openapi: 3.2.0 info: title: Sakura Internet SSO API version: 2.1.0 contact: name: SAKURA internet Inc. description: 'Operations tagged sso across 2 of this provider''s published API definitions: iam-api.yaml, sakura-internet-iam-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://secure.sakura.ad.jp/cloud/api/iam/1.0 security: - ServicePrincipalAuth: [] tags: - name: SSO x-displayName: SSO連携 description: SSO連携に関する機能 paths: /sso-profiles: get: operationId: listSsoProfiles tags: - SSO summary: SSOプロファイル一覧を取得する parameters: - $ref: '#/components/parameters/PaginationPage' - $ref: '#/components/parameters/PaginationPerPage' responses: '200': description: 成功 content: application/json: schema: allOf: - type: object required: - items properties: items: type: array items: $ref: '#/components/schemas/SSOProfile' - $ref: '#/components/schemas/Pagination' '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' post: operationId: createSsoProfile tags: - SSO summary: SSOプロファイルを作成する requestBody: description: IdPの情報 required: true content: application/json: schema: type: object required: - name - description - idp_entity_id - idp_login_url - idp_logout_url - idp_certificate properties: name: type: string description: SSOプロファイル名 example: SSOプロファイル1 description: type: string description: SSOプロファイルの説明 example: SSOプロファイル1の説明 idp_entity_id: type: string description: IdPのエンティティID idp_login_url: type: string description: IdPのログインURL idp_logout_url: type: string description: IdPのログアウトURL idp_certificate: type: string description: IdPのX.509証明書 examples: partial-fields: value: name: SSOプロファイル1 description: SSOプロファイル1の説明 idp_entity_id: '' idp_login_url: '' idp_logout_url: '' idp_certificate: '' summary: IdPの情報を後で設定する場合 complete-fields: value: name: SSOプロファイル1 description: SSOプロファイル1の説明 idp_entity_id: https://idp.example.com/ile2ephei7saeph6 idp_login_url: https://idp.example.com/ile2ephei7saeph6/sso/login idp_logout_url: https://idp.example.com/ile2ephei7saeph6/sso/logout idp_certificate: '-----BEGIN CERTIFICATE----- MIIDqjCCApKgAwIBA -----END CERTIFICATE-----' summary: 全てのフィールドを作成時に指定する場合 responses: '201': description: 成功 content: application/json: schema: $ref: '#/components/schemas/SSOProfile' '400': description: 不正なリクエスト content: application/json: schema: $ref: '#/components/schemas/Http400BadRequest' '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '409': description: 上限に達している content: application/json: schema: $ref: '#/components/schemas/Http409Conflict' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' servers: - url: https://secure.sakura.ad.jp/cloud/api/iam/1.0 /sso-profiles/{sso_profile_id}: parameters: - $ref: '#/components/parameters/SSOProfileID' get: operationId: readSsoProfile tags: - SSO summary: 指定したSSOプロファイルを取得する responses: '200': description: 成功 content: application/json: schema: $ref: '#/components/schemas/SSOProfile' '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '404': description: 指定したSSOプロファイルが存在しない content: application/json: schema: $ref: '#/components/schemas/Http404NotFound' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' put: operationId: updateSsoProfile tags: - SSO summary: 指定したSSOプロファイルを更新する requestBody: required: true content: application/json: schema: type: object required: - name - description - idp_entity_id - idp_login_url - idp_logout_url - idp_certificate properties: name: type: string description: SSOプロファイル名 example: SSOプロファイル1 description: type: string description: SSOプロファイルの説明 example: SSOプロファイル1の説明 idp_entity_id: type: string description: IdPのエンティティID example: https://idp.example.com/ile2ephei7saeph6 idp_login_url: type: string description: IdPのログインURL example: https://idp.example.com/ile2ephei7saeph6/sso/login idp_logout_url: type: string description: IdPのログアウトURL example: https://idp.example.com/ile2ephei7saeph6/sso/logout idp_certificate: type: string description: IdPのX.509証明書 example: '-----BEGIN CERTIFICATE----- MIIDqjCCApKgAwIBA -----END CERTIFICATE-----' responses: '200': description: 成功 content: application/json: schema: $ref: '#/components/schemas/SSOProfile' '400': description: 不正なリクエスト content: application/json: schema: $ref: '#/components/schemas/Http400BadRequest' '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '404': description: 指定したSSOプロファイルが存在しない content: application/json: schema: $ref: '#/components/schemas/Http404NotFound' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' delete: operationId: deleteSsoProfile tags: - SSO summary: 指定したSSOプロファイルを削除する responses: '204': description: 成功 '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '404': description: 指定したSSOプロファイルが存在しない content: application/json: schema: $ref: '#/components/schemas/Http404NotFound' '409': description: 割り当て済みのため削除できない content: application/json: schema: $ref: '#/components/schemas/Http409Conflict' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' servers: - url: https://secure.sakura.ad.jp/cloud/api/iam/1.0 /sso-profiles/{sso_profile_id}/assign: parameters: - $ref: '#/components/parameters/SSOProfileID' post: operationId: assignSsoProfile tags: - SSO summary: 指定したSSOプロファイルを割り当てる description: 割当を行うと会員配下のクラウドユーザすべてで該当SSOプロファイルが有効になります。 responses: '200': description: 成功 content: application/json: schema: $ref: '#/components/schemas/SSOProfile' '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '404': description: 指定したSSOプロファイルが存在しない content: application/json: schema: $ref: '#/components/schemas/Http404NotFound' '409': description: '以下のいずれかの理由で失敗 - 他に割り当て済みのSSOプロファイルがあるため割り当てできない - 設定が不十分なSSOプロファイルを割り当てようとしている ' content: application/json: schema: $ref: '#/components/schemas/Http409Conflict' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' servers: - url: https://secure.sakura.ad.jp/cloud/api/iam/1.0 /sso-profiles/{sso_profile_id}/unassign: parameters: - $ref: '#/components/parameters/SSOProfileID' post: operationId: unassignSsoProfile tags: - SSO summary: 指定したSSOプロファイルの割り当てを外す responses: '200': description: 成功 content: application/json: schema: $ref: '#/components/schemas/SSOProfile' '401': description: 認証情報が無効 content: application/json: schema: $ref: '#/components/schemas/Http401Unauthorized' '403': description: アクセス権限がない content: application/json: schema: $ref: '#/components/schemas/Http403Forbidden' '404': description: 指定したSSOプロファイルが存在しない content: application/json: schema: $ref: '#/components/schemas/Http404NotFound' '429': description: APIリクエストのレートリミット超過 content: application/json: schema: $ref: '#/components/schemas/Http429TooManyRequests' servers: - url: https://secure.sakura.ad.jp/cloud/api/iam/1.0 components: schemas: Http404NotFound: type: object required: - type - status - title - detail properties: type: type: string description: 問題を説明するドキュメントへのURI(基本的にはabout:blank) example: about:blank status: type: integer description: HTTPステータスコード example: 404 title: type: string description: 問題を表す簡単な文字列 example: not_found detail: type: string description: 問題の詳細を説明した文字列(人が読んで問題解決に繋がるような説明) example: 見つかりませんでした。 Http429TooManyRequests: type: object required: - type - status - title - detail properties: type: type: string description: 問題を説明するドキュメントへのURI(基本的にはabout:blank) example: about:blank status: type: integer description: HTTPステータスコード example: 429 title: type: string description: 問題を表す簡単な文字列 example: throttled detail: type: string description: 問題の詳細を説明した文字列(人が読んで問題解決に繋がるような説明) example: リクエストの処理は絞られました。 60秒後に利用可能になります。 SSOProfile: type: object required: - id - name - description - sp_entity_id - sp_acs_url - idp_entity_id - idp_login_url - idp_logout_url - idp_certificate - assigned - created_at - updated_at properties: id: type: integer description: SSOプロファイルID readOnly: true example: 1 name: type: string description: SSOプロファイル名 example: SSOプロファイル1 description: type: string description: SSOプロファイルの説明 example: SSOプロファイル1の説明 sp_entity_id: type: string description: SPのエンティティID readOnly: true example: https://sp.example.com/samlrp/ang5eizeevahvooy sp_acs_url: type: string description: SPのAssertion Consumer Service URL readOnly: true example: https://sp.example.com/samlrp/ang5eizeevahvooy/acs idp_entity_id: type: string description: IdPのエンティティID example: https://idp.example.com/ile2ephei7saeph6 idp_login_url: type: string description: IdPのログインURL example: https://idp.example.com/ile2ephei7saeph6/sso/login idp_logout_url: type: string description: IdPのログアウトURL example: https://idp.example.com/ile2ephei7saeph6/sso/logout idp_certificate: type: string description: IdPのX.509証明書 example: '-----BEGIN CERTIFICATE----- MIIDqjCCApKgAwIBA -----END CERTIFICATE-----' assigned: type: boolean description: このプロファイルを割り当ているかどうか readOnly: true created_at: type: string description: 作成日時 readOnly: true example: 2024-05-01 14:30:00+00:00 updated_at: type: string description: 更新日時 readOnly: true example: 2024-05-02 14:30:00+00:00 Http409Conflict: type: object required: - type - status - title - detail properties: type: type: string description: 問題を説明するドキュメントへのURI(基本的にはabout:blank) example: about:blank status: type: integer description: HTTPステータスコード example: 409 title: type: string description: 問題を表す簡単な文字列 example: conflict detail: type: string description: 問題の詳細を説明した文字列(人が読んで問題解決に繋がるような説明) example: 状態の競合によりリクエストを処理できません。 Http403Forbidden: type: object required: - type - status - title - detail properties: type: type: string description: 問題を説明するドキュメントへのURI(基本的にはabout:blank) example: about:blank status: type: integer description: HTTPステータスコード example: 403 title: type: string description: 問題を表す簡単な文字列 example: permission_denied detail: type: string description: 問題の詳細を説明した文字列(人が読んで問題解決に繋がるような説明) example: このアクションを実行する権限がありません。 Http400BadRequest: type: object required: - type - status - title - detail - errors properties: type: type: string description: 問題を説明するドキュメントへのURI(基本的にはabout:blank) example: about:blank status: type: integer description: HTTPステータスコード example: 400 title: type: string description: 問題を表す簡単な文字列 example: invalid detail: type: string description: 問題の詳細を説明した文字列(人が読んで問題解決に繋がるような説明) example: 不正な入力です。 errors: type: object additionalProperties: type: array items: type: object required: - message - code properties: message: type: string description: エラー内容を説明した文字列 code: type: string description: エラーの内容を表す文字列 description: リクエストボディの特定キーに関するエラー properties: non_field_errors: type: array items: type: object required: - message - code properties: message: type: string description: エラー内容を説明した文字列 code: type: string description: エラーの内容を表す文字列 description: リクエストボディの特定キーに関係しないエラー example: key1: - message: この項目は必須です。 code: required key2: - message: 有効な値ではありません。 code: invalid key3: - message: この項目は少なくとも*文字以上にしてください。 code: min_length key4: - message: この項目が*文字より長くならないようにしてください。 code: max_length Pagination: type: object required: - count - next - previous properties: count: type: integer description: データ総数 example: 100 next: type: - string - 'null' format: uri description: 次のページへのURL example: https://api.example.com/?page=3&per_page=10 previous: type: - string - 'null' format: uri description: 前のページへのURL example: https://api.example.com/?per_page=10 Http401Unauthorized: type: object required: - type - status - title - detail properties: type: type: string description: 問題を説明するドキュメントへのURI(基本的にはabout:blank) example: about:blank status: type: integer description: HTTPステータスコード example: 401 title: type: string description: 問題を表す簡単な文字列 example: authentication_failed detail: type: string description: 問題の詳細を説明した文字列(人が読んで問題解決に繋がるような説明) example: 認証情報が含まれていません。 parameters: PaginationPage: in: query name: page schema: type: integer SSOProfileID: in: path name: sso_profile_id description: SSOプロファイルID required: true schema: type: integer PaginationPerPage: in: query name: per_page schema: type: integer securitySchemes: ServicePrincipalAuth: description: 'サービスプリンシパル認証 - サービスプリンシパルのアクセストークンを指定 ' type: http scheme: bearer ProjectApiKeyAuth: description: 'APIキー認証 - ユーザー名に発行したAPIキーのアクセストークンを指定 - パスワードに発行したAPIキーのアクセストークンシークレットを指定 ' type: http scheme: basic x-refined-from: - iam-api.yaml - sakura-internet-iam-openapi.yml