openapi: 3.0.0 info: version: 2015-07-09 x-release: v4 title: APIs.io Engineering Platform Amazon API Gateway 2014 11 13 Access Identity Providers API description: Amazon API Gateway

Amazon API Gateway helps developers deliver robust, secure, and scalable mobile and web application back ends. API Gateway allows developers to securely connect mobile and web applications to APIs that run on AWS Lambda, Amazon EC2, or other publicly addressable web services that are hosted outside of AWS.

x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: apigateway x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/apigateway-2015-07-09.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://apigateway.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon API Gateway multi-region endpoint - url: https://apigateway.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon API Gateway multi-region endpoint - url: http://apigateway.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia) - url: https://apigateway.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: Access Identity Providers paths: /accounts/{account_id}/access/identity_providers: get: description: Lists all configured identity providers. operationId: access-identity-providers-list-access-identity-providers parameters: - in: path name: account_id required: true schema: $ref: '#/components/schemas/access_identifier' responses: 4XX: content: application/json: schema: $ref: '#/components/schemas/access_api-response-common-failure' description: List Access identity providers response failure '200': content: application/json: schema: $ref: '#/components/schemas/access_response_collection' description: List Access identity providers response security: - api_email: [] api_key: [] summary: APIs.io Engineering Platform List Access identity providers tags: - Access Identity Providers x-api-token-group: - 'Access: Organizations, Identity Providers, and Groups Write' - 'Access: Organizations, Identity Providers, and Groups Read' post: description: Adds a new identity provider to Access. operationId: access-identity-providers-add-an-access-identity-provider parameters: - in: path name: account_id required: true schema: $ref: '#/components/schemas/access_identifier' requestBody: content: application/json: schema: $ref: '#/components/schemas/access_identity-providers' required: true responses: 4XX: content: application/json: schema: $ref: '#/components/schemas/access_api-response-common-failure' description: Add an Access identity provider response failure '201': content: application/json: schema: $ref: '#/components/schemas/access_components-schemas-single_response' description: Add an Access identity provider response security: - api_email: [] api_key: [] summary: APIs.io Engineering Platform Add an Access identity provider tags: - Access Identity Providers x-api-token-group: - 'Access: Organizations, Identity Providers, and Groups Write' /accounts/{account_id}/access/identity_providers/{identity_provider_id}: delete: description: Deletes an identity provider from Access. operationId: access-identity-providers-delete-an-access-identity-provider parameters: - in: path name: identity_provider_id required: true schema: $ref: '#/components/schemas/access_uuid' - in: path name: account_id required: true schema: $ref: '#/components/schemas/access_identifier' responses: 4XX: content: application/json: schema: $ref: '#/components/schemas/access_api-response-common-failure' description: Delete an Access identity provider response failure '202': content: application/json: schema: $ref: '#/components/schemas/access_id_response' description: Delete an Access identity provider response security: - api_email: [] api_key: [] summary: APIs.io Engineering Platform Delete an Access identity provider tags: - Access Identity Providers x-api-token-group: - 'Access: Organizations, Identity Providers, and Groups Write' get: description: Fetches a configured identity provider. operationId: access-identity-providers-get-an-access-identity-provider parameters: - in: path name: identity_provider_id required: true schema: $ref: '#/components/schemas/access_uuid' - in: path name: account_id required: true schema: $ref: '#/components/schemas/access_identifier' responses: 4XX: content: application/json: schema: $ref: '#/components/schemas/access_api-response-common-failure' description: Get an Access identity provider response failure '200': content: application/json: schema: $ref: '#/components/schemas/access_components-schemas-single_response' description: Get an Access identity provider response security: - api_email: [] api_key: [] summary: APIs.io Engineering Platform Get an Access identity provider tags: - Access Identity Providers x-api-token-group: - 'Access: Organizations, Identity Providers, and Groups Write' - 'Access: Organizations, Identity Providers, and Groups Read' put: description: Updates a configured identity provider. operationId: access-identity-providers-update-an-access-identity-provider parameters: - in: path name: identity_provider_id required: true schema: $ref: '#/components/schemas/access_uuid' - in: path name: account_id required: true schema: $ref: '#/components/schemas/access_identifier' requestBody: content: application/json: schema: $ref: '#/components/schemas/access_identity-providers' required: true responses: 4XX: content: application/json: schema: $ref: '#/components/schemas/access_api-response-common-failure' description: Update an Access identity provider response failure '200': content: application/json: schema: $ref: '#/components/schemas/access_components-schemas-single_response' description: Update an Access identity provider response security: - api_email: [] api_key: [] summary: APIs.io Engineering Platform Update an Access identity provider tags: - Access Identity Providers x-api-token-group: - 'Access: Organizations, Identity Providers, and Groups Write' components: schemas: access_response_collection: allOf: - $ref: '#/components/schemas/access_api-response-collection' - properties: result: items: anyOf: - $ref: '#/components/schemas/access_azureAD' - $ref: '#/components/schemas/access_centrify' - $ref: '#/components/schemas/access_facebook' - $ref: '#/components/schemas/access_github' - $ref: '#/components/schemas/access_google' - $ref: '#/components/schemas/access_google-apps' - $ref: '#/components/schemas/access_linkedin' - $ref: '#/components/schemas/access_oidc' - $ref: '#/components/schemas/access_okta' - $ref: '#/components/schemas/access_onelogin' - $ref: '#/components/schemas/access_pingone' - $ref: '#/components/schemas/access_saml' - $ref: '#/components/schemas/access_yandex' type: array type: object type: object access_api-response-collection: allOf: - $ref: '#/components/schemas/access_api-response-common' - properties: result_info: $ref: '#/components/schemas/access_result_info' type: object access_pingone: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: ping_env_id: description: Your PingOne environment identifier example: 342b5660-0c32-4936-a5a4-ce21fae57b0a type: string type: object type: object title: PingOne type: object access_uuid: description: UUID example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415 maxLength: 36 type: string access_identifier: description: Identifier example: 023e105f4ecef8ad9ca31a8372d0c353 maxLength: 32 type: string access_identity-provider: properties: config: description: The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/). type: object id: $ref: '#/components/schemas/access_uuid' name: $ref: '#/components/schemas/access_components-schemas-name' scim_config: description: The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider. properties: enabled: description: A flag to enable or disable SCIM for the identity provider. type: boolean group_member_deprovision: description: A flag to revoke a user's session in Access and force a reauthentication on the user's Gateway session when they have been added or removed from a group in the Identity Provider. type: boolean seat_deprovision: description: A flag to remove a user's seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user_deprovision is also enabled. type: boolean secret: description: A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it token at /access/identity_providers/:idpID/refresh_scim_secret. type: string user_deprovision: description: A flag to enable revoking a user's session in Access and Gateway when they have been deprovisioned in the Identity Provider. type: boolean type: object type: description: The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/). enum: - onetimepin - azureAD - saml - centrify - facebook - github - google-apps - google - linkedin - oidc - okta - onelogin - pingone - yandex example: onetimepin type: string required: - name - type - config type: object access_oidc: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: auth_url: description: The authorization_endpoint URL of your IdP example: https://accounts.google.com/o/oauth2/auth type: string certs_url: description: The jwks_uri endpoint of your IdP to allow the IdP keys to sign the tokens example: https://www.googleapis.com/oauth2/v3/certs type: string scopes: description: OAuth scopes example: - openid - email - profile items: type: string type: array token_url: description: The token_endpoint URL of your IdP example: https://accounts.google.com/o/oauth2/token type: string type: object type: object title: Generic OAuth type: object access_yandex: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: $ref: '#/components/schemas/access_generic-oauth-config' type: object title: Yandex type: object access_result_info: properties: count: description: Total number of results for the requested service example: 1 type: number page: description: Current page within paginated list of results example: 1 type: number per_page: description: Number of results per page of results example: 20 type: number total_count: description: Total results available without any search parameters example: 2000 type: number type: object access_identity-providers: anyOf: - $ref: '#/components/schemas/access_azureAD' - $ref: '#/components/schemas/access_centrify' - $ref: '#/components/schemas/access_facebook' - $ref: '#/components/schemas/access_github' - $ref: '#/components/schemas/access_google' - $ref: '#/components/schemas/access_google-apps' - $ref: '#/components/schemas/access_linkedin' - $ref: '#/components/schemas/access_oidc' - $ref: '#/components/schemas/access_okta' - $ref: '#/components/schemas/access_onelogin' - $ref: '#/components/schemas/access_pingone' - $ref: '#/components/schemas/access_saml' - $ref: '#/components/schemas/access_yandex' - $ref: '#/components/schemas/access_onetimepin' access_api-response-common-failure: properties: errors: allOf: - $ref: '#/components/schemas/access_messages' example: - code: 7003 message: No route for the URI minLength: 1 messages: allOf: - $ref: '#/components/schemas/access_messages' example: [] result: enum: - null nullable: true type: object success: description: Whether the API call was successful enum: - false example: false type: boolean required: - success - errors - messages - result type: object access_google: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' type: object title: Google type: object access_azureAD: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: conditional_access_enabled: description: Should Cloudflare try to load authentication contexts from your account type: boolean directory_id: description: Your Azure directory uuid example: type: string prompt: description: Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn't presented with any interactive prompt. If the request can't be completed silently by using single-sign on, the Microsoft identity platform returns an interaction_required error. prompt=select_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether. enum: - login - select_account - none type: string support_groups: description: Should Cloudflare try to load groups from your account type: boolean type: object type: object title: Azure AD type: object access_centrify: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: centrify_account: description: Your centrify account url example: https://abc123.my.centrify.com/ type: string centrify_app_id: description: Your centrify app id example: exampleapp type: string type: object type: object title: Centrify type: object access_custom-claims-support: properties: claims: description: Custom claims example: - email_verified - preferred_username - custom_claim_name items: type: string type: array email_claim_name: description: The claim name for email in the id_token response. example: custom_claim_name type: string type: object access_generic-oauth-config: properties: client_id: description: Your OAuth Client ID example: type: string client_secret: description: Your OAuth Client Secret example: type: string type: object access_api-response-common: properties: errors: $ref: '#/components/schemas/access_messages' messages: $ref: '#/components/schemas/access_messages' success: description: Whether the API call was successful enum: - true example: true type: boolean required: - success - errors - messages type: object access_messages: example: [] items: properties: code: minimum: 1000 type: integer message: type: string required: - code - message type: object uniqueItems: true type: array access_onetimepin: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: type: object type: enum: - onetimepin title: One Time Pin type: object access_okta: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: authorization_server_id: description: Your okta authorization server id example: aus9o8wzkhckw9TLa0h7z type: string okta_account: description: Your okta account url example: https://dev-abc123.oktapreview.com type: string type: object type: object title: Okta type: object access_id_response: allOf: - $ref: '#/components/schemas/access_api-response-single' - properties: result: properties: id: $ref: '#/components/schemas/access_uuid' type: object access_components-schemas-name: description: The name of the identity provider, shown to users on the login page. example: Widget Corps IDP type: string access_facebook: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: $ref: '#/components/schemas/access_generic-oauth-config' type: object title: Facebook type: object access_components-schemas-single_response: allOf: - $ref: '#/components/schemas/access_api-response-single' - properties: result: $ref: '#/components/schemas/access_identity-providers' access_github: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: $ref: '#/components/schemas/access_generic-oauth-config' type: object title: GitHub type: object access_saml: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: properties: attributes: description: A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules. example: - group - department_code - divison items: type: string type: array email_attribute_name: description: The attribute name for email in the SAML response. example: Email type: string header_attributes: description: Add a list of attribute names that will be returned in the response header from the Access callback. items: properties: attribute_name: description: attribute name from the IDP type: string header_name: description: header that will be added on the request to the origin type: string type: object type: array idp_public_certs: description: X509 certificate to verify the signature in the SAML authentication response items: type: string type: array issuer_url: description: IdP Entity ID or Issuer URL example: https://whoami.com type: string sign_request: description: Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints. type: boolean sso_target_url: description: URL to send the SAML authentication requests to example: https://edgeaccess.org/idp/saml/login type: string type: object type: object title: Generic SAML type: object access_onelogin: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: onelogin_account: description: Your OneLogin account url example: https://mycompany.onelogin.com type: string type: object type: object title: OneLogin type: object access_linkedin: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: $ref: '#/components/schemas/access_generic-oauth-config' type: object title: LinkedIn type: object access_api-response-single: allOf: - $ref: '#/components/schemas/access_api-response-common' type: object access_google-apps: allOf: - $ref: '#/components/schemas/access_identity-provider' - properties: config: allOf: - $ref: '#/components/schemas/access_generic-oauth-config' - $ref: '#/components/schemas/access_custom-claims-support' - properties: apps_domain: description: Your companies TLD example: mycompany.com type: string type: object type: object title: Google Workspace type: object securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/apigateway/ x-hasEquivalentPaths: true