openapi: 3.2.0 info: contact: name: Identity Platform API url: https://github.com/canonical/identity-platform-api description: REST API for the Admin UI service license: name: AGPL-3.0 url: https://github.com/canonical/identity-platform-api/blob/main/LICENSE title: Identity Platform Roles Service API version: '0.1' tags: - name: RolesService paths: /api/v0/roles: get: operationId: RolesService_ListRoles responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesListRolesResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service list roles x-summary-source: derived post: operationId: RolesService_CreateRole requestBody: content: application/json: schema: $ref: '#/components/schemas/rolesRole' required: true x-originalParamName: role responses: '201': content: application/json: schema: $ref: '#/components/schemas/rolesCreateRoleResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service create role x-summary-source: derived /api/v0/roles/{id}: delete: operationId: RolesService_RemoveRole parameters: - in: path name: id required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesRemoveRoleResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service remove role x-summary-source: derived get: operationId: RolesService_GetRole parameters: - in: path name: id required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesGetRoleResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Not found default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service get role x-summary-source: derived patch: operationId: RolesService_UpdateRole parameters: - in: path name: id required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/rolesRole' required: true x-originalParamName: role responses: '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden '501': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Not implemented default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service update role x-summary-source: derived /api/v0/roles/{id}/entitlements: get: operationId: RolesService_ListRoleEntitlements parameters: - in: path name: id required: true schema: type: string - description: Base64 encoded pagination info in: header name: X-Token-Pagination schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesListRoleEntitlementsResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service list role entitlements x-summary-source: derived patch: operationId: RolesService_UpdateRoleEntitlements parameters: - in: path name: id required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/typesPermissions' required: true x-originalParamName: entitlementsPatchReq responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesUpdateRoleEntitlementsResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service update role entitlements x-summary-source: derived /api/v0/roles/{id}/entitlements/{entitlementId}: delete: operationId: RolesService_RemoveRoleEntitlement parameters: - in: path name: id required: true schema: type: string - in: path name: entitlementId required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesRemoveRoleEntitlementResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service remove role entitlement x-summary-source: derived /api/v0/roles/{id}/groups: get: operationId: RolesService_GetRoleGroups parameters: - in: path name: id required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/rolesGetRoleGroupsResp' description: '' '401': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Forbidden default: content: application/json: schema: $ref: '#/components/schemas/typesErrorResponse' description: Internal server error tags: - RolesService summary: Roles service get role groups x-summary-source: derived components: schemas: rolesGetRoleGroupsResp: properties: data: items: type: string type: array message: type: string meta: $ref: '#/components/schemas/typesPagination' status: format: int32 type: integer type: object typesPermissions: properties: updates: items: $ref: '#/components/schemas/typesPermission' type: array type: object rolesCreateRoleResp: properties: data: items: $ref: '#/components/schemas/rolesRole' type: array message: type: string meta: $ref: '#/components/schemas/typesPagination' status: format: int32 type: integer type: object rolesListRolesResp: properties: data: items: type: string type: array message: type: string meta: $ref: '#/components/schemas/typesPagination' status: format: int32 type: integer type: object rolesGetRoleResp: properties: data: items: $ref: '#/components/schemas/rolesRole' type: array message: type: string meta: $ref: '#/components/schemas/typesPagination' status: format: int32 type: integer type: object rolesRole: properties: id: type: string name: type: string type: object typesErrorResponse: properties: message: type: string status: format: int32 type: integer type: object rolesRemoveRoleResp: properties: message: type: string status: format: int32 type: integer type: object rolesListRoleEntitlementsResp: properties: data: items: type: string type: array message: type: string status: format: int32 type: integer type: object typesPermission: properties: object: type: string relation: type: string type: object rolesUpdateRoleEntitlementsResp: properties: message: type: string status: format: int32 type: integer type: object typesPagination: properties: next: type: string pageToken: type: string prev: type: string size: format: int32 type: integer type: object rolesRemoveRoleEntitlementResp: properties: message: type: string status: format: int32 type: integer type: object securitySchemes: OAuth2: flows: authorizationCode: authorizationUrl: https://example.com/oauth/authorize scopes: email: '' openid: '' profile: '' tokenUrl: https://example.com/oauth/token type: oauth2 externalDocs: description: REST API for the Admin UI service url: https://github.com/canonical/identity-platform-admin-ui/blob/main/API.md