Schemas
{
"total": 42,
"limit": 20,
"offset": 0
}
Standard pagination metadata returned with collection responses.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| total |
integer |
true |
none |
Total number of records matching the query. |
| limit |
integer |
true |
none |
Maximum number of records returned in this response. |
| offset |
integer |
true |
none |
Number of records skipped before this page. |
MessageResponse
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| message |
string |
true |
none |
none |
GenericValue
Properties
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
object |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
[any] |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
string |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
number |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
boolean |
false |
none |
none |
GenericObject
Properties
None
ErrorResponse
{
"status": "error",
"code": "ORG_NOT_FOUND",
"message": "string",
"errors": [
{
"field": "string",
"message": "string"
}
]
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| status |
string |
true |
none |
Always "error" for error responses. |
| code |
string |
true |
none |
Machine-readable SCREAMING_SNAKE_CASE catalog code. |
| message |
string |
true |
none |
Human-readable error message. |
| errors |
[object] |
false |
none |
Optional per-field validation errors. |
| » field |
string |
true |
none |
none |
| » message |
string |
true |
none |
none |
Enumerated Values
| Property |
Value |
| status |
error |
OrganizationResponse
{
"id": "acme",
"displayName": "Acme Corporation",
"businessOwner": "string",
"businessOwnerContact": "string",
"businessOwnerEmail": "user@example.com",
"idpRefId": "string",
"cpRefId": "string",
"configuration": {},
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The organization's handle (unique). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
| businessOwner |
string¦null |
false |
none |
none |
| businessOwnerContact |
string¦null |
false |
none |
none |
| businessOwnerEmail |
string(email)¦null |
false |
none |
none |
| idpRefId |
string |
false |
none |
The organization claim value asserted by the configured identity provider (IDP) at single sign-on (SSO) login. On every login, the portal matches the authenticated user's org claim against this value to resolve which organization they belong to — it must exactly match the IDP's claim, or login fails for that org's users. Distinct from cpRefId, which is unrelated to authentication. |
| cpRefId |
string¦null |
false |
none |
Control Plane reference ID. Included in outbound webhook event payloads so subscribers can correlate this organization with its Control Plane (Platform API) counterpart. Not used for authentication or org resolution. |
| configuration |
object |
false |
none |
Free-form organization configuration set by the caller. Which artifact types the portal serves is operator configuration (api_portal.artifacts), not part of this. |
| createdAt |
string(date-time)¦null |
false |
none |
none |
| updatedAt |
string(date-time)¦null |
false |
none |
none |
OrganizationContentUploadResponse
{
"id": "string",
"fileName": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
true |
none |
none |
| fileName |
string |
true |
none |
Original ZIP file name uploaded in the file multipart field. |
OrganizationContentListItemResponse
{
"id": "string",
"fileName": "string",
"fileContent": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
none |
| fileName |
string |
false |
none |
none |
| fileContent |
string¦null |
false |
none |
UTF-8 content string returned for stored organization content records. |
{
"name": "string",
"title": "string",
"remotes": [
{}
],
"version": "string",
"status": "PUBLISHED",
"description": "string",
"type": "RestApi",
"referenceId": "string",
"agentVisibility": "VISIBLE",
"addedLabels": [
"string"
],
"removedLabels": [
"string"
],
"owners": {
"technicalOwner": "string",
"businessOwner": "string",
"businessOwnerEmail": "string",
"technicalOwnerEmail": "string"
},
"apiImageMetadata": {
"property1": "string",
"property2": "string"
},
"tags": [
"string"
],
"labels": [
"string"
],
"id": "string",
"refId": "string",
"endPoints": {
"sandboxURL": "string",
"productionURL": "string"
},
"subscriptionPlans": [
{
"id": "string",
"displayName": "string",
"description": "string",
"limits": [
{
"limitType": "REQUEST_COUNT",
"limitCount": 10000,
"timeUnit": "MINUTE",
"timeAmount": 1
}
],
"refId": "string",
"orgId": "string",
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
]
}
Properties
allOf
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
ApiInfoResponse |
false |
none |
Fields are returned at the root of ApiMetadataResponse / ApiMetadataCreateResponse (not nested under an apiInfo key) — this schema exists only to share the field set between the two via allOf. |
and
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
object |
false |
none |
none |
| » id |
string |
false |
none |
The API's handle (unique per org). Not the internal database uuid. |
| » refId |
string¦null |
false |
none |
Platform API (Control Plane) reference ID for this API. Used for MCP registry visibility filtering and included in outbound webhook event payloads. Null/absent for APIs that exist only in the API Portal and are not registered with the Platform API — e.g. MCP servers published via the registry. |
| » endPoints |
ApiEndpointsResponse |
false |
none |
none |
| » subscriptionPlans |
[SubscriptionPlanResponse] |
false |
none |
none |
{
"name": "string",
"title": "string",
"remotes": [
{}
],
"version": "string",
"status": "PUBLISHED",
"description": "string",
"type": "RestApi",
"referenceId": "string",
"agentVisibility": "VISIBLE",
"addedLabels": [
"string"
],
"removedLabels": [
"string"
],
"owners": {
"technicalOwner": "string",
"businessOwner": "string",
"businessOwnerEmail": "string",
"technicalOwnerEmail": "string"
},
"apiImageMetadata": {
"property1": "string",
"property2": "string"
},
"tags": [
"string"
],
"labels": [
"string"
],
"id": "string",
"refId": "string",
"dataSource": "string",
"planId": "string",
"endPoints": {
"sandboxURL": "string",
"productionURL": "string"
},
"subscriptionPlans": [
{
"id": "string",
"displayName": "string",
"description": "string",
"limits": [
{
"limitType": "REQUEST_COUNT",
"limitCount": 10000,
"timeUnit": "MINUTE",
"timeAmount": 1
}
],
"refId": "string",
"orgId": "string",
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
],
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2026-05-07T08:30:00Z",
"updatedAt": "2026-05-07T08:30:00Z"
}
Properties
allOf
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
ApiInfoResponse |
false |
none |
Fields are returned at the root of ApiMetadataResponse / ApiMetadataCreateResponse (not nested under an apiInfo key) — this schema exists only to share the field set between the two via allOf. |
and
| Name |
Type |
Required |
Restrictions |
Description |
| anonymous |
object |
false |
none |
none |
| » id |
string |
false |
none |
The API's handle (unique per org). Not the internal database uuid. |
| » refId |
string¦null |
false |
none |
Platform API (Control Plane) reference ID for this API. Used for MCP registry visibility filtering and included in outbound webhook event payloads. Null/absent for APIs that exist only in the API Portal and are not registered with the Platform API — e.g. MCP servers published via the registry. |
| » dataSource |
string¦null |
false |
none |
Indicates which content matched the search term: METADATA if the match was in the API's own metadata, or a content type (e.g. a value from the API Content type field) if the match was inside an uploaded content file. Only computed by getAllApiMetadataForOrganization when both the query search parameter is supplied and the database is PostgreSQL — absent on SQLite (the dev default) and absent from every other operation (get/create/update single API). |
| » planId |
string |
false |
none |
none |
| » endPoints |
ApiEndpointsResponse |
false |
none |
none |
| » subscriptionPlans |
[SubscriptionPlanResponse] |
false |
none |
none |
| » createdBy |
string |
false |
none |
Identity of the user who created this API, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| » updatedBy |
string |
false |
none |
Identity of the user who last updated this API, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| » createdAt |
string(date-time) |
false |
none |
none |
| » updatedAt |
string(date-time) |
false |
none |
none |
ApiInfoResponse
{
"name": "string",
"title": "string",
"remotes": [
{}
],
"version": "string",
"status": "PUBLISHED",
"description": "string",
"type": "RestApi",
"referenceId": "string",
"agentVisibility": "VISIBLE",
"addedLabels": [
"string"
],
"removedLabels": [
"string"
],
"owners": {
"technicalOwner": "string",
"businessOwner": "string",
"businessOwnerEmail": "string",
"technicalOwnerEmail": "string"
},
"apiImageMetadata": {
"property1": "string",
"property2": "string"
},
"tags": [
"string"
],
"labels": [
"string"
]
}
Fields are returned at the root of ApiMetadataResponse / ApiMetadataCreateResponse (not nested under an apiInfo key) — this schema exists only to share the field set between the two via allOf.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| name |
string |
false |
none |
none |
| title |
string¦null |
false |
none |
none |
| remotes |
[object] |
false |
none |
none |
| version |
string |
false |
none |
none |
| status |
string |
false |
none |
API lifecycle status. |
| description |
string |
false |
none |
none |
| type |
string |
false |
none |
The stored/returned type constant (src/utils/constants.js API_TYPE) — distinct from the request-time keyword accepted on create/update (see type in ApiMetadataMultipartBody: REST, SOAP, MCP, WS, WEBSUB, GRAPHQL). REST maps to RestApi and WEBSUB maps to WebSubApi; the rest are returned unchanged. |
| referenceId |
string¦null |
false |
none |
External reference ID. Present when the API was created from a YAML artifact whose spec block sets referenceId — the create response echoes the parsed YAML back. |
| agentVisibility |
string |
false |
none |
none |
| addedLabels |
[string] |
false |
none |
none |
| removedLabels |
[string] |
false |
none |
none |
| owners |
ApiOwnersResponse |
false |
none |
none |
| apiImageMetadata |
ApiImageMetadataResponse |
false |
none |
none |
| tags |
[string] |
false |
none |
none |
| labels |
[string] |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
PUBLISHED |
| status |
DEPRECATED |
| type |
RestApi |
| type |
SOAP |
| type |
Mcp |
| type |
WS |
| type |
WebSubApi |
| type |
GRAPHQL |
| agentVisibility |
VISIBLE |
| agentVisibility |
HIDDEN |
ApiOwnersResponse
{
"technicalOwner": "string",
"businessOwner": "string",
"businessOwnerEmail": "string",
"technicalOwnerEmail": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| technicalOwner |
string |
false |
none |
none |
| businessOwner |
string |
false |
none |
none |
| businessOwnerEmail |
string |
false |
none |
none |
| technicalOwnerEmail |
string |
false |
none |
none |
ApiEndpointsResponse
{
"sandboxURL": "string",
"productionURL": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| sandboxURL |
string |
false |
none |
none |
| productionURL |
string |
false |
none |
none |
{
"property1": "string",
"property2": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| additionalProperties |
string |
false |
none |
none |
SubscriptionPlanResponse
{
"id": "string",
"displayName": "string",
"description": "string",
"limits": [
{
"limitType": "REQUEST_COUNT",
"limitCount": 10000,
"timeUnit": "MINUTE",
"timeAmount": 1
}
],
"refId": "string",
"orgId": "string",
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The plan's handle (unique per org). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
| description |
string |
false |
none |
none |
| limits |
[object] |
false |
none |
Rate/quota limits enforced for this plan. Empty when the plan is unlimited. |
| » limitType |
string |
false |
none |
none |
| » limitCount |
any |
false |
none |
Returned as a string when the stored count exceeds the safe integer range, otherwise a number. Unlimited plans have no limit entries — the limits array is empty. |
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| »» anonymous |
integer |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| »» anonymous |
string |
false |
none |
none |
continued
| Name |
Type |
Required |
Restrictions |
Description |
| » timeUnit |
string¦null |
false |
none |
none |
| » timeAmount |
integer |
false |
none |
none |
| refId |
string¦null |
false |
none |
Platform API subscription plan UUID associated with this plan. |
| orgId |
string |
false |
none |
none |
| createdBy |
string |
false |
none |
Identity of the user who created this subscription plan, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| updatedBy |
string |
false |
none |
Identity of the user who last updated this subscription plan, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| createdAt |
string(date-time) |
false |
none |
none |
| updatedAt |
string(date-time) |
false |
none |
none |
Enumerated Values
| Property |
Value |
| limitType |
REQUEST_COUNT |
| limitType |
EVENT_COUNT |
| limitType |
BANDWIDTH |
| limitType |
TOTAL_TOKEN_COUNT |
| timeUnit |
MINUTE |
| timeUnit |
HOUR |
| timeUnit |
DAY |
| timeUnit |
MONTH |
| timeUnit |
null |
LabelResponse
{
"id": "premium",
"displayName": "Premium APIs"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The label's handle (unique per org). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
ApplicationResponse
{
"id": "my-weather-app",
"displayName": "Weather App",
"description": "Application used to call Weather APIs.",
"appKeyMappings": [
{
"asClientId": "asgardeo-client-abc123",
"kmId": "km-uuid-12345",
"type": "PRODUCTION"
}
],
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2026-05-07T08:30:00Z",
"updatedAt": "2026-05-07T08:30:00Z"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The application's handle (unique per org). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
| description |
string |
false |
none |
none |
| appKeyMappings |
[ApplicationKeyMappingSummary] |
false |
none |
[OAuth client ID mapping entry attached to an application.] |
| createdBy |
string |
false |
none |
Identity of the user who created this application, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| updatedBy |
string |
false |
none |
Identity of the user who last updated this application, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| createdAt |
string(date-time) |
false |
none |
none |
| updatedAt |
string(date-time) |
false |
none |
none |
ApplicationKeyMappingSummary
{
"asClientId": "asgardeo-client-abc123",
"kmId": "km-uuid-12345",
"type": "PRODUCTION"
}
OAuth client ID mapping entry attached to an application.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| asClientId |
string |
false |
none |
OAuth client ID, created directly in the key manager and linked to this application. |
| kmId |
string |
false |
none |
UUID of the key manager this client ID is linked to. |
| type |
string |
false |
none |
Key type for this mapping. |
Enumerated Values
| Property |
Value |
| type |
PRODUCTION |
| type |
SANDBOX |
ViewResponse
{
"id": "partner-apis",
"displayName": "Partner APIs",
"labels": [
"partner",
"public"
],
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
true |
none |
The view's handle (unique per org). Not the internal database uuid. |
| displayName |
string |
true |
none |
none |
| labels |
[string] |
true |
none |
none |
| createdBy |
string |
false |
none |
Identity of the user who created this view, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| updatedBy |
string |
false |
none |
Identity of the user who last updated this view, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| createdAt |
string(date-time) |
false |
none |
none |
| updatedAt |
string(date-time) |
false |
none |
none |
OrganizationCreateRequest
{
"displayName": "Acme Corporation",
"businessOwner": "string",
"businessOwnerContact": "string",
"businessOwnerEmail": "user@example.com",
"id": "acme",
"idpRefId": "string",
"cpRefId": "string",
"configuration": {}
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
true |
none |
none |
| businessOwner |
string |
false |
none |
none |
| businessOwnerContact |
string |
false |
none |
none |
| businessOwnerEmail |
string(email) |
false |
none |
none |
| id |
string |
true |
none |
Desired handle for the organization (unique), stored as-is. Used in portal URLs. |
| idpRefId |
string |
true |
none |
The organization claim value asserted by the configured Identity Provider at SSO login. Must exactly match the IDP's org claim for that org's users, or login will fail. Distinct from cpRefId. |
| cpRefId |
string¦null |
false |
none |
Control Plane reference ID, included in outbound webhook event payloads. Not used for authentication. |
| configuration |
object |
false |
none |
Free-form organization configuration. |
OrganizationUpdateRequest
{
"displayName": "Acme Corporation",
"businessOwner": "string",
"businessOwnerContact": "string",
"businessOwnerEmail": "user@example.com",
"id": "acme",
"idpRefId": "string",
"cpRefId": "string",
"configuration": {}
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
true |
none |
none |
| businessOwner |
string |
false |
none |
none |
| businessOwnerContact |
string |
false |
none |
none |
| businessOwnerEmail |
string(email) |
false |
none |
none |
| id |
string |
true |
none |
Desired handle for the organization (unique), stored as-is. Used in portal URLs. |
| idpRefId |
string |
true |
none |
The organization claim value asserted by the configured Identity Provider at SSO login. Must exactly match the IDP's org claim for that org's users, or login will fail. Distinct from cpRefId. |
| cpRefId |
string¦null |
false |
none |
Control Plane reference ID, included in outbound webhook event payloads. Not used for authentication. |
| configuration |
object |
false |
none |
Free-form organization configuration. |
SubscriptionPlanRequest
{
"id": "Gold",
"refId": "string",
"displayName": "string",
"description": "string",
"limits": [
{
"limitType": "REQUEST_COUNT",
"limitCount": 10000,
"timeUnit": "MINUTE",
"timeAmount": 1
}
]
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
Optional desired handle for the plan (unique per org), stored as-is. When omitted, the server generates a UUID handle. When the plan is created from a SubscriptionPlan YAML artifact instead, the handle is always taken from metadata.name. |
| refId |
string |
false |
none |
Platform API subscription plan UUID to associate with this plan. |
| displayName |
string |
true |
none |
none |
| description |
string |
false |
none |
none |
| limits |
[object] |
false |
none |
Rate/quota limits enforced for this plan. Omit or leave empty for an unlimited plan. Replaces the whole limit set on update. |
| » limitType |
string |
false |
none |
none |
| » limitCount |
integer |
true |
none |
Use -1 for unlimited, otherwise a positive number. |
| » timeUnit |
string¦null |
false |
none |
Omit for a limit with no time window. |
| » timeAmount |
integer |
false |
none |
Size of the time window, in timeUnit units. |
| type |
string |
false |
none |
Legacy shorthand accepted only via SubscriptionPlan/SubscriptionPlanList YAML upload (multipart/form-data); converted into limits before storage. Ignored for JSON requests — use limits instead. |
| requestCount |
any |
false |
none |
Legacy YAML shorthand paired with type: requestcount. Use -1 for unlimited. |
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
integer |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
string |
false |
none |
none |
continued
| Name |
Type |
Required |
Restrictions |
Description |
| eventCount |
any |
false |
none |
Legacy YAML shorthand paired with type: eventcount. Use -1 for unlimited. |
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
integer |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
string |
false |
none |
none |
Enumerated Values
| Property |
Value |
| limitType |
REQUEST_COUNT |
| limitType |
EVENT_COUNT |
| limitType |
BANDWIDTH |
| limitType |
TOTAL_TOKEN_COUNT |
| timeUnit |
MINUTE |
| timeUnit |
HOUR |
| timeUnit |
DAY |
| timeUnit |
MONTH |
| timeUnit |
null |
| type |
requestcount |
| type |
eventcount |
LabelRequest
{
"id": "premium",
"displayName": "Premium APIs"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
true |
none |
Desired handle for the label (unique per org), stored as-is. |
| displayName |
string |
true |
none |
none |
ApplicationRequest
{
"displayName": "Weather App",
"id": "my-weather-app",
"description": "Application used to call Weather APIs."
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
true |
none |
none |
| id |
string |
false |
none |
Immutable, org-scoped slug for the application, stored as its handle. Optional — defaults to the application's displayName when omitted. |
| description |
string |
true |
none |
none |
SubscriptionCreateRequest
{
"artifactId": "weather-api-v1",
"subscriptionPlanId": "Gold"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| artifactId |
string |
true |
none |
API ID. |
| subscriptionPlanId |
string |
true |
none |
API Portal subscription plan ID. |
SubscriptionUpdateRequest
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| status |
string |
true |
none |
none |
Enumerated Values
| Property |
Value |
| status |
ACTIVE |
| status |
INACTIVE |
SubscriptionChangePlanRequest
{
"artifactId": "weather-api-v1",
"planId": "Gold"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| artifactId |
string |
false |
none |
API ID the subscription belongs to. Optional — if provided, it is validated against the API derived from the existing subscription record and the request is rejected with 400 if they don't match. It is never used as a fallback: if the API cannot be derived from the subscription record, the request fails with 400 regardless of this value. |
| planId |
string |
true |
none |
API Portal subscription plan ID to switch to. |
SubscriptionResponse
{
"subscriptionId": "sub-12345",
"artifactId": "weather-api-v1",
"subscriptionToken": "a3f1e8b2c4d6e8f0a1b3c5d7e9f10b2c4d6e8f0a1b3c5d7e9f10b2c4d6e8f0a1",
"subscriptionPlanName": "Gold",
"status": "ACTIVE",
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
Subscription payload.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| subscriptionId |
string |
false |
none |
none |
| artifactId |
string |
false |
none |
API ID. |
| subscriptionToken |
string¦null |
false |
none |
Plaintext subscription token, decrypted on every read (not just on create). Null if decryption fails (e.g. the encryption key changed since the token was stored). |
| subscriptionPlanName |
string |
false |
none |
none |
| status |
string |
false |
none |
none |
| createdBy |
string |
false |
none |
Identity of the user who created the subscription, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| updatedBy |
string |
false |
none |
Identity of the user who last updated the subscription, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| createdAt |
string(date-time) |
false |
none |
none |
| updatedAt |
string(date-time) |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
ACTIVE |
| status |
INACTIVE |
ApiKeyRequest
{
"id": "weather_prod_key",
"displayName": "Weather Prod Key",
"subscriptionId": "sub-abc123",
"appId": "my-weather-app",
"expiresAt": "2026-12-31T23:59:59Z"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
Optional handle for the key. When provided it must match the pattern and be unique for this API; when omitted, the server generates a UUID handle. |
| displayName |
string |
false |
none |
Optional human-readable name for the key. Defaults to id when omitted. |
| subscriptionId |
string |
false |
none |
Optional subscription ID to associate the key with. |
| appId |
string |
false |
none |
Optional application ID to associate the key with, for analytics attribution only — it has no effect on the key's validity or authorization. Must belong to the same organization and be owned by the caller. |
| expiresAt |
any |
false |
none |
Optional ISO-8601 datetime with timezone, epoch seconds, or epoch milliseconds. |
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
string(date-time) |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
number |
false |
none |
none |
{
"id": "weather_prod_key",
"displayName": "Weather Prod Key",
"apiId": "weather-api-v1",
"appId": "my-weather-app",
"appDisplayName": "My Mobile App",
"status": "ACTIVE",
"expiresAt": "2026-12-31T23:59:59Z",
"createdAt": "2019-08-24T14:15:22Z",
"revokedAt": "2019-08-24T14:15:22Z"
}
API key metadata returned by list operations. Secret material is omitted.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
none |
| displayName |
string |
false |
none |
none |
| apiId |
string |
false |
none |
API ID the key belongs to. |
| appId |
string¦null |
false |
none |
ID of the application this key is associated with, if any. Analytics attribution only. |
| appDisplayName |
string¦null |
false |
none |
Display name of the associated application, if any. |
| status |
string |
false |
none |
none |
| expiresAt |
string(date-time)¦null |
false |
none |
none |
| createdAt |
string(date-time) |
false |
none |
none |
| revokedAt |
string(date-time)¦null |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
ACTIVE |
| status |
REVOKED |
ApiKeyResponse
{
"id": "weather_prod_key",
"displayName": "Weather Prod Key",
"key": "ak_dGhpcyBpcyBub3QgYSByZWFsIGtleQ",
"expiresAt": "2026-12-31T23:59:59Z",
"status": "ACTIVE"
}
API key response returned by generate/regenerate only. Unlike ApiKeyMetadataResponse, this does not include apiId, appId, appDisplayName, createdAt, or revokedAt — generate/regenerate return only these five fields.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
none |
| displayName |
string |
false |
none |
none |
| key |
string |
false |
none |
One-time plaintext API key secret. |
| expiresAt |
string(date-time)¦null |
false |
none |
none |
| status |
string |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
ACTIVE |
| status |
REVOKED |
ApiKeyApplicationResponse
{
"application": {
"id": "my-weather-app",
"displayName": "My Mobile App"
}
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| application |
object |
false |
none |
none |
| » id |
string |
false |
none |
none |
| » displayName |
string |
false |
none |
none |
KeyManagerRequest
{
"displayName": "Asgardeo",
"id": "asgardeo-prod",
"enabled": true,
"tokenEndpoint": "https://api.asgardeo.io/t/myorg/oauth2/token"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
true |
none |
none |
| id |
string |
false |
none |
Optional desired handle for the key manager (unique per org), stored as-is. When omitted, the server generates a UUID handle. A collision on a handle you supply yourself is reported as 409. |
| enabled |
boolean |
false |
none |
none |
| tokenEndpoint |
string(uri) |
true |
none |
OAuth2 token endpoint. The OAuth application itself must be created directly in this key manager; the portal only proxies client_appKeyMappings token requests to this endpoint. |
KeyManagerUpdateRequest
{
"displayName": "Asgardeo",
"id": "asgardeo-prod",
"enabled": true,
"tokenEndpoint": "https://api.asgardeo.io/t/myorg/oauth2/token"
}
Partial update payload for a key manager. All fields are optional; only supplied fields are applied. Omitted fields retain their stored values.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
false |
none |
none |
| id |
string |
false |
none |
Desired handle for the key manager (unique per org), stored as-is. |
| enabled |
boolean |
false |
none |
none |
| tokenEndpoint |
string(uri) |
false |
none |
none |
KeyManagerResponseSchema
{
"id": "asgardeo-prod",
"displayName": "Asgardeo",
"orgId": "org-12345",
"enabled": true,
"tokenEndpoint": "https://api.asgardeo.io/t/myorg/oauth2/token",
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
Key manager configuration.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The key manager's handle (unique per org). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
| orgId |
string |
false |
none |
none |
| enabled |
boolean |
false |
none |
none |
| tokenEndpoint |
string(uri) |
false |
none |
none |
| createdBy |
string |
false |
none |
Identity of the user who created this key manager, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| updatedBy |
string |
false |
none |
Identity of the user who last updated this key manager, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| createdAt |
string(date-time) |
false |
none |
none |
| updatedAt |
string(date-time) |
false |
none |
none |
KeyManagerPublicResponseSchema
{
"id": "asgardeo-prod",
"displayName": "Asgardeo",
"tokenEndpoint": "https://api.asgardeo.io/t/myorg/oauth2/token"
}
Minimal developer-facing key manager view.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The key manager's handle (unique per org). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
| tokenEndpoint |
string(uri) |
false |
none |
none |
WebhookSubscriberRequest
{
"id": "production-gateway",
"displayName": "Production Gateway",
"targetUrl": "https://gateway.example.com/api-portal-webhook",
"secret": "<shared-secret>",
"events": [
"apikey.*",
"subscription.*"
],
"enabled": true,
"timeoutMs": 5000
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
Optional handle for the webhook subscriber (unique per org), stored as-is. When omitted, the server generates a UUID handle. Supply it only when you need a specific, stable identifier — it is the id used in the resource path, and a collision on a handle you supplied yourself is reported as 409. |
| displayName |
string |
true |
none |
Display name for the webhook subscriber. |
| targetUrl |
string(uri) |
true |
none |
Target URL events are POSTed to. |
| secret |
string |
false |
none |
Shared secret, used for two purposes. It signs outgoing payloads with a hash-based message authentication code (HMAC-SHA256). It also derives, through HKDF-SHA3-256, the AES-256-GCM key that encrypts sensitive fields in apikey.* and subscription.* payloads, so only the subscriber can read the plaintext. Encrypted fields arrive as data.iv, data.tag, and data.ciphertext; the derivation and a worked decryption example are documented in the webhook event catalog. Stored encrypted, and never returned in responses. |
| events |
[string] |
false |
none |
Glob-style event type allowlist (only a trailing * wildcard is supported, e.g. apikey.*). Omit or leave empty to receive all event types. |
| enabled |
boolean |
false |
none |
none |
| timeoutMs |
integer |
false |
none |
none |
WebhookSubscriberResponseSchema
{
"id": "production-gateway",
"orgId": "org-12345",
"displayName": "Production Gateway",
"targetUrl": "https://gateway.example.com/api-portal-webhook",
"enabled": true,
"events": [
"apikey.*",
"subscription.*"
],
"timeoutMs": 5000,
"hasSecret": true,
"createdBy": "alice@example.com",
"updatedBy": "alice@example.com",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z"
}
Webhook subscriber configuration. The secret is never included.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The webhook subscriber's handle (unique per org). Not the internal database uuid. |
| orgId |
string |
false |
none |
none |
| displayName |
string |
false |
none |
none |
| targetUrl |
string(uri) |
false |
none |
none |
| enabled |
boolean |
false |
none |
none |
| events |
[string] |
false |
none |
none |
| timeoutMs |
integer |
false |
none |
none |
| hasSecret |
boolean |
false |
none |
Whether a secret is configured. The same secret serves two purposes. It signs outgoing payloads with a hash-based message authentication code (HMAC), and it derives the AES-256-GCM key that encrypts sensitive fields. Encrypted fields arrive as data.iv, data.tag, and data.ciphertext; the derivation and a worked decryption example are documented in the webhook event catalog. |
| createdBy |
string |
false |
none |
Identity of the user who created this webhook subscriber, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses and list items. |
| updatedBy |
string |
false |
none |
Identity of the user who last updated this webhook subscriber, or deleted_user if that user's IDP reference no longer exists. Present on single-resource GET responses only, omitted on list items. |
| createdAt |
string(date-time) |
false |
none |
none |
| updatedAt |
string(date-time) |
false |
none |
none |
WebhookSubscriberDeliverySummary
{
"deliveryId": "del-abc123",
"eventType": "apikey.generated",
"occurredAt": "2019-08-24T14:15:22Z",
"status": "DELIVERED",
"lastHttpStatus": 200,
"lastError": "string",
"lastAttemptAt": "2019-08-24T14:15:22Z",
"deliveredAt": "2019-08-24T14:15:22Z"
}
A single delivery attempt made to a webhook subscriber.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| deliveryId |
string |
false |
none |
none |
| eventType |
string¦null |
false |
none |
none |
| occurredAt |
string(date-time)¦null |
false |
none |
none |
| status |
string |
false |
none |
none |
| lastHttpStatus |
integer¦null |
false |
none |
none |
| lastError |
string¦null |
false |
none |
none |
| lastAttemptAt |
string(date-time)¦null |
false |
none |
none |
| deliveredAt |
string(date-time)¦null |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
PENDING |
| status |
IN_FLIGHT |
| status |
DELIVERED |
| status |
FAILED |
AppKeyMappingRequest
{
"keyManager": "Resident Key Manager",
"type": "PRODUCTION",
"consumerKey": "consumer-key-123"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| keyManager |
string |
true |
none |
none |
| type |
string |
false |
none |
none |
| consumerKey |
string |
true |
none |
The OAuth client_id, created directly in the key manager. The portal does not store or persist the client secret — it is supplied per-request when generating a token and is only seen transiently during that request. |
Enumerated Values
| Property |
Value |
| type |
PRODUCTION |
| type |
SANDBOX |
ViewCreateRequest
{
"id": "partner-apis",
"displayName": "Partner APIs",
"labels": [
"partner",
"public"
]
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
true |
none |
Desired handle for the view (unique per org), stored as-is. |
| displayName |
string |
false |
none |
Optional display name. Defaults to the handle when omitted. |
| labels |
[string] |
true |
none |
Label names to attach to the view. |
ViewUpdateRequest
{
"displayName": "Partner and Public APIs",
"labels": [
"partner",
"premium"
]
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
false |
none |
none |
| labels |
[string] |
false |
none |
Full desired set of label names for the view. Labels present here but not currently attached are attached; labels currently attached but absent here are detached. Omit to leave labels unchanged. |
OAuthGenerateTokenRequest
{
"consumerSecret": "my-consumer-secret",
"scopes": [
"weather.read"
],
"validityPeriod": 3600
}
OAuth access token generation payload. consumerSecret is required — the portal uses it to call the Authorization Server token endpoint directly.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| consumerSecret |
string |
true |
none |
Client secret for the OAuth application. Not stored by the portal — the caller must supply it on each token generation request. |
| scopes |
[string] |
false |
none |
none |
| validityPeriod |
integer |
false |
none |
none |
ApplicationOAuthKeyResponse
{
"keyMappingId": "km-12345",
"keyManager": "Resident Key Manager",
"type": "PRODUCTION",
"consumerKey": "consumer-key-123",
"tokenEndpoint": "https://api.asgardeo.io/t/myorg/oauth2/token"
}
OAuth key mapping payload.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| keyMappingId |
string |
false |
none |
none |
| keyManager |
string |
false |
none |
none |
| type |
string |
false |
none |
none |
| consumerKey |
string |
false |
none |
none |
| tokenEndpoint |
string(uri) |
false |
none |
none |
OAuthTokenResponse
{
"accessToken": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.example",
"validityTime": 3600,
"tokenScopes": [
"weather.read"
]
}
Access token response proxied from the key manager's token endpoint. Field names are the portal's own camelCase, not the underlying OAuth2 token response's snake_case.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| accessToken |
string |
false |
none |
none |
| validityTime |
integer¦null |
false |
none |
Token lifetime in seconds, as reported by the key manager (expires_in). |
| tokenScopes |
[string] |
false |
none |
none |
APIWorkflowCreateResponse
{
"id": "workflow-12345",
"displayName": "Weather onboarding",
"status": "PUBLISHED"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
none |
| displayName |
string |
false |
none |
none |
| status |
string |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
DRAFT |
| status |
PUBLISHED |
APIWorkflowResponse
{
"id": "workflow-12345",
"displayName": "Weather onboarding",
"description": "string",
"agentPrompt": "string",
"status": "PUBLISHED",
"agentVisibility": "VISIBLE",
"contentType": "ARAZZO",
"apiWorkflowDefinition": "string",
"markdownContent": "string",
"createdAt": "May 7, 2026",
"updatedAt": "string",
"createdBy": "string",
"updatedBy": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| id |
string |
false |
none |
The workflow's handle (unique per org and view). Not the internal database uuid. |
| displayName |
string |
false |
none |
none |
| description |
string |
false |
none |
none |
| agentPrompt |
string |
false |
none |
none |
| status |
string |
false |
none |
none |
| agentVisibility |
string |
false |
none |
none |
| contentType |
string |
false |
none |
none |
| apiWorkflowDefinition |
string¦null |
false |
none |
none |
| markdownContent |
string¦null |
false |
none |
none |
| createdAt |
string |
false |
none |
none |
| updatedAt |
string¦null |
false |
none |
none |
| createdBy |
string¦null |
false |
none |
none |
| updatedBy |
string¦null |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
DRAFT |
| status |
PUBLISHED |
| agentVisibility |
VISIBLE |
| agentVisibility |
HIDDEN |
| contentType |
ARAZZO |
| contentType |
MD |
APIWorkflowPromptResponse
{
"agentPrompt": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| agentPrompt |
string |
false |
none |
none |
APIWorkflowCreateRequest
{
"displayName": "Weather onboarding",
"id": "weather-onboarding",
"description": "Guides users through the Weather API onboarding workflow.",
"agentPrompt": "Follow this workflow to onboard a Weather API user.",
"status": "PUBLISHED",
"agentVisibility": "VISIBLE",
"contentType": "ARAZZO",
"apiWorkflowDefinition": {},
"markdownContent": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
true |
none |
none |
| id |
string |
false |
none |
Desired handle for the workflow (unique per org and view), stored as-is. |
| description |
string |
true |
none |
none |
| agentPrompt |
string |
false |
none |
none |
| status |
string |
false |
none |
none |
| agentVisibility |
string |
false |
none |
none |
| contentType |
string |
false |
none |
none |
| apiWorkflowDefinition |
any |
false |
none |
JSON/YAML Arazzo content when contentType is ARAZZO. |
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
object |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
string |
false |
none |
none |
continued
| Name |
Type |
Required |
Restrictions |
Description |
| markdownContent |
string |
false |
none |
Markdown content when contentType is MD. |
Enumerated Values
| Property |
Value |
| status |
DRAFT |
| status |
PUBLISHED |
| agentVisibility |
VISIBLE |
| agentVisibility |
HIDDEN |
| contentType |
ARAZZO |
| contentType |
MD |
APIWorkflowUpdateRequest
{
"displayName": "Weather onboarding v2",
"id": "weather-onboarding-v2",
"description": "Updated Weather API onboarding workflow.",
"agentPrompt": "string",
"status": "PUBLISHED",
"agentVisibility": "VISIBLE",
"contentType": "ARAZZO",
"apiWorkflowDefinition": {},
"markdownContent": "string"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
false |
none |
none |
| id |
string |
false |
none |
Desired handle for the workflow (unique per org and view), stored as-is. |
| description |
string |
false |
none |
none |
| agentPrompt |
string |
false |
none |
none |
| status |
string |
false |
none |
none |
| agentVisibility |
string |
false |
none |
none |
| contentType |
string |
false |
none |
none |
| apiWorkflowDefinition |
any |
false |
none |
none |
oneOf
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
object |
false |
none |
none |
xor
| Name |
Type |
Required |
Restrictions |
Description |
| » anonymous |
string |
false |
none |
none |
continued
| Name |
Type |
Required |
Restrictions |
Description |
| markdownContent |
string |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
DRAFT |
| status |
PUBLISHED |
| agentVisibility |
VISIBLE |
| agentVisibility |
HIDDEN |
| contentType |
ARAZZO |
| contentType |
MD |
APIWorkflowPromptRequest
{
"displayName": "Weather onboarding",
"description": "Guides users through the Weather API onboarding workflow.",
"apis": [
{}
],
"orgHandle": "acme",
"viewName": "default",
"id": "weather-onboarding"
}
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| displayName |
string |
true |
none |
none |
| description |
string |
true |
none |
none |
| apis |
[object] |
false |
none |
none |
| orgHandle |
string |
false |
none |
none |
| viewName |
string |
false |
none |
none |
| id |
string |
false |
none |
The workflow's (would-be) handle, used only to build the workflow detail URL referenced in the generated prompt. |
WebhookEventDelivery
{
"deliveryId": "del-abc123",
"subscriberId": "sub-xyz789",
"targetUrl": "https://example.com/webhook",
"status": "DELIVERED",
"lastHttpStatus": 200,
"lastError": "string",
"lastAttemptAt": "2019-08-24T14:15:22Z",
"deliveredAt": "2019-08-24T14:15:22Z"
}
A single webhook delivery attempt.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| deliveryId |
string |
false |
none |
none |
| subscriberId |
string |
false |
none |
none |
| targetUrl |
string¦null |
false |
none |
none |
| status |
string |
false |
none |
none |
| lastHttpStatus |
integer¦null |
false |
none |
none |
| lastError |
string¦null |
false |
none |
none |
| lastAttemptAt |
string(date-time)¦null |
false |
none |
none |
| deliveredAt |
string(date-time)¦null |
false |
none |
none |
Enumerated Values
| Property |
Value |
| status |
PENDING |
| status |
IN_FLIGHT |
| status |
DELIVERED |
| status |
FAILED |
WebhookEvent
{
"eventId": "evt-abc123",
"eventType": "apikey.generated",
"orgId": "org-default",
"aggregateType": "apikey",
"aggregateId": "key-12345",
"status": "ALL_DELIVERED",
"occurredAt": "2019-08-24T14:15:22Z",
"deliveries": [
{
"deliveryId": "del-abc123",
"subscriberId": "sub-xyz789",
"targetUrl": "https://example.com/webhook",
"status": "DELIVERED",
"lastHttpStatus": 200,
"lastError": "string",
"lastAttemptAt": "2019-08-24T14:15:22Z",
"deliveredAt": "2019-08-24T14:15:22Z"
}
]
}
A webhook event with its delivery rows.
Properties
| Name |
Type |
Required |
Restrictions |
Description |
| eventId |
string |
false |
none |
none |
| eventType |
string |
false |
none |
none |
| orgId |
string |
false |
none |
none |
| aggregateType |
string |
false |
none |
none |
| aggregateId |
string |
false |
none |
none |
| status |
string |
false |
none |
none |
| occurredAt |
string(date-time) |
false |
none |
none |
| deliveries |
[WebhookEventDelivery] |
false |
none |
[A single webhook delivery attempt.] |
Enumerated Values
| Property |
Value |
| status |
PENDING |
| status |
DISPATCHED |
| status |
ALL_DELIVERED |
| status |
FAILED |