openapi: 3.2.0 info: title: Yugabytedb User Management API version: v1 contact: name: https://docs.yugabyte.com license: name: Polyform Free Trial License 1.0.0 url: https://github.com/yugabyte/yugabyte-db/blob/master/licenses/POLYFORM-FREE-TRIAL-LICENSE-1.0.0.txt termsOfService: TODO(chirag) description: 'Operations tagged User management across 2 of this provider''s published API definitions: openapi_2.yaml, platform.swagger.json. Each path carries the servers of the definition it was published in.' servers: - url: / tags: - name: User Management paths: /api/v1/customers/{cUUID}/reset_password: servers: - url: / put: operationId: resetUserPassword parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: query name: request schema: {} requestBody: content: application/json: schema: $ref: '#/components/schemas/UserPasswordChangeFormData' description: User data containing the current, new password required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/YBPSuccess' description: successful operation security: - apiKeyAuth: [] summary: Reset the user's password tags: - User Management x-codegen-request-body-name: Users /api/v1/customers/{cUUID}/users: servers: - url: / get: operationId: listUsers parameters: - in: path name: cUUID required: true schema: format: uuid type: string - description: Optional email to filter user list in: query name: email schema: default: 'null' type: string responses: '200': content: application/json: schema: items: $ref: '#/components/schemas/UserWithFeatures' type: array description: successful operation security: - apiKeyAuth: [] summary: List all users tags: - User Management post: operationId: createUser parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: query name: request schema: {} requestBody: content: application/json: schema: $ref: '#/components/schemas/UserRegistrationData' description: Details of the new user required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/UserWithFeatures' description: successful operation security: - apiKeyAuth: [] summary: Create a user tags: - User Management x-codegen-request-body-name: User /api/v1/customers/{cUUID}/users/{uUUID}: servers: - url: / delete: description: Deletes the specified user. Note that you can't delete a customer's primary user. operationId: deleteUser parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: path name: uUUID required: true schema: format: uuid type: string - in: query name: request schema: {} responses: '200': content: application/json: schema: $ref: '#/components/schemas/YBPSuccess' description: successful operation security: - apiKeyAuth: [] summary: Delete a user tags: - User Management get: operationId: getUserDetails parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: path name: uUUID required: true schema: format: uuid type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/UserWithFeatures' description: successful operation security: - apiKeyAuth: [] summary: Get a user's details tags: - User Management put: deprecated: true description: 'Deprecated. Use this method instead: setRoleBinding.' operationId: updateUserRole parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: path name: uUUID required: true schema: format: uuid type: string - in: query name: role schema: type: string - in: query name: request schema: {} responses: '200': content: application/json: schema: $ref: '#/components/schemas/YBPSuccess' description: successful operation security: - apiKeyAuth: [] summary: Change a user's role tags: - User Management /api/v1/customers/{cUUID}/users/{uUUID}/change_password: servers: - url: / put: deprecated: true description: Deprecated since YBA version 2024.1.0.0. operationId: changePassword parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: path name: uUUID required: true schema: format: uuid type: string - in: query name: request schema: {} requestBody: content: application/json: schema: $ref: '#/components/schemas/UserRegistrationData' description: User data containing the new password required: true responses: default: content: {} description: successful operation security: - apiKeyAuth: [] summary: Change password - deprecated tags: - User Management x-codegen-request-body-name: Users /api/v1/customers/{cUUID}/users/{uUUID}/oidc_auth_token: servers: - url: / get: operationId: retrieveOIDCAuthToken parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: path name: uUUID required: true schema: format: uuid type: string - in: query name: request schema: {} responses: '200': content: application/json: schema: $ref: '#/components/schemas/UserOIDCAuthToken' description: successful operation security: - apiKeyAuth: [] summary: Retrieve OIDC auth token tags: - User Management /api/v1/customers/{cUUID}/users/{uUUID}/update_profile: servers: - url: / put: operationId: UpdateUserProfile parameters: - in: path name: cUUID required: true schema: format: uuid type: string - in: path name: uUUID required: true schema: format: uuid type: string - in: query name: request schema: {} requestBody: content: application/json: schema: $ref: '#/components/schemas/UserProfileData' description: User data in profile to be updated required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/Users' description: successful operation security: - apiKeyAuth: [] summary: Update a user's profile tags: - User Management x-codegen-request-body-name: Users components: schemas: RoleResourceDefinition: description: Defines the association of Role to Resource Groups. example: resourceGroup: resourceDefinitionSet: - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE roleUUID: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 properties: resourceGroup: $ref: '#/components/schemas/ResourceGroup' roleUUID: description: UUID of the role to attach resource group to. format: uuid type: string required: - roleUUID type: object ResourceDefinition: example: allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE properties: allowAll: description: Select all resources (including future resources) type: boolean resourceType: description: Resource Type enum: - UNIVERSE - ROLE - USER - OTHER type: string resourceUUIDSet: description: Set of resource uuids items: format: uuid type: string type: array uniqueItems: true type: object UserRegistrationData: description: User registration data. The API and UI use this to validate form data. example: features: key: '{}' password: Test@1234 role: Admin timezone: America/Toronto confirmPassword: Test@1234 roleResourceDefinitions: - resourceGroup: resourceDefinitionSet: - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE roleUUID: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - resourceGroup: resourceDefinitionSet: - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE roleUUID: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 email: test@example.com properties: confirmPassword: description: Password confirmation example: Test@1234 type: string email: description: Email address example: test@example.com type: string features: additionalProperties: properties: {} type: object description: User features type: object password: description: Password example: Test@1234 type: string role: description: Deprecated since YBA version 2.19.3.0. Use field roleResourceDefinitions instead. enum: - ConnectOnly - ReadOnly - BackupAdmin - Admin - SuperAdmin example: Admin type: string roleResourceDefinitions: description: List of roles and resource groups defined for user. items: $ref: '#/components/schemas/RoleResourceDefinition' type: array timezone: description: User timezone example: America/Toronto type: string required: - email type: object UserPasswordChangeFormData: description: User registration data. The API and UI use this to validate form data. example: newPassword: Test@1234 currentPassword: Test@1234 properties: currentPassword: description: Current Password example: Test@1234 type: string newPassword: description: New Password example: Test@1234 type: string type: object UserOIDCAuthToken: example: oidcAuthToken: oidcAuthToken properties: oidcAuthToken: description: User OIDC Auth token type: string type: object YBPSuccess: example: success: true message: message properties: message: description: API response message. readOnly: true type: string success: description: API operation status. A value of true indicates the operation was successful. readOnly: true type: boolean type: object UserProfileData: description: User profile data. The API and UI use this to validate form data. example: password: Test@1234 role: Admin timezone: America/Toronto confirmPassword: Test@1234 properties: confirmPassword: description: Password confirmation example: Test@1234 type: string password: description: Password example: Test@1234 type: string role: description: User role enum: - ConnectOnly - ReadOnly - BackupAdmin - Admin - SuperAdmin example: Admin type: string timezone: description: User timezone example: America/Toronto type: string required: - role type: object Users: description: A user associated with a customer example: ldapSpecifiedRole: true customerUUID: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 role: Admin authTokenIssueDate: 2021-06-17 15:00:05+00:00 timezone: timezone oidcJwtAuthToken: oidcJwtAuthToken groupMemberships: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 userType: local creationDate: 2022-12-12 13:07:18+00:00 uuid: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 email: username1@example.com primary: true properties: authTokenIssueDate: description: UI session token creation date example: 2021-06-17 15:00:05+00:00 format: date-time readOnly: true type: string creationDate: description: User creation date example: 2022-12-12 13:07:18+00:00 format: date-time readOnly: true type: string customerUUID: description: Customer UUID format: uuid readOnly: true type: string email: description: User email address example: username1@example.com type: string groupMemberships: items: format: uuid type: string type: array uniqueItems: true ldapSpecifiedRole: description: LDAP Specified Role type: boolean oidcJwtAuthToken: readOnly: true type: string primary: type: boolean role: description: Deprecated since YBA version 2.19.3.0. Use getRoleBindings instead. enum: - ConnectOnly - ReadOnly - BackupAdmin - Admin - SuperAdmin example: Admin type: string timezone: description: User timezone type: string userType: description: User Type enum: - local - ldap - oidc type: string uuid: description: User UUID format: uuid readOnly: true type: string required: - email - groupMemberships - primary type: object ResourceGroup: example: resourceDefinitionSet: - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE - allowAll: true resourceUUIDSet: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 resourceType: UNIVERSE properties: resourceDefinitionSet: items: $ref: '#/components/schemas/ResourceDefinition' type: array uniqueItems: true required: - resourceDefinitionSet type: object UserWithFeatures: description: A user with set of features, associated with a customer example: ldapSpecifiedRole: true customerUUID: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 role: Admin authTokenIssueDate: 2021-06-17 15:00:05+00:00 timezone: timezone oidcJwtAuthToken: oidcJwtAuthToken groupMemberships: - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 - 046b6c7f-0b8a-43b9-b35d-6489e6daee91 userType: local creationDate: 2022-12-12 13:07:18+00:00 uuid: 046b6c7f-0b8a-43b9-b35d-6489e6daee91 email: username1@example.com primary: true properties: authTokenIssueDate: description: UI session token creation date example: 2021-06-17 15:00:05+00:00 format: date-time readOnly: true type: string creationDate: description: User creation date example: 2022-12-12 13:07:18+00:00 format: date-time readOnly: true type: string customerUUID: description: Customer UUID format: uuid readOnly: true type: string email: description: User email address example: username1@example.com type: string groupMemberships: items: format: uuid type: string type: array uniqueItems: true ldapSpecifiedRole: description: LDAP Specified Role type: boolean oidcJwtAuthToken: readOnly: true type: string primary: type: boolean role: description: Deprecated since YBA version 2.19.3.0. Use getRoleBindings instead. enum: - ConnectOnly - ReadOnly - BackupAdmin - Admin - SuperAdmin example: Admin type: string timezone: description: User timezone type: string userType: description: User Type enum: - local - ldap - oidc type: string uuid: description: User UUID format: uuid readOnly: true type: string required: - email - groupMemberships - primary type: object securitySchemes: apiKeyAuth: description: API token passed as header in: header name: X-AUTH-YW-API-TOKEN type: apiKey externalDocs: description: About YugabyteDB Anywhere url: https://docs.yugabyte.com/latest/yugabyte-platform/ x-refined-from: - openapi_2.yaml - platform.swagger.json