openapi: 3.2.0 info: title: Pagopa Users API version: 3.1.0 contact: name: API Support url: https://github.com/pagopa/pdnd-interop-frontend/issues termsOfService: https://selfcare.interop.pagopa.it/ui/it/termini-di-servizio x-summary: PDND Interoperability API description: 'Operations tagged users across 2 of this provider''s published API definitions: interop-api-v3.yaml, pagopa-pdnd-interop-v3-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://api.interop.pagopa.it/v3 description: Production environment security: - DPoPAuth: [] DPoPProofHeader: [] tags: - name: Users description: Users routes paths: /users: get: tags: - Users summary: List Users description: 'Retrieve active users belonging to the requester''s organization. Users are fetched in real-time and not persisted. Access is restricted to m2m-admin role only.' operationId: getUsers parameters: - in: query name: roles description: Filter users by role required: false schema: type: array items: type: string default: [] explode: false - $ref: '#/components/parameters/LimitParam' - $ref: '#/components/parameters/OffsetParam' responses: '200': description: Users retrieved successfully content: application/json: schema: $ref: '#/components/schemas/Users' headers: X-Rate-Limit-Limit: $ref: '#/components/headers/RateLimitLimitHeader' X-Rate-Limit-Remaining: $ref: '#/components/headers/RateLimitRemainingHeader' X-Rate-Limit-Interval: $ref: '#/components/headers/RateLimitIntervalHeader' Digest: $ref: '#/components/headers/IntegrityRest02DigestHeader' Agid-JWT-Signature: $ref: '#/components/headers/IntegrityRest02AgidJwtSignatureHeader' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '429': $ref: '#/components/responses/TooManyRequests' servers: - url: https://api.interop.pagopa.it/v3 description: Production environment /users/{userId}: get: tags: - Users summary: Retrieve a User description: 'Retrieve an active user belonging to the requester''s organization and with a specific user id.' operationId: getUser parameters: - in: path name: userId description: The user id of the user to retrieve required: true schema: type: string format: uuid responses: '200': description: User retrieved successfully content: application/json: schema: $ref: '#/components/schemas/User' headers: X-Rate-Limit-Limit: $ref: '#/components/headers/RateLimitLimitHeader' X-Rate-Limit-Remaining: $ref: '#/components/headers/RateLimitRemainingHeader' X-Rate-Limit-Interval: $ref: '#/components/headers/RateLimitIntervalHeader' Digest: $ref: '#/components/headers/IntegrityRest02DigestHeader' Agid-JWT-Signature: $ref: '#/components/headers/IntegrityRest02AgidJwtSignatureHeader' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '429': $ref: '#/components/responses/TooManyRequests' servers: - url: https://api.interop.pagopa.it/v3 description: Production environment components: responses: Unauthorized: description: Unauthorized content: application/problem+json: schema: $ref: '#/components/schemas/Problem' headers: X-Rate-Limit-Limit: $ref: '#/components/headers/RateLimitLimitHeader' X-Rate-Limit-Remaining: $ref: '#/components/headers/RateLimitRemainingHeader' X-Rate-Limit-Interval: $ref: '#/components/headers/RateLimitIntervalHeader' Digest: $ref: '#/components/headers/IntegrityRest02DigestHeader' Agid-JWT-Signature: $ref: '#/components/headers/IntegrityRest02AgidJwtSignatureHeader' Forbidden: description: Forbidden content: application/problem+json: schema: $ref: '#/components/schemas/Problem' headers: X-Rate-Limit-Limit: $ref: '#/components/headers/RateLimitLimitHeader' X-Rate-Limit-Remaining: $ref: '#/components/headers/RateLimitRemainingHeader' X-Rate-Limit-Interval: $ref: '#/components/headers/RateLimitIntervalHeader' Digest: $ref: '#/components/headers/IntegrityRest02DigestHeader' Agid-JWT-Signature: $ref: '#/components/headers/IntegrityRest02AgidJwtSignatureHeader' BadRequest: description: Bad Request content: application/problem+json: schema: $ref: '#/components/schemas/Problem' headers: X-Rate-Limit-Limit: $ref: '#/components/headers/RateLimitLimitHeader' X-Rate-Limit-Remaining: $ref: '#/components/headers/RateLimitRemainingHeader' X-Rate-Limit-Interval: $ref: '#/components/headers/RateLimitIntervalHeader' Digest: $ref: '#/components/headers/IntegrityRest02DigestHeader' Agid-JWT-Signature: $ref: '#/components/headers/IntegrityRest02AgidJwtSignatureHeader' TooManyRequests: description: Too Many Requests content: application/problem+json: schema: $ref: '#/components/schemas/Problem' headers: X-Rate-Limit-Limit: $ref: '#/components/headers/RateLimitLimitHeader' X-Rate-Limit-Remaining: $ref: '#/components/headers/RateLimitRemainingHeader' X-Rate-Limit-Interval: $ref: '#/components/headers/RateLimitIntervalHeader' Digest: $ref: '#/components/headers/IntegrityRest02DigestHeader' Agid-JWT-Signature: $ref: '#/components/headers/IntegrityRest02AgidJwtSignatureHeader' headers: RateLimitRemainingHeader: schema: type: integer format: int32 minimum: 0 description: Remaining requests within time interval IntegrityRest02DigestHeader: schema: type: string pattern: ^SHA-256=[a-zA-Z0-9+/]{43}=$ description: 'Digest of the body using the canonical JSON representation of the response body. The digest is calculated using the SHA-256 algorithm on the response body exactly as it is sent to the client, encoded in Base64 as per RFC 3230 ' IntegrityRest02AgidJwtSignatureHeader: description: 'The `Agid-JWT-Signature` header contains a JSON Web Signature (JWS) signed with the PDND API private key. It ensures payload integrity and non-repudiation across all responses (both success and error), in compliance with: 1) Linee Guida sull''interoperabilità tecnica delle Pubbliche Amministrazioni - Pattern di sicurezza, 2) RFC 7515 and 3) RFC 7519. ' schema: type: string RateLimitLimitHeader: schema: type: integer format: int32 minimum: 0 description: Max allowed requests within time interval RateLimitIntervalHeader: schema: type: integer format: int32 minimum: 0 description: Time interval in milliseconds. Allowed requests will be constantly replenished during the interval. At the end of the interval the max allowed requests will be available parameters: LimitParam: in: query name: limit description: Maximum number of results to return required: true schema: type: integer format: int32 minimum: 1 maximum: 50 OffsetParam: in: query name: offset description: Pagination starting position required: true schema: type: integer format: int32 minimum: 0 schemas: Problem: properties: type: description: URI reference of type definition type: string status: description: The HTTP status code generated by the origin server for this occurrence of the problem example: 503 format: int32 minimum: 100 type: integer exclusiveMaximum: 600 title: description: A short, summary of the problem type. Written in english and readable example: Service Unavailable maxLength: 64 pattern: ^[ -~]{0,64}$ type: string correlationId: description: Unique identifier of the request example: 53af4f2d-0c87-41ef-a645-b726a821852b maxLength: 64 type: string detail: description: A human readable explanation of the problem example: Request took too long to complete maxLength: 4096 pattern: ^.{0,1024}$ type: string errors: type: array minItems: 1 items: $ref: '#/components/schemas/ProblemError' additionalProperties: false required: - type - status - title ProblemError: properties: code: description: Internal code of the error example: 123-4567 minLength: 8 maxLength: 8 pattern: ^[0-9]{3}-[0-9]{4}$ type: string detail: description: A human readable explanation specific to this occurrence of the problem example: Parameter not valid maxLength: 4096 pattern: ^.{0,1024}$ type: string required: - code - detail User: type: object additionalProperties: false description: User information properties: userId: type: string format: uuid description: User identifier name: type: string description: User first name familyName: type: string description: User last name roles: type: array items: type: string description: User roles required: - userId - name - familyName - roles Pagination: type: object additionalProperties: false properties: offset: type: integer format: int32 minimum: 0 limit: type: integer format: int32 minimum: 1 maximum: 50 totalCount: type: integer format: int32 minimum: 0 required: - offset - limit - totalCount Users: type: object additionalProperties: false description: Paginated list of users properties: results: type: array items: $ref: '#/components/schemas/User' pagination: $ref: '#/components/schemas/Pagination' required: - results - pagination securitySchemes: DPoPAuth: type: http scheme: DPoP description: 'This Authorization header must be used alongside the DPoP Proof JWT. Use: Authorization: DPoP The access token generated must also have a cnf field. ' DPoPProofHeader: type: apiKey in: header name: DPoP description: 'DPoP proof JWT for sender-constrained access. Must accompany the DPoP Authorization header. ' x-refined-from: - interop-api-v3.yaml - pagopa-pdnd-interop-v3-openapi.yml