openapi: 3.2.0 info: title: Dependency Track OAuth API version: 2.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track email: dependencytrack@owasp.org license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged OAuth across 2 of this provider''s published API definitions: dependency-track-openapi-v2.yaml, dependency-track-v2-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api/v2 security: - apiKeyAuth: [] - bearerAuth: [] tags: - name: OAuth description: Endpoints related to OAuth 2.0 token issuance paths: /oauth/token: post: tags: - OAuth summary: Create a Dependency-Track access token description: 'Creates an access token for the requested grant. The access token is an opaque session token. Send it in the `Authorization` header, as `Bearer `. `scope` is not supported. The only grant supported is RFC 8693 token exchange, which requires `subject_token` and `subject_token_type`. Exchanges for a session of a service account also require `workload_identity_provider` and `service_account`, and succeed when a binding of the requested service account matches the subject token. The resulting session has all permissions of the service account.' operationId: createOAuthToken requestBody: content: application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/create-oauth-token-request' required: true responses: '200': description: The access token headers: Cache-Control: description: Always `no-store` schema: maxLength: 32 type: string Pragma: description: Always `no-cache` schema: maxLength: 32 type: string content: application/json: schema: $ref: '#/components/schemas/create-oauth-token-response' '400': description: The request was refused. An unsupported grant yields `unsupported_grant_type`, every other refusal yields `invalid_request`. headers: Cache-Control: description: Always `no-store` schema: maxLength: 32 type: string Pragma: description: Always `no-cache` schema: maxLength: 32 type: string content: application/json: schema: $ref: '#/components/schemas/oauth-token-error' '503': description: The grant cannot be processed because a dependency is unavailable, such as the keys to verify a subject token. Retrying later may succeed. content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' default: $ref: '#/components/responses/generic-error' security: [] servers: - url: /api/v2 components: responses: generic-error: description: Unexpected error content: application/problem+json: schema: $ref: '#/components/schemas/problem-details' schemas: create-oauth-token-response: required: - access_token - expires_in - issued_token_type - token_type type: object properties: access_token: maxLength: 8192 type: string description: An access token. issued_token_type: maxLength: 64 type: string description: Always `urn:ietf:params:oauth:token-type:access_token`. example: urn:ietf:params:oauth:token-type:access_token token_type: maxLength: 32 type: string description: Always `Bearer`. example: Bearer expires_in: maximum: 86400 minimum: 60 type: integer description: How many seconds the access token is valid for. For token exchange, this is the workload identity provider's `session_lifetime_seconds`. format: int32 example: 3600 problem-details: required: - detail - title - type type: object properties: type: type: string description: A URI reference that identifies the problem type format: uri-reference default: about:blank status: maximum: 599 minimum: 400 type: integer description: HTTP status code generated by the origin server for this occurrence of the problem format: int32 example: 500 title: maxLength: 255 type: string description: Short, human-readable summary of the problem type detail: maxLength: 1024 type: string description: Human-readable explanation specific to this occurrence of the problem instance: type: string description: Reference URI that identifies the specific occurrence of the problem format: uri-reference description: An RFC 9457 problem object. externalDocs: url: https://www.rfc-editor.org/rfc/rfc9457.html x-parent: true workload-identity-provider-name: maxLength: 63 pattern: ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ type: string description: The name of the workload identity provider. example: github-actions create-oauth-token-request: required: - grant_type type: object properties: grant_type: maxLength: 64 type: string description: The grant type. Only `urn:ietf:params:oauth:grant-type:token-exchange` is supported. example: urn:ietf:params:oauth:grant-type:token-exchange subject_token: maxLength: 16384 type: string description: The token to exchange. Required for the token exchange grant. At most 16 KiB. subject_token_type: maxLength: 64 type: string description: The type of the subject token. Required for the token exchange grant. `urn:ietf:params:oauth:token-type:jwt` for all workload identity providers, or `urn:ietf:params:oauth:token-type:id_token` for `OIDC` providers. example: urn:ietf:params:oauth:token-type:jwt requested_token_type: maxLength: 64 type: string description: The type of token to issue. Optional. Only `urn:ietf:params:oauth:token-type:access_token` is supported. example: urn:ietf:params:oauth:token-type:access_token workload_identity_provider: $ref: '#/components/schemas/workload-identity-provider-name' service_account: $ref: '#/components/schemas/service-account-name' service-account-name: maxLength: 59 pattern: ^(?![sS][vV][cC]:)[a-zA-Z0-9][a-zA-Z0-9+=,.:@_-]*$ type: string description: The name of the service account, without the reserved `svc:` prefix. example: ci-pipeline oauth-token-error: required: - error type: object properties: error: maxLength: 64 type: string description: The RFC 6749 error code, either `invalid_request` or `unsupported_grant_type`. example: invalid_request error_description: maxLength: 256 type: string description: A short, generic description of the error. securitySchemes: apiKeyAuth: type: apiKey description: Authentication via API key. name: X-Api-Key in: header bearerAuth: type: http description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login`, `POST /api/v1/user/oidc/login`, or `POST /api/v2/oauth/token`.' scheme: bearer bearerFormat: Opaque x-refined-from: - dependency-track-openapi-v2.yaml - dependency-track-v2-openapi.yml