openapi: 3.1.0
info:
contact:
email: support@konghq.com
name: Kong Inc
url: https://konghq.com
description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API.
You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com).
Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.'
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
title: Kong Enterprise Admin ACLs Portal Auth Settings API
version: 3.14.0
servers:
- description: Default Admin API URL
url: '{protocol}://{hostname}:{port}{path}'
variables:
hostname:
default: localhost
description: Hostname for Kong's Admin API
path:
default: /
description: Base path for Kong's Admin API
port:
default: '8001'
description: Port for Kong's Admin API
protocol:
default: http
description: Protocol for requests to Kong's Admin API
enum:
- http
- https
security:
- adminToken: []
tags:
- name: Portal Auth Settings
description: APIs related to configuration of Konnect Developer Portal auth settings.
paths:
/v3/portals/{portalId}/authentication-settings:
parameters:
- $ref: '#/components/parameters/PortalId'
get:
x-speakeasy-entity-operation:
terraform-resource: PortalAuth#read
terraform-datasource: null
operationId: get-portal-authentication-settings
summary: Get Auth Settings
description: Returns the developer authentication configuration for a portal, which determines how developers can log in and how they are assigned to teams.
responses:
'200':
$ref: '#/components/responses/PortalAuthenticationSettings'
'401':
$ref: '#/components/responses/Unauthorized'
tags:
- Portal Auth Settings
patch:
x-speakeasy-entity-operation:
terraform-resource: PortalAuth#create,update
terraform-datasource: null
operationId: update-portal-authentication-settings
summary: Update Auth Settings
description: Updates the developer authentication configuration for a portal. Developers can be allowed to login using basic auth (email & password) or use Single-Sign-On through an Identity Provider. Developers can be automatically assigned to teams by mapping claims from their IdP account.
requestBody:
$ref: '#/components/requestBodies/UpdatePortalAuthenticationSettings'
responses:
'200':
$ref: '#/components/responses/PortalAuthenticationSettings'
'400':
description: Bad Request
content:
application/problem+json:
schema:
$ref: '#/components/schemas/BadRequestError'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
tags:
- Portal Auth Settings
/v3/portals/{portalId}/identity-provider/team-group-mappings:
parameters:
- $ref: '#/components/parameters/PortalId'
get:
operationId: list-portal-team-group-mappings
summary: List Team Group Mappings
description: '**Pre-release Endpoint**
This endpoint is currently in beta and is subject to change.
Lists mappings between Konnect portal teams and Identity Provider (IdP) groups. Returns a 400 error if an IdP has not yet been configured.'
parameters:
- $ref: '#/components/parameters/PageSize'
- $ref: '#/components/parameters/PageNumber'
responses:
'200':
$ref: '#/components/responses/PortalTeamGroupMappingCollection'
'400':
description: Bad Request
content:
application/problem+json:
schema:
$ref: '#/components/schemas/BadRequestError'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
tags:
- Portal Auth Settings
patch:
operationId: update-portal-team-group-mappings
summary: Update Team Group Mappings
description: '**Pre-release Endpoint**
This endpoint is currently in beta and is subject to change.
Allows partial updates to the mappings between Konnect portal teams and Identity Provider (IdP) groups. The request body must be keyed on team ID. For a given team ID, the given group list is a complete replacement. To remove all mappings for a given team, provide an empty group list.
Returns a 400 error if an IdP has not yet been configured, or if a team ID in the request body is not found or is not a UUID.'
requestBody:
$ref: '#/components/requestBodies/UpdatePortalTeamGroupMappings'
responses:
'200':
$ref: '#/components/responses/PortalTeamGroupMappingCollection'
'400':
description: Bad Request
content:
application/problem+json:
schema:
$ref: '#/components/schemas/BadRequestError'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
tags:
- Portal Auth Settings
/v3/portals/{portalId}/identity-providers:
parameters:
- $ref: '#/components/parameters/PortalId'
get:
operationId: get-portal-identity-providers
summary: List Identity Providers
description: 'Retrieves the identity providers available within the portal. This operation provides information about
various identity providers for SAML or OIDC authentication integrations.
'
parameters:
- name: filter
in: query
description: Filter identity providers returned in the response.
required: false
schema:
type: object
properties:
type:
$ref: '#/components/schemas/StringFieldEqualsFilter'
style: deepObject
responses:
'200':
$ref: '#/components/responses/IdentityProviders'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
tags:
- Portal Auth Settings
post:
operationId: create-portal-identity-provider
summary: Create Identity Provider
description: 'Creates a new identity provider. This operation allows the creation of a new identity provider for
authentication purposes.
'
requestBody:
$ref: '#/components/requestBodies/CreateIdentityProviderRequest'
responses:
'201':
$ref: '#/components/responses/IdentityProvider'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'409':
$ref: '#/components/responses/Conflict'
tags:
- Portal Auth Settings
/v3/portals/{portalId}/identity-providers/{id}:
parameters:
- $ref: '#/components/parameters/PortalId'
- $ref: '#/components/parameters/IdentityProviderId'
get:
operationId: get-portal-identity-provider
summary: Get Identity Provider
description: 'Retrieves the configuration of a single identity provider. This operation returns information about a
specific identity provider''s settings and authentication integration details.
'
responses:
'200':
$ref: '#/components/responses/IdentityProvider'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
tags:
- Portal Auth Settings
patch:
operationId: update-portal-identity-provider
summary: Update Identity Provider
description: 'Updates the configuration of an existing identity provider. This operation allows modifications to be made
to an existing identity provider''s configuration.
'
requestBody:
$ref: '#/components/requestBodies/UpdateIdentityProviderRequest'
responses:
'200':
$ref: '#/components/responses/IdentityProvider'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
'409':
$ref: '#/components/responses/Conflict'
tags:
- Portal Auth Settings
delete:
operationId: delete-portal-identity-provider
summary: Delete Identity Provider
description: 'Deletes an existing identity provider configuration. This operation removes a specific identity provider
from the portal.
'
responses:
'204':
description: No Content
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
tags:
- Portal Auth Settings
/v3/portals/{portalId}/identity-providers/{id}/team-group-mappings:
parameters:
- $ref: '#/components/parameters/PortalId'
- $ref: '#/components/parameters/IdentityProviderId'
get:
operationId: list-portal-idp-team-group-mappings
summary: List Team Group Mappings
description: 'Returns a paginated list of team group mappings for the specified identity provider.
'
parameters:
- $ref: '#/components/parameters/PageSize'
- $ref: '#/components/parameters/PageAfter'
- $ref: '#/components/parameters/PageBefore'
- name: filter
in: query
description: Filter mappings by team ID or group name.
required: false
schema:
type: object
properties:
team_id:
$ref: '#/components/schemas/StringFieldEqualsFilter'
group:
$ref: '#/components/schemas/StringFieldEqualsFilter'
style: deepObject
responses:
'200':
$ref: '#/components/responses/PortalIdpTeamGroupMappingCollection'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
tags:
- Portal Auth Settings
post:
operationId: create-portal-idp-team-group-mapping
summary: Create Team Group Mapping
description: 'Creates a new team group mapping for the specified identity provider.
'
requestBody:
$ref: '#/components/requestBodies/CreatePortalIdpTeamGroupMapping'
responses:
'201':
$ref: '#/components/responses/PortalIdpTeamGroupMapping'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
'409':
$ref: '#/components/responses/Conflict'
tags:
- Portal Auth Settings
/v3/portals/{portalId}/identity-providers/{id}/team-group-mappings/{mappingId}:
parameters:
- $ref: '#/components/parameters/PortalId'
- $ref: '#/components/parameters/IdentityProviderId'
- $ref: '#/components/parameters/TeamGroupMappingId'
get:
operationId: get-portal-idp-team-group-mapping
summary: Get Team Group Mapping
description: Returns the team group mapping for the specified ID.
responses:
'200':
$ref: '#/components/responses/PortalIdpTeamGroupMapping'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
tags:
- Portal Auth Settings
delete:
operationId: delete-portal-idp-team-group-mapping
summary: Delete Team Group Mapping
description: 'Deletes a team group mapping by ID.
Returns 204 if the mapping was deleted, or 404 if the mapping was not found.
'
responses:
'204':
description: No Content
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
tags:
- Portal Auth Settings
components:
responses:
PortalTeamGroupMappingCollection:
description: A paginated collection of mappings grouped by team ID.
content:
application/json:
schema:
$ref: '#/components/schemas/PortalTeamGroupMappingResponse'
PortalIdpTeamGroupMapping:
description: A team group mapping for an identity provider.
content:
application/json:
schema:
$ref: '#/components/schemas/PortalIdpTeamGroupMapping'
NotFound:
description: Not Found
content:
application/problem+json:
schema:
$ref: '#/components/schemas/NotFoundError'
BadRequest:
description: Bad Request
content:
application/problem+json:
schema:
$ref: '#/components/schemas/BadRequestError'
IdentityProviders:
description: 'A collection of identity providers. This response contains a collection of identity providers, which may include both OIDC and SAML identity providers.
'
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/IdentityProvider'
title: Identity Provider Collection Response
Conflict:
description: Conflict
content:
application/problem+json:
schema:
$ref: '#/components/schemas/ConflictError'
PortalAuthenticationSettings:
description: Details about a portal's authentication settings.
content:
application/json:
schema:
$ref: '#/components/schemas/PortalAuthenticationSettingsResponse'
Unauthorized:
description: Unauthorized
content:
application/problem+json:
schema:
description: The error response object.
type: object
properties:
status:
description: The HTTP status code.
type: integer
example: 403
title:
description: The Error Response.
type: string
example: Unauthorized
instance:
description: The Konnect traceback code.
type: string
example: konnect:trace:952172606039454040
detail:
description: Details about the error response.
type: string
example: You do not have permission to perform this action
$ref: '#/components/schemas/UnauthorizedError'
title: Unauthorized Response
PortalIdpTeamGroupMappingCollection:
description: A paginated collection of team group mappings.
content:
application/json:
schema:
$ref: '#/components/schemas/PortalIdpTeamGroupMappingCollectionResponse'
Forbidden:
description: Forbidden
content:
application/problem+json:
schema:
$ref: '#/components/schemas/ForbiddenError'
IdentityProvider:
description: 'An identity provider configuration. This response represents the configuration of a specific identity provider, which can be either OIDC or SAML.
'
content:
application/json:
schema:
$ref: '#/components/schemas/IdentityProvider'
schemas:
IdentityProvider:
x-speakeasy-entity: IdentityProvider
description: The identity provider that contains configuration data for authentication integration.
type: object
properties:
id:
$ref: '#/components/schemas/UUID'
type:
$ref: '#/components/schemas/IdentityProviderType'
enabled:
$ref: '#/components/schemas/IdentityProviderEnabled'
login_path:
$ref: '#/components/schemas/IdentityProviderLoginPath'
config:
type: object
oneOf:
- $ref: '#/components/schemas/OIDCIdentityProviderConfig'
- $ref: '#/components/schemas/SAMLIdentityProviderConfig'
created_at:
$ref: '#/components/schemas/CreatedAt'
updated_at:
$ref: '#/components/schemas/UpdatedAt'
title: Identity Provider
InvalidParameterMinimumLength:
type: object
properties:
field:
type: string
example: name
readOnly: true
rule:
description: invalid parameters rules
type: string
enum:
- min_length
- min_digits
- min_lowercase
- min_uppercase
- min_symbols
- min_items
- min
nullable: false
readOnly: true
x-speakeasy-unknown-values: allow
minimum:
type: integer
example: 8
source:
type: string
example: body
reason:
type: string
example: must have at least 8 characters
readOnly: true
additionalProperties: false
required:
- field
- reason
- rule
- minimum
SAMLIdentityProviderMetadata:
description: 'The identity provider''s SAML metadata. If the identity provider supports a metadata URL, you can use the `idp_metadata_url` field instead.
'
type: string
example: "\n\n \n\n"
title: SAML Identity Provider Metadata
PortalTeamGroupMappingResponse:
description: A paginated list of portal team group mappings.
type: object
properties:
meta:
$ref: '#/components/schemas/PaginatedMeta'
data:
type: array
items:
$ref: '#/components/schemas/PortalTeamGroupMapping'
example:
meta:
page:
number: 1
size: 10
total: 2
data:
- team_id: 6801e673-cc10-498a-94cd-4271de07a0d3
groups:
- Tech Leads
- API Engineers
- team_id: 7301e673-cc10-498a-94cd-4271de07a0d3
groups:
- Managers
- Directors
title: PortalTeamGroupMappingResponse
PortalIdpTeamGroupMapping:
type: object
properties:
id:
description: The mapping ID.
type: string
format: uuid
example: a1b2c3d4-e5f6-4a8b-9c0d-1e2f3a4b5c6d
readOnly: true
team_id:
description: The Konnect team ID.
type: string
format: uuid
example: 6801e673-cc10-498a-94cd-4271de07a0d3
group:
description: The IdP group name.
type: string
example: API Engineers
created_at:
description: Creation timestamp.
type: string
format: date-time
example: '2024-01-15T10:30:00Z'
readOnly: true
updated_at:
description: Last update timestamp.
type: string
format: date-time
example: '2024-01-15T10:30:00Z'
readOnly: true
required:
- id
- team_id
- group
- created_at
- updated_at
UpdatedAt:
description: An ISO-8601 timestamp representation of entity update date.
type: string
format: date-time
example: '2022-11-04T20:10:06.927Z'
readOnly: true
x-speakeasy-param-suppress-computed-diff: true
InvalidParameterChoiceItem:
type: object
properties:
field:
type: string
example: name
readOnly: true
rule:
description: invalid parameters rules
type: string
enum:
- enum
nullable: false
readOnly: true
reason:
type: string
example: is a required field
readOnly: true
choices:
type: array
items: {}
minItems: 1
nullable: false
readOnly: true
uniqueItems: true
source:
type: string
example: body
additionalProperties: false
required:
- field
- reason
- rule
- choices
ConflictError:
allOf:
- $ref: '#/components/schemas/BaseError'
- type: object
properties:
status:
example: 409
title:
example: Conflict
type:
example: https://httpstatuses.com/409
instance:
example: kong:trace:1234567890
detail:
example: Conflict
InvalidParameterMaximumLength:
type: object
properties:
field:
type: string
example: name
readOnly: true
rule:
description: invalid parameters rules
type: string
enum:
- max_length
- max_items
- max
nullable: false
readOnly: true
x-speakeasy-unknown-values: allow
maximum:
type: integer
example: 8
source:
type: string
example: body
reason:
type: string
example: must not have more than 8 characters
readOnly: true
additionalProperties: false
required:
- field
- reason
- rule
- maximum
OIDCIdentityProviderClaimMappings:
description: "Defines the mappings between OpenID Connect (OIDC) claims and local claims used by your application for \nauthentication.\n"
type: object
properties:
name:
description: The claim mapping for the user's name.
type: string
example: name
default: name
email:
description: The claim mapping for the user's email address.
type: string
example: email
default: email
groups:
description: The claim mapping for the user's group membership information.
type: string
example: groups
default: groups
title: OIDC Claim Mappings
OIDCIdentityProviderScopes:
description: The scopes requested by your application when authenticating with the identity provider.
type: array
items:
type: string
default:
- email
- openid
- profile
title: OIDC Identity Provider Scopes Property
PortalTeamGroupMappingsUpdateRequest:
description: A set of mappings to update from a team to their groups.
type: object
properties:
data:
description: The IdP groups to map to the given team.
type: array
items:
type: object
properties:
team_id:
type: string
format: uuid
groups:
type: array
items:
type: string
example:
data:
- team_id: af91db4c-6e51-403e-a2bf-33d27ae50c0a
groups:
- Service Developer
title: PortalTeamGroupMappingsUpdateRequest
PortalTeamGroupMapping:
description: A map of portal teams to Identity Provider groups.
type: object
properties:
team_id:
description: The Konnect team ID.
type: string
format: uuid
example: 6801e673-cc10-498a-94cd-4271de07a0d3
groups:
description: The IdP groups that are mapped to the specified team.
type: array
items:
type: string
example: API Engineers
uniqueItems: true
example:
team_id: 6801e673-cc10-498a-94cd-4271de07a0d3
groups:
- Tech Leads
- API Engineers
title: PortalTeamGroupMapping
IdentityProviderLoginPath:
description: The path used for initiating login requests with the identity provider.
type: string
example: myapp
title: Identity Provider Login Path Property
UpdateIdentityProvider:
x-speakeasy-entity: IdentityProvider
description: The identity provider that contains configuration data for updating an authentication integration.
type: object
properties:
enabled:
$ref: '#/components/schemas/IdentityProviderEnabled'
login_path:
$ref: '#/components/schemas/IdentityProviderLoginPath'
config:
type: object
oneOf:
- $ref: '#/components/schemas/OIDCIdentityProviderConfig'
- $ref: '#/components/schemas/SAMLIdentityProviderConfig'
title: Identity Provider
PortalClaimMappings:
description: Mappings from a portal developer atribute to an Identity Provider claim.
type: object
properties:
name:
type: string
example: name
default: name
email:
type: string
example: email
default: email
groups:
type: string
example: custom-group-claim
default: groups
example:
name: name
email: email
groups: custom-group-claim
maxProperties: 3
minProperties: 0
title: PortalClaimMappings
CreateIdentityProvider:
x-speakeasy-entity: IdentityProvider
description: The identity provider that contains configuration data for creating an authentication integration.
type: object
properties:
type:
$ref: '#/components/schemas/IdentityProviderType'
enabled:
$ref: '#/components/schemas/IdentityProviderEnabled'
login_path:
$ref: '#/components/schemas/IdentityProviderLoginPath'
config:
type: object
oneOf:
- $ref: '#/components/schemas/OIDCIdentityProviderConfig'
- $ref: '#/components/schemas/SAMLIdentityProviderConfig'
title: Identity Provider
UUID:
description: Contains a unique identifier used for this resource.
type: string
format: uuid
example: 5f9fd312-a987-4628-b4c5-bb4f4fddd5f7
readOnly: true
SAMLAuthEnabled:
description: A Konnect Identity Admin assigns teams to a developer.
type: boolean
example: false
deprecated: true
x-speakeasy-param-computed: true
ForbiddenError:
allOf:
- $ref: '#/components/schemas/BaseError'
- type: object
properties:
status:
example: 403
title:
example: Forbidden
type:
example: https://httpstatuses.com/403
instance:
example: kong:trace:1234567890
detail:
example: Forbidden
UnauthorizedError:
allOf:
- $ref: '#/components/schemas/BaseError'
- type: object
properties:
status:
example: 401
title:
example: Unauthorized
type:
example: https://httpstatuses.com/401
instance:
example: kong:trace:1234567890
detail:
example: Invalid credentials
CursorMetaPage:
type: object
properties:
first:
description: URI to the first page
type: string
format: path
last:
description: URI to the last page
type: string
format: path
next:
description: URI to the next page
type: string
format: path
nullable: true
previous:
description: URI to the previous page
type: string
format: path
nullable: true
size:
description: Requested page size
type: number
example: 10
required:
- size
- next
- previous
CreatePortalIdpTeamGroupMappingRequest:
type: object
properties:
team_id:
description: The Konnect team ID.
type: string
format: uuid
example: 6801e673-cc10-498a-94cd-4271de07a0d3
group:
description: The IdP group name.
type: string
example: API Engineers
required:
- team_id
- group
SAMLIdentityProviderMetadataURL:
description: The identity provider's metadata URL where the identity provider's metadata can be obtained.
type: string
format: uri
example: https://mocksaml.com/api/saml/metadata
title: SAML Identity Provider Metadata URL
CursorMeta:
description: Pagination metadata.
type: object
properties:
page:
$ref: '#/components/schemas/CursorMetaPage'
required:
- page
OIDCIdentityProviderClientSecret:
description: The Client Secret assigned to your application by the identity provider.
type: string
example: YOUR_CLIENT_SECRET
title: OIDC Identity Provider Login Client Secret Property
writeOnly: true
x-speakeasy-param-sensitive: true
x-speakeasy-terraform-plan-only: true
PortalAuthenticationSettingsResponse:
x-speakeasy-entity: PortalAuth
description: The developer authentication settings for a portal.
type: object
properties:
basic_auth_enabled:
description: The portal has basic auth enabled or disabled.
type: boolean
example: true
oidc_auth_enabled:
$ref: '#/components/schemas/OIDCAuthEnabled'
saml_auth_enabled:
$ref: '#/components/schemas/SAMLAuthEnabled'
oidc_team_mapping_enabled:
$ref: '#/components/schemas/OIDCIdpMappingEnabled'
idp_mapping_enabled:
$ref: '#/components/schemas/IDPMappingEnabled'
konnect_mapping_enabled:
description: A Konnect Identity Admin assigns teams to a developer.
type: boolean
example: false
oidc_config:
description: Configuration properties for an OpenID Connect Identity Provider.
type: object
example:
issuer: https://identity.example.com/v2
client_id: x7id0o42lklas0blidl2
scopes:
- email
- openid
- profile
claim_mappings:
name: name
email: email
groups: custom-group-claim
deprecated: true
properties:
issuer:
type: string
example: https://identity.example.com/v2
client_id:
type: string
example: x7id0o42lklas0blidl2
scopes:
type: array
items:
type: string
default: openid
example:
- email
- openid
- profile
default:
- email
- openid
- profile
claim_mappings:
$ref: '#/components/schemas/PortalClaimMappings'
readOnly: true
required:
- issuer
- client_id
title: PortalOIDCConfig
example:
basic_auth_enabled: true
oidc_auth_enabled: true
oidc_team_mapping_enabled: true
konnect_mapping_enabled: false
oidc_config:
issuer: https://identity.example.com/v2
client_id: x7id0o42lklas0blidl2
scopes:
- email
- openid
- profile
claim_mappings:
name: name
email: email
groups: custom-group-claim
required:
- basic_auth_enabled
- konnect_mapping_enabled
- oidc_auth_enabled
- oidc_team_mapping_enabled
title: PortalAuthenticationSettingsResponse
x-speakeasy-transform-from-api:
jq: ". + {\n oidc_issuer: .oidc_config.issuer,\n oidc_client_id: .oidc_config.client_id,\n oidc_claim_mappings: .oidc_config.claim_mappings,\n oidc_scopes: .oidc_config.scopes\n}\n| del(.oidc_config)\n"
StringFieldEqualsFilter:
description: Filters on the given string field value by exact match.
properties:
eq:
type: string
title: StringFieldEqualsFilter
PaginatedMeta:
description: returns the pagination information
type: object
properties:
page:
$ref: '#/components/schemas/PageMeta'
required:
- page
title: PaginatedMeta
x-speakeasy-terraform-ignore: true
PortalAuthenticationSettingsUpdateRequest:
x-speakeasy-entity: PortalAuth
description: Properties to update a portal's developer auth settings.
type: object
properties:
basic_auth_enabled:
description: The organization has basic auth enabled.
type: boolean
example: true
x-speakeasy-param-computed: true
oidc_auth_enabled:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: boolean
example: false
deprecated: true
x-speakeasy-param-computed: true
saml_auth_enabled:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: boolean
example: false
deprecated: true
x-speakeasy-param-computed: true
oidc_team_mapping_enabled:
$ref: '#/components/schemas/OIDCIdpMappingEnabled'
konnect_mapping_enabled:
description: Whether a Konnect Identity Admin assigns teams to a developer.
type: boolean
example: false
x-speakeasy-param-computed: true
idp_mapping_enabled:
$ref: '#/components/schemas/IDPMappingEnabled'
oidc_issuer:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: string
deprecated: true
oidc_client_id:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: string
deprecated: true
oidc_client_secret:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: string
deprecated: true
oidc_scopes:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: array
items:
type: string
default: openid
default:
- email
- openid
- profile
deprecated: true
oidc_claim_mappings:
description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead.
type: object
example:
name: name
email: email
groups: custom-group-claim
deprecated: true
maxProperties: 3
minProperties: 0
properties:
name:
type: string
example: name
default: name
email:
type: string
example: email
default: email
groups:
type: string
example: custom-group-claim
default: groups
title: PortalClaimMappings
example:
basic_auth_enabled: true
oidc_auth_enabled: true
oidc_team_mapping_enabled: true
konnect_mapping_enabled: false
oidc_issuer: https://identity.example.com/v2
oidc_client_id: x7id0o42lklas0blidl2
oidc_scopes:
- email
- openid
- profile
oidc_claim_mappings:
name: name
email: email
groups: custom-group-claim
title: PortalAuthenticationSettingsUpdateRequest
OIDCIdpMappingEnabled:
description: IdP groups determine the Portal Teams a developer has. Replaced by idp_mapping_enabled.
type: boolean
example: true
deprecated: true
x-speakeasy-param-computed: true
CreatedAt:
description: An ISO-8601 timestamp representation of entity creation date.
type: string
format: date-time
example: '2022-11-04T20:10:06.927Z'
readOnly: true
x-speakeasy-param-suppress-computed-diff: true
BaseError:
description: standard error
type: object
properties:
status:
description: 'The HTTP status code of the error. Useful when passing the response
body to child properties in a frontend UI. Must be returned as an integer.
'
type: integer
readOnly: true
title:
description: 'A short, human-readable summary of the problem. It should not
change between occurences of a problem, except for localization.
Should be provided as "Sentence case" for direct use in the UI.
'
type: string
readOnly: true
type:
description: The error type.
type: string
readOnly: true
instance:
description: 'Used to return the correlation ID back to the user, in the format
kong:trace:. This helps us find the relevant logs
when a customer reports an issue.
'
type: string
readOnly: true
detail:
description: 'A human readable explanation specific to this occurence of the problem.
This field may contain request/entity data to help the user understand
what went wrong. Enclose variable values in square brackets. Should be
provided as "Sentence case" for direct use in the UI.
'
type: string
readOnly: true
required:
- status
- title
- instance
- detail
title: Error
InvalidParameterDependentItem:
type: object
properties:
field:
type: string
example: name
readOnly: true
rule:
description: invalid parameters rules
type: string
enum:
- dependent_fields
nullable: true
readOnly: true
reason:
type: string
example: is a required field
readOnly: true
dependents:
type: array
items: {}
nullable: true
readOnly: true
uniqueItems: true
source:
type: string
example: body
additionalProperties: false
required:
- field
- rule
- reason
- dependents
InvalidRules:
description: invalid parameters rules
type: string
enum:
- required
- is_array
- is_base64
- is_boolean
- is_date_time
- is_integer
- is_null
- is_number
- is_object
- is_string
- is_uuid
- is_fqdn
- is_arn
- unknown_property
- missing_reference
- is_label
- matches_regex
- invalid
- is_supported_network_availability_zone_list
- is_supported_network_cidr_block
- is_supported_provider_region
- type
nullable: true
readOnly: true
x-speakeasy-unknown-values: allow
InvalidParameters:
description: invalid parameters
type: array
items:
oneOf:
- $ref: '#/components/schemas/InvalidParameterStandard'
- $ref: '#/components/schemas/InvalidParameterMinimumLength'
- $ref: '#/components/schemas/InvalidParameterMaximumLength'
- $ref: '#/components/schemas/InvalidParameterChoiceItem'
- $ref: '#/components/schemas/InvalidParameterDependentItem'
minItems: 1
nullable: false
uniqueItems: true
BadRequestError:
allOf:
- $ref: '#/components/schemas/BaseError'
- type: object
required:
- invalid_parameters
properties:
invalid_parameters:
$ref: '#/components/schemas/InvalidParameters'
IdentityProviderEnabled:
description: 'Indicates whether the identity provider is enabled.
Only one identity provider can be active at a time, such as SAML or OIDC.
'
type: boolean
example: true
default: false
title: Identity Provider Enabled Property
IdentityProviderType:
description: Specifies the type of identity provider.
type: string
example: oidc
enum:
- oidc
- saml
x-speakeasy-unknown-values: allow
IDPMappingEnabled:
description: Whether IdP groups determine the Konnect Portal teams a developer has.
type: boolean
example: true
x-speakeasy-param-computed: true
InvalidParameterStandard:
type: object
properties:
field:
type: string
example: name
readOnly: true
rule:
$ref: '#/components/schemas/InvalidRules'
source:
type: string
example: body
reason:
type: string
example: is a required field
readOnly: true
additionalProperties: false
required:
- field
- reason
OIDCAuthEnabled:
description: The portal has OIDC enabled or disabled.
type: boolean
example: false
deprecated: true
x-speakeasy-param-computed: true
SAMLIdentityProviderConfig:
description: The identity provider that contains configuration data for the SAML authentication integration.
type: object
properties:
idp_metadata_url:
$ref: '#/components/schemas/SAMLIdentityProviderMetadataURL'
idp_metadata_xml:
$ref: '#/components/schemas/SAMLIdentityProviderMetadata'
sp_metadata_url:
type: string
format: path
example: /api/v2/developer/authenticate/saml/metadata
readOnly: true
sp_entity_id:
description: The entity ID of the service provider (SP).
type: string
example: https://cloud.konghq.com/sp/00000000-0000-0000-0000-000000000000
readOnly: true
login_url:
description: The URL to redirect users to for initiating login with the identity provider.
type: string
example: https://cloud.konghq.com/login/the-saml-konnect-org
readOnly: true
callback_url:
description: The path URL where the SAML identity provider sends authentication responses after successful login attempts.
type: string
format: path
example: /api/v2/developer/authenticate/saml/acs
readOnly: true
additionalProperties: false
title: SAML Identity Provider Config
OIDCIdentityProviderConfig:
description: The identity provider that contains configuration data for the OIDC authentication integration.
type: object
properties:
issuer_url:
$ref: '#/components/schemas/OIDCIdentityProviderIssuer'
client_id:
$ref: '#/components/schemas/OIDCIdentityProviderClientId'
client_secret:
$ref: '#/components/schemas/OIDCIdentityProviderClientSecret'
scopes:
$ref: '#/components/schemas/OIDCIdentityProviderScopes'
claim_mappings:
$ref: '#/components/schemas/OIDCIdentityProviderClaimMappings'
additionalProperties: false
required:
- issuer_url
- client_id
title: OIDC Identity Provider Config
OIDCIdentityProviderClientId:
description: The client ID assigned to your application by the identity provider.
type: string
example: YOUR_CLIENT_ID
title: OIDC Identity Provider Login Client Id Property
PortalIdpTeamGroupMappingCollectionResponse:
type: object
properties:
meta:
$ref: '#/components/schemas/CursorMeta'
data:
type: array
items:
$ref: '#/components/schemas/PortalIdpTeamGroupMapping'
required:
- meta
- data
OIDCIdentityProviderIssuer:
description: The issuer URI of the identity provider. This is the URL where the provider's metadata can be obtained.
type: string
format: uri
example: https://konghq.okta.com/oauth2/default
title: OIDC Identity Provider Issuer Property
NotFoundError:
allOf:
- $ref: '#/components/schemas/BaseError'
- type: object
properties:
status:
example: 404
title:
example: Not Found
type:
example: https://httpstatuses.com/404
instance:
example: kong:trace:1234567890
detail:
example: Not found
PageMeta:
description: Contains pagination query parameters and the total number of objects returned.
type: object
properties:
number:
type: number
example: 1
x-speakeasy-terraform-ignore: true
size:
type: number
example: 10
x-speakeasy-terraform-ignore: true
total:
type: number
example: 100
x-speakeasy-terraform-ignore: true
required:
- number
- size
- total
requestBodies:
UpdatePortalAuthenticationSettings:
description: Update a portal's developer authentication settings.
content:
application/json:
schema:
$ref: '#/components/schemas/PortalAuthenticationSettingsUpdateRequest'
CreatePortalIdpTeamGroupMapping:
description: Create a team group mapping for an identity provider.
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CreatePortalIdpTeamGroupMappingRequest'
UpdatePortalTeamGroupMappings:
content:
application/json:
schema:
$ref: '#/components/schemas/PortalTeamGroupMappingsUpdateRequest'
CreateIdentityProviderRequest:
description: 'An object representing the configuration for creating a new identity provider. This configuration may pertain to either an OIDC or a SAML identity provider.
'
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CreateIdentityProvider'
UpdateIdentityProviderRequest:
description: 'An object representing the configuration for updating an identity provider. This configuration may pertain to either an OIDC or a SAML identity provider.
'
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateIdentityProvider'
parameters:
IdentityProviderId:
schema:
type: string
format: uuid
example: d32d905a-ed33-46a3-a093-d8f536af9a8a
name: id
in: path
required: true
description: ID of the identity provider.
TeamGroupMappingId:
name: mappingId
in: path
required: true
description: ID of the team group mapping.
schema:
type: string
format: uuid
PageAfter:
name: page[after]
description: Request the next page of data, starting with the item after this parameter.
required: false
in: query
allowEmptyValue: true
schema:
type: string
example: ewogICJpZCI6ICJoZWxsbyB3b3JsZCIKfQ
PageBefore:
name: page[before]
description: Request the next page of data, starting with the item before this parameter.
required: false
in: query
allowEmptyValue: true
schema:
type: string
example: ewogICJpZCI6ICJoZWxsbyB3b3JsZCIKfQ
PageSize:
name: page[size]
description: The maximum number of items to include per page. The last page of a collection may include fewer items.
required: false
in: query
allowEmptyValue: true
schema:
type: integer
example: 10
x-speakeasy-terraform-ignore: true
PageNumber:
name: page[number]
description: Determines which page of the entities to retrieve.
required: false
in: query
allowEmptyValue: true
schema:
type: integer
example: 1
x-speakeasy-terraform-ignore: true
PortalId:
schema:
type: string
format: uuid
example: f32d905a-ed33-46a3-a093-d8f536af9a8a
name: portalId
in: path
required: true
description: ID of the portal.
securitySchemes:
adminToken:
in: header
name: Kong-Admin-Token
type: apiKey
externalDocs:
description: Documentation for Kong Gateway and its APIs
url: https://developer.konghq.com