openapi: 3.2.0 info: title: Fenergo Endpoint Configuration API version: '1.0' description: 'Operations tagged EndpointConfiguration across 2 of this provider''s published API definitions: fenergo-externalauthenticationcommand-v1-0-openapi.json, fenergo-externalauthenticationquery-v1-0-openapi.json. Each path carries the servers of the definition it was published in.' servers: - url: /externalauthenticationcommand - url: /externalauthenticationquery tags: - name: EndpointConfiguration paths: /api/configuration: post: tags: - EndpointConfiguration description: 'Required permissions: Following permissions are required: ExternalAuthenticationCreate' operationId: CreateConfiguration parameters: - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: content: application/json: schema: allOf: - $ref: '#/components/schemas/CreateEndpointConfigurationDtoServiceRequest' responses: '202': description: Accepted content: application/json: schema: $ref: '#/components/schemas/EndpointConfigurationCreatedDtoServiceResponse' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '500': description: Internal Server Error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT security: - Bearer: [] summary: Create configuration x-summary-source: derived put: tags: - EndpointConfiguration description: 'Required permissions: Following permissions are required: ExternalAuthenticationEdit' operationId: UpdateConfiguration parameters: - name: configurationId in: query required: true schema: type: string format: uuid - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 requestBody: content: application/json: schema: allOf: - $ref: '#/components/schemas/CreateEndpointConfigurationDtoServiceRequest' responses: '202': description: Accepted content: application/json: schema: $ref: '#/components/schemas/EndpointConfigurationUpdatedDtoServiceResponse' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '500': description: Internal Server Error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT security: - Bearer: [] summary: Update configuration x-summary-source: derived delete: tags: - EndpointConfiguration description: 'Required permissions: Following permissions are required: ExternalAuthenticationDelete' operationId: DeleteConfiguration parameters: - name: configurationId in: query required: true schema: type: string format: uuid - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '202': description: Accepted '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '500': description: Internal Server Error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT security: - Bearer: [] summary: Delete configuration x-summary-source: derived servers: - url: /externalauthenticationcommand /api/configuration/{configurationId}: get: tags: - EndpointConfiguration summary: Get endpoint configuration for a single configuration ID description: 'This method accepts a configuration ID. The method then returns all endpoint configuration for a specific configuration ID. Required permissions: Following permissions are required: ExternalAuthenticationAccess' operationId: GetConfigurationById parameters: - name: configurationId in: path required: true schema: type: string format: uuid - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Endpoint configurations are returned content: application/json: schema: $ref: '#/components/schemas/GetByIdEndpointConfigurationResponseDtoServiceResponse' '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not Found type: Error errorCode: Error Code '500': description: Internal server error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT security: - Bearer: [] servers: - url: /externalauthenticationquery /api/configuration/getAll: get: tags: - EndpointConfiguration summary: Get all your endpoint configurations description: 'Required permissions: Following permissions are required: ExternalAuthenticationAccess' operationId: GetAllConfigurationsByTenant parameters: - name: X-TENANT-ID in: header description: The UiD of the tenant representing organization required: true schema: type: string example: b11f8be3-f29b-4959-8964-956d4af7c468 responses: '200': description: Success. Endpoint configurations are returned content: application/json: schema: $ref: '#/components/schemas/GetAllEndpointConfigurationResponseDtoListServiceResponse' '400': description: Bad request content: application/json: schema: $ref: '#/components/schemas/ValidationErrorModelListServiceResponse' '404': description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: Not Found type: Error errorCode: Error Code '500': description: Internal server error '401': description: User is not authorized to perform this request content: application/json: example: message: Unauthorized '403': description: Access to resource is forbidden. content: application/json: schema: $ref: '#/components/schemas/ObjectServiceResponse' example: data: {} messages: - message: 'Access denied. Following permissions are required: Permission1, Permission2' type: Forbidden errorCode: Error Code '410': description: Endpoint marked as deprecated was terminated. This response will be present only if the endpoint was marked as deprecated and has reached the sunset date. During the deprecation period, the API will include additional 'sunset' and 'deprecation' headers. content: application/json: schema: $ref: '#/components/schemas/StringServiceResponse' example: data: null messages: - message: This endpoint is obsolete and was terminated on yyyy-MM-dd type: Error errorCode: OBSOLETE_ENDPOINT security: - Bearer: [] servers: - url: /externalauthenticationquery components: schemas: ValidationErrorModelListServiceResponse: type: object properties: data: type: - array - 'null' items: $ref: '#/components/schemas/ValidationErrorModel' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false example: data: - propertyName: data errorMessage: Data is required attemptedValue: '' errorCode: NotNullValidator messages: - message: Data is required type: Error errorCode: Error Code CreateEndpointConfigurationDto: type: object properties: url: type: - string - 'null' description: Contains the URL that relates to this configuration example: https://www.mydomain.com/api isMtlsEnabled: type: boolean description: Indicates if the URL specified above is mTLS enabled example: true endpointCertificate: allOf: - $ref: '#/components/schemas/EndpointCertificateDto' description: 'Contains the certificate settings for the URL specified above. Required when IsMtlsEnabled set to true (optional)' headers: type: - array - 'null' items: $ref: '#/components/schemas/HeaderPropertyDto' description: 'Contains an array of any optional headers that must be sent as part of each request (optional)' oAuthConfiguration: allOf: - $ref: '#/components/schemas/OAuthConfigurationDto' additionalProperties: false description: Request DTO to create or update endpoint configuration EndpointConfigurationCreatedDtoServiceResponse: type: object properties: data: allOf: - $ref: '#/components/schemas/EndpointConfigurationCreatedDto' description: Represents the data of a configuration that has been created messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false EndpointCertificateDto: required: - certificate - isPublicCA type: object properties: isPublicCA: type: boolean description: Specifies that the certificate presented is a publicly signed certificate (or not) example: true certificate: minLength: 1 type: string description: 'Contains the PEM-encoded public key certificate for the specified url. Is required if ''isPublicCA'' is set to false (optional)' example: '-----BEGIN CERTIFICATE-----\nMIICUTCCAfugAwIBAgIBADANBgkqhkiG9w0BAQQFADBXMQswCQYDVQQGEwJ...\n-----END CERTIFICATE-----\n' additionalProperties: false description: DTO to specify server certificate properties EndpointConfigurationCreatedDto: type: object properties: configurationId: type: string description: The unique ID for the endpoint configuration. format: uuid example: 12be522e-66c2-44bb-851e-afc4fc4a33c2 additionalProperties: false description: Represents the data of a configuration that has been created ClientCredentialsConfigurationDto: required: - clientId - url - useBasicAuthentication - useEndpointMtlsConfiguration type: object properties: clientId: minLength: 1 type: string description: Client Id example: my-client-id clientSecret: type: - string - 'null' description: Client secret example: my-client-secret useBasicAuthentication: type: boolean description: Flag to determine if to use basic authentication type url: minLength: 1 type: string description: Contains the URL that relates to this configuration example: https://www.mydomain.com/oauth2/token isMtlsEnabled: type: boolean description: Indicates if the URL specified above is mTLS enabled example: true isJwtClientAssertionEnabled: type: - boolean - 'null' description: Indicates if the URL specified above should use jwt client assertion authentication example: true isJwtClientAssertionEnabledValue: type: boolean description: Indicates the same as Fenergo.Nebula.ExternalAuthentication.Command.Application.Dto.OAuth.ClientCredentialsConfigurationDto.IsJwtClientAssertionEnabled but it's normalized to false when null readOnly: true example: true endpointCertificate: allOf: - $ref: '#/components/schemas/EndpointCertificateDto' description: 'Contains the certificate settings for the URL specified above. Required when IsMtlsEnabled set to true and UseEndpointMtlsConfiguration is set to false. (optional)' headers: type: - array - 'null' items: $ref: '#/components/schemas/HeaderPropertyDto' description: 'Contains an array of any optional headers that must be sent as part of each request (optional)' useEndpointMtlsConfiguration: type: boolean description: Flag to determine if OAuth configuration should use base mtls configuration formValues: type: - array - 'null' items: $ref: '#/components/schemas/FormPropertyDto' description: 'Form values parameters: Contains an array of any optional form values that can be sent as part of each request (optional)' additionalProperties: false FormPropertyDto: type: object properties: name: type: - string - 'null' description: Name of Property example: property-name value: type: - string - 'null' description: Name of Value example: property-value additionalProperties: false EndpointConfigurationUpdatedDto: type: object properties: configurationId: type: string description: The unique ID for the endpoint configuration. format: uuid example: 12be522e-66c2-44bb-851e-afc4fc4a33c2 additionalProperties: false description: Represents the data of a configuration that has been updated EndpointConfigurationUpdatedDtoServiceResponse: type: object properties: data: allOf: - $ref: '#/components/schemas/EndpointConfigurationUpdatedDto' description: Represents the data of a configuration that has been updated messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false ValidationErrorModel: type: object properties: propertyName: type: - string - 'null' errorMessage: type: - string - 'null' attemptedValue: {} errorCode: type: - string - 'null' additionalProperties: false ServiceResponseMessage: type: object properties: message: type: - string - 'null' type: type: - string - 'null' errorCode: type: - string - 'null' additionalProperties: false OAuthConfigurationDto: type: object properties: clientCredentialsConfig: allOf: - $ref: '#/components/schemas/ClientCredentialsConfigurationDto' additionalProperties: false CreateEndpointConfigurationDtoServiceRequest: type: object properties: data: allOf: - $ref: '#/components/schemas/CreateEndpointConfigurationDto' description: Request DTO to create or update endpoint configuration additionalProperties: false HeaderPropertyDto: type: object properties: name: type: - string - 'null' description: Name of Property example: property-name value: type: - string - 'null' description: Name of Value example: property-value additionalProperties: false description: DTO to specify optional request headers ObjectServiceResponse: type: object properties: data: {} messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false StringServiceResponse: type: object properties: data: type: - string - 'null' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false AuthType: enum: - OAuthClientCredentials type: string EndpointCertificateDto_2: type: object properties: isPublicCA: type: boolean description: Specifies that the certificate presented is a publicly signed certificate (or not) example: true certificate: type: - string - 'null' description: 'Contains the PEM-encoded public key certificate for the specified url. Is required if ''isPublicCA'' is set to false (optional)' example: '-----BEGIN CERTIFICATE-----\nMIICUTCCAfugAwIBAgIBADANBgkqhkiG9w0BAQQFADBXMQswCQYDVQQGEwJ...\n-----END CERTIFICATE-----\n' certificateDetails: type: - object - 'null' additionalProperties: type: - string - 'null' description: Contains all attributes of a certificate additionalProperties: false description: Query DTO to return server certificate properties GetAllClientCredentialsConfigurationResponseDto: type: object properties: url: type: - string - 'null' description: Contains the URL that relates to this configuration example: https://www.mydomain.com/oauth2/token isMtlsEnabled: type: boolean description: Indicates if the URL specified above is mTLS enabled example: true isJwtClientAssertionEnabled: type: - boolean - 'null' description: Indicates if the URL specified above should use jwt client assertion authentication example: true hasFormValues: type: boolean description: Indicates if the endpoint contains form values example: true hasHeaders: type: boolean description: Indicates if the endpoint contains headers example: true containsCertificate: type: boolean description: Indicates if the endpoint is Oauth enabled example: true useBasicAuthentication: type: boolean description: Flag to determine if to use basic authentication type example: true useMtlsEndpointConfiguration: type: boolean description: Flag to determine if to use Mtls endpoint configuration example: true additionalProperties: false description: Query DTO to return client credentials configurations GetAllEndpointConfigurationResponseDto: type: object properties: id: type: - string - 'null' description: Contains the unique ID that relates to this configuration example: 4ce5403d-bc16-47bb-9c69-9797dccb49c6 url: type: - string - 'null' description: Contains the URL that relates to this configuration example: https://www.mydomain.com/api isMtlsEnabled: type: boolean description: Indicates if the URL specified above is mTLS enabled example: true hasHeaders: type: boolean description: Indicates if the endpoint contains headers example: true containsCertificate: type: boolean description: Indicates if the endpoint contains a certificate example: true isOauthEnabled: type: boolean description: Indicates if the endpoint is Oauth enabled example: true oAuthConfiguration: allOf: - $ref: '#/components/schemas/GetAllOAuthConfigurationResponseDto' description: 'Contains Oauth configuration settings (optional)' additionalProperties: false description: Query DTO to return list of endpoint configurations GetByIdEndpointConfigurationResponseDtoServiceResponse: type: object properties: data: allOf: - $ref: '#/components/schemas/GetByIdEndpointConfigurationResponseDto' description: Query DTO to return endpoint configurations messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false GetAllEndpointConfigurationResponseDtoListServiceResponse: type: object properties: data: type: - array - 'null' items: $ref: '#/components/schemas/GetAllEndpointConfigurationResponseDto' messages: type: - array - 'null' items: $ref: '#/components/schemas/ServiceResponseMessage' additionalProperties: false FormPropertyDto_2: type: object properties: name: type: - string - 'null' description: Name of Property example: property-name value: type: - string - 'null' description: Name of Value example: property-value additionalProperties: false description: Query DTO to specify form properties GetByIdClientCredentialsConfigurationResponseDto: type: object properties: clientId: type: - string - 'null' description: Client Id example: my-client-id clientSecret: type: - string - 'null' description: Client secret example: my-client-secret useBasicAuthentication: type: boolean description: Flag to determine if to use basic authentication type example: true tokenEndpoint: allOf: - $ref: '#/components/schemas/GetByIdUrlConfigurationResponseDto' description: Contains the configuration setting for a token endpoint useMtlsEndpointConfiguration: type: boolean description: Flag to determine if to use Mtls endpoint configuration example: true additionalProperties: false description: Query DTO to return client credentials configuration GetByIdMtlsCertificateConfigurationResponseDto: type: object properties: endpointCertificate: allOf: - $ref: '#/components/schemas/EndpointCertificateDto_2' description: Contains the certificate settings additionalProperties: false GetByIdEndpointConfigurationResponseDto: type: object properties: id: type: - string - 'null' description: Contains the unique ID that relates to this configuration example: 4ce5403d-bc16-47bb-9c69-9797dccb49c6 tenantId: type: - string - 'null' description: Contains the Tenant ID that relates to this configuration example: d5234c56-0594-41d4-a118-5b1f3ceee348 url: type: - string - 'null' description: Contains the URL that relates to this configuration example: https://www.mydomain.com/api isMtlsEnabled: type: boolean description: Indicates if the URL specified above is mTLS enabled example: true headers: type: - array - 'null' items: $ref: '#/components/schemas/HeaderPropertyDto_2' description: 'Contains an array of any optional headers that must be sent as part of each request (optional)' endpointCertificate: allOf: - $ref: '#/components/schemas/EndpointCertificateDto_2' description: 'Contains the certificate settings for the URL specified above. Required when IsMtlsEnabled set to true (optional)' oAuthConfiguration: allOf: - $ref: '#/components/schemas/GetByIdOAuthConfigurationResponseDto' description: 'Contains Oauth configuration settings (optional)' additionalProperties: false description: Query DTO to return endpoint configurations GetAllOAuthConfigurationResponseDto: type: object properties: authType: allOf: - $ref: '#/components/schemas/AuthType' description: Contains Auth type clientCredentials: allOf: - $ref: '#/components/schemas/GetAllClientCredentialsConfigurationResponseDto' description: Contains client credentials configurations additionalProperties: false description: Query DTO to return list of Oauth configurations GetByIdUrlConfigurationResponseDto: type: object properties: url: type: - string - 'null' description: Contains the URL that relates to this configuration example: https://www.mydomain.com/oauth2/token isMtlsEnabled: type: boolean description: Indicates if the URL specified above is mTLS enabled example: true mtlsConfiguration: allOf: - $ref: '#/components/schemas/GetByIdMtlsCertificateConfigurationResponseDto' description: Contains Mtls configuration settings isJwtClientAssertionEnabled: type: - boolean - 'null' description: Indicates if the URL specified above should use jwt client assertion authentication example: true jwksUrl: type: - string - 'null' description: Indicates the URL path to request for the JWKS endpoint readOnly: true example: 'true' headers: type: - array - 'null' items: $ref: '#/components/schemas/HeaderPropertyDto_2' description: 'Contains an array of any optional headers that must be sent as part of each request (optional)' formProperties: type: - array - 'null' items: $ref: '#/components/schemas/FormPropertyDto_2' description: 'Contains an array of any optional form values that can be sent as part of each request (optional)' additionalProperties: false GetByIdOAuthConfigurationResponseDto: type: object properties: authType: allOf: - $ref: '#/components/schemas/AuthType' description: Contains Auth type clientCredentialsConfig: allOf: - $ref: '#/components/schemas/GetByIdClientCredentialsConfigurationResponseDto' description: Contains client credentials configurations additionalProperties: false description: Query DTO to return list of Oauth configurations HeaderPropertyDto_2: type: object properties: name: type: - string - 'null' description: Name of Property example: property-name value: type: - string - 'null' description: Name of Value example: property-value additionalProperties: false description: Query DTO to specify headers securitySchemes: Bearer: type: apiKey description: Please insert JWT with Bearer into field name: Authorization in: header x-refined-from: - fenergo-externalauthenticationcommand-v1-0-openapi.json - fenergo-externalauthenticationquery-v1-0-openapi.json