openapi: 3.2.0 info: title: Jans Config Auth - Session Management API contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io description: The Jans server tags: - name: Auth - Session Management paths: /api/v1/jans-auth-server/session/sid/{sid}: get: tags: - Auth - Session Management summary: Get session by id description: Get session by id. operationId: get-session-by-id parameters: - name: sid in: path description: Session identifier. required: true schema: type: string responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/SessionId' examples: Response example: description: Response example value: '' '401': description: Unauthorized '404': description: Not Found '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/jans-auth-server/session.readonly - oauth2: - https://jans.io/oauth/jans-auth-server/session.admin - oauth2: - https://jans.io/oauth/config/read-all - oauth2: - https://jans.io/oauth/config/write-all delete: tags: - Auth - Session Management summary: Delete a session description: Delete a session. operationId: delete-session parameters: - name: sid in: path description: Session identifier. required: true schema: type: string responses: '204': description: No Content '401': description: Unauthorized '404': description: Not Found '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/jans-auth-server/session.delete - revoke_session - oauth2: - https://jans.io/oauth/jans-auth-server/session.admin - oauth2: - https://jans.io/oauth/config/delete-all /api/v1/jans-auth-server/session/user/{userDn}: delete: tags: - Auth - Session Management summary: Revoke all sessions by userDn operationId: revoke-user-session parameters: - name: userDn in: path description: User domain name required: true schema: type: string responses: '204': description: No Content '401': description: Unauthorized '404': description: Not Found '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/jans-auth-server/session.delete - revoke_session - oauth2: - https://jans.io/oauth/jans-auth-server/session.admin - oauth2: - https://jans.io/oauth/config/delete-all /api/v1/jans-auth-server/session: get: tags: - Auth - Session Management summary: Return all session operationId: get-sessions responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/SessionPagedResult' examples: Response json example: description: Response json example value: "[\n {\n \"dn\": \"jansId=c0baae4d-3282-4d20-99d9-90c30a1b6e53,ou=sessions,o=jans\",\n \"id\": \"c0baae4d-3282-4d20-99d9-90c30a1b6e53\",\n \"outsideSid\": \"652dc5e2-d95b-416e-b1ca-34b7dfb441d9\",\n \"lastUsedAt\": \"2024-09-24T14:53:13\",\n \"userDn\": \"inum=122ff2df-911d-424b-bbfe-891a43a70e95,ou=people,o=jans\",\n \"authenticationTime\": \"2024-09-24T14:53:13\",\n \"state\": \"authenticated\",\n \"sessionState\": \"34d35953e0008389587369ab1be6d6c93aa6d9e103dc2da93c157fc1b8d12385.696be3a5-d30c-4401-831f-4cd9017e8772\",\n \"permissionGrantedMap\": {\n \"permissionGranted\": {\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\": true\n }\n },\n \"sessionAttributes\": {\n \"acr\": \"simple_password_auth\",\n \"remote_ip\": \"123.201.169.114\",\n \"opbs\": \"355386a7-8e51-488b-ab1d-b65fa9f5a6d5\",\n \"acr_values\": \"simple_password_auth\",\n \"scope\": \"openid profile email user_name\",\n \"response_type\": \"code\",\n \"redirect_uri\": \"https://pujavs-hopeful-colt.gluu.info/admin\",\n \"state\": \"abc\",\n \"nonce\": \"puja\",\n \"client_id\": \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\",\n \"auth_user\": \"admin\",\n \"old_session_id\": \"db06a1ad-fe41-4af1-b6a8-96eac8747b39\",\n \"session_id\": \"c0baae4d-3282-4d20-99d9-90c30a1b6e53\",\n \"sid\": \"652dc5e2-d95b-416e-b1ca-34b7dfb441d9\",\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9_authz_scopes\": \"openid user_name profile email\",\n \"successful_rp_redirect_count\": \"1\"\n },\n \"expirationDate\": \"2024-11-25T14:53:06\",\n \"deletable\": true,\n \"creationDate\": \"2024-09-24T14:53:06\",\n \"persisted\": false,\n \"ttl\": 0,\n \"opbrowserState\": \"355386a7-8e51-488b-ab1d-b65fa9f5a6d5\"\n },\n {\n \"dn\": \"jansId=7cbad817-0b96-40ca-8667-1073bfa726c3,ou=sessions,o=jans\",\n \"id\": \"7cbad817-0b96-40ca-8667-1073bfa726c3\",\n \"outsideSid\": \"5c306424-462c-4b2d-8827-61c93dee54ce\",\n \"lastUsedAt\": \"2024-09-24T14:52:15\",\n \"userDn\": \"inum=122ff2df-911d-424b-bbfe-891a43a70e95,ou=people,o=jans\",\n \"authenticationTime\": \"2024-09-24T14:52:15\",\n \"state\": \"authenticated\",\n \"sessionState\": \"30288a431305c3fe91f716969837e809ae2c86982c8f0481c78c58f2db7dfd93.d3646d5e-62bf-421c-b1cf-51d6c4d6f64e\",\n \"permissionGrantedMap\": {\n \"permissionGranted\": {\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\": true\n }\n },\n \"sessionAttributes\": {\n \"acr\": \"simple_password_auth\",\n \"remote_ip\": \"123.201.169.114\",\n \"opbs\": \"661fbf90-1ffc-4560-9f95-cb113791af38\",\n \"acr_values\": \"simple_password_auth\",\n \"scope\": \"openid profile email user_name jansAdminUIRole\",\n \"response_type\": \"code\",\n \"redirect_uri\": \"https://pujavs-hopeful-colt.gluu.info/admin\",\n \"state\": \"abc\",\n \"nonce\": \"xyz\",\n \"client_id\": \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\",\n \"auth_user\": \"admin\",\n \"old_session_id\": \"84d59a22-e98b-41ab-a195-fe52efbc6cba\",\n \"session_id\": \"7cbad817-0b96-40ca-8667-1073bfa726c3\",\n \"sid\": \"5c306424-462c-4b2d-8827-61c93dee54ce\",\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9_authz_scopes\": \"openid user_name profile email jansAdminUIRole\",\n \"successful_rp_redirect_count\": \"1\"\n },\n \"expirationDate\": \"2024-10-25T14:52:06\",\n \"deletable\": true,\n \"creationDate\": \"2024-09-24T14:52:06\",\n \"persisted\": false,\n \"ttl\": 0,\n \"opbrowserState\": \"661fbf90-1ffc-4560-9f95-cb113791af38\"\n }\n]\n" '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/jans-auth-server/session.readonly - oauth2: - https://jans.io/oauth/jans-auth-server/session.admin - oauth2: - https://jans.io/oauth/config/read-all - oauth2: - https://jans.io/oauth/config/write-all /api/v1/jans-auth-server/session/search: get: tags: - Auth - Session Management summary: Search session operationId: search-session parameters: - name: limit in: query description: Search size - max size of the results to return schema: type: integer format: int32 default: 50 - name: pattern in: query description: Search pattern schema: type: string default: '' - name: startIndex in: query description: The 1-based index of the first query result schema: type: integer format: int32 default: 0 - name: sortBy in: query description: Attribute whose value will be used to order the returned response schema: type: string default: jansId - name: sortOrder in: query description: Order in which the sortBy param is applied. Allowed values are "ascending" and "descending" schema: type: string default: ascending - name: fieldValuePair in: query description: Field and value pair for seraching schema: type: string default: '' examples: Field value example: description: Field value example value: userDn=d5552516-4436-4908-ab36-3e9725246304,expirationDate>2025-09-25,expirationDate<2026-10-15 responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/SessionPagedResult' examples: Response json example: description: Response json example value: "{\n \"start\": 0,\n \"totalEntriesCount\": 2,\n \"entriesCount\": 2,\n \"entries\": [\n {\n \"dn\": \"jansId=7cbad817-0b96-40ca-8667-1073bfa726c3,ou=sessions,o=jans\",\n \"id\": \"7cbad817-0b96-40ca-8667-1073bfa726c3\",\n \"outsideSid\": \"5c306424-462c-4b2d-8827-61c93dee54ce\",\n \"lastUsedAt\": \"2024-09-24T14:52:15\",\n \"userDn\": \"inum=122ff2df-911d-424b-bbfe-891a43a70e95,ou=people,o=jans\",\n \"authenticationTime\": \"2024-09-24T14:52:15\",\n \"state\": \"authenticated\",\n \"sessionState\": \"30288a431305c3fe91f716969837e809ae2c86982c8f0481c78c58f2db7dfd93.d3646d5e-62bf-421c-b1cf-51d6c4d6f64e\",\n \"permissionGrantedMap\": {\n \"permissionGranted\": {\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\": true\n }\n },\n \"sessionAttributes\": {\n \"acr\": \"simple_password_auth\",\n \"remote_ip\": \"123.201.169.114\",\n \"opbs\": \"661fbf90-1ffc-4560-9f95-cb113791af38\",\n \"acr_values\": \"simple_password_auth\",\n \"scope\": \"openid profile email user_name jansAdminUIRole\",\n \"response_type\": \"code\",\n \"redirect_uri\": \"https://pujavs-hopeful-colt.gluu.info/admin\",\n \"state\": \"abc\",\n \"nonce\": \"xyz\",\n \"client_id\": \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\",\n \"auth_user\": \"admin\",\n \"old_session_id\": \"84d59a22-e98b-41ab-a195-fe52efbc6cba\",\n \"session_id\": \"7cbad817-0b96-40ca-8667-1073bfa726c3\",\n \"sid\": \"5c306424-462c-4b2d-8827-61c93dee54ce\",\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9_authz_scopes\": \"openid user_name profile email jansAdminUIRole\",\n \"successful_rp_redirect_count\": \"1\"\n },\n \"expirationDate\": \"2024-10-25T14:52:06\",\n \"deletable\": true,\n \"creationDate\": \"2024-09-24T14:52:06\",\n \"persisted\": false,\n \"ttl\": 0,\n \"opbrowserState\": \"661fbf90-1ffc-4560-9f95-cb113791af38\"\n },\n {\n \"dn\": \"jansId=c0baae4d-3282-4d20-99d9-90c30a1b6e53,ou=sessions,o=jans\",\n \"id\": \"c0baae4d-3282-4d20-99d9-90c30a1b6e53\",\n \"outsideSid\": \"652dc5e2-d95b-416e-b1ca-34b7dfb441d9\",\n \"lastUsedAt\": \"2024-09-24T14:53:13\",\n \"userDn\": \"inum=122ff2df-911d-424b-bbfe-891a43a70e95,ou=people,o=jans\",\n \"authenticationTime\": \"2024-09-24T14:53:13\",\n \"state\": \"authenticated\",\n \"sessionState\": \"34d35953e0008389587369ab1be6d6c93aa6d9e103dc2da93c157fc1b8d12385.696be3a5-d30c-4401-831f-4cd9017e8772\",\n \"permissionGrantedMap\": {\n \"permissionGranted\": {\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\": true\n }\n },\n \"sessionAttributes\": {\n \"acr\": \"simple_password_auth\",\n \"remote_ip\": \"123.201.169.114\",\n \"opbs\": \"355386a7-8e51-488b-ab1d-b65fa9f5a6d5\",\n \"acr_values\": \"simple_password_auth\",\n \"scope\": \"openid profile email user_name\",\n \"response_type\": \"code\",\n \"redirect_uri\": \"https://pujavs-hopeful-colt.gluu.info/admin\",\n \"state\": \"abc\",\n \"nonce\": \"puja\",\n \"client_id\": \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9\",\n \"auth_user\": \"admin\",\n \"old_session_id\": \"db06a1ad-fe41-4af1-b6a8-96eac8747b39\",\n \"session_id\": \"c0baae4d-3282-4d20-99d9-90c30a1b6e53\",\n \"sid\": \"652dc5e2-d95b-416e-b1ca-34b7dfb441d9\",\n \"2000.cc8b29ae-cb4a-49ea-b176-8695e53919d9_authz_scopes\": \"openid user_name profile email\",\n \"successful_rp_redirect_count\": \"1\"\n },\n \"expirationDate\": \"2024-11-25T14:53:06\",\n \"deletable\": true,\n \"creationDate\": \"2024-09-24T14:53:06\",\n \"persisted\": false,\n \"ttl\": 0,\n \"opbrowserState\": \"355386a7-8e51-488b-ab1d-b65fa9f5a6d5\"\n }\n ]\n}\n" '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/jans-auth-server/session.readonly - oauth2: - https://jans.io/oauth/jans-auth-server/session.admin - oauth2: - https://jans.io/oauth/config/read-all - oauth2: - https://jans.io/oauth/config/write-all components: schemas: SessionIdAccessMap: type: object properties: permissionGranted: type: object additionalProperties: type: boolean xml: name: map SessionPagedResult: type: object properties: start: type: integer format: int32 totalEntriesCount: type: integer format: int32 entriesCount: type: integer format: int32 entries: type: array items: $ref: '#/components/schemas/SessionId' SessionId: type: object properties: dn: type: string id: type: string outsideSid: type: string lastUsedAt: type: string format: date-time userDn: type: string authenticationTime: type: string format: date-time state: type: string enum: - unauthenticated - authenticated sessionState: type: string permissionGranted: type: boolean permissionGrantedMap: $ref: '#/components/schemas/SessionIdAccessMap' sessionAttributes: type: object additionalProperties: type: string predefinedAttributes: $ref: '#/components/schemas/SessionIdPredefinedAttributes' deviceSecrets: type: array items: type: string expirationDate: type: string format: date-time deletable: type: boolean creationDate: type: string format: date-time user: $ref: '#/components/schemas/User' ttl: type: integer format: int32 opbrowserState: type: string UserAuthenticator: type: object properties: id: type: string type: type: string custom: type: object additionalProperties: type: object UserAuthenticatorList: type: object properties: authenticators: type: array items: $ref: '#/components/schemas/UserAuthenticator' CustomObjectAttribute: type: object properties: name: type: string multiValued: type: boolean values: type: array items: type: object value: type: object displayValue: type: string SessionIdPredefinedAttributes: type: object properties: index: type: integer format: int32 User: type: object properties: dn: type: string userId: type: string updatedAt: type: string format: date-time createdAt: type: string format: date-time oxAuthPersistentJwt: type: array items: type: string externalUid: type: array items: type: string authenticator: $ref: '#/components/schemas/UserAuthenticatorList' status: type: string enum: - active - inactive - expired - register customAttributes: type: array items: $ref: '#/components/schemas/CustomObjectAttribute' customObjectClasses: type: array items: type: string baseDn: type: string securitySchemes: oauth2: type: oauth2 flows: clientCredentials: tokenUrl: https://{op-hostname}/.../token scopes: https://jans.io/oauth/jans-auth-server/config/properties.readonly: View Auth Server properties related information https://jans.io/oauth/jans-auth-server/config/properties.write: Manage Auth Server properties related information https://jans.io/oauth/config/attributes.readonly: View attribute related information https://jans.io/oauth/config/attributes.write: Manage attribute related information https://jans.io/oauth/config/attributes.delete: Delete attribute related information https://jans.io/oauth/config/acrs.readonly: View ACRS related information https://jans.io/oauth/config/acrs.write: Manage ACRS related information https://jans.io/oauth/config/database/ldap.readonly: View LDAP database related information https://jans.io/oauth/config/database/ldap.write: Manage LDAP database related information https://jans.io/oauth/config/database/ldap.delete: Delete LDAP database related information https://jans.io/oauth/config/scripts.readonly: View cache scripts information https://jans.io/oauth/config/scripts.write: Manage scripts related information https://jans.io/oauth/config/scripts.delete: Delete scripts related information https://jans.io/oauth/config/cache.readonly: View cache related information https://jans.io/oauth/config/cache.write: Manage cache related information https://jans.io/oauth/config/smtp.readonly: View SMTP related information https://jans.io/oauth/config/smtp.write: Manage SMTP related information https://jans.io/oauth/config/smtp.delete: Delete SMTP related information https://jans.io/oauth/config/logging.readonly: View logging related information https://jans.io/oauth/config/logging.write: Manage logging related information https://jans.io/oauth/config/jwks.readonly: View JWKS related information https://jans.io/oauth/config/jwks.write: Manage JWKS related information https://jans.io/oauth/config/jwks.delete: Delete JWKS related information https://jans.io/oauth/config/openid/clients.readonly: View clients related information https://jans.io/oauth/config/openid/clients.write: Manage clients related information https://jans.io/oauth/config/openid/clients.delete: Delete clients related information https://jans.io/oauth/config/scopes.readonly: View scope related information https://jans.io/oauth/config/scopes.write: Manage scope related information https://jans.io/oauth/config/scopes.delete: Delete scope related information https://jans.io/oauth/config/stats.readonly: View server with basic statistic https://jans.io/oauth/config/organization.readonly: View organization configuration information https://jans.io/oauth/config/organization.write: Manage organization configuration information https://jans.io/oauth/config/agama.readonly: View Agama Flow related information https://jans.io/oauth/config/agama.write: Manage Agama Flow related information https://jans.io/oauth/config/agama.delete: Delete Agama Flow related information https://jans.io/oauth/jans-auth-server/session.readonly: View Session related information https://jans.io/oauth/jans-auth-server/session.delete: Delete Session information https://jans.io/oauth/config/read-all: Super admin read access to all configuration resources https://jans.io/oauth/config/write-all: Super admin write access to all configuration resources https://jans.io/oauth/config/delete-all: Super admin delete access to all configuration resources https://jans.io/oauth/config/openid/openid.readonly: View OpenID functionality https://jans.io/oauth/config/openid/openid.write: Manage OpenID functionality https://jans.io/oauth/config/openid/openid.delete: Delete OpenID functionality https://jans.io/oauth/config/uma.readonly: View UMA functionality https://jans.io/oauth/config/uma.write: Manage UMA functionality https://jans.io/oauth/config/uma.delete: Delete UMA functionality https://jans.io/oauth/config/plugin.readonly: View Plugin information https://jans.io/oauth/config/properties.readonly: View Config-API related configuration properties https://jans.io/oauth/config/properties.write: Manage Config-API related configuration properties https://jans.io/oauth/client/authorizations.readonly: View ClientAuthorizations https://jans.io/oauth/client/authorizations.delete: Revoke ClientAuthorizations https://jans.io/oauth/config/asset.readonly: View Jans Assets https://jans.io/oauth/config/asset.write: Manage Jans Assets https://jans.io/oauth/config/asset.delete: Delete Jans Assets https://jans.io/oauth/config/token.readonly: View Token details https://jans.io/oauth/config/token.write: Manage Token details https://jans.io/oauth/config/token.delete: Delete Token details https://jans.io/oauth/config/data.readonly: View Config-API related data https://jans.io/oauth/config/ssa.readonly: View SSA details https://jans.io/oauth/config/ssa.write: Manage SSA details https://jans.io/oauth/config/ssa.delete: Delete SSA details https://jans.io/oauth/jans-auth-server/config/properties.admin: Admin scope for Auth Server properties https://jans.io/oauth/config/attributes.admin: Admin for Attribute management https://jans.io/oauth/config/acrs.admin: Admin for ACRS management https://jans.io/oauth/config/database.admin: Admin for Database config management https://jans.io/oauth/config/scripts.admin: Admin for Scripts management https://jans.io/oauth/config/cache.admin: Admin for Cache management https://jans.io/oauth/config/message.admin: Admin for Message management https://jans.io/oauth/config/smtp.admin: Admin for SMTP management https://jans.io/oauth/config/logging.admin: Admin for Logging management https://jans.io/oauth/config/jwks.admin: Admin for JWKS management https://jans.io/oauth/config/openid/clients.admin: Admin for clients management https://jans.io/oauth/config/token.admin: Admin for Token management https://jans.io/oauth/config/scopes.admin: Admin for scope management https://jans.io/oauth/config/stats.admin: Admin for statistic management https://jans.io/oauth/config/organization.admin: Admin for organization configuration management https://jans.io/oauth/config/agama.admin: Admin for Agama flow management https://jans.io/oauth/jans-auth-server/session.admin: Admin for Session management https://jans.io/oauth/config/uma.admin: Admin for UMA management https://jans.io/oauth/config/plugin.admin: Admin for Plugin management https://jans.io/oauth/config/properties.admin: Admin for Config-API management https://jans.io/oauth/client/authorizations.admin: Admin for Client Authorizations management https://jans.io/oauth/config/asset.admin: Admin for Jans Assets management https://jans.io/auth/ssa.admin: Admin for SSA management https://jans.io/oauth/config/health.admin: Admin for Health API management