API reference
Every HTTP endpoint of the rbac module: authentication, IAM action, parameters, bodies and status codes.
Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.
Admin Boundary Trusts
GET /admin/boundary-trusts
- Authentication: required
- IAM action:
rbac/boundaryTrusts/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
query | uuid |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/boundaryTrusts/admin at the evaluated scope |
POST /admin/boundary-trusts
- Authentication: required
- IAM action:
rbac/boundaryTrusts/admin— evaluated at the platform root
Request body: CreateTrustRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/boundaryTrusts/admin at the evaluated scope |
DELETE /admin/boundary-trusts/{trustId}
- Authentication: required
- IAM action:
rbac/boundaryTrusts/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
trustId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/boundaryTrusts/admin at the evaluated scope |
Admin IAM Members
POST /admin/iam/members
- Authentication: required
- IAM action:
rbac/members/admin— evaluated at the platform root
Request body: AddMemberRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/admin at the evaluated scope |
DELETE /admin/iam/members/{userId}/{tenantId}
- Authentication: required
- IAM action:
rbac/members/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
userId |
path | uuid |
Yes |
tenantId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/admin at the evaluated scope |
Admin IdP Bindings
GET /admin/tenants/{tenantId}/idp-bindings
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
POST /admin/tenants/{tenantId}/idp-bindings
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
Request body: CreateBindingRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
DELETE /admin/tenants/{tenantId}/idp-bindings/{bindingId}
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
bindingId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
Admin Tenant SSO
GET /admin/tenants/{tenantId}/sso
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
PUT /admin/tenants/{tenantId}/sso/domains
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
Request body: SetSsoDomainsRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
POST /admin/tenants/{tenantId}/sso/identity-providers
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
Request body: CreateSsoIdentityProviderRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
DELETE /admin/tenants/{tenantId}/sso/identity-providers/{alias}
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
alias |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
PATCH /admin/tenants/{tenantId}/sso/identity-providers/{alias}
- Authentication: required
- IAM action:
rbac/idpBindings/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
tenantId |
path | uuid |
Yes |
alias |
path | string |
Yes |
Request body: any
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/idpBindings/admin at the evaluated scope |
Admin Users
GET /admin/users
- Authentication: required
Parameters
| Name | In | Type | Required |
|---|---|---|---|
max |
query | integer |
No |
search |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /admin/users/{userId}
- Authentication: required
Parameters
| Name | In | Type | Required |
|---|---|---|---|
userId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Boundary Groups
POST /boundaries/{boundaryId}/providers/authorization/groups
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateBoundaryGroupRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
Boundary Invitations
GET /boundaries/{boundaryId}/providers/authorization/invitations
- Authentication: required
- IAM action:
boundaries/invitations/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
status |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/invitations/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/invitations
- Authentication: required
- IAM action:
boundaries/invitations/create— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateInvitationRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/invitations/create at the evaluated scope |
DELETE /boundaries/{boundaryId}/providers/authorization/invitations/{invitationId}
- Authentication: required
- IAM action:
boundaries/invitations/create— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
invitationId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/invitations/create at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/invitations/{invitationId}/resend
- Authentication: required
- IAM action:
boundaries/invitations/create— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
invitationId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/invitations/create at the evaluated scope |
Boundary purge
POST /boundaries/{boundaryId}/providers/authorization/purge
Remove every role/deny assignment, invitation and JIT request scoped to a boundary
- Authentication: required
- IAM action:
boundaries/delete— evaluated at the platform root - Operation name:
PurgeBoundaryRbac
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/delete at the evaluated scope |
Boundary tenant move
POST /boundaries/{boundaryId}/providers/authorization/tenant-move
Add a boundary's people to its new tenant, retag its groups and retarget its open invitations
- Authentication: required
- IAM action:
boundaries/tenant/admin— evaluated at the platform root - Operation name:
MoveBoundaryTenantRbac
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: BoundaryTenantMoveRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/tenant/admin at the evaluated scope |
Check Access
POST /boundaries/{boundaryId}/providers/authorization/checkAccess
- Authentication: required
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CheckAccessRequestDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Deny Assignments
GET /boundaries/{boundaryId}/providers/authorization/denyAssignments
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
principalId |
query | uuid |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/denyAssignments
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateDenyAssignmentRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/providers/authorization/denyAssignments/{denyId}
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
denyId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
GET /boundaries/{boundaryId}/providers/authorization/denyAssignments/{denyId}
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
denyId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
Docs
GET /docs/rbac/manifest.json
- Authentication: required
- Operation name:
DocsManifest_rbac
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /docs/rbac/{path}
- Authentication: required
- Operation name:
DocsFile_rbac
Parameters
| Name | In | Type | Required |
|---|---|---|---|
path |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
IAM Members
GET /boundaries/{boundaryId}/iam/members
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
DELETE /boundaries/{boundaryId}/iam/members/{userId}
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
userId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
IAM Projector
GET /iam/projector-manifest
The RBAC a cluster needs before the platform can project IAM into it.
- Authentication: required
- IAM action:
rbac/projector/read— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
namespace |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/projector/read at the evaluated scope |
POST /iam/projector-manifest/apply
Applies that RBAC to every cluster, as the caller.
- Authentication: required
- IAM action:
rbac/projector/apply— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
namespace |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/projector/apply at the evaluated scope |
GET /iam/projector-manifest/status
Whether any cluster still needs the projector manifest applied.
- Authentication: required
- IAM action:
rbac/projector/read— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
namespace |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/projector/read at the evaluated scope |
IAM SSO
GET /boundaries/{boundaryId}/iam/sso
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
Invitations (Redeem)
POST /invitations/accept
- Authentication: required
Request body: AcceptInvitationRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /invitations/password-policy
- Authentication: none — anonymous callers are accepted
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
GET /invitations/{token}
- Authentication: none — anonymous callers are accepted
Parameters
| Name | In | Type | Required |
|---|---|---|---|
token |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
POST /invitations/{token}/set-password
- Authentication: none — anonymous callers are accepted
Parameters
| Name | In | Type | Required |
|---|---|---|---|
token |
path | string |
Yes |
Request body: SetInvitationPasswordRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
JIT Access Requests
GET /boundaries/{boundaryId}/providers/authorization/jitAccessRequests
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
principalId |
query | uuid |
No |
status |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/jitAccessRequests
- Authentication: required
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateJitAccessRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /boundaries/{boundaryId}/providers/authorization/jitAccessRequests/{jitId}
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
jitId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/jitAccessRequests/{jitId}/activate
- Authentication: required
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
jitId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
POST /boundaries/{boundaryId}/providers/authorization/jitAccessRequests/{jitId}/approve
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
jitId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/jitAccessRequests/{jitId}/decline
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
jitId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/jitAccessRequests/{jitId}/revoke
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
jitId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
MCP Registration (Admin)
GET /admin/mcp-trusted-hosts
- Authentication: required
- IAM action:
kernel/mcpSettings/manage— evaluated at the platform root - Operation name:
GetMcpTrustedHosts
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold kernel/mcpSettings/manage at the evaluated scope |
PUT /admin/mcp-trusted-hosts
- Authentication: required
- IAM action:
kernel/mcpSettings/manage— evaluated at the platform root - Operation name:
SetMcpTrustedHosts
Request body: SetTrustedHostsRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold kernel/mcpSettings/manage at the evaluated scope |
Password reset
POST /identity/change-password
- Authentication: required
Request body: ChangePasswordRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /identity/password-policy
- Authentication: none — anonymous callers are accepted
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
POST /identity/password-reset
- Authentication: none — anonymous callers are accepted
Request body: RequestPasswordResetRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
GET /identity/password-reset/{token}
- Authentication: none — anonymous callers are accepted
Parameters
| Name | In | Type | Required |
|---|---|---|---|
token |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
POST /identity/password-reset/{token}
- Authentication: none — anonymous callers are accepted
Parameters
| Name | In | Type | Required |
|---|---|---|---|
token |
path | string |
Yes |
Request body: CompletePasswordResetRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK |
Permissions
GET /providers/authorization/permissions
- Authentication: required
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Principals
GET /boundaries/{boundaryId}/providers/authorization/principals
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
includeOtherTenants |
query | boolean |
No |
max |
query | integer |
No |
membersOnly |
query | boolean |
No |
search |
query | string |
No |
type |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
GET /boundaries/{boundaryId}/providers/authorization/principals/{principalId}
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
principalId |
path | uuid |
Yes |
type |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
Role Assignments
GET /boundaries/{boundaryId}/providers/authorization/roleAssignments
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
actionPrefix |
query | string |
No |
principalId |
query | uuid |
No |
scope |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/roleAssignments
- Authentication: required
- IAM action:
rbac/members/write— evaluated at a scope the endpoint resolves from the request
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateRoleAssignmentRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/providers/authorization/roleAssignments/{assignmentId}
- Authentication: required
- IAM action:
rbac/members/write— evaluated at a scope the endpoint resolves from the request
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
assignmentId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
GET /boundaries/{boundaryId}/providers/authorization/roleAssignments/{assignmentId}
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
assignmentId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
Role Definitions
GET /boundaries/{boundaryId}/providers/authorization/roleDefinitions
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/roleDefinitions
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateRoleDefinitionRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/providers/authorization/roleDefinitions/{roleDefId}
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
roleDefId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
GET /boundaries/{boundaryId}/providers/authorization/roleDefinitions/{roleDefId}
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
roleDefId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
PUT /boundaries/{boundaryId}/providers/authorization/roleDefinitions/{roleDefId}
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
roleDefId |
path | uuid |
Yes |
Request body: UpdateRoleDefinitionRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
Service Accounts
GET /boundaries/{boundaryId}/providers/authorization/service-accounts
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
search |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/service-accounts
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateServiceAccountRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/providers/authorization/service-accounts/{id}
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
id |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
GET /boundaries/{boundaryId}/providers/authorization/service-accounts/{id}
- Authentication: required
- IAM action:
rbac/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
id |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/providers/authorization/service-accounts/{id}/rotate-secret
- Authentication: required
- IAM action:
rbac/members/write— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
id |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold rbac/members/write at the evaluated scope |
Other endpoints
GET /readyz
- Authentication: none — anonymous callers are accepted
- Operation name:
StackshipReadiness
Responses
| Status | Meaning | Body |
|---|
Schemas
AcceptInvitationRequest
| Property | Type | Nullable |
|---|---|---|
token |
string |
No |
AddMemberRequest
| Property | Type | Nullable |
|---|---|---|
tenantId |
uuid |
No |
userId |
uuid |
No |
BoundaryTenantMoveRequest
| Property | Type | Nullable |
|---|---|---|
fromTenantId |
uuid |
No |
toTenantId |
uuid |
No |
ChangePasswordRequest
| Property | Type | Nullable |
|---|---|---|
password |
string |
No |
CheckAccessItem
| Property | Type | Nullable |
|---|---|---|
action |
string |
No |
isDataAction |
boolean |
No |
scope |
string |
Yes |
CheckAccessRequestDto
| Property | Type | Nullable |
|---|---|---|
items |
CheckAccessItem [] |
No |
CompletePasswordResetRequest
| Property | Type | Nullable |
|---|---|---|
password |
string |
No |
CreateBindingRequest
| Property | Type | Nullable |
|---|---|---|
keycloakIdpAlias |
string |
No |
CreateBoundaryGroupRequest
| Property | Type | Nullable |
|---|---|---|
name |
string |
No |
roleDefinitionId |
uuid |
No |
scope |
string |
Yes |
CreateDenyAssignmentRequest
| Property | Type | Nullable |
|---|---|---|
actions |
string [] |
No |
applyToChildScopes |
boolean |
No |
dataActions |
string [] |
Yes |
description |
string |
Yes |
excludePrincipals |
uuid [] |
Yes |
name |
string |
No |
notActions |
string [] |
Yes |
notDataActions |
string [] |
Yes |
principals |
uuid [] |
No |
scope |
string |
No |
CreateInvitationRequest
| Property | Type | Nullable |
|---|---|---|
email |
string |
No |
roleDefinitionName |
string |
No |
scope |
string |
Yes |
CreateJitAccessRequest
| Property | Type | Nullable |
|---|---|---|
deduplicate |
boolean |
No |
justification |
string |
No |
requestedDuration |
string |
No |
roleDefinitionId |
uuid |
No |
scope |
string |
No |
CreateRoleAssignmentRequest
| Property | Type | Nullable |
|---|---|---|
principalId |
uuid |
No |
principalType |
string |
Yes |
roleDefinitionId |
uuid |
No |
scope |
string |
No |
CreateRoleDefinitionRequest
| Property | Type | Nullable |
|---|---|---|
actions |
string [] |
No |
assignableScopes |
string [] |
Yes |
dataActions |
string [] |
Yes |
description |
string |
Yes |
name |
string |
No |
notActions |
string [] |
Yes |
notDataActions |
string [] |
Yes |
CreateServiceAccountRequest
| Property | Type | Nullable |
|---|---|---|
description |
string |
Yes |
name |
string |
No |
CreateSsoIdentityProviderRequest
| Property | Type | Nullable |
|---|---|---|
alias |
string |
Yes |
clientId |
string |
Yes |
clientSecret |
string |
Yes |
discoveryUrl |
string |
Yes |
displayName |
string |
Yes |
domain |
string |
Yes |
metadataUrl |
string |
Yes |
redirectWhenEmailMatches |
boolean |
No |
type |
string |
Yes |
CreateTrustRequest
| Property | Type | Nullable |
|---|---|---|
reason |
string |
No |
sourceBoundaryId |
uuid |
No |
targetBoundaryId |
uuid |
No |
RequestPasswordResetRequest
| Property | Type | Nullable |
|---|---|---|
email |
string |
No |
SetInvitationPasswordRequest
| Property | Type | Nullable |
|---|---|---|
firstName |
string |
Yes |
lastName |
string |
Yes |
password |
string |
No |
SetSsoDomainsRequest
| Property | Type | Nullable |
|---|---|---|
domains |
string [] |
Yes |
SetTrustedHostsRequest
| Property | Type | Nullable |
|---|---|---|
hosts |
string [] |
Yes |
UpdateRoleDefinitionRequest
| Property | Type | Nullable |
|---|---|---|
actions |
string [] |
No |
assignableScopes |
string [] |
Yes |
dataActions |
string [] |
Yes |
description |
string |
Yes |
name |
string |
No |
notActions |
string [] |
Yes |
notDataActions |
string [] |
Yes |