openapi: 3.2.0 info: title: SCIM fido2 devices API description: 'Janssen SCIM 2.0 server API. Developers can think of SCIM as a REST API with endpoints exposing CRUD functionality (create, update, retrieve and delete) for identity management resources such as users, groups, and fido devices.' contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io/jans-scim/restv1/v2 tags: - name: fido2 devices description: Endpoints for management of Fido2 devices paths: /Fido2Devices: get: tags: - fido2 devices operationId: get-fido2-devices description: Query Fido 2 resources security: - scim_oauth: - https://jans.io/scim/fido2.read parameters: - name: attributes in: query description: A comma-separated list of attribute names to return in the response schema: type: string - name: excludedAttributes in: query description: When specified, the response will contain a default set of attributes minus those listed here (as a comma-separated list) schema: type: string - name: userId in: query description: Used to restrict the search to fido 2 resources owned by a specific user schema: type: string - name: filter in: query description: An expression specifying the search criteria. See section 3.4.2.2 of RFC 7644 example: userId sw "123-abcde-qwerty" schema: type: string - name: startIndex in: query description: The 1-based index of the first query result schema: type: integer - name: count in: query description: Specifies the desired maximum number of query results per page schema: type: integer - name: sortBy in: query description: The attribute whose value will be used to order the returned responses schema: type: string - name: sortOrder in: query description: Order in which the sortBy param is applied. Allowed values are "ascending" and "descending" schema: type: string responses: 200: description: Successful operation content: application/scim+json: schema: $ref: '#/components/schemas/Fido2ListResponse' application/json: schema: $ref: '#/components/schemas/Fido2ListResponse' 400: description: Parameter count exceeds the maximum allowed value or the filter supplied was unparsable content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 404: description: If userId param was supplied and the user is not known content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: There was an unexpected failure executing the operation content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' summary: Get fido2 devices x-summary-source: derived /Fido2Devices/{id}: get: tags: - fido2 devices operationId: get-fido2-device-by-id description: Retrieves a Fido 2 device by Id security: - scim_oauth: - https://jans.io/scim/fido2.read parameters: - name: attributes in: query description: A comma-separated list of attribute names to return in the response schema: type: string - name: excludedAttributes in: query description: When specified, the response will contain a default set of attributes minus those listed here (as a comma-separated list) schema: type: string - name: userId in: query description: Identifier (inum) of the device owner. This param is not required when underlying database is LDAP schema: type: string - name: id in: path required: true schema: type: string responses: 200: description: Successful operation content: application/scim+json: schema: $ref: '#/components/schemas/Fido2DeviceResource' application/json: schema: $ref: '#/components/schemas/Fido2DeviceResource' 404: description: Id passed unknown content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: There was an unexpected failure executing the operation content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' summary: Get fido2 device by id x-summary-source: derived put: tags: - fido2 devices operationId: update-fido2-device-by-id description: Updates a Fido 2 resource. Update works in a replacement fashion: every attribute value found in the payload sent will replace the one in the existing resource representation. Attributes not passed in the payload will be left intact. security: - scim_oauth: - https://jans.io/scim/fido2.write parameters: - name: attributes in: query description: A comma-separated list of attribute names to return in the response schema: type: string - name: excludedAttributes in: query description: When specified, the response will contain a default set of attributes minus those listed here (as a comma-separated list) schema: type: string - name: id in: path required: true schema: type: string requestBody: description: Payload with the data to replace in the existing device identified by the id param content: application/scim+json: schema: $ref: '#/components/schemas/Fido2DeviceResource' application/json: schema: $ref: '#/components/schemas/Fido2DeviceResource' required: true responses: 200: description: Successful operation content: application/scim+json: schema: $ref: '#/components/schemas/Fido2DeviceResource' application/json: schema: $ref: '#/components/schemas/Fido2DeviceResource' 400: description: 'An invalid value was passed in the payload or there was an attempt to update an immutable attribute ' content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 404: description: Id passed unknown content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: There was an unexpected failure executing the operation content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' x-codegen-request-body-name: fido2DeviceResource summary: Update fido2 device by id x-summary-source: derived delete: tags: - fido2 devices operationId: delete-fido2-device-by-id description: Deletes a Fido 2 resource security: - scim_oauth: - https://jans.io/scim/fido2.write parameters: - name: id in: path description: Identifier of the resource to delete required: true schema: type: string responses: 204: description: Successful operation. Empty response content: {} 404: description: Id passed unknown content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: There was an unexpected failure executing the operation content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' summary: Delete fido2 device by id x-summary-source: derived /Fido2Devices/.search: post: tags: - fido2 devices operationId: search-fido2-device description: Query Fido 2 resources security: - scim_oauth: - https://jans.io/scim/fido2.read parameters: - name: userId in: query description: Used to restrict the search to fido 2 resources owned by a specific user schema: type: string requestBody: description: Payload that represents the search criteria content: application/scim+json: schema: $ref: '#/components/schemas/SearchRequest' examples: samplePayload: externalValue: https://raw.githubusercontent.com/JanssenProject/jans/main/jans-scim/client/src/test/resources/multiple/search_post_2.json application/json: schema: $ref: '#/components/schemas/SearchRequest' examples: samplePayload: externalValue: https://raw.githubusercontent.com/JanssenProject/jans/main/jans-scim/client/src/test/resources/multiple/search_post_2.json required: true responses: 200: description: Successful operation content: application/scim+json: schema: $ref: '#/components/schemas/Fido2ListResponse' 400: description: 'Parameter count exceeds the maximum allowed value, the filter supplied was unparsable, or invalid schema in search request ' content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 404: description: If userId param was supplied and the user is not known content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' 500: description: There was an unexpected failure executing the operation content: application/scim+json: schema: $ref: '#/components/schemas/ErrorResponse' application/json: schema: $ref: '#/components/schemas/ErrorResponse' x-codegen-request-body-name: searchRequest summary: Search fido2 device x-summary-source: derived components: schemas: Fido2DeviceResource: description: Represents a Fido 2 device enrollment allOf: - $ref: '#/components/schemas/BaseResource' - type: object properties: userId: type: string description: Identifies the owner of the enrollment creationDate: type: string description: Date of enrollment in ISO format format: date-time counter: type: integer description: Value used in the Fido 2 endpoints status: type: string enum: - registered - pending - compromised - canceled displayName: type: string description: Device name suitable for display to end-users ErrorResponse: required: - status type: object properties: schemas: type: array items: type: string example: urn:ietf:params:scim:api:messages:2.0:Error status: type: string description: HTTP status code as string scimType: type: string description: A detail error keyword. See table 9 of RFC 7644 detail: type: string description: A detailed human-readable message of the error description: See section 3.12 of RFC 7644 BaseResource: type: object properties: schemas: type: array description: URIs that are used to indicate the namespaces of the SCIM schemas that define the attributes present in the current structure items: type: string id: type: string description: A unique identifier for a SCIM resource. See section 3.1 of RFC 7643 meta: $ref: '#/components/schemas/Meta' Meta: type: object properties: resourceType: type: string created: type: string lastModified: type: string location: type: string description: Descriptive information about a resource. See section 3.1 of RFC 7643 BasicListResponse: type: object properties: schemas: type: array items: type: string example: urn:ietf:params:scim:api:messages:2.0:ListResponse totalResults: type: integer description: Total number of results returned by the search. The value may be larger than the number of resources returned due to pagination startIndex: type: integer description: The 1-based index of the first result in the current set of search results itemsPerPage: type: integer description: The number of resources returned in a results page SearchRequest: type: object properties: schemas: type: array items: type: string example: urn:ietf:params:scim:api:messages:2.0:SearchRequest attributes: type: array description: A list of attribute names to return in the response items: type: string excludedAttributes: type: array description: When specified, the response will contain a default set of attributes minus those listed here items: type: string filter: type: string description: An expression specifying the search criteria. See section 3.4.2.2 of RFC 7644 example: userName eq "jhon" and meta.lastModified gt "2011-05-13T04:42:34Z" sortBy: type: string description: The attribute whose value will be used to order the returned responses sortOrder: type: string description: Order in which the sortBy param is applied. Allowed values are "ascending" and "descending" startIndex: type: integer description: The 1-based index of the first query result count: type: integer description: Specifies the desired maximum number of query results per page description: See section 3.4.3 of RFC 7644 Fido2ListResponse: description: Results for fido 2 devices search allOf: - $ref: '#/components/schemas/BasicListResponse' - type: object properties: Resources: type: array items: $ref: '#/components/schemas/Fido2DeviceResource' securitySchemes: scim_oauth: type: oauth2 description: Endpoints protected by a bearer token passed in the Authorization header. flows: clientCredentials: tokenUrl: https://localhost/jans-auth/restv1/token scopes: https://jans.io/scim/users.read: Query user resources https://jans.io/scim/users.write: Modify user resources https://jans.io/scim/groups.read: Query group resources https://jans.io/scim/groups.write: Modify group resources https://jans.io/scim/fido.read: Query fido resources https://jans.io/scim/fido.write: Modify fido resources https://jans.io/scim/fido2.read: Query fido 2 resources https://jans.io/scim/fido2.write: Modify fido 2 resources https://jans.io/scim/all-resources.search: Access the root .search endpoint https://jans.io/scim/bulk: Send requests to the bulk endpoint https://jans.io/scim/tokens: List and revoke user tokens