openapi: 3.2.0 info: title: Fenergo Clients API version: '1.0' description: 'Operations tagged Clients across 2 of this provider''s published API definitions: fenergo-identitymanagementcommand-v1-0-openapi.json, fenergo-identitymanagementquery-v1-0-openapi.json. Each path carries the servers of the definition it was published in.' servers: - url: /identitymanagementcommand - url: /identitymanagementquery security: - Bearer: [] tags: - name: Clients paths: /api/clients: post: tags: - Clients summary: Adds a new client to the tenant, with the data specified in the request description: 'Required permissions: Following permissions are required: SecurityCreateClient, ClientAdministration' operationId: CreateClient parameters: - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: description: Create client request content: application/json: schema: $ref: '#/components/schemas/CreateClientDtoServiceRequest' responses: '200': description: Success. Client added to the tenant content: application/json: schema: $ref: '#/components/schemas/ClientCreatedDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '409': description: Conflict saving changes in expected version content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: There are conflicts that cannot be resolved automatically, get latest and apply your changes type: Error errorCode: CONFLICT '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT get: tags: - Clients summary: Returns all clients from the tenant description: 'Required permissions: Following permissions are required: ClientAdministration' operationId: GetClients parameters: - name: Size in: query description: Non-negative value indicating desired number of results schema: maximum: 100000 minimum: 0 type: integer format: int32 example: 100 example: 100 - name: From in: query description: Non-negative value indicating the 0-based index of the query result schema: maximum: 2147483647 minimum: 0 type: integer format: int32 example: 0 example: 0 - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Clients data retrieved content: application/json: schema: $ref: '#/components/schemas/ClientApiDtoIEnumerableServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT servers: - url: /identitymanagementcommand /api/clients/{clientId}: delete: tags: - Clients summary: Removes an existing client from the tenant description: 'Required permissions: Following permissions are required: SecurityDeleteClient, ClientAdministration' operationId: DeleteClient parameters: - name: clientId in: path description: The ID of the client that would be removed required: true schema: type: string - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Client removed from the tenant '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not found. The client hasn't been found type: Error errorCode: Error Code '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT patch: tags: - Clients summary: Updates some data of a client that already exists in the tenant description: 'Required permissions: Following permissions are required: SecurityEditClient, ClientAdministration' operationId: PatchClient parameters: - name: clientId in: path description: The ID of the client that would be updated required: true schema: type: string - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: description: Patch client request content: application/json: schema: $ref: '#/components/schemas/PatchClientDtoServiceRequest' responses: '200': description: Success. Client data updated '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not found. The client hasn't been found type: Error errorCode: Error Code '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT get: tags: - Clients summary: Returns the client with the specified id description: 'Required permissions: Following permissions are required: ClientAdministration' operationId: GetClientById parameters: - name: clientId in: path description: Client Id required: true schema: type: string - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Client data retrieved content: application/json: schema: $ref: '#/components/schemas/ClientApiDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not found. The client hasn't been found type: Error errorCode: Error Code '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT servers: - url: /identitymanagementcommand /api/clients/{clientId}/secrets: post: tags: - Clients summary: Adds a new secret to the client description: 'Required permissions: Following permissions are required: SecurityCreateSecret, SecretAdministration' operationId: CreateClientSecret parameters: - name: clientId in: path description: The ID of the client required: true schema: type: string - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: description: Create secret request content: application/json: schema: $ref: '#/components/schemas/CreateClientSecretDtoServiceRequest' responses: '200': description: Success. Secret added to the client content: application/json: schema: $ref: '#/components/schemas/CreatedClientSecretDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values or secret count limit has exceeded content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '409': description: Conflict saving changes in expected version content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: There are conflicts that cannot be resolved automatically, get latest and apply your changes type: Error errorCode: CONFLICT '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT get: tags: - Clients summary: Returns all secrets from the client description: 'Required permissions: Following permissions are required: SecretAdministration' operationId: GetClientSecrets parameters: - name: clientId in: path description: The clientId of the client required: true schema: type: string - name: Size in: query description: Non-negative value indicating desired number of results schema: maximum: 100000 minimum: 0 type: integer format: int32 example: 100 example: 100 - name: From in: query description: Non-negative value indicating the 0-based index of the query result schema: maximum: 2147483647 minimum: 0 type: integer format: int32 example: 0 example: 0 - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Client secrets retrieved content: application/json: schema: $ref: '#/components/schemas/ClientSecretsDtoServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not found. Client secrets have not been found type: Error errorCode: Error Code '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '500': description: Internal server exception. Please, contact your provider. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: null messages: - message: Internal server exception. Please, contact your provider. type: Error errorCode: INTERNAL_SERVER_ERROR '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT servers: - url: /identitymanagementcommand /api/clients/{clientId}/secrets/{secretId}: delete: tags: - Clients summary: Removes an existing secret from the client description: 'Required permissions: Following permissions are required: SecurityDeleteSecret, SecretAdministration' operationId: DeleteClientSecret parameters: - name: clientId in: path description: The ID of the client required: true schema: type: string - name: secretId in: path description: The ID of the secret required: true schema: type: integer format: int32 - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Secret removed from the client '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not found. The client secret has not been found type: Error errorCode: Error Code '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '500': description: Internal server exception. Please, contact your provider. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: null messages: - message: Internal server exception. Please, contact your provider. type: Error errorCode: INTERNAL_SERVER_ERROR '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT get: tags: - Clients summary: Returns the secret by id from the client description: 'Required permissions: Following permissions are required: SecretAdministration' operationId: GetClientSecretById parameters: - name: clientId in: path description: The clientId of the client required: true schema: type: string - name: secretId in: path description: The ID of the client secret required: true schema: type: integer format: int32 - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Client secret retrieved content: application/json: schema: $ref: '#/components/schemas/SecretDtoServiceResponse' '400': description: Bad request. The request has missing/invalid values content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not found. The client secret has not been found type: Error errorCode: Error Code '500': description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT servers: - url: /identitymanagementcommand /api/scopes: get: tags: - Clients summary: Returns all scopes description: 'Required permissions: Following permissions are required: ClientAdministration' operationId: GetScopes parameters: - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Scopes retrieved content: application/json: schema: $ref: '#/components/schemas/ScopesDtoServiceResponse' '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '500': description: Internal server exception. Please, contact your provider. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: null messages: - message: Internal server exception. Please, contact your provider. type: Error errorCode: INTERNAL_SERVER_ERROR '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT servers: - url: /identitymanagementquery components: schemas: ServiceResponse: type: object properties: data: type: - string - 'null' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false PatchClientDto: required: - clientEmails type: object properties: clientName: type: - string - 'null' description: The name of the client example: cli-tool-1 allowedScopes: type: - array - 'null' items: type: string description: Scopes the client has access to example: - scimapi.resource.update - scimapi.resource.query - scimapi.resource.delete - fenx.product.read clientEmails: maxLength: 2000 minLength: 1 type: string description: Client emails used for notifications about certificate expiration. example: Test@fenergo.com additionalProperties: false description: Represents the data transfer object for patching a client (PATCH). PatchClientDtoServiceRequest: type: object properties: data: $ref: '#/components/schemas/PatchClientDto' additionalProperties: false ClientCreatedDtoServiceResponse: type: object properties: data: $ref: '#/components/schemas/ClientCreatedDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false CreatedClientSecretDtoServiceResponse: type: object properties: data: $ref: '#/components/schemas/CreatedClientSecretDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false CreateClientDtoServiceRequest: type: object properties: data: $ref: '#/components/schemas/CreateClientDto' additionalProperties: false CreateClientSecretDtoServiceRequest: type: object properties: data: $ref: '#/components/schemas/CreateClientSecretDto' additionalProperties: false CreateClientDto: required: - allowedScopes - clientEmails - clientName type: object properties: clientName: minLength: 1 type: string description: The name of the client example: cli-tool-1 allowedScopes: type: array items: type: string description: Scopes the client has access to example: - scimapi.resource.update - scimapi.resource.query - scimapi.resource.delete - fenx.product.read clientEmails: maxLength: 2000 minLength: 1 type: string description: Client emails used for notifications about certificate expiration. example: Test@fenergo.com additionalProperties: false description: Represents the data transfer object for creating a client. CreateClientSecretDto: type: object properties: expiration: type: - string - 'null' description: The expiration date of the client secret. format: date-time description: type: - string - 'null' description: The description of the client secret. additionalProperties: false description: Represents client secret. ServiceResponseMessage: type: object properties: message: type: - string - 'null' type: type: - string - 'null' errorCode: type: - string - 'null' additionalProperties: false ClientCreatedDto: required: - clientId type: object properties: clientId: minLength: 1 type: string description: The id of the client created. example: cli-tool-1_b2e58c3e-d66f-4d02-b40e-c8e6585a72a7 additionalProperties: false description: Represents the data transfer object for a client created. CreatedClientSecretDto: type: object properties: secretId: type: integer description: The id of the created client secret. format: int32 secretValue: type: - string - 'null' description: The value of created secret token. additionalProperties: false ObjectServiceResponse: type: object properties: data: {} messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false StringServiceResponse: type: object properties: data: type: - string - 'null' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false SecretDtoServiceResponse: type: object properties: data: $ref: '#/components/schemas/SecretDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false ClientSecretsDto: type: object properties: clientId: type: - string - 'null' description: The id of the client. secrets: type: - array - 'null' items: $ref: '#/components/schemas/SecretDto' description: Paginated collection of client secrets. totalRecords: type: integer description: The total number of secrets for the client. format: int32 additionalProperties: false description: Represents the data transfer object for client secrets. ScopesDto: type: object properties: scopes: type: - array - 'null' items: type: string description: Collection of scope names. additionalProperties: false description: Represents the data transfer object for a scope. ClientApiDtoServiceResponse: type: object properties: data: $ref: '#/components/schemas/ClientApiDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false ScopesDtoServiceResponse: type: object properties: data: $ref: '#/components/schemas/ScopesDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false SecretTypeDTO: enum: - ClientSecret - Certificate type: string SecretDto: type: object properties: id: type: integer description: The id of the client secret. format: int32 type: $ref: '#/components/schemas/SecretTypeDTO' created: type: string description: The creation date of the client secret. format: date-time expiration: type: - string - 'null' description: The expiration date of the client secret. format: date-time description: type: - string - 'null' description: The description of the client secret. clientId: type: - string - 'null' description: The id of the client. additionalProperties: false description: Represents the data transfer object for a client secret. ClientApiDtoIEnumerableServiceResponse: type: object properties: data: type: - array - 'null' items: $ref: '#/components/schemas/ClientApiDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false ClientApiDto: required: - allowedGrantTypes - allowedScopes - clientEmails - clientId - clientName - updated type: object properties: clientId: minLength: 1 type: string description: The unique identifier of the client example: cli-tool-1_b2e58c3e-d66f-4d02-b40e-c8e6585a72a7 clientName: minLength: 1 type: string description: The name of the client example: cli-tool-1 allowedScopes: type: array items: type: string description: Scopes the client has access to example: - scimapi.resource.update - scimapi.resource.query - scimapi.resource.delete - fenx.product.read allowedGrantTypes: type: array items: type: string description: Specifies the grant types the client is allowed to use example: - client_credentials - authorization_code updated: type: string description: Last updated date format: date-time example: '2018-04-08T11:52:00.9273241Z' clientEmails: minLength: 1 type: string description: Emails used for notifications about certificate expiration. example: Test@fenergo.com additionalProperties: false description: Represents the data transfer object for a client. ClientSecretsDtoServiceResponse: type: object properties: data: $ref: '#/components/schemas/ClientSecretsDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false securitySchemes: Bearer: type: apiKey description: Please insert JWT with Bearer into field name: Authorization in: header x-refined-from: - fenergo-identitymanagementcommand-v1-0-openapi.json - fenergo-identitymanagementquery-v1-0-openapi.json