openapi: 3.2.0 info: title: Entur Authentication admin API version: 2026.10.0 contact: name: Entur Team Personalisering url: https://enturas.atlassian.net/wiki/spaces/CULP/overview email: team.personalisering@entur.org termsOfService: https://entur.org description: 'Operations tagged Authentication admin across 2 of this provider''s published API definitions: entur-customers-openapi.json, entur-customers-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://api.entur.io/customers/v2 security: - jwt: [] tags: - name: Authentication admin description: Api for verify credentials, generate and update password. paths: /profiles/{organisationId}/{email}/generate-password: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' put: tags: - Authentication admin summary: Generate password description: Generates a new password for a customer identified by organisationId (numeric) and email address. This endpoint requires an Internal or Partner jwt-token. operationId: generatePassword parameters: - name: organisationId in: path required: true style: simple explode: false schema: type: integer format: int64 - name: email in: path required: true style: simple explode: false schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/GeneratePasswordResponse' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '404': $ref: '#/components/responses/Error404' '500': $ref: '#/components/responses/Error500' x-entur-permissions: value: customers-profile-credentials:endre servers: - url: https://api.entur.io/customers/v2 /profiles/{customerNumber}/set-password: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' put: tags: - Authentication admin summary: Set password description: Set the password for the specified customer. This endpoint requires an Internal or Partner jwt-token. operationId: setPassword parameters: - name: customerNumber in: path required: true style: simple explode: false schema: type: integer format: int64 requestBody: content: application/json: schema: $ref: '#/components/schemas/NewPasswordRequest' required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CustomerResponse' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '404': $ref: '#/components/responses/Error404' '500': $ref: '#/components/responses/Error500' x-entur-permissions: value: customers-profile-credentials:endre servers: - url: https://api.entur.io/customers/v2 /profiles/{customerNumber}/change-password: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' put: tags: - Authentication admin summary: Change password description: Change password for a customer. This method will first validate that the given oldPassword is correct, before storing the new password. This endpoint requires an Internal or Partner jwt-token. operationId: changePassword parameters: - name: customerNumber in: path required: true style: simple explode: false schema: type: integer format: int64 requestBody: content: application/json: schema: $ref: '#/components/schemas/ChangePasswordRequest' required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CustomerResponse' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '404': $ref: '#/components/responses/Error404' '500': $ref: '#/components/responses/Error500' x-entur-permissions: value: customers-profile-credentials:endre servers: - url: https://api.entur.io/customers/v2 /profiles/verify-credentials: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' post: tags: - Authentication admin summary: Verify credentials description: Verify credentials for a customer. The customer is looked up based on the organisation Id of the logged on user, combined with the email address provided in the input. operationId: verifyCredentials requestBody: content: application/json: schema: $ref: '#/components/schemas/VerifyCredentialsRequest' required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/CustomerResponse' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '500': $ref: '#/components/responses/Error500' x-entur-permissions: value: customers-profile-credentials:les servers: - url: https://api.entur.io/customers/v2 /authentication/generate-password: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' put: tags: - Authentication admin summary: Generate password and send email/sms for customer description: Generates a new password for a profile identified by organisationId and email address. The new password is sent to the customer via email and/or sms. operationId: generatePasswordOrchestrator parameters: - name: Authorization in: header required: true style: simple explode: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/GeneratePasswordRequest' required: true responses: '204': description: No Content '400': $ref: '#/components/responses/Error400_customers-orchestrator-customers' '401': $ref: '#/components/responses/Error401_customers-orchestrator-customers' '403': $ref: '#/components/responses/Error403_customers-orchestrator-customers' '404': $ref: '#/components/responses/Error404_customers-orchestrator-customers' '500': $ref: '#/components/responses/Error500_customers-orchestrator-customers' x-entur-permissions: value: customers-profile-credentials:endre servers: - url: https://api.entur.io/customers/v2 components: schemas: CustomerConsent: type: object properties: changedAt: type: string description: When the customer consent was last changed. format: date-time consentChoice: type: boolean description: Whether the customer has approved or declined this consent. consentCode: maxLength: 20 type: string description: The consent code. createdAt: type: string description: When the customer consent was created. format: date-time customerId: type: integer description: Id of the customer. format: int64 description: Legacy consents for a customer ErrorMessage: required: - errorCode - longEnglish - longNorwegian - shortEnglish - shortNorwegian type: object properties: errorCode: type: integer description: The error code. format: int32 longEnglish: type: string description: Long error message (English). longNorwegian: type: string description: Long error message (Norwegian). shortEnglish: type: string description: Short error message (English). shortNorwegian: type: string description: Short error message (Norwegian). description: 'An Error message. ' CustomerAccountResponse: required: - createdAt - createdBy - customerAccountId - customerNumber - id type: object properties: alias: type: string description: Alias for the customer account examples: - Tommy changedAt: type: string description: When the customer account was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' changedBy: type: string description: Who changed the customer account. createdAt: type: string description: When the customer account was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' createdBy: type: string description: Who created the customer account. customerAccountId: type: string description: Customer account id string examples: - ATB:CustomerAccount:abc58673cde-1c82-4bc5-989c-9d5eaa7ea866 customerNumber: type: integer description: Unique customer number format: int64 id: type: integer description: Customer account unique id. format: int64 isDefault: type: boolean description: True if the account is the default account for the customer description: Customer account connected to a customer LocalDateResponse: required: - day - month - year type: object properties: day: type: integer description: day of month format: int32 month: type: integer description: month number format: int32 year: type: integer description: year format: int32 description: Date as object NewPasswordRequest: required: - newPassword type: object properties: newPassword: maxLength: 100 minLength: 1 type: string description: The new password. validationErrors: type: array items: $ref: '#/components/schemas/ErrorMessage' description: The fields used for creating a new password for an user PostalAddressResponse: required: - changedAt - countryCode - createdAt - customerId - id - postCode - town - typeOfAddress type: object properties: addressLine1: maxLength: 80 type: string description: Address line 1. addressLine2: maxLength: 80 type: string description: Address line 2, often used for c/o information. changedAt: type: string description: When the postal address was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' countryCode: maxLength: 3 minLength: 3 type: string description: The address country code. ISO 3166-1 alpha-3 format examples: - NOR createdAt: type: string description: When the postal address was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' customerId: type: integer description: The customer connected to the address. format: int64 id: type: integer description: Postal address id. format: int64 postCode: maxLength: 10 type: string description: The address post code. town: maxLength: 50 type: string description: The address post town. typeOfAddress: type: string description: 'The type of address. Types supported: ''P'' = Private, ''I'' = Invoice, ''S'' = Shadow.' enum: - P - I - S verifiedAt: type: string description: When the address was verified. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' description: Postal address connected to a customer CustomerResponse: required: - changedAt - changedBy - changedByChannel - createdAt - createdBy - createdByChannel - customerNumber - firstName - organisationId - profileType - status - surname - uuid type: object properties: changedAt: type: string description: When the customer was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' changedBy: maxLength: 100 type: string description: Who last changed the customer. Either web, app or username of employee. Used for traceability in accordance with GDPR changedByChannel: maxLength: 100 type: string description: Which sales channel or system who last changed the customer. Used for traceability in accordance with GDPR countryCode: maxLength: 4 type: string description: Telephone number country code, starting with +. examples: - '+47' createdAt: type: string description: When the customer was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' createdBy: maxLength: 100 type: string description: Who created the customer. Either web, app or username of employee. Used for traceability in accordance with GDPR createdByChannel: maxLength: 100 type: string description: Which sales channel or system who created the customer. Used for traceability in accordance with GDPR customerAccountId: maxLength: 60 type: string description: Customer account id used for account based ticketing examples: - XYZ:CustomerAccount: customerAccounts: type: array description: Customer accounts used for account based ticketing items: $ref: '#/components/schemas/CustomerAccountResponse' customerConsents: type: array description: The legacy consents connected to the customer. items: $ref: '#/components/schemas/CustomerConsent' customerNumber: type: integer description: Customer number. format: int64 customerRef: maxLength: 40 type: string description: Optional customer reference. Defaults to customer number if not set. dateOfBirth: $ref: '#/components/schemas/LocalDateResponse' dateOfDeath: $ref: '#/components/schemas/LocalDateResponse' ecardOwnerships: type: array description: The ecards connected to the customer. items: $ref: '#/components/schemas/EcardOwnershipResponse' email: maxLength: 80 type: string description: Contact email. May become different from username emailOld: maxLength: 80 type: string description: When customer is deleted (status='D'), the value of 'email' is moved here to allow creation of a new customer with the same email. emailVerifiedAt: type: string description: When the email was verified. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' expirationDate: type: string description: The date when the customers personal data should be deleted. Personal data will be deleted continuously. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' firstName: maxLength: 50 type: string description: First and middle name. givenConsents: type: array description: The consents connected to the customer. Deprecated deprecated: true items: type: object description: The consents connected to the customer. Deprecated deprecated: true id: type: integer description: Customer id. Deprecated format: int64 deprecated: true landlineNumber: maxLength: 20 type: string description: Landline telephone number. languagePreference: type: string description: Deprecated, please use languagePreferenceISO6393. Which language the customer wants information in. Default is 'NO'. deprecated: true enum: - 'NO' - EN languagePreferenceISO6393: type: string description: Which language the customer wants information in. ISO 639-3 format. Default is 'NOB'. enum: - NOB - NNO - ENG lastSignInAt: type: string description: When the customer last signed in. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' lastSignInFrom: maxLength: 100 type: string description: Where the customer last signed in from. Typically web or app. Typically used to display to the user where the last login was performed. nationality: maxLength: 3 minLength: 3 type: string description: The customers nationality. ISO 3166-1 alpha-3 format examples: - NOR notes: type: array description: Deprecated. The notes connected to the customer. deprecated: true items: $ref: '#/components/schemas/NoteResponse' organisationId: type: integer description: The organisation the customer is registered with. format: int64 parentId: type: object description: Id of the parent customer. Used to connect different customer types. personnelTicketBearer: $ref: '#/components/schemas/PersonnelTicketBearer' postalAddresses: type: array description: The postal addresses connected to the customer. items: $ref: '#/components/schemas/PostalAddressResponse' preferences: type: array description: The preferences connected to the customer. items: $ref: '#/components/schemas/CustomerPreferenceResponse' profileType: type: string description: 'Type of profile. Types supported: ''S'' = Standard customer, ''P'' = Personnel ticket customer, ''T'' = Temporary customer. Default is ''S''.' enum: - S - P - T relatedCustomerNumbers: type: array description: The customer number of profiles which has been merged into the current profile. These may be used to lookup customer information in other systems items: type: integer description: The customer number of profiles which has been merged into the current profile. These may be used to lookup customer information in other systems format: int64 status: type: string description: 'Customer status. Statuses supported: ''A'' = Active, ''P'' = Passive, ''D'' = Deleted. Default is ''A''.' enum: - A - P - D surname: maxLength: 50 type: string description: Surname. telephoneNumber: maxLength: 20 type: string description: Deprecated. Please use countryCode and telephoneNumberNoCountryCode. Telephone number for customer. This should be a cell phone number. telephoneNumberNoCountryCode: maxLength: 12 type: string description: Telephone number without country code or punctuation. telephoneNumberVerifiedAt: type: string description: When the telephone number was verified. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' username: type: string description: Username the customer can use to log unto their profile. Only available on profile type S(tamkunde) and profile status A(ctive) uuid: maxLength: 32 minLength: 32 type: string description: A universal unique id for the customer. 32 random alphanumeric characters. Not RFC 4122 compliant examples: - 7018222E18CB5C46E05400144FF9F89C vippsId: type: string description: Deprecated. The field is no longer stored. Vipps unique user identifier. format: uuid deprecated: true description: A registered customer response ChangePasswordRequest: required: - newPassword - oldPassword type: object properties: newPassword: maxLength: 100 minLength: 1 type: string description: The new user password. oldPassword: maxLength: 100 minLength: 1 type: string description: The old user password. validationErrors: type: array items: $ref: '#/components/schemas/ErrorMessage' description: The fields used when verifying credentials GeneratePasswordRequest: required: - email type: object properties: email: minLength: 1 pattern: ^[a-zA-Z0-9æøåÆØÅ.!#$%&'*+/=?^_`{|}~-]+@[a-zA-Z0-9](?:[a-zA-Z0-9-æøåÆØÅ]{0,61}[a-zA-Z0-9æøåÆØÅ])?(?:\.[a-zA-Z0-9æøåÆØÅ](?:[a-zA-Z0-9-æøåÆØÅ]{0,61}[a-zA-Z0-9æøåÆØÅ])?)*$ type: string description: The email address identifying the profile examples: - customer@example.com organisationId: type: integer description: The organisation the profile belongs to. Default is tenant organisation ID. Only Internal tenants are allowed to override the organisation id format: int64 examples: - 1 description: Generate a new password for a profile identified by email and organisation id ErrorResponse: required: - correlationId - error - message - path - status - timestamp type: object properties: timestamp: type: string description: When the error occurred. format: date-time examples: - '2007-12-03T10:15:30+01:00' status: type: integer description: The http status code. format: int32 examples: - 400 errorCode: type: string description: Application specific error code examples: - '1033' error: type: string description: The http status reason. examples: - Bad request path: type: string description: The request URI. examples: - /loyaltyPrograms message: type: string description: The main error message. examples: - Validation failed for ... correlationId: type: string description: The unique correlation id for the request. examples: - b5d4960d-7ab2-43d6-a8f3-113da042a288 errors: type: array description: Optional list of error specifications. items: $ref: '#/components/schemas/ErrorSpecification' description: Response object for errors occurring in the customers API NoteResponse: required: - changedAt - changedBy - createdAt - createdBy - customerId - id - text type: object properties: changedAt: type: string description: When the note was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' changedBy: maxLength: 100 type: string description: Who last changed the note. createdAt: type: string description: When the note was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' createdBy: maxLength: 100 type: string description: Who created the note. customerId: type: integer description: Id of the customer connected to the note. format: int64 id: type: integer description: Note id. format: int64 text: maxLength: 4000 type: string description: Note content. description: Deprecated VerifyCredentialsRequest: required: - email - password type: object properties: email: maxLength: 80 type: string description: Email used for login. See property 'username' on CustomerResponse lastSignInFrom: maxLength: 100 type: string description: The place if login. Typically web or app. Typically used to display to the user where the last login was performed. password: maxLength: 100 minLength: 1 type: string description: Password used for login. validationErrors: type: array items: $ref: '#/components/schemas/ErrorMessage' description: The fields used when verifying credentials PersonnelTicketBearer: type: object properties: bearerCustomerId: type: integer format: int64 changedAt: type: string format: date-time createdAt: type: string format: date-time isSelfServedRetrieval: type: boolean ticketRightBearer: type: string ticketRightOwner: type: string description: The personnel tickets connected to the customer. Deprecated. Does not contain updated information. ErrorSpecification: required: - defaultMessage - field type: object properties: field: type: string description: The field of the associated object in the request related to the error. defaultMessage: type: string description: The message explaining why the error occurred. rejectedValues: type: object description: A list of rejected values. description: Optional list of error specifications. PreferenceResponse: required: - changedAt - createdAt - id - isActive - preferenceCode - preferenceDescription - preferenceType type: object properties: changedAt: type: string description: When the preference was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' createdAt: type: string description: When the preference was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' id: type: integer description: Preference id. format: int64 isActive: type: boolean description: Whether the preference is active. preferenceCode: maxLength: 20 type: string description: The preference code. preferenceDescription: maxLength: 255 type: string description: A description of the preference. preferenceType: maxLength: 20 type: string description: Type of preference. description: Preference CustomerPreferenceResponse: required: - changedAt - createdAt - preference - preferenceId type: object properties: changedAt: type: string description: When the customer preference was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' createdAt: type: string description: When the customer preference was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' customerId: type: integer description: Id of the customer. Deprecated format: int64 deprecated: true preference: $ref: '#/components/schemas/PreferenceResponse' preferenceId: type: integer description: Id of the preference format: int64 preferenceValue: maxLength: 100 minLength: 1 type: string description: Value of the preference. This can be things like membership number. description: Preferences response for a customer EcardOwnershipResponse: required: - changedAt - createdAt - customerId - ecardNumber - ecardNumber16digits - ecardOperator - id - startOfOwnership type: object properties: bookingDate: type: string description: When the physical ecard was booked. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' changedAt: type: string description: When the ecard was last changed. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' createdAt: type: string description: When the ecard was created. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' customerId: type: integer description: The customer connected to the ecard. Deprecated format: int64 deprecated: true ecardName: maxLength: 100 type: string description: Customer defined ecard alias. ecardNumber: type: integer description: Ecard number. format: int64 ecardNumber16digits: maxLength: 16 minLength: 16 type: string description: The 16 digit ecard number. A combination of ecardNumber, ecardOperator and control digit. ecardOperator: type: integer description: Ecard operator. format: int32 endOfOwnership: type: string description: When the customer removed the ecard connection. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' expirationDate: type: string description: When the physical ecard expires. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' id: type: integer description: Ecard id. format: int64 shippingDate: type: string description: When the physical ecard was shipped to the customer. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' startOfOwnership: type: string description: When the ecard was first connected to the customer. ISO 8601 date format format: date-time examples: - '2019-04-05T14:30:30+02:00' description: Ecards connected to a customer GeneratePasswordResponse: required: - customerNumber - firstName - generatedPassword - organisationId - surname type: object properties: customerNumber: type: integer description: Customer number. format: int64 customerRef: maxLength: 40 type: string description: Customer reference firstName: maxLength: 50 type: string description: Customer first and middle name. generatedPassword: maxLength: 100 type: string description: The new generated password. organisationId: type: integer description: Organisation id. format: int64 surname: maxLength: 50 type: string description: Customer surname. telephoneNumber: maxLength: 20 type: string description: Telephone number for customer. This should be a cell phone number. description: Return object when generating a new password responses: Error500_customers-orchestrator-customers: description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Error401_customers-orchestrator-customers: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Error400: description: Bad request content: application/json: schema: $ref: '#/components/schemas/ErrorMessage' Error401: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/ErrorMessage' Error403_customers-orchestrator-customers: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Error400_customers-orchestrator-customers: description: Bad request content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Error500: description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ErrorMessage' Error404: description: Not found content: application/json: schema: $ref: '#/components/schemas/ErrorMessage' Error404_customers-orchestrator-customers: description: Not found content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Error403: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/ErrorMessage' parameters: X-Correlation-Id: name: X-Correlation-Id in: header description: Correlation id required: false style: simple explode: false schema: type: string ET-Client-Name: name: ET-Client-Name in: header description: 'Entur Client Header. It is required that all consumers identify themselves by using this header. Entur will deploy strict rate-limiting policies on API-consumers who do not identify with a header and reserves the right to block unidentified consumers. The structure of ET-Client-Name should be: `-`.' required: false style: simple explode: false schema: type: string securitySchemes: jwt: type: http scheme: bearer bearerFormat: JWT x-refined-from: - entur-customers-openapi.json - entur-customers-openapi.yml