openapi: 3.2.0 info: title: Confluent Cloud OAuth Tokens (sts/v1) API version: '' x-api-id: 46234552-5833-42eb-ba0f-883ad3f70d2b x-audience: external-public x-logo: url: https://assets.confluent.io/m/1661ef5e4ff82d3d/ description: '# Introduction Note This documents the collection of Confluent Cloud APIs.' servers: - url: https://api.confluent.cloud description: Confluent Cloud API tags: - name: OAuth Tokens (sts/v1) description: '![General Availability](#section/Versioning/API-Lifecycle-Policy) OAuth Token is a JSON Web Token (JWT) that enables the use of external identities to access Confluent Cloud APIs' paths: /sts/v1/oauth2/token: x-lifecycle-stage: General Availability x-self-access: true post: description: '![General Availability](#section/Versioning/API-Lifecycle-Policy) Use this operation to exchange an access token (JWT) issued by an external identity provider for an access token (JWT) issued by Confluent.This enables the use of external identities to access Confluent Cloud APIs.' requestBody: content: application/x-www-form-urlencoded: schema: allOf: - $ref: '#/components/schemas/sts.v1.TokenExchangeRequest' - type: object required: - subject_token - grant_type - identity_pool_id - subject_token_type - requested_token_type x-lifecycle-stage: General Availability x-self-access: true x-name: sts.v1.OauthToken operationId: exchangeStsV1OauthToken summary: Exchange an OAuth Token tags: - OAuth Tokens (sts/v1) responses: '200': description: 'access token used to access public control plane api ' content: application/json: schema: $ref: '#/components/schemas/sts.v1.TokenExchangeReply' '400': $ref: '#/components/responses/BadRequestError' '429': $ref: '#/components/responses/RateLimitError' '500': $ref: '#/components/responses/DefaultSystemError' components: schemas: Error: type: object description: Describes a particular error encountered while performing an operation. properties: id: description: A unique identifier for this particular occurrence of the problem. type: string maxLength: 255 status: description: The HTTP status code applicable to this problem, expressed as a string value. type: string code: description: An application-specific error code, expressed as a string value. type: string title: description: A short, human-readable summary of the problem. It **SHOULD NOT** change from occurrence to occurrence of the problem, except for purposes of localization. type: string detail: description: A human-readable explanation specific to this occurrence of the problem. type: string source: type: object description: If this error was caused by a particular part of the API request, the source will point to the query string parameter or request body property that caused it. properties: pointer: description: A JSON Pointer [RFC6901] to the associated entity in the request document [e.g. "/spec" for a spec object, or "/spec/title" for a specific field]. type: string parameter: description: A string indicating which query parameter caused the error. type: string error_code: type: integer format: int32 message: type: - string - 'null' additionalProperties: false sts.v1.TokenExchangeRequest: type: object description: token exchange request parameters properties: api_version: type: string enum: - sts/v1 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - TokenExchangeRequest id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string maxLength: 255 readOnly: true example: dlz-f3a90de metadata: allOf: - $ref: '#/components/schemas/ObjectMeta' - properties: self: example: https://api.confluent.cloud/sts/v1/token-exchange-requests/ter-12345 resource_name: example: crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/token-exchange-request=ter-12345 grant_type: type: string x-extensible-enum: - urn:ietf:params:oauth:grant-type:token-exchange description: 'The grant type. Must be urn:ietf:params:oauth:grant-type:token-exchange, which indicates a token exchange. ' example: urn:ietf:params:oauth:grant-type:token-exchange subject_token: type: string description: Confluent Cloud only accepts JSON Web Token (JWT) access tokens from customer identity provider example: test_jwt_token identity_pool_id: type: string description: 'Identity pool is a group of external identities that are assigned a certain level of access based on policy ' example: pool_1 subject_token_type: type: string x-extensible-enum: - urn:ietf:params:oauth:token-type:jwt description: 'An identifier for the type of requested security token. Supported values is urn:ietf:params:oauth:token-type:jwt. ' example: urn:ietf:params:oauth:token-type:jwt requested_token_type: type: string x-extensible-enum: - urn:ietf:params:oauth:token-type:access_token description: 'An identifier for the type of requested security token. Supported values is urn:ietf:params:oauth:token-type:access_token. ' example: urn:ietf:params:oauth:token-type:access_token expires_in: type: integer format: int32 description: 'The amount of time, in seconds, between the time when the access token was issued and the time when the access token will expire ' default: 900 maximum: 900 sts.v1.TokenExchangeReply: type: object description: token exchange response required: - access_token - issued_token_type - token_type - expires_in properties: access_token: type: string description: 'An JWT access token, issued by Confluent, in response to the token exchange request. Client application could use the access token to access confluent public api ' issued_token_type: type: string x-extensible-enum: - urn:ietf:params:oauth:token-type:access_token description: The token type. Always matches the value of requested_token_type from the request. example: urn:ietf:params:oauth:token-type:access_token token_type: type: string x-extensible-enum: - Bearer description: Indicates the token type value. The only type that Confluent supports is Bearer example: Bearer expires_in: type: integer format: int32 description: The length of time, in seconds, that the access token is valid. example: 3600 ObjectMeta: description: ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create. required: - self properties: self: description: Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time type: string format: uri readOnly: true example: https://api.confluent.cloud/v2/kafka-clusters/lkc-f3a90de resource_name: description: Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name type: string format: uri readOnly: true example: crn://confluent.cloud/kafka=lkc-f3a90de created_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was created. It is represented in RFC3339 format and is in UTC. updated_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC. deleted_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC. readOnly: true Failure: type: object description: Provides information about problems encountered while performing an operation. required: - errors properties: errors: description: List of errors which caused this operation to fail type: array items: $ref: '#/components/schemas/Error' uniqueItems: true responses: DefaultSystemError: description: Oops, something went wrong! headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '500' code: out_of_gas title: DeLorean Out Of Gas detail: The DeLorean has run out of gas, but Doc Brown will fill 'er up for you asap BadRequestError: description: Bad Request headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '400' code: invalid_filter title: Invalid Filter detail: The 'delorean' resource can't be filtered by 'num_doors' source: parameter: num_doors RateLimitError: description: Rate Limit Exceeded headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. X-RateLimit-Limit: schema: type: integer description: The maximum number of requests you're permitted to make per time period. X-RateLimit-Remaining: schema: type: integer description: The number of requests remaining in the current rate limit window. X-RateLimit-Reset: schema: type: integer description: "The relative time in seconds until the current rate-limit window resets. \n \n**Important:** This differs from Github and Twitter's same-named header which uses UTC epoch seconds. We use relative time to avoid client/server time synchronization issues." Retry-After: schema: type: integer description: The number of seconds to wait until the rate limit window resets. Only sent when the rate limit is reached. securitySchemes: cloud-api-key: type: http scheme: basic description: Authenticate with Cloud API Keys using HTTP Basic Auth. Treat the Cloud API Key ID as the username and Cloud API Key Secret as the password. confluent-sts-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} global-api-key: type: http scheme: basic description: Authenticate with Global API Keys using HTTP Basic Auth. Treat the Global API Key ID as the username and Global API Key Secret as the password. resource-api-key: type: http scheme: basic description: Authenticate with resource-specific API Keys using HTTP Basic Auth. Treat the resource-specific API Key ID as the username and resource-specific API Key Secret as the password. external-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} oauth: type: oauth2 description: Authenticate with OAuth 2.0. Currently this is only supported for partner APIs. flows: clientCredentials: tokenUrl: /oauth2/token scopes: partner:alter: enables partners to alter entitlements partner:create: enables partners to create entitlements and signup on behalf of customers partner:delete: enables partners to delete entitlements and organizations partner:describe: enables partners to read and list entitlements and organizations x-tagGroups: - name: Identity Access Management (v2) tags: - API Keys (iam/v2) - Users (iam/v2) - Service Accounts (iam/v2) - Invitations (iam/v2) - IP Groups (iam/v2) - IP Filters (iam/v2) - IP Filter Summaries (iam/v2) - Role Bindings (iam/v2) - Identity Providers (iam/v2) - Jwks (iam/v2) - Identity Pools (iam/v2) - Group Mappings (iam/v2/sso) - Certificate Authorities (iam/v2) - Certificate Identity Pools (iam/v2) - name: Org API (v2) tags: - Environments (org/v2) - Organizations (org/v2) - name: Notifications API (v1) tags: - Subscriptions (notifications/v1) - Integrations (notifications/v1) - Notification Types (notifications/v1) - Resource Preferences (notifications/v1) - Resource Subscriptions (notifications/v1) - User Notifications (notifications/v1) - name: Cluster Mgmt for Kafka (v2) tags: - Clusters (cmk/v2) - name: Cluster Mgmt for ksqlDB (v2) tags: - Clusters (ksqldbcm/v2) - name: Connect API (v1) tags: - Connectors (connect/v1) - Lifecycle (connect/v1) - Status (connect/v1) - Managed Connector Plugins (connect/v1) - Offsets (connect/v1) - Custom Connector Plugins (connect/v1) - Presigned Urls (connect/v1) - Custom Connector Runtimes (connect/v1) - name: Connect Artifact Management (v1) tags: - Connect Artifacts (cam/v1) - Presigned Urls (cam/v1) - name: Kafka API (v3) tags: - Cluster (v3) - Configs (v3) - ACL (v3) - Consumer Group (v3) - Partition (v3) - Topic (v3) - Records (v3) - Cluster Linking (v3) - Share Group (v3) - Streams Group (v3) - name: Service Quota API (v1) tags: - Applied Quotas (service-quota/v1) - Scopes (service-quota/v1) - name: Partner API (v2) tags: - Entitlements (partner/v2) - Organizations (partner/v2) - Signup (partner/v2) - name: Cluster Mgmt for Schema Registry (v2) tags: - Regions (srcm/v2) - Clusters (srcm/v2) - name: Cluster Mgmt for Schema Registry (v3) tags: - Clusters (srcm/v3) - name: Schema Registry API (v1) tags: - Compatibility (v1) - Config (v1) - Contexts (v1) - Exporters (v1) - Modes (v1) - Schemas (v1) - Subjects (v1) - Key Encryption Keys (v1) - Data Encryption Keys (v1) - name: Catalog API (v1) tags: - Entity (v1) - Search (v1) - Types (v1) - name: Stream Sharing API (v1) tags: - Provider Shared Resources (cdx/v1) - Provider Shares (cdx/v1) - Consumer Shared Resources (cdx/v1) - Consumer Shares (cdx/v1) - Shared Tokens (cdx/v1) - Opt Ins (cdx/v1) - name: Networking (v1) tags: - Networks (networking/v1) - Peerings (networking/v1) - Transit Gateway Attachments (networking/v1) - Private Link Accesses (networking/v1) - Network Link Services (networking/v1) - Network Link Endpoints (networking/v1) - Network Link Service Associations (networking/v1) - IP Addresses (networking/v1) - Private Link Attachments (networking/v1) - Private Link Attachment Connections (networking/v1) - DNS Forwarders (networking/v1) - Access Points (networking/v1) - DNS Records (networking/v1) - Gateways (networking/v1) - name: Security Token Service (v1) tags: - OAuth Tokens (sts/v1) - name: Kafka Quota (v1) tags: - Client Quotas (kafka-quotas/v1) - name: Bring Your Own Key (BYOK) Management (v1) tags: - Keys (byok/v1) - name: Billing API (v1) tags: - Costs (billing/v1) - name: Compute Pool Mgmt for Flink (v2) tags: - Compute Pools (fcpm/v2) - Regions (fcpm/v2) - Org Compute Pool Configs (fcpm/v2) - name: SQL API (v1) tags: - Statements (sql/v1) - Statement Results (sql/v1) - Statement Exceptions (sql/v1) - Connections (sql/v1) - Agents (sql/v1) - Tools (sql/v1) - Materialized Tables (sql/v1) - Materialized Table Versions (sql/v1) - name: Provider Integration Management (v1) tags: - Integrations (pim/v1) - name: Provider Integration Management (v2) tags: - Integrations (pim/v2) - name: Artifact API (v1) tags: - Flink Artifacts (artifact/v1) - Presigned Urls (artifact/v1) - Flink Artifact Versions (artifact/v1) - name: Custom Code Logging API (v1) tags: - Custom Code Loggings (ccl/v1) - name: Tableflow (v1) tags: - Regions (tableflow/v1) - Tableflow Topics (tableflow/v1) - Catalog Integrations (tableflow/v1) - name: Custom Connect Plugin Management (v1) tags: - Custom Connect Plugins (ccpm/v1) - Presigned Urls (ccpm/v1) - Custom Connect Plugin Versions (ccpm/v1) - name: Unified Stream Manager (v1) tags: - Kafka Clusters (usm/v1) - Connect Clusters (usm/v1) - name: Endpoint (v1) tags: - Endpoints (endpoint/v1) - name: Real Time Context Engine (v1) tags: - Rtce Topics (rtce/v1) - Regions (rtce/v1) - name: Analytics (v1alpha1) tags: - Statements (query/v1alpha1)