openapi: 3.0.3 info: title: Windmill Apps OIDC API description: 'Windmill is an open-source developer platform that turns scripts into internal tools, UIs, workflows, and cron jobs, executed by a distributed worker fleet. This is a representative subset of the Windmill REST API - the same surface used by the Windmill CLI and web UI. The authoritative, machine-generated specification is served live at GET /openapi.yaml (see https://app.windmill.dev/openapi.html); this document curates the most commonly used, stable endpoints for discovery. Almost every resource is scoped under a workspace at the /w/{workspace} path prefix. Windmill runs as Windmill Cloud (base https://app.windmill.dev/api) or self-hosted (base http(s)://your-host/api). Requests are authenticated with a Bearer token created in the Windmill UI under account settings, or with a session cookie.' version: 1.745.0 contact: name: Windmill url: https://www.windmill.dev license: name: AGPL-3.0 (community) / Windmill Enterprise License url: https://github.com/windmill-labs/windmill/blob/main/LICENSE servers: - url: https://app.windmill.dev/api description: Windmill Cloud - url: http://localhost:8000/api description: Local development (self-hosted) security: - bearerAuth: [] - cookieAuth: [] tags: - name: OIDC description: Short-lived OIDC token issuance (Enterprise Edition). paths: /w/{workspace}/oidc/token: parameters: - $ref: '#/components/parameters/Workspace' post: operationId: generateOidcToken tags: - OIDC summary: Generate an OIDC token description: Mints a short-lived OIDC (JWT) token, scoped to the current job/identity, for authenticating to external cloud providers without long-lived secrets. Enterprise Edition feature. requestBody: required: false content: application/json: schema: type: object properties: audience: type: string responses: '200': description: The signed OIDC token. content: application/json: schema: type: string '401': $ref: '#/components/responses/Unauthorized' components: responses: Unauthorized: description: Missing or invalid Bearer token or session cookie. content: application/json: schema: $ref: '#/components/schemas/Error' parameters: Workspace: name: workspace in: path required: true description: The workspace id (tenant) the resource belongs to. schema: type: string schemas: Error: type: object properties: error: type: object properties: name: type: string message: type: string securitySchemes: bearerAuth: type: http scheme: bearer description: 'Bearer token created in the Windmill UI under account settings, passed as Authorization: Bearer YOUR_TOKEN.' cookieAuth: type: apiKey in: cookie name: token description: Session cookie set by the Windmill web UI after login.