providers

5 endpoints.

GET/api/providers Bearer token

List the sign-in providers

Every registered OpenID Connect provider, disabled ones included. Rows name the env vars their secrets live in; the secrets themselves are never served.

Responses

StatusDescriptionBody
200The registered providers, oldest first.SignInProviderList
401The access token is missing or invalid.ErrorResponse
500The provider catalogue could not be read.ErrorResponse
POST/api/providers Bearer token

Register a sign-in provider

Registers an OpenID Connect provider whose sign-ins and access tokens this deployment accepts. Secrets stay in the environment: the row names the variables to read. Requires a superuser's access token.

Request body

application/jsonrequiredCreateSignInProviderRequest
FieldTypeRequiredDescription
slugstringyes

at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

display_namestringyes

1–200 characters

issuer_urlstring (uri)yes

at most 500 characters

client_idstringyes

1–500 characters

client_auth_methodstringyes

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none"

client_secret_envstringno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

client_private_key_envstringno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

client_assertion_algorithmstringno

1–20 characters

client_key_idstringno

1–200 characters

audiencestringno

1–500 characters

request_resourcebooleanno

Defaults to false. Requires an audience.

introspection_client_idstring | nullno

Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity.

1–500 characters

introspection_auth_methodstring | nullno

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null

introspection_client_secret_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

introspection_private_key_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

introspection_client_assertion_algorithmstring | nullno

1–20 characters

introspection_client_key_idstring | nullno

1–200 characters

login_scopestringno

Defaults to "openid profile email".

1–500 characters

access_token_algorithmsarray of stringno

Omit to accept the default algorithm set.

at most 20 items

email_verification_strictnessstringno

Defaults to "reject_unverified".

one of "lenient" | "reject_unverified" | "require_verified"

Responses

StatusDescriptionBody
201The registered provider.SignInProvider
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
409The slug or issuer is taken.ErrorResponse
500The provider catalogue could not be written to.ErrorResponse
GET/api/providers/{provider_id} Bearer token

Read one sign-in provider

Parameters

NameInTypeRequiredDescription
provider_idpathstringyesProvider UUID id or slug.

Responses

StatusDescriptionBody
200The provider.SignInProvider
401The access token is missing or invalid.ErrorResponse
404No provider has that id or slug.ErrorResponse
500The provider catalogue could not be read.ErrorResponse
PATCH/api/providers/{provider_id} Bearer token

Update a sign-in provider

Changes a provider's settings; omitted fields keep their values. Disabling a provider stops its sign-ins and token verification while keeping its identities. Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
provider_idpathstringyesProvider UUID id or slug.

Request body

application/jsonrequiredUpdateSignInProviderRequest
FieldTypeRequiredDescription
slugstringno

at most 100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

display_namestringno

1–200 characters

issuer_urlstring (uri)no

at most 500 characters

client_idstringno

1–500 characters

enabledbooleanno—
client_auth_methodstringno

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none"

client_secret_envstring | nullno

Omit to keep the current value; null clears it.

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

client_private_key_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

client_assertion_algorithmstring | nullno

1–20 characters

client_key_idstring | nullno

1–200 characters

audiencestring | nullno

1–500 characters

request_resourcebooleanno—
introspection_client_idstring | nullno

Introspect tokens as this client instead of the login client (an API server id, on a SchemaVaults auth server). The introspection_* fields are replaced together: send this with the others; null (on update) drops the identity.

1–500 characters

introspection_auth_methodstring | nullno

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null

introspection_client_secret_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

introspection_private_key_envstring | nullno

at most 200 characters · matches ^[A-Z_][A-Z0-9_]*$

introspection_client_assertion_algorithmstring | nullno

1–20 characters

introspection_client_key_idstring | nullno

1–200 characters

login_scopestringno

1–500 characters

access_token_algorithmsarray of stringno

at most 20 items

email_verification_strictnessstringno

How the provider's `email_verified` claim gates claiming a pending email link at sign-in: `lenient` links regardless, `reject_unverified` links unless the claim is explicitly false, `require_verified` links only when it is explicitly true.

one of "lenient" | "reject_unverified" | "require_verified"

Responses

StatusDescriptionBody
200The updated provider.SignInProvider
400The request body failed validation, or the settings violate a constraint.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404No provider has that id or slug.ErrorResponse
409The slug or issuer is taken.ErrorResponse
500The provider catalogue could not be written to.ErrorResponse
DELETE/api/providers/{provider_id} Bearer token

Delete a sign-in provider

Removes a provider nothing references. A provider whose identities still exist cannot be deleted — disable it, or detach the identities first. Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
provider_idpathstringyesProvider UUID id or slug.

Responses

StatusDescriptionBody
200The deleted provider.SignInProvider
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404No provider has that id or slug.ErrorResponse
409Sign-in identities still reference the provider.ErrorResponse
500The provider catalogue could not be written to.ErrorResponse