openapi: 3.2.0 info: title: Confluent Cloud Shared Tokens (cdx/v1) API version: '' x-api-id: 46234552-5833-42eb-ba0f-883ad3f70d2b x-audience: external-public x-logo: url: https://assets.confluent.io/m/1661ef5e4ff82d3d/ description: '# Introduction Note This documents the collection of Confluent Cloud APIs.' servers: - url: https://api.confluent.cloud description: Confluent Cloud API tags: - name: Shared Tokens (cdx/v1) description: '![General Availability](#section/Versioning/API-Lifecycle-Policy) Encrypted Token shared with consumer ## The Shared Tokens Model' paths: /cdx/v1/shared-tokens:resources: x-lifecycle-stage: General Availability x-self-access: true post: summary: Validate token to view shared resources description: '![General Availability](#section/Versioning/API-Lifecycle-Policy) Validate and decrypt the shared token and view token''s shared resources' requestBody: content: application/json: schema: allOf: - $ref: '#/components/schemas/cdx.v1.SharedToken' - type: object required: - token x-lifecycle-stage: General Availability x-self-access: true x-name: cdx.v1.SharedToken operationId: resourcesCdxV1SharedToken tags: - Shared Tokens (cdx/v1) security: - cloud-api-key: [] responses: '200': description: 'Consumer validates share token and view consumer resources before redeeming in the workflow ' content: application/json: schema: type: object properties: consumer_shared_resources: type: array items: $ref: '#/components/schemas/cdx.v1.ConsumerSharedResource' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthenticatedError' '403': $ref: '#/components/responses/UnauthorizedError' '404': $ref: '#/components/responses/NotFoundError' '409': $ref: '#/components/responses/ConflictError' '429': $ref: '#/components/responses/RateLimitError' '500': $ref: '#/components/responses/DefaultSystemError' /cdx/v1/shared-tokens:redeem: x-lifecycle-stage: General Availability x-self-access: true post: summary: Redeem token description: '![General Availability](#section/Versioning/API-Lifecycle-Policy) Redeem the shared token for shared topic and cluster access information' requestBody: content: application/json: schema: allOf: - $ref: '#/components/schemas/cdx.v1.RedeemTokenRequest' - type: object required: - token x-lifecycle-stage: General Availability x-self-access: true x-name: cdx.v1.SharedToken operationId: redeemCdxV1SharedToken tags: - Shared Tokens (cdx/v1) security: - cloud-api-key: [] responses: '200': description: 'Consumer redeems shared token ' content: application/json: schema: $ref: '#/components/schemas/cdx.v1.RedeemTokenResponse' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthenticatedError' '403': $ref: '#/components/responses/UnauthorizedError' '404': $ref: '#/components/responses/NotFoundError' '409': $ref: '#/components/responses/ConflictError' '429': $ref: '#/components/responses/RateLimitError' '500': $ref: '#/components/responses/DefaultSystemError' components: schemas: cdx.v1.SharedSubject: type: object description: The shared resource details required: - kind - subject properties: kind: description: The shared resource kind type: string enum: - Subject subject: type: string description: The subject name Error: type: object description: Describes a particular error encountered while performing an operation. properties: id: description: A unique identifier for this particular occurrence of the problem. type: string maxLength: 255 status: description: The HTTP status code applicable to this problem, expressed as a string value. type: string code: description: An application-specific error code, expressed as a string value. type: string title: description: A short, human-readable summary of the problem. It **SHOULD NOT** change from occurrence to occurrence of the problem, except for purposes of localization. type: string detail: description: A human-readable explanation specific to this occurrence of the problem. type: string source: type: object description: If this error was caused by a particular part of the API request, the source will point to the query string parameter or request body property that caused it. properties: pointer: description: A JSON Pointer [RFC6901] to the associated entity in the request document [e.g. "/spec" for a spec object, or "/spec/title" for a specific field]. type: string parameter: description: A string indicating which query parameter caused the error. type: string error_code: type: integer format: int32 message: type: - string - 'null' additionalProperties: false cdx.v1.SharedToken: type: object description: 'Encrypted Token shared with consumer ## The Shared Tokens Model ' properties: api_version: type: string enum: - cdx/v1 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - SharedToken id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string maxLength: 255 readOnly: true example: dlz-f3a90de metadata: allOf: - $ref: '#/components/schemas/ObjectMeta' - properties: self: example: https://api.confluent.cloud/cdx/v1/shared-tokens/st-12345 resource_name: example: crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/shared-token=st-12345 token: type: string description: The encrypted token cdx.v1.ConsumerSharedResource: type: object description: '`ConsumerSharedResource` object contains details of the data stream (topic, schema registry subjects, sharing metadata) that you received through Stream Sharing. ## The Consumer Shared Resources Model ' properties: api_version: type: string enum: - cdx/v1 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - ConsumerSharedResource id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string maxLength: 255 readOnly: true example: dlz-f3a90de metadata: allOf: - $ref: '#/components/schemas/ObjectMeta' - properties: self: example: https://api.confluent.cloud/cdx/v1/consumer-shared-resources/csr-12345 resource_name: example: crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/consumer-shared-resource=csr-12345 cloud: type: string description: The cloud service provider of the provider shared cluster. x-extensible-enum: - AWS - AZURE - GCP example: AWS x-immutable: true readOnly: true network_connection_types: type: array description: 'The network connection types of the provider shared cluster. If the shared cluster is on public internet, then the list will be empty ' items: $ref: '#/components/schemas/cdx.v1.ConnectionType' uniqueItems: true x-immutable: true readOnly: true display_name: type: string description: Consumer resource display name example: Stock Trades x-immutable: true readOnly: true description: type: string description: Description of consumer resource example: This topic provides realtime data for the orders placed through the website x-immutable: true readOnly: true tags: type: array items: type: string description: list of tags example: - recent - pending x-immutable: true readOnly: true schemas: type: array items: allOf: - $ref: '#/components/schemas/cdx.v1.Schema' - type: object description: List of schemas in JSON format. This field is work in progress and subject to changes. x-immutable: true readOnly: true organization_name: type: string description: Shared resource's organization name example: ABC Corp x-immutable: true readOnly: true organization_description: type: string description: Shared resource's organization description example: ABC Corp is the biggest online retailer x-immutable: true readOnly: true organization_contact: type: string format: email example: jane.doe@example.com description: Email of the shared resource's organization contact x-immutable: true readOnly: true logo_url: type: string format: uri description: Resource logo url example: https://confluent.cloud/api/cdx/v1/consumer-shared-resources/sr-123/images/logo x-immutable: true readOnly: true cdx.v1.Schema: type: object properties: subject: type: string description: Name of the subject example: User version: type: integer description: Version number format: int32 example: 1 id: type: integer description: Globally unique identifier of the schema format: int32 example: 100001 schema_type: type: string description: Schema type example: AVRO schema: type: string description: Schema definition string example: '{"schema": "{"type": "string"}"}' description: Schema cdx.v1.RedeemTokenResponse: type: object description: Share details for the consumer org or user properties: api_version: type: string enum: - cdx/v1 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - RedeemTokenResponse id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string maxLength: 255 readOnly: true example: dlz-f3a90de metadata: allOf: - $ref: '#/components/schemas/ObjectMeta' - properties: self: example: https://api.confluent.cloud/cdx/v1/redeem-token-responses/rtr-12345 resource_name: example: crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/redeem-token-response=rtr-12345 api_key: type: string description: The api key readOnly: true secret: type: string description: The api key secret x-redact: true readOnly: true kafka_bootstrap_url: type: string format: uri description: The kafka cluster bootstrap url example: SASL://pkc-xxxxx.us-west-2.aws.confluent.cloud:9092 x-immutable: true readOnly: true schema_registry_api_key: type: string description: The api key for schema registry readOnly: true schema_registry_secret: type: string description: The api key secret for schema registry x-redact: true readOnly: true schema_registry_url: type: string format: uri description: The schema registry endpoint url example: https://psrc-xxxxx.us-west-2.aws.confluent.cloud x-immutable: true readOnly: true resources: type: array minItems: 1 description: List of shared resources items: type: object discriminator: propertyName: kind mapping: Topic: '#/components/schemas/cdx.v1.SharedTopic' Group: '#/components/schemas/cdx.v1.SharedGroup' Subject: '#/components/schemas/cdx.v1.SharedSubject' oneOf: - $ref: '#/components/schemas/cdx.v1.SharedTopic' - $ref: '#/components/schemas/cdx.v1.SharedGroup' - $ref: '#/components/schemas/cdx.v1.SharedSubject' cdx.v1.SharedTopic: type: object description: The shared resource details required: - kind - topic properties: kind: description: The shared resource kind type: string enum: - Topic topic: type: string description: The topic name cdx.v1.ConnectionType: type: string description: Network connection type. x-extensible-enum: - PRIVATELINK example: PRIVATELINK cdx.v1.SharedGroup: type: object description: The shared consumer group required: - kind - group_prefix properties: kind: description: The resource kind type: string enum: - Group group_prefix: type: string description: The consumer group prefix cdx.v1.RedeemTokenRequest: type: object description: Redeem share with token request parameters properties: api_version: type: string enum: - cdx/v1 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - RedeemTokenRequest id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string maxLength: 255 readOnly: true example: dlz-f3a90de metadata: allOf: - $ref: '#/components/schemas/ObjectMeta' - properties: self: example: https://api.confluent.cloud/cdx/v1/redeem-token-requests/rtr-12345 resource_name: example: crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/redeem-token-request=rtr-12345 token: type: string description: The encrypted token aws_account: type: string description: Consumer's AWS account ID for PrivateLink access. example: '000000000000' azure_subscription: type: string description: Consumer's Azure subscription ID for PrivateLink access. example: 00000000-0000-0000-0000-000000000000 gcp_project: type: string minLength: 1 description: Consumer's GCP project ID for Private Service Connect access. ObjectMeta: description: ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create. required: - self properties: self: description: Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time type: string format: uri readOnly: true example: https://api.confluent.cloud/v2/kafka-clusters/lkc-f3a90de resource_name: description: Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name type: string format: uri readOnly: true example: crn://confluent.cloud/kafka=lkc-f3a90de created_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was created. It is represented in RFC3339 format and is in UTC. updated_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC. deleted_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC. readOnly: true Failure: type: object description: Provides information about problems encountered while performing an operation. required: - errors properties: errors: description: List of errors which caused this operation to fail type: array items: $ref: '#/components/schemas/Error' uniqueItems: true responses: UnauthenticatedError: x-summary: Unauthorized description: The request lacks valid authentication credentials for this resource. headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. WWW-Authenticate: schema: type: string description: The unique identifier for the API request. example: Basic error="invalid_key", error_description="The API Key is invalid" content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '401' code: user_unauthenticated title: Authentication Required detail: Valid authentication credentials must be provided UnauthorizedError: x-summary: Forbidden description: The access credentials were considered insufficient to grant access headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '403' code: user_unauthorized title: User Access Unauthorized detail: The user 'mcfly' is not allowed to access the 'delorean' resource without the 'plutonium' role. NotFoundError: description: Not Found headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '404' title: Not Found ConflictError: x-summary: Conflict description: The request is in conflict with the current server state headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. Location: schema: type: string format: uri example: https://api.confluent.cloud/{object}/{id} description: Resource URI of conflicting resource content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '409' code: resource_already_exists title: Resource Already exists detail: The entitlement '91e3e86f-fca6-4f14-98f5-a48e64113ce2' already exists. DefaultSystemError: description: Oops, something went wrong! headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '500' code: out_of_gas title: DeLorean Out Of Gas detail: The DeLorean has run out of gas, but Doc Brown will fill 'er up for you asap BadRequestError: description: Bad Request headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '400' code: invalid_filter title: Invalid Filter detail: The 'delorean' resource can't be filtered by 'num_doors' source: parameter: num_doors RateLimitError: description: Rate Limit Exceeded headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. X-RateLimit-Limit: schema: type: integer description: The maximum number of requests you're permitted to make per time period. X-RateLimit-Remaining: schema: type: integer description: The number of requests remaining in the current rate limit window. X-RateLimit-Reset: schema: type: integer description: "The relative time in seconds until the current rate-limit window resets. \n \n**Important:** This differs from Github and Twitter's same-named header which uses UTC epoch seconds. We use relative time to avoid client/server time synchronization issues." Retry-After: schema: type: integer description: The number of seconds to wait until the rate limit window resets. Only sent when the rate limit is reached. securitySchemes: cloud-api-key: type: http scheme: basic description: Authenticate with Cloud API Keys using HTTP Basic Auth. Treat the Cloud API Key ID as the username and Cloud API Key Secret as the password. confluent-sts-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} global-api-key: type: http scheme: basic description: Authenticate with Global API Keys using HTTP Basic Auth. Treat the Global API Key ID as the username and Global API Key Secret as the password. resource-api-key: type: http scheme: basic description: Authenticate with resource-specific API Keys using HTTP Basic Auth. Treat the resource-specific API Key ID as the username and resource-specific API Key Secret as the password. external-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} oauth: type: oauth2 description: Authenticate with OAuth 2.0. Currently this is only supported for partner APIs. flows: clientCredentials: tokenUrl: /oauth2/token scopes: partner:alter: enables partners to alter entitlements partner:create: enables partners to create entitlements and signup on behalf of customers partner:delete: enables partners to delete entitlements and organizations partner:describe: enables partners to read and list entitlements and organizations x-tagGroups: - name: Identity Access Management (v2) tags: - API Keys (iam/v2) - Users (iam/v2) - Service Accounts (iam/v2) - Invitations (iam/v2) - IP Groups (iam/v2) - IP Filters (iam/v2) - IP Filter Summaries (iam/v2) - Role Bindings (iam/v2) - Identity Providers (iam/v2) - Jwks (iam/v2) - Identity Pools (iam/v2) - Group Mappings (iam/v2/sso) - Certificate Authorities (iam/v2) - Certificate Identity Pools (iam/v2) - name: Org API (v2) tags: - Environments (org/v2) - Organizations (org/v2) - name: Notifications API (v1) tags: - Subscriptions (notifications/v1) - Integrations (notifications/v1) - Notification Types (notifications/v1) - Resource Preferences (notifications/v1) - Resource Subscriptions (notifications/v1) - User Notifications (notifications/v1) - name: Cluster Mgmt for Kafka (v2) tags: - Clusters (cmk/v2) - name: Cluster Mgmt for ksqlDB (v2) tags: - Clusters (ksqldbcm/v2) - name: Connect API (v1) tags: - Connectors (connect/v1) - Lifecycle (connect/v1) - Status (connect/v1) - Managed Connector Plugins (connect/v1) - Offsets (connect/v1) - Custom Connector Plugins (connect/v1) - Presigned Urls (connect/v1) - Custom Connector Runtimes (connect/v1) - name: Connect Artifact Management (v1) tags: - Connect Artifacts (cam/v1) - Presigned Urls (cam/v1) - name: Kafka API (v3) tags: - Cluster (v3) - Configs (v3) - ACL (v3) - Consumer Group (v3) - Partition (v3) - Topic (v3) - Records (v3) - Cluster Linking (v3) - Share Group (v3) - Streams Group (v3) - name: Service Quota API (v1) tags: - Applied Quotas (service-quota/v1) - Scopes (service-quota/v1) - name: Partner API (v2) tags: - Entitlements (partner/v2) - Organizations (partner/v2) - Signup (partner/v2) - name: Cluster Mgmt for Schema Registry (v2) tags: - Regions (srcm/v2) - Clusters (srcm/v2) - name: Cluster Mgmt for Schema Registry (v3) tags: - Clusters (srcm/v3) - name: Schema Registry API (v1) tags: - Compatibility (v1) - Config (v1) - Contexts (v1) - Exporters (v1) - Modes (v1) - Schemas (v1) - Subjects (v1) - Key Encryption Keys (v1) - Data Encryption Keys (v1) - name: Catalog API (v1) tags: - Entity (v1) - Search (v1) - Types (v1) - name: Stream Sharing API (v1) tags: - Provider Shared Resources (cdx/v1) - Provider Shares (cdx/v1) - Consumer Shared Resources (cdx/v1) - Consumer Shares (cdx/v1) - Shared Tokens (cdx/v1) - Opt Ins (cdx/v1) - name: Networking (v1) tags: - Networks (networking/v1) - Peerings (networking/v1) - Transit Gateway Attachments (networking/v1) - Private Link Accesses (networking/v1) - Network Link Services (networking/v1) - Network Link Endpoints (networking/v1) - Network Link Service Associations (networking/v1) - IP Addresses (networking/v1) - Private Link Attachments (networking/v1) - Private Link Attachment Connections (networking/v1) - DNS Forwarders (networking/v1) - Access Points (networking/v1) - DNS Records (networking/v1) - Gateways (networking/v1) - name: Security Token Service (v1) tags: - OAuth Tokens (sts/v1) - name: Kafka Quota (v1) tags: - Client Quotas (kafka-quotas/v1) - name: Bring Your Own Key (BYOK) Management (v1) tags: - Keys (byok/v1) - name: Billing API (v1) tags: - Costs (billing/v1) - name: Compute Pool Mgmt for Flink (v2) tags: - Compute Pools (fcpm/v2) - Regions (fcpm/v2) - Org Compute Pool Configs (fcpm/v2) - name: SQL API (v1) tags: - Statements (sql/v1) - Statement Results (sql/v1) - Statement Exceptions (sql/v1) - Connections (sql/v1) - Agents (sql/v1) - Tools (sql/v1) - Materialized Tables (sql/v1) - Materialized Table Versions (sql/v1) - name: Provider Integration Management (v1) tags: - Integrations (pim/v1) - name: Provider Integration Management (v2) tags: - Integrations (pim/v2) - name: Artifact API (v1) tags: - Flink Artifacts (artifact/v1) - Presigned Urls (artifact/v1) - Flink Artifact Versions (artifact/v1) - name: Custom Code Logging API (v1) tags: - Custom Code Loggings (ccl/v1) - name: Tableflow (v1) tags: - Regions (tableflow/v1) - Tableflow Topics (tableflow/v1) - Catalog Integrations (tableflow/v1) - name: Custom Connect Plugin Management (v1) tags: - Custom Connect Plugins (ccpm/v1) - Presigned Urls (ccpm/v1) - Custom Connect Plugin Versions (ccpm/v1) - name: Unified Stream Manager (v1) tags: - Kafka Clusters (usm/v1) - Connect Clusters (usm/v1) - name: Endpoint (v1) tags: - Endpoints (endpoint/v1) - name: Real Time Context Engine (v1) tags: - Rtce Topics (rtce/v1) - Regions (rtce/v1) - name: Analytics (v1alpha1) tags: - Statements (query/v1alpha1)