openapi: 3.2.0 info: title: IndyKite REST Auth ZEN API description: OpenAPI specifications to test the IndyKite REST Endpoints license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 version: '' servers: - url: https://eu.api.indykite.com - url: https://us.api.indykite.com security: - bearerAuth: [] - APIKey: [] tags: - description: Authorization API implemented according to AuthZEN specification. name: Auth ZEN x-displayName: AuthZEN paths: /access/v1/evaluation: post: summary: AuthZEN specified Evaluation endpoint description: Evaluate the authorization request and return decision in response. tags: - Auth ZEN operationId: createAccessV1Evaluation security: - APIKey: [] requestBody: content: application/json: schema: $ref: '#/components/schemas/restapi.EvaluationRequest' description: Evaluation request required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/restapi.EvaluationResponse' '400': description: Bad request content: application/json: schema: allOf: - $ref: '#/components/schemas/restapi.DetailedError' - properties: errors: items: type: string type: array message: type: string type: object '422': description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/restapi.DetailedError' '500': description: Internal Server Error content: application/json: schema: allOf: - $ref: '#/components/schemas/restapi.ErrorResponse' - properties: message: type: string type: object x-codegen-request-body-name: request /access/v1/evaluations: post: operationId: createAccessV1Evaluations summary: AuthZEN specified Evaluations endpoint security: - APIKey: [] description: Evaluate multiple authorization requests at once and return decisions in response. tags: - Auth ZEN requestBody: content: application/json: schema: $ref: '#/components/schemas/restapi.EvaluationsRequest' description: Evaluation request required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/restapi.EvaluationsResponse' '400': description: Bad request content: application/json: schema: allOf: - $ref: '#/components/schemas/restapi.DetailedError' - properties: errors: items: type: string type: array message: type: string type: object '422': description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/restapi.DetailedError' '500': description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/restapi.ErrorResponse' x-codegen-request-body-name: request /access/v1/search/action: post: operationId: createAccessV1SearchAction summary: AuthZEN specified Action Search API security: - APIKey: [] description: Search for actions allowed to be done by the specified subject on the specified resource. tags: - Auth ZEN requestBody: content: application/json: schema: $ref: '#/components/schemas/restapi.SearchActionRequest' description: Action Search request required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/restapi.SearchActionResponse' '400': description: Bad request content: application/json: schema: allOf: - $ref: '#/components/schemas/restapi.DetailedError' - properties: errors: items: type: string type: array message: type: string type: object '422': description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/restapi.DetailedError' '500': description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/restapi.ErrorResponse' x-codegen-request-body-name: request /access/v1/search/resource: post: operationId: createAccessV1SearchResource summary: AuthZEN specified Resource Search API security: - APIKey: [] description: Search for resources that the specified subject is allowed to do the specified action on. tags: - Auth ZEN requestBody: content: application/json: schema: $ref: '#/components/schemas/restapi.SearchResourceRequest' description: Resource Search request required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/restapi.SearchResourceResponse' '400': description: Bad request content: application/json: schema: allOf: - $ref: '#/components/schemas/restapi.DetailedError' - properties: errors: items: type: string type: array message: type: string type: object '422': description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/restapi.DetailedError' '500': description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/restapi.ErrorResponse' x-codegen-request-body-name: request /access/v1/search/subject: post: operationId: createAccessV1SearchSubject summary: AuthZEN specified Subject Search API security: - APIKey: [] description: Search for subjects allowed to do the specified action on the specified resource. tags: - Auth ZEN requestBody: content: application/json: schema: $ref: '#/components/schemas/restapi.SearchSubjectRequest' description: Subject Search request required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/restapi.SearchSubjectResponse' '400': description: Bad request content: application/json: schema: allOf: - $ref: '#/components/schemas/restapi.DetailedError' - properties: errors: items: type: string type: array message: type: string type: object '422': description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/restapi.DetailedError' '500': description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/restapi.ErrorResponse' x-codegen-request-body-name: request components: schemas: restapi.Action: type: object required: - name properties: name: type: string description: Name specifies the action. examples: - CAN_READ examples: - name: CAN_READ restapi.EvaluationsRequest: type: object required: - evaluations properties: action: $ref: '#/components/schemas/restapi.Action' context: $ref: '#/components/schemas/restapi.Context' evaluations: type: array items: $ref: '#/components/schemas/restapi.OptionalFields' resource: $ref: '#/components/schemas/restapi.Node' subject: $ref: '#/components/schemas/restapi.Node' restapi.SearchSubjectResponse: type: object properties: results: type: array items: $ref: '#/components/schemas/restapi.Node' restapi.SearchResourceResponse: type: object properties: results: type: array items: $ref: '#/components/schemas/restapi.Node' restapi.SearchActionRequest: type: object required: - resource - subject properties: context: $ref: '#/components/schemas/restapi.Context' resource: $ref: '#/components/schemas/restapi.Node' subject: $ref: '#/components/schemas/restapi.Node' restapi.EvaluationResponse: type: object properties: context: $ref: '#/components/schemas/restapi.respContext' decision: type: boolean examples: - true examples: - context: advice: - error: insufficient_user_authentication error_description: A different authentication level is required acr_values: whatever decision: true restapi.EvaluationRequest: type: object required: - action - resource - subject properties: action: $ref: '#/components/schemas/restapi.Action' context: $ref: '#/components/schemas/restapi.Context' resource: $ref: '#/components/schemas/restapi.Node' subject: $ref: '#/components/schemas/restapi.Node' examples: - action: name: CAN_READ context: input_params: additionalProp1: {} additionalProp2: {} policy_tags: - Tag1 - Tag2 resource: id: IdSpecifyingTheNode type: NodeType subject: id: IdSpecifyingTheNode type: NodeType restapi.ErrorResponse: type: object properties: message: type: string examples: - Internal Server Error restapi.OptionalFields: type: object properties: action: $ref: '#/components/schemas/restapi.Action' context: $ref: '#/components/schemas/restapi.Context' resource: $ref: '#/components/schemas/restapi.Node' subject: $ref: '#/components/schemas/restapi.Node' restapi.Node: type: object required: - id - type properties: id: type: string description: ID is a node external_id. examples: - IdSpecifyingTheNode type: type: string description: Type is a node label. examples: - NodeType examples: - id: IdSpecifyingTheNode type: NodeType restapi.Context: type: object properties: input_params: type: object additionalProperties: {} description: 'InputParams map specifies the values of input parameters used within the policies. If a policy uses input parameters and is used for making the decision, they must be sent with the request, otherwise an error is returned.' examples: - additionalProp1: {} additionalProp2: {} policy_tags: type: array description: PolicyTags array limits the policies used to only the policies with the specified tags. items: type: string uniqueItems: true examples: - - tag1 - tag2 examples: - input_params: additionalProp1: {} additionalProp2: {} policy_tags: - Tag1 - Tag2 restapi.SearchSubjectRequest: type: object required: - action - resource - subject properties: action: $ref: '#/components/schemas/restapi.Action' context: $ref: '#/components/schemas/restapi.Context' resource: $ref: '#/components/schemas/restapi.Node' subject: $ref: '#/components/schemas/restapi.NodeType' restapi.NodeType: type: object required: - type properties: type: type: string examples: - NodeType restapi.respContext: type: object properties: advice: type: array items: type: object additionalProperties: type: string reason: type: string examples: - advice: - error: insufficient_user_authentication error_description: A different authentication level is required acr_values: whatever restapi.EvaluationsResponse: type: object properties: evaluations: type: array items: $ref: '#/components/schemas/restapi.EvaluationResponse' restapi.SearchActionResponse: type: object properties: results: type: array items: $ref: '#/components/schemas/restapi.Action' restapi.SearchResourceRequest: type: object required: - action - resource - subject properties: action: $ref: '#/components/schemas/restapi.Action' context: $ref: '#/components/schemas/restapi.Context' resource: $ref: '#/components/schemas/restapi.NodeType' subject: $ref: '#/components/schemas/restapi.Node' restapi.DetailedError: type: object properties: errors: type: array description: Errors are optional and may contain additional details. items: type: string examples: - - missing bearer token message: type: string description: Message describes the error. examples: - unauthorized request securitySchemes: bearerAuth: type: http scheme: bearer description: Bearer token - the value of the Authorization header (without Bearer), e.g. "superSecretToken". APIKey: type: apiKey in: header name: X-IK-ClientKey description: The value of the App Agent credential header must be passed as is, without any prefix. x-tagGroups: - name: Capture REST API tags: - Capture - name: Data Schema REST API tags: - DataSchema - name: ContX IQ REST API tags: - ContX IQ - name: AuthZEN REST API tags: - AuthZEN - Deprecated - name: Entity Matching Pipeline REST API tags: - EntityMatching