openapi: 3.2.0 info: description: 'The Grafana backend exposes an HTTP API, the same API is used by the frontend to do everything from saving dashboards, creating users and updating data sources.' title: Grafana HTTP API. SAML API contact: name: Grafana Labs url: https://grafana.com email: hello@grafana.com version: 0.0.1 servers: - url: /api security: - basic: [] - api_key: [] tags: - name: SAML paths: /logout/saml: get: tags: - SAML summary: GetLogout initiates single logout process operationId: getSAMLLogout responses: '302': description: (empty) '404': $ref: '#/components/responses/notFoundError' '500': $ref: '#/components/responses/internalServerError' /saml/acs: post: tags: - SAML summary: It performs Assertion Consumer Service (ACS) operationId: postACS parameters: - name: RelayState in: query schema: type: string responses: '302': description: (empty) '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' /saml/metadata: get: tags: - SAML summary: It exposes the SP (Grafana's) metadata for the IdP's consumption operationId: getMetadata responses: '200': $ref: '#/components/responses/contentResponse' /saml/slo: get: description: 'There might be two possible requests: 1. Logout response (callback) when Grafana initiates single logout and IdP returns response to logout request. 2. Logout request when another SP initiates single logout and IdP sends logout request to the Grafana, or in case of IdP-initiated logout.' tags: - SAML summary: It performs Single Logout (SLO) callback operationId: getSLO responses: '302': description: (empty) '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' post: description: 'There might be two possible requests: 1. Logout response (callback) when Grafana initiates single logout and IdP returns response to logout request. 2. Logout request when another SP initiates single logout and IdP sends logout request to the Grafana, or in case of IdP-initiated logout.' tags: - SAML summary: It performs Single Logout (SLO) callback operationId: postSLO parameters: - name: SAMLRequest in: query schema: type: string - name: SAMLResponse in: query schema: type: string responses: '302': description: (empty) '400': $ref: '#/components/responses/badRequestError' '403': $ref: '#/components/responses/forbiddenError' '500': $ref: '#/components/responses/internalServerError' components: responses: contentResponse: description: (empty) content: application/json: schema: type: array items: type: integer format: uint8 internalServerError: description: InternalServerError is a general error indicating something went wrong internally. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' badRequestError: description: BadRequestError is returned when the request is invalid and it cannot be processed. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' forbiddenError: description: ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' notFoundError: description: NotFoundError is returned when the requested resource was not found. content: application/json: schema: $ref: '#/components/schemas/ErrorResponseBody' schemas: ErrorResponseBody: type: object required: - message properties: error: description: Error An optional detailed description of the actual error. Only included if running in developer mode. type: string message: description: a human readable version of the error type: string status: description: 'Status An optional status to denote the cause of the error. For example, a 412 Precondition Failed error may include additional information of why that error happened.' type: string securitySchemes: api_key: type: apiKey name: Authorization in: header basic: type: http scheme: basic