openapi: 3.2.0 info: description: 'Use the Managed Access API to approve access requests, create and manage templates, and manage resource approval settings. For more information, see [Managed Access Overview](https://docs.oracle.com/iaas/Content/managed-access/home.htm). Use the table of contents and search tool to explore the Managed Access API. ' title: Managed Access Lockbox Access Context Attribute API version: '20220126' x-provenance: method: harvested first_party: true publisher: Oracle source: https://docs.oracle.com/en-us/iaas/api/specs/f397c9292e6f977d1885091f8a6e9a9c3cdcb882c49d89bc55720e8eec0c02d1.yaml harvested: '2026-08-04' note: Published by Oracle as the contract for the Managed Access API OCI service and stored verbatim; API Evangelist added only this provenance block. x-evidence: - url: https://docs.oracle.com/en-us/iaas/api/specs/index.json what: Oracle's own index of every OCI service specification - url: https://docs.oracle.com/en-us/iaas/api/specs/f397c9292e6f977d1885091f8a6e9a9c3cdcb882c49d89bc55720e8eec0c02d1.yaml what: the harvested document for Managed Access API servers: - url: http://127.0.0.1/20220126 - url: https://127.0.0.1/20220126 tags: - name: lockboxAccessContextAttribute paths: /lockboxAccessContextAttributes: get: description: 'Returns a list of LockboxAccessContextAttributes. ' operationId: ListLockboxAccessContextAttributes parameters: - $ref: '#/components/parameters/PartnerIdOptionalQueryParam' - $ref: '#/components/parameters/LockboxAccessContextAttributeLifecycleStateQueryParam' - $ref: '#/components/parameters/LockboxAccessContextAttributeNameQueryParam' - $ref: '#/components/parameters/PaginationLimitQueryParam' - $ref: '#/components/parameters/PaginationTokenQueryParam' - $ref: '#/components/parameters/SortOrderQueryParam' - $ref: '#/components/parameters/SortByQueryParam' - $ref: '#/components/parameters/RequestIdHeader' responses: 200: description: A page of LockboxAccessContextAttributeSummary objects. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/LockboxAccessContextAttributeCollection' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Gets a list of lockboxAccessContextAttributes tags: - lockboxAccessContextAttribute x-related-resource: '#/definitions/LockboxAccessContextAttributeCollection' post: description: 'Creates a new LockboxAccessContextAttribute. ' operationId: CreateLockboxAccessContextAttribute parameters: - $ref: '#/components/parameters/RetryTokenHeader' - $ref: '#/components/parameters/RequestIdHeader' responses: 201: description: Accepted the request. The LockboxAccessContextAttribute is created. headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' schema: type: string location: description: 'this contains the full URI for the get request, e.g. "https://iaas.us-phoenix-1.oraclecloud.com/20210331/lockbox/" ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/LockboxAccessContextAttribute' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 409: $ref: '#/components/responses/409' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Creates a new LockboxAccessContextAttribute tags: - lockboxAccessContextAttribute x-related-resource: '#/definitions/LockboxAccessContextAttribute' requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateLockboxAccessContextAttributeDetails' description: Details for the new LockboxAccessContextAttribute. required: true /lockboxAccessContextAttributes/{lockboxAccessContextAttributeId}: delete: description: Deletes a LockboxAccessContextAttribute resource by identifier operationId: DeleteLockboxAccessContextAttribute parameters: - $ref: '#/components/parameters/LockboxAccessContextAttributeIdentifierPathParam' - $ref: '#/components/parameters/IfMatchHeader' - $ref: '#/components/parameters/RequestIdHeader' - $ref: '#/components/parameters/RetryTokenHeader' responses: 204: description: LockboxAccessContextAttribute is deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 409: $ref: '#/components/responses/409' 412: $ref: '#/components/responses/412' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Delete a provisioned LockboxAccessContextAttribute tags: - lockboxAccessContextAttribute x-related-resource: '#/definitions/LockboxAccessContextAttribute' get: description: Get an LockboxAccessContextAttribute by identifier operationId: GetLockboxAccessContextAttribute parameters: - $ref: '#/components/parameters/LockboxAccessContextAttributeIdentifierPathParam' - $ref: '#/components/parameters/RequestIdHeader' responses: 200: description: Retrieves the LockboxAccessContextAttribute with the given id headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/LockboxAccessContextAttribute' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Get LockboxAccessContextAttribute tags: - lockboxAccessContextAttribute put: description: Updates the LockboxAccessContextAttribute operationId: UpdateLockboxAccessContextAttribute parameters: - $ref: '#/components/parameters/LockboxAccessContextAttributeIdentifierPathParam' - $ref: '#/components/parameters/IfMatchHeader' - $ref: '#/components/parameters/RequestIdHeader' responses: 200: description: The Lockbox is updated. headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/LockboxAccessContextAttribute' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 405: $ref: '#/components/responses/405' 412: $ref: '#/components/responses/412' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Update the LockboxAccessContextAttribute identified by the id tags: - lockboxAccessContextAttribute x-related-resource: '#/definitions/LockboxAccessContextAttribute' requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateLockboxAccessContextAttributeDetails' description: The information to be updated. required: true components: schemas: UpdateLockboxAccessContextAttributeDetails: description: The action to be updated. properties: defaultValue: description: An optional default value used when access request context value is not provided maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object description: description: The description of the access context attribute maxLength: 255 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object simultaneousAccessState: description: If this access context Attribute enables simultaneous access feature enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/SimultaneousAccessState' values: $ref: '#/components/schemas/AccessContextAttributeValueCollection' type: object LockboxAccessContextAttributeSummary: description: the access context attributes are needed for creating a lockbox properties: defaultValue: description: An optional default value used when access request context value is not provided maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object description: description: The description of the access context attribute maxLength: 255 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object id: description: The unique identifier (OCID) of the access context attribute, which can't be changed after creation. type: string lifecycleState: description: The current state of the access context attribute. type: string x-obmcs-enumref: '#/definitions/LockboxAccessContextAttribute/lifecycleState' name: description: The name of this access context attribute type: string partnerId: description: The unique identifier (OCID) of partner resource creates this access context attribute type: string simultaneousAccessState: description: If this access context attribute enables simultaneous access feature enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/SimultaneousAccessState' systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: The time the the approval template was created. An RFC3339 formatted datetime string format: date-time type: string timeUpdated: description: The time the approval template was updated. An RFC3339 formatted datetime string format: date-time type: string values: $ref: '#/components/schemas/AccessContextAttributeValueCollection' required: - id - name - partnerId type: object Error: description: Error Information. properties: code: description: A short error code that defines the error, meant for programmatic parsing. type: string message: description: A human-readable error string. type: string required: - code - message LockboxAccessContextAttribute: description: the access context attributes are needed for creating a lockbox properties: defaultValue: description: An optional default value used when access request context value is not provided maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object description: description: The description of the access context attribute maxLength: 255 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object id: description: The unique identifier (OCID) of the access context attribute, which can't be changed after creation. type: string lifecycleState: description: The current state of the access context attribute. enum: - ACTIVE - CREATING - UPDATING - DELETING - DELETED - FAILED type: string name: description: The name of this access context attribute type: string partnerId: description: The unique identifier (OCID) of partner resource creates this access context attribute type: string simultaneousAccessState: description: If this access context attribute enables simultaneous access feature enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/SimultaneousAccessState' systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: The time the the approval template was created. An RFC3339 formatted datetime string format: date-time type: string timeUpdated: description: The time the approval template was updated. An RFC3339 formatted datetime string format: date-time type: string values: $ref: '#/components/schemas/AccessContextAttributeValueCollection' required: - id - name - partnerId type: object LockboxAccessContextAttributeCollection: description: Results of access context attribute search. properties: items: description: List of AccessContextAttribute. items: $ref: '#/components/schemas/LockboxAccessContextAttributeSummary' type: array required: - items type: object CreateLockboxAccessContextAttributeDetails: description: The information about new AccessContextAttribute properties: defaultValue: description: An optional default value used when access request context value is not provided maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object description: description: The description of the access context attribute maxLength: 255 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object name: description: The name of this accessContextAttribute maxLength: 255 minLength: 1 type: string partnerId: description: The unique identifier (OCID) of partner resource creates this access context attribute type: string simultaneousAccessState: description: If this access context attribute enables simultaneous access feature enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/SimultaneousAccessState' values: $ref: '#/components/schemas/AccessContextAttributeValueCollection' required: - name - partnerId type: object AccessContextAttributeValue: description: Defined by partner, these attributes provides context for creating access request properties: simultaneousAccessState: description: If this credential allows simultaneous access enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/SimultaneousAccessState' value: description: The value of the access context attribute maxLength: 255 minLength: 1 type: string required: - value type: object AccessContextAttributeValueCollection: description: Contains access context attritbue value entries properties: items: description: List of access context attribute values items: $ref: '#/components/schemas/AccessContextAttributeValue' type: array required: - items type: object parameters: PaginationTokenQueryParam: description: A token representing the position at which to start retrieving results. This must come from the `opc-next-page` header field of a previous response. in: query name: page x-default-description: 'null' schema: type: string minLength: 1 SortByQueryParam: description: 'The field to sort by. Only one sort order may be provided. Default order for timeCreated is descending. Default order for displayName is ascending. ' in: query name: sortBy schema: type: string enum: - timeCreated - displayName - id default: timeCreated LockboxAccessContextAttributeNameQueryParam: description: A filter to return the access context attribute that matches the entire name given. in: query name: name x-default-description: 'null' schema: type: string maxLength: 255 minLength: 1 LockboxAccessContextAttributeLifecycleStateQueryParam: description: A filter to return only resources their lifecycleState matches the given lifecycleState. in: query name: lifecycleState x-default-description: 'null' x-obmcs-enumref: '#/definitions/LockboxAccessContextAttribute/lifecycleState' schema: type: string IfMatchHeader: description: 'For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource''s current etag value. ' in: header name: if-match required: false schema: type: string PartnerIdOptionalQueryParam: description: The unique identifier (OCID) of the associated partner. in: query name: partnerId x-default-description: 'null' schema: type: string maxLength: 255 minLength: 1 PaginationLimitQueryParam: description: The maximum number of items to return. in: query name: limit schema: type: integer default: 10 maximum: 1000 minimum: 1 LockboxAccessContextAttributeIdentifierPathParam: description: unique AccessContextAttribute identifier in: path name: lockboxAccessContextAttributeId required: true schema: type: string SortOrderQueryParam: description: The sort order to use, either 'ASC' or 'DESC'. in: query name: sortOrder x-default-description: 'The default value depends upon `sortBy`, and in general is ''DESC'' when sorting by time and ''ASC'' otherwise. ' x-obmcs-top-level-enum: '#/definitions/SortOrder' schema: type: string enum: - ASC - DESC RetryTokenHeader: description: 'A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations. For example, if a resource has been deleted and purged from the system, then a retry of the original creation request might be rejected. ' in: header name: opc-retry-token required: false schema: type: string maxLength: 64 minLength: 1 RequestIdHeader: description: The client request ID for tracing. in: header name: opc-request-id schema: type: string responses: default: description: Unknown Error headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/Error' x-anchors: x-headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' type: string location: description: 'this contains the full URI for the get request, e.g. "https://iaas.us-phoenix-1.oraclecloud.com/20210331/lockbox/" ' type: string opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'Unique Oracle-assigned identifier for the asynchronous work. You can use this to query its status. ' type: string retry-after: description: A decimal number representing the number of seconds the client should wait before polling this endpoint again. type: integer x-properties: compartmentId: description: The unique identifier (OCID) of the compartment where the resource is located. maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object x-obmcs-client-retries-enabled: true x-oracle-package: com.oracle.pic.lockbox