch file whose upload has completed successfully. type: string required: - fileId type: object UpdateWarehouseCredentialInputWithPathParams: additionalProperties: false properties: id: type: string revoked: description: Indicates whether or not the WarehouseCredential has been revoked. When a WarehouseCredential is revoked, the credentials are deleted in the warehouse and can not be reactivated. The only valid value for this field is `true`. type: boolean required: - id - revoked type: object PrincipalRef: properties: __typename: type: string id: format: api_id type: string type: object WarehouseCredential: description: 'Represents credentials for connecting to Benchling''s data warehouse, enabling users to query data using SQL tools like database clients or BI platforms. This includes all warehouse login types: user-generated Direct Access credentials, as well as temporary Insights and Agent credentials. Each WarehouseCredential is tied to a specific Benchling `user` whose permissions determine what data is accessible through those credentials. Credentials can have an optional `expiresAt` date for time-limited access and can be permanently disabled via the `revoked` flag. Once revoked, credentials cannot be reactivated. Users can create multiple credentials (up to a per-user limit) with different `label` values to distinguish between uses.' properties: __typename: type: string createdAt: format: datetime type: - 'null' - string expiresAt: description: 'The time after which new connections using the username/password will not be permitted. Upon expiration, currently open connections are not terminated.' format: datetime type: - 'null' - string id: type: string label: description: An optional label defined by the user who created the WarehouseCredential. type: - 'null' - string modifiedAt: format: datetime type: - 'null' - string revoked: description: 'Indicates whether or not the WarehouseCredential has been revoked. When a WarehouseCredential is revoked, the credentials are deleted in the warehouse and can not be reactivated.' type: boolean user: $ref: '#/components/schemas/PrincipalRef' description: The Benchling user whose permissions are used when creating the WarehouseCredential username: description: The username to connect to the warehouse. type: string type: object WarehouseCredentialRef: properties: __typename: type: string id: format: api_id type: string type: object CreateWarehouseCredentialOutput: description: 'Output of the create warehouse credential custom method. Contains the created credential and the one-time password that must be saved by the caller.' properties: password: description: 'The generated password for the warehouse credential. This value is only returned once at creation time and cannot be retrieved again.' type: string warehouseCredential: $ref: '#/components/schemas/WarehouseCredentialRef' description: The created WarehouseCredential. type: object GeneralError: properties: detail: type: - 'null' - string - object instance: type: string status: type: integer title: type: - 'null' - string type: type: string required: - type - title - detail - status - instance type: object responses: TooManyRequests: content: application/problem+json: schema: $ref: '#/components/schemas/GeneralError' description: Too Many Requests NotFound: content: application/problem+json: schema: $ref: '#/components/schemas/GeneralError' description: Not Found BadRequest: content: application/problem+json: schema: $ref: '#/components/schemas/GeneralError' description: Bad Request Forbidden: content: application/problem+json: schema: $ref: '#/components/schemas/GeneralError' description: Forbidden InternalServerError: content: application/problem+json: schema: $ref: '#/components/schemas/InternalServerError' description: Internal Server Error securitySchemes: basicApiKeyAuth: description: Use issued API key for standard access to the API scheme: basic type: http basicClientIdSecretAuth: description: Auth used as part of client credentials OAuth flow prior to receiving a bearer token. scheme: basic type: http oAuth: description: OAuth2 Client Credentials flow intended for service access flows: clientCredentials: scopes: {} tokenUrl: /oauth/token type: oauth2