openapi: 3.2.0 info: title: Janssen Authorization Server Session Management API description: Janssen Authorization Server - OAuth 2.0 server; OpenID Connect Provider (OP) & UMA Authorization Server (AS) contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io/jans-auth tags: - name: Session Management paths: /restv1/session_status: get: tags: - Session Management summary: Determine current session status description: Determine current session status. operationId: session_status responses: 200: description: OK content: application/json: schema: title: SessionStateObject type: object properties: state: type: string description: String that represents the End-User's login state at the OP. It MUST NOT contain the space (\" \") character. auth_time: type: string format: date description: specifies the time at which session was authenticated. example: 100000000 custom_state: type: string /restv1/end_session: get: tags: - Session Management summary: End current session description: End current session. operationId: end_session parameters: - name: id_token_hint in: query description: Previously issued ID Token (id_token) passed to the logout endpoint as a hint about the End-User's current authenticated session with the Client. This is used as an indication of the identity of the End-User that the RP is requesting be logged out by the OP. The OP need not be listed as an audience of the ID Token when it is used as an id_token_hint value. schema: type: string - name: post_logout_redirect_uri in: query description: URL to which the RP is requesting that the End-User's User Agent be redirected after a logout has been performed. The value MUST have been previously registered with the OP, either using the post_logout_redirect_uris Registration parameter or via another mechanism. If supplied, the OP SHOULD honor this request following the logout. schema: type: string - name: state in: query description: Opaque value used by the RP to maintain state between the logout request and the callback to the endpoint specified by the post_logout_redirect_uri parameter. If included in the logout request, the OP passes this value back to the RP using the state query parameter when redirecting the User Agent back to the RP. schema: type: string - name: session_id in: query description: Session Id schema: type: string - name: client_id in: query description: Client Id. It can be useful to specify client id explicitly in case id_token and session are expired so AS can still validate post_logout_redirect_uri schema: type: string responses: 200: description: OK - User redirected to logout page content: {} 302: $ref: '#/components/responses/Found' 400: description: Error codes for end session endpoint. content: application/json: schema: title: EndSessionError type: object required: - error - error_description properties: error: type: string format: enum example: - invalid_grant - invalid_request - invalid_grant_and_session - session_not_passed - post_logout_uri_not_passed - post_logout_uri_not_associated_with_client error_description: type: string details: type: string 500: $ref: '#/components/responses/InternalServerError' components: responses: Found: description: Resource Found. content: {} InternalServerError: description: Internal error occured. Please check log file for details. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' schemas: ErrorResponse: required: - error - error_description type: object properties: error: type: string error_description: type: string details: type: string securitySchemes: bearer: type: http scheme: bearer