openapi: 3.0.3 info: version: 1.2.0 title: Hanko Admin Audit Logs Token API description: '## Introduction This is the OpenAPI specification for the [Hanko Admin API](https://github.com/teamhanko/hanko/blob/main/backend/README.md#start-private-api). ## Authentication The Admin API must be protected by an access management system. --- ' contact: email: developers@hanko.io license: name: AGPL-3.0-or-later url: https://www.gnu.org/licenses/agpl-3.0.txt servers: - url: https://{tenant_id}.hanko.io/admin variables: tenant_id: default: '' description: The (UU)ID of a tenant. Replace the default value with your tenant ID. tags: - name: Token paths: /token: post: deprecated: true summary: Exchange one time token for session description: 'Provide a one time token (e.g. obtained through the [thirdparty callback](#tag/Third-Party/operation/thirdPartyCallback)) to retrieve a session JWT as cookie and/or via `X-Auth-Token` header. ' operationId: token tags: - Token requestBody: content: application/json: schema: type: object properties: value: type: string format: base64url responses: '200': description: Successful token exchange headers: X-Auth-Token: description: 'Present only on successful exchange and when enabled via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `session.enable_auth_token_header` for purposes of cross-domain communication between client and Hanko API. ' schema: $ref: '#/components/schemas/X-Auth-Token' X-Session-Lifetime: description: 'Contains the seconds until the session expires. ' schema: $ref: '#/components/schemas/X-Session-Lifetime' Set-Cookie: description: 'Present only on successful exchange. Contains the JSON Web Token (JWT) that must be provided to protected endpoints. Cookie attributes (e.g. domain) can be set via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `session.cookie`. ' schema: $ref: '#/components/schemas/CookieSession' content: application/json: schema: type: object properties: user_id: description: The ID of the user on whose behalf the token was exchanged. allOf: - $ref: '#/components/schemas/UUID4' '400': $ref: '#/components/responses/BadRequest' '404': $ref: '#/components/responses/NotFound' '422': $ref: '#/components/responses/unprocessableEntity' '429': $ref: '#/components/responses/TooManyRequests' components: schemas: X-Session-Lifetime: description: 'Contains the seconds until the session expires. ' type: number UUID4: type: string format: uuid4 example: c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c Error: type: object required: - code - message properties: code: type: integer format: int32 message: type: string X-Auth-Token: description: 'Enable via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `session.enable_auth_token_header` for purposes of cross-domain communication between client and Hanko API. ' type: string format: JWT externalDocs: url: https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config CookieSession: type: string description: Value `` is a [JSON Web Token](https://www.rfc-editor.org/rfc/rfc7519.html) example: hanko=; Path=/; HttpOnly responses: unprocessableEntity: description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 422 message: Unprocessable Entity BadRequest: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 400 message: Bad Request NotFound: description: Not Found content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 404 message: Not found TooManyRequests: description: Too Many Requests content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 429 message: Too Many Requests securitySchemes: BearerApiKeyAuth: description: Bearer authentication header of the form `Bearer `, where `` is your API key. Must only be used when using Hanko Cloud. type: http scheme: bearer bearerFormat: API Key externalDocs: description: More about Hanko url: https://github.com/teamhanko/hanko