openapi: 3.1.0 info: contact: email: support@konghq.com name: Kong Inc url: https://konghq.com description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API. You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com). Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.' license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html title: Kong Enterprise Admin ACLs Portal Auth Settings API version: 3.14.0 servers: - description: Default Admin API URL url: '{protocol}://{hostname}:{port}{path}' variables: hostname: default: localhost description: Hostname for Kong's Admin API path: default: / description: Base path for Kong's Admin API port: default: '8001' description: Port for Kong's Admin API protocol: default: http description: Protocol for requests to Kong's Admin API enum: - http - https security: - adminToken: [] tags: - name: Portal Auth Settings description: APIs related to configuration of Konnect Developer Portal auth settings. paths: /v3/portals/{portalId}/authentication-settings: parameters: - $ref: '#/components/parameters/PortalId' get: x-speakeasy-entity-operation: terraform-resource: PortalAuth#read terraform-datasource: null operationId: get-portal-authentication-settings summary: Get Auth Settings description: Returns the developer authentication configuration for a portal, which determines how developers can log in and how they are assigned to teams. responses: '200': $ref: '#/components/responses/PortalAuthenticationSettings' '401': $ref: '#/components/responses/Unauthorized' tags: - Portal Auth Settings patch: x-speakeasy-entity-operation: terraform-resource: PortalAuth#create,update terraform-datasource: null operationId: update-portal-authentication-settings summary: Update Auth Settings description: Updates the developer authentication configuration for a portal. Developers can be allowed to login using basic auth (email & password) or use Single-Sign-On through an Identity Provider. Developers can be automatically assigned to teams by mapping claims from their IdP account. requestBody: $ref: '#/components/requestBodies/UpdatePortalAuthenticationSettings' responses: '200': $ref: '#/components/responses/PortalAuthenticationSettings' '400': description: Bad Request content: application/problem+json: schema: $ref: '#/components/schemas/BadRequestError' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' tags: - Portal Auth Settings /v3/portals/{portalId}/identity-provider/team-group-mappings: parameters: - $ref: '#/components/parameters/PortalId' get: operationId: list-portal-team-group-mappings summary: List Team Group Mappings description: '**Pre-release Endpoint** This endpoint is currently in beta and is subject to change. Lists mappings between Konnect portal teams and Identity Provider (IdP) groups. Returns a 400 error if an IdP has not yet been configured.' parameters: - $ref: '#/components/parameters/PageSize' - $ref: '#/components/parameters/PageNumber' responses: '200': $ref: '#/components/responses/PortalTeamGroupMappingCollection' '400': description: Bad Request content: application/problem+json: schema: $ref: '#/components/schemas/BadRequestError' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' tags: - Portal Auth Settings patch: operationId: update-portal-team-group-mappings summary: Update Team Group Mappings description: '**Pre-release Endpoint** This endpoint is currently in beta and is subject to change. Allows partial updates to the mappings between Konnect portal teams and Identity Provider (IdP) groups. The request body must be keyed on team ID. For a given team ID, the given group list is a complete replacement. To remove all mappings for a given team, provide an empty group list. Returns a 400 error if an IdP has not yet been configured, or if a team ID in the request body is not found or is not a UUID.' requestBody: $ref: '#/components/requestBodies/UpdatePortalTeamGroupMappings' responses: '200': $ref: '#/components/responses/PortalTeamGroupMappingCollection' '400': description: Bad Request content: application/problem+json: schema: $ref: '#/components/schemas/BadRequestError' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' tags: - Portal Auth Settings /v3/portals/{portalId}/identity-providers: parameters: - $ref: '#/components/parameters/PortalId' get: operationId: get-portal-identity-providers summary: List Identity Providers description: 'Retrieves the identity providers available within the portal. This operation provides information about various identity providers for SAML or OIDC authentication integrations. ' parameters: - name: filter in: query description: Filter identity providers returned in the response. required: false schema: type: object properties: type: $ref: '#/components/schemas/StringFieldEqualsFilter' style: deepObject responses: '200': $ref: '#/components/responses/IdentityProviders' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' tags: - Portal Auth Settings post: operationId: create-portal-identity-provider summary: Create Identity Provider description: 'Creates a new identity provider. This operation allows the creation of a new identity provider for authentication purposes. ' requestBody: $ref: '#/components/requestBodies/CreateIdentityProviderRequest' responses: '201': $ref: '#/components/responses/IdentityProvider' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '409': $ref: '#/components/responses/Conflict' tags: - Portal Auth Settings /v3/portals/{portalId}/identity-providers/{id}: parameters: - $ref: '#/components/parameters/PortalId' - $ref: '#/components/parameters/IdentityProviderId' get: operationId: get-portal-identity-provider summary: Get Identity Provider description: 'Retrieves the configuration of a single identity provider. This operation returns information about a specific identity provider''s settings and authentication integration details. ' responses: '200': $ref: '#/components/responses/IdentityProvider' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' tags: - Portal Auth Settings patch: operationId: update-portal-identity-provider summary: Update Identity Provider description: 'Updates the configuration of an existing identity provider. This operation allows modifications to be made to an existing identity provider''s configuration. ' requestBody: $ref: '#/components/requestBodies/UpdateIdentityProviderRequest' responses: '200': $ref: '#/components/responses/IdentityProvider' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '409': $ref: '#/components/responses/Conflict' tags: - Portal Auth Settings delete: operationId: delete-portal-identity-provider summary: Delete Identity Provider description: 'Deletes an existing identity provider configuration. This operation removes a specific identity provider from the portal. ' responses: '204': description: No Content '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' tags: - Portal Auth Settings /v3/portals/{portalId}/identity-providers/{id}/team-group-mappings: parameters: - $ref: '#/components/parameters/PortalId' - $ref: '#/components/parameters/IdentityProviderId' get: operationId: list-portal-idp-team-group-mappings summary: List Team Group Mappings description: 'Returns a paginated list of team group mappings for the specified identity provider. ' parameters: - $ref: '#/components/parameters/PageSize' - $ref: '#/components/parameters/PageAfter' - $ref: '#/components/parameters/PageBefore' - name: filter in: query description: Filter mappings by team ID or group name. required: false schema: type: object properties: team_id: $ref: '#/components/schemas/StringFieldEqualsFilter' group: $ref: '#/components/schemas/StringFieldEqualsFilter' style: deepObject responses: '200': $ref: '#/components/responses/PortalIdpTeamGroupMappingCollection' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' tags: - Portal Auth Settings post: operationId: create-portal-idp-team-group-mapping summary: Create Team Group Mapping description: 'Creates a new team group mapping for the specified identity provider. ' requestBody: $ref: '#/components/requestBodies/CreatePortalIdpTeamGroupMapping' responses: '201': $ref: '#/components/responses/PortalIdpTeamGroupMapping' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '409': $ref: '#/components/responses/Conflict' tags: - Portal Auth Settings /v3/portals/{portalId}/identity-providers/{id}/team-group-mappings/{mappingId}: parameters: - $ref: '#/components/parameters/PortalId' - $ref: '#/components/parameters/IdentityProviderId' - $ref: '#/components/parameters/TeamGroupMappingId' get: operationId: get-portal-idp-team-group-mapping summary: Get Team Group Mapping description: Returns the team group mapping for the specified ID. responses: '200': $ref: '#/components/responses/PortalIdpTeamGroupMapping' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' tags: - Portal Auth Settings delete: operationId: delete-portal-idp-team-group-mapping summary: Delete Team Group Mapping description: 'Deletes a team group mapping by ID. Returns 204 if the mapping was deleted, or 404 if the mapping was not found. ' responses: '204': description: No Content '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' tags: - Portal Auth Settings components: responses: PortalTeamGroupMappingCollection: description: A paginated collection of mappings grouped by team ID. content: application/json: schema: $ref: '#/components/schemas/PortalTeamGroupMappingResponse' PortalIdpTeamGroupMapping: description: A team group mapping for an identity provider. content: application/json: schema: $ref: '#/components/schemas/PortalIdpTeamGroupMapping' NotFound: description: Not Found content: application/problem+json: schema: $ref: '#/components/schemas/NotFoundError' BadRequest: description: Bad Request content: application/problem+json: schema: $ref: '#/components/schemas/BadRequestError' IdentityProviders: description: 'A collection of identity providers. This response contains a collection of identity providers, which may include both OIDC and SAML identity providers. ' content: application/json: schema: type: array items: $ref: '#/components/schemas/IdentityProvider' title: Identity Provider Collection Response Conflict: description: Conflict content: application/problem+json: schema: $ref: '#/components/schemas/ConflictError' PortalAuthenticationSettings: description: Details about a portal's authentication settings. content: application/json: schema: $ref: '#/components/schemas/PortalAuthenticationSettingsResponse' Unauthorized: description: Unauthorized content: application/problem+json: schema: description: The error response object. type: object properties: status: description: The HTTP status code. type: integer example: 403 title: description: The Error Response. type: string example: Unauthorized instance: description: The Konnect traceback code. type: string example: konnect:trace:952172606039454040 detail: description: Details about the error response. type: string example: You do not have permission to perform this action $ref: '#/components/schemas/UnauthorizedError' title: Unauthorized Response PortalIdpTeamGroupMappingCollection: description: A paginated collection of team group mappings. content: application/json: schema: $ref: '#/components/schemas/PortalIdpTeamGroupMappingCollectionResponse' Forbidden: description: Forbidden content: application/problem+json: schema: $ref: '#/components/schemas/ForbiddenError' IdentityProvider: description: 'An identity provider configuration. This response represents the configuration of a specific identity provider, which can be either OIDC or SAML. ' content: application/json: schema: $ref: '#/components/schemas/IdentityProvider' schemas: IdentityProvider: x-speakeasy-entity: IdentityProvider description: The identity provider that contains configuration data for authentication integration. type: object properties: id: $ref: '#/components/schemas/UUID' type: $ref: '#/components/schemas/IdentityProviderType' enabled: $ref: '#/components/schemas/IdentityProviderEnabled' login_path: $ref: '#/components/schemas/IdentityProviderLoginPath' config: type: object oneOf: - $ref: '#/components/schemas/OIDCIdentityProviderConfig' - $ref: '#/components/schemas/SAMLIdentityProviderConfig' created_at: $ref: '#/components/schemas/CreatedAt' updated_at: $ref: '#/components/schemas/UpdatedAt' title: Identity Provider InvalidParameterMinimumLength: type: object properties: field: type: string example: name readOnly: true rule: description: invalid parameters rules type: string enum: - min_length - min_digits - min_lowercase - min_uppercase - min_symbols - min_items - min nullable: false readOnly: true x-speakeasy-unknown-values: allow minimum: type: integer example: 8 source: type: string example: body reason: type: string example: must have at least 8 characters readOnly: true additionalProperties: false required: - field - reason - rule - minimum SAMLIdentityProviderMetadata: description: 'The identity provider''s SAML metadata. If the identity provider supports a metadata URL, you can use the `idp_metadata_url` field instead. ' type: string example: "\n\n \n\n" title: SAML Identity Provider Metadata PortalTeamGroupMappingResponse: description: A paginated list of portal team group mappings. type: object properties: meta: $ref: '#/components/schemas/PaginatedMeta' data: type: array items: $ref: '#/components/schemas/PortalTeamGroupMapping' example: meta: page: number: 1 size: 10 total: 2 data: - team_id: 6801e673-cc10-498a-94cd-4271de07a0d3 groups: - Tech Leads - API Engineers - team_id: 7301e673-cc10-498a-94cd-4271de07a0d3 groups: - Managers - Directors title: PortalTeamGroupMappingResponse PortalIdpTeamGroupMapping: type: object properties: id: description: The mapping ID. type: string format: uuid example: a1b2c3d4-e5f6-4a8b-9c0d-1e2f3a4b5c6d readOnly: true team_id: description: The Konnect team ID. type: string format: uuid example: 6801e673-cc10-498a-94cd-4271de07a0d3 group: description: The IdP group name. type: string example: API Engineers created_at: description: Creation timestamp. type: string format: date-time example: '2024-01-15T10:30:00Z' readOnly: true updated_at: description: Last update timestamp. type: string format: date-time example: '2024-01-15T10:30:00Z' readOnly: true required: - id - team_id - group - created_at - updated_at UpdatedAt: description: An ISO-8601 timestamp representation of entity update date. type: string format: date-time example: '2022-11-04T20:10:06.927Z' readOnly: true x-speakeasy-param-suppress-computed-diff: true InvalidParameterChoiceItem: type: object properties: field: type: string example: name readOnly: true rule: description: invalid parameters rules type: string enum: - enum nullable: false readOnly: true reason: type: string example: is a required field readOnly: true choices: type: array items: {} minItems: 1 nullable: false readOnly: true uniqueItems: true source: type: string example: body additionalProperties: false required: - field - reason - rule - choices ConflictError: allOf: - $ref: '#/components/schemas/BaseError' - type: object properties: status: example: 409 title: example: Conflict type: example: https://httpstatuses.com/409 instance: example: kong:trace:1234567890 detail: example: Conflict InvalidParameterMaximumLength: type: object properties: field: type: string example: name readOnly: true rule: description: invalid parameters rules type: string enum: - max_length - max_items - max nullable: false readOnly: true x-speakeasy-unknown-values: allow maximum: type: integer example: 8 source: type: string example: body reason: type: string example: must not have more than 8 characters readOnly: true additionalProperties: false required: - field - reason - rule - maximum OIDCIdentityProviderClaimMappings: description: "Defines the mappings between OpenID Connect (OIDC) claims and local claims used by your application for \nauthentication.\n" type: object properties: name: description: The claim mapping for the user's name. type: string example: name default: name email: description: The claim mapping for the user's email address. type: string example: email default: email groups: description: The claim mapping for the user's group membership information. type: string example: groups default: groups title: OIDC Claim Mappings OIDCIdentityProviderScopes: description: The scopes requested by your application when authenticating with the identity provider. type: array items: type: string default: - email - openid - profile title: OIDC Identity Provider Scopes Property PortalTeamGroupMappingsUpdateRequest: description: A set of mappings to update from a team to their groups. type: object properties: data: description: The IdP groups to map to the given team. type: array items: type: object properties: team_id: type: string format: uuid groups: type: array items: type: string example: data: - team_id: af91db4c-6e51-403e-a2bf-33d27ae50c0a groups: - Service Developer title: PortalTeamGroupMappingsUpdateRequest PortalTeamGroupMapping: description: A map of portal teams to Identity Provider groups. type: object properties: team_id: description: The Konnect team ID. type: string format: uuid example: 6801e673-cc10-498a-94cd-4271de07a0d3 groups: description: The IdP groups that are mapped to the specified team. type: array items: type: string example: API Engineers uniqueItems: true example: team_id: 6801e673-cc10-498a-94cd-4271de07a0d3 groups: - Tech Leads - API Engineers title: PortalTeamGroupMapping IdentityProviderLoginPath: description: The path used for initiating login requests with the identity provider. type: string example: myapp title: Identity Provider Login Path Property UpdateIdentityProvider: x-speakeasy-entity: IdentityProvider description: The identity provider that contains configuration data for updating an authentication integration. type: object properties: enabled: $ref: '#/components/schemas/IdentityProviderEnabled' login_path: $ref: '#/components/schemas/IdentityProviderLoginPath' config: type: object oneOf: - $ref: '#/components/schemas/OIDCIdentityProviderConfig' - $ref: '#/components/schemas/SAMLIdentityProviderConfig' title: Identity Provider PortalClaimMappings: description: Mappings from a portal developer atribute to an Identity Provider claim. type: object properties: name: type: string example: name default: name email: type: string example: email default: email groups: type: string example: custom-group-claim default: groups example: name: name email: email groups: custom-group-claim maxProperties: 3 minProperties: 0 title: PortalClaimMappings CreateIdentityProvider: x-speakeasy-entity: IdentityProvider description: The identity provider that contains configuration data for creating an authentication integration. type: object properties: type: $ref: '#/components/schemas/IdentityProviderType' enabled: $ref: '#/components/schemas/IdentityProviderEnabled' login_path: $ref: '#/components/schemas/IdentityProviderLoginPath' config: type: object oneOf: - $ref: '#/components/schemas/OIDCIdentityProviderConfig' - $ref: '#/components/schemas/SAMLIdentityProviderConfig' title: Identity Provider UUID: description: Contains a unique identifier used for this resource. type: string format: uuid example: 5f9fd312-a987-4628-b4c5-bb4f4fddd5f7 readOnly: true SAMLAuthEnabled: description: A Konnect Identity Admin assigns teams to a developer. type: boolean example: false deprecated: true x-speakeasy-param-computed: true ForbiddenError: allOf: - $ref: '#/components/schemas/BaseError' - type: object properties: status: example: 403 title: example: Forbidden type: example: https://httpstatuses.com/403 instance: example: kong:trace:1234567890 detail: example: Forbidden UnauthorizedError: allOf: - $ref: '#/components/schemas/BaseError' - type: object properties: status: example: 401 title: example: Unauthorized type: example: https://httpstatuses.com/401 instance: example: kong:trace:1234567890 detail: example: Invalid credentials CursorMetaPage: type: object properties: first: description: URI to the first page type: string format: path last: description: URI to the last page type: string format: path next: description: URI to the next page type: string format: path nullable: true previous: description: URI to the previous page type: string format: path nullable: true size: description: Requested page size type: number example: 10 required: - size - next - previous CreatePortalIdpTeamGroupMappingRequest: type: object properties: team_id: description: The Konnect team ID. type: string format: uuid example: 6801e673-cc10-498a-94cd-4271de07a0d3 group: description: The IdP group name. type: string example: API Engineers required: - team_id - group SAMLIdentityProviderMetadataURL: description: The identity provider's metadata URL where the identity provider's metadata can be obtained. type: string format: uri example: https://mocksaml.com/api/saml/metadata title: SAML Identity Provider Metadata URL CursorMeta: description: Pagination metadata. type: object properties: page: $ref: '#/components/schemas/CursorMetaPage' required: - page OIDCIdentityProviderClientSecret: description: The Client Secret assigned to your application by the identity provider. type: string example: YOUR_CLIENT_SECRET title: OIDC Identity Provider Login Client Secret Property writeOnly: true x-speakeasy-param-sensitive: true x-speakeasy-terraform-plan-only: true PortalAuthenticationSettingsResponse: x-speakeasy-entity: PortalAuth description: The developer authentication settings for a portal. type: object properties: basic_auth_enabled: description: The portal has basic auth enabled or disabled. type: boolean example: true oidc_auth_enabled: $ref: '#/components/schemas/OIDCAuthEnabled' saml_auth_enabled: $ref: '#/components/schemas/SAMLAuthEnabled' oidc_team_mapping_enabled: $ref: '#/components/schemas/OIDCIdpMappingEnabled' idp_mapping_enabled: $ref: '#/components/schemas/IDPMappingEnabled' konnect_mapping_enabled: description: A Konnect Identity Admin assigns teams to a developer. type: boolean example: false oidc_config: description: Configuration properties for an OpenID Connect Identity Provider. type: object example: issuer: https://identity.example.com/v2 client_id: x7id0o42lklas0blidl2 scopes: - email - openid - profile claim_mappings: name: name email: email groups: custom-group-claim deprecated: true properties: issuer: type: string example: https://identity.example.com/v2 client_id: type: string example: x7id0o42lklas0blidl2 scopes: type: array items: type: string default: openid example: - email - openid - profile default: - email - openid - profile claim_mappings: $ref: '#/components/schemas/PortalClaimMappings' readOnly: true required: - issuer - client_id title: PortalOIDCConfig example: basic_auth_enabled: true oidc_auth_enabled: true oidc_team_mapping_enabled: true konnect_mapping_enabled: false oidc_config: issuer: https://identity.example.com/v2 client_id: x7id0o42lklas0blidl2 scopes: - email - openid - profile claim_mappings: name: name email: email groups: custom-group-claim required: - basic_auth_enabled - konnect_mapping_enabled - oidc_auth_enabled - oidc_team_mapping_enabled title: PortalAuthenticationSettingsResponse x-speakeasy-transform-from-api: jq: ". + {\n oidc_issuer: .oidc_config.issuer,\n oidc_client_id: .oidc_config.client_id,\n oidc_claim_mappings: .oidc_config.claim_mappings,\n oidc_scopes: .oidc_config.scopes\n}\n| del(.oidc_config)\n" StringFieldEqualsFilter: description: Filters on the given string field value by exact match. properties: eq: type: string title: StringFieldEqualsFilter PaginatedMeta: description: returns the pagination information type: object properties: page: $ref: '#/components/schemas/PageMeta' required: - page title: PaginatedMeta x-speakeasy-terraform-ignore: true PortalAuthenticationSettingsUpdateRequest: x-speakeasy-entity: PortalAuth description: Properties to update a portal's developer auth settings. type: object properties: basic_auth_enabled: description: The organization has basic auth enabled. type: boolean example: true x-speakeasy-param-computed: true oidc_auth_enabled: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: boolean example: false deprecated: true x-speakeasy-param-computed: true saml_auth_enabled: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: boolean example: false deprecated: true x-speakeasy-param-computed: true oidc_team_mapping_enabled: $ref: '#/components/schemas/OIDCIdpMappingEnabled' konnect_mapping_enabled: description: Whether a Konnect Identity Admin assigns teams to a developer. type: boolean example: false x-speakeasy-param-computed: true idp_mapping_enabled: $ref: '#/components/schemas/IDPMappingEnabled' oidc_issuer: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: string deprecated: true oidc_client_id: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: string deprecated: true oidc_client_secret: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: string deprecated: true oidc_scopes: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: array items: type: string default: openid default: - email - openid - profile deprecated: true oidc_claim_mappings: description: Deprecated. Use the [Identity Provider API](https://developer.konghq.com/api/konnect/portal-management/v3/#/operations/update-portal-identity-provider) instead. type: object example: name: name email: email groups: custom-group-claim deprecated: true maxProperties: 3 minProperties: 0 properties: name: type: string example: name default: name email: type: string example: email default: email groups: type: string example: custom-group-claim default: groups title: PortalClaimMappings example: basic_auth_enabled: true oidc_auth_enabled: true oidc_team_mapping_enabled: true konnect_mapping_enabled: false oidc_issuer: https://identity.example.com/v2 oidc_client_id: x7id0o42lklas0blidl2 oidc_scopes: - email - openid - profile oidc_claim_mappings: name: name email: email groups: custom-group-claim title: PortalAuthenticationSettingsUpdateRequest OIDCIdpMappingEnabled: description: IdP groups determine the Portal Teams a developer has. Replaced by idp_mapping_enabled. type: boolean example: true deprecated: true x-speakeasy-param-computed: true CreatedAt: description: An ISO-8601 timestamp representation of entity creation date. type: string format: date-time example: '2022-11-04T20:10:06.927Z' readOnly: true x-speakeasy-param-suppress-computed-diff: true BaseError: description: standard error type: object properties: status: description: 'The HTTP status code of the error. Useful when passing the response body to child properties in a frontend UI. Must be returned as an integer. ' type: integer readOnly: true title: description: 'A short, human-readable summary of the problem. It should not change between occurences of a problem, except for localization. Should be provided as "Sentence case" for direct use in the UI. ' type: string readOnly: true type: description: The error type. type: string readOnly: true instance: description: 'Used to return the correlation ID back to the user, in the format kong:trace:. This helps us find the relevant logs when a customer reports an issue. ' type: string readOnly: true detail: description: 'A human readable explanation specific to this occurence of the problem. This field may contain request/entity data to help the user understand what went wrong. Enclose variable values in square brackets. Should be provided as "Sentence case" for direct use in the UI. ' type: string readOnly: true required: - status - title - instance - detail title: Error InvalidParameterDependentItem: type: object properties: field: type: string example: name readOnly: true rule: description: invalid parameters rules type: string enum: - dependent_fields nullable: true readOnly: true reason: type: string example: is a required field readOnly: true dependents: type: array items: {} nullable: true readOnly: true uniqueItems: true source: type: string example: body additionalProperties: false required: - field - rule - reason - dependents InvalidRules: description: invalid parameters rules type: string enum: - required - is_array - is_base64 - is_boolean - is_date_time - is_integer - is_null - is_number - is_object - is_string - is_uuid - is_fqdn - is_arn - unknown_property - missing_reference - is_label - matches_regex - invalid - is_supported_network_availability_zone_list - is_supported_network_cidr_block - is_supported_provider_region - type nullable: true readOnly: true x-speakeasy-unknown-values: allow InvalidParameters: description: invalid parameters type: array items: oneOf: - $ref: '#/components/schemas/InvalidParameterStandard' - $ref: '#/components/schemas/InvalidParameterMinimumLength' - $ref: '#/components/schemas/InvalidParameterMaximumLength' - $ref: '#/components/schemas/InvalidParameterChoiceItem' - $ref: '#/components/schemas/InvalidParameterDependentItem' minItems: 1 nullable: false uniqueItems: true BadRequestError: allOf: - $ref: '#/components/schemas/BaseError' - type: object required: - invalid_parameters properties: invalid_parameters: $ref: '#/components/schemas/InvalidParameters' IdentityProviderEnabled: description: 'Indicates whether the identity provider is enabled. Only one identity provider can be active at a time, such as SAML or OIDC. ' type: boolean example: true default: false title: Identity Provider Enabled Property IdentityProviderType: description: Specifies the type of identity provider. type: string example: oidc enum: - oidc - saml x-speakeasy-unknown-values: allow IDPMappingEnabled: description: Whether IdP groups determine the Konnect Portal teams a developer has. type: boolean example: true x-speakeasy-param-computed: true InvalidParameterStandard: type: object properties: field: type: string example: name readOnly: true rule: $ref: '#/components/schemas/InvalidRules' source: type: string example: body reason: type: string example: is a required field readOnly: true additionalProperties: false required: - field - reason OIDCAuthEnabled: description: The portal has OIDC enabled or disabled. type: boolean example: false deprecated: true x-speakeasy-param-computed: true SAMLIdentityProviderConfig: description: The identity provider that contains configuration data for the SAML authentication integration. type: object properties: idp_metadata_url: $ref: '#/components/schemas/SAMLIdentityProviderMetadataURL' idp_metadata_xml: $ref: '#/components/schemas/SAMLIdentityProviderMetadata' sp_metadata_url: type: string format: path example: /api/v2/developer/authenticate/saml/metadata readOnly: true sp_entity_id: description: The entity ID of the service provider (SP). type: string example: https://cloud.konghq.com/sp/00000000-0000-0000-0000-000000000000 readOnly: true login_url: description: The URL to redirect users to for initiating login with the identity provider. type: string example: https://cloud.konghq.com/login/the-saml-konnect-org readOnly: true callback_url: description: The path URL where the SAML identity provider sends authentication responses after successful login attempts. type: string format: path example: /api/v2/developer/authenticate/saml/acs readOnly: true additionalProperties: false title: SAML Identity Provider Config OIDCIdentityProviderConfig: description: The identity provider that contains configuration data for the OIDC authentication integration. type: object properties: issuer_url: $ref: '#/components/schemas/OIDCIdentityProviderIssuer' client_id: $ref: '#/components/schemas/OIDCIdentityProviderClientId' client_secret: $ref: '#/components/schemas/OIDCIdentityProviderClientSecret' scopes: $ref: '#/components/schemas/OIDCIdentityProviderScopes' claim_mappings: $ref: '#/components/schemas/OIDCIdentityProviderClaimMappings' additionalProperties: false required: - issuer_url - client_id title: OIDC Identity Provider Config OIDCIdentityProviderClientId: description: The client ID assigned to your application by the identity provider. type: string example: YOUR_CLIENT_ID title: OIDC Identity Provider Login Client Id Property PortalIdpTeamGroupMappingCollectionResponse: type: object properties: meta: $ref: '#/components/schemas/CursorMeta' data: type: array items: $ref: '#/components/schemas/PortalIdpTeamGroupMapping' required: - meta - data OIDCIdentityProviderIssuer: description: The issuer URI of the identity provider. This is the URL where the provider's metadata can be obtained. type: string format: uri example: https://konghq.okta.com/oauth2/default title: OIDC Identity Provider Issuer Property NotFoundError: allOf: - $ref: '#/components/schemas/BaseError' - type: object properties: status: example: 404 title: example: Not Found type: example: https://httpstatuses.com/404 instance: example: kong:trace:1234567890 detail: example: Not found PageMeta: description: Contains pagination query parameters and the total number of objects returned. type: object properties: number: type: number example: 1 x-speakeasy-terraform-ignore: true size: type: number example: 10 x-speakeasy-terraform-ignore: true total: type: number example: 100 x-speakeasy-terraform-ignore: true required: - number - size - total requestBodies: UpdatePortalAuthenticationSettings: description: Update a portal's developer authentication settings. content: application/json: schema: $ref: '#/components/schemas/PortalAuthenticationSettingsUpdateRequest' CreatePortalIdpTeamGroupMapping: description: Create a team group mapping for an identity provider. required: true content: application/json: schema: $ref: '#/components/schemas/CreatePortalIdpTeamGroupMappingRequest' UpdatePortalTeamGroupMappings: content: application/json: schema: $ref: '#/components/schemas/PortalTeamGroupMappingsUpdateRequest' CreateIdentityProviderRequest: description: 'An object representing the configuration for creating a new identity provider. This configuration may pertain to either an OIDC or a SAML identity provider. ' required: true content: application/json: schema: $ref: '#/components/schemas/CreateIdentityProvider' UpdateIdentityProviderRequest: description: 'An object representing the configuration for updating an identity provider. This configuration may pertain to either an OIDC or a SAML identity provider. ' required: true content: application/json: schema: $ref: '#/components/schemas/UpdateIdentityProvider' parameters: IdentityProviderId: schema: type: string format: uuid example: d32d905a-ed33-46a3-a093-d8f536af9a8a name: id in: path required: true description: ID of the identity provider. TeamGroupMappingId: name: mappingId in: path required: true description: ID of the team group mapping. schema: type: string format: uuid PageAfter: name: page[after] description: Request the next page of data, starting with the item after this parameter. required: false in: query allowEmptyValue: true schema: type: string example: ewogICJpZCI6ICJoZWxsbyB3b3JsZCIKfQ PageBefore: name: page[before] description: Request the next page of data, starting with the item before this parameter. required: false in: query allowEmptyValue: true schema: type: string example: ewogICJpZCI6ICJoZWxsbyB3b3JsZCIKfQ PageSize: name: page[size] description: The maximum number of items to include per page. The last page of a collection may include fewer items. required: false in: query allowEmptyValue: true schema: type: integer example: 10 x-speakeasy-terraform-ignore: true PageNumber: name: page[number] description: Determines which page of the entities to retrieve. required: false in: query allowEmptyValue: true schema: type: integer example: 1 x-speakeasy-terraform-ignore: true PortalId: schema: type: string format: uuid example: f32d905a-ed33-46a3-a093-d8f536af9a8a name: portalId in: path required: true description: ID of the portal. securitySchemes: adminToken: in: header name: Kong-Admin-Token type: apiKey externalDocs: description: Documentation for Kong Gateway and its APIs url: https://developer.konghq.com