openapi: 3.1.0 info: title: OpenBMC Redfish AccountService SessionService API description: OpenBMC exposes a Redfish-conformant REST API over HTTPS for managing server baseboard management controllers (BMCs). The API provides programmatic access to chassis, manager, system, power, log, event, and update services. Authentication is performed via a session token returned from the SessionService and supplied in the X-Auth-Token header on subsequent requests. This OpenAPI definition reflects the endpoints documented in the OpenBMC Redfish cheatsheet. version: 1.0.0 contact: name: OpenBMC Documentation url: https://github.com/openbmc/docs servers: - url: https://{bmc}/redfish/v1 description: OpenBMC Redfish service root on a BMC host variables: bmc: default: bmc.example.com description: Hostname or IP address of the OpenBMC-managed BMC security: - SessionToken: [] tags: - name: SessionService paths: /SessionService/Sessions: post: summary: Create a Redfish session description: Authenticates a user and creates a session. The X-Auth-Token response header value must be sent on subsequent requests. operationId: createSession security: [] requestBody: required: true content: application/json: schema: type: object required: - UserName - Password properties: UserName: type: string Password: type: string responses: '201': description: Session created headers: X-Auth-Token: schema: type: string description: Session authentication token content: application/json: schema: type: object tags: - SessionService components: securitySchemes: SessionToken: type: apiKey in: header name: X-Auth-Token description: Redfish session token obtained from POST /SessionService/Sessions