openapi: 3.2.0 info: title: Confluent Cloud Signup (partner/v2) API version: '' x-api-id: 46234552-5833-42eb-ba0f-883ad3f70d2b x-audience: external-public x-logo: url: https://assets.confluent.io/m/1661ef5e4ff82d3d/ description: '# Introduction Note This documents the collection of Confluent Cloud APIs.' servers: - url: https://api.confluent.cloud description: Confluent Cloud API tags: - name: Signup (partner/v2) description: '![Early Access](#section/Versioning/API-Lifecycle-Policy) ![Request Access To Partner v2](mailto:ccloud-api-access+partner-v2-early-access@confluent.io?subject=Request%20to%20join%20partner/v2%20API%20Early%20Access&body=I%E2%80%99d%20like%20to%20join%20the%20Confluent%20Cloud%20API%20Early%20Access%20for%20partner/v2%20to%20provide%20early%20feedback%21%20My%20Cloud%20Organization%20ID%20is%20%3Cretrieve%20from%20https%3A//confluent.cloud/settings/billing/payment%3E.) `Signup` APIs can only…' paths: /partner/v2/signup: post: summary: Signup an Organization on behalf of a Customer description: '![Early Access](#section/Versioning/API-Lifecycle-Policy) ![Request Access To Partner v2](mailto:ccloud-api-access+partner-v2-early-access@confluent.io?subject=Request%20to%20join%20partner/v2%20API%20Early%20Access&body=I%E2%80%99d%20like%20to%20join%20the%20Confluent%20Cloud%20API%20Early%20Access%20for%20partner/v2%20to%20provide%20early%20feedback%21%20My%20Cloud%20Organization%20ID%20is%20%3Cretrieve%20from%20https%3A//confluent.cloud/settings/billing/payment%3E.) Create an organization for a customer. You must pass in either an entitlement object reference (a url to a previously created entitlement) or entitlement details. If you pass in an entitlement object reference, we will link with the created entitlement. If you pass in the entitlement details, we will create the entitlement with the organization in a single transaction. If you pass in user details (email, given name, and family name), we will create a user as well. If you do not pass in user details, you MUST call `/partner/v2/signup/activate` with user details to complete signup.' parameters: - name: dry_run in: query required: false schema: type: boolean description: If true, only perform validation of signup requestBody: description: A JSON object containing signup information content: application/json: schema: $ref: '#/components/schemas/PartnerSignupRequest' x-lifecycle-stage: Early Access operationId: signup tags: - Signup (partner/v2) security: - oauth: - partner:create responses: '201': description: Successful signup. content: application/json: schema: $ref: '#/components/schemas/PartnerSignupResponse' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthenticatedError' '403': $ref: '#/components/responses/UnauthorizedError' '409': $ref: '#/components/responses/ConflictError' '429': $ref: '#/components/responses/RateLimitError' '500': $ref: '#/components/responses/DefaultSystemError' /partner/v2/signup/activate: x-lifecycle-stage: Early Access post: summary: Activate an Incomplete Signup description: '![Early Access](#section/Versioning/API-Lifecycle-Policy) ![Request Access To Partner v2](mailto:ccloud-api-access+partner-v2-early-access@confluent.io?subject=Request%20to%20join%20partner/v2%20API%20Early%20Access&body=I%E2%80%99d%20like%20to%20join%20the%20Confluent%20Cloud%20API%20Early%20Access%20for%20partner/v2%20to%20provide%20early%20feedback%21%20My%20Cloud%20Organization%20ID%20is%20%3Cretrieve%20from%20https%3A//confluent.cloud/settings/billing/payment%3E.) Creates a user in the organization previously created in `/partner/v2/signup`. This completes the signup process if you did not pass in user details to `/partner/v2/signup`. Calling this endpoint if the signup process has been completed will result in a `409 Conflict` error.' requestBody: description: A JSON object containing signup information content: application/json: schema: $ref: '#/components/schemas/ActivatePartnerSignupRequest' x-lifecycle-stage: Early Access operationId: activateSignup tags: - Signup (partner/v2) security: - oauth: - partner:create responses: '201': description: Successful signup activation. User is being created. content: application/json: schema: $ref: '#/components/schemas/PartnerSignupResponse' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthenticatedError' '403': $ref: '#/components/responses/UnauthorizedError' '409': $ref: '#/components/responses/ConflictError' '429': $ref: '#/components/responses/RateLimitError' '500': $ref: '#/components/responses/DefaultSystemError' /partner/v2/signup/link: post: summary: Signup a Customer by Linking to an Existing Organization description: '![Early Access](#section/Versioning/API-Lifecycle-Policy) ![Request Access To Partner v2](mailto:ccloud-api-access+partner-v2-early-access@confluent.io?subject=Request%20to%20join%20partner/v2%20API%20Early%20Access&body=I%E2%80%99d%20like%20to%20join%20the%20Confluent%20Cloud%20API%20Early%20Access%20for%20partner/v2%20to%20provide%20early%20feedback%21%20My%20Cloud%20Organization%20ID%20is%20%3Cretrieve%20from%20https%3A//confluent.cloud/settings/billing/payment%3E.) Signup a customer by linking a new entitlement to an existing Confluent Cloud organization.' parameters: - name: dry_run in: query required: false schema: type: boolean description: If true, only perform validation of signup requestBody: description: A JSON object containing signup information content: application/json: schema: $ref: '#/components/schemas/PartnerLinkRequest' x-lifecycle-stage: Early Access operationId: signupPartnerV2Link tags: - Signup (partner/v2) security: - oauth: - partner:create responses: '201': description: Successful signup. content: application/json: schema: $ref: '#/components/schemas/PartnerSignupResponse' '400': $ref: '#/components/responses/BadRequestError' '401': $ref: '#/components/responses/UnauthenticatedError' '403': $ref: '#/components/responses/UnauthorizedError' '409': $ref: '#/components/responses/ConflictError' '429': $ref: '#/components/responses/RateLimitError' '500': $ref: '#/components/responses/DefaultSystemError' components: schemas: PartnerLinkRequest: type: object description: The partner linking request required: - token - organization - entitlement properties: token: type: string description: The linking token that was generated. example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c x-redact: true organization: allOf: - $ref: '#/components/schemas/partner.v2.Organization' - required: - sso_config entitlement: oneOf: - allOf: - $ref: '#/components/schemas/partner.v2.Entitlement' - required: - external_id - name - plan_id - product_id - allOf: - $ref: '#/components/schemas/ObjectReference' - required: - related PartnerSignupResponse: type: object description: The partner signup response required: - organization_id - sso_url properties: organization_id: type: string description: The ID of the organization example: b3a17773-05cc-4431-9560-433fb4613da8 sso_url: type: string format: uri description: The login URL for the customer to access Confluent Cloud example: https://confluent.cloud/login/sso/AzureAD-OIDC-Conn display_message: type: string description: The display message contains useful information which is shown on the Marketplace UI to the customers. example: Your support plan will remain the same, to change the plan, follow this [link](https://docs.confluent.io/cloud/current/faq.html#how-do-i-change-support-plans). PartnerSignupRequest: type: object description: The partner signup request required: - organization - entitlement properties: organization: allOf: - $ref: '#/components/schemas/partner.v2.Organization' - required: - name - sso_config user: allOf: - $ref: '#/components/schemas/v2.User' - required: - given_name - family_name - email entitlement: oneOf: - allOf: - $ref: '#/components/schemas/partner.v2.Entitlement' - required: - external_id - name - plan_id - product_id - allOf: - $ref: '#/components/schemas/ObjectReference' - required: - related Error: type: object description: Describes a particular error encountered while performing an operation. properties: id: description: A unique identifier for this particular occurrence of the problem. type: string maxLength: 255 status: description: The HTTP status code applicable to this problem, expressed as a string value. type: string code: description: An application-specific error code, expressed as a string value. type: string title: description: A short, human-readable summary of the problem. It **SHOULD NOT** change from occurrence to occurrence of the problem, except for purposes of localization. type: string detail: description: A human-readable explanation specific to this occurrence of the problem. type: string source: type: object description: If this error was caused by a particular part of the API request, the source will point to the query string parameter or request body property that caused it. properties: pointer: description: A JSON Pointer [RFC6901] to the associated entity in the request document [e.g. "/spec" for a spec object, or "/spec/title" for a specific field]. type: string parameter: description: A string indicating which query parameter caused the error. type: string error_code: type: integer format: int32 message: type: - string - 'null' additionalProperties: false v2.User: type: object ActivatePartnerSignupRequest: type: object description: The partner signup activation request required: - user - organization_id properties: user: allOf: - $ref: '#/components/schemas/v2.User' - required: - given_name - family_name - email organization_id: type: string description: The ID of the organization example: b3a17773-05cc-4431-9560-433fb4613da8 partner.v2.Organization: type: object description: '`Organizations` objects represent an entire Confluent Cloud organization.' properties: api_version: type: string enum: - partner/v2 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - Organization id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string readOnly: true example: dlz-f3a90de metadata: $ref: '#/components/schemas/ObjectMeta' name: type: string description: The name of the organization example: Acme Organization pattern: ^[^<>#%'*^`{|}~\"]{1,31}$ sso_url: type: string format: uri description: The login URL for the customer to access Confluent Cloud example: https://confluent.cloud/login/sso/AzureAD-OIDC-Conn readOnly: true sso_config: oneOf: - $ref: '#/components/schemas/AzureSSOConfig' discriminator: propertyName: kind additionalProperties: false AzureSSOConfig: type: object required: - kind - tenant_id properties: kind: type: string example: AzureSSOConfig tenant_id: type: string example: b3a17773-05cc-4431-9560-433fb4613da8 description: The Azure AD tenant ID ObjectMeta: description: ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create. required: - self properties: self: description: Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time type: string format: uri readOnly: true example: https://api.confluent.cloud/v2/kafka-clusters/lkc-f3a90de resource_name: description: Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name type: string format: uri readOnly: true example: crn://confluent.cloud/kafka=lkc-f3a90de created_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was created. It is represented in RFC3339 format and is in UTC. updated_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC. deleted_at: type: string format: date-time example: '2006-01-02T15:04:05-07:00' readOnly: true description: The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC. readOnly: true partner.v2.Entitlement: type: object description: '`Entitlement` objects represent metadata about a marketplace entitlement.' properties: api_version: type: string enum: - partner/v2 description: APIVersion defines the schema version of this representation of a resource. readOnly: true kind: type: string description: Kind defines the object this REST resource represents. readOnly: true enum: - Entitlement id: description: ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space"). type: string readOnly: true example: dlz-f3a90de metadata: $ref: '#/components/schemas/ObjectMeta' external_id: type: string description: The unique external ID of the entitlement (this should be unique to customer) example: 1111-2222-3333-4444 name: type: string description: The name of the entitlement example: Acme Prod Entitlement plan_id: type: string description: The plan ID the entitlement example: confluent-cloud-payg-prod x-extensible-enum: - confluent-cloud-payg-prod - payg-prod.gcpmarketplace.confluent.cloud product_id: type: string description: The product ID of the entitlement example: confluent-cloud-kafka-service-azure x-extensible-enum: - confluent-cloud-kafka-service-azure - confluent-cloud-for-apache-kafka - payg-prod.gcpmarketplace.confluent.cloud usage_reporting_id: type: string description: 'The usage reporting ID of the entitlement (if usage reporting uses a different ID, otherwise, same as external_id) ' example: 1111-2222-3333-4444 resource_id: type: string description: The resource ID of the entitlement example: 1111-2222-3333-4444 organization: allOf: - $ref: '#/components/schemas/ObjectReference' - required: - related description: The organization associated with this object. additionalProperties: false Failure: type: object description: Provides information about problems encountered while performing an operation. required: - errors properties: errors: description: List of errors which caused this operation to fail type: array items: $ref: '#/components/schemas/Error' uniqueItems: true ObjectReference: type: object description: ObjectReference provides information for you to locate the referred object required: - id - related - resource_name properties: id: type: string description: ID of the referred resource minLength: 1 maxLength: 255 environment: type: string description: Environment of the referred resource, if env-scoped minLength: 1 maxLength: 255 related: type: string format: uri description: API URL for accessing or modifying the referred object minLength: 1 readOnly: true resource_name: type: string format: uri description: CRN reference to the referred resource minLength: 1 readOnly: true api_version: type: string description: API group and version of the referred resource minLength: 1 readOnly: true kind: type: string description: Kind of the referred resource minLength: 1 readOnly: true responses: UnauthenticatedError: x-summary: Unauthorized description: The request lacks valid authentication credentials for this resource. headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. WWW-Authenticate: schema: type: string description: The unique identifier for the API request. example: Basic error="invalid_key", error_description="The API Key is invalid" content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '401' code: user_unauthenticated title: Authentication Required detail: Valid authentication credentials must be provided DefaultSystemError: description: Oops, something went wrong! headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '500' code: out_of_gas title: DeLorean Out Of Gas detail: The DeLorean has run out of gas, but Doc Brown will fill 'er up for you asap ConflictError: x-summary: Conflict description: The request is in conflict with the current server state headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. Location: schema: type: string format: uri example: https://api.confluent.cloud/{object}/{id} description: Resource URI of conflicting resource content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '409' code: resource_already_exists title: Resource Already exists detail: The entitlement '91e3e86f-fca6-4f14-98f5-a48e64113ce2' already exists. UnauthorizedError: x-summary: Forbidden description: The access credentials were considered insufficient to grant access headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '403' code: user_unauthorized title: User Access Unauthorized detail: The user 'mcfly' is not allowed to access the 'delorean' resource without the 'plutonium' role. BadRequestError: description: Bad Request headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. content: application/json: schema: $ref: '#/components/schemas/Failure' example: errors: - id: ed42afdc-f0d5-4c0d-b428-9fc6ed6e279d status: '400' code: invalid_filter title: Invalid Filter detail: The 'delorean' resource can't be filtered by 'num_doors' source: parameter: num_doors RateLimitError: description: Rate Limit Exceeded headers: X-Request-Id: schema: type: string description: The unique identifier for the API request. X-RateLimit-Limit: schema: type: integer description: The maximum number of requests you're permitted to make per time period. X-RateLimit-Remaining: schema: type: integer description: The number of requests remaining in the current rate limit window. X-RateLimit-Reset: schema: type: integer description: "The relative time in seconds until the current rate-limit window resets. \n \n**Important:** This differs from Github and Twitter's same-named header which uses UTC epoch seconds. We use relative time to avoid client/server time synchronization issues." Retry-After: schema: type: integer description: The number of seconds to wait until the rate limit window resets. Only sent when the rate limit is reached. securitySchemes: cloud-api-key: type: http scheme: basic description: Authenticate with Cloud API Keys using HTTP Basic Auth. Treat the Cloud API Key ID as the username and Cloud API Key Secret as the password. confluent-sts-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} global-api-key: type: http scheme: basic description: Authenticate with Global API Keys using HTTP Basic Auth. Treat the Global API Key ID as the username and Global API Key Secret as the password. resource-api-key: type: http scheme: basic description: Authenticate with resource-specific API Keys using HTTP Basic Auth. Treat the resource-specific API Key ID as the username and resource-specific API Key Secret as the password. external-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} oauth: type: oauth2 description: Authenticate with OAuth 2.0. Currently this is only supported for partner APIs. flows: clientCredentials: tokenUrl: /oauth2/token scopes: partner:alter: enables partners to alter entitlements partner:create: enables partners to create entitlements and signup on behalf of customers partner:delete: enables partners to delete entitlements and organizations partner:describe: enables partners to read and list entitlements and organizations x-tagGroups: - name: Identity Access Management (v2) tags: - API Keys (iam/v2) - Users (iam/v2) - Service Accounts (iam/v2) - Invitations (iam/v2) - IP Groups (iam/v2) - IP Filters (iam/v2) - IP Filter Summaries (iam/v2) - Role Bindings (iam/v2) - Identity Providers (iam/v2) - Jwks (iam/v2) - Identity Pools (iam/v2) - Group Mappings (iam/v2/sso) - Certificate Authorities (iam/v2) - Certificate Identity Pools (iam/v2) - name: Org API (v2) tags: - Environments (org/v2) - Organizations (org/v2) - name: Notifications API (v1) tags: - Subscriptions (notifications/v1) - Integrations (notifications/v1) - Notification Types (notifications/v1) - Resource Preferences (notifications/v1) - Resource Subscriptions (notifications/v1) - User Notifications (notifications/v1) - name: Cluster Mgmt for Kafka (v2) tags: - Clusters (cmk/v2) - name: Cluster Mgmt for ksqlDB (v2) tags: - Clusters (ksqldbcm/v2) - name: Connect API (v1) tags: - Connectors (connect/v1) - Lifecycle (connect/v1) - Status (connect/v1) - Managed Connector Plugins (connect/v1) - Offsets (connect/v1) - Custom Connector Plugins (connect/v1) - Presigned Urls (connect/v1) - Custom Connector Runtimes (connect/v1) - name: Connect Artifact Management (v1) tags: - Connect Artifacts (cam/v1) - Presigned Urls (cam/v1) - name: Kafka API (v3) tags: - Cluster (v3) - Configs (v3) - ACL (v3) - Consumer Group (v3) - Partition (v3) - Topic (v3) - Records (v3) - Cluster Linking (v3) - Share Group (v3) - Streams Group (v3) - name: Service Quota API (v1) tags: - Applied Quotas (service-quota/v1) - Scopes (service-quota/v1) - name: Partner API (v2) tags: - Entitlements (partner/v2) - Organizations (partner/v2) - Signup (partner/v2) - name: Cluster Mgmt for Schema Registry (v2) tags: - Regions (srcm/v2) - Clusters (srcm/v2) - name: Cluster Mgmt for Schema Registry (v3) tags: - Clusters (srcm/v3) - name: Schema Registry API (v1) tags: - Compatibility (v1) - Config (v1) - Contexts (v1) - Exporters (v1) - Modes (v1) - Schemas (v1) - Subjects (v1) - Key Encryption Keys (v1) - Data Encryption Keys (v1) - name: Catalog API (v1) tags: - Entity (v1) - Search (v1) - Types (v1) - name: Stream Sharing API (v1) tags: - Provider Shared Resources (cdx/v1) - Provider Shares (cdx/v1) - Consumer Shared Resources (cdx/v1) - Consumer Shares (cdx/v1) - Shared Tokens (cdx/v1) - Opt Ins (cdx/v1) - name: Networking (v1) tags: - Networks (networking/v1) - Peerings (networking/v1) - Transit Gateway Attachments (networking/v1) - Private Link Accesses (networking/v1) - Network Link Services (networking/v1) - Network Link Endpoints (networking/v1) - Network Link Service Associations (networking/v1) - IP Addresses (networking/v1) - Private Link Attachments (networking/v1) - Private Link Attachment Connections (networking/v1) - DNS Forwarders (networking/v1) - Access Points (networking/v1) - DNS Records (networking/v1) - Gateways (networking/v1) - name: Security Token Service (v1) tags: - OAuth Tokens (sts/v1) - name: Kafka Quota (v1) tags: - Client Quotas (kafka-quotas/v1) - name: Bring Your Own Key (BYOK) Management (v1) tags: - Keys (byok/v1) - name: Billing API (v1) tags: - Costs (billing/v1) - name: Compute Pool Mgmt for Flink (v2) tags: - Compute Pools (fcpm/v2) - Regions (fcpm/v2) - Org Compute Pool Configs (fcpm/v2) - name: SQL API (v1) tags: - Statements (sql/v1) - Statement Results (sql/v1) - Statement Exceptions (sql/v1) - Connections (sql/v1) - Agents (sql/v1) - Tools (sql/v1) - Materialized Tables (sql/v1) - Materialized Table Versions (sql/v1) - name: Provider Integration Management (v1) tags: - Integrations (pim/v1) - name: Provider Integration Management (v2) tags: - Integrations (pim/v2) - name: Artifact API (v1) tags: - Flink Artifacts (artifact/v1) - Presigned Urls (artifact/v1) - Flink Artifact Versions (artifact/v1) - name: Custom Code Logging API (v1) tags: - Custom Code Loggings (ccl/v1) - name: Tableflow (v1) tags: - Regions (tableflow/v1) - Tableflow Topics (tableflow/v1) - Catalog Integrations (tableflow/v1) - name: Custom Connect Plugin Management (v1) tags: - Custom Connect Plugins (ccpm/v1) - Presigned Urls (ccpm/v1) - Custom Connect Plugin Versions (ccpm/v1) - name: Unified Stream Manager (v1) tags: - Kafka Clusters (usm/v1) - Connect Clusters (usm/v1) - name: Endpoint (v1) tags: - Endpoints (endpoint/v1) - name: Real Time Context Engine (v1) tags: - Rtce Topics (rtce/v1) - Regions (rtce/v1) - name: Analytics (v1alpha1) tags: - Statements (query/v1alpha1)