openapi: 3.2.0 info: contact: email: lxd@lists.canonical.com name: LXD upstream url: https://github.com/canonical/lxd description: 'This is the REST API used by all LXD clients. Internal endpoints aren''t included in this documentation. The LXD API is available over both a local unix+http and remote https API. Authentication for local users relies on group membership and access to the unix socket. For remote users, the default authentication method is TLS client.' license: name: AGPL-3.0-only url: https://www.gnu.org/licenses/agpl-3.0.en.html title: LXD external REST Oidc Sessions API version: '1.0' tags: - name: oidc_sessions paths: /1.0/auth/oidc-sessions: get: description: Returns a list of OIDC sessions (URLs). operationId: oidc_sessions_get parameters: - description: Email address of user example: jane.doe@example.com in: query name: email schema: type: string responses: '200': description: API endpoints content: application/json: schema: description: Sync response properties: metadata: description: List of endpoints example: "[\n \"/1.0/auth/oidc-sessions/01993cf9-7cf5-7ecb-8946-7736875a8322\",\n \"/1.0/auth/oidc-sessions/01993cf9-a97e-76ef-9382-4434fee8b469\"\n]" items: type: string type: array status: description: Status description example: Success type: string status_code: description: Status code example: 200 type: integer type: description: Response type example: sync type: string type: object '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get OIDC session URLs tags: - oidc_sessions /1.0/auth/oidc-sessions/{id}: delete: description: Deletes the OIDC session operationId: oidc_session_delete responses: '200': $ref: '#/components/responses/EmptySyncResponse' '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Delete an OIDC session tags: - oidc_sessions get: description: Gets a specific OIDC session. operationId: oidc_session_get responses: '200': description: '' content: application/json: schema: description: Sync response properties: metadata: $ref: '#/components/schemas/OIDCSession' status: description: Status description example: Success type: string status_code: description: Status code example: 200 type: integer type: description: Response type example: sync type: string type: object '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get the OIDC session tags: - oidc_sessions /1.0/auth/oidc-sessions?recursion=1: get: description: Returns a list of OIDC sessions. operationId: oidc_sessions_get_recursion1 parameters: - description: Email address of user example: jane.doe@example.com in: query name: email schema: type: string responses: '200': description: API endpoints content: application/json: schema: description: Sync response properties: metadata: description: List of auth groups items: $ref: '#/components/schemas/OIDCSession' type: array status: description: Status description example: Success type: string status_code: description: Status code example: 200 type: integer type: description: Response type example: sync type: string type: object '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get the OIDC sessions tags: - oidc_sessions components: schemas: OIDCSession: properties: created_at: description: CreatedAt is when the session was started. example: '2025-09-11T15:14:04+00:00' format: date-time type: string x-go-name: CreatedAt email: description: Email is the email of the user that holds the session. example: jane.doe@example.com type: string x-go-name: Email expires_at: description: ExpiresAt is when the session will expire. example: '2025-09-11T15:14:04+00:00' format: date-time type: string x-go-name: ExpiresAt ip: description: IP is the IP address of the user that holds the session. example: 10.21.242.46 type: string x-go-name: IP user_agent: description: UserAgent is the UserAgent of the user that holds the session. example: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 type: string x-go-name: UserAgent username: description: Username is the name of the user that holds the session. example: Jane Doe type: string x-go-name: Username uuid: description: UUID is the session UUID. example: 01993985-7b5d-7a7e-afeb-23e8f6a15cf4 type: string x-go-name: UUID title: OIDCSession contains session details for a current login. type: object x-go-package: github.com/canonical/lxd/shared/api responses: EmptySyncResponse: description: Empty sync response content: application/json: schema: properties: status: example: Success type: string x-go-name: Status status_code: example: 200 format: int64 type: integer x-go-name: StatusCode type: example: sync type: string x-go-name: Type type: object InternalServerError: description: Internal Server Error content: application/json: schema: properties: error: example: internal server error type: string x-go-name: Error error_code: example: 500 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object BadRequest: description: Bad Request content: application/json: schema: properties: error: example: bad request type: string x-go-name: Error error_code: example: 400 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object Forbidden: description: Forbidden content: application/json: schema: properties: error: example: not authorized type: string x-go-name: Error error_code: example: 403 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object