{"items":[{"type":"link","label":"Management Apps","link":"/openapi/user/management-apps.openapi","routeSlug":"/openapi/user/management-apps.openapi","content":{"contentType":"overview","meta":{"name":"Management Apps"},"children":[{"nodeType":"container","panels":[{"title":"Download OpenAPI description","titleTranslationKey":"download.description.title","children":[{"kind":"download","label":"management-apps.openapi.json","url":"/_bundle/openapi/user/management-apps.openapi.json?download"},{"kind":"download","label":"management-apps.openapi.yaml","url":"/_bundle/openapi/user/management-apps.openapi.yaml?download"}]},{"title":"Overview","titleTranslationKey":"info.title","children":[]},{"title":"Languages","titleTranslationKey":"languages.title","children":[{"kind":"languages","options":[{"key":"curl","title":"cURL","lang":"curl"},{"key":"node","title":"Node.js","lang":"Node.js"},{"key":"go","title":"Go","lang":"Go"},{"key":"javascript","title":"JavaScript","lang":"JavaScript"},{"key":"java","title":"Java","lang":"Java"},{"key":"python","title":"Python","lang":"Python"}]}]},{"title":"Servers","titleTranslationKey":"servers.title","children":[{"kind":"servers","servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"mode":"default"}]}],"children":[{"nodeType":"overview-section-wrapper","children":[{"nodeType":"header","level":1,"label":"Management Apps","showPageActions":true},{"nodeType":"overview-section-wrapper","children":[{"nodeType":"markdoc","content":"View, create, and update your management applications. These are typically backend services accessing our platform to perform administrative actions. They can be used to generate client credentials that have tenant-level access to users, roles, apps, settings, and more."}],"sectionId":"/openapi/user/management-apps.openapi"}],"sectionId":"/openapi/user/management-apps.openapi"}]}]}},{"label":"Create management app","deprecated":false,"httpVerb":"post","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/user/management-apps.openapi/other/createmanagementapplication","routeSlug":"/openapi/user/management-apps.openapi/other/createmanagementapplication","metadata":{"seo":{"title":"Create management app","description":"Create a management application"}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"createManagementApplication","name":"Create management app","isWebhook":false,"pointer":"/paths/~1v1~1management~1applications/post","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Create management app","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Create a management application"},{"nodeType":"security","requirements":[{"schemes":[{"name":"ClientAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by an end-user application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to resources and data on the tenant level or associated with the specific application (but not other apps in the tenant)"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]},{"schemes":[{"name":"AdminAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by a management application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to all resources for the tenant and its apps"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]}]},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","required":true,"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/ApiCreateManagementAppInput"}},"schemaId":"components/schemas/ApiCreateManagementAppInput","pointer":"/paths/~1v1~1management~1applications/post/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"POST","path":"/v1/management/applications","servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"parameters":{"path":[],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"ClientAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]},{"schemes":[{"id":"AdminAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]}],"requestBody":{"application/json":{"schemaId":"components/schemas/ApiCreateManagementAppInput"}},"responseCodes":["201","400"],"pointer":"/v1/management/applications","href":"other/createmanagementapplication","openApiOperationId":"createManagementApplication","summary":"Create management app","securityGroups":[{"ClientAccessToken":[]},{"AdminAccessToken":[]}]},"isWebhook":false,"hideReplay":false,"servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"schemaId":"components/schemas/ApiCreateManagementAppInput","mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/ApiCreateManagementAppInput"}},"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"201","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_398"}},"schemaId":"schema_398"},{"code":"400","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}},"schemaId":"components/schemas/BadRequestHttpError"}],"pointer":"/paths/~1v1~1management~1applications/post/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"201","schemaId":"schema_398","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_398"}}},{"code":"400","schemaId":"components/schemas/BadRequestHttpError","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}}}],"examples":[]}]}]}]},"httpPath":"/v1/management/applications"},{"label":"Get management apps","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/user/management-apps.openapi/other/getallmanagementapplications","routeSlug":"/openapi/user/management-apps.openapi/other/getallmanagementapplications","metadata":{"seo":{"title":"Get management apps","description":"Retrieve a list of all management applications"}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"getAllManagementApplications","name":"Get management apps","isWebhook":false,"pointer":"/paths/~1v1~1management~1applications/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get management apps","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Retrieve a list of all management applications"},{"nodeType":"security","requirements":[{"schemes":[{"name":"ClientAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by an end-user application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to resources and data on the tenant level or associated with the specific application (but not other apps in the tenant)"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]},{"schemes":[{"name":"AdminAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by a management application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to all resources for the tenant and its apps"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]}]}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/v1/management/applications","servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"parameters":{"path":[],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"ClientAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]},{"schemes":[{"id":"AdminAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]}],"responseCodes":["200","400"],"pointer":"/v1/management/applications","href":"other/getallmanagementapplications","openApiOperationId":"getAllManagementApplications","summary":"Get management apps","securityGroups":[{"ClientAccessToken":[]},{"AdminAccessToken":[]}]},"isWebhook":false,"hideReplay":false,"servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_399"}},"schemaId":"schema_399"},{"code":"400","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}},"schemaId":"components/schemas/BadRequestHttpError"}],"pointer":"/paths/~1v1~1management~1applications/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"schema_399","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_399"}}},{"code":"400","schemaId":"components/schemas/BadRequestHttpError","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}}}],"examples":[]}]}]}]},"httpPath":"/v1/management/applications"},{"label":"Update management app","deprecated":false,"httpVerb":"put","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/user/management-apps.openapi/other/updatemanagementapplication","routeSlug":"/openapi/user/management-apps.openapi/other/updatemanagementapplication","metadata":{"seo":{"title":"Update management app","description":"Update a management application. Note: Fields that are objects cannot be partially updated, since the new value you set will just replace the current one."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"updateManagementApplication","name":"Update management app","isWebhook":false,"pointer":"/paths/~1v1~1management~1applications~1{app_id}/put","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Update management app","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Update a management application. Note: Fields that are objects cannot be partially updated, since the new value you set will just replace the current one."},{"nodeType":"security","requirements":[{"schemes":[{"name":"ClientAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by an end-user application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to resources and data on the tenant level or associated with the specific application (but not other apps in the tenant)"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]},{"schemes":[{"name":"AdminAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by a management application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to all resources for the tenant and its apps"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"app_id","in":"path","schemaId":"schema_400","required":true}],"pointer":"/paths/~1v1~1management~1applications~1{app_id}/put/parameters"},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","required":true,"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/ApiUpdateManagementAppInput"}},"schemaId":"components/schemas/ApiUpdateManagementAppInput","pointer":"/paths/~1v1~1management~1applications~1{app_id}/put/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"PUT","path":"/v1/management/applications/{app_id}","servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"parameters":{"path":[{"name":"app_id","in":"path","required":true,"schemaId":"schema_400"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"ClientAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]},{"schemes":[{"id":"AdminAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]}],"requestBody":{"application/json":{"schemaId":"components/schemas/ApiUpdateManagementAppInput"}},"responseCodes":["200","400","404"],"pointer":"/v1/management/applications/{app_id}","href":"other/updatemanagementapplication","openApiOperationId":"updateManagementApplication","summary":"Update management app","securityGroups":[{"ClientAccessToken":[]},{"AdminAccessToken":[]}]},"isWebhook":false,"hideReplay":false,"servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"schemaId":"components/schemas/ApiUpdateManagementAppInput","mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/ApiUpdateManagementAppInput"}},"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_401"}},"schemaId":"schema_401"},{"code":"400","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}},"schemaId":"components/schemas/BadRequestHttpError"},{"code":"404","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/NotFoundHttpError"}},"schemaId":"components/schemas/NotFoundHttpError"}],"pointer":"/paths/~1v1~1management~1applications~1{app_id}/put/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"schema_401","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_401"}}},{"code":"400","schemaId":"components/schemas/BadRequestHttpError","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}}},{"code":"404","schemaId":"components/schemas/NotFoundHttpError","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/NotFoundHttpError"}}}],"examples":[]}]}]}]},"httpPath":"/v1/management/applications/{app_id}"},{"label":"Delete management app","deprecated":false,"httpVerb":"delete","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/user/management-apps.openapi/other/deletemanagementapplication","routeSlug":"/openapi/user/management-apps.openapi/other/deletemanagementapplication","metadata":{"seo":{"title":"Delete management app","description":"Delete a management application and remove role assignments belonging to it."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"deleteManagementApplication","name":"Delete management app","isWebhook":false,"pointer":"/paths/~1v1~1management~1applications~1{app_id}/delete","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Delete management app","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Delete a management application and remove role assignments belonging to it."},{"nodeType":"security","requirements":[{"schemes":[{"name":"ClientAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by an end-user application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to resources and data on the tenant level or associated with the specific application (but not other apps in the tenant)"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]},{"schemes":[{"name":"AdminAccessToken","scopes":[],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by a management application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to all resources for the tenant and its apps"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"app_id","in":"path","schemaId":"schema_400","required":true}],"pointer":"/paths/~1v1~1management~1applications~1{app_id}/delete/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"DELETE","path":"/v1/management/applications/{app_id}","servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"parameters":{"path":[{"name":"app_id","in":"path","required":true,"schemaId":"schema_400"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"ClientAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]},{"schemes":[{"id":"AdminAccessToken","type":"oauth2","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}],"scopes":[]}],"responseCodes":["204","400","404"],"pointer":"/v1/management/applications/{app_id}","href":"other/deletemanagementapplication","openApiOperationId":"deleteManagementApplication","summary":"Delete management app","securityGroups":[{"ClientAccessToken":[]},{"AdminAccessToken":[]}]},"isWebhook":false,"hideReplay":false,"servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"204"},{"code":"400","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}},"schemaId":"components/schemas/BadRequestHttpError"},{"code":"404","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/NotFoundHttpError"}},"schemaId":"components/schemas/NotFoundHttpError"}],"pointer":"/paths/~1v1~1management~1applications~1{app_id}/delete/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"204"},{"code":"400","schemaId":"components/schemas/BadRequestHttpError","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/BadRequestHttpError"}}},{"code":"404","schemaId":"components/schemas/NotFoundHttpError","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/NotFoundHttpError"}}}],"examples":[]}]}]}]},"httpPath":"/v1/management/applications/{app_id}"}],"store":{"schemaStore":{"components/schemas/BadRequestHttpError":{"id":"components/schemas/BadRequestHttpError","kind":"json-schema","title":"BadRequestHttpError","data":{"type":"object","properties":{"message":{"example":"Bad request","type":"array","items":{"type":"string"}},"error_code":{"type":"number","example":400}},"required":["message","error_code"]}},"components/schemas/ApiAppWithoutLogo":{"id":"components/schemas/ApiAppWithoutLogo","kind":"json-schema","title":"ApiAppWithoutLogo","data":{"type":"object","properties":{"app_id":{"type":"string","description":"Application ID"},"tenant_id":{"type":"string","description":"Tenant ID"},"app_name":{"type":"string","description":"Application name displayed in the Admin Portal"},"app_description":{"type":"string","description":"Short description of your application, displayed in the Admin Portal"},"client_type":{"type":"string","enum":["web","native"],"description":"Type of the default client","default":"web","deprecated":true},"client_id":{"type":"string","description":"Client ID of the default client used for API requests","deprecated":true},"client_display_name":{"type":"string","description":"Client name of the default client to display when needed","deprecated":true},"client_description":{"type":"string","description":"Short description of the default client","deprecated":true},"client_secret":{"type":"string","description":"Client secret of the default client used to obtain tokens for API authorization","deprecated":true},"redirect_uris":{"description":"List of URI approved for redirects for your default client","deprecated":true,"type":"array","items":{"type":"string"}},"login_preferences":{"$ref":"#/components/schemas/ApiLoginPreferences"},"created_at":{"format":"date-time","type":"string","description":"Date the application was created"},"created_by":{"type":"string","description":"The user that created the application"},"updated_at":{"format":"date-time","type":"string","description":"Date the application was last updated"},"resources":{"description":"List of resources the default client is allowed to explicitly request access to","deprecated":true,"type":"array","items":{"type":"string"}},"service_providers":{"description":"List of service providers this application is allowed to explicitly redirect to","type":"array","items":{"type":"string"}},"authenticator_preferences":{"description":"Configures the application as the Authentication Hub of this tenant, allowing other apps to use it to perform a centralized login.","allOf":[{"$ref":"#/components/schemas/ApiAuthenticatorAppPreferences"}]},"allow_public_signup":{"type":"boolean","description":"Determines if the application is allowed to request to create new users via login flows"},"client_auth_method":{"type":"string","enum":["client_secret_basic","self_signed_tls_client_auth","tls_client_auth","none","private_key_jwt"],"description":"This field is deprecated- to configure pkce use \"pkce\" field instead","deprecated":true},"pkce":{"type":"string","enum":["enforcePkceInsteadOfClientCredentials","enforcePkceAlongsideClientCredentials","allowPkceAlongsideClientCredentials"],"description":"PKCE configuration"},"device_authorization":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Configuration for an "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"https://www.rfc-editor.org/rfc/rfc8628"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth Device Authorization Flow"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of the default client"},"children":[]}]}]}],"deprecated":true,"allOf":[{"$ref":"#/components/schemas/ApiDeviceAuthConfiguration"}]},"ciba_authorization":{"description":"CIBA authorization flow configuration of the default client","deprecated":true,"allOf":[{"$ref":"#/components/schemas/ApiCibaAuthConfiguration"}]},"password_sharing_group_id":{"type":"string","description":"If the app has opted in to password sharing, this identifies the group of apps that it shares passwords with."},"login_uri":{"type":"string","description":"URI used to redirect the user to the login page of the application (when needed)","example":"https://www.example.com/login","nullable":true},"b2b_invite_journey_id":{"type":"string","description":"Journey ID used for B2B invite magic-link flows","nullable":true},"invite_member_uri":{"type":"string","description":"URI used to redirect the member to the login page of the application (when needed)","example":"https://www.example.com/login","nullable":true},"invite_client_id":{"type":"string","description":"Client used for the email magic link invitation flow"},"subdomain":{"type":"string","description":"Subdomain of Org admin portal that can be offered for organizations to manage their users (when needed)","example":"myapp"},"invite_member_email_expiration_minutes":{"type":"number","description":"Member invite email link expiration in minutes","default":2880},"custom_domain":{"description":"Custom domain of the application that can be offered for the application to be accessed from","allOf":[{"$ref":"#/components/schemas/ApiCustomDomainOutput"}]},"external_communication":{"description":"External communication configuration for the application","allOf":[{"$ref":"#/components/schemas/ApiExternalCommunication"}]},"signing_key_enabled":{"type":"boolean","description":"Determines if application specific signing key is enabled"},"refresh_token_invalidation_trigger_configuration":{"description":"Refresh token invalidation trigger configuration","allOf":[{"$ref":"#/components/schemas/ApiRefreshTokenInvalidationTriggerConfiguration"}]},"application_type":{"type":"string","enum":["ido","basic"],"description":"Application type"}},"required":["app_id","tenant_id","app_name","app_description","login_preferences","created_at","created_by","updated_at","service_providers","authenticator_preferences","allow_public_signup"]}},"components/schemas/ApiCreateManagementAppInput":{"id":"components/schemas/ApiCreateManagementAppInput","kind":"json-schema","title":"ApiCreateManagementAppInput","data":{"type":"object","properties":{"app_name":{"type":"string","description":"Name of the application","example":"My App"},"app_description":{"type":"string","description":"Short description of the application"},"login_uri":{"type":"string","description":"URI used to redirect the user to the login page of the application (when needed)","example":"https://www.example.com/login"},"b2b_invite_journey_id":{"type":"string","description":"Journey ID used for B2B invite magic-link flows"},"invite_member_uri":{"type":"string","description":"URI used to redirect the member to the login page of the application (when needed)","example":"https://www.example.com/login"},"invite_member_email_expiration_minutes":{"type":"number","description":"Member invite email link expiration in minutes","default":2880},"refresh_token_invalidation_trigger_configuration":{"description":"Refresh token invalidation trigger configuration","allOf":[{"$ref":"#/components/schemas/ApiRefreshTokenInvalidationTriggerConfiguration"}]},"first_client_authentication_protocol":{"type":"string","description":"Defines the first client authentication protocol.","enum":["oidc","saml"]},"first_client":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Creates first client for the application. Client can be OIDC or SAML, depending what is set in first_client_authentication_protocol"},"children":[]}]}]}],"oneOf":[{"$ref":"#/components/schemas/ApiCreateOidcClientInput"},{"$ref":"#/components/schemas/ApiCreateSamlClientInput"}]},"subdomain":{"type":"string","description":"Subdomain of Org admin portal that can be offered for organizations to manage their users (when needed)","example":"myapp"},"custom_domain":{"type":"string","description":"Domain of the application that can be offered for the application to be accessed from","example":"myapp.com"},"pkce":{"type":"string","enum":["enforcePkceInsteadOfClientCredentials","enforcePkceAlongsideClientCredentials","allowPkceAlongsideClientCredentials"],"description":"PKCE configuration for client"},"should_delete_signing_key":{"type":"boolean","description":"Determines whether the application-specific signing key should be deleted when disabled. If deleted, any tokens previously issued with this key will no longer be valid.","default":false},"signing_key_enabled":{"type":"boolean","description":"Determines if application specific signing key is enabled","default":false},"invite_client_id":{"type":"string","description":"Client used for the email magic link invitation flow"}},"required":["app_name"]}},"components/schemas/ApiApp":{"id":"components/schemas/ApiApp","kind":"json-schema","title":"ApiApp","data":{"type":"object","properties":{"app_id":{"type":"string","description":"Application ID"},"tenant_id":{"type":"string","description":"Tenant ID"},"app_name":{"type":"string","description":"Application name displayed in the Admin Portal"},"app_description":{"type":"string","description":"Short description of your application, displayed in the Admin Portal"},"client_type":{"type":"string","enum":["web","native"],"description":"Type of the default client","default":"web","deprecated":true},"logo":{"type":"string","description":"URI of your application's logo, such as a logo used in email templates","nullable":true},"client_id":{"type":"string","description":"Client ID of the default client used for API requests","deprecated":true},"client_display_name":{"type":"string","description":"Client name of the default client to display when needed","deprecated":true},"client_description":{"type":"string","description":"Short description of the default client","deprecated":true},"client_secret":{"type":"string","description":"Client secret of the default client used to obtain tokens for API authorization","deprecated":true},"redirect_uris":{"description":"List of URI approved for redirects for your default client","deprecated":true,"type":"array","items":{"type":"string"}},"login_preferences":{"$ref":"#/components/schemas/ApiLoginPreferences"},"created_at":{"format":"date-time","type":"string","description":"Date the application was created"},"created_by":{"type":"string","description":"The user that created the application"},"updated_at":{"format":"date-time","type":"string","description":"Date the application was last updated"},"resources":{"description":"List of resources the default client is allowed to explicitly request access to","deprecated":true,"type":"array","items":{"type":"string"}},"service_providers":{"description":"List of service providers this application is allowed to explicitly redirect to","type":"array","items":{"type":"string"}},"authenticator_preferences":{"description":"Configures the application as the Authentication Hub of this tenant, allowing other apps to use it to perform a centralized login.","allOf":[{"$ref":"#/components/schemas/ApiAuthenticatorAppPreferences"}]},"allow_public_signup":{"type":"boolean","description":"Determines if the application is allowed to request to create new users via login flows"},"client_auth_method":{"type":"string","enum":["client_secret_basic","self_signed_tls_client_auth","tls_client_auth","none","private_key_jwt"],"description":"This field is deprecated- to configure pkce use \"pkce\" field instead","deprecated":true},"pkce":{"type":"string","enum":["enforcePkceInsteadOfClientCredentials","enforcePkceAlongsideClientCredentials","allowPkceAlongsideClientCredentials"],"description":"PKCE configuration"},"device_authorization":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Configuration for an "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"https://www.rfc-editor.org/rfc/rfc8628"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth Device Authorization Flow"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of the default client"},"children":[]}]}]}],"deprecated":true,"allOf":[{"$ref":"#/components/schemas/ApiDeviceAuthConfiguration"}]},"ciba_authorization":{"description":"CIBA authorization flow configuration of the default client","deprecated":true,"allOf":[{"$ref":"#/components/schemas/ApiCibaAuthConfiguration"}]},"password_sharing_group_id":{"type":"string","description":"If the app has opted in to password sharing, this identifies the group of apps that it shares passwords with."},"login_uri":{"type":"string","description":"URI used to redirect the user to the login page of the application (when needed)","example":"https://www.example.com/login","nullable":true},"b2b_invite_journey_id":{"type":"string","description":"Journey ID used for B2B invite magic-link flows","nullable":true},"invite_member_uri":{"type":"string","description":"URI used to redirect the member to the login page of the application (when needed)","example":"https://www.example.com/login","nullable":true},"invite_client_id":{"type":"string","description":"Client used for the email magic link invitation flow"},"subdomain":{"type":"string","description":"Subdomain of Org admin portal that can be offered for organizations to manage their users (when needed)","example":"myapp"},"invite_member_email_expiration_minutes":{"type":"number","description":"Member invite email link expiration in minutes","default":2880},"custom_domain":{"description":"Custom domain of the application that can be offered for the application to be accessed from","allOf":[{"$ref":"#/components/schemas/ApiCustomDomainOutput"}]},"external_communication":{"description":"External communication configuration for the application","allOf":[{"$ref":"#/components/schemas/ApiExternalCommunication"}]},"signing_key_enabled":{"type":"boolean","description":"Determines if application specific signing key is enabled"},"refresh_token_invalidation_trigger_configuration":{"description":"Refresh token invalidation trigger configuration","allOf":[{"$ref":"#/components/schemas/ApiRefreshTokenInvalidationTriggerConfiguration"}]},"application_type":{"type":"string","enum":["ido","basic"],"description":"Application type"}},"required":["app_id","tenant_id","app_name","app_description","login_preferences","created_at","created_by","updated_at","service_providers","authenticator_preferences","allow_public_signup"]}},"components/schemas/ApiUpdateManagementAppInput":{"id":"components/schemas/ApiUpdateManagementAppInput","kind":"json-schema","title":"ApiUpdateManagementAppInput","data":{"type":"object","properties":{"app_name":{"type":"string","description":"Name of the application","example":"My App"},"app_description":{"type":"string","description":"Short description of the application"},"login_uri":{"type":"string","description":"URI used to redirect the user to the login page of the application (when needed)","example":"https://www.example.com/login"},"b2b_invite_journey_id":{"type":"string","description":"Journey ID used for B2B invite magic-link flows"},"invite_member_uri":{"type":"string","description":"URI used to redirect the member to the login page of the application (when needed)","example":"https://www.example.com/login"},"invite_member_email_expiration_minutes":{"type":"number","description":"Member invite email link expiration in minutes","default":2880},"refresh_token_invalidation_trigger_configuration":{"description":"Refresh token invalidation trigger configuration","allOf":[{"$ref":"#/components/schemas/ApiRefreshTokenInvalidationTriggerConfiguration"}]},"first_client_authentication_protocol":{"type":"string","description":"Defines the first client authentication protocol.","enum":["oidc","saml"]},"first_client":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Creates first client for the application. Client can be OIDC or SAML, depending what is set in first_client_authentication_protocol"},"children":[]}]}]}],"oneOf":[{"$ref":"#/components/schemas/ApiCreateOidcClientInput"},{"$ref":"#/components/schemas/ApiCreateSamlClientInput"}]},"subdomain":{"type":"string","description":"Subdomain of Org admin portal that can be offered for organizations to manage their users (when needed)","example":"myapp"},"custom_domain":{"type":"string","description":"Domain of the application that can be offered for the application to be accessed from","example":"myapp.com"},"pkce":{"type":"string","enum":["enforcePkceInsteadOfClientCredentials","enforcePkceAlongsideClientCredentials","allowPkceAlongsideClientCredentials"],"description":"PKCE configuration for client"},"should_delete_signing_key":{"type":"boolean","description":"Determines whether the application-specific signing key should be deleted when disabled. If deleted, any tokens previously issued with this key will no longer be valid.","default":false},"signing_key_enabled":{"type":"boolean","description":"Determines if application specific signing key is enabled","default":false},"invite_client_id":{"type":"string","description":"Client used for the email magic link invitation flow"}}}},"components/schemas/NotFoundHttpError":{"id":"components/schemas/NotFoundHttpError","kind":"json-schema","title":"NotFoundHttpError","data":{"type":"object","properties":{"message":{"type":"string"},"error_code":{"type":"number","example":404}},"required":["message","error_code"]}},"components/schemas/ApiLoginPreferences":{"id":"components/schemas/ApiLoginPreferences","kind":"json-schema","title":"ApiLoginPreferences","data":{"type":"object","properties":{"auth_methods":{"description":"Login preferences","allOf":[{"$ref":"#/components/schemas/ApiAuthMethods"}]}},"required":["auth_methods"]}},"components/schemas/ApiAuthenticatorAppPreferences":{"id":"components/schemas/ApiAuthenticatorAppPreferences","kind":"json-schema","title":"ApiAuthenticatorAppPreferences","data":{"type":"object","properties":{"is_centralized":{"type":"boolean","description":"Indicates whether to set the application as the Authentication Hub for this tenant","default":false},"login_uri":{"type":"string","description":"URI of the application that will initiate an authentication flow when centralized login is requested","example":"https://www.example.com/login"}},"required":["is_centralized","login_uri"]}},"components/schemas/ApiDeviceAuthConfiguration":{"id":"components/schemas/ApiDeviceAuthConfiguration","kind":"json-schema","title":"ApiDeviceAuthConfiguration","data":{"type":"object","properties":{"enabled":{"type":"boolean","description":"Determines if the client is allowed to use the OAuth device authorization flow","default":false},"approval_uri":{"type":"string","description":"The URI of the page that allows the user to approve the access request","example":"https://www.example.com/device/approval"},"success_uri":{"type":"string","description":"Callback URI that receives an indication of whether the end-user authentication was completed successfully.","example":"https://www.example.com/device/complete"},"input_uri":{"type":"string","description":"The URI of the page that allows the user to enter the code","example":"https://www.example.com/device/start"}},"required":["enabled","approval_uri","success_uri","input_uri"]}},"components/schemas/ApiCibaAuthConfiguration":{"id":"components/schemas/ApiCibaAuthConfiguration","kind":"json-schema","title":"ApiCibaAuthConfiguration","data":{"type":"object","properties":{"enabled":{"type":"boolean","description":"Determines if the client is allowed to use the OAuth CIBA authorization flow","default":false},"login_uri":{"type":"string","description":"The URI of the page that allows the user to log-in and verify the access request","example":"https://www.example.com/ciba/login"}},"required":["enabled"]}},"components/schemas/ApiCustomDomainOutput":{"id":"components/schemas/ApiCustomDomainOutput","kind":"json-schema","title":"ApiCustomDomainOutput","data":{"type":"object","properties":{"domain":{"type":"string","description":"Domain of the application that can be offered for the application to be accessed from","example":"myapp.com"},"updated_at":{"format":"date-time","type":"string","description":"Date the custom domain was last updated"},"status":{"type":"string","enum":["pending","verified","error"],"description":"The status of the custom domain validation process","default":"pending"},"error":{"type":"string","description":"The error message if the custom domain validation process failed"}},"required":["domain","updated_at"]}},"components/schemas/ApiExternalCommunication":{"id":"components/schemas/ApiExternalCommunication","kind":"json-schema","title":"ApiExternalCommunication","data":{"type":"object","properties":{"language":{"type":"string","enum":["en","es","pt","fr","ja","fr-CA"],"description":"Language configuration for the external communication. The default language is english.","default":"en"}}}},"components/schemas/ApiRefreshTokenInvalidationTriggerConfiguration":{"id":"components/schemas/ApiRefreshTokenInvalidationTriggerConfiguration","kind":"json-schema","title":"ApiRefreshTokenInvalidationTriggerConfiguration","data":{"type":"object","properties":{"invalidateOnMemberSuspension":{"type":"boolean","description":"Determines if refresh tokens should be invalidated when a member is suspended","default":true},"invalidateOnMemberPasswordReset":{"type":"boolean","description":"Determines if refresh tokens should be invalidated when a member resets their password","default":true},"invalidateOnMemberRoleUpdate":{"type":"boolean","description":"Determines if refresh tokens should be invalidated when a member role is updated","default":true}}}},"components/schemas/ApiCreateOidcClientInput":{"id":"components/schemas/ApiCreateOidcClientInput","kind":"json-schema","title":"ApiCreateOidcClientInput","data":{"type":"object","properties":{"name":{"type":"string","description":"Name of the client","example":"My Client"},"description":{"type":"string","description":"Short description of the client"},"resources":{"description":"List of resources IDs associated with this client","type":"array","items":{"type":"string"}},"authentication_protocol":{"type":"string","enum":["oidc","saml"],"description":"Authentication protocol used by the client","default":"oidc"},"client_group_id":{"type":"string","description":"Id of client group to associate with"},"default_custom_claims":{"type":"array","description":"List of client default custom claims","items":{"type":"string","enum":["tid","fname","lname","mname","email","email_verified","phone_number","phone_number_verified","groups","new_user","birthday","language","city","address","country","street_address","address_type","webauthn","roles","ts_roles","role_values","ts_permissions","permissions","approval_data","custom_group_data","username","secondary_phone_numbers","secondary_emails","picture","created_at","last_auth","auth_time","external_account_id","external_user_id","app_name","custom_data","custom_app_data","ai_actor"]}},"default_user_info_claims":{"type":"array","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"List of client default custom claims returned by the UserInfo endpoint. Ignored when sync_id_token_claims_to_userinfo is true. In this case default_custom_claims is mirrored instead."},"children":[]}]}]}],"items":{"type":"string","enum":["tid","fname","lname","mname","email","email_verified","phone_number","phone_number_verified","groups","new_user","birthday","language","city","address","country","street_address","address_type","webauthn","roles","ts_roles","role_values","ts_permissions","permissions","approval_data","custom_group_data","username","secondary_phone_numbers","secondary_emails","picture","created_at","last_auth","auth_time","external_account_id","external_user_id","app_name","custom_data","custom_app_data","ai_actor"]}},"sync_id_token_claims_to_userinfo":{"type":"boolean","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"When true, UserInfo custom claims are kept in sync with default_custom_claims (the ID Token list) and any explicitly configured default_user_info_claims are ignored."},"children":[]}]}]}],"default":false},"short_cookies_samesite_type":{"type":"string","enum":["lax","none"],"description":"Short cookies samesite type. Possible values: \"none\", \"lax\", \"strict\". Default: \"lax\"","default":"lax"},"redirect_uris":{"description":"List of URIs approved for redirects for your client","example":["https://www.example.com/login"],"type":"array","items":{"type":"string"}},"client_type":{"type":"string","enum":["web","native"],"description":"Client type","default":"web"},"device_authorization":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Configuration for an "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"https://www.rfc-editor.org/rfc/rfc8628"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth Device Authorization Flow"},"children":[]}]}]}]}],"allOf":[{"$ref":"#/components/schemas/ApiDeviceAuthConfiguration"}]},"ciba_authorization":{"description":"CIBA authorization flow configuration","allOf":[{"$ref":"#/components/schemas/ApiCibaAuthConfiguration"}]},"is_third_party":{"type":"boolean","description":"Is third party client"},"allowed_scopes":{"description":"Allowed scopes","type":"array","items":{"type":"string"}},"consent_uri":{"type":"string","description":"Consent URI"},"consent_validity_period":{"type":"number","description":"Consent validity period"},"pkce":{"type":"string","enum":["enforcePkceInsteadOfClientCredentials","enforcePkceAlongsideClientCredentials","allowPkceAlongsideClientCredentials"],"description":"PKCE configuration"},"supported_prompts":{"type":"array","example":["login","consent","none"],"description":"Supported prompts for the OIDC authentication flow","items":{"type":"string","enum":["login","consent","none"]}},"token_expiration":{"description":"Token expiration settings","allOf":[{"$ref":"#/components/schemas/ApiTokenExpirationConfiguration"}]},"session_expiration":{"type":"number","description":"Session expiration time (seconds)"},"enforce_par":{"type":"boolean","description":"enforce PAR (Pushed Authorization Request) for this client"},"role_ids":{"description":"Role IDs","type":"array","items":{"type":"string"}},"fapi_version_compliancy":{"type":"boolean","description":"FAPI 2.0 compliancy configuration"},"token_endpoint_auth_method":{"type":"string","enum":["client_secret_basic","self_signed_tls_client_auth","tls_client_auth","none","private_key_jwt"],"description":"This field is deprecated- to configure pkce use \"pkce\" field instead","default":"client_secret_basic","deprecated":true},"response_types":{"type":"array","default":["code","id_token"],"example":["code"],"items":{"type":"string","enum":["code","id_token"]}},"authentication_configuration":{"description":"Client authentication configuration","allOf":[{"$ref":"#/components/schemas/ApiClientAuthenticationConfiguration"}]},"id_token_encryption":{"description":"ID Token encryption configuration","allOf":[{"$ref":"#/components/schemas/ApiIdTokenEncryptionConfiguration"}]}},"required":["name"]}},"components/schemas/ApiCreateSamlClientInput":{"id":"components/schemas/ApiCreateSamlClientInput","kind":"json-schema","title":"ApiCreateSamlClientInput","data":{"type":"object","properties":{"name":{"type":"string","description":"Name of the client","example":"My Client"},"description":{"type":"string","description":"Short description of the client"},"resources":{"description":"List of resources IDs associated with this client","type":"array","items":{"type":"string"}},"authentication_protocol":{"type":"string","enum":["oidc","saml"],"description":"Authentication protocol used by the client","default":"oidc"},"client_group_id":{"type":"string","description":"Id of client group to associate with"},"default_custom_claims":{"type":"array","description":"List of client default custom claims","items":{"type":"string","enum":["tid","fname","lname","mname","email","email_verified","phone_number","phone_number_verified","groups","new_user","birthday","language","city","address","country","street_address","address_type","webauthn","roles","ts_roles","role_values","ts_permissions","permissions","approval_data","custom_group_data","username","secondary_phone_numbers","secondary_emails","picture","created_at","last_auth","auth_time","external_account_id","external_user_id","app_name","custom_data","custom_app_data","ai_actor"]}},"default_user_info_claims":{"type":"array","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"List of client default custom claims returned by the UserInfo endpoint. Ignored when sync_id_token_claims_to_userinfo is true. In this case default_custom_claims is mirrored instead."},"children":[]}]}]}],"items":{"type":"string","enum":["tid","fname","lname","mname","email","email_verified","phone_number","phone_number_verified","groups","new_user","birthday","language","city","address","country","street_address","address_type","webauthn","roles","ts_roles","role_values","ts_permissions","permissions","approval_data","custom_group_data","username","secondary_phone_numbers","secondary_emails","picture","created_at","last_auth","auth_time","external_account_id","external_user_id","app_name","custom_data","custom_app_data","ai_actor"]}},"sync_id_token_claims_to_userinfo":{"type":"boolean","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"When true, UserInfo custom claims are kept in sync with default_custom_claims (the ID Token list) and any explicitly configured default_user_info_claims are ignored."},"children":[]}]}]}],"default":false},"short_cookies_samesite_type":{"type":"string","enum":["lax","none"],"description":"Short cookies samesite type. Possible values: \"none\", \"lax\", \"strict\". Default: \"lax\"","default":"lax"},"sp_acs_url":{"type":"string","description":"SAML ACS URL"},"sp_entity_id":{"type":"string","description":"SAML Service provider entity ID"},"sp_name_id_type":{"type":"string","enum":["email","secondaryEmail","username","phoneNumber","externalUserId"],"description":"SAML Name ID Type"},"supported_prompts":{"type":"array","example":["login","consent","none"],"description":"Supported prompts for the OIDC authentication flow","items":{"type":"string","enum":["login","consent","none"]}},"sign_assertion":{"type":"boolean","description":"Sign SAML assertion"},"optional_acs_url":{"type":"boolean","description":"Allow ACS URL to be optional"},"use_centralized_login":{"type":"boolean","description":"When enabled, SAML SP-initiated SSO redirects to the tenant centralized hub application instead of hosted login"}},"required":["name","sp_entity_id"]}},"components/schemas/ApiAuthMethods":{"id":"components/schemas/ApiAuthMethods","kind":"json-schema","title":"ApiAuthMethods","data":{"type":"object","properties":{"google":{"description":"Google login configuration","allOf":[{"$ref":"#/components/schemas/ClientSecretConfiguration"}]},"facebook":{"description":"Facebook login configuration","allOf":[{"$ref":"#/components/schemas/FacebookConfiguration"}]},"email":{"description":"Email magic link login configuration","allOf":[{"$ref":"#/components/schemas/EmailConfiguration"}]},"email_otp":{"description":"Email one time password login configuration","allOf":[{"$ref":"#/components/schemas/EmailOtpConfiguration"}]},"apple":{"description":"Apple login configuration","allOf":[{"$ref":"#/components/schemas/AppleConfiguration"}]},"sms":{"description":"SMS one time password login configuration","allOf":[{"$ref":"#/components/schemas/SMSConfiguration"}]},"webauthn_api":{"description":"WebAuthn API configuration","allOf":[{"$ref":"#/components/schemas/WebAuthnApiConfiguration"}]},"line":{"description":"Line login configuration","allOf":[{"$ref":"#/components/schemas/ClientSecretConfiguration"}]},"password":{"description":"Password login configuration","allOf":[{"$ref":"#/components/schemas/PasswordConfiguration"}]},"totp":{"description":"TOTP login configuration","allOf":[{"$ref":"#/components/schemas/TotpConfiguration"}]},"push":{"description":"Push configuration","allOf":[{"$ref":"#/components/schemas/PushConfiguration"}]},"tiktok":{"description":"TikTok login configuration","allOf":[{"$ref":"#/components/schemas/ClientSecretConfiguration"}]},"pin_authenticator":{"description":"PIN authenticator configuration","allOf":[{"$ref":"#/components/schemas/PinAuthenticatorConfiguration"}]},"face":{"description":"Face authenticator configuration","allOf":[{"$ref":"#/components/schemas/FaceAuthenticatorConfiguration"}]}}}},"components/schemas/ApiTokenExpirationConfiguration":{"id":"components/schemas/ApiTokenExpirationConfiguration","kind":"json-schema","title":"ApiTokenExpirationConfiguration","data":{"type":"object","properties":{"access_token_ttl":{"type":"number","description":"Access token time-to-live"},"refresh_token_ttl":{"type":"number","description":"Refresh token time-to-live"},"max_refresh_rotate":{"type":"number","description":"Maximum time the refresh token can be rotated"}}}},"components/schemas/ApiClientAuthenticationConfiguration":{"id":"components/schemas/ApiClientAuthenticationConfiguration","kind":"json-schema","title":"ApiClientAuthenticationConfiguration","data":{"type":"object","properties":{"method":{"type":"string","enum":["client_secret_basic","self_signed_tls_client_auth","tls_client_auth","private_key_jwt"],"description":"Client authentication method","default":"client_secret_basic"},"tls_client_auth":{"description":"TLS client authentication configuration for mTLS","allOf":[{"$ref":"#/components/schemas/TlsClientAuth"}]},"isMtlsCertTokenBound":{"type":"boolean","description":"States whether to bind the access token to the client certificate when mTLS is enabled"},"jwks":{"type":"object","description":"A set of JWK keys containing the public keys for the Client to use for authentication"}},"required":["method"]}},"components/schemas/ApiIdTokenEncryptionConfiguration":{"id":"components/schemas/ApiIdTokenEncryptionConfiguration","kind":"json-schema","title":"ApiIdTokenEncryptionConfiguration","data":{"type":"object","properties":{"enabled":{"type":"boolean","description":"Determines if ID token encryption is enabled for the client","default":false},"jwks":{"type":"object","description":"A set of JWK keys containing the public keys for the client to use for ID token encryption"}},"required":["enabled"]}},"components/schemas/ClientSecretConfiguration":{"id":"components/schemas/ClientSecretConfiguration","kind":"json-schema","title":"ClientSecretConfiguration","data":{"type":"object","properties":{"clientId":{"type":"string","description":"Client ID retrieved from the identity provider"},"clientSecret":{"type":"string","description":"Client Secret retrieved from the identity provider"},"redirectUris":{"description":"List of URIs approved for redirects for your client","example":["https://www.example.com/login"],"type":"array","items":{"type":"string"}}},"required":["clientId"]}},"components/schemas/FacebookConfiguration":{"id":"components/schemas/FacebookConfiguration","kind":"json-schema","title":"FacebookConfiguration","data":{"type":"object","properties":{"clientId":{"type":"string","description":"Client ID retrieved from the identity provider"},"clientSecret":{"type":"string","description":"Client Secret retrieved from the identity provider"},"redirectUris":{"description":"List of URIs approved for redirects for your client","example":["https://www.example.com/login"],"type":"array","items":{"type":"string"}},"blockSignupWithoutEmail":{"type":"boolean","default":false,"description":"Blocks creating a new user when Facebook does not return an email address, which happens when the end-user declines to share their email on the consent screen. Existing users are not affected."}},"required":["clientId"]}},"components/schemas/EmailConfiguration":{"id":"components/schemas/EmailConfiguration","kind":"json-schema","title":"EmailConfiguration","data":{"type":"object","properties":{"expiresIn":{"type":"number","description":"Number of minutes until the email link/code expires"},"linksPerUser":{"type":"number","description":"Allowed magic links to send a user per minute"},"message":{"$ref":"#/components/schemas/MessageConfiguration"}},"required":["expiresIn","linksPerUser","message"]}},"components/schemas/EmailOtpConfiguration":{"id":"components/schemas/EmailOtpConfiguration","kind":"json-schema","title":"EmailOtpConfiguration","data":{"type":"object","properties":{"expiresIn":{"type":"number","description":"Number of minutes until the OTP expires"},"lockoutDuration":{"type":"number","description":"OTP lockout duration (in minutes) after maximum attempts are reached","example":15},"maxFailures":{"type":"number","description":"Number of wrong OTP attempts allowed before the passcode is invalidated. Must be between 1 and 20.","example":3},"codeLength":{"type":"number","description":"The length of the generated OTP code. Must be between 4 and 8.","example":6},"crossClientsAllowed":{"type":"boolean","description":"Determines if OTP authentication is allowed across different clients within the same application","default":false},"message":{"$ref":"#/components/schemas/MessageConfiguration"}},"required":["expiresIn","maxFailures","message"]}},"components/schemas/AppleConfiguration":{"id":"components/schemas/AppleConfiguration","kind":"json-schema","title":"AppleConfiguration","data":{"type":"object","properties":{"clientId":{"type":"string","description":"Services ID retrieved from Apple"},"clientSecret":{"type":"string","description":"Client Secret Signing Key retrieved from Apple"},"redirectUris":{"description":"List of URIs approved for redirects for your client","example":["https://www.example.com/login"],"type":"array","items":{"type":"string"}},"appleTeamId":{"type":"string","description":"Apple Team ID"},"keyId":{"type":"string","description":"Apple Key ID"}},"required":["clientId","appleTeamId","keyId"]}},"components/schemas/SMSConfiguration":{"id":"components/schemas/SMSConfiguration","kind":"json-schema","title":"SMSConfiguration","data":{"type":"object","properties":{"expiresIn":{"type":"number","description":"Number of minutes until the OTP expires"},"lockoutDuration":{"type":"number","description":"OTP lockout duration (in minutes) after maximum attempts are reached","example":15},"maxFailures":{"type":"number","description":"Number of wrong OTP attempts allowed before the passcode is invalidated. Must be between 1 and 20.","example":3},"codeLength":{"type":"number","description":"The length of the generated OTP code. Must be between 4 and 8.","example":6},"crossClientsAllowed":{"type":"boolean","description":"Determines if OTP authentication is allowed across different clients within the same application","default":false}},"required":["expiresIn","maxFailures"]}},"components/schemas/WebAuthnApiConfiguration":{"id":"components/schemas/WebAuthnApiConfiguration","kind":"json-schema","title":"WebAuthnApiConfiguration","data":{"type":"object","properties":{"failuresExpireIn":{"type":"number","description":"Number of minutes until previous failed attempts are considered expired. Must be between 1 and 525600 minutes (1 year).","default":15,"example":15,"minimum":1,"maximum":525600},"lockoutTiers":{"description":"Progressive lockout tiers based on failed attempts","type":"array","items":{"$ref":"#/components/schemas/LockoutTier"}},"rpId":{"type":"string","description":"Domain to which WebAuthn credentials are registered and used to authenticate (e.g., example.com)"},"rpWebOrigins":{"description":"A list of Web origins that will be used to request registration and authentication. The origin must match the domain of the RP ID, but may be a subdomain of the RP ID (e.g., https://login.example.com ). The origin must also include the HTTPS scheme and port (if relevant).","type":"array","items":{"type":"string"}},"rpMobileOrigins":{"description":"A list of mobile origins that will be used to request registration and authentication. The origin must match the domain of the RP ID.","type":"array","items":{"type":"string"}},"replaceExistingPasskey":{"type":"boolean","description":"Set to true in order to replace the existing passkey. Default is False.","default":false},"maxFailures":{"type":"number","description":"Number of wrong attempts allowed before the passcode is invalidated. Must be between 1 and 20.","example":3,"default":5,"deprecated":true},"lockoutDuration":{"type":"number","description":"Lockout duration (in minutes) after maximum attempts are reached","example":15,"default":15,"deprecated":true},"allowSyncedPasskeys":{"type":"boolean","description":"Allow synced passkeys","default":true},"enforceAttestation":{"type":"boolean","description":"Enforce attestation for device-bound passkeys","default":false},"attestationType":{"type":"string","enum":["none","indirect","direct"],"description":"Attestation conveyance preference (none, indirect, or direct)","default":"none"},"aaguidAllowList":{"description":"List of allowed AAGUIDs (Authenticator Attestation GUIDs). If specified, only authenticators with these AAGUIDs will be accepted. Mutually exclusive with aaguidBlockList.","type":"array","items":{"type":"string"}},"aaguidBlockList":{"description":"List of blocked AAGUIDs (Authenticator Attestation GUIDs). Authenticators with these AAGUIDs will be rejected. Mutually exclusive with aaguidAllowList.","type":"array","items":{"type":"string"}},"rpOrigin":{"type":"string","deprecated":true,"description":"Web origin that will be used to request registration and authentication. The origin must match the domain of the RP ID, but may be a subdomain of the RP ID (e.g., https://login.example.com ). The origin must also include the HTTPS scheme and port (if relevant)."},"rpOrigins":{"deprecated":true,"description":"Use rpWebOrigins or rpMobileOrigins instead","type":"array","items":{"type":"string"}}},"required":["rpId"]}},"components/schemas/PasswordConfiguration":{"id":"components/schemas/PasswordConfiguration","kind":"json-schema","title":"PasswordConfiguration","data":{"type":"object","properties":{"failuresExpireIn":{"type":"number","description":"Number of minutes until previous failed attempts are considered expired. Must be between 1 and 525600 minutes (1 year).","default":15,"example":15,"minimum":1,"maximum":525600},"lockoutTiers":{"description":"Progressive lockout tiers based on failed attempts","type":"array","items":{"$ref":"#/components/schemas/LockoutTier"}},"resetValidityMinutes":{"type":"number","description":"Number of minutes until reset password token/OTP expires.","default":5,"example":5,"minimum":5,"maximum":60},"passwordComplexity":{"type":"number","description":"Password complexity. Must be between 1 and 5.","default":5,"example":5,"minimum":1,"maximum":5},"passwordMinLength":{"type":"number","description":"Minimum required length of the password.","default":14,"example":14,"minimum":5,"maximum":14},"blockPreviousPasswords":{"type":"number","description":"Number of most recent passwords to block the user from setting as their new password.","default":0,"example":0,"minimum":0,"maximum":20},"checkHibp":{"type":"boolean","description":"Check password updates against HIBP.","default":false},"checkDictionary":{"type":"boolean","description":"Check password updates against a predefined dictionary.","default":false},"passwordExpiresIn":{"type":"number","description":"Number of days until the password expires. Must be between 1 and 1096 days (3 years).","default":90,"example":90,"minimum":1,"maximum":1096},"ignoreExpiration":{"type":"boolean","description":"Ignore password expiration. If true, the password will never expire.","default":false},"maxPasswordFailures":{"type":"number","description":"Number of wrong password attempts allowed before the user is suspended. Must be between 1 and 20.","default":5,"example":5,"minimum":1,"maximum":20},"passwordSuspensionDuration":{"type":"number","description":"Number of minutes to suspend the user from authenticating using password after the maximum number of allowed failed attempts is exceeded. Must be between 1 and 525600 minutes (1 year).","default":15,"example":15,"minimum":1,"maximum":525600},"tempPasswordValidityHours":{"type":"number","description":"Number of hours until temporary passwords are considered expired. Must be between 1 and 8760 hours (1 year).","example":24,"minimum":1,"maximum":8760},"message":{"$ref":"#/components/schemas/MessageConfiguration"},"requireMFA":{"type":"boolean","description":"Require multi-factor authentication for password reset flows.","default":false},"codeLength":{"type":"number","description":"The length of the generated OTP code. Must be between 4 and 8.","example":6},"notifyOnPasswordUpdate":{"type":"boolean","default":false,"description":"Send email to end-user upon password update"}},"required":["resetValidityMinutes","passwordComplexity","passwordMinLength","blockPreviousPasswords","passwordExpiresIn","message"]}},"components/schemas/TotpConfiguration":{"id":"components/schemas/TotpConfiguration","kind":"json-schema","title":"TotpConfiguration","data":{"type":"object","properties":{"failuresExpireIn":{"type":"number","description":"Number of minutes until previous failed attempts are considered expired. Must be between 1 and 525600 minutes (1 year).","default":15,"example":15,"minimum":1,"maximum":525600},"lockoutTiers":{"description":"Progressive lockout tiers based on failed attempts","type":"array","items":{"$ref":"#/components/schemas/LockoutTier"}},"algorithm":{"type":"string","enum":["sha1","sha256","sha512"],"description":"The algorithm used to generate the TOTP code","default":"sha1"},"digits":{"type":"number","description":"Number of digits in the generated TOTP code, must be 6 or 8","example":6,"default":6},"period":{"type":"number","description":"Number of seconds in which the TOTP code is valid","example":30,"default":30},"window":{"type":"number","description":"Number of windows to check for valid TOTP codes","example":2,"default":1},"issuer":{"type":"string","description":"TOTP issuer","example":"My Company"},"maxFailures":{"type":"number","description":"Number of wrong TOTP attempts allowed before the passcode is invalidated. Must be between 1 and 20.","example":3,"default":5,"deprecated":true},"lockoutDuration":{"type":"number","description":"TOTP lockout duration (in minutes) after maximum attempts are reached","example":15,"default":15,"deprecated":true},"maxTotpPerUser":{"type":"number","description":"Maximum number of TOTP authenticators allowed per user. Must be between 1 and 50.","example":1,"default":1}}}},"components/schemas/PushConfiguration":{"id":"components/schemas/PushConfiguration","kind":"json-schema","title":"PushConfiguration","data":{"type":"object","properties":{"apn":{"description":"APN configuration. Can be a single object or an array of objects.","oneOf":[{"$ref":"#/components/schemas/APNConfiguration"},{"type":"array","items":{"$ref":"#/components/schemas/APNConfiguration"}}],"items":{"type":"string"}},"fcm":{"description":"FCM configuration","allOf":[{"$ref":"#/components/schemas/FcmConfiguration"}]}}}},"components/schemas/PinAuthenticatorConfiguration":{"id":"components/schemas/PinAuthenticatorConfiguration","kind":"json-schema","title":"PinAuthenticatorConfiguration","data":{"type":"object","properties":{"failuresExpireIn":{"type":"number","description":"Number of minutes until previous failed attempts are considered expired. Must be between 1 and 525600 minutes (1 year).","default":15,"example":15,"minimum":1,"maximum":525600},"lockoutTiers":{"description":"Progressive lockout tiers based on failed attempts","type":"array","items":{"$ref":"#/components/schemas/LockoutTier"}},"maxFailures":{"type":"number","description":"Number of wrong PIN Authenticator attempts allowed before the passcode is invalidated. Must be between 1 and 20.","example":3,"default":5,"deprecated":true},"lockoutDuration":{"type":"number","description":"PIN Authenticator lockout duration (in minutes) after maximum attempts are reached","example":15,"default":15,"deprecated":true}}}},"components/schemas/FaceAuthenticatorConfiguration":{"id":"components/schemas/FaceAuthenticatorConfiguration","kind":"json-schema","title":"FaceAuthenticatorConfiguration","data":{"type":"object","properties":{"failuresExpireIn":{"type":"number","description":"Number of minutes until previous failed attempts are considered expired. Must be between 1 and 525600 minutes (1 year).","default":15,"example":15,"minimum":1,"maximum":525600},"lockoutTiers":{"description":"Progressive lockout tiers based on failed attempts","type":"array","items":{"$ref":"#/components/schemas/LockoutTier"}},"maxFailures":{"type":"number","description":"Number of wrong Face Authenticator attempts allowed. Must be between 1 and 20.","example":3,"default":5,"deprecated":true},"lockoutDuration":{"type":"number","description":"Face Authenticator lockout duration (in minutes) after maximum attempts are reached","example":15,"default":15,"deprecated":true},"saveImageEmbedding":{"type":"boolean","description":"Enables saving the image embedding","default":true}}}},"components/schemas/TlsClientAuth":{"id":"components/schemas/TlsClientAuth","kind":"json-schema","title":"TlsClientAuth","data":{"type":"object","properties":{"certificate_chain":{"type":"string","description":"Certificate chain including intermediate CA certificates used for client certificate validation"},"distinguished_name":{"type":"number","description":"The length of the generated OTP code. Must be between 4 and 8.","example":6},"ocsp_on":{"type":"boolean","description":"Enables OCSP (Online Certificate Status Protocol) verification"},"ocsp_responder_uri":{"type":"string","description":"OCSP responder URI"},"ocsp_responder_certificate":{"type":"string","description":"OCSP responder certificate used for signature verification"},"ocsp_fail_open":{"type":"boolean","description":"OCSP fail-open"}}}},"components/schemas/MessageConfiguration":{"id":"components/schemas/MessageConfiguration","kind":"json-schema","title":"MessageConfiguration","data":{"type":"object","properties":{"primaryColor":{"type":"string","description":"Primary color of the email, specified as a Hex color"},"from":{"type":"string","description":"Origin of the email message"},"subject":{"type":"string","description":"Subject of the email message"}},"required":["primaryColor"]}},"components/schemas/LockoutTier":{"id":"components/schemas/LockoutTier","kind":"json-schema","title":"LockoutTier","data":{"type":"object","properties":{"attempts":{"type":"number","description":"Number of failed attempts before this tier is triggered","example":3,"minimum":1},"duration":{"type":"number","description":"Lockout duration in minutes for this tier","example":15,"minimum":1,"maximum":525600}},"required":["attempts","duration"]}},"components/schemas/APNConfiguration":{"id":"components/schemas/APNConfiguration","kind":"json-schema","title":"APNConfiguration","data":{"type":"object","properties":{"key":{"type":"string","description":"APN key"},"keyId":{"type":"string","description":"APN key id"},"teamId":{"type":"string","description":"APN team id"},"bundle":{"type":"string","description":"APN bundle"},"isProduction":{"type":"boolean","description":"Is Production APN Environment"}},"required":["key","keyId","teamId","bundle"]}},"components/schemas/FcmConfiguration":{"id":"components/schemas/FcmConfiguration","kind":"json-schema","title":"FcmConfiguration","data":{"type":"object","properties":{"key":{"type":"object","description":"FCM key"}},"required":["key"]}},"schema_398":{"kind":"json-schema","data":{"title":"ApiCreatedResponse-createManagementApplication","type":"object","required":["result"],"description":"App successfully created","properties":{"result":{"$ref":"#/components/schemas/ApiApp"}}},"id":"schema_398"},"schema_399":{"kind":"json-schema","data":{"title":"ApiOkResponse-getAllManagementApplications","type":"object","required":["result"],"description":"Successfully fetched management applications","properties":{"result":{"type":"array","items":{"$ref":"#/components/schemas/ApiAppWithoutLogo"}}}},"id":"schema_399"},"schema_400":{"kind":"json-schema","data":{"type":"string"},"id":"schema_400"},"schema_401":{"kind":"json-schema","data":{"title":"ApiOkResponse-updateManagementApplication","type":"object","required":["result"],"description":"App successfully updated","properties":{"result":{"$ref":"#/components/schemas/ApiApp"}}},"id":"schema_401"}},"exampleStore":{},"securitySchemeStore":{"bearer":{"id":"bearer","type":"http","scheme":"bearer","bearerFormat":"JWT"},"UserAccessToken":{"id":"UserAccessToken","type":"http","scheme":"bearer","bearerFormat":"JWT","description":"A token returned upon end-user authentication, which provides access to resources and data for the user and app for which it was generated"},"AdminAccessToken":{"id":"AdminAccessToken","type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by a management application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to all resources for the tenant and its apps"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}},"ClientAccessToken":{"id":"ClientAccessToken","type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A token generated by an end-user application using the "},"children":[]},{"$$mdtype":"Node","type":"link","inline":true,"attributes":{"href":"/openapi/token.openapi/other/getaccesstoken"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"token endpoint"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". It provides access to resources and data on the tenant level or associated with the specific application (but not other apps in the tenant)"},"children":[]}]}]}],"flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}},"OrgAdminAccessToken":{"id":"OrgAdminAccessToken","type":"oauth2","description":"A token returned upon B2B authentication for a user that has the organizationAdmin or organizationCreator role.","flows":{"clientCredentials":{"tokenUrl":"/oidc/token","scopes":{}}}}},"servers":[{"url":"https://api.sbx.transmitsecurity.io/cis","description":"Sandbox environment"},{"url":"https://api.transmitsecurity.io/cis","description":"US production environment"},{"url":"https://api.eu.transmitsecurity.io/cis","description":"EU production environment"},{"url":"https://api.ca.transmitsecurity.io/cis","description":"CA production environment"},{"url":"https://api.au.transmitsecurity.io/cis","description":"AU production environment"},{"url":"https://api.gasne1-ts01.transmitsecurity.io/cis","description":"JP production environment"}]},"options":{"corsProxyUrl":"https://cors.redoc.ly","hideSchemaTitles":true,"onlyRequiredInSamples":false,"hideDownloadButtons":false,"codeSamples":{"skipOptionalParameters":false,"languages":[{"lang":"curl","label":"cURL"},{"lang":"Node.js"},{"lang":"Go"},{"lang":"JavaScript"},{"lang":"Java"},{"lang":"Python"}]},"feedback":{"hide":true,"settings":{"label":""}},"hideSidebar":true,"mockServer":{"off":true},"disableRouter":true,"downloadUrls":[{"url":"/_bundle/openapi/user/management-apps.openapi.json?download"},{"url":"/_bundle/openapi/user/management-apps.openapi.yaml?download"}],"excludeFromSearch":false,"specType":"openapi","markdocOptions":{"tags":{},"nodes":{},"components":{}},"metadata":{"title":"Management Apps","description":"View, create, and update your management applications. These are typically backend services accessing our platform to perform administrative actions. They can be used to generate client credentials that have tenant-level access to users, roles, apps, settings, and more."}},"baseSlug":"/openapi/user/management-apps.openapi","routesMapping":{}}