openapi: 3.2.0 info: title: Token Authentication Web Service REST API V2 Crn API description: This is the API specification for V2 of the UW-IT Token Authentication Rest API. Note that there are header and querystring paramemters not documentered here (see also https://wiki.cac.washington.edu/x/GY6kB). The -type and -pretty querystring parameters are included here for GET requests since they make testing much easier. version: 2.0.0 servers: - url: https://taws.s.uw.edu:716/token/v2 tags: - name: Crn paths: /crn/{user}: get: tags: - Crn summary: The Crn endpoint returns the user's crn list description: The Crn endpoint returns the user's crn list for use in subsequent Preauth and Auth calls. parameters: - name: user in: path description: User identifier. Typically a UWNetID required: true schema: type: string format: string - name: -type in: query description: Data return type schema: type: string format: string default: json - name: -pretty in: query description: Request pretty-printed data for humans schema: type: boolean default: true responses: '200': description: An array of Crn objects content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/CrnGetResult' '400': description: Invalid user content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '404': description: User did not match any records content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '405': description: Method not allowed content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '406': description: Content type not supported content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '500': description: Internal Server Error content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '501': description: Not implemented content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '503': description: Service Unavailable content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' operationId: getCrnByUser x-operation-id-source: derived put: tags: - Crn summary: The Crn endpoint sets the user's crn list description: The Crn endpoint sets the user's crn list or can rename the user identifier. parameters: - name: user in: path description: User identifier. Typically a UWNetID required: true schema: type: string format: string - name: crns in: query description: User's crn list. schema: type: string format: string - name: new_user in: query description: User's new identifier. schema: type: string format: string - name: -type in: query description: Data return type schema: type: string format: string default: json - name: -pretty in: query description: Request pretty-printed data for humans schema: type: boolean default: true responses: '200': description: Success content: {} '400': description: Invalid user content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '404': description: User did not match any records content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '405': description: Method not allowed content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '406': description: Content type not supported content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '500': description: Internal Server Error content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '501': description: Not implemented content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '503': description: Service Unavailable content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' operationId: putCrnByUser x-operation-id-source: derived delete: tags: - Crn summary: The Crn endpoint deletes the user's crn list description: The Crn endpoint deletes the user's crn list. parameters: - name: user in: path description: User identifier. Typically a UWNetID required: true schema: type: string format: string - name: -type in: query description: Data return type schema: type: string format: string default: json - name: -pretty in: query description: Request pretty-printed data for humans schema: type: boolean default: true responses: '200': description: Success content: {} '400': description: Invalid user content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '404': description: User did not match any records content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '405': description: Method not allowed content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '406': description: Content type not supported content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '500': description: Internal Server Error content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '501': description: Not implemented content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' '503': description: Service Unavailable content: application/json; charset=UTF-8; v=2.0: schema: $ref: '#/components/schemas/Error' operationId: deleteCrnByUser x-operation-id-source: derived components: schemas: CrnGetResult: type: object properties: crn: type: array description: Array of crn objects matching search parameter items: type: object properties: user: type: string description: Unique identifier for a person. crns: type: string description: List of crn's for 2fa authentication Error: type: object properties: error: type: object properties: code: type: integer format: int32 message: type: string externalDocs: description: UW-IT Token Authentication Web Service (TAWS) V2 API documentation url: https://iam-tools.u.washington.edu/apis/tawsv2/ x-operator: institution x-provenance: method: searched source: https://iam-tools.u.washington.edu/apis/tawsv2/tawsv2.yaml generated: '2026-08-30' note: Fetched verbatim from the UW-IT IAM tools API documentation host on 2026-08-30 (HTTP 200). servers[] resolve to University of Washington registrable domains (uw.edu / washington.edu), so the operator is the institution, not a vendor. Only externalDocs, x-operator and x-provenance were added; info and paths are as published. pristine_copy: openapi/_original/university-of-washington-token-authentication-web-service-v2.yaml