openapi: 3.0.1 info: title: m3ter Account PermissionPolicy API description: "If you are using Postman, you can:\n- Use the **Download** button above to download the m3ter Open API spec JSON file and then import this file as the **m3ter API Collection** into your Workspace. See [Importing the m3ter Open API](https://www.m3ter.com/docs/guides/m3ter-apis/getting-started-with-api-calls#importing-the-m3ter-open-api) in our main user Documentation for details.\n- Copy this link: [m3ter-Template API Collection](https://www.datocms-assets.com/78893/1672846767-m3ter-template-api-collection-postman_collection.json) and use it to import the **m3ter-Template API Collection** into your Workspace. See [Importing the m3ter Template API Collection](https://www.m3ter.com/docs/guides/m3ter-apis/getting-started-with-api-calls#importing-the-m3ter-template-api-collection) in our main user Documentation for details.\n\n---\n\n# Introduction\nThe m3ter platform supports two HTTP-based REST APIs returning JSON encoded responses:\n- The **Ingest API**, which you can use for submitting raw data measurements. *(See the [Submit Measurements](https://www.m3ter.com/docs/api#tag/Measurements/operation/SubmitMeasurements) endpoint in this API Reference.)*\n- The **Config API**, which you can use for configuration and management. *(All other endpoints in this API Reference.)* \n\n## Authentication and Authorization\nOur APIs use an industry-standard authorization protocol known as the OAuth 2.0 specification.\n\nOAuth2 supports several grant types, each designed for a specific use case. m3ter uses the following two grant types:\n - **Authorization Code**: Used for human login access via the m3ter Console.\n - **Client Credentials**: Used for machine-to-machine communication and API access.\n\nComplete the following flow for API access:\n\n1. **Create a Service User and add Permissions**: Log in to the m3ter Console, go to **Settings**, **Access** then **Service Users** tab, and create a Service User. To enable API calls, grant the user **Administrator** permissions. \n \n2. **Generate Access Keys**: In the Console, open the *Overview* page for the Service User by clicking on the name. Generate an **Access Key id** and **Api Secret**. Make sure you copy the **Api Secret** because it is only visible at the time of creation. \n\nSee [Service Authentication](https://www.m3ter.com/docs/guides/authenticating-with-the-platform/service-authentication) for detailed instructions and an example.\n\n3. **Obtain a Bearer Token using Basic Auth**: We implement the OAuth 2.0 Client Credentials Grant authentication flow for Service User Authentication. Submit a request to the m3ter OAuth Client Credentials authentication flow, using your concatenated **Access Key id** and **Api Secret** to obtain a Bearer Token for your Service User. *See examples below.* \n \n4. **Bearer Token Usage**: Use the HTTP 'Authorization' header with the bearer token to authorise all subsequent API requests. \n\n> Warning: The Bearer Token is valid for 18,000 seconds or 5 hours. When the token has expired, you must obtain a new one.\n\nBelow are two examples for obtaining a Bearer Token using Basic Auth: the first in cURL and the second as a Python script. \n\n### cURL Example\n1. Open your terminal or command prompt. \n2. Use the following `cURL` command to obtain a Bearer Token:\n\n```bash\ncurl -X POST https://api.m3ter.com/oauth/token \\\n -H 'Content-Type: application/x-www-form-urlencoded' \\\n -u your_access_key_id:your_api_secret \\\n -d 'grant_type=client_credentials'\n```\n\nReplace `your_access_key_id` and `your_api_secret` with your actual **Access Key id** and **Api Secret**.\n\n3. Run the command, and if successful, it will return a JSON response containing the Bearer Token. The response will look like this:\n\n```json\n{\n \"access_token\": \"your_bearer_token\",\n \"token_type\": \"Bearer\",\n \"expires_in\": 18000\n}\n```\n\nYou can then use the Bearer Token *(the value of `\"access_token\"`)* for subsequent API calls to m3ter.\n\n### Python Example\n1. Install the `requests` library if you haven't already:\n\n```bash\npip install requests\n```\n\n2. Use the following Python script to obtain a Bearer Token:\n\n```python\nimport requests\nimport base64\n\n# Replace these with your Access Key id and Api Secret\naccess_key_id = 'your_access_key_id'\napi_secret = 'your_api_secret'\n\n# Encode the Access Key id and Api Secret in base64 format\ncredentials = base64.b64encode(f'{access_key_id}:{api_secret}'.encode('utf-8')).decode('utf-8')\n\n# Set the m3ter token endpoint URL\ntoken_url = 'https://api.m3ter.com/oauth/token'\n\n# Set the headers for the request\nheaders = {\n 'Authorization': f'Basic {credentials}',\n 'Content-Type': 'application/x-www-form-urlencoded'\n}\n\n# Set the payload for the request\npayload = {\n 'grant_type': 'client_credentials'\n}\n\n# Send the request to obtain the Bearer Token\nresponse = requests.post(token_url, headers=headers, data=payload)\n\n# Check if the request was successful\nif response.status_code == 200:\n # Extract the Bearer Token from the response\n bearer_token = response.json()['access_token']\n print(f'Bearer Token: {bearer_token}')\nelse:\n print(f'Error: {response.status_code} - {response.text}')\n```\n\nReplace `your_access_key_id` and `your_api_secret` with your actual **Access Key id** and **Api Secret**. \n\n3. Run the script, and if successful, it will print the Bearer Token. You can then use this Bearer Token for subsequent API calls to m3ter.\n\n## Submitting Personally Identifiable Information (PII)\n**IMPORTANT!** Under the [Data Processing Agreement](https://www.m3ter.com/docs/legal/dpa), the only fields permissible for use in submitting any of your end-customer PII data in m3ter are the ``name``, ``address``, and ``emailAddress`` fields on the **Account** entity - see the details for [Create Account](https://www.m3ter.com/docs/api#operation/PostAccount). See also section 4.2 of the [Terms of Service](https://www.m3ter.com/docs/legal/terms-of-service).\n\n## Rate and Payload Limits\n### Config API Request Rate Limits\nSee [Config API Limits](https://www.m3ter.com/docs/guides/m3ter-apis/config-api-limits).\n\n### Data Explorer API Request Rate Limits\nSee [Data Explorer Request Rate Limits](https://www.m3ter.com/docs/guides/m3ter-apis/config-api-limits#date-explorer-request-rate-limits).\n\n### Ingest API Request Rate and Payload Limits\nSee [Ingest API Limits](https://www.m3ter.com/docs/guides/m3ter-apis/ingest-api-limits) for more information.\n\n## Pagination\n**List Endpoints**\nAPI endpoints that have a List resources request support cursor-based pagination - for example, the `List Accounts` request. These List calls support pagination by taking the two parameters `pageSize` and `nextToken`. \n\nThe response of a List API call is a single page list. If the `nextToken` parameter is not supplied, the first page returned contains the newest objects chronologically. Specify a `nextToken` to retrieve the page of older objects that occur immediately after the last object on the previous page.\n\nUse `pageSize` to limit the list results per page, typically this allows up to a maximum of 100 or 200 per page.\n\n**Search Endpoints**\nAPI endpoints that have a Search resources request support cursor-based pagination - for example, the `Search Accounts` request. These Search calls support pagination by taking the two parameters `pageSize` and `fromDocument`.\n\nThe response of a Search API call is a single page list. If the `fromDocument` parameter is not supplied, the first page returned contains the newest objects chronologically. Specify a `fromDocument` to retrieve the page of older objects that occur immediately after the last object on the previous page.\n\nUse `pageSize` to limit the list results per page, typically this allows up to a maximum of 100 or 200 per page. Default is 10.\n\n## API Quick Start\nSee [Getting Started with API Calls](https://www.m3ter.com/docs/guides/m3ter-apis/getting-started-with-api-calls) for detailed guidance on how to use our API to:\n* Create a Service User and add permissions.\n* Generate access keys for the Service User.\n* Use basic authentication to obtain a Bearer Token.\n\nFor further guidance, also see [Creating and Configuring Service Users](https://www.m3ter.com/docs/guides/organization-and-access-management/managing-users/creating-and-configuring-service-users).\n\n## Other Languages\nIf you want to work with the m3ter REST APIs using other languages such as:\n* Python\n* JavaScript\n* C++\n\nPlease see the [Developer Tools](https://www.m3ter.com/docs/guides/developer-tools) topic in our main documentation for information about available SDKs.\n\n\n# Authentication\n" version: '1.0' x-logo: url: https://console.m3ter.com/m3ter-logo-black.svg servers: - url: https://api.m3ter.com security: - OAuth2: [] tags: - name: PermissionPolicy description: 'Endpoints for Permission Policy related operations such as creation, update, add and retrieve. Permission Policies can restrict or grant access to specific resources for both Users *(people)* and Service Users *(automated processes with direct API access)*. This enables you to control precisely what a User can do in your m3ter Organization. For more details, see [Understanding, Creating, and Managing Permission Policies](https://www.m3ter.com/docs/guides/organization-and-access-management/creating-and-managing-permissions#permission-policy-statements---available-actions-and-resources) in our main Documentation.' paths: /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/addtousergroup: post: tags: - PermissionPolicy summary: Add a PermissionPolicy to a user group description: Add a permission Policy to a user group operationId: AddPermissionPolicyToUserGroup parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/removefromuser: post: tags: - PermissionPolicy summary: Remove a PermissionPolicy from a user description: Remove a permission policy from a user. operationId: RemovePermissionPolicyFromUser parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission that was removed content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/addtouser: post: tags: - PermissionPolicy summary: Add a PermissionPolicy to a user description: Add a permission policy to a user. operationId: AddPermissionPolicyToUser parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/addtosupportusers: post: tags: - PermissionPolicy summary: Add a PermissionPolicy to support users for an organization description: Add a permission policy to support users for an organization. operationId: AddPermissionPolicyToSupportUsers parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/addtoserviceuser: post: tags: - PermissionPolicy summary: Add a PermissionPolicy to a service user description: Add a permission policy to a service user. operationId: AddPermissionPolicyToServiceUser parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/removefromserviceuser: post: tags: - PermissionPolicy summary: Remove a PermissionPolicy from a service user description: Remove a permission policy from a service user. operationId: RemovePermissionPolicyFromServiceUser parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies: get: tags: - PermissionPolicy summary: List PermissionPolicies description: Retrieve a list of PermissionPolicy entities operationId: ListPermissionPolicies parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: pageSize in: query description: Number of permission polices to retrieve per page required: false allowEmptyValue: true style: form explode: true schema: maximum: 100 minimum: 1 type: integer format: int32 - name: nextToken in: query description: nextToken for multi page retrievals required: false allowEmptyValue: true style: form explode: true schema: type: string responses: '200': description: ListPermissionPolicies 200 response content: application/json: schema: $ref: '#/components/schemas/PaginatedPermissionPolicyResponseData' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' post: tags: - PermissionPolicy summary: Create Permission Policy description: "Create a new Permission Policy\n\n**NOTE:** When you set up a policy statement for this call using the `permissionPolicy` request parameter to specify the `effect`, `action`, and `resource`, you must use all lower case and the format as shown in this example for a Permission Policy statement that grants full CRUD access to all meters:\n```\n\"permissionPolicy\" : [\n\t{\n\t\t\"effect\" : \"allow\",\n\t\t\"action\" : [\n\t\t\"config:create\",\n\t\t\"config:delete\",\n\t\t\"config:retrieve\",\n\t\t\"config:update\"\n\t\t]\n\t\t\"resource\" : [\n\t\t\"config:meter/*\"\n\t\t]\n\t}\n]\n```\n\nFor more details and further examples, see [Understanding, Creating, and Managing Permission Policies](https://www.m3ter.com/docs/guides/organization-and-access-management/creating-and-managing-permissions#permission-policy-statements---available-actions-and-resources) in our main Documentation." operationId: PostPermissionPolicy parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PermissionPolicyRequest' required: true responses: '200': description: Returns the new Permission Policy content: application/json: schema: $ref: '#/components/schemas/PermissionPolicyResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/removefromsupportusers: post: tags: - PermissionPolicy summary: Remove a PermissionPolicy from support users for an organization description: Remove a permission policy from support users for an organization. operationId: RemovePermissionPolicyFromSupportUsers parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string responses: '200': description: Returns the PrincipalPermission content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{permissionPolicyId}/removefromusergroup: post: tags: - PermissionPolicy summary: Remove a PermissionPolicy from a user group description: Remove a permission policy from a user group. operationId: RemovePermissionPolicyFromUserGroup parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: permissionPolicyId in: path description: UUID of the permission policy required: true style: simple explode: false schema: type: string requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionRequest' required: true responses: '200': description: Returns the PrincipalPermission that was removed content: application/json: schema: $ref: '#/components/schemas/PrincipalPermissionResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' /organizations/{orgId}/permissionpolicies/{id}: get: tags: - PermissionPolicy summary: Retrieve Permission Policy description: Retrieve the permission policy for the UUID operationId: GetPermissionPolicy parameters: - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead - name: id in: path description: The UUID of the PermissionPolicy to retrieve. required: true style: simple explode: false schema: type: string responses: '200': description: Returns the PermissionPolicy content: application/json: schema: $ref: '#/components/schemas/PermissionPolicyResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' put: tags: - PermissionPolicy summary: Update Permission Policy description: "Update a Permission Policy for the UUID\n\n**NOTE:** When you set up a policy statement for this call to specify the `effect`, `action`, and `resource`, you must use all lower case and the format as shown in this example - a Permission Policy statement that grants full CRUD access to all meters:\n```\n\"permissionPolicy\" : [\n\t{\n\t\t\"effect\" : \"allow\",\n\t\t\"action\" : [\n\t\t\"config:create\",\n\t\t\"config:delete\",\n\t\t\"config:retrieve\",\n\t\t\"config:update\"\n\t\t]\n\t\t\"resource\" : [\n\t\t\"config:meter/*\"\n\t\t]\n\t}\n]\n```\n\nFor more details and further examples, see [Understanding, Creating, and Managing Permission Policies](https://www.m3ter.com/docs/guides/organization-and-access-management/creating-and-managing-permissions#permission-policy-statements---available-actions-and-resources) in our main Documentation." operationId: PutPermissionPolicy parameters: - name: id in: path description: The UUID of the PermissionPolicy to update. required: true style: simple explode: false schema: type: string - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead requestBody: description: '' content: application/json: schema: $ref: '#/components/schemas/PermissionPolicyRequest' required: true responses: '200': description: Returns the updated version of the PermissionPolicy content: application/json: schema: $ref: '#/components/schemas/PermissionPolicyResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' delete: tags: - PermissionPolicy summary: Delete Permission Policy description: Delete the PermissionPolicy for the UUID operationId: DeletePermissionPolicy parameters: - name: id in: path description: The UUID of the PermissionPolicy to delete. required: true style: simple explode: false schema: type: string - name: orgId in: path description: UUID of the organization required: true style: simple explode: false schema: type: string deprecated: true x-stainless-deprecation-message: the org id should be set at the client level instead responses: '200': description: Returns the PermissionPolicy that was deleted content: application/json: schema: $ref: '#/components/schemas/PermissionPolicyResponse' 4XX: $ref: '#/components/responses/Error' 5XX: $ref: '#/components/responses/Error' components: schemas: PermissionPolicyRequest: required: - name - permissionPolicy type: object properties: version: type: integer description: 'The version number of the entity: * **Create entity:** Not valid for initial insertion of new entity - do not use for Create. On initial Create, version is set at 1 and listed in the response. * **Update Entity:** On Update, version is required and must match the existing version because a check is performed to ensure sequential versioning is preserved. Version is incremented by 1 and listed in the response. ' format: int64 x-stainless-terraform-configurability: computed x-stainless-terraform-always-send: true name: maxLength: 100 minLength: 1 type: string description: '' permissionPolicy: minItems: 1 type: array description: '' items: $ref: '#/components/schemas/PermissionStatement' description: '' PrincipalPermissionResponse: type: object description: '' allOf: - $ref: '#/components/schemas/AbstractResponse' - properties: permissionPolicyId: type: string description: '' principalId: type: string description: '' principalType: description: '' $ref: '#/components/schemas/PrincipalType' dtCreated: type: string description: The DateTime *(in ISO-8601 format)* when the principal permission was created. format: date-time x-stainless-skip: - terraform dtLastModified: type: string description: The DateTime *(in ISO-8601 format)* when the principal permission was last modified. format: date-time x-stainless-skip: - terraform createdBy: type: string description: The id of the user who created this principal permission. x-stainless-skip: - terraform lastModifiedBy: type: string description: The id of the user who last modified this principal permission. x-stainless-skip: - terraform PermissionRequest: $ref: '#/components/schemas/AbstractRequest' PermissionStatement: required: - action - effect - resource type: object properties: effect: description: 'Specifies whether or not the user is allowed to perform the action on the resource. **NOTE:** Use lower case, for example: `"allow"`. If you use upper case, you''ll receive an error.' $ref: '#/components/schemas/PermissionEffect' action: type: array description: 'The actions available to users who are assigned the Permission Policy - what they can do or cannot do with respect to the specified resource. **NOTE:** Use lower case and a colon-separated format, for example, if you want to confer full CRUD, use: ``` "config:create", "config:delete", "config:retrieve", "config:update" ```' items: $ref: '#/components/schemas/PermissionAction' resource: minItems: 1 type: array description: See [Statements - Available Resources](https://www.m3ter.com/docs/guides/managing-organization-and-users/creating-and-managing-permissions#statements---available-resources) for a listing of available resources for Permission Policy statements. items: type: string description: '' PrincipalPermissionRequest: type: object description: '' allOf: - $ref: '#/components/schemas/AbstractRequest' - required: - principalId properties: principalId: minLength: 1 type: string description: '' AbstractResponse: required: - id type: object properties: id: type: string description: 'The UUID of the entity. ' version: type: integer description: 'The version number: - **Create:** On initial Create to insert a new entity, the version is set at 1 in the response. - **Update:** On successful Update, the version is incremented by 1 in the response.' format: int64 x-stainless-terraform-configurability: computed x-stainless-terraform-always-send: true description: '' PermissionEffect: type: string description: '' enum: - ALLOW - DENY PermissionPolicyResponse: type: object description: '' allOf: - $ref: '#/components/schemas/AbstractResponse' - properties: name: type: string description: The name of the Permission Policy. permissionPolicy: type: array description: 'Array containing the Permission Policies information. ' items: $ref: '#/components/schemas/PermissionStatement' managedPolicy: type: boolean description: 'Indicates whether this is a system generated Managed Permission Policy. ' dtCreated: type: string description: The date and time *(in ISO-8601 format)* when the Permission Policy was created. format: date-time x-stainless-skip: - terraform dtLastModified: type: string description: The date and time *(in ISO-8601 format)* when the Permission Policy was last modified. format: date-time x-stainless-skip: - terraform createdBy: type: string description: The unique identifier (UUID) of the user who created this Permission Policy. x-stainless-skip: - terraform lastModifiedBy: type: string description: The unique identifier (UUID) of the user who last modified this Permission Policy. x-stainless-skip: - terraform PrincipalType: type: string description: '' enum: - USER - USERGROUP - SERVICEUSER - SUPPORTUSERS AbstractRequest: type: object properties: version: type: integer description: 'The version number of the entity: - **Create entity:** Not valid for initial insertion of new entity - *do not use for Create*. On initial Create, version is set at 1 and listed in the response. - **Update Entity:** On Update, version is required and must match the existing version because a check is performed to ensure sequential versioning is preserved. Version is incremented by 1 and listed in the response.' format: int64 x-stainless-terraform-configurability: computed x-stainless-terraform-always-send: true description: '' PermissionAction: type: string description: '' enum: - ALL - CONFIG_CREATE - CONFIG_RETRIEVE - CONFIG_UPDATE - CONFIG_DELETE - CONFIG_EXPORT - ANALYTICS_QUERY - MEASUREMENTS_UPLOAD - MEASUREMENTS_FILEUPLOAD - MEASUREMENTS_RETRIEVE - MEASUREMENTS_EXPORT - FORECAST_RETRIEVE - HEALTHSCORES_RETRIEVE - ANOMALIES_RETRIEVE - EXPORTS_DOWNLOAD - MARKETPLACE_USAGE_CREATE - MARKETPLACE_USAGE_RETRIEVE - AUDIT_RETRIEVE PaginatedPermissionPolicyResponseData: type: object properties: data: type: array description: '' items: $ref: '#/components/schemas/PermissionPolicyResponse' nextToken: type: string description: '' description: '' responses: Error: description: Error message content: application/json: schema: type: object properties: message: type: string securitySchemes: OAuth2: type: oauth2 description: "m3ter supports machine to machine authentication using the `clientCredentials` OAuth2 flow.\n\nThe `authorizationCode` flow controls access for human users via the m3ter Console application. \n" flows: clientCredentials: tokenUrl: /oauth/token scopes: m3ter-resources/m3ter-scope: m3ter resources measurements:upload: Upload measurements measurements:fileUpload: Upload file measurements:retrieve: Retrieve measurements authorizationCode: authorizationUrl: https://m3ter.auth.us-east-1.amazoncognito.com/oauth2/authorize tokenUrl: https://m3ter.auth.us-east-1.amazoncognito.com/oauth2/token scopes: m3ter-resources/m3ter-scope: m3ter resources openid: OpenID email: email measurements:upload: Upload measurements measurements:fileUpload: Upload file measurements:retrieve: Retrieve measurements