openapi: 3.2.0 info: title: Entur Security Policy API version: 2026.10.0 description: 'Operations tagged security-policy across 2 of this provider''s published API definitions: entur-products-openapi.json, entur-products-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://api.entur.io/products description: Production environment - url: https://api.staging.entur.io/products description: Staging environment - url: https://api.dev.entur.io/products description: Development environment security: - jwt: [] tags: - name: security policy paths: /security-policy: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' get: tags: - security policy summary: Retrieves all security policies operationId: security-policy_getAll parameters: - name: orgId in: query description: The unique id to identify an organisation required: false style: form explode: true schema: type: string - name: fareFrameId in: query description: The unique id to identify a dataset to an organisation required: false style: form explode: true schema: type: string - name: minimizeDataLoad in: query required: false style: form explode: true schema: type: boolean - name: statusFilter in: query description: 'Filter by status. Allowed values: DRAFT, PROPOSED, VERSIONED, DEPRECATED, ALL. Defaults to ALL if not specified. Mutually exclusive with validOnDate.' required: false style: form explode: true schema: type: array items: type: string examples: default: value: - DRAFT - PROPOSED - name: validOnDate in: query description: 'Return the SecurityPolicies valid on this date, example: 2024-06-01T00:00:00Z. Note that, if called in the production environment, only VERSIONED SecurityPolicies are returned. And in the staging environment, PROPOSED SecurityPolicies are preferred to VERSIONED ones. Mutually exclusive with statusFilter.' required: false style: form explode: true schema: type: string - name: If-None-Match in: header description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource. required: false style: simple explode: false schema: type: string responses: '200': description: Returns the info content: application/json: schema: type: array items: $ref: '#/components/schemas/SecurityPolicy' '304': description: Not Modified '400': description: Bad Request content: application/problem+json: schema: type: string '401': description: Unauthorized content: application/problem+json: schema: type: string '403': description: Authorization failed content: application/problem+json: schema: type: string '404': description: Not Found content: application/problem+json: schema: type: string '500': description: Internal server error content: application/problem+json: schema: type: string security: - basic_auth: [] x-entur-permissions: value: product-api-access:les post: tags: - security policy summary: Create a SecurityPolicy operationId: security-policy_create parameters: [] requestBody: content: application/json: schema: $ref: '#/components/schemas/SecurityPolicy' required: true responses: '204': description: Entity created successfully '400': description: Validation errors content: application/problem+json: schema: type: string '401': description: Unauthorized content: application/problem+json: schema: type: string '403': description: Forbidden content: application/problem+json: schema: type: string '404': description: Not Found content: application/problem+json: schema: type: string '409': description: Already registered content: application/problem+json: schema: type: string '500': description: Internal server error content: application/problem+json: schema: type: string security: - basic_auth: [] x-entur-permissions: value: product-api-access:endre servers: - url: https://api.entur.io/products description: Production environment - url: https://api.staging.entur.io/products description: Staging environment - url: https://api.dev.entur.io/products description: Development environment /security-policy/defaults: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' get: tags: - security policy summary: Retrieves default security policies operationId: security-policy_getDefaults parameters: - name: If-None-Match in: header description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource. required: false style: simple explode: false schema: type: string responses: '200': description: Returns the info content: application/json: schema: type: array items: $ref: '#/components/schemas/SecurityPolicy' '304': description: Not Modified '400': description: Bad Request content: application/problem+json: schema: type: string '401': description: Unauthorized content: application/problem+json: schema: type: string '403': description: Authorization failed content: application/problem+json: schema: type: string '404': description: Resource not found content: application/problem+json: schema: type: string '500': description: Internal server error content: application/problem+json: schema: type: string security: - basic_auth: [] x-entur-permissions: value: product-api-access:les servers: - url: https://api.entur.io/products description: Production environment - url: https://api.staging.entur.io/products description: Staging environment - url: https://api.dev.entur.io/products description: Development environment /security-policy/{id}: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' get: tags: - security policy summary: Retrieves a security policy by id. description: Optional validOnDate query parameter (defaults to now). In prod returns the VERSIONED element; in staging/dev PROPOSED is preferred over VERSIONED. operationId: security-policy_getByIdAndValidOnDate parameters: - name: id in: path description: The id to identify a SecurityPolicy required: true style: simple explode: false schema: type: string - name: validOnDate in: query description: Return the version valid on the given date (ISO-8601). Defaults to now. required: false style: form explode: true schema: type: string format: date-time - name: If-None-Match in: header description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource. required: false style: simple explode: false schema: type: string responses: '200': description: Returns the info content: application/json: schema: $ref: '#/components/schemas/SecurityPolicy' '304': description: Not Modified '400': description: Bad Request content: application/problem+json: schema: type: string '401': description: Unauthorized content: application/problem+json: schema: type: string '403': description: Forbidden content: application/problem+json: schema: type: string '404': description: Resource not found content: application/problem+json: schema: type: string '500': description: Internal server error content: application/problem+json: schema: type: string security: - basic_auth: [] x-entur-permissions: value: product-api-access:les servers: - url: https://api.entur.io/products description: Production environment - url: https://api.staging.entur.io/products description: Staging environment - url: https://api.dev.entur.io/products description: Development environment /security-policy/{id}/{version}: parameters: - $ref: '#/components/parameters/ET-Client-Name' - $ref: '#/components/parameters/X-Correlation-Id' get: tags: - security policy summary: Retrieves security policy for id and version operationId: security-policy_getById parameters: - name: id in: path description: The id to identify a SecurityPolicy required: true style: simple explode: false schema: pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string - name: version in: path description: The id for the version of the SecurityPolicy required: true style: simple explode: false schema: pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string - name: If-None-Match in: header description: Used to make conditional requests. It allows the client to provide an ETag value, and the server will process the request only if the ETag does not match the current version of the resource. required: false style: simple explode: false schema: type: string responses: '200': description: Returns the info content: application/json: schema: $ref: '#/components/schemas/SecurityPolicy' '304': description: Not Modified '400': description: Bad Request content: application/problem+json: schema: type: string '401': description: Unauthorized content: application/problem+json: schema: type: string '403': description: Authorization failed content: application/problem+json: schema: type: string '404': description: Resource not found content: application/problem+json: schema: type: string '500': description: Internal server error content: application/problem+json: schema: type: string security: - basic_auth: [] x-entur-permissions: value: product-api-access:les put: tags: - security policy summary: Updates an existing SecurityPolicy operationId: security-policy_update parameters: - name: id in: path description: The id to identify a SecurityPolicy required: true style: simple explode: false schema: pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string - name: version in: path description: The id for the version of the SecurityPolicy required: true style: simple explode: false schema: pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/SecurityPolicy' required: true responses: '204': description: Entity updated successfully '400': description: Validation errors content: application/problem+json: schema: type: string '401': description: Missing Authorization content: application/problem+json: schema: type: string '403': description: Authorization failed content: application/problem+json: schema: type: string '404': description: Resource not found content: application/problem+json: schema: type: string '409': description: Conflict content: application/problem+json: schema: type: string '500': description: Internal server error content: application/problem+json: schema: type: string security: - basic_auth: [] x-entur-permissions: value: product-api-access:endre servers: - url: https://api.entur.io/products description: Production environment - url: https://api.staging.entur.io/products description: Staging environment - url: https://api.dev.entur.io/products description: Development environment components: schemas: VersionOfObjectRef: required: - nameOfClass - ref - version type: object properties: nameOfClass: minLength: 1 type: string description: Name of class. ref: minLength: 1 pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string description: The netex id reference to the object. version: type: string description: Version. description: Fare frame ref. TextInLanguage: required: - lang - value type: object properties: lang: minLength: 1 type: string description: Language code. examples: - nob value: minLength: 1 type: string description: The text. description: Text in a specific language. SecurityPolicy: required: - changed - created - id - minimumAccountSecurityLevel - modification - nameOfClass - status - version type: object properties: changed: type: string description: Changed readOnly: true created: type: string description: Created readOnly: true description: type: array description: Description. items: $ref: '#/components/schemas/TextInLanguage' fareFrameRef: $ref: '#/components/schemas/VersionOfObjectRef' id: minLength: 1 pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string description: Id examples: - NSB:SecurityPolicy:HighValueProduct minimumAccountSecurityLevel: type: integer description: 'Required (minimum) sequrity level of a product. The value is specified as a negative number, 0 is the highest level of security (most secure). In Entur we use three default levels: -50, -120 and -200. We have default implementations of SecurityPolicies for these three levels, and these can be retrieved from the security-policy/defaults endpoint.' format: int32 modification: type: string description: Modification status. readOnly: true enum: - NEW - REVISE - DELETE examples: - NEW name: type: array description: Name. items: $ref: '#/components/schemas/TextInLanguage' nameOfClass: type: string description: NameOfClass readOnly: true examples: - SecurityPolicy status: type: string description: Status readOnly: true enum: - DRAFT - PROPOSED - VERSIONED - DEPRECATED examples: - DRAFT version: minLength: 1 pattern: ^([A-Z]{3}):([A-Za-z]*):([0-9A-Za-z_\-]*)$ type: string description: Version examples: - NSB:Version:V1 parameters: X-Correlation-Id: name: X-Correlation-Id in: header description: Correlation id required: false style: simple explode: false schema: type: string ET-Client-Name: name: ET-Client-Name in: header description: 'Entur Client Header. It is required that all consumers identify themselves by using this header. Entur will deploy strict rate-limiting policies on API-consumers who do not identify with a header and reserves the right to block unidentified consumers. The structure of ET-Client-Name should be: `-`.' required: false style: simple explode: false schema: type: string securitySchemes: jwt: type: http scheme: bearer bearerFormat: JWT x-refined-from: - entur-products-openapi.json - entur-products-openapi.yml