openapi: 3.0.3 info: title: CubeSigner Account Policies API description: The CubeSigner management and signing service. contact: name: Cubist Inc. email: hello@cubist.dev version: v0.1.0 servers: - url: https://gamma.signer.cubist.dev description: Testing and staging environment - url: https://prod.signer.cubist.dev description: Production environment security: - Cognito: [] tags: - name: Policies paths: /v0/org/{org_id}/policies: get: tags: - Policies summary: List Policies description: 'List Policies Returns the list of all policies in the Org.' operationId: listPolicies parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: page.size in: query description: 'Max number of items to return per page. If the actual number of returned items may be less that this, even if there exist more data in the result set. To reliably determine if more data is left in the result set, inspect the [UnencryptedLastEvalKey] value in the response object.' required: false schema: type: integer format: int32 default: 100 maximum: 1001 minimum: 1 style: form - name: page.start in: query description: 'The start of the page. Omit to start from the beginning; otherwise, only specify a the exact value previously returned as ''last_evaluated_key'' from the same endpoint.' required: false schema: type: string nullable: true style: form - name: policy_type in: query description: The optional type of policies to return required: false schema: allOf: - $ref: '#/components/schemas/PolicyType' nullable: true style: form example: Key responses: '200': $ref: '#/components/responses/PaginatedListPoliciesResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:list post: tags: - Policies summary: Create Policy description: 'Create Policy Creates a new named policy in the organization. The user making the request is the owner of the policy, giving them edit access to the policy along with the org owners.' operationId: createPolicy parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a requestBody: content: application/json: schema: $ref: '#/components/schemas/CreatePolicyRequest' required: true responses: '200': $ref: '#/components/responses/PolicyInfo' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:create /v0/org/{org_id}/policies/{policy_id}: delete: tags: - Policies summary: Delete Policy description: 'Delete Policy Delete the named policy with the given name or id.' operationId: deletePolicy parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: policy_id in: path description: Name or ID of the desired NamedPolicy required: true schema: type: string example: NamedPolicy#124dfe3e-3bbd-487d-80c0-53c55e8ab87a requestBody: content: application/json: schema: $ref: '#/components/schemas/Empty' required: true responses: '200': $ref: '#/components/responses/EmptyImpl' '202': description: '' content: application/json: schema: $ref: '#/components/schemas/AcceptedResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:delete patch: tags: - Policies summary: Update Policy description: 'Update Policy Updates the policy with the given name or id.' operationId: updatePolicy parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: policy_id in: path description: Name or ID of the desired NamedPolicy required: true schema: type: string example: NamedPolicy#124dfe3e-3bbd-487d-80c0-53c55e8ab87a requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdatePolicyRequest' required: true responses: '200': $ref: '#/components/responses/PolicyInfo' '202': description: '' content: application/json: schema: $ref: '#/components/schemas/AcceptedResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:update - manage:policy:update:rule - manage:policy:update:owner - manage:policy:update:name - manage:policy:update:editPolicy /v0/org/{org_id}/policies/{policy_id}/logs: post: tags: - Policies summary: Get Policy Logs description: 'Get Policy Logs Returns the logs for the given policy, within the given timeframe.' operationId: getPolicyLogs parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: policy_id in: path description: Name or ID of the desired NamedPolicy required: true schema: type: string example: NamedPolicy#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: page.size in: query description: 'Max number of items to return per page. If the actual number of returned items may be less that this, even if there exist more data in the result set. To reliably determine if more data is left in the result set, inspect the [UnencryptedLastEvalKey] value in the response object.' required: false schema: type: integer format: int32 default: 100 maximum: 1001 minimum: 1 style: form - name: page.start in: query description: 'The start of the page. Omit to start from the beginning; otherwise, only specify a the exact value previously returned as ''last_evaluated_key'' from the same endpoint.' required: false schema: type: string nullable: true style: form requestBody: content: application/json: schema: $ref: '#/components/schemas/PolicyLogsRequest' required: true responses: '200': $ref: '#/components/responses/PaginatedPolicyLogsResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:logs:get /v0/org/{org_id}/policies/{policy_id}/{version}: get: tags: - Policies summary: Get Policy description: 'Get Policy Returns the specified version or latest of a named policy with the given name or id.' operationId: getPolicy parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: policy_id in: path description: Name or ID of the desired NamedPolicy required: true schema: type: string example: NamedPolicy#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: version in: path description: The policy version, either 'latest' or 'v'. required: true schema: type: string example: latest responses: '200': $ref: '#/components/responses/PolicyInfo' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:get /v0/org/{org_id}/policies/{policy_id}/{version}/invoke: post: tags: - Policies summary: Invoke Policy description: 'Invoke Policy Invokes the [NamedPolicy] with the given ID with the given request information. It is only supported for Wasm policies.' operationId: invokePolicy parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: policy_id in: path description: Name or ID of the desired NamedPolicy required: true schema: type: string example: NamedPolicy#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: version in: path description: The policy version, either 'latest' or 'v'. required: true schema: type: string example: latest requestBody: content: application/json: schema: $ref: '#/components/schemas/InvokePolicyRequest' required: true responses: '200': $ref: '#/components/responses/InvokePolicyResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:invoke /v0/org/{org_id}/policy/buckets: get: tags: - Policies summary: List Buckets description: 'List Buckets List available meta information about all policy KV store buckets in the org.' operationId: listPolicyBuckets parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: page.size in: query description: 'Max number of items to return per page. If the actual number of returned items may be less that this, even if there exist more data in the result set. To reliably determine if more data is left in the result set, inspect the [UnencryptedLastEvalKey] value in the response object.' required: false schema: type: integer format: int32 default: 100 maximum: 1001 minimum: 1 style: form - name: page.start in: query description: 'The start of the page. Omit to start from the beginning; otherwise, only specify a the exact value previously returned as ''last_evaluated_key'' from the same endpoint.' required: false schema: type: string nullable: true style: form responses: '200': $ref: '#/components/responses/PaginatedListBucketsResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:buckets:list /v0/org/{org_id}/policy/buckets/{bucket_name}: get: tags: - Policies summary: Get Bucket description: 'Get Bucket Returns the meta information of a policy KV store bucket.' operationId: getPolicyBucket parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: bucket_name in: path required: true schema: type: string responses: '200': $ref: '#/components/responses/BucketInfo' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:bucket:get patch: tags: - Policies summary: Update Bucket description: 'Update Bucket Updates meta information for an existing policy KV store bucket.' operationId: updatePolicyBucket parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: bucket_name in: path required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateBucketRequest' required: true responses: '200': $ref: '#/components/responses/BucketInfo' '202': description: '' content: application/json: schema: $ref: '#/components/schemas/AcceptedResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:bucket:update:acl - manage:policy:bucket:update:metadata /v0/org/{org_id}/policy/import_key: get: tags: - Policies summary: Create Policy Import Key description: 'Create Policy Import Key Generate an ephemeral key that a client can use for encrypting data related to Wasm policies (e.g., policy secrets).' operationId: createPolicyImportKey parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a responses: '200': $ref: '#/components/responses/CreatePolicyImportKeyResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:createImportKey /v0/org/{org_id}/policy/secrets: get: tags: - Policies summary: Get the org-wide policy secrets. description: 'Get the org-wide policy secrets. Note that this only returns the keys for the secrets, omitting the values. The values are secret and are not accessible outside Wasm policy execution.' operationId: getPolicySecrets parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a responses: '200': $ref: '#/components/responses/PolicySecretsInfo' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:secrets:get patch: tags: - Policies summary: Update org-level policy secrets description: 'Update org-level policy secrets The provided secrets will replace any existing org-level secrets. It fails if the secrets weren''t previously created. Must be permitted by the policy secret''s edit policy if set, and the org''s edit policy otherwise.' operationId: updatePolicySecrets parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdatePolicySecretsRequest' required: true responses: '200': $ref: '#/components/responses/PolicySecretsInfo' '202': description: '' content: application/json: schema: $ref: '#/components/schemas/AcceptedResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:secrets:update - manage:policy:secrets:update:values - manage:policy:secrets:update:editPolicy /v0/org/{org_id}/policy/secrets/{secret_name}: put: tags: - Policies summary: Create or overwrite an org-level policy secret. description: 'Create or overwrite an org-level policy secret. Must be permitted by the policy secret''s edit policy if set, and the org''s edit policy otherwise.' operationId: setPolicySecret parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: secret_name in: path required: true schema: type: string style: simple requestBody: content: application/json: schema: $ref: '#/components/schemas/SetPolicySecretRequest' required: true responses: '200': $ref: '#/components/responses/PolicySecretsInfo' '202': description: '' content: application/json: schema: $ref: '#/components/schemas/AcceptedResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:secrets:update:values delete: tags: - Policies summary: Delete an org-level policy secret. description: 'Delete an org-level policy secret. Must be permitted by the policy secret''s edit policy if set, and the org''s edit policy otherwise.' operationId: deletePolicySecret parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a - name: secret_name in: path required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/Empty' required: true responses: '200': $ref: '#/components/responses/PolicySecretsInfo' '202': description: '' content: application/json: schema: $ref: '#/components/schemas/AcceptedResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:secrets:update:values /v0/org/{org_id}/policy/wasm: post: tags: - Policies summary: Upload Wasm Policy description: 'Upload Wasm Policy Returns a signed URL for uploading a wasm policy to CubeSigner. The policy will be deleted if not attached to a [NamedPolicy] soon after the upload has been completed.' operationId: uploadWasmPolicy parameters: - name: org_id in: path description: Name or ID of the desired Org required: true schema: type: string example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a requestBody: content: application/json: schema: $ref: '#/components/schemas/UploadWasmPolicyRequest' required: true responses: '200': $ref: '#/components/responses/UploadWasmPolicyResponse' default: description: '' content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' security: - SignerAuth: - manage:policy:wasm:upload components: schemas: EpochDateTime: type: integer format: int64 description: 'DateTime measured in seconds since unix epoch. A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`] representing the number of seconds since [`SystemTime::UNIX_EPOCH`].' minimum: 0 UpdateBucketRequest: type: object description: The information needed to update a bucket. properties: acl: description: Access-control entries defining how the bucket can be accessed. nullable: true expected_version: type: integer format: int64 description: If set, updating only succeeds if the current version matches this value. nullable: true minimum: 0 metadata: description: Optional metadata. nullable: true owner: type: string description: Update the owner of the bucket example: User#00000000-0000-0000-0000-000000000000 nullable: true WasmPolicyResponse: oneOf: - type: object required: - response properties: response: type: string enum: - Allow - type: object description: The policy denied signing the transaction. required: - reason - response properties: reason: type: string description: The reason for the denial. response: type: string enum: - Deny - type: object description: The policy failed to execute successfully, and exited with an error. required: - error - response properties: error: type: string description: The error from the Policy Engine. response: type: string enum: - Error description: The response from invoking a Wasm policy. discriminator: propertyName: response Empty: default: null nullable: true MfaRequiredArgs: type: object required: - id - ids - org_id properties: id: type: string description: Always set to first MFA id from `Self::ids` ids: type: array items: type: string minLength: 1 description: Non-empty MFA request IDs org_id: type: string description: Organization id policy_eval_tree: description: Optional policy evaluation tree (included in signer responses, when requested) nullable: true session: allOf: - $ref: '#/components/schemas/NewSessionResponse' nullable: true B32: type: string description: Wrapper around a zeroizing 32-byte fixed-size array ScopeSet: oneOf: - type: string description: All scopes enum: - All - type: object required: - AllExcept properties: AllExcept: type: array items: $ref: '#/components/schemas/Scope' description: All scopes except these (including those transitively implied). - type: object required: - AllOf properties: AllOf: type: array items: $ref: '#/components/schemas/Scope' description: All of these scopes (including those transitively implied). description: A set of scopes. CommonFields: allOf: - type: object description: 'Versioning fields (e.g., version number, creation time, and last modified times) that are common to different types of resources.' properties: created: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true last_modified: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true version: type: integer format: int64 description: Version of this object minimum: 0 - type: object properties: edit_policy: $ref: '#/components/schemas/EditPolicy' metadata: description: 'User-defined metadata. When rendering (e.g., in the browser) you should treat it as untrusted user data (and avoid injecting metadata into HTML directly) if untrusted users can create/update keys (or their metadata).' description: 'Fields that are common to different types of resources such as keys, roles, etc. Includes versioning fields plus metadata, edit policy, etc.' SecretValue: oneOf: - type: string description: 'A secret value. Config values are encrypted in transit and at rest.' - type: object description: 'A secret value encrypted to this organization''s Wasm policy. Each value is encrypted with its own ephemeral key.' required: - encrypted_value - salt - client_public_key properties: client_public_key: type: string description: 'The client''s ephemeral public key used to derive a shared key. This is a base64-encoded, SEC1-encoded P384 public key.' encrypted_value: type: string description: 'The encrypted secret value. This is a base64-encoded ciphertext.' salt: type: string description: 'A salt value used to derive a shared key for AES-GCM. This is a base64-encoded byte string.' description: The value of a policy secret. AcceptedValue: oneOf: - type: object required: - SignDryRun properties: SignDryRun: $ref: '#/components/schemas/SignDryRunArgs' - type: object required: - BinanceDryRun properties: BinanceDryRun: $ref: '#/components/schemas/BinanceDryRunArgs' - type: object required: - BybitDryRun properties: BybitDryRun: $ref: '#/components/schemas/BybitDryRunArgs' - type: object required: - CoinbaseDryRun properties: CoinbaseDryRun: $ref: '#/components/schemas/CoinbaseDryRunArgs' - type: object required: - MfaRequired properties: MfaRequired: $ref: '#/components/schemas/MfaRequiredArgs' description: Different responses we return for success status codes. NotFoundErrorCode: type: string enum: - UriSegmentMissing - UriSegmentInvalid - TotpNotConfigured - FidoKeyNotFound - FidoChallengeNotFound - TotpChallengeNotFound - UserExportRequestNotFound - UserExportCiphertextNotFound - OrgExportCiphertextNotFound - UploadObjectNotFound - PolicySecretNotFound - BucketMetaNotFound - TimestreamDisabled - CustomChainNotFound - InvitationNotFound - TransactionNotFound - EmailConfigNotFound HttpRequestCmp: oneOf: - type: string description: The requests must match exactly. Any given MFA receipt can be used at most once. enum: - Eq - type: object required: - EvmTx properties: EvmTx: $ref: '#/components/schemas/EvmTxCmp' - type: object required: - SolanaTx properties: SolanaTx: $ref: '#/components/schemas/SolanaTxCmp' description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request]) SolanaTxCmp: type: object properties: ignore_blockhash: type: boolean description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different. BadGatewayErrorCode: type: string enum: - Generic - CustomChainRpcError - EsploraApiError - SentryApiError - CallWebhookError - OAuthProviderError - OidcDisoveryFailed - OidcIssuerJwkEndpointUnavailable - SmtpServerUnavailable InternalErrorCode: type: string enum: - NoMaterialId - InvalidAuditLogEntry - UnexpectedCheckerRule - UnresolvedPolicyReference - UnexpectedAclAction - FidoKeyAssociatedWithMultipleUsers - ClaimsParseError - InvalidThrottleId - InvalidEmailAddress - EmailTemplateRender - OidcIdentityHeaderMissing - OidcIdentityParseError - SystemTimeError - PasswordHashParseError - SendMailError - ReqwestError - EmailConstructionError - TsWriteError - TsQueryError - DbQueryError - DbGetError - DbDeleteError - DbPutError - DbUpdateError - SerdeError - TestAndSetError - DbGetItemsError - DbWriteError - CubistSignerError - CwListMetricsError - CwPutMetricDataError - GetAwsSecretError - SecretNotFound - KmsGenerateRandomError - MalformedTotpBytes - KmsGenerateRandomNoResponseError - CreateKeyError - ParseDerivationPathError - SplitSignerError - CreateImportKeyError - CreateEotsNoncesError - EotsSignError - BabylonCovSignError - CognitoDeleteUserError - CognitoListUsersError - CognitoGetUserError - MissingUserEmail - CognitoResendUserInvitation - CognitoSetUserPasswordError - GenericInternalError - AssumeRoleWithoutEvidence - OidcAuthWithoutOrg - MissingKeyMetadata - KmsEnableKeyError - KmsDisableKeyError - LambdaInvokeError - LambdaNoResponseError - LambdaFailure - LambdaUnparsableResponse - SerializeEncryptedExportKeyError - DeserializeEncryptedExportKeyError - ReEncryptUserExport - S3UploadError - S3DownloadError - S3CopyError - S3ListObjectsError - S3DeleteObjectsError - S3BuildError - S3PresignedUrlError - ManagedStateMissing - InternalHeaderMissing - InvalidInternalHeaderValue - RequestLocalStateAlreadySet - OidcOrgMismatch - OidcIssuerInvalidJwk - InvalidPkForMaterialId - SegwitTweakFailed - UncheckedOrg - SessionOrgIdMissing - AvaSignCredsMissing - AvaSignSignatureMissing - ExpectedRoleSession - InvalidThirdPartyIdentity - CognitoGetUser - SnsSubscribeError - SnsUnsubscribeError - SnsGetSubscriptionAttributesError - SnsSubscriptionAttributesMissing - SnsSetSubscriptionAttributesError - SnsPublishBatchError - InconsistentMultiValueTestAndSet - MaterialIdError - InvalidBtcAddress - HistoricalTxBodyMissing - InvalidOperation - ParentOrgNotFound - OrgParentLoop - ResolvedParentOrgWithNoScopeCeiling - InvalidUploadObjectId - PolicyEngineNotFound - PolicyEngineError - PolicySecretsEncryptionError - CreatePolicyImportKeyError - InvalidAlias - EmptyUpdateModifiedObject - EmptyUpdateModifiedActions - DbContactAddressesInvalid - InvalidEvmSigedRlp - InvalidErc20Data - InvalidRpcUrl PolicyAttachedToId: oneOf: - type: object required: - key_id - role_id properties: key_id: type: string description: The id of the key in the role the policy should be attached to. example: Key#0x8e3484687e66cdd26cf04c3647633ab4f3570148 role_id: type: string description: The id of the role the key is in. example: Role#bfe3eccb-731e-430d-b1e5-ac1363e6b06b - type: object required: - key_id properties: key_id: type: string description: The id of the key the policy should be attached to. example: Key#0x8e3484687e66cdd26cf04c3647633ab4f3570148 - type: object required: - role_id properties: role_id: type: string description: The id of the role the policy should be attached to. example: Role#bfe3eccb-731e-430d-b1e5-ac1363e6b06b - type: object required: - org_id properties: org_id: type: string description: The id of the org the policy should be attached to. example: Org#b0156abd-53bd-4043-8e55-57f7af9512d5 description: The id for attaching a named policy to a key, role, or key in role. SignerErrorCode: oneOf: - $ref: '#/components/schemas/SignerErrorOwnCodes' - $ref: '#/components/schemas/AcceptedValueCode' - $ref: '#/components/schemas/BadRequestErrorCode' - $ref: '#/components/schemas/BadGatewayErrorCode' - $ref: '#/components/schemas/NotFoundErrorCode' - $ref: '#/components/schemas/ForbiddenErrorCode' - $ref: '#/components/schemas/UnauthorizedErrorCode' - $ref: '#/components/schemas/PreconditionErrorCode' - $ref: '#/components/schemas/TimeoutErrorCode' - $ref: '#/components/schemas/ConflictErrorCode' - $ref: '#/components/schemas/InternalErrorCode' EvmTxDepositErrorCode: type: string enum: - EvmTxDepositReceiverMismatch - EvmTxDepositEmptyData - EvmTxDepositEmptyChainId - EvmTxDepositEmptyReceiver - EvmTxDepositUnexpectedValue - EvmTxDepositUnexpectedDataLength - EvmTxDepositNoAbi - EvmTxDepositNoDepositFunction - EvmTxDepositUnexpectedFunctionName - EvmTxDepositUnexpectedValidatorKey - EvmTxDepositInvalidValidatorKey - EvmTxDepositMissingDepositArg - EvmTxDepositWrongDepositArgType - EvmTxDepositValidatorKeyNotInRole - EvmTxDepositUnexpectedWithdrawalCredentials - EvmTxDepositUnresolvedRole - EvmTxDepositInvalidDepositEncoding InvokePolicyRequest: type: object description: A request containing the data that a Wasm policy should be invoked with. properties: key_id: type: string description: 'An optional Key ID. If defined, the policy will be invoked as if it is signing the message with this key.' nullable: true request: description: The "request body" that should be sent to the policy. nullable: true role_id: type: string description: An optional Role ID. If `None`, the policy will be invoked from the current user session. nullable: true EditPolicy: type: object description: 'A policy which governs when and who is allowed to update the entity this policy is attached to (e.g., a role or a key). When attached to a role, by default, this policy applies to role deletion and all role updates (including adding/removing keys and users); in terms of scopes, it applies to `manage:role:update:*` and `manage:role:delete`. When attached to a key, by default, this policy applies to key deletion, all key updates, and adding/removing that key to/from a role; in terms of scopes, it applies to `manage:key:update:*`, `manage:key:delete`, `manage:role:update:key:*`. This default can be changed by setting the `applies_to_scopes` property.' properties: applies_to_scopes: $ref: '#/components/schemas/ScopeSet' mfa: allOf: - $ref: '#/components/schemas/MfaPolicy' nullable: true time_lock_until: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true OperationKind: type: string description: All different kinds of sensitive operations enum: - AvaSign - AvaChainTxSign - BabylonCovSign - BabylonRegistration - BabylonStaking - BinanceSubToMaster - BinanceSubToSub - BinanceUniversalTransfer - BinanceSubAccountAssets - BinanceAccountInfo - BinanceSubAccountTransferHistory - BinanceUniversalTransferHistory - BinanceWithdraw - BinanceWithdrawHistory - BinanceDeposit - BinanceDepositHistory - BinanceListSubAccounts - BinanceCoinInfo - BlobSign - BtcMessageSign - BtcSign - BybitQueryUser - BybitQuerySubMembers - BybitQueryCoinsBalance - BybitQueryDepositAddress - BybitUniversalTransfer - BybitWithdraw - BybitWithdrawals - CoinbaseListAccounts - CoinbaseListPortfolios - CoinbaseMoveFunds - DiffieHellman - PsbtSign - TaprootSign - Eip191Sign - Eip712Sign - Eip7702Sign - EotsNonces - EotsSign - Eth1Sign - Eth2Sign - Eth2Stake - Eth2Unstake - SolanaSign - SuiSign - TendermintSign - RoleUpdate KeyImportKey: type: object description: A wrapped key-import key required: - public_key - sk_enc - dk_enc - expires properties: dk_enc: type: string description: Base64-encoded, encrypted data key. expires: type: integer format: int64 description: Expiration timestamp expressed as seconds since the UNIX epoch. minimum: 0 public_key: type: string description: 'The ephemeral public key to which an imported key should be encrypted. This is a P384 public key in base64-encoded uncompressed SECG format.' sk_enc: type: string description: Base64-encoded, encrypted secret key. ErrorResponse: type: object description: The structure of ErrorResponse must match the response template that AWS uses required: - message - error_code properties: accepted: allOf: - $ref: '#/components/schemas/AcceptedValue' nullable: true error_code: $ref: '#/components/schemas/SignerErrorCode' message: type: string description: Error message policy_eval_tree: description: Optional policy evaluation tree (included in signer responses, when requested) nullable: true request_id: type: string description: Optional request identifier PreconditionErrorOwnCodes: type: string enum: - FailOnMfaRequired - KeyRegionLocked - KeyRegionChangedRecently - MfaRegionLocked - Eth2ProposerSlotTooLow - Eth2AttestationSourceEpochTooLow - Eth2AttestationTargetEpochTooLow - Eth2ConcurrentBlockSigning - Eth2ConcurrentAttestationSigning - Eth2MultiDepositToNonGeneratedKey - Eth2MultiDepositUnknownInitialDeposit - Eth2MultiDepositWithdrawalAddressMismatch - ConcurrentSigningWhenTimeLimitPolicyIsDefined - BabylonEotsConcurrentSigning - TendermintStateError - TendermintConcurrentSigning - MfaApprovalsNotYetValid PolicyInfo: type: object description: A struct containing all the information about a specific version of a policy. required: - policy_id - rules - version - name - policy_type - created - owner - attached_to properties: acl: type: array items: {} description: The access-control entries for the policy. nullable: true attached_to: type: array items: $ref: '#/components/schemas/PolicyAttachedToId' description: A list of entities (keys, roles, etc.) the policy is attached to. created: $ref: '#/components/schemas/EpochDateTime' edit_policy: $ref: '#/components/schemas/EditPolicy' metadata: description: User-defined metadata for the named policy. name: type: string description: The name of the policy. owner: $ref: '#/components/schemas/Id' policy_id: type: string description: The policy id policy_type: $ref: '#/components/schemas/PolicyType' rules: type: array items: {} description: The policy rule. version: type: integer format: int64 description: The policy rule's version. minimum: 0 ExplicitScope: type: string title: ExplicitScope description: Explicitly named scopes for accessing CubeSigner APIs enum: - sign:* - sign:ava - sign:binance:* - sign:binance:subToMaster - sign:binance:subToSub - sign:binance:universalTransfer - sign:binance:subAccountAssets - sign:binance:accountInfo - sign:binance:subAccountTransferHistory - sign:binance:universalTransferHistory - sign:binance:withdraw - sign:binance:withdrawHistory - sign:binance:deposit - sign:binance:depositHistory - sign:binance:listSubAccounts - sign:binance:coinInfo - sign:bybit:* - sign:bybit:queryUser - sign:bybit:querySubMembers - sign:bybit:queryCoinsBalance - sign:bybit:queryDepositAddress - sign:bybit:universalTransfer - sign:bybit:withdraw - sign:bybit:withdrawals - sign:coinbase:* - sign:coinbase:accounts:list - sign:coinbase:portfolios:list - sign:coinbase:funds:move - sign:blob - sign:diffieHellman - sign:btc:* - sign:btc:segwit - sign:btc:taproot - sign:btc:psbt:* - sign:btc:psbt:doge - sign:btc:psbt:legacy - sign:btc:psbt:segwit - sign:btc:psbt:taproot - sign:btc:psbt:ltcSegwit - sign:btc:message:* - sign:btc:message:segwit - sign:btc:message:legacy - sign:babylon:* - sign:babylon:eots:* - sign:babylon:eots:nonces - sign:babylon:eots:sign - sign:babylon:staking:* - sign:babylon:staking:deposit - sign:babylon:staking:unbond - sign:babylon:staking:withdraw - sign:babylon:staking:slash - sign:babylon:registration - sign:babylon:covenant - sign:evm:* - sign:evm:tx - sign:evm:eip191 - sign:evm:eip712 - sign:evm:eip7702 - sign:eth2:* - sign:eth2:validate - sign:eth2:stake - sign:eth2:unstake - sign:solana - sign:sui - sign:tendermint - sign:mmi - manage:* - manage:readonly - manage:email:* - manage:email:get - manage:email:update - manage:email:delete - manage:mfa:* - manage:mfa:readonly - manage:mfa:list - manage:mfa:vote:* - manage:mfa:vote:cs - manage:mfa:vote:email - manage:mfa:vote:fido - manage:mfa:vote:totp - manage:mfa:register:* - manage:mfa:register:fido - manage:mfa:register:totp - manage:mfa:register:email - manage:mfa:unregister:* - manage:mfa:unregister:fido - manage:mfa:unregister:totp - manage:mfa:verify:* - manage:mfa:verify:totp - manage:key:* - manage:key:readonly - manage:key:get - manage:key:attest - manage:key:listRoles - manage:key:list - manage:key:history:tx:list - manage:key:create - manage:key:import - manage:key:update:* - manage:key:update:owner - manage:key:update:policy - manage:key:update:enabled - manage:key:update:region - manage:key:update:metadata - manage:key:update:properties - manage:key:update:editPolicy - manage:key:delete - manage:policy:* - manage:policy:readonly - manage:policy:create - manage:policy:get - manage:policy:list - manage:policy:delete - manage:policy:update:* - manage:policy:update:owner - manage:policy:update:name - manage:policy:update:acl - manage:policy:update:editPolicy - manage:policy:update:metadata - manage:policy:update:rule - manage:policy:invoke - manage:policy:wasm:* - manage:policy:wasm:upload - manage:policy:secrets:* - manage:policy:secrets:get - manage:policy:secrets:update:* - manage:policy:secrets:update:values - manage:policy:secrets:update:acl - manage:policy:secrets:update:editPolicy - manage:policy:buckets:* - manage:policy:buckets:get - manage:policy:buckets:list - manage:policy:buckets:update:* - manage:policy:buckets:update:owner - manage:policy:buckets:update:acl - manage:policy:buckets:update:metadata - manage:contact:* - manage:contact:readonly - manage:contact:create - manage:contact:get - manage:contact:list - manage:contact:delete - manage:contact:update:* - manage:contact:update:name - manage:contact:update:addresses - manage:contact:update:owner - manage:contact:update:labels - manage:contact:update:metadata - manage:contact:update:editPolicy - manage:contact:lookup:* - manage:contact:lookup:address - manage:policy:createImportKey - manage:role:* - manage:role:readonly - manage:role:create - manage:role:delete - manage:role:get:* - manage:role:attest - manage:role:get:keys - manage:role:get:keys:list - manage:role:get:keys:get - manage:role:get:users - manage:role:list - manage:role:update:* - manage:role:update:enabled - manage:role:update:policy - manage:role:update:editPolicy - manage:role:update:actions - manage:role:update:key:* - manage:role:update:key:add - manage:role:update:key:remove - manage:role:update:user:* - manage:role:update:user:add - manage:role:update:user:remove - manage:role:history:tx:list - manage:identity:* - manage:identity:readonly - manage:identity:verify - manage:identity:add - manage:identity:remove - manage:identity:list - manage:org:* - manage:org:create - manage:org:metrics:query - manage:org:audit:query - manage:org:readonly - manage:org:addUser - manage:org:inviteUser - manage:org:inviteAlien - manage:org:invitation:list - manage:org:invitation:cancel - manage:org:updateMembership:* - manage:org:updateMembership:owner - manage:org:updateMembership:member - manage:org:updateMembership:alien - manage:org:listUsers - manage:org:user:get - manage:org:deleteUser:* - manage:org:deleteUser:owner - manage:org:deleteUser:member - manage:org:deleteUser:alien - manage:org:get - manage:org:update:* - manage:org:update:enabled - manage:org:update:policy - manage:org:update:signPolicy - manage:org:update:export - manage:org:update:totpFailureLimit - manage:org:update:notificationEndpoints - manage:org:update:defaultInviteKind - manage:org:update:idpConfiguration - manage:org:update:passkeyConfiguration - manage:org:update:emailPreferences - manage:org:update:historicalData - manage:org:update:requireScopeCeiling - manage:org:update:alienLoginRequirement - manage:org:update:memberLoginRequirement - manage:org:update:keyExportRequirement - manage:org:update:allowedMfaTypes - manage:org:update:policyEngineConf - manage:org:update:customChains - manage:org:update:extProps - manage:org:update:editPolicy - manage:org:user:resetMfa - manage:session:* - manage:session:readonly - manage:session:get - manage:session:list - manage:session:create - manage:session:extend - manage:session:revoke - manage:export:* - manage:export:readonly - manage:export:org:* - manage:export:org:get - manage:export:user:* - manage:export:user:delete - manage:export:user:list - manage:authMigration:* - manage:authMigration:identity:add - manage:authMigration:identity:remove - manage:authMigration:user:update - manage:mmi:* - manage:mmi:readonly - manage:mmi:get - manage:mmi:list - manage:mmi:reject - manage:mmi:delete - export:* - export:user:* - export:user:init - export:user:complete - mmi:* - orgAccess:* - orgAccess:child:* - rpc:* - rpc:createTransaction:* - rpc:createTransaction:evm - rpc:retryTransaction - rpc:cancelTransaction - rpc:getTransaction - rpc:listTransactions - rpc:btcListUtxos - rpc:binance - rpc:bybit - rpc:coinbase PolicyErrorOwnCodes: type: string enum: - Inapplicable - SuiTxReceiversDisallowedTransactionKind - SuiTxReceiversDisallowedTransferAddress - SuiTxReceiversDisallowedCommand - BtcTxDisallowedOutputs - BtcSignatureExceededValue - BtcValueOverflow - BtcSighashTypeDisallowed - Eip7702AddressMismatch - EvmTxReceiverMismatch - EvmTxChainIdMismatch - EvmTxSenderMismatch - EvmTxExceededValue - EvmTxExceededGasCost - EvmTxGasCostUndefined - EvmDataDisallowed - Erc20DataInvalid - EvmContractAddressUndefined - EvmContractChainIdUndefined - EvmDataNotDefined - EvmDataInvalid - EvmContractNotInAllowlist - Erc20ExceededTransferLimit - Erc20ReceiverMismatch - Erc20ExceededApproveLimit - Erc20SpenderMismatch - EvmFunctionNotInAllowlist - EvmFunctionCallInvalid - EvmFunctionCallDisallowedArg - PolicyDisjunctionError - PolicyNegationError - Eth2ExceededMaxUnstake - Eth2ConcurrentUnstaking - NotInIpv4Allowlist - NotInOriginAllowlist - NotInOperationAllowlist - InvalidSourceIp - RawSigningNotAllowed - DiffieHellmanExchangeNotAllowed - Eip712SigningNotAllowed - OidcSourceNotAllowed - NoOidcAuthSourcesDefined - AddKeyToRoleDisallowed - KeysAlreadyInRole - KeyInMultipleRoles - KeyAccessError - RequireRoleSessionKeyAccessError - BtcMessageSigningNotAllowed - Eip191SigningNotAllowed - Eip7702SigningNotAllowed - TaprootSigningDisallowed - SegwitSigningDisallowed - PsbtSigningDisallowed - BabylonStakingDisallowed - TimeLocked - CelPolicyDenied - BabylonStakingNetwork - BabylonStakingParamsVersion - BabylonStakingExplicitParams - BabylonStakingStakerPk - BabylonStakingFinalityProviderPk - BabylonStakingLockTime - BabylonStakingValue - BabylonStakingChangeAddress - BabylonStakingFee - BabylonStakingWithdrawalAddress - BabylonStakingBbnAddress - SolanaInstructionCountLow - SolanaInstructionCountHigh - SolanaNotInInstructionAllowlist - SolanaInstructionMismatch - WasmPoliciesDisabled - WasmPolicyDenied - WasmPolicyFailed - WebhookPoliciesDisabled - DeniedByWebhook - ExplicitlyDenied ClientSessionInfo: type: object description: 'Session information sent to the client. This struct works in tandem with its server-side counterpart [`SessionData`].' required: - session_id - auth_token - refresh_token - epoch - epoch_token - auth_token_exp - refresh_token_exp properties: auth_token: type: string description: Token to use for authorization. auth_token_exp: $ref: '#/components/schemas/EpochDateTime' epoch: type: integer format: int32 description: Epoch at which the token was last refreshed minimum: 0 epoch_token: $ref: '#/components/schemas/B32' refresh_token: type: string description: Token to use for refreshing the `(auth, refresh)` token pair refresh_token_exp: $ref: '#/components/schemas/EpochDateTime' session_id: type: string description: Session ID UploadWasmPolicyRequest: type: object description: Request for uploading a wasm policy required: - hash properties: hash: $ref: '#/components/schemas/UploadObjectHash' SecretInfo: type: object description: Information about a specific secret. required: - name properties: acl: type: array items: {} description: The access-control entries for this secret. nullable: true name: type: string description: The name of the secret. AcceptedValueCode: type: string enum: - SignDryRun - BinanceDryRun - BybitDryRun - CoinbaseDryRun - MfaRequired BinanceDryRunArgs: type: object required: - method - url properties: method: type: string description: The Binance API method that would have been used url: type: string description: The Binance API url method that would have been called BybitDryRunArgs: type: object required: - method - url - payload properties: method: type: string description: The Bybit API method that would have been used payload: type: string description: The request body (for POST endpoints) or query string (for GET endpoints). url: type: string description: The Bybit API url that would have been called CoinbaseDryRunArgs: type: object required: - method - url properties: method: type: string description: The Coinbase API method that would have been used url: type: string description: The Coinbase API url method that would have been called SignDryRunArgs: type: object required: - mfa_requests properties: mfa_requests: type: array items: $ref: '#/components/schemas/MfaRequestInfo' description: Whether MFA is required policy_eval_tree: description: Optional policy evaluation tree, if requested nullable: true ConflictErrorCode: type: string enum: - ConcurrentRequestDisallowed - ConcurrentLockCreation Id: type: string MfaType: type: string format: '''CubeSigner'' | ''Fido'' | `FidoKey#${string}` | ''Totp'' | ''EmailOtp'' | `EmailOtp#${number}`' description: Different types that can be used to approve an MFA request pattern: ^(CubeSigner|Totp|EmailOtp|EmailOtp#\d+|Fido|FidoKey#[^#\s]+)$ PolicyErrorCode: oneOf: - $ref: '#/components/schemas/PolicyErrorOwnCodes' - $ref: '#/components/schemas/EvmTxDepositErrorCode' PolicyType: type: string description: 'The type of a [NamedPolicy]. The type of a policy is set at creation time, and is used to offer guarantees about the current and all future versions of a [NamedPolicy].' enum: - Key - Role - Wasm MfaRequestInfo: type: object description: Returned as a response from multiple routes (e.g., 'get mfa', 'approve mfa', 'approve totp'). required: - id - expires_at - request - status - created_by - provenance properties: created_at: $ref: '#/components/schemas/EpochDateTime' created_by: type: string description: The session identity (user or role) that created this request. expires_at: $ref: '#/components/schemas/EpochDateTime' id: type: string description: Approval request ID. not_valid_until: $ref: '#/components/schemas/EpochDateTime' provenance: type: string description: MFA policy provenance enum: - Org - Key - KeyInRole - Role - User - EditPolicy receipt: allOf: - $ref: '#/components/schemas/Receipt' nullable: true region: type: string description: The region this MFA request was created in. It can only be redeemed from the same region. related_ids: type: array items: type: string description: 'If set, contains the IDs of all MFA requests (including this one!) that were generated at once for the same CubeSigner operation. If not set, it means that this was the lone MFA request generated for `request`. This is useful so that a client can discover all the MFAs whose receipts must be submitted together to carry out the original CubeSigner operation.' request: $ref: '#/components/schemas/HttpRequest' status: $ref: '#/components/schemas/Status' BadRequestErrorCode: type: string enum: - GenericBadRequest - DisallowedAllowRuleReference - InvalidPaginationToken - InvalidEmail - InvalidEmailTemplate - QueryMetricsError - InvalidTelegramData - ValidationError - WebhookPolicyTimeoutOutOfBounds - WebhookPolicyDisallowedUrlScheme - WebhookPolicyDisallowedUrlHost - WebhookPolicyDisallowedHeaders - ReservedName - UserEmailNotConfigured - EmailPasswordNotFound - PasswordAuthNotAllowedByInvitation - OneTimeCodeExpired - InvalidBody - InvalidJwt - InvitationNoLongerValid - TokenRequestError - InvalidMfaReceipt - InvalidMfaPolicyCount - InvalidMfaPolicyNumAuthFactors - InvalidMfaPolicyNumAllowedApprovers - InvalidMfaPolicyGracePeriodTooLong - InvalidBabylonStakingPolicyParams - InvalidSuiTxReceiversEmptyAllowlist - InvalidBtcTxReceiversEmptyAllowlist - InvalidRequireRoleSessionAllowlist - InvalidCreateKeyCount - InvalidDiffieHellmanCount - OrgInviteExistingUser - OrgUserAlreadyExists - OrgNameTaken - KwkNotFoundInRegion - OrgIsNotOrgExport - RoleNameTaken - PolicyNameTaken - NameTaken - ContactNameInvalid - ContactAddressesInvalid - ContactLabelInvalid - ContactModified - PolicyNotFound - PolicyVersionNotFound - PolicyRuleDisallowedByType - PolicyTypeDisallowed - PolicyDuplicateError - PolicyStillAttached - PolicyModified - PolicyNotAttached - AddKeyToRoleCountTooHigh - InvalidKeyId - InvalidTimeLockAlreadyInThePast - InvalidRestrictedScopes - InvalidUpdate - InvalidMetadataLength - InvalidLength - InvalidKeyMaterialId - KeyNotFound - SiweChallengeNotFound - SiweInvalidRequest - SiwsChallengeNotFound - SiwsInvalidRequest - UserExportDerivedKey - UserExportPublicKeyInvalid - NistP256PublicKeyInvalid - UnableToAccessSmtpRelay - UserExportInProgress - RoleNotFound - InvalidRoleNameOrId - InvalidMfaReceiptOrgIdMissing - InvalidMfaReceiptInvalidOrgId - MfaRequestNotFound - InvalidKeyType - InvalidPropertiesForKeyType - MismatchedKeyPropertiesPatch - MissingBinanceApiKey - MissingBybitApiKey - MissingCoinbaseApiKey - BinanceKeyMasterMismatch - BybitAccountMismatch - InvalidKeyMaterial - InvalidHexValue - InvalidBase32Value - InvalidBase58Value - InvalidBase64Value - InvalidSs58Value - InvalidForkVersionLength - InvalidEthAddress - InvalidStellarAddress - InvalidOrgNameOrId - InvalidUpdateOrgRequestDisallowedMfaType - InvalidUpdateOrgRequestEmptyAllowedMfaTypes - EmailOtpDelayTooShortForRegisterMfa - InvalidStakeDeposit - InvalidBlobSignRequest - InvalidDiffieHellmanRequest - InvalidSolanaSignRequest - InvalidEip712SignRequest - InvalidEip7702SignRequest - OnlySpecifyOne - IncompatibleParams - NoOidcDataInProof - InvalidEvmSignRequest - InvalidEth2SignRequest - InvalidDeriveKeyRequest - InvalidStakingAmount - CustomStakingAmountNotAllowedForWrapperContract - InvalidUnstakeRequest - InvalidCreateUserRequest - UserAlreadyExists - IdpUserAlreadyExists - CognitoUserAlreadyOrgMember - UserNotFound - UserWithEmailNotFound - PolicyKeyMismatch - EmptyScopes - InvalidScopesForRoleSession - InvalidLifetime - NoSingleKeyForUser - InvalidOrgPolicyRule - SourceIpAllowlistEmpty - LimitWindowTooLong - Erc20ContractDisallowed - EmptyRuleError - PolicyFieldValidationError - OptionalListEmpty - MultipleExclusiveFieldsProvided - DuplicateFieldEntry - InvalidRange - InvalidOrgPolicyRepeatedRule - InvalidSuiTransaction - SuiSenderMismatch - AvaSignHashError - AvaSignError - BtcSegwitHashError - BtcTaprootHashError - BtcSignError - TaprootSignError - Eip712SignError - InvalidMemberRoleInUserAdd - InvalidMemberRoleInRecipientAdd - ThirdPartyUserAlreadyExists - OidcIdentityAlreadyExists - UserAlreadyHasIdentity - ThirdPartyUserNotFound - DeleteOidcUserError - DeleteUserError - SessionRoleMismatch - InvalidOidcToken - InvalidOidcIdentity - OidcIssuerUnsupported - OidcIssuerNotAllowed - OidcIssuerNoApplicableJwk - FidoKeyAlreadyRegistered - FidoKeySignCountTooLow - FidoVerificationFailed - FidoChallengeMfaMismatch - UnsupportedLegacyCognitoSession - InvalidIdentityProof - PaginationDataExpired - ExistingKeysViolateExclusiveKeyAccess - ExportDelayTooShort - ExportWindowTooLong - InvalidTotpFailureLimit - InvalidEip191SignRequest - CannotResendUserInvitation - InvalidNotificationEndpointCount - CannotDeletePendingSubscription - InvalidNotificationUrlProtocol - EmptyOneOfOrgEventFilter - EmptyAllExceptOrgEventFilter - InvalidTapNodeHash - InvalidOneTimeCode - MessageNotFound - MessageAlreadySigned - MessageRejected - MessageReplaced - InvalidMessageType - EmptyAddress - InvalidEth2SigningPolicySlotRange - InvalidEth2SigningPolicyEpochRange - InvalidEth2SigningPolicyTimestampRange - InvalidEth2SigningPolicyOverlappingRule - RpcUrlMissing - MmiChainIdMissing - EthersInvalidRpcUrl - EthersGetTransactionCountError - InvalidPassword - BabylonStakingFeePlusDustOverflow - BabylonStaking - BabylonStakingIncorrectKey - BabylonStakingSegwitNonDeposit - BabylonStakingRegistrationRequiresTaproot - PsbtSigning - TooManyResets - TooManyRequests - TooManyFailedLogins - BadBtcMessageSignP2shFlag - InvalidTendermintRequest - PolicyVersionMaxReached - PolicyVersionInvalid - PolicySecretLimitReached - PolicySecretTooLarge - InvalidImportKey - AlienOwnerInvalid - EmptyUpdateRequest - InvalidPolicyReference - PolicyEngineDisabled - InvalidWasmPolicy - CelProgramTooLarge - InvalidPolicy - RedundantDerivationPath - ImportKeyMissing - InvalidAbiMethods - BabylonCovSign - InvalidPolicyLogsRequest - UserProfileMigrationMultipleEntries - UserProfileMigrationTooManyItems - InputTooShort - InvalidTweakLength - InvalidCustomChains - InvalidRpcRequest SignerErrorOwnCodes: type: string enum: - PreComputed - StatusCodeWithMessage - JrpcError - UnhandledError - ProxyStartError - EnclaveError - PolicyErrorWithEvalTree - RpcApi Scope: oneOf: - $ref: '#/components/schemas/ExplicitScope' - type: string title: OtherScopes description: Scopes including wildcard fragments for accessing CubeSigner APIs pattern: ^(orgAccess:child)(:[^:]+)?$ description: All scopes for accessing CubeSigner APIs UpdatePolicyRequest: type: object description: Request body for updating a named policy. properties: acl: description: New Access-control entries. nullable: true edit_policy: allOf: - $ref: '#/components/schemas/EditPolicy' nullable: true metadata: description: A new metadata. nullable: true name: type: string description: A new name for the policy. nullable: true owner: type: string description: A new owner for the policy. nullable: true rules: type: array items: {} description: New policy rules. nullable: true BucketInfo: allOf: - allOf: - type: object description: 'Versioning fields (e.g., version number, creation time, and last modified times) that are common to different types of resources.' properties: created: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true last_modified: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true version: type: integer format: int64 description: Version of this object minimum: 0 - type: object required: - owner - org_id properties: acl: type: array items: {} description: The access-control entries for the bucket. nullable: true metadata: description: Arbitrary user-defined metadata. org_id: $ref: '#/components/schemas/Id' owner: $ref: '#/components/schemas/Id' description: 'Sub-entity of org where per-bucket metadata (like ACL) is stored. The [Id] of a [BucketMeta] must be the bucket name.' - type: object required: - name properties: name: type: string description: The name of the bucket. description: Information about a policy KV store bucket. Seconds: type: integer format: int64 description: 'Duration measured in seconds A wrapper type for serialization that encodes a `Duration` as a `u64` representing the number of seconds.' minimum: 0 UpdatePolicySecretsRequest: type: object description: A request for updating Org-level policy secrets properties: edit_policy: allOf: - $ref: '#/components/schemas/EditPolicy' nullable: true PreconditionErrorCode: oneOf: - $ref: '#/components/schemas/PreconditionErrorOwnCodes' - $ref: '#/components/schemas/PolicyErrorCode' MfaPolicy: type: object properties: allowed_approvers: type: array items: type: string description: Users who are allowed to approve. If empty at creation time, default to the current user. allowed_mfa_types: type: array items: $ref: '#/components/schemas/MfaType' description: Allowed approval types. When omitted, defaults to any. nullable: true count: type: integer format: int32 description: How many users to require to approve (defaults to 1). minimum: 0 lifetime: $ref: '#/components/schemas/Seconds' num_auth_factors: type: integer format: int32 description: How many auth factors to require per user (defaults to 1). minimum: 0 request_comparer: $ref: '#/components/schemas/HttpRequestCmp' restricted_operations: type: array items: $ref: '#/components/schemas/OperationKind' description: 'CubeSigner operations to which this policy should apply. When omitted, applies to all operations.' nullable: true time_delay: $ref: '#/components/schemas/Seconds' example: allowed_approvers: - User#fabc3f88-04e0-471b-9657-0ae12a3cd73e - User#d796c369-9974-473b-ab9e-e4a2418d2d07 count: 2 lifetime: 900 UploadObjectHash: type: string format: binary description: The SHA-256 hash of the object for an [UploadRequest]. NewSessionResponse: type: object description: Information about a new session, returned from multiple endpoints (e.g., login, refresh, etc.). required: - org_id - token - refresh_token - session_info properties: expiration: type: integer format: int64 description: Session expiration (in seconds since UNIX epoch), beyond which it cannot be refreshed. example: 1701879640 minimum: 0 org_id: $ref: '#/components/schemas/Id' refresh_token: type: string description: Token that can be used to refresh this session. session_info: $ref: '#/components/schemas/ClientSessionInfo' token: type: string description: 'New token to be used for authentication. Requests to signing endpoints should include this value in the `Authorization` header.' HttpRequest: type: object description: 'Information about the request. Captures all the relevant info (including the request body) about requests that require MFA. We use this to verify that when a request is resumed (after obtaining necessary MFA approvals) it is exactly the same as it originally was.' required: - method - path properties: body: type: object description: HTTP request body nullable: true method: type: string description: HTTP method of the request path: type: string description: HTTP path of the request, excluding the host ApprovalInfo: type: object required: - timestamp properties: timestamp: $ref: '#/components/schemas/EpochDateTime' Receipt: type: object description: Receipt that an MFA request was approved. required: - confirmation - final_approver - timestamp properties: confirmation: type: string description: Confirmation code the user needs to present when resuming the original request. example: ba1d75dd-d999-4c1b-944d-25c25440c8af final_approver: type: string description: The ID of the logged-in user whose action created this approval. timestamp: $ref: '#/components/schemas/EpochDateTime' UnauthorizedErrorCode: type: string enum: - AuthorizationHeaderMissing - EndpointRequiresUserSession - RefreshTokenMissing AcceptedResponse: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object SetPolicySecretRequest: type: object description: 'A request for setting an Org-level policy secret. Either `value` or `acl` must be provided.' properties: acl: description: 'The secret''s access-control entries. Can be `None` if the request is creating a secret without ACL or updating an existing secret''s value.' nullable: true import_key: allOf: - $ref: '#/components/schemas/KeyImportKey' nullable: true value: allOf: - $ref: '#/components/schemas/SecretValue' nullable: true TimeoutErrorCode: type: string enum: - PolicyEngineTimeout - WasmPolicyExecutionTimeout ForbiddenErrorCode: type: string enum: - AlienKeyCreate - CannotAssumeIdentity - SentryDisallowed - PasskeyLoginDisabled - PasskeyNotRegistered - CannotCreateOrg - WrongMfaEmailOtpJwt - OrgFlagNotSet - FidoRequiredToRemoveTotp - OidcIdentityLimitReached - OidcScopeCeilingMissing - OidcIssuerNotAllowedForMemberRole - OidcNoMemberRolesAllowed - EmailOtpNotConfigured - MfaChallengeExpired - ChainIdNotAllowed - InvalidOrg - OrgIdMismatch - SessionForWrongOrg - SelfDelete - SelfDisable - SelfMfaReset - InvalidOrgMembershipRoleChange - UserDisabled - OrgDisabled - OrgNotFound - OrgWithoutOwner - OrphanedUser - OidcUserNotFound - UserNotInOrg - UserNotOrgOwner - UserNotKeyOwner - InvalidRole - DisabledRole - KeyDisabled - KeyNotInRole - ContactNotInOrg - UserExportRequestNotInOrg - UserExportRequestInvalid - UserExportDisabled - UserNotOriginalKeyOwner - UserNotInRole - MustBeFullMember - SessionExpired - SessionChanged - SessionRevoked - ExpectedUserSession - SessionRoleChanged - ScopedNameNotFound - SessionInvalidEpochToken - SessionInvalidRefreshToken - SessionRefreshTokenExpired - InvalidAuthHeader - SessionNotFound - InvalidArn - SessionInvalidAuthToken - SessionAuthTokenExpired - SessionPossiblyStolenToken - MfaDisallowedIdentity - MfaDisallowedApprover - MfaTypeNotAllowed - MfaNotApprovedYet - MfaConfirmationCodeMismatch - MfaHttpRequestMismatch - MfaRemoveBelowMin - MfaOrgRequirementNotMet - MfaRegistrationDisallowed - TotpAlreadyConfigured - TotpConfigurationChanged - MfaTotpBadConfiguration - MfaTotpBadCode - MfaTotpRateLimit - ImproperSessionScope - FullSessionRequired - SessionWithoutAnyScopeUnder - UserRoleUnprivileged - MemberRoleForbidden - MfaNotConfigured - RemoveLastOidcIdentity - OperationNotAllowed - OrgExportRetrievalDisabled - ChangingKeyExportRequirementIsDisabled - AutoAddBlsKeyToProtectedRole - UserNotPolicyOwner - UserNotContactOwner - UserNotBucketOwner - LegacySessionCannotHaveScopeCeiling - RoleInParentOrgNotAllowed - RemoveKeyFromRoleUserNotAllowed - SiweChallengeExpired - SiweMessageNotValid - SiweMessageInvalidSignature - SiwsChallengeExpired - SiwsDomain - SiwsMessageInvalid - Acl PolicyLogsRequest: type: object description: A request for querying Wasm policy logs. properties: end_time: type: integer format: int64 description: End time in seconds since unix epoch. If omitted, defaults to 'now'. nullable: true minimum: 0 start_time: type: integer format: int64 description: Start time in seconds since unix epoch. If omitted, defaults to 24 hours ago. nullable: true minimum: 0 version: type: string description: 'The version of the policy to get the logs for. If omitted, all policy logs are retrieved.' nullable: true CreatePolicyRequest: type: object description: Request for creating a named policy required: - rules - name - policy_type properties: acl: type: array items: {} description: 'Access-control entries defining how the policy can be accessed, modified, attached and executed.' example: - action: attach resources: - key_id: '*' role_id: Role#e427c28a-9c5b-49cc-a257-878aea58a22c subjects: '*' - action: sign subjects: Role#e427c28a-9c5b-49cc-a257-878aea58a22c nullable: true edit_policy: allOf: - $ref: '#/components/schemas/EditPolicy' nullable: true metadata: description: Optional metadata. nullable: true name: type: string description: 'The policy name. Must be unique among the named policies in this org. Duplicate policy names will be rejected.' example: my_policy pattern: ^[_a-zA-Z0-9]{3,30}$ policy_type: $ref: '#/components/schemas/PolicyType' rules: type: array items: {} description: The policy rules. example: - RequireMfa: count: 1 Status: type: object required: - count - num_auth_factors - allowed_approvers - approved_by properties: allowed_approvers: type: array items: type: string description: Users who are allowed to approve. Must be non-empty. allowed_mfa_types: type: array items: $ref: '#/components/schemas/MfaType' description: Allowed approval types. When omitted, defaults to any. nullable: true approved_by: type: object description: Users who have already approved additionalProperties: type: object additionalProperties: $ref: '#/components/schemas/ApprovalInfo' count: type: integer format: int32 description: How many users must approve minimum: 0 num_auth_factors: type: integer format: int32 description: How many auth factors to require per user minimum: 0 request_comparer: $ref: '#/components/schemas/HttpRequestCmp' EvmTxCmp: type: object properties: grace: type: integer format: int64 description: 'To prevent replay attacks, any given MFA receipt is normally allowed to be used only once. In this case, however, because EVM transactions already have a replay prevention mechanism (namely the ''nonce'' property), we allow the user to specify a grace period (in seconds) to indicate how long an MFA receipt should remain valid after its first use. Note that we allow both ''grace'' and ''ignore_nonce'' to be set because once an MFA request enters its grace period we unconditionally set its ''ignore_nonce'' property to ''false'' to ensure that any subsequent requests that claim the same receipt must sign for the same nonce as the request we signed originally with that receipt. Also note that the grace period cannot extend the lifetime of an MFA request beyond its original expiration date. The grace period must not be greater than 30 days.' nullable: true minimum: 0 ignore_gas: type: boolean description: Whether the 'gas' property of the EVM transaction is allowed to be different. ignore_nonce: type: boolean description: Whether the 'nonce' property of the EVM transaction is allowed to be different. responses: PaginatedPolicyLogsResponse: description: '' content: application/json: schema: allOf: - type: object description: A set of logs for a Wasm policy. required: - logs properties: logs: type: array items: type: object additionalProperties: type: string description: The policy execution logs - type: object properties: last_evaluated_key: type: string description: 'If set, the content of `response` does not contain the entire result set. To fetch the next page of the result set, call the same endpoint but specify this value as the ''page.start'' query parameter.' nullable: true description: 'Response type that wraps another type and adds base64url-encoded encrypted `last_evaluated_key` value (which can the user pass back to use as a url query parameter to continue pagination).' PaginatedListPoliciesResponse: description: '' content: application/json: schema: allOf: - type: object description: Response to a request for listing all of an Org's named policies. required: - policies properties: policies: type: array items: $ref: '#/components/schemas/PolicyInfo' description: The Org's named policies. - type: object properties: last_evaluated_key: type: string description: 'If set, the content of `response` does not contain the entire result set. To fetch the next page of the result set, call the same endpoint but specify this value as the ''page.start'' query parameter.' nullable: true description: 'Response type that wraps another type and adds base64url-encoded encrypted `last_evaluated_key` value (which can the user pass back to use as a url query parameter to continue pagination).' PolicySecretsInfo: description: A struct containing all non-secret information about policy secrets. content: application/json: schema: allOf: - $ref: '#/components/schemas/CommonFields' - type: object required: - names - secrets properties: names: type: array items: type: string description: The names of the secrets. deprecated: true uniqueItems: true secrets: type: array items: $ref: '#/components/schemas/SecretInfo' description: The policy secrets. description: A struct containing all non-secret information about policy secrets. CreatePolicyImportKeyResponse: description: 'The response to [create_import_key] containing the generated key and enclave attestations.' content: application/json: schema: allOf: - $ref: '#/components/schemas/KeyImportKey' - type: object required: - enclave_attestation - enclave_signature properties: enclave_attestation: type: string description: 'An attestation document from a secure enclave, including an RSA signing key used to sign the contents of this message.' enclave_signature: type: string description: 'An RSA-PSS-SHA256 signature on the public key and encrypted secrets attesting to their generation inside a secure enclave.' description: 'The response to [create_import_key] containing the generated key and enclave attestations.' PolicyInfo: description: A struct containing all the information about a specific version of a policy. content: application/json: schema: type: object description: A struct containing all the information about a specific version of a policy. required: - policy_id - rules - version - name - policy_type - created - owner - attached_to properties: acl: type: array items: {} description: The access-control entries for the policy. nullable: true attached_to: type: array items: $ref: '#/components/schemas/PolicyAttachedToId' description: A list of entities (keys, roles, etc.) the policy is attached to. created: $ref: '#/components/schemas/EpochDateTime' edit_policy: $ref: '#/components/schemas/EditPolicy' metadata: description: User-defined metadata for the named policy. name: type: string description: The name of the policy. owner: $ref: '#/components/schemas/Id' policy_id: type: string description: The policy id policy_type: $ref: '#/components/schemas/PolicyType' rules: type: array items: {} description: The policy rule. version: type: integer format: int64 description: The policy rule's version. minimum: 0 EmptyImpl: description: '' content: application/json: schema: type: object required: - status properties: status: type: string PaginatedListBucketsResponse: description: '' content: application/json: schema: allOf: - type: object description: A list of policy KV store buckets. required: - buckets properties: buckets: type: array items: $ref: '#/components/schemas/BucketInfo' description: The buckets in the organization. - type: object properties: last_evaluated_key: type: string description: 'If set, the content of `response` does not contain the entire result set. To fetch the next page of the result set, call the same endpoint but specify this value as the ''page.start'' query parameter.' nullable: true description: 'Response type that wraps another type and adds base64url-encoded encrypted `last_evaluated_key` value (which can the user pass back to use as a url query parameter to continue pagination).' BucketInfo: description: Information about a policy KV store bucket. content: application/json: schema: allOf: - allOf: - type: object description: 'Versioning fields (e.g., version number, creation time, and last modified times) that are common to different types of resources.' properties: created: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true last_modified: allOf: - $ref: '#/components/schemas/EpochDateTime' nullable: true version: type: integer format: int64 description: Version of this object minimum: 0 - type: object required: - owner - org_id properties: acl: type: array items: {} description: The access-control entries for the bucket. nullable: true metadata: description: Arbitrary user-defined metadata. org_id: $ref: '#/components/schemas/Id' owner: $ref: '#/components/schemas/Id' description: 'Sub-entity of org where per-bucket metadata (like ACL) is stored. The [Id] of a [BucketMeta] must be the bucket name.' - type: object required: - name properties: name: type: string description: The name of the bucket. description: Information about a policy KV store bucket. InvokePolicyResponse: description: The result of invoking a Wasm policy. content: application/json: schema: type: object description: The result of invoking a Wasm policy. required: - response - stdout - stderr properties: response: $ref: '#/components/schemas/WasmPolicyResponse' stderr: type: string description: 'The bytes written to `stderr`, encoded as a hex-string. In most cases, these bytes correspond to a UTF-8-encoded `String`.' stdout: type: string description: 'The bytes written to `stdout`, encoded as a hex-string. In most cases, these bytes correspond to a UTF-8-encoded `String`.' UploadWasmPolicyResponse: description: The response to a request for uploading a wasm policy content: application/json: schema: type: object description: The response to a request for uploading a wasm policy required: - signed_url properties: signed_url: type: string description: A signed URL for uploading the requested wasm policy. securitySchemes: Oidc: type: apiKey in: header name: Authorization description: OIDC tokens allow users to authenticate using a third-party service. These are exchanged for signer session tokens. SignerAuth: type: apiKey in: header name: Authorization description: Signing API end-points use session tokens for auth. Specifically, with each request you need to use the \`token\` from your signer session (which you create with `cs token create`).