openapi: 3.2.0 info: version: V1 title: Orion Connect Security/Privileges API x-swagger-net-version: 8.4.12.001 servers: - url: https://api.orionadvisor.com/api tags: - name: Security/Privileges paths: /v1/Security/Privileges: get: tags: - Security/Privileges operationId: Privileges_GetPrivileges parameters: - name: loginEntityId in: query required: false schema: type: string enum: - BrokerDealer - Wholesaler - Representative - Client - RIA - Administrator - SubAdvisor - ThirdPartyAdministrator - Custodian - PlanSponsor - ThirdParty - ServiceAccount - Participant - RepAccountManager - Payee - RIATable - Cotenant - name: type in: query required: false schema: type: string enum: - Unknown - Apps - Records - Actions - Advanced - Applinks - FeatureFlags - name: categoryId in: query required: false schema: type: integer format: int32 responses: '200': description: OK content: text/plain: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' xml: name: PrivilegeDto wrapped: true type: array application/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' xml: name: PrivilegeDto wrapped: true type: array text/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' xml: name: PrivilegeDto wrapped: true type: array application/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' xml: name: PrivilegeDto wrapped: true type: array text/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' xml: name: PrivilegeDto wrapped: true type: array multipart/form-data: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' xml: name: PrivilegeDto wrapped: true type: array security: - Authorization: [] summary: Privileges get privileges x-summary-source: derived post: tags: - Security/Privileges operationId: Privileges_CreatePrivlegeAsync parameters: - name: ct in: header required: true responses: '200': description: OK content: text/plain: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' application/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' text/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' application/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' text/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' multipart/form-data: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' security: - Authorization: [] requestBody: content: text/plain: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' text/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' text/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' multipart/form-data: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' required: true summary: Privileges create privlege async x-summary-source: derived /v1/Security/Privileges/{code}: get: tags: - Security/Privileges operationId: Privileges_GetByCodeAsync parameters: - name: code in: path required: true schema: type: string - name: ct in: header required: true responses: '200': description: OK content: text/plain: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' application/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' text/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' application/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' text/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' multipart/form-data: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' security: - Authorization: [] summary: Privileges get by code async x-summary-source: derived put: tags: - Security/Privileges operationId: Privileges_UpdatePrivlegeAsync parameters: - name: code in: path required: true schema: type: string - name: ct in: header required: true responses: '200': description: OK content: text/plain: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' application/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' text/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' application/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' text/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' multipart/form-data: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDto' security: - Authorization: [] requestBody: content: text/plain: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' text/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' text/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' multipart/form-data: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' required: true summary: Privileges update privlege async x-summary-source: derived /v1/Security/Privileges/{code}/Roles: get: tags: - Security/Privileges summary: Gets details about the privilege specified by the {code}, along with the Roles… operationId: Privileges_GetByCodeWithFirmRoles parameters: - name: code in: path description: The code uniquely identifying the privilege. required: true schema: type: string responses: '200': description: OK content: text/plain: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array application/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array text/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array application/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array text/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array multipart/form-data: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array security: - Authorization: [] /v1/Security/Privileges/{key}: get: tags: - Security/Privileges operationId: Privileges_GetPrivilege parameters: - name: key in: path required: true schema: type: integer format: int32 responses: '200': description: OK content: text/plain: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' text/json: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' application/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' text/xml: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' multipart/form-data: schema: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeDetailsDto' security: - Authorization: [] summary: Privileges get privilege x-summary-source: derived /v1/Security/Privileges/{key}/AllowedEntitiesHistory: get: tags: - Security/Privileges operationId: Privileges_GetPrivilegeAllowedEntitiesHistory parameters: - name: key in: path required: true schema: type: integer format: int32 responses: '200': description: OK content: text/plain: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto' xml: name: PrivilegeAllowEntityHistoryDto wrapped: true type: array application/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto' xml: name: PrivilegeAllowEntityHistoryDto wrapped: true type: array text/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto' xml: name: PrivilegeAllowEntityHistoryDto wrapped: true type: array application/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto' xml: name: PrivilegeAllowEntityHistoryDto wrapped: true type: array text/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto' xml: name: PrivilegeAllowEntityHistoryDto wrapped: true type: array multipart/form-data: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto' xml: name: PrivilegeAllowEntityHistoryDto wrapped: true type: array security: - Authorization: [] summary: Privileges get privilege allowed entities history x-summary-source: derived /v1/Security/Privileges/{key}/Histories: get: tags: - Security/Privileges operationId: Privileges_GetPrivilegeHistory parameters: - name: key in: path required: true schema: type: integer format: int32 responses: '200': description: OK content: text/plain: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeHistoryDto' xml: name: PrivilegeHistoryDto wrapped: true type: array application/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeHistoryDto' xml: name: PrivilegeHistoryDto wrapped: true type: array text/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeHistoryDto' xml: name: PrivilegeHistoryDto wrapped: true type: array application/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeHistoryDto' xml: name: PrivilegeHistoryDto wrapped: true type: array text/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeHistoryDto' xml: name: PrivilegeHistoryDto wrapped: true type: array multipart/form-data: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeHistoryDto' xml: name: PrivilegeHistoryDto wrapped: true type: array security: - Authorization: [] summary: Privileges get privilege history x-summary-source: derived /v1/Security/Privileges/{key}/Roles: get: tags: - Security/Privileges summary: Gets details about the privilege specified by the {key}, along with the Roles… operationId: Privileges_GetByKeyWithFirmRoles parameters: - name: key in: path description: The ID of the privilege. required: true schema: type: integer format: int32 responses: '200': description: OK content: text/plain: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array application/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array text/json: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array application/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array text/xml: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array multipart/form-data: schema: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RoleDetailsDto' xml: name: RoleDetailsDto wrapped: true type: array security: - Authorization: [] /v1/Security/Privileges/Categories: get: tags: - Security/Privileges operationId: Privileges_GetCategories responses: '200': description: OK content: text/plain: schema: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array application/json: schema: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array text/json: schema: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array application/xml: schema: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array text/xml: schema: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array multipart/form-data: schema: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array security: - Authorization: [] summary: Privileges get categories x-summary-source: derived components: schemas: OAS.WebApi.DTO.Security.PrivilegeDetailsDto: properties: loginEntities: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.PrivilegeLoginEntitiesDto' xml: name: PrivilegeLoginEntitiesDto wrapped: true type: array firmTypes: type: string enum: - None - Foundations - Essentials - Advantage - OrionTradingOnly - OrionRiskOnly - OrionComplianceOnly - OrionPlanningOnly - OasLegacy loginEntityAllowedAccess: type: string enum: - None - Read - Edit - Delete id: type: integer format: int32 name: type: string code: type: string description: type: string type: type: string enum: - Unknown - Apps - Records - Actions - Advanced - Applinks - FeatureFlags categoryName: type: string availableAccessType: type: string enum: - None - Read - Edit - Delete categoryId: type: integer format: int32 isIncludedByDefault: type: boolean revokeOnLockdownType: type: string enum: - None - Billing alClientIds: items: type: integer format: int32 type: array dbLimitationAdminOverride: type: boolean firmTypeExceptions: items: type: integer format: int32 type: array xml: name: PrivilegeDetailsDto type: object OAS.WebApi.DTO.Security.RolePrivilegeDto: properties: id: type: integer format: int32 categoryId: type: integer format: int32 categoryName: type: string availableAccessType: type: string enum: - None - Read - Edit - Delete name: type: string description: type: string type: type: string enum: - Unknown - Apps - Records - Actions - Advanced - Applinks - FeatureFlags code: type: string readIsGranted: type: boolean editIsGranted: type: boolean deleteIsGranted: type: boolean xml: name: RolePrivilegeDto type: object OAS.WebApi.DTO.Security.PrivilegeAllowEntityHistoryDto: properties: id: type: integer format: int32 privilege: type: integer format: int32 loginEntity: type: string enum: - BrokerDealer - Wholesaler - Representative - Client - RIA - Administrator - SubAdvisor - ThirdPartyAdministrator - Custodian - PlanSponsor - ThirdParty - ServiceAccount - Participant - RepAccountManager - Payee - RIATable - Cotenant accessType: type: string enum: - None - Read - Edit - Delete auditByDisplayName: type: string auditedDate: type: string format: date-time changeType: type: string xml: name: PrivilegeAllowEntityHistoryDto type: object OAS.WebApi.DTO.Security.RoleDetailsDto: properties: canEdit: type: boolean privileges: items: $ref: '#/components/schemas/OAS.WebApi.DTO.Security.RolePrivilegeDto' xml: name: RolePrivilegeDto wrapped: true type: array defaultDashboardId: type: integer format: int32 dashboards: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array defaultPVDashboardId: type: integer format: int32 pvDashboards: items: $ref: '#/components/schemas/OAS.DataModel.SimpleEntity' xml: name: SimpleEntity wrapped: true type: array id: type: integer format: int32 clientName: type: string name: type: string loginEntityId: type: string enum: - BrokerDealer - Wholesaler - Representative - Client - RIA - Administrator - SubAdvisor - ThirdPartyAdministrator - Custodian - PlanSponsor - ThirdParty - ServiceAccount - Participant - RepAccountManager - Payee - RIATable - Cotenant isGlobal: type: boolean loginEntityDescription: type: string tokenLife: type: number format: double assignedProfiles: type: integer format: int32 xml: name: RoleDetailsDto type: object OAS.WebApi.DTO.Security.PrivilegeLoginEntitiesDto: properties: id: type: string enum: - BrokerDealer - Wholesaler - Representative - Client - RIA - Administrator - SubAdvisor - ThirdPartyAdministrator - Custodian - PlanSponsor - ThirdParty - ServiceAccount - Participant - RepAccountManager - Payee - RIATable - Cotenant entity: type: string enum: - Undefined - Payee - BrokerDealer - Wholesaler - Representative - Client - Registration - Account - Asset - Product - Transaction - Distribution - FundFamily - Personal - PayoutSchedule - FeeSchedule - Platform - RIA - Custodian - Journal - SWP - Other - NASD - CashFunding - Bill - BillInstance - BillMasterPayout - Model - NewAccountClient - NewAccountReg - DownloadExclusion - Price - UserDefinedFields - NewAcctUserDef - ManagersMessage - IndexEntry - PerformanceFee - PerformancePayout - NewAccountAsset - Owner - Administrator - OutsideClient - SubAdvisor - ModelRange - FaxCover - Fax - OneTimeDistribution - WebLogin - Plan401k - BillAccountItem - ThirdPartyAdministrator - CrmContact - Participant - PlanSponsor - CRMEmailList - ThirdParty - WorkflowItem - WorkflowAction - ServiceAccount - EntityOption - HouseholdMember - DownloadSymbol - IndexBlend - NABenefit - AggregateModel - CompositeRange - RepAccountManager - ScriptsScrubs - ServiceAccountBrokerDealer - BusinessLine - Blob - AssetClass - ServiceAccountLite - NewAcctUserDefDtl - Branch - AssetLevelStrategy - Report - DataQueries - PriceUnUsed - ModelItem - AssetCategory - RiskCategory - PlatformRange - Dividend - RegistrationType - CustodianCommon - RepState - QpeDashboard - ReportBatch - ModelGroup - ShareClass - DownloadFile - User - DynamicGrouping - ProductType - ProductSubType - InvestmentObjective - PortfolioGroup - OrionRealizedLot - OrionUnrealizedLot - CustodianRealizedLot - CustodianUnrealizedLot - AssetCategoryParent - TaxType - AuditRequest - AuditRequestLetter - ManagedUnmanaged - AuditRowAttachment - InformPolicy - InformAnswerAttachment - UserDetail - BillPayMethod - ModelInclusion - CommunityModel - EclipseModel - Global - ClientCategory - Taxability - Qualified - TaxID - BondState - ProductTaxability - TargetAllocation - RIATable - ProductRegion - ProductPropertyType - ProductManagerAip - MoodyRating - SPRating - BondMaturityYear - InterestRate - RegistrationTaxType - MaturityPeriod - NewHousehold - BillPayoutDashboardPayment - OptionLevel - MarginAgreement - PrimeBrokerage - InformHistoricalDocument - SleeveStrategyAggregate - MorningstarSector - BillEntity - SleeveStrategy - MorningstarGeography - GenericProspect - BillEntityType - AdditionalRep - BillPayoutReport - ProductSubHolding - DownloadSource - ModelVsActual - ProductVintageYear - EclipsePortfolio - Country - Currency - SecurityClassification1 - SecurityClassification2 - SecurityClassification3 - SecurityClassification4 - SecurityClassification5 - SecurityClassification6 - SecurityClassification7 - SecurityClassification8 - SecurityClassification9 - SecurityClassification10 - SecurityClassification11 - SecurityClassification12 - SecurityClassification13 - SecurityClassification14 - SecurityClassification15 - SecurityClassification16 - SecurityClassification17 - SecurityClassification18 - SecurityClassification19 - SecurityClassification20 - SecurityClassification21 - SecurityClassification22 - SecurityClassification23 - SecurityClassification24 - SecurityClassification25 - DownloadRecord - CustomGrouping - Cotenant - AllocatedUnrealizedCostBasis - AllocatedRealizedCostBasis entityDesc: type: string isTableBased: type: boolean accessType: type: string enum: - None - Read - Edit - Delete xml: name: PrivilegeLoginEntitiesDto type: object OAS.WebApi.DTO.Security.PrivilegeHistoryDto: properties: id: type: integer format: int32 privilegeId: type: integer format: int32 privilegeCategory: type: integer format: int32 name: type: string code: type: string description: type: string type: type: integer format: int32 accessType: type: string enum: - None - Read - Edit - Delete firmTypes: type: string enum: - None - Foundations - Essentials - Advantage - OrionTradingOnly - OrionRiskOnly - OrionComplianceOnly - OrionPlanningOnly - OasLegacy auditedByDisplayName: type: string auditedDate: type: string format: date-time changeType: type: string isIncludedByDefault: type: boolean revokeOnLockdownType: type: string enum: - None - Billing dbLimitationAdminOverride: type: boolean xml: name: PrivilegeHistoryDto type: object OAS.WebApi.DTO.Security.PrivilegeDto: properties: loginEntityAllowedAccess: type: string enum: - None - Read - Edit - Delete id: type: integer format: int32 name: type: string code: type: string description: type: string type: type: string enum: - Unknown - Apps - Records - Actions - Advanced - Applinks - FeatureFlags categoryName: type: string availableAccessType: type: string enum: - None - Read - Edit - Delete categoryId: type: integer format: int32 isIncludedByDefault: type: boolean revokeOnLockdownType: type: string enum: - None - Billing alClientIds: items: type: integer format: int32 type: array dbLimitationAdminOverride: type: boolean firmTypeExceptions: items: type: integer format: int32 type: array xml: name: PrivilegeDto type: object OAS.DataModel.SimpleEntity: properties: id: type: integer format: int32 name: type: string xml: name: SimpleEntity type: object securitySchemes: Authorization: type: apiKey description: 'JWT Authorization header using the Session scheme. Example: "Authorization: Session {token}"' name: Authorization in: header